From fa62e1bf4b56bbfb1211baa24454f31c35f188dd Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 12 Dec 2024 19:35:50 +0000 Subject: [PATCH] Publish Advisories GHSA-w7rg-7wq2-pjrw GHSA-43mq-6xmg-29vm GHSA-c7xh-gjv4-4jgv --- .../2024/10/GHSA-w7rg-7wq2-pjrw/GHSA-w7rg-7wq2-pjrw.json | 4 ++-- .../2024/12/GHSA-43mq-6xmg-29vm/GHSA-43mq-6xmg-29vm.json | 5 +++-- .../2024/12/GHSA-c7xh-gjv4-4jgv/GHSA-c7xh-gjv4-4jgv.json | 6 +++++- 3 files changed, 10 insertions(+), 5 deletions(-) diff --git a/advisories/github-reviewed/2024/10/GHSA-w7rg-7wq2-pjrw/GHSA-w7rg-7wq2-pjrw.json b/advisories/github-reviewed/2024/10/GHSA-w7rg-7wq2-pjrw/GHSA-w7rg-7wq2-pjrw.json index a2b76bfed39..cf4d8f49b3c 100644 --- a/advisories/github-reviewed/2024/10/GHSA-w7rg-7wq2-pjrw/GHSA-w7rg-7wq2-pjrw.json +++ b/advisories/github-reviewed/2024/10/GHSA-w7rg-7wq2-pjrw/GHSA-w7rg-7wq2-pjrw.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-w7rg-7wq2-pjrw", - "modified": "2024-10-11T17:09:26Z", + "modified": "2024-12-12T19:34:27Z", "published": "2024-10-10T12:31:13Z", "aliases": [ "CVE-2024-45149" ], "summary": "Magento Open Source Improper Access Control vulnerability", - "details": "Adobe Commerce versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and have a low impact on confidentiality. Exploitation of this issue does not require user interaction.", + "details": "Magento Open Source versions 2.4.7-p2, 2.4.6-p7, 2.4.5-p9, 2.4.4-p10 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. A high-privileged attacker could leverage this vulnerability to bypass security measures and have a low impact on confidentiality. Exploitation of this issue does not require user interaction.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2024/12/GHSA-43mq-6xmg-29vm/GHSA-43mq-6xmg-29vm.json b/advisories/github-reviewed/2024/12/GHSA-43mq-6xmg-29vm/GHSA-43mq-6xmg-29vm.json index fe0d6092049..8939e60da1a 100644 --- a/advisories/github-reviewed/2024/12/GHSA-43mq-6xmg-29vm/GHSA-43mq-6xmg-29vm.json +++ b/advisories/github-reviewed/2024/12/GHSA-43mq-6xmg-29vm/GHSA-43mq-6xmg-29vm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-43mq-6xmg-29vm", - "modified": "2024-12-11T22:02:54Z", + "modified": "2024-12-12T19:35:12Z", "published": "2024-12-11T18:30:42Z", "aliases": [ "CVE-2024-53677" @@ -51,7 +51,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-22" + "CWE-22", + "CWE-434" ], "severity": "CRITICAL", "github_reviewed": true, diff --git a/advisories/github-reviewed/2024/12/GHSA-c7xh-gjv4-4jgv/GHSA-c7xh-gjv4-4jgv.json b/advisories/github-reviewed/2024/12/GHSA-c7xh-gjv4-4jgv/GHSA-c7xh-gjv4-4jgv.json index a4325943985..4f651a8044d 100644 --- a/advisories/github-reviewed/2024/12/GHSA-c7xh-gjv4-4jgv/GHSA-c7xh-gjv4-4jgv.json +++ b/advisories/github-reviewed/2024/12/GHSA-c7xh-gjv4-4jgv/GHSA-c7xh-gjv4-4jgv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c7xh-gjv4-4jgv", - "modified": "2024-12-11T18:42:30Z", + "modified": "2024-12-12T19:33:14Z", "published": "2024-12-11T18:42:30Z", "aliases": [], "summary": "kcp's impersonation allows access to global administrative groups", @@ -52,6 +52,10 @@ { "type": "PACKAGE", "url": "https://github.com/kcp-dev/kcp" + }, + { + "type": "WEB", + "url": "https://pkg.go.dev/vuln/GO-2024-3325" } ], "database_specific": {