From faac91dc547ea837806d287856340057567273e9 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 20 Oct 2023 22:39:09 +0000 Subject: [PATCH] Publish Advisories GHSA-6hv3-9fqx-8pg5 GHSA-cp2p-6xh4-jmcp GHSA-cgf8-h3fp-h956 --- .../GHSA-6hv3-9fqx-8pg5.json | 31 ++++++++++++++--- .../GHSA-cp2p-6xh4-jmcp.json | 33 ++++++++++++++++--- .../GHSA-cgf8-h3fp-h956.json | 33 ++++++++++++++++--- 3 files changed, 83 insertions(+), 14 deletions(-) rename advisories/{unreviewed => github-reviewed}/2023/01/GHSA-6hv3-9fqx-8pg5/GHSA-6hv3-9fqx-8pg5.json (71%) rename advisories/{unreviewed => github-reviewed}/2023/01/GHSA-cp2p-6xh4-jmcp/GHSA-cp2p-6xh4-jmcp.json (50%) rename advisories/{unreviewed => github-reviewed}/2023/10/GHSA-cgf8-h3fp-h956/GHSA-cgf8-h3fp-h956.json (61%) diff --git a/advisories/unreviewed/2023/01/GHSA-6hv3-9fqx-8pg5/GHSA-6hv3-9fqx-8pg5.json b/advisories/github-reviewed/2023/01/GHSA-6hv3-9fqx-8pg5/GHSA-6hv3-9fqx-8pg5.json similarity index 71% rename from advisories/unreviewed/2023/01/GHSA-6hv3-9fqx-8pg5/GHSA-6hv3-9fqx-8pg5.json rename to advisories/github-reviewed/2023/01/GHSA-6hv3-9fqx-8pg5/GHSA-6hv3-9fqx-8pg5.json index 3da9bd562a4..dda22efdaee 100644 --- a/advisories/unreviewed/2023/01/GHSA-6hv3-9fqx-8pg5/GHSA-6hv3-9fqx-8pg5.json +++ b/advisories/github-reviewed/2023/01/GHSA-6hv3-9fqx-8pg5/GHSA-6hv3-9fqx-8pg5.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-6hv3-9fqx-8pg5", - "modified": "2023-02-07T21:30:27Z", + "modified": "2023-10-20T22:38:29Z", "published": "2023-01-29T21:34:04Z", "aliases": [ "CVE-2016-15022" ], + "summary": "CImage Cross-site Scripting vulnerability", "details": "A vulnerability was found in mosbth cimage up to 0.7.18. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file check_system.php. The manipulation of the argument $_SERVER['SERVER_SOFTWARE'] leads to cross site scripting. The attack can be launched remotely. Upgrading to version 0.7.19 is able to address this issue. The name of the patch is 401478c8393989836beeddfeac5ce44570af162b. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-219715.", "severity": [ { @@ -14,7 +15,25 @@ } ], "affected": [ - + { + "package": { + "ecosystem": "Packagist", + "name": "mos/cimage" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.7.19" + } + ] + } + ] + } ], "references": [ { @@ -25,6 +44,10 @@ "type": "WEB", "url": "https://github.com/mosbth/cimage/commit/401478c8393989836beeddfeac5ce44570af162b" }, + { + "type": "PACKAGE", + "url": "https://github.com/mosbth/cimage" + }, { "type": "WEB", "url": "https://github.com/mosbth/cimage/releases/tag/v0.7.19" @@ -43,8 +66,8 @@ "CWE-79" ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2023-10-20T22:38:29Z", "nvd_published_at": "2023-01-29T19:15:00Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/01/GHSA-cp2p-6xh4-jmcp/GHSA-cp2p-6xh4-jmcp.json b/advisories/github-reviewed/2023/01/GHSA-cp2p-6xh4-jmcp/GHSA-cp2p-6xh4-jmcp.json similarity index 50% rename from advisories/unreviewed/2023/01/GHSA-cp2p-6xh4-jmcp/GHSA-cp2p-6xh4-jmcp.json rename to advisories/github-reviewed/2023/01/GHSA-cp2p-6xh4-jmcp/GHSA-cp2p-6xh4-jmcp.json index 3d23b401508..f8fa93f7f13 100644 --- a/advisories/unreviewed/2023/01/GHSA-cp2p-6xh4-jmcp/GHSA-cp2p-6xh4-jmcp.json +++ b/advisories/github-reviewed/2023/01/GHSA-cp2p-6xh4-jmcp/GHSA-cp2p-6xh4-jmcp.json @@ -1,12 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-cp2p-6xh4-jmcp", - "modified": "2023-01-09T21:30:23Z", + "modified": "2023-10-20T22:38:12Z", "published": "2023-01-02T18:30:27Z", "aliases": [ "CVE-2015-10009" ], - "details": "A vulnerability was found in nterchange up to 4.1.0. It has been rated as critical. This issue affects the function getContent of the file app/controllers/code_caller_controller.php. The manipulation of the argument q with the input %5C%27%29;phpinfo%28%29;/* leads to code injection. The exploit has been disclosed to the public and may be used. Upgrading to version 4.1.1 is able to address this issue. The name of the patch is fba7d89176fba8fe289edd58835fe45080797d99. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-217187.", + "summary": "nterchange Code Injection vulnerability", + "details": "A vulnerability was found in nterchange up to 4.1.0. It has been rated as critical. This issue affects the function getContent of the file `app/controllers/code_caller_controller.php`. The manipulation of the argument q with the input %5C%27%29;phpinfo%28%29;/* leads to code injection. The exploit has been disclosed to the public and may be used. Upgrading to version 4.1.1 is able to address this issue. The name of the patch is fba7d89176fba8fe289edd58835fe45080797d99. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-217187.", "severity": [ { "type": "CVSS_V3", @@ -14,7 +15,25 @@ } ], "affected": [ - + { + "package": { + "ecosystem": "Packagist", + "name": "nonfiction/nterchange" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.1.1" + } + ] + } + ] + } ], "references": [ { @@ -25,6 +44,10 @@ "type": "WEB", "url": "https://github.com/nonfiction/nterchange_backend/commit/fba7d89176fba8fe289edd58835fe45080797d99" }, + { + "type": "PACKAGE", + "url": "https://github.com/nonfiction/nterchange_backend" + }, { "type": "WEB", "url": "https://github.com/nonfiction/nterchange_backend/releases/tag/4.1.1" @@ -43,8 +66,8 @@ "CWE-94" ], "severity": "CRITICAL", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2023-10-20T22:38:12Z", "nvd_published_at": "2023-01-02T16:15:00Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-cgf8-h3fp-h956/GHSA-cgf8-h3fp-h956.json b/advisories/github-reviewed/2023/10/GHSA-cgf8-h3fp-h956/GHSA-cgf8-h3fp-h956.json similarity index 61% rename from advisories/unreviewed/2023/10/GHSA-cgf8-h3fp-h956/GHSA-cgf8-h3fp-h956.json rename to advisories/github-reviewed/2023/10/GHSA-cgf8-h3fp-h956/GHSA-cgf8-h3fp-h956.json index 5d8d2ec9ea5..5b4eaabd90d 100644 --- a/advisories/unreviewed/2023/10/GHSA-cgf8-h3fp-h956/GHSA-cgf8-h3fp-h956.json +++ b/advisories/github-reviewed/2023/10/GHSA-cgf8-h3fp-h956/GHSA-cgf8-h3fp-h956.json @@ -1,17 +1,36 @@ { "schema_version": "1.4.0", "id": "GHSA-cgf8-h3fp-h956", - "modified": "2023-10-20T06:30:19Z", + "modified": "2023-10-20T22:37:41Z", "published": "2023-10-20T06:30:19Z", "aliases": [ "CVE-2023-46277" ], + "summary": "Pleaser privilege escalation vulnerability", "details": "please (aka pleaser) through 0.5.4 allows privilege escalation through the TIOCSTI and/or TIOCLINUX ioctl. (If both TIOCSTI and TIOCLINUX are disabled, this cannot be exploited.)", "severity": [ ], "affected": [ - + { + "package": { + "ecosystem": "crates.io", + "name": "pleaser" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "0.5.4" + } + ] + } + ] + } ], "references": [ { @@ -22,6 +41,10 @@ "type": "WEB", "url": "https://github.com/rustsec/advisory-db/pull/1798" }, + { + "type": "PACKAGE", + "url": "https://gitlab.com/edneville/please" + }, { "type": "WEB", "url": "https://gitlab.com/edneville/please/-/issues/13" @@ -39,9 +62,9 @@ "cwe_ids": [ ], - "severity": null, - "github_reviewed": false, - "github_reviewed_at": null, + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2023-10-20T22:37:41Z", "nvd_published_at": null } } \ No newline at end of file