File tree Expand file tree Collapse file tree 2 files changed +64
-0
lines changed Expand file tree Collapse file tree 2 files changed +64
-0
lines changed Original file line number Diff line number Diff line change
1
+ ---
2
+ gem : sequenceserver
3
+ cve : 2024-42360
4
+ ghsa : qv32-5wm2-p32h
5
+ url : https://github.com/wurmlab/sequenceserver/security/advisories/GHSA-qv32-5wm2-p32h
6
+ title : Command Injection in sequenceserver gem
7
+ date : 2024-08-13
8
+ description : |
9
+ ### Impact
10
+
11
+ Several HTTP endpoints did not properly sanitize user input
12
+ and/or query parameters. This could be exploited to inject
13
+ and run unwanted shell commands
14
+
15
+ ### Patches
16
+
17
+ Fixed in 3.1.2
18
+
19
+ ### Workarounds
20
+
21
+ No known workarounds
22
+ cvss_v3 : 9.8
23
+ patched_versions :
24
+ - " >= 3.1.2"
25
+ related :
26
+ url :
27
+ - https://github.com/wurmlab/sequenceserver/security/advisories/GHSA-qv32-5wm2-p32h
28
+ - https://github.com/wurmlab/sequenceserver/commit/457e52709f7f9ed2fceed59b3db564cb50785dba
29
+ - https://github.com/advisories/GHSA-qv32-5wm2-p32h
Original file line number Diff line number Diff line change
1
+ ---
2
+ gem : spina
3
+ cve : 2024-7106
4
+ ghsa : wqw3-p83g-r24v
5
+ url : https://github.com/advisories/GHSA-wqw3-p83g-r24v
6
+ title : Cross-Site Request Forgery in Spina
7
+ date : 2024-07-25
8
+ description : |
9
+ A vulnerability classified as problematic was found in
10
+ Spina CMS 2.18.0.
11
+
12
+ Affected by this vulnerability is an unknown functionality
13
+ of the file /admin/media_folders.
14
+
15
+ The manipulation leads to cross-site request forgery.
16
+ The attack can be launched remotely.
17
+
18
+ The exploit has been disclosed to the public and may be used.
19
+
20
+ The associated identifier of this vulnerability is VDB-272431.
21
+
22
+ NOTE: The vendor was contacted early about this disclosure
23
+ but did not respond in any way.
24
+ cvss_v2 : 5.0
25
+ cvss_v3 : 4.3
26
+ cvss_v4 : 6.9
27
+ notes : Never patched
28
+ related :
29
+ url :
30
+ - https://nvd.nist.gov/vuln/detail/CVE-2024-7106
31
+ - https://github.com/topsky979/Security-Collections/blob/main/cve3/README.md
32
+ - https://vuldb.com/?ctiid.272431
33
+ - https://vuldb.com/?id.272431
34
+ - https://vuldb.com/?submit.376769
35
+ - https://github.com/advisories/GHSA-wqw3-p83g-r24v
You can’t perform that action at this time.
0 commit comments