{"id":"GHSA-hgq9-q8g2-3jmg","summary":"Command Injection in VIVO Vitro","details":"SPARQL Injection in VIVO Vitro v1.10.0 allows a remote attacker to execute arbitrary SPARQL via the uri parameter, leading to a regular expression denial of service (ReDoS), as demonstrated by crafted use of FILTER%20regex in a /individual?uri= request.","aliases":["CVE-2019-6986"],"modified":"2024-02-16T08:08:49.908321Z","published":"2022-05-13T01:22:47Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2022-11-01T23:33:34Z","nvd_published_at":"2019-01-28T15:29:00Z","cwe_ids":["CWE-400","CWE-77"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-6986"},{"type":"WEB","url":"https://github.com/vivo-project/Vitro/pull/111"},{"type":"WEB","url":"https://github.com/vivo-project/Vitro/pull/111/commits/248ef19107a5ac6f86304fd8f3bc75f3787f8d49"},{"type":"WEB","url":"https://github.com/kevinbackhouse/SecurityExploits/tree/0ec74459ac53685a7959ed58d580ef8abece3685/vivo-project"},{"type":"PACKAGE","url":"https://github.com/vivo-project/Vitro"},{"type":"WEB","url":"https://jira.duraspace.org/browse/VIVO-1697"},{"type":"WEB","url":"http://packetstormsecurity.com/files/172838/VIVO-SPARQL-Injection.html"}],"affected":[{"package":{"name":"org.vivoweb:vitro-project","ecosystem":"Maven","purl":"pkg:maven/org.vivoweb/vitro-project"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.11.0"}]}],"versions":["1.10.0","1.10.0-alpha1","1.10.0-alpha2","1.10.0-beta1","1.10.0-beta2","1.9.0","1.9.0-alpha-1","1.9.0-alpha-2","1.9.0-rc1","1.9.1","1.9.2","1.9.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-hgq9-q8g2-3jmg/GHSA-hgq9-q8g2-3jmg.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}