Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2024-12-05 05:14:56 +00:00
parent e9d0c66519
commit 036d386c5c
905 changed files with 1185 additions and 3555 deletions
@@ -8,9 +8,7 @@
],
"summary": "Moderate severity vulnerability that affects Microsoft.AspNetCore.Mvc and Microsoft.AspNetCore.Mvc.Core",
"details": "Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to bypass Enhanced Security Usage taggings when they present a certificate that is invalid for a specific use, aka \".NET Security Feature Bypass Vulnerability.\"",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -4,14 +4,10 @@
"modified": "2024-10-25T20:48:46Z",
"published": "2020-03-13T20:05:10Z",
"withdrawn": "2020-06-16T20:25:44Z",
"aliases": [
],
"aliases": [],
"summary": "Duplicate Advisory: python-gnupg allows context-dependent attackers to trick gnupg to decrypt other ciphertext than intended",
"details": "**Withdrawn:** Duplicate of GHSA-2fch-jvg5-crf6",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -104,9 +100,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2020-03-13T20:04:45Z",
@@ -54,9 +54,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2022-03-01T19:41:50Z",
File diff suppressed because one or more lines are too long
@@ -50,9 +50,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "CRITICAL",
"github_reviewed": true,
"github_reviewed_at": "2022-03-03T22:04:31Z",
@@ -3,14 +3,10 @@
"id": "GHSA-chxf-fjcf-7fwp",
"modified": "2022-03-01T21:04:07Z",
"published": "2022-03-01T21:04:07Z",
"aliases": [
],
"aliases": [],
"summary": "Possible filesystem space exhaustion by local users",
"details": "`fscrypt` through v0.3.2 creates a world-writable directory by default when setting up a filesystem, allowing unprivileged users to exhaust filesystem space. We recommend upgrading to `fscrypt` v0.3.3 or above and adjusting the permissions on existing `fscrypt` metadata directories where applicable.\n\nFor more details, see [CVE-2022-25326](https://www.cve.org/CVERecord?id=CVE-2022-25326) and https://github.com/google/fscrypt#setting-up-fscrypt-on-a-filesystem.\n",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -43,9 +39,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2022-03-01T21:04:07Z",
@@ -3,14 +3,10 @@
"id": "GHSA-gv9j-4w24-q7vx",
"modified": "2022-03-01T21:03:11Z",
"published": "2022-03-01T21:03:11Z",
"aliases": [
],
"aliases": [],
"summary": "Improper random number generation in github.com/coredns/coredns",
"details": "### Impact\n\nCoreDNS before 1.6.6 (using go DNS package < 1.1.25) improperly generates random numbers because math/rand is used. The TXID becomes predictable, leading to response forgeries.\n\n### Patches\nThe problem has been fixed in 1.6.6+.\n\n### References\n- [CVE-2019-19794](https://nvd.nist.gov/vuln/detail/CVE-2019-19794)\n\n### For more information\nPlease consult [our security guide](https://github.com/coredns/coredns/blob/master/.github/SECURITY.md) for more information regarding our security process.\n",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
File diff suppressed because one or more lines are too long
@@ -8,9 +8,7 @@
],
"summary": "Improper regex in htaccess file",
"details": "### Impact\nthe default .htaccess file has some restrictions in the access to PHP files to only allow specific PHP files to be executed in the root of the application.\n\nThis logic isn't correct, as the regex in the second FilesMatch only checks the filename, not the full path.\n\n### Patches\nPlease upgrade to 3.3.5 or 4.2.0 \n\n### Workarounds\nNo\n\n### References\n\n- Release post: https://www.mautic.org/blog/community/mautic-4-2-one-small-step-mautic\n- Internally tracked under MST-32\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Email us at [security@mautic.org](mailto:security@mautic.org)\n",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -58,9 +56,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2022-03-01T22:05:34Z",
@@ -3,14 +3,10 @@
"id": "GHSA-p93v-m2r2-4387",
"modified": "2022-03-01T21:05:01Z",
"published": "2022-03-01T21:05:01Z",
"aliases": [
],
"aliases": [],
"summary": "Denial of service via insufficient metadata validation",
"details": "The PAM module for `fscrypt` through v0.3.2 doesn't adequately validate `fscrypt` metadata files, allowing users to create malicious metadata files that prevent other users from logging in. A local user can cause a denial of service by creating a `fscrypt` metadata file that prevents other users from logging into the system. We recommend upgrading to v0.3.3 or above.\n\nFor more details, see [CVE-2022-25327](https://www.cve.org/CVERecord?id=CVE-2022-25327).",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -43,9 +39,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2022-03-01T21:05:01Z",
@@ -3,14 +3,10 @@
"id": "GHSA-v3wr-67px-44xg",
"modified": "2022-03-03T19:11:14Z",
"published": "2022-03-03T19:11:14Z",
"aliases": [
],
"aliases": [],
"summary": "Execution with Unnecessary Privileges in arc-electron",
"details": "### Impact\n\nWhen the end-user click on the response header that contains a link the target will be opened in ARC new window. This window will have the default preload script loaded which allows the scripts embedded in the link target to execute any logic that ARC has access to from the renderer process, which includes file system access, data store access (which may contain sensitive information), and some additional processes that only ARC should have access to.\n\n### Patches\n\nThis is patched in version 17.0.9.\n\n### Workarounds\n\nDo not click onto any link in the response headers view.\n\n### For more information\n\nIf you have any questions or comments about this advisory:\n* Open an issue in [advanced-rest-client/arc-electron](https://github.com/advanced-rest-client/arc-electron)\n* Email us at [Salesforce Security](mailto:security@salesforce.com)\n",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -43,9 +39,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2022-03-03T19:11:14Z",
@@ -3,14 +3,10 @@
"id": "GHSA-w4f8-fxq2-j35v",
"modified": "2022-03-01T21:04:57Z",
"published": "2022-03-01T21:04:57Z",
"aliases": [
],
"aliases": [],
"summary": "Possible privilege escalation via bash completion script",
"details": "The bash completion script for `fscrypt` through v0.3.2 allows injection of commands via crafted mountpoint paths, allowing privilege escalation under a specific set of circumstances. A local user who has control over mountpoint paths could potentially escalate their privileges if they create a malicious mountpoint path and if the system administrator happens to be using the `fscrypt` bash completion script to complete mountpoint paths. We recommend upgrading to v0.3.3 or above.\n\nFor more details, see [CVE-2022-25328](https://www.cve.org/CVERecord?id=CVE-2022-25328).",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -43,9 +39,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2022-03-01T21:04:57Z",
@@ -81,9 +81,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-05-10T21:49:12Z",
@@ -3,9 +3,7 @@
"id": "GHSA-75j2-9gmc-m855",
"modified": "2024-09-25T21:53:27Z",
"published": "2024-09-25T21:53:27Z",
"aliases": [
],
"aliases": [],
"summary": "Camaleon CMS vulnerable to stored XSS through user file upload (GHSL-2024-184)",
"details": "A stored cross-site scripting has been found in the image upload functionality that can be used by normal registered users:\nIt is possible to upload a SVG image containing JavaScript and it's also possible to upload a HTML document when the format\nparameter is manually changed to [documents][1] or a string of an [unsupported format][2]. If an authenticated user or administrator visits that uploaded image or document malicious JavaScript can be executed on their behalf (e.g. changing or deleting content inside of the CMS.)\n\n[1]: https://github.com/owen2345/camaleon-cms/blob/feccb96e542319ed608acd3a16fa5d92f13ede67/app/uploaders/camaleon_cms_uploader.rb#L105-L106\n[2]: https://github.com/owen2345/camaleon-cms/blob/feccb96e542319ed608acd3a16fa5d92f13ede67/app/uploaders/camaleon_cms_uploader.rb#L110-L111\n\n## Impact\n\nThis issue may lead to account takeover due to reflected Cross-site scripting (XSS).\n\n## Remediation\n\nOnly allow the upload of safe files such as PNG, TXT and others or serve all \"unsafe\" files such as SVG and other files with a content-disposition: attachment header, which should prevent browsers from displaying them.\n\nAdditionally, a [Content security policy (CSP)][3] can be created that disallows inlined script. (Other parts of the application might need modification to continue functioning.)\n\n[3]: https://web.dev/articles/csp\n\nTo prevent the theft of the auth_token it could be marked with HttpOnly. This would however not prevent that actions could be performed as the authenticated user/administrator. Furthermore, it could make sense to use the authentication provided by Ruby on Rails, so that stolen tokens cannot be used anymore after some time.\n",
"severity": [
@@ -66,9 +66,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2024-09-18T17:38:50Z",
@@ -3,9 +3,7 @@
"id": "GHSA-m842-4qm8-7gpq",
"modified": "2024-09-25T21:48:24Z",
"published": "2024-09-25T21:48:24Z",
"aliases": [
],
"aliases": [],
"summary": "Gradio allows users to access arbitrary files",
"details": "### Impact\nThis vulnerability allows users of Gradio applications that have a public link (such as on Hugging Face Spaces) to access files on the machine hosting the Gradio application. This involves intercepting and modifying the network requests made by the Gradio app to the server. \n\n### Patches\nYes, the problem has been patched in Gradio version 4.19.2 or higher. We have no knowledge of this exploit being used against users of Gradio applications, but we encourage all users to upgrade to Gradio 4.19.2 or higher.\n\nFixed in: https://github.com/gradio-app/gradio/commit/16fbe9cd0cffa9f2a824a0165beb43446114eec7\nCVE: https://nvd.nist.gov/vuln/detail/CVE-2024-1728",
"severity": [
@@ -54,9 +52,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "CRITICAL",
"github_reviewed": true,
"github_reviewed_at": "2024-09-25T21:48:24Z",
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"affected": [],
"references": [
{
"type": "ADVISORY",
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"affected": [],
"references": [
{
"type": "ADVISORY",
@@ -7,12 +7,8 @@
"CVE-2022-25104"
],
"details": "HorizontCMS v1.0.0-beta.2 was discovered to contain an arbitrary file download vulnerability via the component /admin/file-manager/.",
"severity": [
],
"affected": [
],
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"affected": [],
"references": [
{
"type": "ADVISORY",

Some files were not shown because too many files have changed in this diff Show More