Skip to content

File tree

8 files changed

+103
-59
lines changed

8 files changed

+103
-59
lines changed

advisories/github-reviewed/2023/11/GHSA-7h4p-27mh-hmrw/GHSA-7h4p-27mh-hmrw.json

Lines changed: 9 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-7h4p-27mh-hmrw",
4-
"modified": "2024-09-20T15:08:16Z",
4+
"modified": "2025-11-04T19:43:27Z",
55
"published": "2023-11-03T06:36:29Z",
66
"aliases": [
77
"CVE-2023-41164"
@@ -118,10 +118,18 @@
118118
"type": "WEB",
119119
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HJFRPUHDYJHBH3KYHSPGULQM4JN7BMSU"
120120
},
121+
{
122+
"type": "WEB",
123+
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZQJOMNRMVPCN5WMIZ7YSX5LQ7IR2NY4D"
124+
},
121125
{
122126
"type": "WEB",
123127
"url": "https://lists.fedoraproject.org/archives/list/[email protected]/message/HJFRPUHDYJHBH3KYHSPGULQM4JN7BMSU"
124128
},
129+
{
130+
"type": "WEB",
131+
"url": "https://lists.fedoraproject.org/archives/list/[email protected]/message/ZQJOMNRMVPCN5WMIZ7YSX5LQ7IR2NY4D"
132+
},
125133
{
126134
"type": "WEB",
127135
"url": "https://security.netapp.com/advisory/ntap-20231214-0002"

advisories/github-reviewed/2023/11/GHSA-h8gc-pgj2-vjm3/GHSA-h8gc-pgj2-vjm3.json

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-h8gc-pgj2-vjm3",
4-
"modified": "2024-11-18T16:26:32Z",
4+
"modified": "2025-11-04T19:43:42Z",
55
"published": "2023-11-03T06:36:30Z",
66
"aliases": [
77
"CVE-2023-43665"
@@ -126,6 +126,10 @@
126126
"type": "WEB",
127127
"url": "https://lists.fedoraproject.org/archives/list/[email protected]/message/HJFRPUHDYJHBH3KYHSPGULQM4JN7BMSU"
128128
},
129+
{
130+
"type": "WEB",
131+
"url": "https://lists.fedoraproject.org/archives/list/[email protected]/message/ZQJOMNRMVPCN5WMIZ7YSX5LQ7IR2NY4D"
132+
},
129133
{
130134
"type": "WEB",
131135
"url": "https://security.netapp.com/advisory/ntap-20231221-0001"

advisories/github-reviewed/2024/02/GHSA-4g9r-vxhx-9pgx/GHSA-4g9r-vxhx-9pgx.json

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-4g9r-vxhx-9pgx",
4-
"modified": "2025-02-13T19:13:39Z",
4+
"modified": "2025-11-04T19:43:57Z",
55
"published": "2024-02-19T09:30:50Z",
66
"aliases": [
77
"CVE-2024-25710"
@@ -52,6 +52,10 @@
5252
"type": "WEB",
5353
"url": "https://security.netapp.com/advisory/ntap-20240307-0010"
5454
},
55+
{
56+
"type": "WEB",
57+
"url": "http://seclists.org/fulldisclosure/2024/Aug/37"
58+
},
5559
{
5660
"type": "WEB",
5761
"url": "http://www.openwall.com/lists/oss-security/2024/02/19/1"

advisories/github-reviewed/2024/02/GHSA-xxj9-f6rv-m3x4/GHSA-xxj9-f6rv-m3x4.json

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-xxj9-f6rv-m3x4",
4-
"modified": "2024-11-18T16:26:35Z",
4+
"modified": "2025-11-04T19:44:12Z",
55
"published": "2024-02-07T00:30:25Z",
66
"aliases": [
77
"CVE-2024-24680"
@@ -126,6 +126,10 @@
126126
"type": "WEB",
127127
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZQJOMNRMVPCN5WMIZ7YSX5LQ7IR2NY4D"
128128
},
129+
{
130+
"type": "WEB",
131+
"url": "https://lists.fedoraproject.org/archives/list/[email protected]/message/ZQJOMNRMVPCN5WMIZ7YSX5LQ7IR2NY4D"
132+
},
129133
{
130134
"type": "WEB",
131135
"url": "https://www.djangoproject.com/weblog/2024/feb/06/security-releases"

advisories/github-reviewed/2024/04/GHSA-9qxr-qj54-h672/GHSA-9qxr-qj54-h672.json

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,13 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-9qxr-qj54-h672",
4-
"modified": "2024-04-20T00:31:52Z",
4+
"modified": "2025-11-04T19:44:42Z",
55
"published": "2024-04-04T14:20:54Z",
66
"aliases": [
77
"CVE-2024-30261"
88
],
99
"summary": "Undici's fetch with integrity option is too lax when algorithm is specified but hash value is in incorrect",
10-
"details": "### Impact\n\nIf an attacker can alter the `integrity` option passed to `fetch()`, they can let `fetch()` accept requests as valid even if they have been tampered.\n\n### Patches\n\nFixed in https://github.com/nodejs/undici/commit/d542b8cd39ec1ba303f038ea26098c3f355974f3.\nFixes has been released in v5.28.4 and v6.11.1.\n\n\n### Workarounds\n\nEnsure that `integrity` cannot be tampered with.\n\n### References\n\nhttps://hackerone.com/reports/2377760\n",
10+
"details": "### Impact\n\nIf an attacker can alter the `integrity` option passed to `fetch()`, they can let `fetch()` accept requests as valid even if they have been tampered.\n\n### Patches\n\nFixed in https://github.com/nodejs/undici/commit/d542b8cd39ec1ba303f038ea26098c3f355974f3.\nFixes has been released in v5.28.4 and v6.11.1.\n\n\n### Workarounds\n\nEnsure that `integrity` cannot be tampered with.\n\n### References\n\nhttps://hackerone.com/reports/2377760",
1111
"severity": [
1212
{
1313
"type": "CVSS_V3",
@@ -90,6 +90,10 @@
9090
{
9191
"type": "WEB",
9292
"url": "https://lists.fedoraproject.org/archives/list/[email protected]/message/P6Q4RGETHVYVHDIQGTJGU5AV6NJEI67E"
93+
},
94+
{
95+
"type": "WEB",
96+
"url": "https://security.netapp.com/advisory/ntap-20240905-0008"
9397
}
9498
],
9599
"database_specific": {

advisories/github-reviewed/2024/04/GHSA-m4v8-wqvr-p9f7/GHSA-m4v8-wqvr-p9f7.json

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-m4v8-wqvr-p9f7",
4-
"modified": "2025-02-13T19:02:14Z",
4+
"modified": "2025-11-04T19:44:28Z",
55
"published": "2024-04-04T14:20:39Z",
66
"aliases": [
77
"CVE-2024-30260"
@@ -90,6 +90,10 @@
9090
{
9191
"type": "WEB",
9292
"url": "https://lists.fedoraproject.org/archives/list/[email protected]/message/P6Q4RGETHVYVHDIQGTJGU5AV6NJEI67E"
93+
},
94+
{
95+
"type": "WEB",
96+
"url": "https://security.netapp.com/advisory/ntap-20240905-0008"
9397
}
9498
],
9599
"database_specific": {
Lines changed: 68 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,68 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-8m2r-x2m2-3wmw",
4+
"modified": "2025-11-04T19:43:57Z",
5+
"published": "2025-01-28T15:31:57Z",
6+
"withdrawn": "2025-11-04T19:43:57Z",
7+
"aliases": [],
8+
"summary": "Duplicate Advisory: Pimcore Authenticated Stored Cross-Site Scripting (XSS) Via Search Document",
9+
"details": "Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-xr3m-6gq6-22cg. This link is maintained to preserve external references.\n\nOriginal Description\nA vulnerability classified as problematic was found in Pimcore 11.4.2. Affected by this vulnerability is an unknown functionality of the component Search Document. The manipulation leads to basic cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.",
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N"
14+
},
15+
{
16+
"type": "CVSS_V4",
17+
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
18+
}
19+
],
20+
"affected": [
21+
{
22+
"package": {
23+
"ecosystem": "Packagist",
24+
"name": "pimcore/pimcore"
25+
},
26+
"ranges": [
27+
{
28+
"type": "ECOSYSTEM",
29+
"events": [
30+
{
31+
"introduced": "11.4.2"
32+
}
33+
]
34+
}
35+
],
36+
"database_specific": {
37+
"last_known_affected_version_range": "< 11.5.3"
38+
}
39+
}
40+
],
41+
"references": [
42+
{
43+
"type": "WEB",
44+
"url": "https://github.com/pimcore/pimcore/security/advisories/GHSA-xr3m-6gq6-22cg"
45+
},
46+
{
47+
"type": "ADVISORY",
48+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11954"
49+
},
50+
{
51+
"type": "WEB",
52+
"url": "https://vuldb.com/?ctiid.293905"
53+
},
54+
{
55+
"type": "WEB",
56+
"url": "https://vuldb.com/?id.293905"
57+
}
58+
],
59+
"database_specific": {
60+
"cwe_ids": [
61+
"CWE-74"
62+
],
63+
"severity": "MODERATE",
64+
"github_reviewed": true,
65+
"github_reviewed_at": "2025-11-04T19:43:57Z",
66+
"nvd_published_at": "2025-01-28T14:15:29Z"
67+
}
68+
}

advisories/unreviewed/2025/01/GHSA-8m2r-x2m2-3wmw/GHSA-8m2r-x2m2-3wmw.json

Lines changed: 0 additions & 52 deletions
This file was deleted.

0 commit comments

Comments
 (0)