mirror of
https://github.com/netbirdio/advisory-database.git
synced 2026-05-22 18:04:22 -07:00
Publish Advisories
GHSA-7jr6-prv4-5wf5 GHSA-28r2-q6m8-9hpx GHSA-cjr4-fv6c-f3mv GHSA-p782-xgp4-8hr8 GHSA-qpgx-64h2-gc3c GHSA-2m4x-4q9j-w97g
This commit is contained in:
@@ -1,13 +1,14 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-7jr6-prv4-5wf5",
|
||||
"modified": "2023-08-30T10:26:47Z",
|
||||
"modified": "2024-05-20T21:26:28Z",
|
||||
"published": "2021-06-23T18:14:31Z",
|
||||
"withdrawn": "2024-05-20T21:26:28Z",
|
||||
"aliases": [
|
||||
"CVE-2021-32690"
|
||||
|
||||
],
|
||||
"summary": "Helm passes repository credentials to alternate domain",
|
||||
"details": "Helm is a tool for managing Charts (packages of pre-configured Kubernetes resources). In versions of helm prior to 3.6.1, a vulnerability exists where the username and password credentials associated with a Helm repository could be passed on to another domain referenced by that Helm repository. This issue has been resolved in 3.6.1. There is a workaround through which one may check for improperly passed credentials. One may use a username and password for a Helm repository and may audit the Helm repository in order to check for another domain being used that could have received the credentials. In the `index.yaml` file for that repository, one may look for another domain in the `urls` list for the chart versions. If there is another domain found and that chart version was pulled or installed, the credentials would be passed on.",
|
||||
"summary": "Duplicate Advisory: Helm passes repository credentials to alternate domain",
|
||||
"details": "## Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-56hp-xqp3-w2jf. This link is maintained to preserve external references.\n\n## Original Description\nHelm is a tool for managing Charts (packages of pre-configured Kubernetes resources). In versions of helm prior to 3.6.1, a vulnerability exists where the username and password credentials associated with a Helm repository could be passed on to another domain referenced by that Helm repository. This issue has been resolved in 3.6.1. There is a workaround through which one may check for improperly passed credentials. One may use a username and password for a Helm repository and may audit the Helm repository in order to check for another domain being used that could have received the credentials. In the `index.yaml` file for that repository, one may look for another domain in the `urls` list for the chart versions. If there is another domain found and that chart version was pulled or installed, the credentials would be passed on.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-28r2-q6m8-9hpx",
|
||||
"modified": "2022-11-21T19:45:07Z",
|
||||
"modified": "2024-05-20T21:27:04Z",
|
||||
"published": "2022-05-26T00:01:27Z",
|
||||
"aliases": [
|
||||
"CVE-2022-30323"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-cjr4-fv6c-f3mv",
|
||||
"modified": "2022-11-21T19:45:28Z",
|
||||
"modified": "2024-05-20T21:26:59Z",
|
||||
"published": "2022-05-26T00:01:27Z",
|
||||
"aliases": [
|
||||
"CVE-2022-30322"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-p782-xgp4-8hr8",
|
||||
"modified": "2023-10-03T10:14:44Z",
|
||||
"modified": "2024-05-20T21:27:32Z",
|
||||
"published": "2022-06-24T00:00:30Z",
|
||||
"aliases": [
|
||||
"CVE-2022-29526"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-qpgx-64h2-gc3c",
|
||||
"modified": "2023-08-28T22:32:08Z",
|
||||
"modified": "2024-05-20T21:27:26Z",
|
||||
"published": "2022-06-17T01:03:47Z",
|
||||
"aliases": [
|
||||
"CVE-2022-25856"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-2m4x-4q9j-w97g",
|
||||
"modified": "2022-07-13T20:04:43Z",
|
||||
"modified": "2024-05-20T21:27:56Z",
|
||||
"published": "2022-07-01T00:01:03Z",
|
||||
"aliases": [
|
||||
"CVE-2022-33082"
|
||||
|
||||
Reference in New Issue
Block a user