From cdfa7e5f9a3cff915fc830f061da98868d9bb65f Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 17 Sep 2024 16:25:58 +0000 Subject: [PATCH] Publish Advisories GHSA-77gj-crhp-3gvx GHSA-78x2-cwp9-5j42 --- .../2024/08/GHSA-77gj-crhp-3gvx/GHSA-77gj-crhp-3gvx.json | 4 ++-- .../2024/08/GHSA-78x2-cwp9-5j42/GHSA-78x2-cwp9-5j42.json | 4 ++-- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/advisories/github-reviewed/2024/08/GHSA-77gj-crhp-3gvx/GHSA-77gj-crhp-3gvx.json b/advisories/github-reviewed/2024/08/GHSA-77gj-crhp-3gvx/GHSA-77gj-crhp-3gvx.json index b4a5e87a0fc..782f082b608 100644 --- a/advisories/github-reviewed/2024/08/GHSA-77gj-crhp-3gvx/GHSA-77gj-crhp-3gvx.json +++ b/advisories/github-reviewed/2024/08/GHSA-77gj-crhp-3gvx/GHSA-77gj-crhp-3gvx.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-77gj-crhp-3gvx", - "modified": "2024-08-20T18:25:15Z", + "modified": "2024-09-17T16:24:34Z", "published": "2024-08-20T18:25:15Z", "aliases": [ "CVE-2024-43376" ], "summary": "Umbraco CMS vulnerable to Generation of Error Message Containing Sensitive Information", - "details": "### Impact\nSome endpoints in the Management API can return stack trace information, even when Umbraco is not in debug mode.", + "details": "### Impact\nSome endpoints in the Management API can return stack trace information, even when Umbraco is not in debug mode.\n\n### Explanation of the vulnerability\nManagement API endpoints leaked stack traces in case of Internal server errors, no matter if the debug setting was disabled.\n\nE.g. when paging with negative numbers in some apis\n\n\n", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2024/08/GHSA-78x2-cwp9-5j42/GHSA-78x2-cwp9-5j42.json b/advisories/github-reviewed/2024/08/GHSA-78x2-cwp9-5j42/GHSA-78x2-cwp9-5j42.json index 0a2125c7e8a..e13fed038e9 100644 --- a/advisories/github-reviewed/2024/08/GHSA-78x2-cwp9-5j42/GHSA-78x2-cwp9-5j42.json +++ b/advisories/github-reviewed/2024/08/GHSA-78x2-cwp9-5j42/GHSA-78x2-cwp9-5j42.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-78x2-cwp9-5j42", - "modified": "2024-08-26T21:25:01Z", + "modified": "2024-09-17T16:25:26Z", "published": "2024-08-20T20:04:49Z", "aliases": [ "CVE-2024-43409" ], "summary": "Ghost's improper authentication allows access to member information and actions", - "details": "### Impact\n\nImproper authentication on some endpoints used for member actions would allow an attacker to perform member-only actions, and read member information.\n\n### Vulnerable versions\n\nThis security vulnerability is present in Ghost v4.46.0-v5.89.5.\n\n### Patches\n\nv5.89.5 contains a fix for this issue.\n\n### Workarounds\n\nNone.\n\n### For more information\n\nIf you have any questions or comments about this advisory:\n\n* Email us at [security@ghost.org](mailto:security@ghost.org)\n", + "details": "### Impact\n\nImproper authentication on some endpoints used for member actions would allow an attacker to perform member-only actions, and read member information.\n\n### Vulnerable versions\n\nThis security vulnerability is present in Ghost v4.46.0-v5.89.5.\n\nGhost(Pro) customers are automatically updated to fixed versions ahead of disclosure.\n\nIf you're a self-hoster, please follow our [update instructions](https://ghost.org/docs/update).\n\n### Patches\n\nv5.89.5 contains a fix for this issue.\n\n### Workarounds\n\nNone.\n\n### For more information\n\nIf you have any questions or comments about this advisory:\n\n* Email us at [security@ghost.org](mailto:security@ghost.org)\n", "severity": [ { "type": "CVSS_V3",