From ae73e9aabdca6fbaa06c52b8346bcbac574035e2 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 2 Aug 2024 10:46:46 +0000 Subject: [PATCH] Publish GHSA-rmqp-mvv2-54c6 --- .../02/GHSA-rmqp-mvv2-54c6/GHSA-rmqp-mvv2-54c6.json | 11 +++++++++-- 1 file changed, 9 insertions(+), 2 deletions(-) diff --git a/advisories/github-reviewed/2024/02/GHSA-rmqp-mvv2-54c6/GHSA-rmqp-mvv2-54c6.json b/advisories/github-reviewed/2024/02/GHSA-rmqp-mvv2-54c6/GHSA-rmqp-mvv2-54c6.json index 912d922a605..11cbb20ad00 100644 --- a/advisories/github-reviewed/2024/02/GHSA-rmqp-mvv2-54c6/GHSA-rmqp-mvv2-54c6.json +++ b/advisories/github-reviewed/2024/02/GHSA-rmqp-mvv2-54c6/GHSA-rmqp-mvv2-54c6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rmqp-mvv2-54c6", - "modified": "2024-02-22T19:31:41Z", + "modified": "2024-08-02T10:45:18Z", "published": "2024-02-22T12:30:56Z", "aliases": [ "CVE-2024-22393" @@ -9,7 +9,14 @@ "summary": "Apache Answer Unrestricted Upload of File with Dangerous Type vulnerability", "details": "Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer through 1.2.1.\n\nPixel Flood Attack by uploading large pixel files will cause server out of memory. A logged-in user can cause such an attack by uploading an image when posting content.\n\nUsers are recommended to upgrade to version 1.2.5, which fixes the issue.\n\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N" + } ], "affected": [ {