vuln-list-alt/oval/p9/ALT-PU-2022-1526/definitions.json
2024-04-16 14:26:14 +00:00

161 lines
6.4 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20221526",
"Version": "oval:org.altlinux.errata:def:20221526",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2022-1526: package `glpi` update to version 9.5.7-alt1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch p9"
],
"Products": [
"ALT Server",
"ALT Virtualization Server",
"ALT Workstation",
"ALT Workstation K",
"ALT Education",
"Simply Linux",
"Starterkit"
]
}
],
"References": [
{
"RefID": "ALT-PU-2022-1526",
"RefURL": "https://errata.altlinux.org/ALT-PU-2022-1526",
"Source": "ALTPU"
},
{
"RefID": "BDU:2022-00590",
"RefURL": "https://bdu.fstec.ru/vul/2022-00590",
"Source": "BDU"
},
{
"RefID": "BDU:2022-00591",
"RefURL": "https://bdu.fstec.ru/vul/2022-00591",
"Source": "BDU"
},
{
"RefID": "CVE-2022-21719",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2022-21719",
"Source": "CVE"
},
{
"RefID": "CVE-2022-21720",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2022-21720",
"Source": "CVE"
}
],
"Description": "This update upgrades glpi to version 9.5.7-alt1. \nSecurity Fix(es):\n\n * BDU:2022-00590: Уязвимость системы работы с заявками и инцидентами GLPI, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю осуществлять межсайтовые сценарные атаки\n\n * BDU:2022-00591: Уязвимость системы работы с заявками и инцидентами GLPI, связанная с непринятием мер по защите структуры запроса SQL, позволяющая нарушителю выполнять произвольный SQL-запрос\n\n * CVE-2022-21719: GLPI is a free asset and IT management software package. All GLPI versions prior to 9.5.7 are vulnerable to reflected cross-site scripting. Version 9.5.7 contains a patch for this issue. There are no known workarounds.\n\n * CVE-2022-21720: GLPI is a free asset and IT management software package. Prior to version 9.5.7, an entity administrator is capable of retrieving normally inaccessible data via SQL injection. Version 9.5.7 contains a patch for this issue. As a workaround, disabling the `Entities` update right prevents exploitation of this vulnerability.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "Critical",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2022-03-21"
},
"Updated": {
"Date": "2022-03-21"
},
"BDUs": [
{
"ID": "BDU:2022-00590",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:P/A:N",
"CVSS3": "AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"CWE": "CWE-79",
"Href": "https://bdu.fstec.ru/vul/2022-00590",
"Impact": "Low",
"Public": "20220127"
},
{
"ID": "BDU:2022-00591",
"CVSS": "AV:N/AC:L/Au:N/C:C/I:C/A:N",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
"CWE": "CWE-89",
"Href": "https://bdu.fstec.ru/vul/2022-00591",
"Impact": "Critical",
"Public": "20220127"
}
],
"CVEs": [
{
"ID": "CVE-2022-21719",
"CVSS": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"CWE": "CWE-79",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2022-21719",
"Impact": "Low",
"Public": "20220128"
},
{
"ID": "CVE-2022-21720",
"CVSS": "AV:N/AC:L/Au:S/C:P/I:N/A:N",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N",
"CWE": "CWE-89",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2022-21720",
"Impact": "Low",
"Public": "20220128"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:kworkstation:9",
"cpe:/o:alt:workstation:9",
"cpe:/o:alt:server:9",
"cpe:/o:alt:server-v:9",
"cpe:/o:alt:education:9",
"cpe:/o:alt:slinux:9",
"cpe:/o:alt:starterkit:p9",
"cpe:/o:alt:kworkstation:9.1",
"cpe:/o:alt:workstation:9.1",
"cpe:/o:alt:server:9.1",
"cpe:/o:alt:server-v:9.1",
"cpe:/o:alt:education:9.1",
"cpe:/o:alt:slinux:9.1",
"cpe:/o:alt:starterkit:9.1",
"cpe:/o:alt:kworkstation:9.2",
"cpe:/o:alt:workstation:9.2",
"cpe:/o:alt:server:9.2",
"cpe:/o:alt:server-v:9.2",
"cpe:/o:alt:education:9.2",
"cpe:/o:alt:slinux:9.2",
"cpe:/o:alt:starterkit:9.2"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:1001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20221526001",
"Comment": "glpi is earlier than 0:9.5.7-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20221526002",
"Comment": "glpi-apache2 is earlier than 0:9.5.7-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20221526003",
"Comment": "glpi-php7 is earlier than 0:9.5.7-alt1"
}
]
}
]
}
}
]
}