René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

108 lines
3.9 KiB
JSON

{
"id": "CVE-2022-31185",
"sourceIdentifier": "security-advisories@github.com",
"published": "2022-08-01T20:15:08.527",
"lastModified": "2022-08-09T18:41:06.327",
"vulnStatus": "Analyzed",
"descriptions": [
{
"lang": "en",
"value": "mprweb is a hosting platform for the makedeb Package Repository. Email addresses were found to not have been hidden, even if a user had clicked the `Hide Email Address` checkbox on their account page, or during signup. This could lead to an account's email being leaked, which may be problematic if your email needs to remain private for any reason. Users hosting their own mprweb instance will need to upgrade to the latest commit to get this fixed. Users on the official instance will already have this issue fixed."
},
{
"lang": "es",
"value": "mprweb es una plataforma de alojamiento para el repositorio de paquetes makedeb. Ha sido encontrado que las direcciones de correo electr\u00f3nico no han sido ocultado, incluso si un usuario ha hecho clic en la casilla \"Hide Email Address\" en su p\u00e1gina de cuenta, o durante el registro. Esto puede conllevar a que el correo electr\u00f3nico de una cuenta sea filtrado, lo que puede ser problem\u00e1tico si su correo electr\u00f3nico necesita permanecer privado por alguna raz\u00f3n. Los usuarios que alojen su propia instancia de mprweb tendr\u00e1n que actualizar a la \u00faltima confirmaci\u00f3n para que esto sea solucionado. Los usuarios de la instancia oficial ya presentan este problema solucionado"
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 5.3,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 3.9,
"impactScore": 1.4
},
{
"source": "security-advisories@github.com",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 5.3,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 3.9,
"impactScore": 1.4
}
]
},
"weaknesses": [
{
"source": "security-advisories@github.com",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:makedp:mprweb:*:*:*:*:*:*:*:*",
"versionEndIncluding": "5.0.0",
"matchCriteriaId": "E50F5AA7-7D45-46A4-86EF-C1328A8EED58"
}
]
}
]
}
],
"references": [
{
"url": "https://github.com/makedeb/mprweb/commit/d13e3f2f5a9c0b0f6782f35d837090732026ad77",
"source": "security-advisories@github.com",
"tags": [
"Patch",
"Third Party Advisory"
]
},
{
"url": "https://github.com/makedeb/mprweb/security/advisories/GHSA-jm39-h693-678g",
"source": "security-advisories@github.com",
"tags": [
"Third Party Advisory"
]
}
]
}