Publish Advisories

GHSA-w7rg-7wq2-pjrw
GHSA-43mq-6xmg-29vm
GHSA-c7xh-gjv4-4jgv
This commit is contained in:
advisory-database[bot]
2024-12-12 19:35:50 +00:00
parent 1d601b18f6
commit fa62e1bf4b
3 changed files with 10 additions and 5 deletions
@@ -1,13 +1,13 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w7rg-7wq2-pjrw",
"modified": "2024-10-11T17:09:26Z",
"modified": "2024-12-12T19:34:27Z",
"published": "2024-10-10T12:31:13Z",
"aliases": [
"CVE-2024-45149"
],
"summary": "Magento Open Source Improper Access Control vulnerability",
"details": "Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and have a low impact on confidentiality. Exploitation of this issue does not require user interaction.",
"details": "Magento Open Source versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A high-privileged attacker could leverage this vulnerability to bypass security measures and have a low impact on confidentiality. Exploitation of this issue does not require user interaction.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-43mq-6xmg-29vm",
"modified": "2024-12-11T22:02:54Z",
"modified": "2024-12-12T19:35:12Z",
"published": "2024-12-11T18:30:42Z",
"aliases": [
"CVE-2024-53677"
@@ -51,7 +51,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-22"
"CWE-22",
"CWE-434"
],
"severity": "CRITICAL",
"github_reviewed": true,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c7xh-gjv4-4jgv",
"modified": "2024-12-11T18:42:30Z",
"modified": "2024-12-12T19:33:14Z",
"published": "2024-12-11T18:42:30Z",
"aliases": [],
"summary": "kcp's impersonation allows access to global administrative groups",
@@ -52,6 +52,10 @@
{
"type": "PACKAGE",
"url": "https://github.com/kcp-dev/kcp"
},
{
"type": "WEB",
"url": "https://pkg.go.dev/vuln/GO-2024-3325"
}
],
"database_specific": {