Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

dotnetnuke.core.9.2.1.533.nupkg: 10 vulnerabilities (highest severity is: 7.5) #12

Open
mend-bolt-for-github bot opened this issue Jul 6, 2023 · 0 comments
Labels
Mend: dependency security vulnerability Security vulnerability detected by Mend

Comments

@mend-bolt-for-github
Copy link
Contributor

mend-bolt-for-github bot commented Jul 6, 2023

Vulnerable Library - dotnetnuke.core.9.2.1.533.nupkg

DNN Platform is an open source web application framework. This package contains only the core DNN Platform library.

Library home page: https://api.nuget.org/packages/dotnetnuke.core.9.2.1.533.nupkg

Path to dependency file: /Modules/YafToDnnForumMigration/Upendo.Modules.YafToDnnForumMigration.csproj

Path to vulnerable library: /tmp/ws-ua_20230706232019_ZCFCNG/dotnet_JECQUB/20230706232019/DotNetNuke.Core.9.2.1.533/DotNetNuke.Core.9.2.1.533.nupkg

Found in HEAD commit: 474c0373c1c9d816e68d571122d2f262c41a0773

Vulnerabilities

CVE Severity CVSS Dependency Type Fixed in (dotnetnuke.core.9.2.1.533.nupkg version) Remediation Available
CVE-2018-15812 High 7.5 dotnetnuke.core.9.2.1.533.nupkg Direct 9.2.2
CVE-2021-40186 High 7.5 dotnetnuke.core.9.2.1.533.nupkg Direct DotNetNuke.Web - 9.11.0;DotNetNuke.Core - 9.11.0
CVE-2018-15811 High 7.5 dotnetnuke.core.9.2.1.533.nupkg Direct 9.3.0
CVE-2018-18326 High 7.5 dotnetnuke.core.9.2.1.533.nupkg Direct 9.3.0
CVE-2018-18325 High 7.5 dotnetnuke.core.9.2.1.533.nupkg Direct 9.3.0
CVE-2020-5188 Medium 6.5 dotnetnuke.core.9.2.1.533.nupkg Direct N/A
CVE-2019-12562 Medium 6.1 dotnetnuke.core.9.2.1.533.nupkg Direct 9.4.0
CVE-2021-31858 Medium 5.4 dotnetnuke.core.9.2.1.533.nupkg Direct DotNetNuke.Core - 9.11.0
CVE-2020-5186 Medium 5.4 dotnetnuke.core.9.2.1.533.nupkg Direct N/A
CVE-2022-2922 Medium 4.9 dotnetnuke.core.9.2.1.533.nupkg Direct DotNetNuke.Core - 9.11.0, DotNetNuke.Web - 9.11.0

Details

CVE-2018-15812

Vulnerable Library - dotnetnuke.core.9.2.1.533.nupkg

DNN Platform is an open source web application framework. This package contains only the core DNN Platform library.

Library home page: https://api.nuget.org/packages/dotnetnuke.core.9.2.1.533.nupkg

Path to dependency file: /Modules/YafToDnnForumMigration/Upendo.Modules.YafToDnnForumMigration.csproj

Path to vulnerable library: /tmp/ws-ua_20230706232019_ZCFCNG/dotnet_JECQUB/20230706232019/DotNetNuke.Core.9.2.1.533/DotNetNuke.Core.9.2.1.533.nupkg

Dependency Hierarchy:

  • dotnetnuke.core.9.2.1.533.nupkg (Vulnerable Library)

Found in HEAD commit: 474c0373c1c9d816e68d571122d2f262c41a0773

Found in base branch: dev

Vulnerability Details

DNN (aka DotNetNuke) 9.2 through 9.2.1 incorrectly converts encryption key source values, resulting in lower than expected entropy.

Publish Date: 2019-07-03

URL: CVE-2018-15812

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: None
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://www.dnnsoftware.com/community/security/security-center

Release Date: 2019-07-03

Fix Resolution: 9.2.2

Step up your Open Source Security Game with Mend here

CVE-2021-40186

Vulnerable Library - dotnetnuke.core.9.2.1.533.nupkg

DNN Platform is an open source web application framework. This package contains only the core DNN Platform library.

Library home page: https://api.nuget.org/packages/dotnetnuke.core.9.2.1.533.nupkg

Path to dependency file: /Modules/YafToDnnForumMigration/Upendo.Modules.YafToDnnForumMigration.csproj

Path to vulnerable library: /tmp/ws-ua_20230706232019_ZCFCNG/dotnet_JECQUB/20230706232019/DotNetNuke.Core.9.2.1.533/DotNetNuke.Core.9.2.1.533.nupkg

Dependency Hierarchy:

  • dotnetnuke.core.9.2.1.533.nupkg (Vulnerable Library)

Found in HEAD commit: 474c0373c1c9d816e68d571122d2f262c41a0773

Found in base branch: dev

Vulnerability Details

The AppCheck research team identified a Server-Side Request Forgery (SSRF) vulnerability within the DNN CMS platform, formerly known as DotNetNuke. SSRF vulnerabilities allow the attacker to exploit the target system to make network requests on their behalf, allowing a range of possible attacks. In the most common scenario, the attacker exploits SSRF vulnerabilities to attack systems behind the firewall and access sensitive information from Cloud Provider metadata services.

Publish Date: 2022-06-02

URL: CVE-2021-40186

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: None
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://nvd.nist.gov/vuln/detail/CVE-2021-40186

Release Date: 2022-06-02

Fix Resolution: DotNetNuke.Web - 9.11.0;DotNetNuke.Core - 9.11.0

Step up your Open Source Security Game with Mend here

CVE-2018-15811

Vulnerable Library - dotnetnuke.core.9.2.1.533.nupkg

DNN Platform is an open source web application framework. This package contains only the core DNN Platform library.

Library home page: https://api.nuget.org/packages/dotnetnuke.core.9.2.1.533.nupkg

Path to dependency file: /Modules/YafToDnnForumMigration/Upendo.Modules.YafToDnnForumMigration.csproj

Path to vulnerable library: /tmp/ws-ua_20230706232019_ZCFCNG/dotnet_JECQUB/20230706232019/DotNetNuke.Core.9.2.1.533/DotNetNuke.Core.9.2.1.533.nupkg

Dependency Hierarchy:

  • dotnetnuke.core.9.2.1.533.nupkg (Vulnerable Library)

Found in HEAD commit: 474c0373c1c9d816e68d571122d2f262c41a0773

Found in base branch: dev

Vulnerability Details

DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters.

Publish Date: 2019-07-03

URL: CVE-2018-15811

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: None
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2019-07-03

Fix Resolution: 9.3.0

Step up your Open Source Security Game with Mend here

CVE-2018-18326

Vulnerable Library - dotnetnuke.core.9.2.1.533.nupkg

DNN Platform is an open source web application framework. This package contains only the core DNN Platform library.

Library home page: https://api.nuget.org/packages/dotnetnuke.core.9.2.1.533.nupkg

Path to dependency file: /Modules/YafToDnnForumMigration/Upendo.Modules.YafToDnnForumMigration.csproj

Path to vulnerable library: /tmp/ws-ua_20230706232019_ZCFCNG/dotnet_JECQUB/20230706232019/DotNetNuke.Core.9.2.1.533/DotNetNuke.Core.9.2.1.533.nupkg

Dependency Hierarchy:

  • dotnetnuke.core.9.2.1.533.nupkg (Vulnerable Library)

Found in HEAD commit: 474c0373c1c9d816e68d571122d2f262c41a0773

Found in base branch: dev

Vulnerability Details

DNN (aka DotNetNuke) 9.2 through 9.2.2 incorrectly converts encryption key source values, resulting in lower than expected entropy. NOTE: this issue exists because of an incomplete fix for CVE-2018-15812.

Publish Date: 2019-07-03

URL: CVE-2018-18326

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: None
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://www.dnnsoftware.com/community/security/security-center

Release Date: 2019-07-03

Fix Resolution: 9.3.0

Step up your Open Source Security Game with Mend here

CVE-2018-18325

Vulnerable Library - dotnetnuke.core.9.2.1.533.nupkg

DNN Platform is an open source web application framework. This package contains only the core DNN Platform library.

Library home page: https://api.nuget.org/packages/dotnetnuke.core.9.2.1.533.nupkg

Path to dependency file: /Modules/YafToDnnForumMigration/Upendo.Modules.YafToDnnForumMigration.csproj

Path to vulnerable library: /tmp/ws-ua_20230706232019_ZCFCNG/dotnet_JECQUB/20230706232019/DotNetNuke.Core.9.2.1.533/DotNetNuke.Core.9.2.1.533.nupkg

Dependency Hierarchy:

  • dotnetnuke.core.9.2.1.533.nupkg (Vulnerable Library)

Found in HEAD commit: 474c0373c1c9d816e68d571122d2f262c41a0773

Found in base branch: dev

Vulnerability Details

DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters. NOTE: this issue exists because of an incomplete fix for CVE-2018-15811.

Publish Date: 2019-07-03

URL: CVE-2018-18325

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: None
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://pentest-tools.com/blog/exploit-dotnetnuke-cookie-deserialization/

Release Date: 2019-07-03

Fix Resolution: 9.3.0

Step up your Open Source Security Game with Mend here

CVE-2020-5188

Vulnerable Library - dotnetnuke.core.9.2.1.533.nupkg

DNN Platform is an open source web application framework. This package contains only the core DNN Platform library.

Library home page: https://api.nuget.org/packages/dotnetnuke.core.9.2.1.533.nupkg

Path to dependency file: /Modules/YafToDnnForumMigration/Upendo.Modules.YafToDnnForumMigration.csproj

Path to vulnerable library: /tmp/ws-ua_20230706232019_ZCFCNG/dotnet_JECQUB/20230706232019/DotNetNuke.Core.9.2.1.533/DotNetNuke.Core.9.2.1.533.nupkg

Dependency Hierarchy:

  • dotnetnuke.core.9.2.1.533.nupkg (Vulnerable Library)

Found in HEAD commit: 474c0373c1c9d816e68d571122d2f262c41a0773

Found in base branch: dev

Vulnerability Details

DNN (formerly DotNetNuke) through 9.4.4 has Insecure Permissions.

Publish Date: 2020-02-24

URL: CVE-2020-5188

CVSS 3 Score Details (6.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: Low
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: High
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Step up your Open Source Security Game with Mend here

CVE-2019-12562

Vulnerable Library - dotnetnuke.core.9.2.1.533.nupkg

DNN Platform is an open source web application framework. This package contains only the core DNN Platform library.

Library home page: https://api.nuget.org/packages/dotnetnuke.core.9.2.1.533.nupkg

Path to dependency file: /Modules/YafToDnnForumMigration/Upendo.Modules.YafToDnnForumMigration.csproj

Path to vulnerable library: /tmp/ws-ua_20230706232019_ZCFCNG/dotnet_JECQUB/20230706232019/DotNetNuke.Core.9.2.1.533/DotNetNuke.Core.9.2.1.533.nupkg

Dependency Hierarchy:

  • dotnetnuke.core.9.2.1.533.nupkg (Vulnerable Library)

Found in HEAD commit: 474c0373c1c9d816e68d571122d2f262c41a0773

Found in base branch: dev

Vulnerability Details

Stored Cross-Site Scripting in DotNetNuke (DNN) Version before 9.4.0 allows remote attackers to store and embed the malicious script into the admin notification page. The exploit could be used to perfom any action with admin privileges such as managing content, adding users, uploading backdoors to the server, etc. Successful exploitation occurs when an admin user visits a notification page with stored cross-site scripting.

Publish Date: 2019-09-26

URL: CVE-2019-12562

CVSS 3 Score Details (6.1)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: Required
    • Scope: Changed
  • Impact Metrics:
    • Confidentiality Impact: Low
    • Integrity Impact: Low
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12562

Release Date: 2019-09-26

Fix Resolution: 9.4.0

Step up your Open Source Security Game with Mend here

CVE-2021-31858

Vulnerable Library - dotnetnuke.core.9.2.1.533.nupkg

DNN Platform is an open source web application framework. This package contains only the core DNN Platform library.

Library home page: https://api.nuget.org/packages/dotnetnuke.core.9.2.1.533.nupkg

Path to dependency file: /Modules/YafToDnnForumMigration/Upendo.Modules.YafToDnnForumMigration.csproj

Path to vulnerable library: /tmp/ws-ua_20230706232019_ZCFCNG/dotnet_JECQUB/20230706232019/DotNetNuke.Core.9.2.1.533/DotNetNuke.Core.9.2.1.533.nupkg

Dependency Hierarchy:

  • dotnetnuke.core.9.2.1.533.nupkg (Vulnerable Library)

Found in HEAD commit: 474c0373c1c9d816e68d571122d2f262c41a0773

Found in base branch: dev

Vulnerability Details

DotNetNuke (DNN) 9.9.1 CMS is vulnerable to a Stored Cross-Site Scripting vulnerability in the user profile biography section which allows remote authenticated users to inject arbitrary code via a crafted payload.

Publish Date: 2022-07-20

URL: CVE-2021-31858

CVSS 3 Score Details (5.4)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: Low
    • User Interaction: Required
    • Scope: Changed
  • Impact Metrics:
    • Confidentiality Impact: Low
    • Integrity Impact: Low
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://nvd.nist.gov/vuln/detail/CVE-2021-31858

Release Date: 2022-07-20

Fix Resolution: DotNetNuke.Core - 9.11.0

Step up your Open Source Security Game with Mend here

CVE-2020-5186

Vulnerable Library - dotnetnuke.core.9.2.1.533.nupkg

DNN Platform is an open source web application framework. This package contains only the core DNN Platform library.

Library home page: https://api.nuget.org/packages/dotnetnuke.core.9.2.1.533.nupkg

Path to dependency file: /Modules/YafToDnnForumMigration/Upendo.Modules.YafToDnnForumMigration.csproj

Path to vulnerable library: /tmp/ws-ua_20230706232019_ZCFCNG/dotnet_JECQUB/20230706232019/DotNetNuke.Core.9.2.1.533/DotNetNuke.Core.9.2.1.533.nupkg

Dependency Hierarchy:

  • dotnetnuke.core.9.2.1.533.nupkg (Vulnerable Library)

Found in HEAD commit: 474c0373c1c9d816e68d571122d2f262c41a0773

Found in base branch: dev

Vulnerability Details

DNN (formerly DotNetNuke) through 9.4.4 allows XSS (issue 1 of 2).

Publish Date: 2020-02-24

URL: CVE-2020-5186

CVSS 3 Score Details (5.4)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: Low
    • User Interaction: Required
    • Scope: Changed
  • Impact Metrics:
    • Confidentiality Impact: Low
    • Integrity Impact: Low
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Step up your Open Source Security Game with Mend here

CVE-2022-2922

Vulnerable Library - dotnetnuke.core.9.2.1.533.nupkg

DNN Platform is an open source web application framework. This package contains only the core DNN Platform library.

Library home page: https://api.nuget.org/packages/dotnetnuke.core.9.2.1.533.nupkg

Path to dependency file: /Modules/YafToDnnForumMigration/Upendo.Modules.YafToDnnForumMigration.csproj

Path to vulnerable library: /tmp/ws-ua_20230706232019_ZCFCNG/dotnet_JECQUB/20230706232019/DotNetNuke.Core.9.2.1.533/DotNetNuke.Core.9.2.1.533.nupkg

Dependency Hierarchy:

  • dotnetnuke.core.9.2.1.533.nupkg (Vulnerable Library)

Found in HEAD commit: 474c0373c1c9d816e68d571122d2f262c41a0773

Found in base branch: dev

Vulnerability Details

Relative Path Traversal in GitHub repository dnnsoftware/dnn.platform prior to 9.11.0.

Publish Date: 2022-09-30

URL: CVE-2022-2922

CVSS 3 Score Details (4.9)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: High
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: High
    • Integrity Impact: None
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-9w72-2f23-57gm

Release Date: 2022-09-30

Fix Resolution: DotNetNuke.Core - 9.11.0, DotNetNuke.Web - 9.11.0

Step up your Open Source Security Game with Mend here

@mend-bolt-for-github mend-bolt-for-github bot added the Mend: dependency security vulnerability Security vulnerability detected by Mend label Jul 6, 2023
@mend-bolt-for-github mend-bolt-for-github bot changed the title dotnetnuke.core.9.2.1.533.nupkg: 11 vulnerabilities (highest severity is: 8.8) dotnetnuke.core.9.2.1.533.nupkg: 10 vulnerabilities (highest severity is: 7.5) Jul 24, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Mend: dependency security vulnerability Security vulnerability detected by Mend
Projects
None yet
Development

No branches or pull requests

0 participants