René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

143 lines
5.2 KiB
JSON

{
"id": "CVE-2022-29230",
"sourceIdentifier": "security-advisories@github.com",
"published": "2022-05-18T21:15:07.823",
"lastModified": "2022-06-01T19:55:39.590",
"vulnStatus": "Analyzed",
"descriptions": [
{
"lang": "en",
"value": "Hydrogen is a React-based framework for building dynamic, Shopify-powered custom storefronts. There is a potential Cross-Site Scripting (XSS) vulnerability where an arbitrary user is able to execute scripts on pages that are built with Hydrogen. This affects all versions of Hydrogen starting from version 0.10.0 to 0.18.0. This vulnerability is exploitable in applications whose hydrating data is user controlled. All Hydrogen users should upgrade their project to version 0.19.0. There is no current workaround, and users should update as soon as possible. Additionally, the Content Security Policy is not an effective mitigation for this vulnerability."
},
{
"lang": "es",
"value": "Hydrogen es un marco de trabajo basado en React para la construcci\u00f3n de escaparates personalizados din\u00e1micos impulsados por Shopify. Se presenta una potencial vulnerabilidad de tipo Cross-Site Scripting (XSS) donde un usuario arbitrario es capaz de ejecutar scripts en p\u00e1ginas que son construidas con Hydrogen. Esto afecta a todas las versiones de Hydrogen desde versi\u00f3n 0.10.0 hasta 0.18.0. Esta vulnerabilidad es explotable en aplicaciones cuyos datos de hidrataci\u00f3n son controlados por el usuario. Todos los usuarios de Hydrogen deber\u00edan actualizar sus proyectos a versi\u00f3n 0.19.0. No se presenta una medida de mitigaci\u00f3n actual, y los usuarios deber\u00edan actualizar lo antes posible. Adem\u00e1s, la Pol\u00edtica de Seguridad de Contenidos no es una mitigaci\u00f3n efectiva para esta vulnerabilidad"
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "REQUIRED",
"scope": "CHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"availabilityImpact": "NONE",
"baseScore": 5.4,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 2.3,
"impactScore": 2.7
},
{
"source": "security-advisories@github.com",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"availabilityImpact": "LOW",
"baseScore": 6.3,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 2.8,
"impactScore": 3.4
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:S/C:N/I:P/A:N",
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "SINGLE",
"confidentialityImpact": "NONE",
"integrityImpact": "PARTIAL",
"availabilityImpact": "NONE",
"baseScore": 3.5
},
"baseSeverity": "LOW",
"exploitabilityScore": 6.8,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"weaknesses": [
{
"source": "security-advisories@github.com",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:shopify:hydrogen:*:*:*:*:*:node.js:*:*",
"versionStartIncluding": "0.10.0",
"versionEndExcluding": "0.19.0",
"matchCriteriaId": "17B85941-2E8A-464A-B36A-D690068208CA"
}
]
}
]
}
],
"references": [
{
"url": "https://github.com/Shopify/hydrogen/pull/1272",
"source": "security-advisories@github.com",
"tags": [
"Issue Tracking",
"Patch",
"Third Party Advisory"
]
},
{
"url": "https://github.com/Shopify/hydrogen/releases/tag/%40shopify/hydrogen%400.19.0",
"source": "security-advisories@github.com",
"tags": [
"Patch",
"Third Party Advisory"
]
},
{
"url": "https://github.com/Shopify/hydrogen/security/advisories/GHSA-6j22-wv8g-894f",
"source": "security-advisories@github.com",
"tags": [
"Third Party Advisory"
]
}
]
}