diff --git a/advisories/github-reviewed/2022/05/GHSA-77p4-wfr8-977w/GHSA-77p4-wfr8-977w.json b/advisories/github-reviewed/2022/05/GHSA-77p4-wfr8-977w/GHSA-77p4-wfr8-977w.json new file mode 100644 index 00000000000..4a1972bc794 --- /dev/null +++ b/advisories/github-reviewed/2022/05/GHSA-77p4-wfr8-977w/GHSA-77p4-wfr8-977w.json @@ -0,0 +1,164 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-77p4-wfr8-977w", + "modified": "2024-04-25T21:35:12Z", + "published": "2022-05-24T17:03:52Z", + "aliases": [ + "CVE-2019-19848" + ], + "summary": "TYPO3 Directory Traversal on ZIP extraction", + "details": "An issue was discovered in TYPO3 before 8.7.30, 9.x before 9.5.12, and 10.x before 10.2.2. It has been discovered that the extraction of manually uploaded ZIP archives in Extension Manager is vulnerable to directory traversal. Admin privileges are required in order to exploit this vulnerability. (In v9 LTS and later, System Maintainer privileges are also required.)", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "typo3/cms-core" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "10.0.0" + }, + { + "fixed": "10.2.2" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "typo3/cms-core" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "8.0.0" + }, + { + "fixed": "8.7.30" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "typo3/cms-core" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "9.0.0" + }, + { + "fixed": "9.5.12" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "typo3/cms" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "10.0.0" + }, + { + "fixed": "10.2.2" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "typo3/cms" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "8.0.0" + }, + { + "fixed": "8.7.30" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "typo3/cms" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "9.0.0" + }, + { + "fixed": "9.5.12" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-19848" + }, + { + "type": "WEB", + "url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms-core/CVE-2019-19848.yaml" + }, + { + "type": "WEB", + "url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms/CVE-2019-19848.yaml" + }, + { + "type": "WEB", + "url": "https://review.typo3.org/q/%2522Resolves:+%252388764%2522+topic:security" + }, + { + "type": "WEB", + "url": "https://typo3.org/security/advisory/typo3-core-sa-2019-024" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-04-25T21:35:12Z", + "nvd_published_at": "2019-12-17T17:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-989h-wv8x-933p/GHSA-989h-wv8x-933p.json b/advisories/github-reviewed/2022/05/GHSA-989h-wv8x-933p/GHSA-989h-wv8x-933p.json similarity index 51% rename from advisories/unreviewed/2022/05/GHSA-989h-wv8x-933p/GHSA-989h-wv8x-933p.json rename to advisories/github-reviewed/2022/05/GHSA-989h-wv8x-933p/GHSA-989h-wv8x-933p.json index 6c9cab4f2ca..3ad4dccb228 100644 --- a/advisories/unreviewed/2022/05/GHSA-989h-wv8x-933p/GHSA-989h-wv8x-933p.json +++ b/advisories/github-reviewed/2022/05/GHSA-989h-wv8x-933p/GHSA-989h-wv8x-933p.json @@ -1,23 +1,84 @@ { "schema_version": "1.4.0", "id": "GHSA-989h-wv8x-933p", - "modified": "2022-05-14T02:48:01Z", + "modified": "2024-04-25T21:35:17Z", "published": "2022-05-14T02:48:01Z", "aliases": [ "CVE-2015-5956" ], + "summary": "TYPO3 cross-site scripting (XSS)", "details": "The sanitizeLocalUrl function in TYPO3 6.x before 6.2.15, 7.x before 7.4.0, 4.5.40, and earlier allows remote authenticated users to bypass the XSS filter and conduct cross-site scripting (XSS) attacks via a base64 encoded data URI, as demonstrated by the (1) returnUrl parameter to show_rechis.php and the (2) redirect_url parameter to index.php.", "severity": [ ], "affected": [ - + { + "package": { + "ecosystem": "Packagist", + "name": "typo3/cms" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "6.0" + }, + { + "fixed": "6.2.15" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "typo3/cms" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "7.0" + }, + { + "fixed": "7.4.0" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "typo3/cms" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "4.0" + }, + { + "last_affected": "4.5.40" + } + ] + } + ] + } ], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2015-5956" }, + { + "type": "WEB", + "url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms/CVE-2015-5956.yaml" + }, { "type": "WEB", "url": "https://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2015-009" @@ -44,8 +105,8 @@ "CWE-79" ], "severity": "LOW", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-04-25T21:35:16Z", "nvd_published_at": "2015-09-16T14:59:00Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2022/05/GHSA-q8cr-xphm-7gfv/GHSA-q8cr-xphm-7gfv.json b/advisories/github-reviewed/2022/05/GHSA-q8cr-xphm-7gfv/GHSA-q8cr-xphm-7gfv.json new file mode 100644 index 00000000000..f40fe471d0f --- /dev/null +++ b/advisories/github-reviewed/2022/05/GHSA-q8cr-xphm-7gfv/GHSA-q8cr-xphm-7gfv.json @@ -0,0 +1,107 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q8cr-xphm-7gfv", + "modified": "2024-04-25T21:34:47Z", + "published": "2022-05-13T01:24:28Z", + "aliases": [ + "CVE-2017-1000009" + ], + "summary": "Akeneo PIM vulnerable to shell injection in the mass edition", + "details": "Akeneo PIM CE and EE <1.6.6, <1.5.15, <1.4.28 are vulnerable to shell injection in the mass edition, resulting in remote execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "akeneo/pim-community-dev" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "1.4" + }, + { + "fixed": "1.4.28" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "akeneo/pim-community-dev" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "1.5" + }, + { + "fixed": "1.5.15" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "akeneo/pim-community-dev" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "1.6" + }, + { + "fixed": "1.6.6" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2017-1000009" + }, + { + "type": "PACKAGE", + "url": "https://github.com/akeneo/pim-community-dev" + }, + { + "type": "WEB", + "url": "https://github.com/akeneo/pim-community-dev/blob/1.5/CHANGELOG-1.5.md#bug-fixes-2" + }, + { + "type": "WEB", + "url": "https://github.com/akeneo/pim-community-dev/blob/master/CHANGELOG-1.4.md#bug-fixes" + }, + { + "type": "WEB", + "url": "https://github.com/akeneo/pim-community-dev/blob/master/CHANGELOG-1.6.md#bug-fixes-2" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", + "github_reviewed": true, + "github_reviewed_at": "2024-04-25T21:34:47Z", + "nvd_published_at": "2017-07-17T13:18:00Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2022/05/GHSA-rcgc-4xfc-564v/GHSA-rcgc-4xfc-564v.json b/advisories/github-reviewed/2022/05/GHSA-rcgc-4xfc-564v/GHSA-rcgc-4xfc-564v.json new file mode 100644 index 00000000000..89266ce524e --- /dev/null +++ b/advisories/github-reviewed/2022/05/GHSA-rcgc-4xfc-564v/GHSA-rcgc-4xfc-564v.json @@ -0,0 +1,164 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rcgc-4xfc-564v", + "modified": "2024-04-25T21:35:08Z", + "published": "2022-05-24T17:03:52Z", + "aliases": [ + "CVE-2019-19849" + ], + "summary": "TYPO3 Insecure Deserialization in Query Generator & Query View", + "details": "An issue was discovered in TYPO3 before 8.7.30, 9.x before 9.5.12, and 10.x before 10.2.2. It has been discovered that the classes QueryGenerator and QueryView are vulnerable to insecure deserialization. One exploitable scenario requires having the system extension ext:lowlevel (Backend Module: DB Check) installed, with a valid backend user who has administrator privileges. The other exploitable scenario requires having the system extension ext:sys_action installed, with a valid backend user who has limited privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "typo3/cms-core" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "10.0.0" + }, + { + "fixed": "10.2.1" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "typo3/cms-core" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "8.0.0" + }, + { + "fixed": "8.7.30" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "typo3/cms-core" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "9.0.0" + }, + { + "fixed": "9.5.12" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "typo3/cms" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "10.0.0" + }, + { + "fixed": "10.2.1" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "typo3/cms" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "8.0.0" + }, + { + "fixed": "8.7.30" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "typo3/cms" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "9.0.0" + }, + { + "fixed": "9.5.12" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-19849" + }, + { + "type": "WEB", + "url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms-core/CVE-2019-19849.yaml" + }, + { + "type": "WEB", + "url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms/CVE-2019-19849.yaml" + }, + { + "type": "WEB", + "url": "https://review.typo3.org/q/%2522Resolves:+%252389005%2522+topic:security" + }, + { + "type": "WEB", + "url": "https://typo3.org/security/advisory/typo3-core-sa-2019-026" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": true, + "github_reviewed_at": "2024-04-25T21:35:08Z", + "nvd_published_at": "2019-12-17T17:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-77p4-wfr8-977w/GHSA-77p4-wfr8-977w.json b/advisories/unreviewed/2022/05/GHSA-77p4-wfr8-977w/GHSA-77p4-wfr8-977w.json deleted file mode 100644 index c9694a29ab2..00000000000 --- a/advisories/unreviewed/2022/05/GHSA-77p4-wfr8-977w/GHSA-77p4-wfr8-977w.json +++ /dev/null @@ -1,39 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-77p4-wfr8-977w", - "modified": "2022-05-24T17:03:52Z", - "published": "2022-05-24T17:03:52Z", - "aliases": [ - "CVE-2019-19848" - ], - "details": "An issue was discovered in TYPO3 before 8.7.30, 9.x before 9.5.12, and 10.x before 10.2.2. It has been discovered that the extraction of manually uploaded ZIP archives in Extension Manager is vulnerable to directory traversal. Admin privileges are required in order to exploit this vulnerability. (In v9 LTS and later, System Maintainer privileges are also required.)", - "severity": [ - - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-19848" - }, - { - "type": "WEB", - "url": "https://review.typo3.org/q/%2522Resolves:+%252388764%2522+topic:security" - }, - { - "type": "WEB", - "url": "https://typo3.org/security/advisory/typo3-core-sa-2019-024" - } - ], - "database_specific": { - "cwe_ids": [ - - ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2019-12-17T17:15:00Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-q8cr-xphm-7gfv/GHSA-q8cr-xphm-7gfv.json b/advisories/unreviewed/2022/05/GHSA-q8cr-xphm-7gfv/GHSA-q8cr-xphm-7gfv.json deleted file mode 100644 index 95010be3b24..00000000000 --- a/advisories/unreviewed/2022/05/GHSA-q8cr-xphm-7gfv/GHSA-q8cr-xphm-7gfv.json +++ /dev/null @@ -1,46 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-q8cr-xphm-7gfv", - "modified": "2022-05-13T01:24:28Z", - "published": "2022-05-13T01:24:28Z", - "aliases": [ - "CVE-2017-1000009" - ], - "details": "Akeneo PIM CE and EE <1.6.6, <1.5.15, <1.4.28 are vulnerable to shell injection in the mass edition, resulting in remote execution.", - "severity": [ - { - "type": "CVSS_V3", - "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" - } - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2017-1000009" - }, - { - "type": "WEB", - "url": "https://github.com/akeneo/pim-community-dev/blob/1.5/CHANGELOG-1.5.md#bug-fixes-2" - }, - { - "type": "WEB", - "url": "https://github.com/akeneo/pim-community-dev/blob/master/CHANGELOG-1.4.md#bug-fixes" - }, - { - "type": "WEB", - "url": "https://github.com/akeneo/pim-community-dev/blob/master/CHANGELOG-1.6.md#bug-fixes-2" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-78" - ], - "severity": "CRITICAL", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2017-07-17T13:18:00Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-rcgc-4xfc-564v/GHSA-rcgc-4xfc-564v.json b/advisories/unreviewed/2022/05/GHSA-rcgc-4xfc-564v/GHSA-rcgc-4xfc-564v.json deleted file mode 100644 index df7e93bece9..00000000000 --- a/advisories/unreviewed/2022/05/GHSA-rcgc-4xfc-564v/GHSA-rcgc-4xfc-564v.json +++ /dev/null @@ -1,39 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-rcgc-4xfc-564v", - "modified": "2022-05-24T17:03:52Z", - "published": "2022-05-24T17:03:52Z", - "aliases": [ - "CVE-2019-19849" - ], - "details": "An issue was discovered in TYPO3 before 8.7.30, 9.x before 9.5.12, and 10.x before 10.2.2. It has been discovered that the classes QueryGenerator and QueryView are vulnerable to insecure deserialization. One exploitable scenario requires having the system extension ext:lowlevel (Backend Module: DB Check) installed, with a valid backend user who has administrator privileges. The other exploitable scenario requires having the system extension ext:sys_action installed, with a valid backend user who has limited privileges.", - "severity": [ - - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-19849" - }, - { - "type": "WEB", - "url": "https://review.typo3.org/q/%2522Resolves:+%252389005%2522+topic:security" - }, - { - "type": "WEB", - "url": "https://typo3.org/security/advisory/typo3-core-sa-2019-026" - } - ], - "database_specific": { - "cwe_ids": [ - - ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2019-12-17T17:15:00Z" - } -} \ No newline at end of file