diff --git a/advisories/github-reviewed/2022/01/GHSA-3mm4-w7v6-4rhv/GHSA-3mm4-w7v6-4rhv.json b/advisories/github-reviewed/2022/01/GHSA-3mm4-w7v6-4rhv/GHSA-3mm4-w7v6-4rhv.json new file mode 100644 index 00000000000..e3b445b17b5 --- /dev/null +++ b/advisories/github-reviewed/2022/01/GHSA-3mm4-w7v6-4rhv/GHSA-3mm4-w7v6-4rhv.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3mm4-w7v6-4rhv", + "modified": "2025-01-13T15:22:57Z", + "published": "2022-01-20T00:01:54Z", + "aliases": [ + "CVE-2022-23435" + ], + "summary": "android-gif-drawable vulerable to denial of service due to unrestricted comment length", + "details": "decoding.c in android-gif-drawable before 1.2.24 does not limit the maximum length of a comment, leading to denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Maven", + "name": "pl.droidsonroids.gif:android-gif-drawable" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.2.24" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-23435" + }, + { + "type": "WEB", + "url": "https://github.com/koral--/android-gif-drawable/issues/792#issuecomment-1048850678" + }, + { + "type": "WEB", + "url": "https://github.com/koral--/android-gif-drawable/commit/9f0f0c89e6fa38548163771feeb4bde84b828887" + }, + { + "type": "PACKAGE", + "url": "https://github.com/koral--/android-gif-drawable" + }, + { + "type": "WEB", + "url": "https://github.com/koral--/android-gif-drawable/compare/v1.2.23...v1.2.24" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-770" + ], + "severity": "HIGH", + "github_reviewed": true, + "github_reviewed_at": "2025-01-13T15:22:57Z", + "nvd_published_at": "2022-01-19T01:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2025/01/GHSA-97h9-p9f8-4p3r/GHSA-97h9-p9f8-4p3r.json b/advisories/github-reviewed/2025/01/GHSA-97h9-p9f8-4p3r/GHSA-97h9-p9f8-4p3r.json new file mode 100644 index 00000000000..61ca807b469 --- /dev/null +++ b/advisories/github-reviewed/2025/01/GHSA-97h9-p9f8-4p3r/GHSA-97h9-p9f8-4p3r.json @@ -0,0 +1,61 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-97h9-p9f8-4p3r", + "modified": "2025-01-13T15:23:30Z", + "published": "2025-01-10T21:31:27Z", + "aliases": [ + "CVE-2024-33299" + ], + "summary": "Microweber Cross-site Scripting vulnerability", + "details": "Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the First Name and Last Name parameters in the endpoint /admin/module/view?type=users", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:P" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "microweber/microweber" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "2.0.9" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33299" + }, + { + "type": "WEB", + "url": "https://github.com/MathSabo/CVE-2024-33299" + }, + { + "type": "PACKAGE", + "url": "https://github.com/microweber/microweber" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2025-01-13T15:23:30Z", + "nvd_published_at": "2025-01-10T20:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2025/01/GHSA-j4v9-cm37-h7c2/GHSA-j4v9-cm37-h7c2.json b/advisories/github-reviewed/2025/01/GHSA-j4v9-cm37-h7c2/GHSA-j4v9-cm37-h7c2.json new file mode 100644 index 00000000000..8bdf7f5123a --- /dev/null +++ b/advisories/github-reviewed/2025/01/GHSA-j4v9-cm37-h7c2/GHSA-j4v9-cm37-h7c2.json @@ -0,0 +1,61 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j4v9-cm37-h7c2", + "modified": "2025-01-13T15:23:12Z", + "published": "2025-01-10T21:31:27Z", + "aliases": [ + "CVE-2024-33297" + ], + "summary": "Microweber Cross-site Scripting vulnerability", + "details": "Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the campaign Name (Internal Name) field in the Add new campaign function", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:P" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "microweber/microweber" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "2.0.9" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33297" + }, + { + "type": "WEB", + "url": "https://github.com/MathSabo/CVE-2024-33297" + }, + { + "type": "PACKAGE", + "url": "https://github.com/microweber/microweber" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2025-01-13T15:23:12Z", + "nvd_published_at": "2025-01-10T20:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2025/01/GHSA-w5g5-4jj3-8f6v/GHSA-w5g5-4jj3-8f6v.json b/advisories/github-reviewed/2025/01/GHSA-w5g5-4jj3-8f6v/GHSA-w5g5-4jj3-8f6v.json new file mode 100644 index 00000000000..dbe94e73dcd --- /dev/null +++ b/advisories/github-reviewed/2025/01/GHSA-w5g5-4jj3-8f6v/GHSA-w5g5-4jj3-8f6v.json @@ -0,0 +1,61 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w5g5-4jj3-8f6v", + "modified": "2025-01-13T15:23:23Z", + "published": "2025-01-10T21:31:27Z", + "aliases": [ + "CVE-2024-33298" + ], + "summary": "Microweber Cross-site Scripting vulnerability", + "details": "Microweber Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the create new backup function in the endpoint /admin/module/view?type=admin__backup", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:P" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "microweber/microweber" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "2.0.9" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33298" + }, + { + "type": "WEB", + "url": "https://github.com/MathSabo/CVE-2024-33298" + }, + { + "type": "PACKAGE", + "url": "https://github.com/microweber/microweber" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2025-01-13T15:23:23Z", + "nvd_published_at": "2025-01-10T20:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/01/GHSA-3mm4-w7v6-4rhv/GHSA-3mm4-w7v6-4rhv.json b/advisories/unreviewed/2022/01/GHSA-3mm4-w7v6-4rhv/GHSA-3mm4-w7v6-4rhv.json deleted file mode 100644 index 4331cad12dd..00000000000 --- a/advisories/unreviewed/2022/01/GHSA-3mm4-w7v6-4rhv/GHSA-3mm4-w7v6-4rhv.json +++ /dev/null @@ -1,33 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-3mm4-w7v6-4rhv", - "modified": "2022-01-26T00:02:58Z", - "published": "2022-01-20T00:01:54Z", - "aliases": [ - "CVE-2022-23435" - ], - "details": "decoding.c in android-gif-drawable before 1.2.24 does not limit the maximum length of a comment, leading to denial of service.", - "severity": [], - "affected": [], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-23435" - }, - { - "type": "WEB", - "url": "https://github.com/koral--/android-gif-drawable/commit/9f0f0c89e6fa38548163771feeb4bde84b828887" - }, - { - "type": "WEB", - "url": "https://github.com/koral--/android-gif-drawable/compare/v1.2.23...v1.2.24" - } - ], - "database_specific": { - "cwe_ids": [], - "severity": "HIGH", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2022-01-19T01:15:00Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-97h9-p9f8-4p3r/GHSA-97h9-p9f8-4p3r.json b/advisories/unreviewed/2025/01/GHSA-97h9-p9f8-4p3r/GHSA-97h9-p9f8-4p3r.json deleted file mode 100644 index 78d5932b387..00000000000 --- a/advisories/unreviewed/2025/01/GHSA-97h9-p9f8-4p3r/GHSA-97h9-p9f8-4p3r.json +++ /dev/null @@ -1,29 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-97h9-p9f8-4p3r", - "modified": "2025-01-10T21:31:27Z", - "published": "2025-01-10T21:31:27Z", - "aliases": [ - "CVE-2024-33299" - ], - "details": "Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the First Name and Last Name parameters in the endpoint /admin/module/view?type=users", - "severity": [], - "affected": [], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33299" - }, - { - "type": "WEB", - "url": "https://github.com/MathSabo/CVE-2024-33299" - } - ], - "database_specific": { - "cwe_ids": [], - "severity": null, - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2025-01-10T20:15:30Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-j4v9-cm37-h7c2/GHSA-j4v9-cm37-h7c2.json b/advisories/unreviewed/2025/01/GHSA-j4v9-cm37-h7c2/GHSA-j4v9-cm37-h7c2.json deleted file mode 100644 index 034452a7c94..00000000000 --- a/advisories/unreviewed/2025/01/GHSA-j4v9-cm37-h7c2/GHSA-j4v9-cm37-h7c2.json +++ /dev/null @@ -1,29 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-j4v9-cm37-h7c2", - "modified": "2025-01-10T21:31:27Z", - "published": "2025-01-10T21:31:27Z", - "aliases": [ - "CVE-2024-33297" - ], - "details": "Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the campaign Name (Internal Name) field in the Add new campaign function", - "severity": [], - "affected": [], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33297" - }, - { - "type": "WEB", - "url": "https://github.com/MathSabo/CVE-2024-33297" - } - ], - "database_specific": { - "cwe_ids": [], - "severity": null, - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2025-01-10T20:15:30Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-w5g5-4jj3-8f6v/GHSA-w5g5-4jj3-8f6v.json b/advisories/unreviewed/2025/01/GHSA-w5g5-4jj3-8f6v/GHSA-w5g5-4jj3-8f6v.json deleted file mode 100644 index 386cbe38114..00000000000 --- a/advisories/unreviewed/2025/01/GHSA-w5g5-4jj3-8f6v/GHSA-w5g5-4jj3-8f6v.json +++ /dev/null @@ -1,29 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-w5g5-4jj3-8f6v", - "modified": "2025-01-10T21:31:27Z", - "published": "2025-01-10T21:31:27Z", - "aliases": [ - "CVE-2024-33298" - ], - "details": "Microweber Cross Site Scripting vulnerability in Microweber v.2.0.9 allows a remote attacker to execute arbitrary code via the create new backup function in the endpoint /admin/module/view?type=admin__backup", - "severity": [], - "affected": [], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33298" - }, - { - "type": "WEB", - "url": "https://github.com/MathSabo/CVE-2024-33298" - } - ], - "database_specific": { - "cwe_ids": [], - "severity": null, - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2025-01-10T20:15:30Z" - } -} \ No newline at end of file