From fc729a8f17b43746f26653921ca22ce0e103ba8f Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 12 Feb 2025 18:20:16 +0000 Subject: [PATCH] Publish Advisories GHSA-m6jm-3v38-76j4 GHSA-552f-97wf-pmpq GHSA-74p6-39f2-23v3 GHSA-35fc-9hrj-3585 GHSA-76h9-2vwh-w278 GHSA-787v-v9vq-4rgv --- .../2024/02/GHSA-m6jm-3v38-76j4/GHSA-m6jm-3v38-76j4.json | 4 ++-- .../2024/03/GHSA-552f-97wf-pmpq/GHSA-552f-97wf-pmpq.json | 5 +++-- .../2024/04/GHSA-74p6-39f2-23v3/GHSA-74p6-39f2-23v3.json | 4 ++-- .../2024/12/GHSA-35fc-9hrj-3585/GHSA-35fc-9hrj-3585.json | 2 +- .../2024/12/GHSA-76h9-2vwh-w278/GHSA-76h9-2vwh-w278.json | 2 +- .../2024/12/GHSA-787v-v9vq-4rgv/GHSA-787v-v9vq-4rgv.json | 2 +- 6 files changed, 10 insertions(+), 9 deletions(-) diff --git a/advisories/github-reviewed/2024/02/GHSA-m6jm-3v38-76j4/GHSA-m6jm-3v38-76j4.json b/advisories/github-reviewed/2024/02/GHSA-m6jm-3v38-76j4/GHSA-m6jm-3v38-76j4.json index 49d305623f9..8a5bd52e0aa 100644 --- a/advisories/github-reviewed/2024/02/GHSA-m6jm-3v38-76j4/GHSA-m6jm-3v38-76j4.json +++ b/advisories/github-reviewed/2024/02/GHSA-m6jm-3v38-76j4/GHSA-m6jm-3v38-76j4.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-m6jm-3v38-76j4", - "modified": "2024-12-31T18:39:41Z", + "modified": "2025-02-12T18:18:43Z", "published": "2024-02-28T12:30:26Z", "aliases": [ "CVE-2024-24772" ], "summary": "Apache Superset: Improper Neutralization of custom SQL on embedded context", - "details": "A guest user could exploit a chart data REST API and send arbitrary SQL statements that on error could leak information from the underlying analytics database.This issue affects Apache Superset: before 3.0.4, from 3.1.0 before 3.1.1.\n\nUsers are recommended to upgrade to version 3.1.1 or 3.0.4, which fixes the issue.\n\n", + "details": "A guest user could exploit a chart data REST API and send arbitrary SQL statements that on error could leak information from the underlying analytics database.This issue affects Apache Superset: before 3.0.4, from 3.1.0 before 3.1.1.\n\nUsers are recommended to upgrade to version 3.1.1 or 3.0.4, which fixes the issue.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2024/03/GHSA-552f-97wf-pmpq/GHSA-552f-97wf-pmpq.json b/advisories/github-reviewed/2024/03/GHSA-552f-97wf-pmpq/GHSA-552f-97wf-pmpq.json index 57d119a62ca..d211f746bb4 100644 --- a/advisories/github-reviewed/2024/03/GHSA-552f-97wf-pmpq/GHSA-552f-97wf-pmpq.json +++ b/advisories/github-reviewed/2024/03/GHSA-552f-97wf-pmpq/GHSA-552f-97wf-pmpq.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-552f-97wf-pmpq", - "modified": "2024-03-20T21:37:59Z", + "modified": "2025-02-12T18:19:44Z", "published": "2024-03-20T17:54:35Z", "aliases": [ "CVE-2024-28868" ], "summary": "Umbraco possible user enumeration ", - "details": "### Impact\nA user enumeration attack is possible.\n\n### Affected versions\nUmbraco 10 with access to the native login screen\n\n### Patches\nThis is fixed in 10.8.5\n\n\n### Workarounds\nDisabling the native login screen, by exclusively use external logins.\n\n\n", + "details": "### Impact\nA user enumeration attack is possible.\n\n### Affected versions\nUmbraco 10 with access to the native login screen\n\n### Patches\nThis is fixed in 10.8.5\n\n\n### Workarounds\nDisabling the native login screen, by exclusively use external logins.", "severity": [ { "type": "CVSS_V3", @@ -55,6 +55,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-203", "CWE-204" ], "severity": "LOW", diff --git a/advisories/github-reviewed/2024/04/GHSA-74p6-39f2-23v3/GHSA-74p6-39f2-23v3.json b/advisories/github-reviewed/2024/04/GHSA-74p6-39f2-23v3/GHSA-74p6-39f2-23v3.json index 6e1a7a1c27c..4f5ca4de368 100644 --- a/advisories/github-reviewed/2024/04/GHSA-74p6-39f2-23v3/GHSA-74p6-39f2-23v3.json +++ b/advisories/github-reviewed/2024/04/GHSA-74p6-39f2-23v3/GHSA-74p6-39f2-23v3.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-74p6-39f2-23v3", - "modified": "2024-04-17T18:20:28Z", + "modified": "2025-02-12T18:19:46Z", "published": "2024-04-17T18:20:28Z", "aliases": [ "CVE-2024-29035" ], "summary": "Blind SSRF Leads to Port Scan by using Webhooks", - "details": "### Impact\nFailing webhooks logs are available when solution is not in debug mode. Those logs can contain information that is critical.\n \n### Affected Versions\nUmbraco versions 13.0.0 - 13.1.1\n\n### Patches\n13.1.1\n\n### Workarounds\nDisabling webhooks functionality.\n", + "details": "### Impact\nFailing webhooks logs are available when solution is not in debug mode. Those logs can contain information that is critical.\n \n### Affected Versions\nUmbraco versions 13.0.0 - 13.1.1\n\n### Patches\n13.1.1\n\n### Workarounds\nDisabling webhooks functionality.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2024/12/GHSA-35fc-9hrj-3585/GHSA-35fc-9hrj-3585.json b/advisories/github-reviewed/2024/12/GHSA-35fc-9hrj-3585/GHSA-35fc-9hrj-3585.json index f3de1a75c97..4a528053e8b 100644 --- a/advisories/github-reviewed/2024/12/GHSA-35fc-9hrj-3585/GHSA-35fc-9hrj-3585.json +++ b/advisories/github-reviewed/2024/12/GHSA-35fc-9hrj-3585/GHSA-35fc-9hrj-3585.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-35fc-9hrj-3585", - "modified": "2025-02-11T19:01:24Z", + "modified": "2025-02-12T18:18:44Z", "published": "2024-12-09T15:31:37Z", "aliases": [ "CVE-2024-53949" diff --git a/advisories/github-reviewed/2024/12/GHSA-76h9-2vwh-w278/GHSA-76h9-2vwh-w278.json b/advisories/github-reviewed/2024/12/GHSA-76h9-2vwh-w278/GHSA-76h9-2vwh-w278.json index c68e50a9e5e..9017e191bfe 100644 --- a/advisories/github-reviewed/2024/12/GHSA-76h9-2vwh-w278/GHSA-76h9-2vwh-w278.json +++ b/advisories/github-reviewed/2024/12/GHSA-76h9-2vwh-w278/GHSA-76h9-2vwh-w278.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-76h9-2vwh-w278", - "modified": "2025-02-11T19:03:54Z", + "modified": "2025-02-12T18:18:48Z", "published": "2024-12-25T12:30:45Z", "aliases": [ "CVE-2024-52046" diff --git a/advisories/github-reviewed/2024/12/GHSA-787v-v9vq-4rgv/GHSA-787v-v9vq-4rgv.json b/advisories/github-reviewed/2024/12/GHSA-787v-v9vq-4rgv/GHSA-787v-v9vq-4rgv.json index 895bc15f10d..6af7fb546e9 100644 --- a/advisories/github-reviewed/2024/12/GHSA-787v-v9vq-4rgv/GHSA-787v-v9vq-4rgv.json +++ b/advisories/github-reviewed/2024/12/GHSA-787v-v9vq-4rgv/GHSA-787v-v9vq-4rgv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-787v-v9vq-4rgv", - "modified": "2025-02-11T17:38:53Z", + "modified": "2025-02-12T18:18:46Z", "published": "2024-12-12T15:31:09Z", "aliases": [ "CVE-2024-55633"