Skip to content

migros/migros-security-advisories

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

16 Commits
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Migros Security Advisories

Below you find a curated list of security advisories published by the Security Operations / Cyber Defense Center team of MGB (Migros-Genossenschafts-Bund) found during penetration tests or red team engagements.

Overview

The table below provides a summary of all published advisories, including key details such as dates, identifiers, severity scores, affected vendors, and products.

Date MSEC ID Vendor ID CVE ID CVSS 4.0 Vendor Product Vulnerability Advisory
20.05.2025 MSEC-2025-001 n/a CVE-2024-42912 8.6 META-INF Email This Issue Stored Cross-Site Scripting Open
20.05.2025 MSEC-2025-002 ODOO-SA-2024-12-23 CVE-2024-12368 8.7 Odoo Odoo Authenticated Account Takeover Open
04.06.2025 MSEC-2025-003 n/a CVE-2025-5597 10.0 WF Steuerungstechnik GmbH airleader MASTER Authentication Bypass Open
04.06.2025 MSEC-2025-004 n/a CVE-2025-5598 9.2 WF Steuerungstechnik GmbH airleader MASTER Path Traversal Open

Vulnerability Disclosure Process

The following figure illustrates the underlying vulnerability disclosure process, outlining the steps for reporting, managing, and resolving security vulnerabilities responsibly. Vulnerability Disclosure Process The figure represents a reference process that serves as a foundational guideline. It can be adapted or modified as needed to ensure responsible and context-appropriate publication.

Contact

Please contact damiano.esposito@mgb.ch for issues relating to this repository. Please contact media@migros.ch for press inquiries.

About

Migros Security Advisories

Topics

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published