From 105e70fcc33d1f9e59d1dc3cf3bcb70df7481038 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 20 May 2024 21:28:25 +0000 Subject: [PATCH] Publish Advisories GHSA-7jr6-prv4-5wf5 GHSA-28r2-q6m8-9hpx GHSA-cjr4-fv6c-f3mv GHSA-p782-xgp4-8hr8 GHSA-qpgx-64h2-gc3c GHSA-2m4x-4q9j-w97g --- .../2021/06/GHSA-7jr6-prv4-5wf5/GHSA-7jr6-prv4-5wf5.json | 9 +++++---- .../2022/05/GHSA-28r2-q6m8-9hpx/GHSA-28r2-q6m8-9hpx.json | 2 +- .../2022/05/GHSA-cjr4-fv6c-f3mv/GHSA-cjr4-fv6c-f3mv.json | 2 +- .../2022/06/GHSA-p782-xgp4-8hr8/GHSA-p782-xgp4-8hr8.json | 2 +- .../2022/06/GHSA-qpgx-64h2-gc3c/GHSA-qpgx-64h2-gc3c.json | 2 +- .../2022/07/GHSA-2m4x-4q9j-w97g/GHSA-2m4x-4q9j-w97g.json | 2 +- 6 files changed, 10 insertions(+), 9 deletions(-) diff --git a/advisories/github-reviewed/2021/06/GHSA-7jr6-prv4-5wf5/GHSA-7jr6-prv4-5wf5.json b/advisories/github-reviewed/2021/06/GHSA-7jr6-prv4-5wf5/GHSA-7jr6-prv4-5wf5.json index 0e46fd8ecc9..cc0a291a82a 100644 --- a/advisories/github-reviewed/2021/06/GHSA-7jr6-prv4-5wf5/GHSA-7jr6-prv4-5wf5.json +++ b/advisories/github-reviewed/2021/06/GHSA-7jr6-prv4-5wf5/GHSA-7jr6-prv4-5wf5.json @@ -1,13 +1,14 @@ { "schema_version": "1.4.0", "id": "GHSA-7jr6-prv4-5wf5", - "modified": "2023-08-30T10:26:47Z", + "modified": "2024-05-20T21:26:28Z", "published": "2021-06-23T18:14:31Z", + "withdrawn": "2024-05-20T21:26:28Z", "aliases": [ - "CVE-2021-32690" + ], - "summary": "Helm passes repository credentials to alternate domain", - "details": "Helm is a tool for managing Charts (packages of pre-configured Kubernetes resources). In versions of helm prior to 3.6.1, a vulnerability exists where the username and password credentials associated with a Helm repository could be passed on to another domain referenced by that Helm repository. This issue has been resolved in 3.6.1. There is a workaround through which one may check for improperly passed credentials. One may use a username and password for a Helm repository and may audit the Helm repository in order to check for another domain being used that could have received the credentials. In the `index.yaml` file for that repository, one may look for another domain in the `urls` list for the chart versions. If there is another domain found and that chart version was pulled or installed, the credentials would be passed on.", + "summary": "Duplicate Advisory: Helm passes repository credentials to alternate domain", + "details": "## Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-56hp-xqp3-w2jf. This link is maintained to preserve external references.\n\n## Original Description\nHelm is a tool for managing Charts (packages of pre-configured Kubernetes resources). In versions of helm prior to 3.6.1, a vulnerability exists where the username and password credentials associated with a Helm repository could be passed on to another domain referenced by that Helm repository. This issue has been resolved in 3.6.1. There is a workaround through which one may check for improperly passed credentials. One may use a username and password for a Helm repository and may audit the Helm repository in order to check for another domain being used that could have received the credentials. In the `index.yaml` file for that repository, one may look for another domain in the `urls` list for the chart versions. If there is another domain found and that chart version was pulled or installed, the credentials would be passed on.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2022/05/GHSA-28r2-q6m8-9hpx/GHSA-28r2-q6m8-9hpx.json b/advisories/github-reviewed/2022/05/GHSA-28r2-q6m8-9hpx/GHSA-28r2-q6m8-9hpx.json index 823d7af165d..7d87e4891a0 100644 --- a/advisories/github-reviewed/2022/05/GHSA-28r2-q6m8-9hpx/GHSA-28r2-q6m8-9hpx.json +++ b/advisories/github-reviewed/2022/05/GHSA-28r2-q6m8-9hpx/GHSA-28r2-q6m8-9hpx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-28r2-q6m8-9hpx", - "modified": "2022-11-21T19:45:07Z", + "modified": "2024-05-20T21:27:04Z", "published": "2022-05-26T00:01:27Z", "aliases": [ "CVE-2022-30323" diff --git a/advisories/github-reviewed/2022/05/GHSA-cjr4-fv6c-f3mv/GHSA-cjr4-fv6c-f3mv.json b/advisories/github-reviewed/2022/05/GHSA-cjr4-fv6c-f3mv/GHSA-cjr4-fv6c-f3mv.json index b19f69648ff..aff1095c8e6 100644 --- a/advisories/github-reviewed/2022/05/GHSA-cjr4-fv6c-f3mv/GHSA-cjr4-fv6c-f3mv.json +++ b/advisories/github-reviewed/2022/05/GHSA-cjr4-fv6c-f3mv/GHSA-cjr4-fv6c-f3mv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cjr4-fv6c-f3mv", - "modified": "2022-11-21T19:45:28Z", + "modified": "2024-05-20T21:26:59Z", "published": "2022-05-26T00:01:27Z", "aliases": [ "CVE-2022-30322" diff --git a/advisories/github-reviewed/2022/06/GHSA-p782-xgp4-8hr8/GHSA-p782-xgp4-8hr8.json b/advisories/github-reviewed/2022/06/GHSA-p782-xgp4-8hr8/GHSA-p782-xgp4-8hr8.json index e5aec78b387..55b329dea66 100644 --- a/advisories/github-reviewed/2022/06/GHSA-p782-xgp4-8hr8/GHSA-p782-xgp4-8hr8.json +++ b/advisories/github-reviewed/2022/06/GHSA-p782-xgp4-8hr8/GHSA-p782-xgp4-8hr8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p782-xgp4-8hr8", - "modified": "2023-10-03T10:14:44Z", + "modified": "2024-05-20T21:27:32Z", "published": "2022-06-24T00:00:30Z", "aliases": [ "CVE-2022-29526" diff --git a/advisories/github-reviewed/2022/06/GHSA-qpgx-64h2-gc3c/GHSA-qpgx-64h2-gc3c.json b/advisories/github-reviewed/2022/06/GHSA-qpgx-64h2-gc3c/GHSA-qpgx-64h2-gc3c.json index cdcb6ea3c17..958af694855 100644 --- a/advisories/github-reviewed/2022/06/GHSA-qpgx-64h2-gc3c/GHSA-qpgx-64h2-gc3c.json +++ b/advisories/github-reviewed/2022/06/GHSA-qpgx-64h2-gc3c/GHSA-qpgx-64h2-gc3c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qpgx-64h2-gc3c", - "modified": "2023-08-28T22:32:08Z", + "modified": "2024-05-20T21:27:26Z", "published": "2022-06-17T01:03:47Z", "aliases": [ "CVE-2022-25856" diff --git a/advisories/github-reviewed/2022/07/GHSA-2m4x-4q9j-w97g/GHSA-2m4x-4q9j-w97g.json b/advisories/github-reviewed/2022/07/GHSA-2m4x-4q9j-w97g/GHSA-2m4x-4q9j-w97g.json index d4ec90b1004..c8c71518fca 100644 --- a/advisories/github-reviewed/2022/07/GHSA-2m4x-4q9j-w97g/GHSA-2m4x-4q9j-w97g.json +++ b/advisories/github-reviewed/2022/07/GHSA-2m4x-4q9j-w97g/GHSA-2m4x-4q9j-w97g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2m4x-4q9j-w97g", - "modified": "2022-07-13T20:04:43Z", + "modified": "2024-05-20T21:27:56Z", "published": "2022-07-01T00:01:03Z", "aliases": [ "CVE-2022-33082"