diff --git a/advisories/github-reviewed/2024/03/GHSA-cqfh-c4c5-c2hg/GHSA-cqfh-c4c5-c2hg.json b/advisories/github-reviewed/2024/03/GHSA-cqfh-c4c5-c2hg/GHSA-cqfh-c4c5-c2hg.json new file mode 100644 index 00000000000..80f57641d0b --- /dev/null +++ b/advisories/github-reviewed/2024/03/GHSA-cqfh-c4c5-c2hg/GHSA-cqfh-c4c5-c2hg.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cqfh-c4c5-c2hg", + "modified": "2024-08-29T18:02:23Z", + "published": "2024-03-28T00:31:40Z", + "aliases": [ + "CVE-2024-25354" + ], + "summary": "domain-suffix RegEx Denial of Service", + "details": "RegEx Denial of Service in domain-suffix 1.0.8 allows attackers to crash the application via crafted input to the parse function.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "npm", + "name": "domain-suffix" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "1.0.8" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25354" + }, + { + "type": "WEB", + "url": "https://gist.github.com/6en6ar/c3b11b4058b8e2bc54717408d451fb79" + }, + { + "type": "PACKAGE", + "url": "https://github.com/ikrong/domain-suffix" + }, + { + "type": "WEB", + "url": "https://github.com/ikrong/domain-suffix/blob/master/src/domainSuffix.ts" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1333" + ], + "severity": "HIGH", + "github_reviewed": true, + "github_reviewed_at": "2024-08-29T18:02:23Z", + "nvd_published_at": "2024-03-27T22:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/03/GHSA-pc95-3wgm-x28p/GHSA-pc95-3wgm-x28p.json b/advisories/github-reviewed/2024/03/GHSA-pc95-3wgm-x28p/GHSA-pc95-3wgm-x28p.json new file mode 100644 index 00000000000..b4a940beaf2 --- /dev/null +++ b/advisories/github-reviewed/2024/03/GHSA-pc95-3wgm-x28p/GHSA-pc95-3wgm-x28p.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pc95-3wgm-x28p", + "modified": "2024-08-29T18:01:50Z", + "published": "2024-03-22T06:30:23Z", + "aliases": [ + "CVE-2024-29271" + ], + "summary": "VvvebJs Reflected Cross-Site Scripting (XSS) vulnerability", + "details": "A reflected Cross-Site Scripting (XSS) vulnerability in VvvebJs before version 1.7.5 allows remote attackers to execute arbitrary code and obtain sensitive information via the `action` parameter in `save.php`.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "npm", + "name": "vvvebjs" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.7.5" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29271" + }, + { + "type": "WEB", + "url": "https://github.com/givanz/VvvebJs/issues/342" + }, + { + "type": "WEB", + "url": "https://github.com/givanz/VvvebJs/commit/c0c0545b44b23acc288ef907fb498ce15b9b576e" + }, + { + "type": "PACKAGE", + "url": "https://github.com/givanz/VvvebJs" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-08-29T18:01:50Z", + "nvd_published_at": "2024-03-22T04:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/08/GHSA-mgwr-h7mv-fh29/GHSA-mgwr-h7mv-fh29.json b/advisories/github-reviewed/2024/08/GHSA-mgwr-h7mv-fh29/GHSA-mgwr-h7mv-fh29.json new file mode 100644 index 00000000000..4b9f2a10a1b --- /dev/null +++ b/advisories/github-reviewed/2024/08/GHSA-mgwr-h7mv-fh29/GHSA-mgwr-h7mv-fh29.json @@ -0,0 +1,85 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mgwr-h7mv-fh29", + "modified": "2024-08-29T18:00:45Z", + "published": "2024-08-29T18:00:45Z", + "aliases": [ + "CVE-2024-45054" + ], + "summary": "Hwameistor Potential Permission Leakage of Cluster Level ", + "details": "### Impact\n_What kind of vulnerability is it? Who is impacted?_\nThis ClusterRole has * verbs of * resources. If a malicious user can access the worker node which has hwameistor's deployment, he/she can abuse these excessive permissions to do whatever he/she likes to the whole cluster, resulting in a cluster-level privilege escalation.\n\n### Patches\n_Has the problem been patched? What versions should users upgrade to?_\n>= v0.14.6\n\n### Workarounds\n_Is there a way for users to fix or remediate the vulnerability without upgrading?_\nUpdate and Limit the ClusterRole using [security-role](https://github.com/hwameistor/hwameistor/blob/main/helm/hwameistor/templates/clusterrole.yaml).\n\n### References\n_Are there any links users can visit to find out more?_\nissues:\nhttps://github.com/hwameistor/hwameistor/issues/1457\nhttps://github.com/hwameistor/hwameistor/issues/1460\n\nalso reported by users via mails: \n[sparkEchooo](https://github.com/sparkEchooo), [younaman](https://github.com/younaman)\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Go", + "name": "github.com/hwameistor/hwameistor" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.14.6" + } + ] + } + ], + "database_specific": { + "last_known_affected_version_range": "<= 0.14.5" + } + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/hwameistor/hwameistor/security/advisories/GHSA-mgwr-h7mv-fh29" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45054" + }, + { + "type": "WEB", + "url": "https://github.com/hwameistor/hwameistor/issues/1457" + }, + { + "type": "WEB", + "url": "https://github.com/hwameistor/hwameistor/issues/1460" + }, + { + "type": "WEB", + "url": "https://github.com/hwameistor/hwameistor/commit/edf4cebed73cadd230bf97eab65c5311f2858450" + }, + { + "type": "PACKAGE", + "url": "https://github.com/hwameistor/hwameistor" + }, + { + "type": "WEB", + "url": "https://github.com/hwameistor/hwameistor/blob/main/helm/hwameistor/templates/clusterrole.yaml" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200", + "CWE-266" + ], + "severity": "LOW", + "github_reviewed": true, + "github_reviewed_at": "2024-08-29T18:00:45Z", + "nvd_published_at": "2024-08-28T20:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-cqfh-c4c5-c2hg/GHSA-cqfh-c4c5-c2hg.json b/advisories/unreviewed/2024/03/GHSA-cqfh-c4c5-c2hg/GHSA-cqfh-c4c5-c2hg.json deleted file mode 100644 index e50577b253c..00000000000 --- a/advisories/unreviewed/2024/03/GHSA-cqfh-c4c5-c2hg/GHSA-cqfh-c4c5-c2hg.json +++ /dev/null @@ -1,38 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-cqfh-c4c5-c2hg", - "modified": "2024-08-28T15:31:13Z", - "published": "2024-03-28T00:31:40Z", - "aliases": [ - "CVE-2024-25354" - ], - "details": "RegEx Denial of Service in domain-suffix 1.0.8 allows attackers to crash the application via crafted input to the parse function.", - "severity": [ - { - "type": "CVSS_V3", - "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" - } - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25354" - }, - { - "type": "WEB", - "url": "https://gist.github.com/6en6ar/c3b11b4058b8e2bc54717408d451fb79" - } - ], - "database_specific": { - "cwe_ids": [ - - ], - "severity": "HIGH", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2024-03-27T22:15:10Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-pc95-3wgm-x28p/GHSA-pc95-3wgm-x28p.json b/advisories/unreviewed/2024/03/GHSA-pc95-3wgm-x28p/GHSA-pc95-3wgm-x28p.json deleted file mode 100644 index 9770d0d83b6..00000000000 --- a/advisories/unreviewed/2024/03/GHSA-pc95-3wgm-x28p/GHSA-pc95-3wgm-x28p.json +++ /dev/null @@ -1,42 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-pc95-3wgm-x28p", - "modified": "2024-08-28T15:31:13Z", - "published": "2024-03-22T06:30:23Z", - "aliases": [ - "CVE-2024-29271" - ], - "details": "Reflected Cross-Site Scripting (XSS) vulnerability in VvvebJs before version 1.7.7, allows remote attackers to execute arbitrary code and obtain sensitive information via the action parameter in save.php.", - "severity": [ - { - "type": "CVSS_V3", - "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" - } - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-29271" - }, - { - "type": "WEB", - "url": "https://github.com/givanz/VvvebJs/issues/342" - }, - { - "type": "WEB", - "url": "https://github.com/givanz/VvvebJs/commit/c0c0545b44b23acc288ef907fb498ce15b9b576e" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-79" - ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2024-03-22T04:15:11Z" - } -} \ No newline at end of file