Publish Advisories

GHSA-4mg4-wvmx-5332
GHSA-gc9g-67cq-p7v4
GHSA-hm2p-fhwx-9285
GHSA-rr8j-7w34-xp5j
This commit is contained in:
advisory-database[bot]
2024-10-18 21:50:40 +00:00
parent b7ab9dbabb
commit bb9d2b0934
4 changed files with 53 additions and 5 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4mg4-wvmx-5332",
"modified": "2021-05-27T21:39:48Z",
"modified": "2024-10-18T21:49:19Z",
"published": "2021-06-15T16:11:47Z",
"aliases": [
"CVE-2021-33510"
@@ -12,6 +12,10 @@
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
}
],
"affected": [
@@ -40,6 +44,18 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-33510"
},
{
"type": "ADVISORY",
"url": "https://github.com/advisories/GHSA-4mg4-wvmx-5332"
},
{
"type": "PACKAGE",
"url": "https://github.com/plone/Plone"
},
{
"type": "WEB",
"url": "https://github.com/pypa/advisory-database/tree/main/vulns/plone/PYSEC-2021-82.yaml"
},
{
"type": "WEB",
"url": "https://plone.org/security/hotfix/20210518/server-side-request-forgery-via-event-ical-url"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gc9g-67cq-p7v4",
"modified": "2021-05-27T21:47:01Z",
"modified": "2024-10-18T21:48:44Z",
"published": "2021-06-15T16:12:04Z",
"aliases": [
"CVE-2021-33511"
@@ -12,6 +12,10 @@
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
}
],
"affected": [
@@ -40,6 +44,18 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-33511"
},
{
"type": "ADVISORY",
"url": "https://github.com/advisories/GHSA-gc9g-67cq-p7v4"
},
{
"type": "PACKAGE",
"url": "https://github.com/plone/Plone"
},
{
"type": "WEB",
"url": "https://github.com/pypa/advisory-database/tree/main/vulns/plone/PYSEC-2021-83.yaml"
},
{
"type": "WEB",
"url": "https://plone.org/security/hotfix/20210518/server-side-request-forgery-via-lxml-parser"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hm2p-fhwx-9285",
"modified": "2021-05-27T21:32:19Z",
"modified": "2024-10-18T21:49:59Z",
"published": "2021-06-15T16:11:38Z",
"aliases": [
"CVE-2021-33509"
@@ -12,6 +12,10 @@
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"
}
],
"affected": [
@@ -40,6 +44,18 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-33509"
},
{
"type": "ADVISORY",
"url": "https://github.com/advisories/GHSA-hm2p-fhwx-9285"
},
{
"type": "PACKAGE",
"url": "https://github.com/plone/Plone"
},
{
"type": "WEB",
"url": "https://github.com/pypa/advisory-database/tree/main/vulns/plone/PYSEC-2021-81.yaml"
},
{
"type": "WEB",
"url": "https://plone.org/security/hotfix/20210518/writing-arbitrary-files-via-docutils-and-python-script"
@@ -1,13 +1,13 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rr8j-7w34-xp5j",
"modified": "2024-10-11T16:52:47Z",
"modified": "2024-10-18T21:48:29Z",
"published": "2024-10-10T21:30:43Z",
"aliases": [
"CVE-2024-9180"
],
"summary": "Vault Community Edition privilege escalation vulnerability",
"details": "A privileged Vault operator with write permissions to the root namespaces identity endpoint could escalate their privileges to Vaults root policy. Fixed in Vault Community Edition 1.18.0 and Vault Enterprise 1.18.0, 1.17.7, 1.16.11, and 1.15.16.",
"details": "A privileged Vault operator with write permissions to the root namespaces identity endpoint could escalate their privileges to Vaults root policy. Fixed in Vault Community Edition 1.18.0 and Vault Enterprise 1.18.0, 1.17.7, 1.16.11, and 1.15.16",
"severity": [
{
"type": "CVSS_V3",