Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2023-05-22 00:31:34 +00:00
parent cfe8e27452
commit b0fe9dc6b1
33 changed files with 277 additions and 15 deletions
@@ -33,6 +33,10 @@
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZTIAMP7QJDKV4ADDLR4GVVX2TXYLHVOZ/"
},
{
"type": "WEB",
"url": "https://security.gentoo.org/glsa/202305-26"
},
{
"type": "WEB",
"url": "https://talosintelligence.com/vulnerability_reports/TALOS-2021-1349"
@@ -44,6 +48,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-119",
"CWE-787"
],
"severity": "HIGH",
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7h7h-4rmp-2qm5",
"modified": "2021-12-30T00:00:35Z",
"modified": "2023-05-22T00:30:18Z",
"published": "2021-12-21T00:00:46Z",
"aliases": [
"CVE-2021-44858"
],
"details": "An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. It is possible to use action=edit&undo= followed by action=mcrundo and action=mcrrestore to view private pages on a private wiki that has at least one page set in $wgWhitelistRead.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
@@ -22,6 +25,10 @@
"type": "WEB",
"url": "https://phabricator.wikimedia.org/T297322"
},
{
"type": "WEB",
"url": "https://security.gentoo.org/glsa/202305-24"
},
{
"type": "WEB",
"url": "https://www.mediawiki.org/wiki/2021-12_security_release/FAQ"
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8rcg-5g7w-gw95",
"modified": "2021-12-22T00:01:38Z",
"modified": "2023-05-22T00:30:18Z",
"published": "2021-12-18T00:01:08Z",
"aliases": [
"CVE-2021-45038"
],
"details": "An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. By using an action=rollback query, attackers can view private wiki contents.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [
@@ -22,6 +25,10 @@
"type": "WEB",
"url": "https://phabricator.wikimedia.org/T297574"
},
{
"type": "WEB",
"url": "https://security.gentoo.org/glsa/202305-24"
},
{
"type": "WEB",
"url": "https://www.mediawiki.org/wiki/2021-12_security_release/FAQ"
@@ -25,6 +25,10 @@
"type": "WEB",
"url": "https://phabricator.wikimedia.org/T297322"
},
{
"type": "WEB",
"url": "https://security.gentoo.org/glsa/202305-24"
},
{
"type": "WEB",
"url": "https://www.mediawiki.org/wiki/2021-12_security_release/FAQ"
@@ -32,7 +36,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-269"
"CWE-269",
"CWE-862"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -33,6 +33,10 @@
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VUMH3CWGVSMR2UIZEA35Q5UB7PDVVVYS/"
},
{
"type": "WEB",
"url": "https://security.gentoo.org/glsa/202305-26"
},
{
"type": "WEB",
"url": "https://www.debian.org/security/2022/dsa-5077"
@@ -33,6 +33,10 @@
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VUMH3CWGVSMR2UIZEA35Q5UB7PDVVVYS/"
},
{
"type": "WEB",
"url": "https://security.gentoo.org/glsa/202305-26"
},
{
"type": "WEB",
"url": "https://www.debian.org/security/2022/dsa-5077"
@@ -33,6 +33,10 @@
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VUMH3CWGVSMR2UIZEA35Q5UB7PDVVVYS/"
},
{
"type": "WEB",
"url": "https://security.gentoo.org/glsa/202305-26"
},
{
"type": "WEB",
"url": "https://www.debian.org/security/2022/dsa-5077"
@@ -28,6 +28,10 @@
{
"type": "WEB",
"url": "https://phabricator.wikimedia.org/T304126"
},
{
"type": "WEB",
"url": "https://security.gentoo.org/glsa/202305-24"
}
],
"database_specific": {
@@ -33,6 +33,10 @@
"type": "WEB",
"url": "https://phabricator.wikimedia.org/T297543"
},
{
"type": "WEB",
"url": "https://security.gentoo.org/glsa/202305-24"
},
{
"type": "WEB",
"url": "https://www.debian.org/security/2022/dsa-5246"
@@ -28,6 +28,10 @@
{
"type": "WEB",
"url": "https://phabricator.wikimedia.org/T294256"
},
{
"type": "WEB",
"url": "https://security.gentoo.org/glsa/202305-24"
}
],
"database_specific": {
@@ -28,6 +28,10 @@
{
"type": "WEB",
"url": "https://phabricator.wikimedia.org/T302248"
},
{
"type": "WEB",
"url": "https://security.gentoo.org/glsa/202305-24"
}
],
"database_specific": {
@@ -48,6 +48,10 @@
{
"type": "WEB",
"url": "https://portswigger.net/daily-swig/waf-bypass-severe-owasp-modsecurity-core-rule-set-bug-was-present-for-several-years"
},
{
"type": "WEB",
"url": "https://security.gentoo.org/glsa/202305-25"
}
],
"database_specific": {
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6w7p-46mm-c2fc",
"modified": "2022-05-24T19:17:14Z",
"modified": "2023-05-22T00:30:17Z",
"published": "2022-05-24T19:17:14Z",
"aliases": [
"CVE-2021-41798"
],
"details": "MediaWiki before 1.36.2 allows XSS. Month related MediaWiki messages are not escaped before being used on the Special:Search results page.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -33,6 +36,10 @@
{
"type": "WEB",
"url": "https://phabricator.wikimedia.org/T285515"
},
{
"type": "WEB",
"url": "https://security.gentoo.org/glsa/202305-24"
}
],
"database_specific": {
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c8wv-qwwc-6j73",
"modified": "2022-05-24T19:17:14Z",
"modified": "2023-05-22T00:30:18Z",
"published": "2022-05-24T19:17:14Z",
"aliases": [
"CVE-2021-41800"
],
"details": "MediaWiki before 1.36.2 allows a denial of service (resource consumption because of lengthy query processing time). Visiting Special:Contributions can sometimes result in a long running SQL query because PoolCounter protection is mishandled.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
}
],
"affected": [
@@ -41,6 +44,10 @@
{
"type": "WEB",
"url": "https://phabricator.wikimedia.org/T284419"
},
{
"type": "WEB",
"url": "https://security.gentoo.org/glsa/202305-24"
}
],
"database_specific": {
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h7pp-5ppj-95mv",
"modified": "2022-05-24T19:17:14Z",
"modified": "2023-05-22T00:30:18Z",
"published": "2022-05-24T19:17:14Z",
"aliases": [
"CVE-2021-41799"
],
"details": "MediaWiki before 1.36.2 allows a denial of service (resource consumption because of lengthy query processing time). ApiQueryBacklinks (action=query&list=backlinks) can cause a full table scan.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
@@ -37,6 +40,10 @@
{
"type": "WEB",
"url": "https://phabricator.wikimedia.org/T290394"
},
{
"type": "WEB",
"url": "https://security.gentoo.org/glsa/202305-24"
}
],
"database_specific": {
@@ -33,6 +33,10 @@
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZTIAMP7QJDKV4ADDLR4GVVX2TXYLHVOZ/"
},
{
"type": "WEB",
"url": "https://security.gentoo.org/glsa/202305-26"
},
{
"type": "WEB",
"url": "https://talosintelligence.com/vulnerability_reports/TALOS-2021-1351"
@@ -33,6 +33,10 @@
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZTIAMP7QJDKV4ADDLR4GVVX2TXYLHVOZ/"
},
{
"type": "WEB",
"url": "https://security.gentoo.org/glsa/202305-26"
},
{
"type": "WEB",
"url": "https://talosintelligence.com/vulnerability_reports/TALOS-2021-1350"
@@ -44,6 +48,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-119",
"CWE-787"
],
"severity": "HIGH",
@@ -37,6 +37,10 @@
"type": "WEB",
"url": "https://phabricator.wikimedia.org/T308473"
},
{
"type": "WEB",
"url": "https://security.gentoo.org/glsa/202305-24"
},
{
"type": "WEB",
"url": "https://www.debian.org/security/2022/dsa-5246"
@@ -37,6 +37,10 @@
"type": "WEB",
"url": "https://phabricator.wikimedia.org/T308471"
},
{
"type": "WEB",
"url": "https://security.gentoo.org/glsa/202305-24"
},
{
"type": "WEB",
"url": "https://www.debian.org/security/2022/dsa-5246"
@@ -40,11 +40,16 @@
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YPQ6CCMX3MU4A7MTCGQJA7VMJW3IQDXV/"
},
{
"type": "WEB",
"url": "https://security.gentoo.org/glsa/202305-25"
}
],
"database_specific": {
"cwe_ids": [
"CWE-116"
"CWE-116",
"CWE-863"
],
"severity": "HIGH",
"github_reviewed": false,

Some files were not shown because too many files have changed in this diff Show More