From 0c972c093cfd62ff84a82ebf2e137cc62d9c787e Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 27 Nov 2024 21:57:44 +0000 Subject: [PATCH] Publish Advisories GHSA-9g6g-xqv5-8g5w GHSA-27wf-5967-98gx GHSA-7f6p-phw2-8253 GHSA-mr95-vfcf-fx9p --- .../GHSA-9g6g-xqv5-8g5w/GHSA-9g6g-xqv5-8g5w.json | 10 +++++++++- .../GHSA-27wf-5967-98gx/GHSA-27wf-5967-98gx.json | 10 +++++++++- .../GHSA-7f6p-phw2-8253/GHSA-7f6p-phw2-8253.json | 14 ++++---------- .../GHSA-mr95-vfcf-fx9p/GHSA-mr95-vfcf-fx9p.json | 6 +++++- 4 files changed, 27 insertions(+), 13 deletions(-) diff --git a/advisories/github-reviewed/2024/06/GHSA-9g6g-xqv5-8g5w/GHSA-9g6g-xqv5-8g5w.json b/advisories/github-reviewed/2024/06/GHSA-9g6g-xqv5-8g5w/GHSA-9g6g-xqv5-8g5w.json index 52b08da8399..a4cc6ef3e15 100644 --- a/advisories/github-reviewed/2024/06/GHSA-9g6g-xqv5-8g5w/GHSA-9g6g-xqv5-8g5w.json +++ b/advisories/github-reviewed/2024/06/GHSA-9g6g-xqv5-8g5w/GHSA-9g6g-xqv5-8g5w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9g6g-xqv5-8g5w", - "modified": "2024-11-21T23:19:51Z", + "modified": "2024-11-27T21:55:55Z", "published": "2024-06-25T21:31:15Z", "aliases": [ "CVE-2024-37820" @@ -12,6 +12,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N" } ], "affected": [ @@ -52,6 +56,10 @@ "type": "WEB", "url": "https://gist.github.com/ycybfhb/a9c1e14ce281f2f553adca84d384b761" }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-9g6g-xqv5-8g5w" + }, { "type": "PACKAGE", "url": "https://github.com/pingcap/tidb" diff --git a/advisories/github-reviewed/2024/11/GHSA-27wf-5967-98gx/GHSA-27wf-5967-98gx.json b/advisories/github-reviewed/2024/11/GHSA-27wf-5967-98gx/GHSA-27wf-5967-98gx.json index ea8e983586a..730a66870ef 100644 --- a/advisories/github-reviewed/2024/11/GHSA-27wf-5967-98gx/GHSA-27wf-5967-98gx.json +++ b/advisories/github-reviewed/2024/11/GHSA-27wf-5967-98gx/GHSA-27wf-5967-98gx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-27wf-5967-98gx", - "modified": "2024-11-22T22:50:21Z", + "modified": "2024-11-27T21:57:06Z", "published": "2024-11-22T21:32:15Z", "aliases": [ "CVE-2024-10220" @@ -12,6 +12,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N" } ], "affected": [ @@ -86,6 +90,10 @@ "type": "WEB", "url": "https://github.com/kubernetes/kubernetes/commit/1ab06efe92d8e898ca1931471c9533ce94aba29b" }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-27wf-5967-98gx" + }, { "type": "PACKAGE", "url": "https://github.com/kubernetes/kubernetes" diff --git a/advisories/github-reviewed/2024/11/GHSA-7f6p-phw2-8253/GHSA-7f6p-phw2-8253.json b/advisories/github-reviewed/2024/11/GHSA-7f6p-phw2-8253/GHSA-7f6p-phw2-8253.json index 8020e63b6b4..b9458e5843b 100644 --- a/advisories/github-reviewed/2024/11/GHSA-7f6p-phw2-8253/GHSA-7f6p-phw2-8253.json +++ b/advisories/github-reviewed/2024/11/GHSA-7f6p-phw2-8253/GHSA-7f6p-phw2-8253.json @@ -1,16 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-7f6p-phw2-8253", - "modified": "2024-11-25T15:11:11Z", + "modified": "2024-11-27T21:57:16Z", "published": "2024-11-25T15:11:11Z", - "aliases": [ - - ], + "aliases": [], "summary": "Taurus multi-party-sig has OT-based ECDSA protocol implementation flaws", "details": "Coinbase researchers reported 2 security issues in our implementation of the oblivious transfer (OT) based protocol [DKLS](https://eprint.iacr.org/2018/499.pdf):\n\n### 1. Secret share recovery attack\n\nIf the base OT setup of the protocol is reused for another execution of the OT extension, then a malicious participant can extract a bit of the secret of another participant. By repeating the execution they can eventually recover the whole secret.\n\nTherefore, unlike our comments suggested, you **must not reuse an OT setup** for multiple protocol executions. \n\nWe're adding a warning in the code:\n\nhttps://github.com/taurushq-io/multi-party-sig/blob/9e4400fccee89be6195d0a12dd0ed052288d5040/internal/ot/extended.go#L114\n\n### 2. Invalid security proof due to incorrect operator\n\nThe original 2018 version of the DKLS had a typo in the OT extension protocol when computing the check value in the OT extension: the paper noted a XOR whereas it should be a field multiplication. This erroneous behavior was implemented [in our code](https://github.com/taurushq-io/multi-party-sig/blob/4d84aafb57b437da1b933db9a265fb7ce4e7c138/internal/ot/extended.go#L188). \n\nThe proof of security fails in this case. No concrete attack is known, however.\n\nThe [2023 update](https://eprint.iacr.org/2018/499.pdf) of the DKLS paper reported that typo and updated the protocol definition.\n\nAs of 20241124, patching is in progress (branch [otfix](https://github.com/taurushq-io/multi-party-sig/tree/otfix)), but not merged to the main branch yes as the tests fail to pass. We're troubleshooting the issue and will merge into the main branch when it's resolved.\n\n### Workarounds\n\nDo not reuse an OT setup, to eliminate the secret recovery attack.\n \nAvoid using our implementation of the DKLS protocol until we patch it, and maybe avoid DKLS altogether.\n\n### Credits\n\nThank you to the Coinbase researchers Yi-Hsiu Chen and Samuel Ranellucci for discovering these issues and providing a comprehensive write-up. Thank you to Yehuda Lindell for coordinating the disclosure.\n\n\n", - "severity": [ - - ], + "severity": [], "affected": [ { "package": { @@ -59,9 +55,7 @@ } ], "database_specific": { - "cwe_ids": [ - - ], + "cwe_ids": [], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2024-11-25T15:11:11Z", diff --git a/advisories/github-reviewed/2024/11/GHSA-mr95-vfcf-fx9p/GHSA-mr95-vfcf-fx9p.json b/advisories/github-reviewed/2024/11/GHSA-mr95-vfcf-fx9p/GHSA-mr95-vfcf-fx9p.json index 852a6c2a597..4bf5f86ff5d 100644 --- a/advisories/github-reviewed/2024/11/GHSA-mr95-vfcf-fx9p/GHSA-mr95-vfcf-fx9p.json +++ b/advisories/github-reviewed/2024/11/GHSA-mr95-vfcf-fx9p/GHSA-mr95-vfcf-fx9p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mr95-vfcf-fx9p", - "modified": "2024-11-22T22:50:08Z", + "modified": "2024-11-27T21:56:44Z", "published": "2024-11-22T21:32:14Z", "aliases": [ "CVE-2024-45719" @@ -12,6 +12,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N" } ], "affected": [