{"id":"GHSA-x86x-qhf8-f37w","summary":"willdurand/js-translation-bundle potential path traversal attack and remote code injection","details":"A path traversal and a javascript code injection vulnerabilities were identified in willdurand/js-translation-bundle versions prior to 2.1.1. ","modified":"2024-12-04T05:34:33.641176Z","published":"2024-06-07T22:20:27Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2024-06-07T22:20:27Z","nvd_published_at":null,"cwe_ids":["CWE-22","CWE-74"],"severity":"CRITICAL"},"references":[{"type":"WEB","url":"https://github.com/willdurand/BazingaJsTranslationBundle/commit/7accee93569c3f3d2379f035a41ece66522801fc"},{"type":"WEB","url":"https://github.com/willdurand/BazingaJsTranslationBundle/commit/df6c0fd603c0192ebc5584991a52a1092c5f60bd"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/willdurand/js-translation-bundle/2014-07-29-1.yaml"},{"type":"PACKAGE","url":"https://github.com/willdurand/BazingaJsTranslationBundle"},{"type":"WEB","url":"https://github.com/willdurand/BazingaJsTranslationBundle/releases/tag/v2.1.1"}],"affected":[{"package":{"name":"willdurand/js-translation-bundle","ecosystem":"Packagist","purl":"pkg:composer/willdurand/js-translation-bundle"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.1.1"}]}],"versions":["0.0.1","0.0.2","0.0.3","0.0.4","0.0.5","0.1.0","0.1.1","0.1.2","0.1.3","0.2.0","0.2.1","0.3.0","1.0.0","1.0.1","1.0.2","1.0.3","1.1.0","1.1.1","1.1.2","1.2.0","1.2.1","1.2.2","v2.0.0","v2.0.0-alpha1","v2.0.0-alpha2","v2.0.0-alpha3","v2.0.0-alpha4","v2.1.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/06/GHSA-x86x-qhf8-f37w/GHSA-x86x-qhf8-f37w.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}