diff --git a/advisories/github-reviewed/2024/09/GHSA-39v3-f278-vj3g/GHSA-39v3-f278-vj3g.json b/advisories/github-reviewed/2024/09/GHSA-39v3-f278-vj3g/GHSA-39v3-f278-vj3g.json new file mode 100644 index 00000000000..666c2b1440d --- /dev/null +++ b/advisories/github-reviewed/2024/09/GHSA-39v3-f278-vj3g/GHSA-39v3-f278-vj3g.json @@ -0,0 +1,61 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-39v3-f278-vj3g", + "modified": "2024-09-17T21:30:20Z", + "published": "2024-09-17T21:30:20Z", + "aliases": [ + "CVE-2024-45816" + ], + "summary": "@backstage/plugin-techdocs-backend storage bucket Directory Traversal vulnerability", + "details": "### Impact\n\nWhen using the AWS S3 or GCS storage provider for TechDocs it is possible to access content in the entire storage bucket. This can leak contents of the bucket that are not intended to be accessible, as well as bypass permission checks in Backstage.\n\n### Patches\n\nThis has been fixed in the 1.10.13 release of the `@backstage/plugin-techdocs-backend` package.\n\n### References\n\nIf you have any questions or comments about this advisory:\n\nOpen an issue in the [Backstage repository](https://github.com/backstage/backstage)\nVisit our Discord, linked to in [Backstage README](https://github.com/backstage/backstage)\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "npm", + "name": "@backstage/plugin-techdocs-backend" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.10.13" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/backstage/backstage/security/advisories/GHSA-39v3-f278-vj3g" + }, + { + "type": "PACKAGE", + "url": "https://github.com/backstage/backstage" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-23" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-09-17T21:30:20Z", + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/09/GHSA-3x3f-jcp3-g22j/GHSA-3x3f-jcp3-g22j.json b/advisories/github-reviewed/2024/09/GHSA-3x3f-jcp3-g22j/GHSA-3x3f-jcp3-g22j.json new file mode 100644 index 00000000000..6eb86990b0a --- /dev/null +++ b/advisories/github-reviewed/2024/09/GHSA-3x3f-jcp3-g22j/GHSA-3x3f-jcp3-g22j.json @@ -0,0 +1,61 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3x3f-jcp3-g22j", + "modified": "2024-09-17T21:29:49Z", + "published": "2024-09-17T21:29:49Z", + "aliases": [ + "CVE-2024-45815" + ], + "summary": "@backstage/plugin-catalog-backend Prototype Pollution vulnerability", + "details": "### Impact\n\nA malicious actor with authenticated access to a Backstage instance with the catalog backend plugin installed is able to interrupt the service using a specially crafted query to the catalog API.\n\n### Patches\n\nThis has been fixed in the `1.26.0` release of the `@backstage/plugin-catalog-backend` package.\n\n### References\n\nIf you have any questions or comments about this advisory:\n\nOpen an issue in the [Backstage repository](https://github.com/backstage/backstage)\nVisit our Discord, linked to in [Backstage README](https://github.com/backstage/backstage)\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "npm", + "name": "@backstage/plugin-catalog-backend" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.26.0" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/backstage/backstage/security/advisories/GHSA-3x3f-jcp3-g22j" + }, + { + "type": "PACKAGE", + "url": "https://github.com/backstage/backstage" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1321" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-09-17T21:29:49Z", + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/09/GHSA-q25c-r482-77p9/GHSA-q25c-r482-77p9.json b/advisories/github-reviewed/2024/09/GHSA-q25c-r482-77p9/GHSA-q25c-r482-77p9.json new file mode 100644 index 00000000000..851d018c765 --- /dev/null +++ b/advisories/github-reviewed/2024/09/GHSA-q25c-r482-77p9/GHSA-q25c-r482-77p9.json @@ -0,0 +1,138 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q25c-r482-77p9", + "modified": "2024-09-17T21:29:12Z", + "published": "2024-09-17T15:31:23Z", + "aliases": [ + "CVE-2024-47047" + ], + "summary": "powermail TYPO3 extension has Insecure Direct Object Reference", + "details": "An issue was discovered in the powermail extension through 12.4.0 for TYPO3. It fails to validate the mail parameter of the createAction, resulting in Insecure Direct Object Reference (IDOR) in some configurations. An unauthenticated attacker can use this to display user-submitted data of all forms persisted by the extension. The fixed versions are 7.5.1, 8.5.1, 10.9.1, and 12.4.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:F/RL:O/RC:C" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "in2code/powermail" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "7.5.1" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "in2code/powermail" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "8.0.0" + }, + { + "fixed": "8.5.1" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "in2code/powermail" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "9.0.0" + }, + { + "fixed": "10.9.1" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "in2code/powermail" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "11.0.0" + }, + { + "fixed": "12.4.1" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47047" + }, + { + "type": "WEB", + "url": "https://github.com/in2code-de/powermail/commit/095a17637b6370aefd5390663cc11af47210f575" + }, + { + "type": "WEB", + "url": "https://github.com/in2code-de/powermail/commit/682194d71a5f67fa39d899a9625ba69bb62f9bd8" + }, + { + "type": "WEB", + "url": "https://github.com/in2code-de/powermail/commit/91015da289111b86b8dbcb2553d5a722b944231e" + }, + { + "type": "WEB", + "url": "https://github.com/in2code-de/powermail/commit/bbadb8d7a71ddb469d07d106551938c91465b811" + }, + { + "type": "PACKAGE", + "url": "https://github.com/in2code-de/powermail" + }, + { + "type": "WEB", + "url": "https://typo3.org/security/advisory/typo3-ext-sa-2024-007" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-09-17T21:29:11Z", + "nvd_published_at": "2024-09-17T14:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-q25c-r482-77p9/GHSA-q25c-r482-77p9.json b/advisories/unreviewed/2024/09/GHSA-q25c-r482-77p9/GHSA-q25c-r482-77p9.json deleted file mode 100644 index c171cd63b77..00000000000 --- a/advisories/unreviewed/2024/09/GHSA-q25c-r482-77p9/GHSA-q25c-r482-77p9.json +++ /dev/null @@ -1,35 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-q25c-r482-77p9", - "modified": "2024-09-17T15:31:23Z", - "published": "2024-09-17T15:31:23Z", - "aliases": [ - "CVE-2024-47047" - ], - "details": "An issue was discovered in the powermail extension through 12.4.0 for TYPO3. It fails to validate the mail parameter of the createAction, resulting in Insecure Direct Object Reference (IDOR) in some configurations. An unauthenticated attacker can use this to display user-submitted data of all forms persisted by the extension. The fixed versions are 7.5.1, 8.5.1, 10.9.1, and 12.4.1.", - "severity": [ - - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47047" - }, - { - "type": "WEB", - "url": "https://typo3.org/security/advisory/typo3-ext-sa-2024-007" - } - ], - "database_specific": { - "cwe_ids": [ - - ], - "severity": null, - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2024-09-17T14:15:17Z" - } -} \ No newline at end of file