From ec4b8fd093d462cf099a7dd47ec2b7e8ff08f783 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 4 Mar 2025 18:31:50 +0000 Subject: [PATCH] Publish Advisories GHSA-7pfc-834q-h497 GHSA-c9h9-h5gf-885r GHSA-hqgj-4396-hmxv GHSA-7pfc-834q-h497 GHSA-c9h9-h5gf-885r GHSA-hqgj-4396-hmxv --- .../GHSA-7pfc-834q-h497.json | 180 ++++++++++++++++++ .../GHSA-c9h9-h5gf-885r.json | 149 +++++++++++++++ .../GHSA-hqgj-4396-hmxv.json | 149 +++++++++++++++ .../GHSA-7pfc-834q-h497.json | 36 ---- .../GHSA-c9h9-h5gf-885r.json | 36 ---- .../GHSA-hqgj-4396-hmxv.json | 36 ---- 6 files changed, 478 insertions(+), 108 deletions(-) create mode 100644 advisories/github-reviewed/2023/10/GHSA-7pfc-834q-h497/GHSA-7pfc-834q-h497.json create mode 100644 advisories/github-reviewed/2024/02/GHSA-c9h9-h5gf-885r/GHSA-c9h9-h5gf-885r.json create mode 100644 advisories/github-reviewed/2024/02/GHSA-hqgj-4396-hmxv/GHSA-hqgj-4396-hmxv.json delete mode 100644 advisories/unreviewed/2023/10/GHSA-7pfc-834q-h497/GHSA-7pfc-834q-h497.json delete mode 100644 advisories/unreviewed/2024/02/GHSA-c9h9-h5gf-885r/GHSA-c9h9-h5gf-885r.json delete mode 100644 advisories/unreviewed/2024/02/GHSA-hqgj-4396-hmxv/GHSA-hqgj-4396-hmxv.json diff --git a/advisories/github-reviewed/2023/10/GHSA-7pfc-834q-h497/GHSA-7pfc-834q-h497.json b/advisories/github-reviewed/2023/10/GHSA-7pfc-834q-h497/GHSA-7pfc-834q-h497.json new file mode 100644 index 00000000000..b04de44f777 --- /dev/null +++ b/advisories/github-reviewed/2023/10/GHSA-7pfc-834q-h497/GHSA-7pfc-834q-h497.json @@ -0,0 +1,180 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7pfc-834q-h497", + "modified": "2025-03-04T18:28:58Z", + "published": "2023-10-13T09:30:23Z", + "aliases": [ + "CVE-2023-38251" + ], + "summary": "Magento Open Source allows Uncontrolled Resource Consumption", + "details": "Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by an Uncontrolled Resource Consumption vulnerability that could lead into a minor application denial-of-service. Exploitation of this issue does not require user interaction.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.4.7-beta1" + }, + { + "fixed": "2.4.7-beta2" + } + ] + } + ], + "versions": [ + "2.4.7-beta1" + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "versions": [ + "2.4.7" + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "versions": [ + "2.4.6" + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "versions": [ + "2.4.5" + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "versions": [ + "2.4.4" + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.4.6-p1" + }, + { + "fixed": "2.4.6-p3" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.4.5-p1" + }, + { + "fixed": "2.4.5-p5" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.4.4-p1" + }, + { + "fixed": "2.4.4-p6" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/project-community-edition" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "2.0.2" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38251" + }, + { + "type": "PACKAGE", + "url": "https://github.com/magento/magento2" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/magento/apsb23-50.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2025-03-04T18:28:58Z", + "nvd_published_at": "2023-10-13T07:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/02/GHSA-c9h9-h5gf-885r/GHSA-c9h9-h5gf-885r.json b/advisories/github-reviewed/2024/02/GHSA-c9h9-h5gf-885r/GHSA-c9h9-h5gf-885r.json new file mode 100644 index 00000000000..92db7316e63 --- /dev/null +++ b/advisories/github-reviewed/2024/02/GHSA-c9h9-h5gf-885r/GHSA-c9h9-h5gf-885r.json @@ -0,0 +1,149 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c9h9-h5gf-885r", + "modified": "2025-03-04T18:29:16Z", + "published": "2024-02-15T15:30:29Z", + "aliases": [ + "CVE-2024-20716" + ], + "summary": "Magento Open Source allows Uncontrolled Resource Consumption", + "details": "Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to an application denial-of-service. A high-privileged attacker could leverage this vulnerability to exhaust system resources, causing the application to slow down or crash. Exploitation of this issue does not require user interaction.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "versions": [ + "2.4.6" + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "versions": [ + "2.4.5" + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "versions": [ + "2.4.4" + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.4.6-p1" + }, + { + "fixed": "2.4.6-p4" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.4.5-p1" + }, + { + "fixed": "2.4.5-p6" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.4.4-p1" + }, + { + "fixed": "2.4.4-p7" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/project-community-edition" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "2.0.2" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20716" + }, + { + "type": "PACKAGE", + "url": "https://github.com/magento/magento2" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/magento/apsb24-03.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2025-03-04T18:29:16Z", + "nvd_published_at": "2024-02-15T14:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/02/GHSA-hqgj-4396-hmxv/GHSA-hqgj-4396-hmxv.json b/advisories/github-reviewed/2024/02/GHSA-hqgj-4396-hmxv/GHSA-hqgj-4396-hmxv.json new file mode 100644 index 00000000000..92c5b45ccd0 --- /dev/null +++ b/advisories/github-reviewed/2024/02/GHSA-hqgj-4396-hmxv/GHSA-hqgj-4396-hmxv.json @@ -0,0 +1,149 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hqgj-4396-hmxv", + "modified": "2025-03-04T18:30:32Z", + "published": "2024-02-15T15:30:29Z", + "aliases": [ + "CVE-2024-20718" + ], + "summary": "Magento Open Source allows Cross-Site Request Forgery (CSRF)", + "details": "Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to trick a victim into performing actions they did not intend to do, which could be used to bypass security measures and gain unauthorized access. Exploitation of this issue requires user interaction, typically in the form of the victim clicking a link or visiting a malicious website.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "versions": [ + "2.4.6" + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "versions": [ + "2.4.5" + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "versions": [ + "2.4.4" + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.4.6-p1" + }, + { + "fixed": "2.4.6-p4" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.4.5-p1" + }, + { + "fixed": "2.4.5-p6" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.4.4-p1" + }, + { + "fixed": "2.4.4-p7" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/project-community-edition" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "2.0.2" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20718" + }, + { + "type": "PACKAGE", + "url": "https://github.com/magento/magento2" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/magento/apsb24-03.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2025-03-04T18:30:32Z", + "nvd_published_at": "2024-02-15T14:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-7pfc-834q-h497/GHSA-7pfc-834q-h497.json b/advisories/unreviewed/2023/10/GHSA-7pfc-834q-h497/GHSA-7pfc-834q-h497.json deleted file mode 100644 index c3f3f2de0fe..00000000000 --- a/advisories/unreviewed/2023/10/GHSA-7pfc-834q-h497/GHSA-7pfc-834q-h497.json +++ /dev/null @@ -1,36 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-7pfc-834q-h497", - "modified": "2024-04-04T08:37:37Z", - "published": "2023-10-13T09:30:23Z", - "aliases": [ - "CVE-2023-38251" - ], - "details": "Adobe Commerce versions 2.4.7-beta1 (and earlier), 2.4.6-p2 (and earlier), 2.4.5-p4 (and earlier) and 2.4.4-p5 (and earlier) are affected by a Uncontrolled Resource Consumption vulnerability that could lead in minor application denial-of-service. Exploitation of this issue does not require user interaction.", - "severity": [ - { - "type": "CVSS_V3", - "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" - } - ], - "affected": [], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38251" - }, - { - "type": "WEB", - "url": "https://helpx.adobe.com/security/products/magento/apsb23-50.html" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-400" - ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2023-10-13T07:15:41Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-c9h9-h5gf-885r/GHSA-c9h9-h5gf-885r.json b/advisories/unreviewed/2024/02/GHSA-c9h9-h5gf-885r/GHSA-c9h9-h5gf-885r.json deleted file mode 100644 index ecb3c6d481d..00000000000 --- a/advisories/unreviewed/2024/02/GHSA-c9h9-h5gf-885r/GHSA-c9h9-h5gf-885r.json +++ /dev/null @@ -1,36 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-c9h9-h5gf-885r", - "modified": "2024-02-15T15:30:29Z", - "published": "2024-02-15T15:30:29Z", - "aliases": [ - "CVE-2024-20716" - ], - "details": "Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to an application denial-of-service. A high-privileged attacker could leverage this vulnerability to exhaust system resources, causing the application to slow down or crash. Exploitation of this issue does not require user interaction.", - "severity": [ - { - "type": "CVSS_V3", - "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H" - } - ], - "affected": [], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20716" - }, - { - "type": "WEB", - "url": "https://helpx.adobe.com/security/products/magento/apsb24-03.html" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-400" - ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2024-02-15T14:15:45Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-hqgj-4396-hmxv/GHSA-hqgj-4396-hmxv.json b/advisories/unreviewed/2024/02/GHSA-hqgj-4396-hmxv/GHSA-hqgj-4396-hmxv.json deleted file mode 100644 index 44afd18454a..00000000000 --- a/advisories/unreviewed/2024/02/GHSA-hqgj-4396-hmxv/GHSA-hqgj-4396-hmxv.json +++ /dev/null @@ -1,36 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-hqgj-4396-hmxv", - "modified": "2024-02-15T15:30:29Z", - "published": "2024-02-15T15:30:29Z", - "aliases": [ - "CVE-2024-20718" - ], - "details": "Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to trick a victim into performing actions they did not intend to do, which could be used to bypass security measures and gain unauthorized access. Exploitation of this issue requires user interaction, typically in the form of the victim clicking a link or visiting a malicious website.", - "severity": [ - { - "type": "CVSS_V3", - "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" - } - ], - "affected": [], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-20718" - }, - { - "type": "WEB", - "url": "https://helpx.adobe.com/security/products/magento/apsb24-03.html" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-352" - ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2024-02-15T14:15:45Z" - } -} \ No newline at end of file