"-Synchronized-Data."

This commit is contained in:
CVE Team 2023-05-07 02:00:33 +00:00
parent 48443e1797
commit 48851a61d9
No known key found for this signature in database
GPG Key ID: E3252B3D49582C98
2 changed files with 132 additions and 6 deletions

View File

@ -1,17 +1,71 @@
{
"data_type": "CVE",
"data_format": "MITRE",
"data_version": "4.0",
"CVE_data_meta": {
"ID": "CVE-2023-31047",
"ASSIGNER": "cve@mitre.org",
"STATE": "RESERVED"
"ID": "CVE-2023-31047",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "n/a",
"version": {
"version_data": [
{
"version_value": "n/a"
}
]
}
}
]
},
"vendor_name": "n/a"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided."
"value": "In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one form field to upload multiple files. This multiple upload has never been supported by forms.FileField or forms.ImageField (only the last uploaded file was validated). However, Django's \"Uploading multiple files\" documentation suggested otherwise."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "n/a"
}
]
}
]
},
"references": {
"reference_data": [
{
"url": "https://groups.google.com/forum/#!forum/django-announce",
"refsource": "MISC",
"name": "https://groups.google.com/forum/#!forum/django-announce"
},
{
"url": "https://docs.djangoproject.com/en/4.2/releases/security/",
"refsource": "MISC",
"name": "https://docs.djangoproject.com/en/4.2/releases/security/"
},
{
"refsource": "CONFIRM",
"name": "https://www.djangoproject.com/weblog/2023/may/03/security-releases/",
"url": "https://www.djangoproject.com/weblog/2023/may/03/security-releases/"
}
]
}

View File

@ -0,0 +1,72 @@
{
"CVE_data_meta": {
"ASSIGNER": "cve@mitre.org",
"ID": "CVE-2023-32290",
"STATE": "PUBLIC"
},
"affects": {
"vendor": {
"vendor_data": [
{
"product": {
"product_data": [
{
"product_name": "n/a",
"version": {
"version_data": [
{
"version_value": "n/a"
}
]
}
}
]
},
"vendor_name": "n/a"
}
]
}
},
"data_format": "MITRE",
"data_type": "CVE",
"data_version": "4.0",
"description": {
"description_data": [
{
"lang": "eng",
"value": "The myMail app through 14.30 for iOS sends cleartext credentials in a situation where STARTTLS is expected by a server."
}
]
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "n/a"
}
]
}
]
},
"references": {
"reference_data": [
{
"url": "https://news.ycombinator.com/item?id=35845308",
"refsource": "MISC",
"name": "https://news.ycombinator.com/item?id=35845308"
},
{
"url": "https://apps.apple.com/fm/app/mymail-email-app-for-gmail/id722120997",
"refsource": "MISC",
"name": "https://apps.apple.com/fm/app/mymail-email-app-for-gmail/id722120997"
},
{
"url": "https://mailbox.org/en/post/mailbox-org-discovers-unencrypted-password-transmission-in-mymail",
"refsource": "MISC",
"name": "https://mailbox.org/en/post/mailbox-org-discovers-unencrypted-password-transmission-in-mymail"
}
]
}
}