File tree Expand file tree Collapse file tree
Expand file tree Collapse file tree Original file line number Diff line number Diff line change 1+ ---
2+ gem : sequenceserver
3+ cve : 2024-42360
4+ ghsa : qv32-5wm2-p32h
5+ url : https://github.com/wurmlab/sequenceserver/security/advisories/GHSA-qv32-5wm2-p32h
6+ title : Command Injection in sequenceserver gem
7+ date : 2024-08-13
8+ description : |
9+ ### Impact
10+
11+ Several HTTP endpoints did not properly sanitize user input
12+ and/or query parameters. This could be exploited to inject
13+ and run unwanted shell commands
14+
15+ ### Patches
16+
17+ Fixed in 3.1.2
18+
19+ ### Workarounds
20+
21+ No known workarounds
22+ cvss_v3 : 9.8
23+ patched_versions :
24+ - " >= 3.1.2"
25+ related :
26+ url :
27+ - https://github.com/wurmlab/sequenceserver/security/advisories/GHSA-qv32-5wm2-p32h
28+ - https://github.com/wurmlab/sequenceserver/commit/457e52709f7f9ed2fceed59b3db564cb50785dba
29+ - https://github.com/advisories/GHSA-qv32-5wm2-p32h
Original file line number Diff line number Diff line change 1+ ---
2+ gem : spina
3+ cve : 2024-7106
4+ ghsa : wqw3-p83g-r24v
5+ url : https://github.com/advisories/GHSA-wqw3-p83g-r24v
6+ title : Cross-Site Request Forgery in Spina
7+ date : 2024-07-25
8+ description : |
9+ A vulnerability classified as problematic was found in
10+ Spina CMS 2.18.0.
11+
12+ Affected by this vulnerability is an unknown functionality
13+ of the file /admin/media_folders.
14+
15+ The manipulation leads to cross-site request forgery.
16+ The attack can be launched remotely.
17+
18+ The exploit has been disclosed to the public and may be used.
19+
20+ The associated identifier of this vulnerability is VDB-272431.
21+
22+ NOTE: The vendor was contacted early about this disclosure
23+ but did not respond in any way.
24+ cvss_v2 : 5.0
25+ cvss_v3 : 4.3
26+ cvss_v4 : 6.9
27+ notes : Never patched
28+ related :
29+ url :
30+ - https://nvd.nist.gov/vuln/detail/CVE-2024-7106
31+ - https://github.com/topsky979/Security-Collections/blob/main/cve3/README.md
32+ - https://vuldb.com/?ctiid.272431
33+ - https://vuldb.com/?id.272431
34+ - https://vuldb.com/?submit.376769
35+ - https://github.com/advisories/GHSA-wqw3-p83g-r24v
You can’t perform that action at this time.
0 commit comments