Publish Advisories

GHSA-77gj-crhp-3gvx
GHSA-78x2-cwp9-5j42
This commit is contained in:
advisory-database[bot]
2024-09-17 16:25:58 +00:00
parent 90540116b3
commit cdfa7e5f9a
2 changed files with 4 additions and 4 deletions
@@ -1,13 +1,13 @@
{
"schema_version": "1.4.0",
"id": "GHSA-77gj-crhp-3gvx",
"modified": "2024-08-20T18:25:15Z",
"modified": "2024-09-17T16:24:34Z",
"published": "2024-08-20T18:25:15Z",
"aliases": [
"CVE-2024-43376"
],
"summary": "Umbraco CMS vulnerable to Generation of Error Message Containing Sensitive Information",
"details": "### Impact\nSome endpoints in the Management API can return stack trace information, even when Umbraco is not in debug mode.",
"details": "### Impact\nSome endpoints in the Management API can return stack trace information, even when Umbraco is not in debug mode.\n\n### Explanation of the vulnerability\nManagement API endpoints leaked stack traces in case of Internal server errors, no matter if the debug setting was disabled.\n\nE.g. when paging with negative numbers in some apis\n\n\n",
"severity": [
{
"type": "CVSS_V3",
@@ -1,13 +1,13 @@
{
"schema_version": "1.4.0",
"id": "GHSA-78x2-cwp9-5j42",
"modified": "2024-08-26T21:25:01Z",
"modified": "2024-09-17T16:25:26Z",
"published": "2024-08-20T20:04:49Z",
"aliases": [
"CVE-2024-43409"
],
"summary": "Ghost's improper authentication allows access to member information and actions",
"details": "### Impact\n\nImproper authentication on some endpoints used for member actions would allow an attacker to perform member-only actions, and read member information.\n\n### Vulnerable versions\n\nThis security vulnerability is present in Ghost v4.46.0-v5.89.5.\n\n### Patches\n\nv5.89.5 contains a fix for this issue.\n\n### Workarounds\n\nNone.\n\n### For more information\n\nIf you have any questions or comments about this advisory:\n\n* Email us at [security@ghost.org](mailto:security@ghost.org)\n",
"details": "### Impact\n\nImproper authentication on some endpoints used for member actions would allow an attacker to perform member-only actions, and read member information.\n\n### Vulnerable versions\n\nThis security vulnerability is present in Ghost v4.46.0-v5.89.5.\n\nGhost(Pro) customers are automatically updated to fixed versions ahead of disclosure.\n\nIf you're a self-hoster, please follow our [update instructions](https://ghost.org/docs/update).\n\n### Patches\n\nv5.89.5 contains a fix for this issue.\n\n### Workarounds\n\nNone.\n\n### For more information\n\nIf you have any questions or comments about this advisory:\n\n* Email us at [security@ghost.org](mailto:security@ghost.org)\n",
"severity": [
{
"type": "CVSS_V3",