Publish Advisories

GHSA-gjhc-6xm7-mc8q
GHSA-hf3r-vmrv-7w29
GHSA-q5pp-5q2h-g8rv
This commit is contained in:
advisory-database[bot]
2024-01-03 22:29:18 +00:00
parent b2edfe2e8f
commit e523cc5f24
3 changed files with 6 additions and 6 deletions
@@ -1,11 +1,11 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gjhc-6xm7-mc8q",
"modified": "2024-01-03T21:21:37Z",
"modified": "2024-01-03T22:27:29Z",
"published": "2024-01-03T18:30:51Z",
"withdrawn": "2024-01-03T21:21:37Z",
"aliases": [
"CVE-2024-21908"
],
"summary": "Duplicate Advisory: Cross-site scripting vulnerability in TinyMCE",
"details": "### Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-5h9g-x5rv-25wg. This link is maintained to preserve external references.\n\n### Original Description\nTinyMCE versions before 5.9.0 are affected by a stored cross-site scripting vulnerability. An unauthenticated and remote attacker could insert crafted HTML into the editor resulting in arbitrary JavaScript execution in another user's browser.\n\n\n\n",
@@ -1,11 +1,11 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hf3r-vmrv-7w29",
"modified": "2024-01-03T21:06:15Z",
"modified": "2024-01-03T22:28:05Z",
"published": "2024-01-03T18:30:51Z",
"withdrawn": "2024-01-03T21:06:15Z",
"aliases": [
"CVE-2024-21909"
],
"summary": "Duplicate Advisory: Denial of service in CBOR library",
"details": "### Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-6r92-cgxc-r5fg. This link is maintained to preserve external references.\n\n### Original Description\nPeterO.Cbor versions 4.0.0 through 4.5.0 are vulnerable to a denial of \nservice vulnerability. An attacker may trigger the denial of service \ncondition by providing crafted data to the DecodeFromBytes or other \ndecoding mechanisms in PeterO.Cbor. Depending on the usage of the \nlibrary, an unauthenticated and remote attacker may be able to cause the\n denial of service condition.\n",
@@ -1,11 +1,11 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q5pp-5q2h-g8rv",
"modified": "2024-01-03T21:25:16Z",
"modified": "2024-01-03T22:27:37Z",
"published": "2024-01-03T18:30:51Z",
"withdrawn": "2024-01-03T21:25:16Z",
"aliases": [
"CVE-2024-21911"
],
"summary": "Duplicate Advisory: Cross-site scripting vulnerability in TinyMCE",
"details": "### Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-5h9g-x5rv-25wg. This link is maintained to preserve external references.\n\n### Original Description\nTinyMCE versions before 5.6.0 are affected by a stored cross-site scripting vulnerability. An unauthenticated and remote attacker could insert crafted HTML into the editor resulting in arbitrary JavaScript execution in another user's browser.",