mirror of
https://github.com/CVEProject/cvelist.git
synced 2025-07-29 05:56:59 +00:00
408 lines
20 KiB
JSON
408 lines
20 KiB
JSON
{
|
|
"data_version": "4.0",
|
|
"data_type": "CVE",
|
|
"data_format": "MITRE",
|
|
"CVE_data_meta": {
|
|
"ID": "CVE-2024-6441",
|
|
"ASSIGNER": "cna@vuldb.com",
|
|
"STATE": "PUBLIC"
|
|
},
|
|
"description": {
|
|
"description_data": [
|
|
{
|
|
"lang": "eng",
|
|
"value": "A vulnerability was found in ORIPA up to 1.72. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file src/main/java/oripa/persistence/doc/loader/LoaderXML.java. The manipulation leads to deserialization. The attack can be launched remotely. Upgrading to version 1.80 is able to address this issue. It is recommended to upgrade the affected component. The identifier VDB-270169 was assigned to this vulnerability."
|
|
},
|
|
{
|
|
"lang": "deu",
|
|
"value": "In ORIPA bis 1.72 wurde eine kritische Schwachstelle ausgemacht. Hierbei betrifft es unbekannten Programmcode der Datei src/main/java/oripa/persistence/doc/loader/LoaderXML.java. Durch das Beeinflussen mit unbekannten Daten kann eine deserialization-Schwachstelle ausgenutzt werden. Umgesetzt werden kann der Angriff \u00fcber das Netzwerk. Ein Aktualisieren auf die Version 1.80 vermag dieses Problem zu l\u00f6sen. Als bestm\u00f6gliche Massnahme wird das Einspielen eines Upgrades empfohlen."
|
|
}
|
|
]
|
|
},
|
|
"problemtype": {
|
|
"problemtype_data": [
|
|
{
|
|
"description": [
|
|
{
|
|
"lang": "eng",
|
|
"value": "CWE-502 Deserialization",
|
|
"cweId": "CWE-502"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
"affects": {
|
|
"vendor": {
|
|
"vendor_data": [
|
|
{
|
|
"vendor_name": "n/a",
|
|
"product": {
|
|
"product_data": [
|
|
{
|
|
"product_name": "ORIPA",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.0"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.1"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.2"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.3"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.4"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.5"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.6"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.7"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.8"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.9"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.10"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.11"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.12"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.13"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.14"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.15"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.16"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.17"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.18"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.19"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.20"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.21"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.22"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.23"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.24"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.25"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.26"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.27"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.28"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.29"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.30"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.31"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.32"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.33"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.34"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.35"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.36"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.37"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.38"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.39"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.40"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.41"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.42"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.43"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.44"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.45"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.46"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.47"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.48"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.49"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.50"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.51"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.52"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.53"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.54"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.55"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.56"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.57"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.58"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.59"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.60"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.61"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.62"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.63"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.64"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.65"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.66"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.67"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.68"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.69"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.70"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.71"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "1.72"
|
|
}
|
|
]
|
|
}
|
|
}
|
|
]
|
|
}
|
|
}
|
|
]
|
|
}
|
|
},
|
|
"references": {
|
|
"reference_data": [
|
|
{
|
|
"url": "https://vuldb.com/?id.270169",
|
|
"refsource": "MISC",
|
|
"name": "https://vuldb.com/?id.270169"
|
|
},
|
|
{
|
|
"url": "https://vuldb.com/?ctiid.270169",
|
|
"refsource": "MISC",
|
|
"name": "https://vuldb.com/?ctiid.270169"
|
|
},
|
|
{
|
|
"url": "https://vuldb.com/?submit.367350",
|
|
"refsource": "MISC",
|
|
"name": "https://vuldb.com/?submit.367350"
|
|
},
|
|
{
|
|
"url": "https://github.com/oripa/oripa/issues/355",
|
|
"refsource": "MISC",
|
|
"name": "https://github.com/oripa/oripa/issues/355"
|
|
},
|
|
{
|
|
"url": "https://github.com/oripa/oripa/pull/356/commits/1abf8eb9b6b173d86d277426db1a551d6490c94a",
|
|
"refsource": "MISC",
|
|
"name": "https://github.com/oripa/oripa/pull/356/commits/1abf8eb9b6b173d86d277426db1a551d6490c94a"
|
|
},
|
|
{
|
|
"url": "https://github.com/oripa/oripa/milestone/15",
|
|
"refsource": "MISC",
|
|
"name": "https://github.com/oripa/oripa/milestone/15"
|
|
}
|
|
]
|
|
},
|
|
"credits": [
|
|
{
|
|
"lang": "en",
|
|
"value": "aftersnow (VulDB User)"
|
|
}
|
|
],
|
|
"impact": {
|
|
"cvss": [
|
|
{
|
|
"version": "3.1",
|
|
"baseScore": 6.3,
|
|
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
|
|
"baseSeverity": "MEDIUM"
|
|
},
|
|
{
|
|
"version": "3.0",
|
|
"baseScore": 6.3,
|
|
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
|
|
"baseSeverity": "MEDIUM"
|
|
},
|
|
{
|
|
"version": "2.0",
|
|
"baseScore": 6.5,
|
|
"vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P"
|
|
}
|
|
]
|
|
}
|
|
} |