From 509ea4ff9e82834518da32615affa005bf11ff9f Mon Sep 17 00:00:00 2001 From: Kurt Seifried Date: Fri, 29 Dec 2017 13:51:32 -0700 Subject: [PATCH 1/3] Added CVE-2017-1000468 --- 2017/1000xxx/CVE-2017-1000468.json | 1 + 1 file changed, 1 insertion(+) create mode 100644 2017/1000xxx/CVE-2017-1000468.json diff --git a/2017/1000xxx/CVE-2017-1000468.json b/2017/1000xxx/CVE-2017-1000468.json new file mode 100644 index 00000000000..3b1000ebcd4 --- /dev/null +++ b/2017/1000xxx/CVE-2017-1000468.json @@ -0,0 +1 @@ +{"data_version": "4.0","references": {"reference_data": [{"url": "https://github.com/forkcms/forkcms/issues/2341"}]},"description": {"description_data": [{"lang": "eng","value": "Forkcms version 5.0.6 is vulnerable to stored cross-site scripting vulnerability, within the create new page section, which can result in disruption of service and execution of javascript code. "}]},"data_type": "CVE","affects": {"vendor": {"vendor_data": [{"product": {"product_data": [{"version": {"version_data": [{"version_value": "<= Forkcms v5.0.6"}]},"product_name": "forkcms"}]},"vendor_name": "forkcms"}]}},"CVE_data_meta": {"DATE_ASSIGNED": "2017-12-29","ID": "CVE-2017-1000468","ASSIGNER": "kurt@seifried.org","REQUESTER": "sajeeb.lohani@bulletproof.sh"},"data_format": "MITRE","problemtype": {"problemtype_data": [{"description": [{"lang": "eng","value": "CWE-79"}]}]}} \ No newline at end of file From c5e70df156ea7245cef978ac3fce35adaf77bbbd Mon Sep 17 00:00:00 2001 From: Kurt Seifried Date: Mon, 22 Jan 2018 13:55:25 -0700 Subject: [PATCH 2/3] updated CVE-2017-1000468 --- 2017/1000xxx/CVE-2017-1000468.json | 21 ++++++++++++++++++++- 1 file changed, 20 insertions(+), 1 deletion(-) diff --git a/2017/1000xxx/CVE-2017-1000468.json b/2017/1000xxx/CVE-2017-1000468.json index 3b1000ebcd4..25d8ffdfe1e 100644 --- a/2017/1000xxx/CVE-2017-1000468.json +++ b/2017/1000xxx/CVE-2017-1000468.json @@ -1 +1,20 @@ -{"data_version": "4.0","references": {"reference_data": [{"url": "https://github.com/forkcms/forkcms/issues/2341"}]},"description": {"description_data": [{"lang": "eng","value": "Forkcms version 5.0.6 is vulnerable to stored cross-site scripting vulnerability, within the create new page section, which can result in disruption of service and execution of javascript code. "}]},"data_type": "CVE","affects": {"vendor": {"vendor_data": [{"product": {"product_data": [{"version": {"version_data": [{"version_value": "<= Forkcms v5.0.6"}]},"product_name": "forkcms"}]},"vendor_name": "forkcms"}]}},"CVE_data_meta": {"DATE_ASSIGNED": "2017-12-29","ID": "CVE-2017-1000468","ASSIGNER": "kurt@seifried.org","REQUESTER": "sajeeb.lohani@bulletproof.sh"},"data_format": "MITRE","problemtype": {"problemtype_data": [{"description": [{"lang": "eng","value": "CWE-79"}]}]}} \ No newline at end of file +{ + "data_version": "4.0", + "description": { + "description_data": [ + { + "lang": "eng", + "value": "** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA due to lack of a reference providing provenance. Notes: none." + } + ] + }, + "data_type": "CVE", + "CVE_data_meta": { + "DATE_ASSIGNED": "2017-12-29", + "ID": "CVE-2017-1000468", + "ASSIGNER": "kurt@seifried.org", + "REQUESTER": "sajeeb.lohani@bulletproof.sh", + "STATE": "REJECT" + }, + "data_format": "MITRE" +} From 5c363bfdc92e953fc2eed1071e162fdf25ee7eab Mon Sep 17 00:00:00 2001 From: Kurt Seifried Date: Wed, 24 Jan 2018 19:43:57 -0700 Subject: [PATCH 3/3] updated reason for reject --- 2017/1000xxx/CVE-2017-1000468.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/2017/1000xxx/CVE-2017-1000468.json b/2017/1000xxx/CVE-2017-1000468.json index 25d8ffdfe1e..6e793a6b07b 100644 --- a/2017/1000xxx/CVE-2017-1000468.json +++ b/2017/1000xxx/CVE-2017-1000468.json @@ -4,7 +4,7 @@ "description_data": [ { "lang": "eng", - "value": "** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA due to lack of a reference providing provenance. Notes: none." + "value": "** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA due to further investigation which showed that it was not a security issue. Notes: none." } ] },