2024-12-08 03:06:42 +00:00

64 lines
2.4 KiB
JSON

{
"id": "CVE-2024-41811",
"sourceIdentifier": "security-advisories@github.com",
"published": "2024-08-05T21:15:38.673",
"lastModified": "2024-08-06T16:30:24.547",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "ipl/web is a set of common web components for php projects. Some of the recent development by Icinga is, under certain circumstances, susceptible to cross site request forgery. (CSRF). All affected products, in any version, will be unaffected by this once `icinga-php-library` is upgraded. Version 0.10.1 includes a fix for this. It will be published as part of the `icinga-php-library` v0.14.1 release."
},
{
"lang": "es",
"value": "ipl/web es un conjunto de componentes web comunes para proyectos php. Algunos de los desarrollos recientes de Icinga son, bajo ciertas circunstancias, susceptibles a cross site request forgery. (CSRF). Todos los productos afectados, en cualquier versi\u00f3n, no se ver\u00e1n afectados por esto una vez que se actualice `icinga-php-library`. La versi\u00f3n 0.10.1 incluye una soluci\u00f3n para esto. Se publicar\u00e1 como parte de la versi\u00f3n `icinga-php-library` v0.14.1."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "security-advisories@github.com",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:L",
"baseScore": 3.9,
"baseSeverity": "LOW",
"attackVector": "NETWORK",
"attackComplexity": "HIGH",
"privilegesRequired": "HIGH",
"userInteraction": "REQUIRED",
"scope": "UNCHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"availabilityImpact": "LOW"
},
"exploitabilityScore": 0.5,
"impactScore": 3.4
}
]
},
"weaknesses": [
{
"source": "security-advisories@github.com",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-352"
}
]
}
],
"references": [
{
"url": "https://github.com/Icinga/ipl-web/commit/492336fdb57a5bb0881ed642ab36f5841337571e",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/Icinga/ipl-web/security/advisories/GHSA-w9pg-7c3h-fc8j",
"source": "security-advisories@github.com"
}
]
}