From c3a178248bbce84740a3516adc4c265ac15abe39 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 8 Jul 2024 18:35:36 +0000 Subject: [PATCH] Publish GHSA-r4ph-mx67-x58p --- .../GHSA-r4ph-mx67-x58p.json | 27 +++---------------- 1 file changed, 4 insertions(+), 23 deletions(-) diff --git a/advisories/github-reviewed/2022/05/GHSA-r4ph-mx67-x58p/GHSA-r4ph-mx67-x58p.json b/advisories/github-reviewed/2022/05/GHSA-r4ph-mx67-x58p/GHSA-r4ph-mx67-x58p.json index 1029ae9be12..46f579d41ca 100644 --- a/advisories/github-reviewed/2022/05/GHSA-r4ph-mx67-x58p/GHSA-r4ph-mx67-x58p.json +++ b/advisories/github-reviewed/2022/05/GHSA-r4ph-mx67-x58p/GHSA-r4ph-mx67-x58p.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-r4ph-mx67-x58p", - "modified": "2024-04-24T22:41:45Z", + "modified": "2024-07-08T18:34:12Z", "published": "2022-05-24T17:24:28Z", "aliases": [ "CVE-2020-13997" ], "summary": "Shopware database password is leaked to an unauthenticated users", - "details": "In Shopware before 6.2.3, the database password is leaked to an unauthenticated user when a DriverException occurs and verbose error handling is enabled.", + "details": "In Shopware 6 before 6.2.3, the database password is leaked to an unauthenticated user when a DriverException occurs and verbose error handling is enabled. This vulnerability does not affect the shopware 5 release branch (`shopware/shopware` on packagist).", "severity": [ { "type": "CVSS_V3", @@ -25,26 +25,7 @@ "type": "ECOSYSTEM", "events": [ { - "introduced": "0" - }, - { - "fixed": "6.2.3" - } - ] - } - ] - }, - { - "package": { - "ecosystem": "Packagist", - "name": "shopware/shopware" - }, - "ranges": [ - { - "type": "ECOSYSTEM", - "events": [ - { - "introduced": "0" + "introduced": "6.0.0" }, { "fixed": "6.2.3" @@ -63,7 +44,7 @@ "type": "ECOSYSTEM", "events": [ { - "introduced": "0" + "introduced": "6.0.0" }, { "fixed": "6.2.3"