diff --git a/advisories/github-reviewed/2022/05/GHSA-9x76-mp7r-2xc5/GHSA-9x76-mp7r-2xc5.json b/advisories/github-reviewed/2022/05/GHSA-9x76-mp7r-2xc5/GHSA-9x76-mp7r-2xc5.json new file mode 100644 index 00000000000..4b60ae7535f --- /dev/null +++ b/advisories/github-reviewed/2022/05/GHSA-9x76-mp7r-2xc5/GHSA-9x76-mp7r-2xc5.json @@ -0,0 +1,123 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9x76-mp7r-2xc5", + "modified": "2025-04-22T18:44:44Z", + "published": "2022-05-17T02:34:08Z", + "aliases": [ + "CVE-2017-7620" + ], + "summary": "MantisBT vulnerable to CSRF and Open Redirect attacks", + "details": "MantisBT before 1.3.11, 2.x before 2.3.3, and 2.4.x before 2.4.1 omits a backslash check in string_api.php and consequently has conflicting interpretations of an initial \\/ substring as introducing either a local pathname or a remote hostname, which leads to (1) arbitrary Permalink Injection via CSRF attacks on a permalink_page.php?url= URI and (2) an open redirect via a login_page.php?return= URI.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "mantisbt/mantisbt" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.3.11" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "mantisbt/mantisbt" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.0.0" + }, + { + "fixed": "2.3.3" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "mantisbt/mantisbt" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.4.0" + }, + { + "fixed": "2.4.1" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2017-7620" + }, + { + "type": "WEB", + "url": "https://github.com/mantisbt/mantisbt/commit/2d2309a384bcd9d4b6d7d2928e8ded2c46d2d7b0" + }, + { + "type": "WEB", + "url": "https://github.com/mantisbt/mantisbt/commit/8b6787c8d321ee0ced5fb74ac3f34b67b4b7b26c" + }, + { + "type": "WEB", + "url": "https://github.com/mantisbt/mantisbt/commit/c4f50e5df6b189abb1d717a5f7dbab5cbfef8165" + }, + { + "type": "PACKAGE", + "url": "https://github.com/mantisbt/mantisbt" + }, + { + "type": "WEB", + "url": "https://mantisbt.org/bugs/view.php?id=22702" + }, + { + "type": "WEB", + "url": "https://mantisbt.org/bugs/view.php?id=22816" + }, + { + "type": "WEB", + "url": "https://www.exploit-db.com/exploits/42043" + }, + { + "type": "WEB", + "url": "http://hyp3rlinx.altervista.org/advisories/MANTIS-BUG-TRACKER-CSRF-PERMALINK-INJECTION.txt" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2025-04-22T18:44:43Z", + "nvd_published_at": "2017-05-21T14:29:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-p2j4-vrgx-96qg/GHSA-p2j4-vrgx-96qg.json b/advisories/github-reviewed/2022/05/GHSA-p2j4-vrgx-96qg/GHSA-p2j4-vrgx-96qg.json similarity index 60% rename from advisories/unreviewed/2022/05/GHSA-p2j4-vrgx-96qg/GHSA-p2j4-vrgx-96qg.json rename to advisories/github-reviewed/2022/05/GHSA-p2j4-vrgx-96qg/GHSA-p2j4-vrgx-96qg.json index 30f0e486aa4..64d314c0a2b 100644 --- a/advisories/unreviewed/2022/05/GHSA-p2j4-vrgx-96qg/GHSA-p2j4-vrgx-96qg.json +++ b/advisories/github-reviewed/2022/05/GHSA-p2j4-vrgx-96qg/GHSA-p2j4-vrgx-96qg.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-p2j4-vrgx-96qg", - "modified": "2025-04-20T03:37:51Z", + "modified": "2025-04-22T18:43:57Z", "published": "2022-05-17T02:43:14Z", "aliases": [ "CVE-2017-9071" ], + "summary": "MODX Revolution XSS via HTTP Host header", "details": "In MODX Revolution before 2.5.7, an attacker might be able to trigger XSS by injecting a payload into the HTTP Host header of a request. This is exploitable only in conjunction with other issues such as Cache Poisoning.", "severity": [ { @@ -13,7 +14,27 @@ "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N" } ], - "affected": [], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "modx/revolution" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.5.7" + } + ] + } + ] + } + ], "references": [ { "type": "ADVISORY", @@ -26,6 +47,10 @@ { "type": "WEB", "url": "https://citadelo.com/en/2017/04/modx-revolution-cms" + }, + { + "type": "PACKAGE", + "url": "https://github.com/modxcms/revolution" } ], "database_specific": { @@ -33,8 +58,8 @@ "CWE-79" ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2025-04-22T18:43:57Z", "nvd_published_at": "2017-05-18T16:29:00Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-qxh9-r8xw-7v99/GHSA-qxh9-r8xw-7v99.json b/advisories/github-reviewed/2022/05/GHSA-qxh9-r8xw-7v99/GHSA-qxh9-r8xw-7v99.json similarity index 72% rename from advisories/unreviewed/2022/05/GHSA-qxh9-r8xw-7v99/GHSA-qxh9-r8xw-7v99.json rename to advisories/github-reviewed/2022/05/GHSA-qxh9-r8xw-7v99/GHSA-qxh9-r8xw-7v99.json index d95f2f80cc2..9d26b42ae39 100644 --- a/advisories/unreviewed/2022/05/GHSA-qxh9-r8xw-7v99/GHSA-qxh9-r8xw-7v99.json +++ b/advisories/github-reviewed/2022/05/GHSA-qxh9-r8xw-7v99/GHSA-qxh9-r8xw-7v99.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-qxh9-r8xw-7v99", - "modified": "2025-04-20T03:37:53Z", + "modified": "2025-04-22T18:45:30Z", "published": "2022-05-13T01:17:50Z", "aliases": [ "CVE-2017-9111" ], + "summary": "OpenEXR invalid write", "details": "In OpenEXR 2.2.0, an invalid write of size 8 in the storeSSE function in ImfOptimizedPixelReading.h could cause the application to crash or execute arbitrary code.", "severity": [ { @@ -13,7 +14,27 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], - "affected": [], + "affected": [ + { + "package": { + "ecosystem": "PyPI", + "name": "OpenEXR" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.2.1" + } + ] + } + ] + } + ], "references": [ { "type": "ADVISORY", @@ -27,6 +48,10 @@ "type": "WEB", "url": "https://github.com/openexr/openexr/pull/233" }, + { + "type": "PACKAGE", + "url": "https://github.com/AcademySoftwareFoundation/openexr" + }, { "type": "WEB", "url": "https://github.com/openexr/openexr/releases/tag/v2.2.1" @@ -61,10 +86,12 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "HIGH", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2025-04-22T18:45:29Z", "nvd_published_at": "2017-05-21T18:29:00Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-9x76-mp7r-2xc5/GHSA-9x76-mp7r-2xc5.json b/advisories/unreviewed/2022/05/GHSA-9x76-mp7r-2xc5/GHSA-9x76-mp7r-2xc5.json deleted file mode 100644 index 60624b14273..00000000000 --- a/advisories/unreviewed/2022/05/GHSA-9x76-mp7r-2xc5/GHSA-9x76-mp7r-2xc5.json +++ /dev/null @@ -1,52 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-9x76-mp7r-2xc5", - "modified": "2025-04-20T03:37:52Z", - "published": "2022-05-17T02:34:08Z", - "aliases": [ - "CVE-2017-7620" - ], - "details": "MantisBT before 1.3.11, 2.x before 2.3.3, and 2.4.x before 2.4.1 omits a backslash check in string_api.php and consequently has conflicting interpretations of an initial \\/ substring as introducing either a local pathname or a remote hostname, which leads to (1) arbitrary Permalink Injection via CSRF attacks on a permalink_page.php?url= URI and (2) an open redirect via a login_page.php?return= URI.", - "severity": [ - { - "type": "CVSS_V3", - "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" - } - ], - "affected": [], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2017-7620" - }, - { - "type": "WEB", - "url": "https://mantisbt.org/bugs/view.php?id=22702" - }, - { - "type": "WEB", - "url": "https://mantisbt.org/bugs/view.php?id=22816" - }, - { - "type": "WEB", - "url": "https://www.exploit-db.com/exploits/42043" - }, - { - "type": "WEB", - "url": "http://hyp3rlinx.altervista.org/advisories/MANTIS-BUG-TRACKER-CSRF-PERMALINK-INJECTION.txt" - }, - { - "type": "WEB", - "url": "http://www.securitytracker.com/id/1038538" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-352" - ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2017-05-21T14:29:00Z" - } -} \ No newline at end of file