From cd75fb60852a4adb2a7801147ac2a6d50bb5f092 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 3 Jan 2024 21:42:31 +0000 Subject: [PATCH] Publish Advisories GHSA-3vvh-8c65-32j4 GHSA-p4v8-jgcv-9g75 GHSA-xgpm-q3mq-46rq GHSA-3vvh-8c65-32j4 --- .../GHSA-3vvh-8c65-32j4.json | 61 ++++++++++++ .../GHSA-p4v8-jgcv-9g75.json | 62 ++++++++++++ .../GHSA-xgpm-q3mq-46rq.json | 96 +++++++++++++++++++ .../GHSA-3vvh-8c65-32j4.json | 35 ------- 4 files changed, 219 insertions(+), 35 deletions(-) create mode 100644 advisories/github-reviewed/2023/12/GHSA-3vvh-8c65-32j4/GHSA-3vvh-8c65-32j4.json create mode 100644 advisories/github-reviewed/2024/01/GHSA-p4v8-jgcv-9g75/GHSA-p4v8-jgcv-9g75.json create mode 100644 advisories/github-reviewed/2024/01/GHSA-xgpm-q3mq-46rq/GHSA-xgpm-q3mq-46rq.json delete mode 100644 advisories/unreviewed/2023/12/GHSA-3vvh-8c65-32j4/GHSA-3vvh-8c65-32j4.json diff --git a/advisories/github-reviewed/2023/12/GHSA-3vvh-8c65-32j4/GHSA-3vvh-8c65-32j4.json b/advisories/github-reviewed/2023/12/GHSA-3vvh-8c65-32j4/GHSA-3vvh-8c65-32j4.json new file mode 100644 index 00000000000..9ac9b29c162 --- /dev/null +++ b/advisories/github-reviewed/2023/12/GHSA-3vvh-8c65-32j4/GHSA-3vvh-8c65-32j4.json @@ -0,0 +1,61 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3vvh-8c65-32j4", + "modified": "2024-01-03T21:40:24Z", + "published": "2023-12-30T18:30:35Z", + "aliases": [ + "CVE-2023-50578" + ], + "summary": "Mingsoft MCMS SQL injection", + "details": "Mingsoft MCMS v5.2.9 was discovered to contain a SQL injection vulnerability via the categoryType parameter at /content/list.do.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Maven", + "name": "net.mingsoft:ms-mcms" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "5.2.9" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50578" + }, + { + "type": "WEB", + "url": "https://gitee.com/mingSoft/MCMS/issues/I8MAJK" + }, + { + "type": "PACKAGE", + "url": "https://github.com/ming-soft/MCMS" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": true, + "github_reviewed_at": "2024-01-03T21:40:24Z", + "nvd_published_at": "2023-12-30T16:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/01/GHSA-p4v8-jgcv-9g75/GHSA-p4v8-jgcv-9g75.json b/advisories/github-reviewed/2024/01/GHSA-p4v8-jgcv-9g75/GHSA-p4v8-jgcv-9g75.json new file mode 100644 index 00000000000..11387ca238d --- /dev/null +++ b/advisories/github-reviewed/2024/01/GHSA-p4v8-jgcv-9g75/GHSA-p4v8-jgcv-9g75.json @@ -0,0 +1,62 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p4v8-jgcv-9g75", + "modified": "2024-01-03T21:40:45Z", + "published": "2024-01-03T21:40:45Z", + "aliases": [ + + ], + "summary": "safe_pqc_kyber leaks parts of secret keys", + "details": "### Impact\nOn some platforms, when an attacker can time decapsulation, and in particular when the attacker can forge cipher texts, they can learn (parts of) the secret key.\n\nDoes not apply to ephemeral usage, such as when used in the regular way in TLS.\n\n### Patches\nPatched in 0.6.2.\n\n\n### References\n- [kyberslash.cr.yp.to](https://kyberslash.cr.yp.to)", + "severity": [ + + ], + "affected": [ + { + "package": { + "ecosystem": "crates.io", + "name": "safe_pqc_kyber" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.6.2" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/bwesterb/argyle-kyber/security/advisories/GHSA-p4v8-jgcv-9g75" + }, + { + "type": "WEB", + "url": "https://github.com/bwesterb/argyle-kyber/commit/b5c6ad13f4eece80e59c6ebeafd787ba1519f5f6" + }, + { + "type": "PACKAGE", + "url": "https://github.com/bwesterb/argyle-kyber" + }, + { + "type": "WEB", + "url": "https://kyberslash.cr.yp.to/" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": true, + "github_reviewed_at": "2024-01-03T21:40:45Z", + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/01/GHSA-xgpm-q3mq-46rq/GHSA-xgpm-q3mq-46rq.json b/advisories/github-reviewed/2024/01/GHSA-xgpm-q3mq-46rq/GHSA-xgpm-q3mq-46rq.json new file mode 100644 index 00000000000..7b6c938cfbf --- /dev/null +++ b/advisories/github-reviewed/2024/01/GHSA-xgpm-q3mq-46rq/GHSA-xgpm-q3mq-46rq.json @@ -0,0 +1,96 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xgpm-q3mq-46rq", + "modified": "2024-01-03T21:41:14Z", + "published": "2024-01-03T21:41:14Z", + "aliases": [ + "CVE-2024-21627" + ], + "summary": "PrestaShop some attribute not escaped in Validate::isCleanHTML method", + "details": "### Description\nSome event attributes are not detected by the isCleanHTML method\n\n### Impact\nSome modules using the isCleanHTML method could be vulnerable to xss\n\n### Patches\n8.1.3, 1.7.8.11\n\n### Workarounds\nThe best workaround is to use the `HTMLPurifier` library to sanitize html input coming from users. The library is already available as a dependency in the PrestaShop project. Beware though that in legacy object models, fields of `HTML` type will call `isCleanHTML`.\n\n### Reporters\n\nReported by Antonio Russo (@Antonio-R1 on GitHub) and Antonio Rocco Spataro (@antoniospataro on GitHub).\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "prestashop/prestashop" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "8.0.0-beta.1" + }, + { + "fixed": "8.1.3" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "prestashop/prestashop" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.7.8.11" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/PrestaShop/PrestaShop/security/advisories/GHSA-xgpm-q3mq-46rq" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21627" + }, + { + "type": "WEB", + "url": "https://github.com/PrestaShop/PrestaShop/commit/0ed1af8de500538490f88e9e794e2e8113fb8df7" + }, + { + "type": "WEB", + "url": "https://github.com/PrestaShop/PrestaShop/commit/73cfb44666818eefd501b526a894fe884dd12129" + }, + { + "type": "WEB", + "url": "https://github.com/PrestaShop/PrestaShop/commit/ba06d18466df5b92cb841d504cc7210121104883" + }, + { + "type": "WEB", + "url": "https://github.com/PrestaShop/PrestaShop/commit/f799dcff564cd1b7ead932ffc3343b675107dbce" + }, + { + "type": "PACKAGE", + "url": "https://github.com/PrestaShop/PrestaShop" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": true, + "github_reviewed_at": "2024-01-03T21:41:14Z", + "nvd_published_at": "2024-01-02T21:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-3vvh-8c65-32j4/GHSA-3vvh-8c65-32j4.json b/advisories/unreviewed/2023/12/GHSA-3vvh-8c65-32j4/GHSA-3vvh-8c65-32j4.json deleted file mode 100644 index 29a69d5d3dc..00000000000 --- a/advisories/unreviewed/2023/12/GHSA-3vvh-8c65-32j4/GHSA-3vvh-8c65-32j4.json +++ /dev/null @@ -1,35 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-3vvh-8c65-32j4", - "modified": "2023-12-30T18:30:35Z", - "published": "2023-12-30T18:30:35Z", - "aliases": [ - "CVE-2023-50578" - ], - "details": "Mingsoft MCMS v5.2.9 was discovered to contain a SQL injection vulnerability via the categoryType parameter at /content/list.do.", - "severity": [ - - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50578" - }, - { - "type": "WEB", - "url": "https://gitee.com/mingSoft/MCMS/issues/I8MAJK" - } - ], - "database_specific": { - "cwe_ids": [ - - ], - "severity": null, - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2023-12-30T16:15:44Z" - } -} \ No newline at end of file