Publish Advisories

GHSA-66pq-hqv5-228g
GHSA-r44w-pfx8-28jv
GHSA-vxmc-qg5x-pvfx
GHSA-7m6v-q233-q9j9
GHSA-r44w-pfx8-28jv
GHSA-vxmc-qg5x-pvfx
This commit is contained in:
advisory-database[bot]
2025-04-21 22:52:12 +00:00
parent c99f00fb16
commit edd0e1c71d
6 changed files with 290 additions and 82 deletions
@@ -1,11 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-66pq-hqv5-228g",
"modified": "2025-04-20T03:31:08Z",
"modified": "2025-04-21T22:50:55Z",
"published": "2022-05-13T01:11:39Z",
"aliases": [
"CVE-2016-10027"
],
"summary": "Smack allows the bypass of TLS protections",
"details": "Race condition in the XMPP library in Smack before 4.1.9, when the SecurityMode.required TLS setting has been set, allows man-in-the-middle attackers to bypass TLS protections and trigger use of cleartext for client authentication by stripping the \"starttls\" feature from a server response.",
"severity": [
{
@@ -13,7 +14,27 @@
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [],
"affected": [
{
"package": {
"ecosystem": "Maven",
"name": "org.igniterealtime.smack:smack-core"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "4.1.9"
}
]
}
]
}
],
"references": [
{
"type": "ADVISORY",
@@ -31,6 +52,10 @@
"type": "WEB",
"url": "https://community.igniterealtime.org/blogs/ignite/2016/11/22/smack-security-advisory-2016-11-22"
},
{
"type": "PACKAGE",
"url": "https://github.com/igniterealtime/Smack"
},
{
"type": "WEB",
"url": "https://issues.igniterealtime.org/projects/SMACK/issues/SMACK-739"
@@ -46,10 +71,6 @@
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2016/12/22/12"
},
{
"type": "WEB",
"url": "http://www.securityfocus.com/bid/95129"
}
],
"database_specific": {
@@ -57,8 +78,8 @@
"CWE-362"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"github_reviewed": true,
"github_reviewed_at": "2025-04-21T22:50:55Z",
"nvd_published_at": "2017-01-12T23:59:00Z"
}
}
@@ -0,0 +1,100 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r44w-pfx8-28jv",
"modified": "2025-04-21T22:51:45Z",
"published": "2022-12-14T21:30:16Z",
"aliases": [
"CVE-2022-47411"
],
"summary": " \"Newsletter subscriber management\" (fp_newsletter) TYPO3 extension leaks subscriber data",
"details": "An issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x before 2.1.2, 2.2.1 through 2.4.0, and 3.x before 3.2.6 for TYPO3. Data about subscribers may be obtained via unsubscribeAction operations.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
{
"package": {
"ecosystem": "Packagist",
"name": "fixpunkt/fp-newsletter"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "1.1.1"
}
]
}
]
},
{
"package": {
"ecosystem": "Packagist",
"name": "fixpunkt/fp-newsletter"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "1.2.0"
},
{
"fixed": "2.1.2"
}
]
}
]
},
{
"package": {
"ecosystem": "Packagist",
"name": "fixpunkt/fp-newsletter"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "3.0.0"
},
{
"fixed": "3.2.6"
}
]
}
]
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-47411"
},
{
"type": "PACKAGE",
"url": "https://github.com/bihor/fp_newsletter"
},
{
"type": "WEB",
"url": "https://typo3.org/security/advisory/typo3-ext-sa-2022-017"
}
],
"database_specific": {
"cwe_ids": [
"CWE-200",
"CWE-668"
],
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2025-04-21T22:51:45Z",
"nvd_published_at": "2022-12-14T21:15:00Z"
}
}
@@ -0,0 +1,100 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vxmc-qg5x-pvfx",
"modified": "2025-04-21T22:51:49Z",
"published": "2022-12-14T21:30:16Z",
"aliases": [
"CVE-2022-47410"
],
"summary": " \"Newsletter subscriber management\" (fp_newsletter) TYPO3 extension leaks subscriber data",
"details": "An issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x before 2.1.2, 2.2.1 through 2.4.0, and 3.x before 3.2.6 for TYPO3. Data about subscribers may be obtained via createAction operations.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
{
"package": {
"ecosystem": "Packagist",
"name": "fixpunkt/fp-newsletter"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "1.1.1"
}
]
}
]
},
{
"package": {
"ecosystem": "Packagist",
"name": "fixpunkt/fp-newsletter"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "1.2.0"
},
{
"fixed": "2.1.2"
}
]
}
]
},
{
"package": {
"ecosystem": "Packagist",
"name": "fixpunkt/fp-newsletter"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "3.0.0"
},
{
"fixed": "3.2.6"
}
]
}
]
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-47410"
},
{
"type": "PACKAGE",
"url": "https://github.com/bihor/fp_newsletter"
},
{
"type": "WEB",
"url": "https://typo3.org/security/advisory/typo3-ext-sa-2022-017"
}
],
"database_specific": {
"cwe_ids": [
"CWE-200",
"CWE-668"
],
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2025-04-21T22:51:49Z",
"nvd_published_at": "2022-12-14T21:15:00Z"
}
}
File diff suppressed because one or more lines are too long
@@ -1,37 +0,0 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r44w-pfx8-28jv",
"modified": "2022-12-17T00:30:21Z",
"published": "2022-12-14T21:30:16Z",
"aliases": [
"CVE-2022-47411"
],
"details": "An issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x before 2.1.2, 2.2.1 through 2.4.0, and 3.x before 3.2.6 for TYPO3. Data about subscribers may be obtained via unsubscribeAction operations.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-47411"
},
{
"type": "WEB",
"url": "https://typo3.org/security/advisory/typo3-ext-sa-2022-017"
}
],
"database_specific": {
"cwe_ids": [
"CWE-200",
"CWE-668"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2022-12-14T21:15:00Z"
}
}
@@ -1,37 +0,0 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vxmc-qg5x-pvfx",
"modified": "2022-12-17T00:30:21Z",
"published": "2022-12-14T21:30:16Z",
"aliases": [
"CVE-2022-47410"
],
"details": "An issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension before 1.1.1, 1.2.0, 2.x before 2.1.2, 2.2.1 through 2.4.0, and 3.x before 3.2.6 for TYPO3. Data about subscribers may be obtained via createAction operations.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-47410"
},
{
"type": "WEB",
"url": "https://typo3.org/security/advisory/typo3-ext-sa-2022-017"
}
],
"database_specific": {
"cwe_ids": [
"CWE-200",
"CWE-668"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2022-12-14T21:15:00Z"
}
}