From f9b885d2353d7e5cd4a0ffd1cefbdb4482fe3b1b Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 11 Apr 2025 20:02:36 +0000 Subject: [PATCH] Publish Advisories GHSA-j5rc-cr5w-vfg6 GHSA-mp9g-4rg9-8rcm GHSA-wg4m-vvp6-2hc5 GHSA-mp9g-4rg9-8rcm --- .../GHSA-j5rc-cr5w-vfg6.json | 47 +++++++--- .../GHSA-mp9g-4rg9-8rcm.json | 84 +++++++++++++++++ .../GHSA-wg4m-vvp6-2hc5.json | 89 ++++++++++++------- .../GHSA-mp9g-4rg9-8rcm.json | 35 -------- 4 files changed, 180 insertions(+), 75 deletions(-) rename advisories/{unreviewed => github-reviewed}/2022/05/GHSA-j5rc-cr5w-vfg6/GHSA-j5rc-cr5w-vfg6.json (51%) create mode 100644 advisories/github-reviewed/2022/05/GHSA-mp9g-4rg9-8rcm/GHSA-mp9g-4rg9-8rcm.json rename advisories/{unreviewed => github-reviewed}/2022/05/GHSA-wg4m-vvp6-2hc5/GHSA-wg4m-vvp6-2hc5.json (56%) delete mode 100644 advisories/unreviewed/2022/05/GHSA-mp9g-4rg9-8rcm/GHSA-mp9g-4rg9-8rcm.json diff --git a/advisories/unreviewed/2022/05/GHSA-j5rc-cr5w-vfg6/GHSA-j5rc-cr5w-vfg6.json b/advisories/github-reviewed/2022/05/GHSA-j5rc-cr5w-vfg6/GHSA-j5rc-cr5w-vfg6.json similarity index 51% rename from advisories/unreviewed/2022/05/GHSA-j5rc-cr5w-vfg6/GHSA-j5rc-cr5w-vfg6.json rename to advisories/github-reviewed/2022/05/GHSA-j5rc-cr5w-vfg6/GHSA-j5rc-cr5w-vfg6.json index 304148a5d8a..61ca08a2196 100644 --- a/advisories/unreviewed/2022/05/GHSA-j5rc-cr5w-vfg6/GHSA-j5rc-cr5w-vfg6.json +++ b/advisories/github-reviewed/2022/05/GHSA-j5rc-cr5w-vfg6/GHSA-j5rc-cr5w-vfg6.json @@ -1,19 +1,49 @@ { "schema_version": "1.4.0", "id": "GHSA-j5rc-cr5w-vfg6", - "modified": "2025-04-11T03:34:28Z", + "modified": "2025-04-11T20:01:58Z", "published": "2022-05-13T01:13:08Z", "aliases": [ "CVE-2010-1613" ], + "summary": "Moodle Session Fixation vulnerability", "details": "Moodle 1.8.x and 1.9.x before 1.9.8 does not enable the \"Regenerate session id during login\" setting by default, which makes it easier for remote attackers to conduct session fixation attacks.", - "severity": [], - "affected": [], + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "moodle/moodle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "1.8.0" + }, + { + "fixed": "1.9.8" + } + ] + } + ] + } + ], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2010-1613" }, + { + "type": "PACKAGE", + "url": "https://github.com/moodle/moodle" + }, { "type": "WEB", "url": "http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html" @@ -21,19 +51,16 @@ { "type": "WEB", "url": "http://moodle.org/security" - }, - { - "type": "WEB", - "url": "http://www.vupen.com/english/advisories/2010/1107" } ], "database_specific": { "cwe_ids": [ - "CWE-287" + "CWE-287", + "CWE-384" ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2025-04-11T20:01:58Z", "nvd_published_at": "2010-04-29T21:30:00Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2022/05/GHSA-mp9g-4rg9-8rcm/GHSA-mp9g-4rg9-8rcm.json b/advisories/github-reviewed/2022/05/GHSA-mp9g-4rg9-8rcm/GHSA-mp9g-4rg9-8rcm.json new file mode 100644 index 00000000000..79edcab4ce0 --- /dev/null +++ b/advisories/github-reviewed/2022/05/GHSA-mp9g-4rg9-8rcm/GHSA-mp9g-4rg9-8rcm.json @@ -0,0 +1,84 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mp9g-4rg9-8rcm", + "modified": "2025-04-11T20:00:18Z", + "published": "2022-05-02T03:58:18Z", + "aliases": [ + "CVE-2009-4803" + ], + "summary": "Accessibility Glossary (a21glossary) SQL injection vulnerability", + "details": "SQL injection vulnerability in the Accessibility Glossary (a21glossary) extension 0.4.10 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "svewap/a21glossary" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "0.4.10" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "wapplersystems/a21glossary" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "0.4.10" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2009-4803" + }, + { + "type": "PACKAGE", + "url": "https://github.com/WapplerSystems/a21glossary" + }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20090822085638/http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-003" + }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20200228204747/http://www.securityfocus.com/bid/33997" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": true, + "github_reviewed_at": "2025-04-11T20:00:18Z", + "nvd_published_at": "2010-04-23T14:30:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-wg4m-vvp6-2hc5/GHSA-wg4m-vvp6-2hc5.json b/advisories/github-reviewed/2022/05/GHSA-wg4m-vvp6-2hc5/GHSA-wg4m-vvp6-2hc5.json similarity index 56% rename from advisories/unreviewed/2022/05/GHSA-wg4m-vvp6-2hc5/GHSA-wg4m-vvp6-2hc5.json rename to advisories/github-reviewed/2022/05/GHSA-wg4m-vvp6-2hc5/GHSA-wg4m-vvp6-2hc5.json index 910d1a06387..0c1c3d61af2 100644 --- a/advisories/unreviewed/2022/05/GHSA-wg4m-vvp6-2hc5/GHSA-wg4m-vvp6-2hc5.json +++ b/advisories/github-reviewed/2022/05/GHSA-wg4m-vvp6-2hc5/GHSA-wg4m-vvp6-2hc5.json @@ -1,14 +1,59 @@ { "schema_version": "1.4.0", "id": "GHSA-wg4m-vvp6-2hc5", - "modified": "2025-04-11T03:34:24Z", + "modified": "2025-04-11T20:01:05Z", "published": "2022-05-14T02:45:01Z", "aliases": [ "CVE-2010-1593" ], + "summary": "SilverStripe vulnerable to Cross-site Scripting", "details": "Multiple cross-site scripting (XSS) vulnerabilities in SilverStripe before 2.3.5 allow remote attackers to inject arbitrary web script or HTML via (1) the CommenterURL parameter to PostCommentForm, and in the Forum module before 0.2.5 in SilverStripe before 2.3.5 allow remote attackers to inject arbitrary web script or HTML via (2) the Search parameter to forums/search (aka the search script).", - "severity": [], - "affected": [], + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "silverstripe/cms" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.3.5" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "silverstripe/framework" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.3.5" + } + ] + } + ] + } + ], "references": [ { "type": "ADVISORY", @@ -22,6 +67,14 @@ "type": "WEB", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/55839" }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20200228222759/https://www.securityfocus.com/bid/37923" + }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20201208002434/http://www.securityfocus.com/archive/1/509139/100/0/threaded" + }, { "type": "WEB", "url": "http://archives.neohapsis.com/archives/fulldisclosure/2010-01/0450.html" @@ -38,30 +91,6 @@ "type": "WEB", "url": "http://open.silverstripe.org/wiki/ChangeLog/2.3.5" }, - { - "type": "WEB", - "url": "http://osvdb.org/61921" - }, - { - "type": "WEB", - "url": "http://osvdb.org/61923" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/38290" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/38347" - }, - { - "type": "WEB", - "url": "http://www.securityfocus.com/archive/1/509139/100/0/threaded" - }, - { - "type": "WEB", - "url": "http://www.securityfocus.com/bid/37923" - }, { "type": "WEB", "url": "http://www.silverstripe.org/security-releases" @@ -71,9 +100,9 @@ "cwe_ids": [ "CWE-79" ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "severity": "LOW", + "github_reviewed": true, + "github_reviewed_at": "2025-04-11T20:01:05Z", "nvd_published_at": "2010-04-28T23:30:00Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-mp9g-4rg9-8rcm/GHSA-mp9g-4rg9-8rcm.json b/advisories/unreviewed/2022/05/GHSA-mp9g-4rg9-8rcm/GHSA-mp9g-4rg9-8rcm.json deleted file mode 100644 index c2981bfab0c..00000000000 --- a/advisories/unreviewed/2022/05/GHSA-mp9g-4rg9-8rcm/GHSA-mp9g-4rg9-8rcm.json +++ /dev/null @@ -1,35 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-mp9g-4rg9-8rcm", - "modified": "2025-04-11T03:34:12Z", - "published": "2022-05-02T03:58:18Z", - "aliases": [ - "CVE-2009-4803" - ], - "details": "SQL injection vulnerability in the Accessibility Glossary (a21glossary) extension 0.4.10 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.", - "severity": [], - "affected": [], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2009-4803" - }, - { - "type": "WEB", - "url": "http://typo3.org/teams/security/security-bulletins/typo3-sa-2009-003" - }, - { - "type": "WEB", - "url": "http://www.securityfocus.com/bid/33997" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-89" - ], - "severity": "HIGH", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2010-04-23T14:30:00Z" - } -} \ No newline at end of file