Publish Advisories

GHSA-f6mm-5fc7-3g3c
GHSA-qjqg-4wg7-957h
GHSA-qjqg-4wg7-957h
This commit is contained in:
advisory-database[bot]
2024-05-15 17:18:38 +00:00
parent 35e8eda3b2
commit 0881ed793e
3 changed files with 166 additions and 42 deletions
@@ -0,0 +1,68 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f6mm-5fc7-3g3c",
"modified": "2024-05-15T17:17:10Z",
"published": "2024-05-15T17:17:10Z",
"aliases": [
],
"summary": "goreleaser shows environment by default",
"details": "### Summary\nSince #4787 the log output is printed on the INFO level, while previously it was logged on DEBUG. This means if the `go build` output is non-empty, goreleaser leaks the environment.\n\n### PoC\n* Create a Go project with dependencies, do not pull them yet (or run goreleaser later in a container, or delete `$GOPATH/pkg`).\n* Make sure to have secrets set in the environment\n* Make sure to not have `go mod tidy` in a before hook\n* Run `goreleaser release --clean`\n* Go prints lots of `go: downloading ...` lines, which triggers the \"if output not empty, log it\" line, which includes the environment.\n\n### Impact\nCredentials and tokens are leaked.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
{
"package": {
"ecosystem": "Go",
"name": "github.com/goreleaser/goreleaser"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "1.26.0"
},
{
"fixed": "1.26.1"
}
]
}
],
"versions": [
"1.26.0"
]
}
],
"references": [
{
"type": "WEB",
"url": "https://github.com/goreleaser/goreleaser/security/advisories/GHSA-f6mm-5fc7-3g3c"
},
{
"type": "WEB",
"url": "https://github.com/goreleaser/goreleaser/pull/4787"
},
{
"type": "WEB",
"url": "https://github.com/goreleaser/goreleaser/commit/22f734e41f7a5111a031a3a4eb714c1b6aa6456b"
},
{
"type": "PACKAGE",
"url": "https://github.com/goreleaser/goreleaser"
}
],
"database_specific": {
"cwe_ids": [
"CWE-532"
],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-05-15T17:17:10Z",
"nvd_published_at": null
}
}
@@ -0,0 +1,98 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qjqg-4wg7-957h",
"modified": "2024-05-15T17:16:58Z",
"published": "2024-05-15T03:30:43Z",
"aliases": [
"CVE-2024-3744"
],
"summary": "azure-file-csi-driver leaks service account tokens in the logs",
"details": "A security issue was discovered in azure-file-csi-driver where an actor with access to the driver logs could observe service account tokens. These tokens could then potentially be exchanged with external cloud providers to access secrets stored in cloud vault solutions. Tokens are only logged when TokenRequests is configured in the CSIDriver object and the driver is set to run at log level 2 or greater via the -v flag.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
}
],
"affected": [
{
"package": {
"ecosystem": "Go",
"name": "sigs.k8s.io/azurefile-csi-driver"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "1.29.4"
}
]
}
],
"database_specific": {
"last_known_affected_version_range": "<= 1.29.3"
}
},
{
"package": {
"ecosystem": "Go",
"name": "sigs.k8s.io/azurefile-csi-driver"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "1.30.0"
},
{
"fixed": "1.30.1"
}
]
}
],
"versions": [
"1.30.0"
]
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3744"
},
{
"type": "WEB",
"url": "https://github.com/kubernetes/kubernetes/issues/124759"
},
{
"type": "WEB",
"url": "https://github.com/kubernetes-sigs/azurefile-csi-driver/commit/a1b7446de942136419f07394efeef804523f87ae"
},
{
"type": "WEB",
"url": "https://github.com/kubernetes-sigs/azurefile-csi-driver/commit/e11ff3dc2c03894cde692213308f9991e7bbd5bf"
},
{
"type": "PACKAGE",
"url": "https://github.com/kubernetes-sigs/azurefile-csi-driver"
},
{
"type": "WEB",
"url": "https://groups.google.com/g/kubernetes-security-announce/c/hcgZE2MQo1A/m/Y4C6q-CYAgAJ"
}
],
"database_specific": {
"cwe_ids": [
"CWE-532"
],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-05-15T17:16:58Z",
"nvd_published_at": "2024-05-15T01:15:07Z"
}
}
@@ -1,42 +0,0 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qjqg-4wg7-957h",
"modified": "2024-05-15T03:30:43Z",
"published": "2024-05-15T03:30:43Z",
"aliases": [
"CVE-2024-3744"
],
"details": "A security issue was discovered in azure-file-csi-driver where an actor with access to the driver logs could observe service account tokens. These tokens could then potentially be exchanged with external cloud providers to access secrets stored in cloud vault solutions. Tokens are only logged when TokenRequests is configured in the CSIDriver object and the driver is set to run at log level 2 or greater via the -v flag.\n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3744"
},
{
"type": "WEB",
"url": "https://github.com/kubernetes/kubernetes/issues/124759"
},
{
"type": "WEB",
"url": "https://groups.google.com/g/kubernetes-security-announce/c/hcgZE2MQo1A/m/Y4C6q-CYAgAJ"
}
],
"database_specific": {
"cwe_ids": [
"CWE-532"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-15T01:15:07Z"
}
}