Publish Advisories

GHSA-6x49-w35h-wqrj
GHSA-jqpc-rc7g-vf83
GHSA-qjfx-fvx7-3wvw
GHSA-6x49-w35h-wqrj
GHSA-qjfx-fvx7-3wvw
This commit is contained in:
advisory-database[bot]
2023-12-15 23:20:49 +00:00
parent 86054ff89e
commit b8f057f60f
5 changed files with 211 additions and 81 deletions
@@ -0,0 +1,81 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6x49-w35h-wqrj",
"modified": "2023-12-15T23:20:28Z",
"published": "2023-12-15T09:30:17Z",
"aliases": [
"CVE-2023-29234"
],
"summary": "Bypass serialize checks in Apache Dubbo",
"details": "A deserialization vulnerability existed when decode a malicious package.This issue affects Apache Dubbo: from 3.1.0 through 3.1.10, from 3.2.0 through 3.2.4.\n\nUsers are recommended to upgrade to the latest version, which fixes the issue.\n\n",
"severity": [
],
"affected": [
{
"package": {
"ecosystem": "Maven",
"name": "org.apache.dubbo:dubbo"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "3.1.0"
},
{
"fixed": "3.1.11"
}
]
}
]
},
{
"package": {
"ecosystem": "Maven",
"name": "org.apache.dubbo:dubbo"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "3.2.0"
},
{
"fixed": "3.2.5"
}
]
}
]
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29234"
},
{
"type": "PACKAGE",
"url": "https://github.com/apache/dubbo"
},
{
"type": "WEB",
"url": "https://lists.apache.org/thread/wb2df2whkdnbgp54nnqn0m94rllx8f77"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2023/12/15/2"
}
],
"database_specific": {
"cwe_ids": [
"CWE-502"
],
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2023-12-15T23:20:28Z",
"nvd_published_at": "2023-12-15T09:15:07Z"
}
}
File diff suppressed because one or more lines are too long
@@ -0,0 +1,65 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qjfx-fvx7-3wvw",
"modified": "2023-12-15T23:19:56Z",
"published": "2023-12-15T03:30:18Z",
"aliases": [
"CVE-2023-6832"
],
"summary": "Business Logic Errors in microweber/microweber",
"details": "A vulnerability has been identified in microweber where users can purchase items with a coupon code. If the admin disables the use of the coupon code functionality, but the user sends requests to the API that handles the coupon code, the user can exploit the vulnerability and obtain items at a lower price.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:L"
}
],
"affected": [
{
"package": {
"ecosystem": "Packagist",
"name": "microweber/microweber"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "2.0"
}
]
}
]
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6832"
},
{
"type": "WEB",
"url": "https://github.com/microweber/microweber/commit/890e9838aabbc799ebefcf6b20ba25e0fd6dbfee"
},
{
"type": "PACKAGE",
"url": "https://github.com/microweber/microweber"
},
{
"type": "WEB",
"url": "https://huntr.com/bounties/53105a20-f4b1-45ad-a734-0349de6d7376"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2023-12-15T23:19:56Z",
"nvd_published_at": "2023-12-15T01:15:08Z"
}
}
@@ -1,39 +0,0 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6x49-w35h-wqrj",
"modified": "2023-12-15T09:30:17Z",
"published": "2023-12-15T09:30:17Z",
"aliases": [
"CVE-2023-29234"
],
"details": "A deserialization vulnerability existed when decode a malicious package.This issue affects Apache Dubbo: from 3.1.0 through 3.1.10, from 3.2.0 through 3.2.4.\n\nUsers are recommended to upgrade to the latest version, which fixes the issue.\n\n",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29234"
},
{
"type": "WEB",
"url": "https://lists.apache.org/thread/wb2df2whkdnbgp54nnqn0m94rllx8f77"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2023/12/15/2"
}
],
"database_specific": {
"cwe_ids": [
"CWE-502"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-15T09:15:07Z"
}
}
@@ -1,42 +0,0 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qjfx-fvx7-3wvw",
"modified": "2023-12-15T03:30:18Z",
"published": "2023-12-15T03:30:18Z",
"aliases": [
"CVE-2023-6832"
],
"details": "Business Logic Errors in GitHub repository microweber/microweber prior to 2.0.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6832"
},
{
"type": "WEB",
"url": "https://github.com/microweber/microweber/commit/890e9838aabbc799ebefcf6b20ba25e0fd6dbfee"
},
{
"type": "WEB",
"url": "https://huntr.com/bounties/53105a20-f4b1-45ad-a734-0349de6d7376"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-12-15T01:15:08Z"
}
}