diff --git a/advisories/github-reviewed/2024/02/GHSA-p5q9-86w4-2xr5/GHSA-p5q9-86w4-2xr5.json b/advisories/github-reviewed/2024/02/GHSA-p5q9-86w4-2xr5/GHSA-p5q9-86w4-2xr5.json new file mode 100644 index 00000000000..ea197503800 --- /dev/null +++ b/advisories/github-reviewed/2024/02/GHSA-p5q9-86w4-2xr5/GHSA-p5q9-86w4-2xr5.json @@ -0,0 +1,100 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p5q9-86w4-2xr5", + "modified": "2024-02-27T18:58:24Z", + "published": "2024-02-27T15:30:31Z", + "aliases": [ + "CVE-2023-51747" + ], + "summary": "Apache James vulnerable to SMTP smuggling", + "details": "Apache James prior to versions 3.8.1 and 3.7.5 is vulnerable to SMTP smuggling.\n\nA lenient behaviour in line delimiter handling might create a difference of interpretation between the sender and the receiver which can be exploited by an attacker to forge an SMTP envelop, allowing for instance to bypass SPF checks.\n\nThe patch implies enforcement of CRLF as a line delimiter as part of the DATA transaction.\n\nWe recommend James users to upgrade to non vulnerable versions.", + "severity": [ + + ], + "affected": [ + { + "package": { + "ecosystem": "Maven", + "name": "org.apache.james:james-project" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.7.5" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "org.apache.james:james-project" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.8.0" + }, + { + "fixed": "3.8.1" + } + ] + } + ], + "versions": [ + "3.8.0" + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51747" + }, + { + "type": "WEB", + "url": "https://github.com/apache/james-project/commit/d1ef102540e504c067b6c1721a6f1e7eee9c6fc6" + }, + { + "type": "WEB", + "url": "https://github.com/apache/james-project/commit/d5cd8bb098aa78d8d62c9645f3c532689ef1cb03" + }, + { + "type": "PACKAGE", + "url": "https://github.com/apache/james-project" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/rxkwbkh9vgbl9rzx1fkllyk3krhgydko" + }, + { + "type": "WEB", + "url": "https://postfix.org/smtp-smuggling.html" + }, + { + "type": "WEB", + "url": "https://sec-consult.com/blog/detail/smtp-smuggling-spoofing-e-mails-worldwide" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/02/27/4" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-02-27T18:58:24Z", + "nvd_published_at": "2024-02-27T14:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2021/11/GHSA-c89g-8x66-fjfg/GHSA-c89g-8x66-fjfg.json b/advisories/unreviewed/2021/11/GHSA-c89g-8x66-fjfg/GHSA-c89g-8x66-fjfg.json index 884bead35a3..f71ab56e9d2 100644 --- a/advisories/unreviewed/2021/11/GHSA-c89g-8x66-fjfg/GHSA-c89g-8x66-fjfg.json +++ b/advisories/unreviewed/2021/11/GHSA-c89g-8x66-fjfg/GHSA-c89g-8x66-fjfg.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c89g-8x66-fjfg", - "modified": "2021-11-21T00:00:39Z", + "modified": "2024-02-27T18:59:04Z", "published": "2021-11-21T00:00:39Z", "aliases": [ "CVE-2021-34358" ], "details": "We have already fixed this vulnerability in the following versions of QmailAgent: QmailAgent 3.0.2 ( 2021/08/25 ) and later", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-352" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2021-11-20T01:15:00Z" diff --git a/advisories/unreviewed/2021/11/GHSA-hjq5-v65p-2p24/GHSA-hjq5-v65p-2p24.json b/advisories/unreviewed/2021/11/GHSA-hjq5-v65p-2p24/GHSA-hjq5-v65p-2p24.json index b0e7c2e9ba7..372255f4572 100644 --- a/advisories/unreviewed/2021/11/GHSA-hjq5-v65p-2p24/GHSA-hjq5-v65p-2p24.json +++ b/advisories/unreviewed/2021/11/GHSA-hjq5-v65p-2p24/GHSA-hjq5-v65p-2p24.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-hjq5-v65p-2p24", - "modified": "2021-11-20T00:00:54Z", + "modified": "2024-02-27T18:59:09Z", "published": "2021-11-20T00:00:54Z", "aliases": [ "CVE-2021-41435" ], "details": "A brute-force protection bypass in CAPTCHA protection in ASUS ROG Rapture GT-AX11000, RT-AX3000, RT-AX55, RT-AX56U, RT-AX56U_V2, RT-AX58U, RT-AX82U, RT-AX82U GUNDAM EDITION, RT-AX86 Series(RT-AX86U/RT-AX86S), RT-AX86U ZAKU II EDITION, RT-AX88U, RT-AX92U, TUF Gaming AX3000, TUF Gaming AX5400 (TUF-AX5400), ASUS ZenWiFi XD6, ASUS ZenWiFi AX (XT8) before 3.0.0.4.386.45898, and RT-AX68U before 3.0.0.4.386.45911, allows a remote attacker to attempt any number of login attempts via sending a specific HTTP request.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -53,9 +56,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-307" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2021-11-19T12:15:00Z" diff --git a/advisories/unreviewed/2021/11/GHSA-wv95-5rrj-gjm9/GHSA-wv95-5rrj-gjm9.json b/advisories/unreviewed/2021/11/GHSA-wv95-5rrj-gjm9/GHSA-wv95-5rrj-gjm9.json index e3dabde5866..8c1495d4655 100644 --- a/advisories/unreviewed/2021/11/GHSA-wv95-5rrj-gjm9/GHSA-wv95-5rrj-gjm9.json +++ b/advisories/unreviewed/2021/11/GHSA-wv95-5rrj-gjm9/GHSA-wv95-5rrj-gjm9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-wv95-5rrj-gjm9", - "modified": "2021-11-21T00:00:39Z", + "modified": "2024-02-27T18:59:12Z", "published": "2021-11-21T00:00:39Z", "aliases": [ "CVE-2021-36320" ], "details": "Dell Networking X-Series firmware versions prior to 3.0.1.8 contain an authentication bypass vulnerability. A remote unauthenticated attacker may potentially hijack a session and access the webserver by forging the session ID.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -27,7 +30,7 @@ "cwe_ids": [ "CWE-331" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2021-11-20T02:15:00Z" diff --git a/advisories/unreviewed/2024/02/GHSA-p5q9-86w4-2xr5/GHSA-p5q9-86w4-2xr5.json b/advisories/unreviewed/2024/02/GHSA-p5q9-86w4-2xr5/GHSA-p5q9-86w4-2xr5.json deleted file mode 100644 index ffa04e275ef..00000000000 --- a/advisories/unreviewed/2024/02/GHSA-p5q9-86w4-2xr5/GHSA-p5q9-86w4-2xr5.json +++ /dev/null @@ -1,47 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-p5q9-86w4-2xr5", - "modified": "2024-02-27T15:30:31Z", - "published": "2024-02-27T15:30:31Z", - "aliases": [ - "CVE-2023-51747" - ], - "details": "Apache James prior to versions 3.8.1 and 3.7.5 is vulnerable to SMTP smuggling.\n\nA lenient behaviour in line delimiter handling might create a difference of interpretation between the sender and the receiver which can be exploited by an attacker to forge an SMTP envelop, allowing for instance to bypass SPF checks.\n\nThe patch implies enforcement of CRLF as a line delimiter as part of the DATA transaction.\n\nWe recommend James users to upgrade to non vulnerable versions.\n", - "severity": [ - - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51747" - }, - { - "type": "WEB", - "url": "https://lists.apache.org/thread/rxkwbkh9vgbl9rzx1fkllyk3krhgydko" - }, - { - "type": "WEB", - "url": "https://postfix.org/smtp-smuggling.html" - }, - { - "type": "WEB", - "url": "https://sec-consult.com/blog/detail/smtp-smuggling-spoofing-e-mails-worldwide" - }, - { - "type": "WEB", - "url": "http://www.openwall.com/lists/oss-security/2024/02/27/4" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-20" - ], - "severity": null, - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2024-02-27T14:15:27Z" - } -} \ No newline at end of file