Publish Advisories

GHSA-v352-rg37-5q5m
GHSA-xqxc-x6p3-w683
This commit is contained in:
advisory-database[bot]
2025-06-04 21:15:33 +00:00
parent a64bff8af7
commit 0357108544
2 changed files with 139 additions and 1 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v352-rg37-5q5m",
"modified": "2024-11-18T16:26:59Z",
"modified": "2025-06-04T21:14:18Z",
"published": "2024-08-02T12:31:43Z",
"aliases": [
"CVE-2024-27181"
@@ -51,6 +51,10 @@
{
"type": "WEB",
"url": "https://lists.apache.org/thread/hosd73l7hxb3rpt5rb0yg0ld11zph4c6"
},
{
"type": "WEB",
"url": "https://www.openwall.com/lists/oss-security/2024/08/02/3"
}
],
"database_specific": {
@@ -0,0 +1,134 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xqxc-x6p3-w683",
"modified": "2025-06-04T21:13:44Z",
"published": "2025-06-04T21:13:44Z",
"aliases": [
"CVE-2025-48888"
],
"summary": "Deno run with --allow-read and --deny-read flags results in allowed",
"details": "### Summary\n\n`deno run --allow-read --deny-read main.ts` results in allowed, even though 'deny' should be stronger. Same with all global unary permissions given as `--allow-* --deny-*`.\n\n### Details\n\nCaused by the fast exit logic in #22894.\n\n### PoC\n\nRun the above command expecting no permissions to be passed.\n\n### Impact\n\nThis only affects a nonsensical combination of flags, so there shouldn't be a real impact on the userbase.",
"severity": [
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P"
}
],
"affected": [
{
"package": {
"ecosystem": "crates.io",
"name": "deno"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "1.41.3"
},
{
"fixed": "2.1.13"
}
]
}
]
},
{
"package": {
"ecosystem": "crates.io",
"name": "deno"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "2.2.0"
},
{
"fixed": "2.2.13"
}
]
}
]
},
{
"package": {
"ecosystem": "crates.io",
"name": "deno"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "2.3.0"
},
{
"fixed": "2.3.2"
}
]
}
]
},
{
"package": {
"ecosystem": "crates.io",
"name": "deno_runtime"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0.150.0"
},
{
"fixed": "0.212.0"
}
]
}
]
}
],
"references": [
{
"type": "WEB",
"url": "https://github.com/denoland/deno/security/advisories/GHSA-xqxc-x6p3-w683"
},
{
"type": "WEB",
"url": "https://github.com/denoland/deno/pull/22894"
},
{
"type": "WEB",
"url": "https://github.com/denoland/deno/pull/29213"
},
{
"type": "WEB",
"url": "https://github.com/denoland/deno/commit/2f0fae9d9071dcaf0a689bc7097584b1b9ebc8db"
},
{
"type": "WEB",
"url": "https://github.com/denoland/deno/commit/9d665572d3cd39f997e29e6daac7c1102fc5c04f"
},
{
"type": "WEB",
"url": "https://github.com/denoland/deno/commit/ef315b56c26c9ef5f25284a5100d2ed525a148cf"
},
{
"type": "PACKAGE",
"url": "https://github.com/denoland/deno"
}
],
"database_specific": {
"cwe_ids": [
"CWE-863"
],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2025-06-04T21:13:44Z",
"nvd_published_at": null
}
}