diff --git a/advisories/github-reviewed/2024/02/GHSA-44jg-jgjx-3xg5/GHSA-44jg-jgjx-3xg5.json b/advisories/github-reviewed/2024/02/GHSA-44jg-jgjx-3xg5/GHSA-44jg-jgjx-3xg5.json new file mode 100644 index 00000000000..88694f837aa --- /dev/null +++ b/advisories/github-reviewed/2024/02/GHSA-44jg-jgjx-3xg5/GHSA-44jg-jgjx-3xg5.json @@ -0,0 +1,118 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-44jg-jgjx-3xg5", + "modified": "2024-02-21T23:30:36Z", + "published": "2024-02-21T03:30:38Z", + "aliases": [ + "CVE-2024-25603" + ], + "summary": "Liferay Portal's Dynamic Data Mapping module's DDMForm and Liferay DXP vulnerable to stored Cross-site Scripting", + "details": "Stored cross-site scripting (XSS) vulnerability in the Dynamic Data Mapping module's DDMForm in Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13, 7.3 before update 4, 7.2 before fix pack 17, and older unsupported versions allows remote authenticated users to inject arbitrary web script or HTML via the instanceId parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Maven", + "name": "com.liferay.portal:release.portal.bom" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "7.4.3.4" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "com.liferay.portal:release.dxp.bom" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "7.4.13.u1" + }, + { + "last_affected": "7.4.13.u102" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "com.liferay.portal:release.dxp.bom" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "7.3.10.ep3" + }, + { + "fixed": "7.3.10.u4" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "com.liferay.portal:release.dxp.bom" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "7.2.0" + }, + { + "fixed": "7.2.10.fp17" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25603" + }, + { + "type": "PACKAGE", + "url": "https://github.com/liferay/liferay-portal" + }, + { + "type": "WEB", + "url": "https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2024-25603" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "CRITICAL", + "github_reviewed": true, + "github_reviewed_at": "2024-02-21T23:30:35Z", + "nvd_published_at": "2024-02-21T03:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/02/GHSA-468x-frcm-ghx6/GHSA-468x-frcm-ghx6.json b/advisories/github-reviewed/2024/02/GHSA-468x-frcm-ghx6/GHSA-468x-frcm-ghx6.json new file mode 100644 index 00000000000..f145a954a78 --- /dev/null +++ b/advisories/github-reviewed/2024/02/GHSA-468x-frcm-ghx6/GHSA-468x-frcm-ghx6.json @@ -0,0 +1,99 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-468x-frcm-ghx6", + "modified": "2024-02-21T23:30:00Z", + "published": "2024-02-21T03:30:37Z", + "aliases": [ + "CVE-2023-40191" + ], + "summary": "Liferay Portal and Liferay DXP vulnerable to reflected Cross-site Scripting", + "details": "Reflected cross-site scripting (XSS) vulnerability in the instance settings for Accounts in Liferay Portal 7.4.3.44 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 6, and 7.4 update 44 through 92 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into the “Blocked Email Domains” text field", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Maven", + "name": "com.liferay.portal:release.portal.bom" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "7.4.3.44" + }, + { + "last_affected": "7.4.3.97" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "com.liferay.portal:release.dxp.bom" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2023.Q3" + }, + { + "fixed": "2023.Q3.6" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "com.liferay.portal:release.dxp.bom" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "7.4.13.u44" + }, + { + "last_affected": "7.4.13.u92" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40191" + }, + { + "type": "PACKAGE", + "url": "https://github.com/liferay/liferay-portal" + }, + { + "type": "WEB", + "url": "https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2023-40191" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "CRITICAL", + "github_reviewed": true, + "github_reviewed_at": "2024-02-21T23:30:00Z", + "nvd_published_at": "2024-02-21T03:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/02/GHSA-54pv-r62j-9qqc/GHSA-54pv-r62j-9qqc.json b/advisories/github-reviewed/2024/02/GHSA-54pv-r62j-9qqc/GHSA-54pv-r62j-9qqc.json new file mode 100644 index 00000000000..030c7d226e5 --- /dev/null +++ b/advisories/github-reviewed/2024/02/GHSA-54pv-r62j-9qqc/GHSA-54pv-r62j-9qqc.json @@ -0,0 +1,118 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-54pv-r62j-9qqc", + "modified": "2024-02-21T23:29:48Z", + "published": "2024-02-21T03:30:37Z", + "aliases": [ + "CVE-2023-42496" + ], + "summary": "Liferay Portal and Liferay DXP vulnerable to reflected Cross-site Scripting", + "details": "Reflected cross-site scripting (XSS) vulnerability on the add assignees to a role page in Liferay Portal 7.3.3 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 6, 7.4 GA through update 92, and 7.3 before update 34 allows remote attackers to inject arbitrary web script or HTML via the `_com_liferay_roles_admin_web_portlet_RolesAdminPortlet_tabs2` parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Maven", + "name": "com.liferay.portal:release.portal.bom" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "7.3.3" + }, + { + "last_affected": "7.4.3.97" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "com.liferay.portal:release.dxp.bom" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "7.4.10.ep1" + }, + { + "last_affected": "7.4.13.u92" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "com.liferay.portal:release.dxp.bom" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "7.3.10.ep3" + }, + { + "fixed": "7.3.10.u34" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "com.liferay.portal:release.dxp.bom" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2023.Q3" + }, + { + "fixed": "2023.Q3.6" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-42496" + }, + { + "type": "PACKAGE", + "url": "https://github.com/liferay/liferay-portal" + }, + { + "type": "WEB", + "url": "https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2023-42496" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "CRITICAL", + "github_reviewed": true, + "github_reviewed_at": "2024-02-21T23:29:48Z", + "nvd_published_at": "2024-02-21T03:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/02/GHSA-73x3-8mrg-5r93/GHSA-73x3-8mrg-5r93.json b/advisories/github-reviewed/2024/02/GHSA-73x3-8mrg-5r93/GHSA-73x3-8mrg-5r93.json new file mode 100644 index 00000000000..b5d51efdff4 --- /dev/null +++ b/advisories/github-reviewed/2024/02/GHSA-73x3-8mrg-5r93/GHSA-73x3-8mrg-5r93.json @@ -0,0 +1,99 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-73x3-8mrg-5r93", + "modified": "2024-02-21T23:30:19Z", + "published": "2024-02-21T03:30:37Z", + "aliases": [ + "CVE-2023-42498" + ], + "summary": "Liferay Portal Language Override edit screen and Liferay DXP vulnerable to reflected Cross-site Scripting", + "details": "Reflected cross-site scripting (XSS) vulnerability in the Language Override edit screen in Liferay Portal 7.4.3.8 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 5, and 7.4 update 4 through 92 allows remote attackers to inject arbitrary web script or HTML via the `_com_liferay_portal_language_override_web_internal_portlet_PLOPortlet_key` parameter.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Maven", + "name": "com.liferay.portal:release.portal.bom" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "7.4.3.8" + }, + { + "last_affected": "7.4.3.97" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "com.liferay.portal:release.dxp.bom" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2023.Q3" + }, + { + "fixed": "2023.Q3.5" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "com.liferay.portal:release.dxp.bom" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "7.4.13.u4" + }, + { + "last_affected": "7.4.13.u92" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-42498" + }, + { + "type": "PACKAGE", + "url": "https://github.com/liferay/liferay-portal" + }, + { + "type": "WEB", + "url": "https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2023-42498" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "CRITICAL", + "github_reviewed": true, + "github_reviewed_at": "2024-02-21T23:30:19Z", + "nvd_published_at": "2024-02-21T03:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/02/GHSA-cr36-3vqf-x5w5/GHSA-cr36-3vqf-x5w5.json b/advisories/github-reviewed/2024/02/GHSA-cr36-3vqf-x5w5/GHSA-cr36-3vqf-x5w5.json new file mode 100644 index 00000000000..83a71ac1c52 --- /dev/null +++ b/advisories/github-reviewed/2024/02/GHSA-cr36-3vqf-x5w5/GHSA-cr36-3vqf-x5w5.json @@ -0,0 +1,99 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cr36-3vqf-x5w5", + "modified": "2024-02-21T23:29:35Z", + "published": "2024-02-21T03:30:37Z", + "aliases": [ + "CVE-2024-25601" + ], + "summary": "Liferay Portal Expando module and Liferay DXP vulnerable to stored Cross-site Scripting", + "details": "Stored cross-site scripting (XSS) vulnerability in Expando module's geolocation custom fields in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported versions allows remote authenticated users to inject arbitrary web script or HTML via a crafted payload injected into the name text field of a geolocation custom field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Maven", + "name": "com.liferay.portal:release.portal.bom" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "7.4.2" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "com.liferay.portal:release.dxp.bom" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "7.3.0" + }, + { + "fixed": "7.3.10.u4" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "com.liferay.portal:release.dxp.bom" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "7.2.0" + }, + { + "fixed": "7.2.10.fp17" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25601" + }, + { + "type": "PACKAGE", + "url": "https://github.com/liferay/liferay-portal" + }, + { + "type": "WEB", + "url": "https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2024-25601" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "CRITICAL", + "github_reviewed": true, + "github_reviewed_at": "2024-02-21T23:29:35Z", + "nvd_published_at": "2024-02-21T02:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/02/GHSA-rwhv-hvj2-qrqm/GHSA-rwhv-hvj2-qrqm.json b/advisories/github-reviewed/2024/02/GHSA-rwhv-hvj2-qrqm/GHSA-rwhv-hvj2-qrqm.json new file mode 100644 index 00000000000..fe66841d8da --- /dev/null +++ b/advisories/github-reviewed/2024/02/GHSA-rwhv-hvj2-qrqm/GHSA-rwhv-hvj2-qrqm.json @@ -0,0 +1,118 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rwhv-hvj2-qrqm", + "modified": "2024-02-21T23:31:54Z", + "published": "2024-02-21T03:30:38Z", + "aliases": [ + "CVE-2024-26269" + ], + "summary": "Liferay Portal Frontend JS module's portlet.js and Liferay DXP vulnerable to Cross-site Scripting", + "details": "Cross-site scripting (XSS) vulnerability in the Frontend JS module's portlet.js in Liferay Portal 7.2.0 through 7.4.3.37, and Liferay DXP 7.4 before update 38, 7.3 before update 11, 7.2 before fix pack 20, and older unsupported versions allows remote attackers to inject arbitrary web script or HTML via the anchor (hash) part of a URL.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Maven", + "name": "com.liferay.portal:release.portal.bom" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "7.2.0" + }, + { + "last_affected": "7.4.3.37" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "com.liferay.portal:release.dxp.bom" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "7.4.13.u1" + }, + { + "fixed": "7.4.13.u38" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "com.liferay.portal:release.dxp.bom" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "7.3.10.ep3" + }, + { + "fixed": "7.3.10.u11" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "com.liferay.portal:release.dxp.bom" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "7.2.0" + }, + { + "fixed": "7.2.10.fp20" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26269" + }, + { + "type": "PACKAGE", + "url": "https://github.com/liferay/liferay-portal" + }, + { + "type": "WEB", + "url": "https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2024-26269" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "CRITICAL", + "github_reviewed": true, + "github_reviewed_at": "2024-02-21T23:31:54Z", + "nvd_published_at": "2024-02-21T03:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/02/GHSA-rwxc-4cmw-7x75/GHSA-rwxc-4cmw-7x75.json b/advisories/github-reviewed/2024/02/GHSA-rwxc-4cmw-7x75/GHSA-rwxc-4cmw-7x75.json new file mode 100644 index 00000000000..62b882e9887 --- /dev/null +++ b/advisories/github-reviewed/2024/02/GHSA-rwxc-4cmw-7x75/GHSA-rwxc-4cmw-7x75.json @@ -0,0 +1,118 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rwxc-4cmw-7x75", + "modified": "2024-02-21T23:30:52Z", + "published": "2024-02-21T03:30:38Z", + "aliases": [ + "CVE-2024-26266" + ], + "summary": "Liferay Portal and Liferay DXP vulnerable to stored Cross-site Scripting", + "details": "Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.2.0 through 7.4.3.13, and older unsupported versions, and Liferay DXP 7.4 before update 10, 7.3 before update 4, 7.2 before fix pack 17, and older unsupported versions allow remote authenticated users to inject arbitrary web script or HTML via a crafted payload injected into the first/middle/last name text field of the user who creates an entry in the (1) Announcement widget, or (2) Alerts widget.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Maven", + "name": "com.liferay.portal:release.portal.bom" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "7.4.3.13" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "com.liferay.portal:release.dxp.bom" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "7.4.13.u1" + }, + { + "fixed": "7.4.13.u10" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "com.liferay.portal:release.dxp.bom" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "7.3.10.ep3" + }, + { + "fixed": "7.3.10.u4" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "com.liferay.portal:release.dxp.bom" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "7.2.0" + }, + { + "fixed": "7.2.10.fp17" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26266" + }, + { + "type": "PACKAGE", + "url": "https://github.com/liferay/liferay-portal" + }, + { + "type": "WEB", + "url": "https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2024-26266" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "CRITICAL", + "github_reviewed": true, + "github_reviewed_at": "2024-02-21T23:30:52Z", + "nvd_published_at": "2024-02-21T03:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-44jg-jgjx-3xg5/GHSA-44jg-jgjx-3xg5.json b/advisories/unreviewed/2024/02/GHSA-44jg-jgjx-3xg5/GHSA-44jg-jgjx-3xg5.json deleted file mode 100644 index cf8353e8b51..00000000000 --- a/advisories/unreviewed/2024/02/GHSA-44jg-jgjx-3xg5/GHSA-44jg-jgjx-3xg5.json +++ /dev/null @@ -1,38 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-44jg-jgjx-3xg5", - "modified": "2024-02-21T03:30:38Z", - "published": "2024-02-21T03:30:38Z", - "aliases": [ - "CVE-2024-25603" - ], - "details": "Stored cross-site scripting (XSS) vulnerability in the Dynamic Data Mapping module's DDMForm in Liferay Portal 7.2.0 through 7.4.3.4, and older unsupported versions, and Liferay DXP 7.4.13, 7.3 before update 4, 7.2 before fix pack 17, and older unsupported versions allows remote authenticated users to inject arbitrary web script or HTML via the instanceId parameter.", - "severity": [ - { - "type": "CVSS_V3", - "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H" - } - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25603" - }, - { - "type": "WEB", - "url": "https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2024-25603" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-79" - ], - "severity": "CRITICAL", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2024-02-21T03:15:09Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-468x-frcm-ghx6/GHSA-468x-frcm-ghx6.json b/advisories/unreviewed/2024/02/GHSA-468x-frcm-ghx6/GHSA-468x-frcm-ghx6.json deleted file mode 100644 index 6caf2adcb57..00000000000 --- a/advisories/unreviewed/2024/02/GHSA-468x-frcm-ghx6/GHSA-468x-frcm-ghx6.json +++ /dev/null @@ -1,38 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-468x-frcm-ghx6", - "modified": "2024-02-21T03:30:37Z", - "published": "2024-02-21T03:30:37Z", - "aliases": [ - "CVE-2023-40191" - ], - "details": "Reflected cross-site scripting (XSS) vulnerability in the instance settings for Accounts in Liferay Portal 7.4.3.44 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 6, and 7.4 update 44 through 92 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into the “Blocked Email Domains” text field", - "severity": [ - { - "type": "CVSS_V3", - "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H" - } - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-40191" - }, - { - "type": "WEB", - "url": "https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2023-40191" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-79" - ], - "severity": "CRITICAL", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2024-02-21T03:15:07Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-54pv-r62j-9qqc/GHSA-54pv-r62j-9qqc.json b/advisories/unreviewed/2024/02/GHSA-54pv-r62j-9qqc/GHSA-54pv-r62j-9qqc.json deleted file mode 100644 index 5b4d6d83f61..00000000000 --- a/advisories/unreviewed/2024/02/GHSA-54pv-r62j-9qqc/GHSA-54pv-r62j-9qqc.json +++ /dev/null @@ -1,38 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-54pv-r62j-9qqc", - "modified": "2024-02-21T03:30:37Z", - "published": "2024-02-21T03:30:37Z", - "aliases": [ - "CVE-2023-42496" - ], - "details": "Reflected cross-site scripting (XSS) vulnerability on the add assignees to a role page in Liferay Portal 7.3.3 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 6, 7.4 GA through update 92, and 7.3 before update 34 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_roles_admin_web_portlet_RolesAdminPortlet_tabs2 parameter.", - "severity": [ - { - "type": "CVSS_V3", - "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" - } - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-42496" - }, - { - "type": "WEB", - "url": "https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2023-42496" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-79" - ], - "severity": "CRITICAL", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2024-02-21T03:15:08Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-73x3-8mrg-5r93/GHSA-73x3-8mrg-5r93.json b/advisories/unreviewed/2024/02/GHSA-73x3-8mrg-5r93/GHSA-73x3-8mrg-5r93.json deleted file mode 100644 index e4cacb31dd9..00000000000 --- a/advisories/unreviewed/2024/02/GHSA-73x3-8mrg-5r93/GHSA-73x3-8mrg-5r93.json +++ /dev/null @@ -1,38 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-73x3-8mrg-5r93", - "modified": "2024-02-21T03:30:37Z", - "published": "2024-02-21T03:30:37Z", - "aliases": [ - "CVE-2023-42498" - ], - "details": "Reflected cross-site scripting (XSS) vulnerability in the Language Override edit screen in Liferay Portal 7.4.3.8 through 7.4.3.97, and Liferay DXP 2023.Q3 before patch 5, and 7.4 update 4 through 92 allows remote attackers to inject arbitrary web script or HTML via the _com_liferay_portal_language_override_web_internal_portlet_PLOPortlet_key parameter.", - "severity": [ - { - "type": "CVSS_V3", - "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" - } - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-42498" - }, - { - "type": "WEB", - "url": "https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2023-42498" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-79" - ], - "severity": "CRITICAL", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2024-02-21T03:15:08Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-cr36-3vqf-x5w5/GHSA-cr36-3vqf-x5w5.json b/advisories/unreviewed/2024/02/GHSA-cr36-3vqf-x5w5/GHSA-cr36-3vqf-x5w5.json deleted file mode 100644 index b0175646ce0..00000000000 --- a/advisories/unreviewed/2024/02/GHSA-cr36-3vqf-x5w5/GHSA-cr36-3vqf-x5w5.json +++ /dev/null @@ -1,38 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-cr36-3vqf-x5w5", - "modified": "2024-02-21T03:30:37Z", - "published": "2024-02-21T03:30:37Z", - "aliases": [ - "CVE-2024-25601" - ], - "details": "Stored cross-site scripting (XSS) vulnerability in Expando module's geolocation custom fields in Liferay Portal 7.2.0 through 7.4.2, and older unsupported versions, and Liferay DXP 7.3 before service pack 3, 7.2 before fix pack 17, and older unsupported versions allows remote authenticated users to inject arbitrary web script or HTML via a crafted payload injected into the name text field of a geolocation custom field.", - "severity": [ - { - "type": "CVSS_V3", - "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H" - } - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25601" - }, - { - "type": "WEB", - "url": "https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2024-25601" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-79" - ], - "severity": "CRITICAL", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2024-02-21T02:15:30Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-rwhv-hvj2-qrqm/GHSA-rwhv-hvj2-qrqm.json b/advisories/unreviewed/2024/02/GHSA-rwhv-hvj2-qrqm/GHSA-rwhv-hvj2-qrqm.json deleted file mode 100644 index 3535d1cf3c4..00000000000 --- a/advisories/unreviewed/2024/02/GHSA-rwhv-hvj2-qrqm/GHSA-rwhv-hvj2-qrqm.json +++ /dev/null @@ -1,38 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-rwhv-hvj2-qrqm", - "modified": "2024-02-21T03:30:38Z", - "published": "2024-02-21T03:30:38Z", - "aliases": [ - "CVE-2024-26269" - ], - "details": "Cross-site scripting (XSS) vulnerability in the Frontend JS module's portlet.js in Liferay Portal 7.2.0 through 7.4.3.37, and Liferay DXP 7.4 before update 38, 7.3 before update 11, 7.2 before fix pack 20, and older unsupported versions allows remote attackers to inject arbitrary web script or HTML via the anchor (hash) part of a URL.", - "severity": [ - { - "type": "CVSS_V3", - "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" - } - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26269" - }, - { - "type": "WEB", - "url": "https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2024-26269" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-79" - ], - "severity": "CRITICAL", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2024-02-21T03:15:09Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-rwxc-4cmw-7x75/GHSA-rwxc-4cmw-7x75.json b/advisories/unreviewed/2024/02/GHSA-rwxc-4cmw-7x75/GHSA-rwxc-4cmw-7x75.json deleted file mode 100644 index ecbbc7616b9..00000000000 --- a/advisories/unreviewed/2024/02/GHSA-rwxc-4cmw-7x75/GHSA-rwxc-4cmw-7x75.json +++ /dev/null @@ -1,38 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-rwxc-4cmw-7x75", - "modified": "2024-02-21T03:30:38Z", - "published": "2024-02-21T03:30:38Z", - "aliases": [ - "CVE-2024-26266" - ], - "details": "Multiple stored cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.2.0 through 7.4.3.13, and older unsupported versions, and Liferay DXP 7.4 before update 10, 7.3 before update 4, 7.2 before fix pack 17, and older unsupported versions allow remote authenticated users to inject arbitrary web script or HTML via a crafted payload injected into the first/middle/last name text field of the user who creates an entry in the (1) Announcement widget, or (2) Alerts widget.", - "severity": [ - { - "type": "CVSS_V3", - "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H" - } - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26266" - }, - { - "type": "WEB", - "url": "https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2024-26266" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-79" - ], - "severity": "CRITICAL", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2024-02-21T03:15:09Z" - } -} \ No newline at end of file