Show plain JSON{"dataType": "CVE_RECORD", "dataVersion": "5.1", "cveMetadata": {"cveId": "CVE-2024-39319", "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa", "state": "PUBLISHED", "assignerShortName": "GitHub_M", "dateReserved": "2024-06-21T18:15:22.262Z", "datePublished": "2024-09-26T16:07:01.482Z", "dateUpdated": "2024-09-26T18:24:00.120Z"}, "containers": {"cna": {"title": "aimeos/ai-controller-frontend has IDOR vulnerability in account profile page", "problemTypes": [{"descriptions": [{"cweId": "CWE-639", "lang": "en", "description": "CWE-639: Authorization Bypass Through User-Controlled Key", "type": "CWE"}]}], "metrics": [{"cvssV3_0": {"attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 5.3, "baseSeverity": "MEDIUM", "confidentialityImpact": "NONE", "integrityImpact": "LOW", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N", "version": "3.0"}}], "references": [{"name": "https://github.com/aimeos/ai-controller-frontend/security/advisories/GHSA-rw3j-574h-mrcq", "tags": ["x_refsource_CONFIRM"], "url": "https://github.com/aimeos/ai-controller-frontend/security/advisories/GHSA-rw3j-574h-mrcq"}, {"name": "https://github.com/aimeos/ai-controller-frontend/commit/2ad5c062a629af374da470a319914c321c9bfee2", "tags": ["x_refsource_MISC"], "url": "https://github.com/aimeos/ai-controller-frontend/commit/2ad5c062a629af374da470a319914c321c9bfee2"}, {"name": "https://github.com/aimeos/ai-controller-frontend/commit/53eebdc51fae34440dfd768a7811c169c7779aa9", "tags": ["x_refsource_MISC"], "url": "https://github.com/aimeos/ai-controller-frontend/commit/53eebdc51fae34440dfd768a7811c169c7779aa9"}, {"name": "https://github.com/aimeos/ai-controller-frontend/commit/5833db6d18a889b94dc036dfb84b6f5cca73fbac", "tags": ["x_refsource_MISC"], "url": "https://github.com/aimeos/ai-controller-frontend/commit/5833db6d18a889b94dc036dfb84b6f5cca73fbac"}, {"name": "https://github.com/aimeos/ai-controller-frontend/commit/6ea6b82f5a1fc18c574cb6f97225930d139b14a5", "tags": ["x_refsource_MISC"], "url": "https://github.com/aimeos/ai-controller-frontend/commit/6ea6b82f5a1fc18c574cb6f97225930d139b14a5"}, {"name": "https://github.com/aimeos/ai-controller-frontend/commit/700da5ea2b622724b68c8684346bf74ac3bbca9b", "tags": ["x_refsource_MISC"], "url": "https://github.com/aimeos/ai-controller-frontend/commit/700da5ea2b622724b68c8684346bf74ac3bbca9b"}, {"name": "https://github.com/aimeos/ai-controller-frontend/commit/7c93139f86eff9ec26b117a8918e06ce6cc0000f", "tags": ["x_refsource_MISC"], "url": "https://github.com/aimeos/ai-controller-frontend/commit/7c93139f86eff9ec26b117a8918e06ce6cc0000f"}, {"name": "https://github.com/aimeos/ai-controller-frontend/commit/ae7baa3f2fbf594c2c1e4b1aae83364a84b241a6", "tags": ["x_refsource_MISC"], "url": "https://github.com/aimeos/ai-controller-frontend/commit/ae7baa3f2fbf594c2c1e4b1aae83364a84b241a6"}, {"name": "https://github.com/aimeos/ai-controller-frontend/commit/cd8c95aa4663f54bd66a69c5952f2e42405426f3", "tags": ["x_refsource_MISC"], "url": "https://github.com/aimeos/ai-controller-frontend/commit/cd8c95aa4663f54bd66a69c5952f2e42405426f3"}, {"name": "https://github.com/aimeos/ai-controller-frontend/commit/d4eac06f3a25330c089d8be4397f2ab1936dd9bb", "tags": ["x_refsource_MISC"], "url": "https://github.com/aimeos/ai-controller-frontend/commit/d4eac06f3a25330c089d8be4397f2ab1936dd9bb"}, {"name": "https://github.com/aimeos/ai-controller-frontend/commit/f7c6a9ce2a6f5a9ad4af31313508870a78398f85", "tags": ["x_refsource_MISC"], "url": "https://github.com/aimeos/ai-controller-frontend/commit/f7c6a9ce2a6f5a9ad4af31313508870a78398f85"}], "affected": [{"vendor": "aimeos", "product": "ai-controller-frontend", "versions": [{"version": "= 2024.04.1", "status": "affected"}, {"version": ">= 2023.04.1, < 2023.10.9", "status": "affected"}, {"version": ">= 2022.04.1, < 2022.10.8", "status": "affected"}, {"version": ">= 2021.04.1, < 2021.10.8", "status": "affected"}, {"version": "< 2020.10.15", "status": "affected"}]}], "providerMetadata": {"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa", "shortName": "GitHub_M", "dateUpdated": "2024-09-26T16:07:01.482Z"}, "descriptions": [{"lang": "en", "value": "aimeos/ai-controller-frontend is the Aimeos frontend controller package for e-commerce projects. Prior to versions 2024.4.2, 2023.10.9, 2022.10.8, 2021.10.8, and 2020.10.15, an insecure direct object reference allows an attacker to disable subscriptions and reviews of another customer. Versions 2024.4.2, 2023.10.9, 2022.10.8, 2021.10.8, and 2020.10.15 fix this issue."}], "source": {"advisory": "GHSA-rw3j-574h-mrcq", "discovery": "UNKNOWN"}}, "adp": [{"affected": [{"vendor": "aimeos_project", "product": "ai-controller-frontend", "cpes": ["cpe:2.3:a:aimeos_project:ai-controller-frontend:*:*:*:*:*:*:*:*"], "defaultStatus": "unknown", "versions": [{"version": "2024.04.1", "status": "affected"}, {"version": "2023.04.1", "status": "affected", "lessThan": "2023.10.9", "versionType": "custom"}, {"version": "2022.04.1", "status": "affected", "lessThan": "2022.10.8", "versionType": "custom"}, {"version": "2021.04.1", "status": "affected", "lessThan": "2021.10.8", "versionType": "custom"}, {"version": "0", "status": "affected", "lessThan": "2020.10.15", "versionType": "custom"}]}], "metrics": [{"other": {"type": "ssvc", "content": {"timestamp": "2024-09-26T17:55:58.738464Z", "id": "CVE-2024-39319", "options": [{"Exploitation": "none"}, {"Automatable": "yes"}, {"Technical Impact": "partial"}], "role": "CISA Coordinator", "version": "2.0.3"}}}], "title": "CISA ADP Vulnrichment", "providerMetadata": {"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2024-09-26T18:24:00.120Z"}}]}}