diff --git a/advisories/github-reviewed/2024/06/GHSA-cchp-3rq6-69wj/GHSA-cchp-3rq6-69wj.json b/advisories/github-reviewed/2024/06/GHSA-cchp-3rq6-69wj/GHSA-cchp-3rq6-69wj.json new file mode 100644 index 00000000000..6e6d510f073 --- /dev/null +++ b/advisories/github-reviewed/2024/06/GHSA-cchp-3rq6-69wj/GHSA-cchp-3rq6-69wj.json @@ -0,0 +1,84 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cchp-3rq6-69wj", + "modified": "2024-06-21T15:07:37Z", + "published": "2024-06-21T09:30:26Z", + "aliases": [ + "CVE-2024-38874" + ], + "summary": "events2 TYPO3 extension insecure direct object reference (IDOR) vulnerability", + "details": "An issue was discovered in the events2 (aka Events 2) extension before 8.3.8 and 9.x before 9.0.6 for TYPO3. Missing access checks in the management plugin lead to an insecure direct object reference (IDOR) vulnerability with the potential to activate or delete various events for unauthenticated users.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "jweiland/events2" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "8.3.8" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "jweiland/events2" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "9.0.0" + }, + { + "fixed": "9.0.6" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38874" + }, + { + "type": "PACKAGE", + "url": "https://github.com/jweiland-net/events2" + }, + { + "type": "WEB", + "url": "https://typo3.org/security/advisory/typo3-ext-sa-2024-003" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-06-21T15:07:37Z", + "nvd_published_at": "2024-06-21T07:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-jg62-h7pv-hxgv/GHSA-jg62-h7pv-hxgv.json b/advisories/github-reviewed/2024/06/GHSA-jg62-h7pv-hxgv/GHSA-jg62-h7pv-hxgv.json similarity index 56% rename from advisories/unreviewed/2024/06/GHSA-jg62-h7pv-hxgv/GHSA-jg62-h7pv-hxgv.json rename to advisories/github-reviewed/2024/06/GHSA-jg62-h7pv-hxgv/GHSA-jg62-h7pv-hxgv.json index 126e739db9b..f3103029108 100644 --- a/advisories/unreviewed/2024/06/GHSA-jg62-h7pv-hxgv/GHSA-jg62-h7pv-hxgv.json +++ b/advisories/github-reviewed/2024/06/GHSA-jg62-h7pv-hxgv/GHSA-jg62-h7pv-hxgv.json @@ -1,26 +1,53 @@ { "schema_version": "1.4.0", "id": "GHSA-jg62-h7pv-hxgv", - "modified": "2024-06-21T09:30:26Z", + "modified": "2024-06-21T15:08:59Z", "published": "2024-06-21T09:30:26Z", "aliases": [ "CVE-2024-38873" ], + "summary": "FriendlyCaptcha Plugin for TYPO3 Captcha Check Bypass", "details": "An issue was discovered in the friendlycaptcha_official (aka Integration of Friendly Captcha) extension before 0.1.4 for TYPO3. The extension fails to check the requirement of the captcha field in submitted form data, allowing a remote user to bypass the captcha check. This only affects the captcha integration for the ext:form extension.", "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N" } ], "affected": [ - + { + "package": { + "ecosystem": "Packagist", + "name": "studiomitte/friendlycaptcha" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.1.4" + } + ] + } + ] + } ], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38873" }, + { + "type": "PACKAGE", + "url": "https://github.com/studiomitte/friendlycaptcha-typo3" + }, { "type": "WEB", "url": "https://typo3.org/security/advisory/typo3-ext-sa-2024-004" @@ -28,11 +55,11 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-06-21T15:08:59Z", "nvd_published_at": "2024-06-21T07:15:09Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-cchp-3rq6-69wj/GHSA-cchp-3rq6-69wj.json b/advisories/unreviewed/2024/06/GHSA-cchp-3rq6-69wj/GHSA-cchp-3rq6-69wj.json deleted file mode 100644 index 9e612c0b83e..00000000000 --- a/advisories/unreviewed/2024/06/GHSA-cchp-3rq6-69wj/GHSA-cchp-3rq6-69wj.json +++ /dev/null @@ -1,38 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-cchp-3rq6-69wj", - "modified": "2024-06-21T09:30:26Z", - "published": "2024-06-21T09:30:26Z", - "aliases": [ - "CVE-2024-38874" - ], - "details": "An issue was discovered in the events2 (aka Events 2) extension before 8.3.8 and 9.x before 9.0.6 for TYPO3. Missing access checks in the management plugin lead to an insecure direct object reference (IDOR) vulnerability with the potential to activate or delete various events for unauthenticated users.", - "severity": [ - { - "type": "CVSS_V3", - "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" - } - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-38874" - }, - { - "type": "WEB", - "url": "https://typo3.org/security/advisory/typo3-ext-sa-2024-003" - } - ], - "database_specific": { - "cwe_ids": [ - - ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2024-06-21T07:15:10Z" - } -} \ No newline at end of file