File tree Expand file tree Collapse file tree
Expand file tree Collapse file tree Original file line number Diff line number Diff line change @@ -30,13 +30,24 @@ advisory:
3030 cvss_v4 : 6.0
3131 unaffected_versions :
3232 - " < 2.4.5.0"
33- notes : Never patched; last release was 2.9.1
33+ patched_versions :
34+ - " >= 2.9.2"
3435 related :
3536 url :
3637 - https://nvd.nist.gov/vuln/detail/CVE-2026-1776
38+ - https://rubygems.org/gems/camaleon_cms/versions/2.9.2
39+ - https://github.com/owen2345/camaleon-cms/releases/tag/2.9.2
3740 - https://github.com/owen2345/camaleon-cms/pull/1127
3841 - https://github.com/owen2345/camaleon-cms/commit/f54a77e2a7be601215ea1b396038c589a0cab9af
3942 - https://camaleon.website
4043 - https://www.vulncheck.com/advisories/camaleon-cms-aws-uploader-authenticated-path-traversal-arbitrary-file-read
4144 - https://github.com/advisories/GHSA-jw5g-f64p-6x78
45+ notes : |
46+ - Note that the rubygem name is "camaleon_cms" and
47+ repo name is "camaleon-cms".
48+ - Found PR#1127 (from GHSA and nvd.nist.gov) in
49+ https://github.com/owen2345/camaleon-cms/releases/tag/2.9.2
50+ release notes.
51+ - cvss_v3 from nvd.nist.gov URL.
52+ - cvss_v4 from GHSA and nvd.nist.gov URLs.
4253---
You can’t perform that action at this time.
0 commit comments