mirror of
https://github.com/netbirdio/advisory-database.git
synced 2026-05-22 18:04:22 -07:00
Publish Advisories
GHSA-xjm6-jfmg-qc6p GHSA-rhc2-23c2-ww7c
This commit is contained in:
@@ -1,10 +1,10 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-xjm6-jfmg-qc6p",
|
||||
"modified": "2024-05-29T14:38:11Z",
|
||||
"modified": "2024-06-11T20:56:12Z",
|
||||
"published": "2024-05-29T14:38:11Z",
|
||||
"aliases": [
|
||||
|
||||
"CVE-2024-37294"
|
||||
],
|
||||
"summary": "Aimeos denial of service vulnerability in SaaS and marketplace setups",
|
||||
"details": "### Impact\nAll SaaS and marketplace setups using Aimeos version from 2022/2023/2024 are affected by a potential denial of service attack\n\n### Patches\nUpgrade to the latest 2022.10 LTS, 2023.10 LTS and 2024.04.7 version of the aimeos/aimeos-core package\n",
|
||||
@@ -78,6 +78,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/aimeos/aimeos-core/security/advisories/GHSA-xjm6-jfmg-qc6p"
|
||||
},
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37294"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/aimeos/aimeos-core/commit/66edb06a53e51d90e075aad1932811c53c40af6f"
|
||||
@@ -114,6 +118,6 @@
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": true,
|
||||
"github_reviewed_at": "2024-05-29T14:38:11Z",
|
||||
"nvd_published_at": null
|
||||
"nvd_published_at": "2024-06-11T15:16:09Z"
|
||||
}
|
||||
}
|
||||
@@ -1,10 +1,10 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-rhc2-23c2-ww7c",
|
||||
"modified": "2024-06-05T13:29:47Z",
|
||||
"modified": "2024-06-11T20:56:22Z",
|
||||
"published": "2024-06-05T13:29:47Z",
|
||||
"aliases": [
|
||||
|
||||
"CVE-2024-37295"
|
||||
],
|
||||
"summary": "Remote code execution in web server context",
|
||||
"details": "### Impact\nUser with administrative privileges and upload files that look like images but contain PHP code which can then be executed in the context of the web server.\n",
|
||||
@@ -40,6 +40,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/aimeos/aimeos-core/security/advisories/GHSA-rhc2-23c2-ww7c"
|
||||
},
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37295"
|
||||
},
|
||||
{
|
||||
"type": "PACKAGE",
|
||||
"url": "https://github.com/aimeos/aimeos-core"
|
||||
@@ -52,6 +56,6 @@
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": true,
|
||||
"github_reviewed_at": "2024-06-05T13:29:47Z",
|
||||
"nvd_published_at": null
|
||||
"nvd_published_at": "2024-06-11T15:16:09Z"
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user