diff --git a/advisories/unreviewed/2022/05/GHSA-2h23-c973-x63q/GHSA-2h23-c973-x63q.json b/advisories/github-reviewed/2022/05/GHSA-2h23-c973-x63q/GHSA-2h23-c973-x63q.json similarity index 66% rename from advisories/unreviewed/2022/05/GHSA-2h23-c973-x63q/GHSA-2h23-c973-x63q.json rename to advisories/github-reviewed/2022/05/GHSA-2h23-c973-x63q/GHSA-2h23-c973-x63q.json index 442f7114b76..af3045f5d0e 100644 --- a/advisories/unreviewed/2022/05/GHSA-2h23-c973-x63q/GHSA-2h23-c973-x63q.json +++ b/advisories/github-reviewed/2022/05/GHSA-2h23-c973-x63q/GHSA-2h23-c973-x63q.json @@ -1,14 +1,40 @@ { "schema_version": "1.4.0", "id": "GHSA-2h23-c973-x63q", - "modified": "2025-04-11T03:53:42Z", + "modified": "2025-04-12T02:27:53Z", "published": "2022-05-17T01:51:40Z", "aliases": [ "CVE-2011-4782" ], + "summary": "phpMyAdmin Cross-site Scripting vulnerability", "details": "Cross-site scripting (XSS) vulnerability in libraries/config/ConfigFile.class.php in the setup interface in phpMyAdmin 3.4.x before 3.4.9 allows remote attackers to inject arbitrary web script or HTML via the host parameter.", - "severity": [], - "affected": [], + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "phpmyadmin/phpmyadmin" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.4.0" + }, + { + "fixed": "3.4.9" + } + ] + } + ] + } + ], "references": [ { "type": "ADVISORY", @@ -18,6 +44,10 @@ "type": "WEB", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/71938" }, + { + "type": "PACKAGE", + "url": "https://github.com/phpmyadmin/phpmyadmin" + }, { "type": "WEB", "url": "http://lists.fedoraproject.org/pipermail/package-announce/2012-January/071523.html" @@ -47,9 +77,9 @@ "cwe_ids": [ "CWE-79" ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "severity": "LOW", + "github_reviewed": true, + "github_reviewed_at": "2025-04-12T02:27:53Z", "nvd_published_at": "2011-12-22T20:55:00Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-j473-c3rr-rx9p/GHSA-j473-c3rr-rx9p.json b/advisories/github-reviewed/2022/05/GHSA-j473-c3rr-rx9p/GHSA-j473-c3rr-rx9p.json similarity index 68% rename from advisories/unreviewed/2022/05/GHSA-j473-c3rr-rx9p/GHSA-j473-c3rr-rx9p.json rename to advisories/github-reviewed/2022/05/GHSA-j473-c3rr-rx9p/GHSA-j473-c3rr-rx9p.json index d2129db5657..98ab35b0b15 100644 --- a/advisories/unreviewed/2022/05/GHSA-j473-c3rr-rx9p/GHSA-j473-c3rr-rx9p.json +++ b/advisories/github-reviewed/2022/05/GHSA-j473-c3rr-rx9p/GHSA-j473-c3rr-rx9p.json @@ -1,19 +1,44 @@ { "schema_version": "1.4.0", "id": "GHSA-j473-c3rr-rx9p", - "modified": "2025-04-11T03:54:34Z", + "modified": "2025-04-12T02:28:13Z", "published": "2022-05-17T05:15:11Z", "aliases": [ "CVE-2011-4314" ], + "summary": "OpenID4Java does not verify that Attribute Exchange (AX) information is signed", "details": "message/ax/AxMessage.java in OpenID4Java before 0.9.6 final, as used in JBoss Enterprise Application Platform 5.1 before 5.1.2, Step2, Kay Framework before 1.0.2, and possibly other products does not verify that Attribute Exchange (AX) information is signed, which allows remote attackers to modify potentially sensitive AX information without detection via a man-in-the-middle (MITM) attack.", "severity": [], - "affected": [], + "affected": [ + { + "package": { + "ecosystem": "Maven", + "name": "org.openid4java:openid4java" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.9.6" + } + ] + } + ] + } + ], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2011-4314" }, + { + "type": "PACKAGE", + "url": "https://github.com/jbufu/openid4java" + }, { "type": "WEB", "url": "https://issues.jboss.org/browse/JBEPP-1368" @@ -22,6 +47,10 @@ "type": "WEB", "url": "https://issues.jboss.org/browse/SOA-3597" }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20201207151157/http://securitytracker.com/id?1026400" + }, { "type": "WEB", "url": "http://openid.net/2011/05/05/attribute-exchange-security-alert" @@ -34,22 +63,6 @@ "type": "WEB", "url": "http://rhn.redhat.com/errata/RHSA-2012-0519.html" }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/44496" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/48697" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/48954" - }, - { - "type": "WEB", - "url": "http://securitytracker.com/id?1026400" - }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2011/11/16/1" @@ -65,11 +78,12 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-345" ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2025-04-12T02:28:13Z", "nvd_published_at": "2012-01-27T15:55:00Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2022/05/GHSA-rmqc-wfjm-3f66/GHSA-rmqc-wfjm-3f66.json b/advisories/github-reviewed/2022/05/GHSA-rmqc-wfjm-3f66/GHSA-rmqc-wfjm-3f66.json new file mode 100644 index 00000000000..2123413f512 --- /dev/null +++ b/advisories/github-reviewed/2022/05/GHSA-rmqc-wfjm-3f66/GHSA-rmqc-wfjm-3f66.json @@ -0,0 +1,123 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rmqc-wfjm-3f66", + "modified": "2025-04-12T02:29:03Z", + "published": "2022-05-17T01:55:58Z", + "aliases": [ + "CVE-2010-5101" + ], + "summary": "TYPO3 Directory Traversal vulnerability", + "details": "Directory traversal vulnerability in the TypoScript setup in TYPO3 4.2.x before 4.2.16, 4.3.x before 4.3.9, and 4.4.x before 4.4.5 allows remote authenticated administrators to read arbitrary files via unspecified vectors related to the \"file inclusion functionality.\"", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "typo3/cms" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "4.2.0" + }, + { + "fixed": "4.2.16" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "typo3/cms" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "4.3.0" + }, + { + "fixed": "4.3.9" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "typo3/cms" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "4.4.0" + }, + { + "fixed": "4.4.5" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2010-5101" + }, + { + "type": "WEB", + "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/64180" + }, + { + "type": "PACKAGE", + "url": "https://github.com/TYPO3/typo3" + }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20120123102224/http://www.securityfocus.com/bid/45470" + }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20121103085228/http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-sa-2010-022" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2011/01/13/2" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2012/05/10/7" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2012/05/11/3" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2012/05/12/5" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2025-04-12T02:29:03Z", + "nvd_published_at": "2012-05-21T20:55:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-wvq5-72qp-grjw/GHSA-wvq5-72qp-grjw.json b/advisories/github-reviewed/2022/05/GHSA-wvq5-72qp-grjw/GHSA-wvq5-72qp-grjw.json similarity index 64% rename from advisories/unreviewed/2022/05/GHSA-wvq5-72qp-grjw/GHSA-wvq5-72qp-grjw.json rename to advisories/github-reviewed/2022/05/GHSA-wvq5-72qp-grjw/GHSA-wvq5-72qp-grjw.json index 71cfde6586d..b30e112ca5c 100644 --- a/advisories/unreviewed/2022/05/GHSA-wvq5-72qp-grjw/GHSA-wvq5-72qp-grjw.json +++ b/advisories/github-reviewed/2022/05/GHSA-wvq5-72qp-grjw/GHSA-wvq5-72qp-grjw.json @@ -1,14 +1,40 @@ { "schema_version": "1.4.0", "id": "GHSA-wvq5-72qp-grjw", - "modified": "2025-04-11T03:55:19Z", + "modified": "2025-04-12T02:28:31Z", "published": "2022-05-17T01:52:07Z", "aliases": [ "CVE-2011-4340" ], + "summary": "Symphony CMS vulnerable to Cross-site Scripting", "details": "Multiple cross-site scripting (XSS) vulnerabilities in Symphony CMS 2.2.3 and possibly other versions before 2.2.4 allow remote authenticated users with Author privileges to inject arbitrary web script or HTML via (1) the profile parameter to extensions/profiledevkit/content/content.profile.php, as demonstrated via requests to (a) the default URI, (b) about/, or (c) drafts/; or (2) the filter parameter in symphony/lib/core/class.symphony.php, as demonstrated via requests to (d) symphony/publish/comments or (e) symphony/publish/images. NOTE: some of these details are obtained from third party information.", - "severity": [], - "affected": [], + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "symphonycms/symphony-2" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.2.4" + } + ] + } + ] + } + ], "references": [ { "type": "ADVISORY", @@ -18,6 +44,14 @@ "type": "WEB", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/71106" }, + { + "type": "PACKAGE", + "url": "https://github.com/symphonycms/symphonycms" + }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20120614074927/http://www.mavitunasecurity.com/xss-and-sql-injection-vulnerabilities-in-symphony-cms" + }, { "type": "WEB", "url": "http://packetstormsecurity.org/files/view/106493/symphonycms-sqlxss.txt" @@ -26,29 +60,13 @@ "type": "WEB", "url": "http://seclists.org/bugtraq/2011/Nov/8" }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/46663" - }, { "type": "WEB", "url": "http://symphony-cms.com/download/releases/version/2.2.4" }, - { - "type": "WEB", - "url": "http://www.mavitunasecurity.com/xss-and-sql-injection-vulnerabilities-in-symphony-cms" - }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2011/11/22/9" - }, - { - "type": "WEB", - "url": "http://www.osvdb.org/76882" - }, - { - "type": "WEB", - "url": "http://www.osvdb.org/76883" } ], "database_specific": { @@ -56,8 +74,8 @@ "CWE-79" ], "severity": "LOW", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2025-04-12T02:28:31Z", "nvd_published_at": "2012-02-12T22:55:00Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-rmqc-wfjm-3f66/GHSA-rmqc-wfjm-3f66.json b/advisories/unreviewed/2022/05/GHSA-rmqc-wfjm-3f66/GHSA-rmqc-wfjm-3f66.json deleted file mode 100644 index fb5e0abc8a2..00000000000 --- a/advisories/unreviewed/2022/05/GHSA-rmqc-wfjm-3f66/GHSA-rmqc-wfjm-3f66.json +++ /dev/null @@ -1,63 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-rmqc-wfjm-3f66", - "modified": "2025-04-11T03:57:48Z", - "published": "2022-05-17T01:55:58Z", - "aliases": [ - "CVE-2010-5101" - ], - "details": "Directory traversal vulnerability in the TypoScript setup in TYPO3 4.2.x before 4.2.16, 4.3.x before 4.3.9, and 4.4.x before 4.4.5 allows remote authenticated administrators to read arbitrary files via unspecified vectors related to the \"file inclusion functionality.\"", - "severity": [], - "affected": [], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2010-5101" - }, - { - "type": "WEB", - "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/64180" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/35770" - }, - { - "type": "WEB", - "url": "http://typo3.org/teams/security/security-bulletins/typo3-core/typo3-sa-2010-022" - }, - { - "type": "WEB", - "url": "http://www.openwall.com/lists/oss-security/2011/01/13/2" - }, - { - "type": "WEB", - "url": "http://www.openwall.com/lists/oss-security/2012/05/10/7" - }, - { - "type": "WEB", - "url": "http://www.openwall.com/lists/oss-security/2012/05/11/3" - }, - { - "type": "WEB", - "url": "http://www.openwall.com/lists/oss-security/2012/05/12/5" - }, - { - "type": "WEB", - "url": "http://www.osvdb.org/70119" - }, - { - "type": "WEB", - "url": "http://www.securityfocus.com/bid/45470" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-22" - ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2012-05-21T20:55:00Z" - } -} \ No newline at end of file