Publish Advisories

GHSA-m6jm-3v38-76j4
GHSA-552f-97wf-pmpq
GHSA-74p6-39f2-23v3
GHSA-35fc-9hrj-3585
GHSA-76h9-2vwh-w278
GHSA-787v-v9vq-4rgv
This commit is contained in:
advisory-database[bot]
2025-02-12 18:20:16 +00:00
parent d94dd22fcf
commit fc729a8f17
6 changed files with 10 additions and 9 deletions
@@ -1,13 +1,13 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m6jm-3v38-76j4",
"modified": "2024-12-31T18:39:41Z",
"modified": "2025-02-12T18:18:43Z",
"published": "2024-02-28T12:30:26Z",
"aliases": [
"CVE-2024-24772"
],
"summary": "Apache Superset: Improper Neutralization of custom SQL on embedded context",
"details": "A guest user could exploit a chart data REST API and send arbitrary SQL statements that on error could leak information from the underlying analytics database.This issue affects Apache Superset: before 3.0.4, from 3.1.0 before 3.1.1.\n\nUsers are recommended to upgrade to version 3.1.1 or 3.0.4, which fixes the issue.\n\n",
"details": "A guest user could exploit a chart data REST API and send arbitrary SQL statements that on error could leak information from the underlying analytics database.This issue affects Apache Superset: before 3.0.4, from 3.1.0 before 3.1.1.\n\nUsers are recommended to upgrade to version 3.1.1 or 3.0.4, which fixes the issue.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,13 +1,13 @@
{
"schema_version": "1.4.0",
"id": "GHSA-552f-97wf-pmpq",
"modified": "2024-03-20T21:37:59Z",
"modified": "2025-02-12T18:19:44Z",
"published": "2024-03-20T17:54:35Z",
"aliases": [
"CVE-2024-28868"
],
"summary": "Umbraco possible user enumeration ",
"details": "### Impact\nA user enumeration attack is possible.\n\n### Affected versions\nUmbraco 10 with access to the native login screen\n\n### Patches\nThis is fixed in 10.8.5\n\n\n### Workarounds\nDisabling the native login screen, by exclusively use external logins.\n\n\n",
"details": "### Impact\nA user enumeration attack is possible.\n\n### Affected versions\nUmbraco 10 with access to the native login screen\n\n### Patches\nThis is fixed in 10.8.5\n\n\n### Workarounds\nDisabling the native login screen, by exclusively use external logins.",
"severity": [
{
"type": "CVSS_V3",
@@ -55,6 +55,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-203",
"CWE-204"
],
"severity": "LOW",
@@ -1,13 +1,13 @@
{
"schema_version": "1.4.0",
"id": "GHSA-74p6-39f2-23v3",
"modified": "2024-04-17T18:20:28Z",
"modified": "2025-02-12T18:19:46Z",
"published": "2024-04-17T18:20:28Z",
"aliases": [
"CVE-2024-29035"
],
"summary": "Blind SSRF Leads to Port Scan by using Webhooks",
"details": "### Impact\nFailing webhooks logs are available when solution is not in debug mode. Those logs can contain information that is critical.\n \n### Affected Versions\nUmbraco versions 13.0.0 - 13.1.1\n\n### Patches\n13.1.1\n\n### Workarounds\nDisabling webhooks functionality.\n",
"details": "### Impact\nFailing webhooks logs are available when solution is not in debug mode. Those logs can contain information that is critical.\n \n### Affected Versions\nUmbraco versions 13.0.0 - 13.1.1\n\n### Patches\n13.1.1\n\n### Workarounds\nDisabling webhooks functionality.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-35fc-9hrj-3585",
"modified": "2025-02-11T19:01:24Z",
"modified": "2025-02-12T18:18:44Z",
"published": "2024-12-09T15:31:37Z",
"aliases": [
"CVE-2024-53949"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-76h9-2vwh-w278",
"modified": "2025-02-11T19:03:54Z",
"modified": "2025-02-12T18:18:48Z",
"published": "2024-12-25T12:30:45Z",
"aliases": [
"CVE-2024-52046"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-787v-v9vq-4rgv",
"modified": "2025-02-11T17:38:53Z",
"modified": "2025-02-12T18:18:46Z",
"published": "2024-12-12T15:31:09Z",
"aliases": [
"CVE-2024-55633"