From 1521cb3289c7c900fd042d153de4583f33909140 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 13 Feb 2025 19:29:07 +0000 Subject: [PATCH] Publish Advisories GHSA-2j39-qcjm-428w GHSA-6p62-6cg9-f5f5 GHSA-6x49-w35h-wqrj GHSA-95mg-jgfx-54v9 GHSA-97rv-88gf-phvr GHSA-g49j-j489-3xpf --- .../12/GHSA-2j39-qcjm-428w/GHSA-2j39-qcjm-428w.json | 4 ++-- .../12/GHSA-6p62-6cg9-f5f5/GHSA-6p62-6cg9-f5f5.json | 4 ++-- .../12/GHSA-6x49-w35h-wqrj/GHSA-6x49-w35h-wqrj.json | 13 +++++++++---- .../12/GHSA-95mg-jgfx-54v9/GHSA-95mg-jgfx-54v9.json | 12 ++++++++++-- .../12/GHSA-97rv-88gf-phvr/GHSA-97rv-88gf-phvr.json | 4 ++-- .../12/GHSA-g49j-j489-3xpf/GHSA-g49j-j489-3xpf.json | 4 ++-- 6 files changed, 27 insertions(+), 14 deletions(-) diff --git a/advisories/github-reviewed/2023/12/GHSA-2j39-qcjm-428w/GHSA-2j39-qcjm-428w.json b/advisories/github-reviewed/2023/12/GHSA-2j39-qcjm-428w/GHSA-2j39-qcjm-428w.json index 13502ec40c7..108823c4697 100644 --- a/advisories/github-reviewed/2023/12/GHSA-2j39-qcjm-428w/GHSA-2j39-qcjm-428w.json +++ b/advisories/github-reviewed/2023/12/GHSA-2j39-qcjm-428w/GHSA-2j39-qcjm-428w.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-2j39-qcjm-428w", - "modified": "2023-12-18T20:35:59Z", + "modified": "2025-02-13T19:28:02Z", "published": "2023-12-07T09:30:45Z", "aliases": [ "CVE-2023-50164" ], "summary": "Apache Struts vulnerable to path traversal", - "details": "An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remote Code Execution.\nUsers are recommended to upgrade to versions Struts 2.5.33 or Struts 6.3.0.2 or greater to fix this issue.\n", + "details": "An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remote Code Execution.\nUsers are recommended to upgrade to versions Struts 2.5.33 or Struts 6.3.0.2 or greater to fix this issue.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2023/12/GHSA-6p62-6cg9-f5f5/GHSA-6p62-6cg9-f5f5.json b/advisories/github-reviewed/2023/12/GHSA-6p62-6cg9-f5f5/GHSA-6p62-6cg9-f5f5.json index 8c6496e1abb..461bf184598 100644 --- a/advisories/github-reviewed/2023/12/GHSA-6p62-6cg9-f5f5/GHSA-6p62-6cg9-f5f5.json +++ b/advisories/github-reviewed/2023/12/GHSA-6p62-6cg9-f5f5/GHSA-6p62-6cg9-f5f5.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-6p62-6cg9-f5f5", - "modified": "2024-05-20T21:59:29Z", + "modified": "2025-02-13T19:28:18Z", "published": "2023-12-09T00:35:05Z", "aliases": [ "CVE-2023-6337" ], "summary": "Memory exhaustion in HashiCorp Vault", - "details": "HashiCorp Vault and Vault Enterprise 1.12.0 and newer are vulnerable to a denial of service through memory exhaustion of the host when handling large unauthenticated and authenticated HTTP requests from a client. Vault will attempt to map the request to memory, resulting in the exhaustion of available memory on the host, which may cause Vault to crash.\n\nFixed in Vault 1.15.4, 1.14.8, 1.13.12.\n\n", + "details": "HashiCorp Vault and Vault Enterprise 1.12.0 and newer are vulnerable to a denial of service through memory exhaustion of the host when handling large unauthenticated and authenticated HTTP requests from a client. Vault will attempt to map the request to memory, resulting in the exhaustion of available memory on the host, which may cause Vault to crash.\n\nFixed in Vault 1.15.4, 1.14.8, 1.13.12.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2023/12/GHSA-6x49-w35h-wqrj/GHSA-6x49-w35h-wqrj.json b/advisories/github-reviewed/2023/12/GHSA-6x49-w35h-wqrj/GHSA-6x49-w35h-wqrj.json index cf34e6a5bd4..bbdcc0b4dcb 100644 --- a/advisories/github-reviewed/2023/12/GHSA-6x49-w35h-wqrj/GHSA-6x49-w35h-wqrj.json +++ b/advisories/github-reviewed/2023/12/GHSA-6x49-w35h-wqrj/GHSA-6x49-w35h-wqrj.json @@ -1,14 +1,19 @@ { "schema_version": "1.4.0", "id": "GHSA-6x49-w35h-wqrj", - "modified": "2023-12-15T23:20:28Z", + "modified": "2025-02-13T19:28:23Z", "published": "2023-12-15T09:30:17Z", "aliases": [ "CVE-2023-29234" ], "summary": "Bypass serialize checks in Apache Dubbo", - "details": "A deserialization vulnerability existed when decode a malicious package.This issue affects Apache Dubbo: from 3.1.0 through 3.1.10, from 3.2.0 through 3.2.4.\n\nUsers are recommended to upgrade to the latest version, which fixes the issue.\n\n", - "severity": [], + "details": "A deserialization vulnerability existed when decode a malicious package.This issue affects Apache Dubbo: from 3.1.0 through 3.1.10, from 3.2.0 through 3.2.4.\n\nUsers are recommended to upgrade to the latest version, which fixes the issue.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [ { "package": { @@ -71,7 +76,7 @@ "cwe_ids": [ "CWE-502" ], - "severity": "HIGH", + "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2023-12-15T23:20:28Z", "nvd_published_at": "2023-12-15T09:15:07Z" diff --git a/advisories/github-reviewed/2023/12/GHSA-95mg-jgfx-54v9/GHSA-95mg-jgfx-54v9.json b/advisories/github-reviewed/2023/12/GHSA-95mg-jgfx-54v9/GHSA-95mg-jgfx-54v9.json index f996277262b..b8fc955695b 100644 --- a/advisories/github-reviewed/2023/12/GHSA-95mg-jgfx-54v9/GHSA-95mg-jgfx-54v9.json +++ b/advisories/github-reviewed/2023/12/GHSA-95mg-jgfx-54v9/GHSA-95mg-jgfx-54v9.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-95mg-jgfx-54v9", - "modified": "2024-06-28T16:19:13Z", + "modified": "2025-02-13T19:28:15Z", "published": "2023-12-19T12:30:19Z", "aliases": [ "CVE-2023-46104" ], "summary": "Apache Superset uncontrolled resource consumption", - "details": "Uncontrolled resource consumption can be triggered by authenticated attacker that uploads a malicious ZIP to import database, dashboards or datasets.  \nThis vulnerability exists in Apache Superset versions up to and including 2.1.2 and versions 3.0.0, 3.0.1.\n", + "details": "Uncontrolled resource consumption can be triggered by authenticated attacker that uploads a malicious ZIP to import database, dashboards or datasets.  \nThis vulnerability exists in Apache Superset versions up to and including 2.1.2 and versions 3.0.0, 3.0.1.", "severity": [ { "type": "CVSS_V3", @@ -78,6 +78,14 @@ { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2023/12/19/1" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/02/14/2" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/02/14/3" } ], "database_specific": { diff --git a/advisories/github-reviewed/2023/12/GHSA-97rv-88gf-phvr/GHSA-97rv-88gf-phvr.json b/advisories/github-reviewed/2023/12/GHSA-97rv-88gf-phvr/GHSA-97rv-88gf-phvr.json index ca01dc8142d..403f780120d 100644 --- a/advisories/github-reviewed/2023/12/GHSA-97rv-88gf-phvr/GHSA-97rv-88gf-phvr.json +++ b/advisories/github-reviewed/2023/12/GHSA-97rv-88gf-phvr/GHSA-97rv-88gf-phvr.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-97rv-88gf-phvr", - "modified": "2023-12-19T21:42:31Z", + "modified": "2025-02-13T19:28:14Z", "published": "2023-12-15T09:30:17Z", "aliases": [ "CVE-2023-46279" ], "summary": "Apache Dubbo: Bypass deny serialize list check in Apache Dubbo", - "details": "Deserialization of Untrusted Data vulnerability in Apache Dubbo.This issue only affects Apache Dubbo 3.1.5.\n\nUsers are recommended to upgrade to the latest version, which fixes the issue.\n\n", + "details": "Deserialization of Untrusted Data vulnerability in Apache Dubbo.This issue only affects Apache Dubbo 3.1.5.\n\nUsers are recommended to upgrade to the latest version, which fixes the issue.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2023/12/GHSA-g49j-j489-3xpf/GHSA-g49j-j489-3xpf.json b/advisories/github-reviewed/2023/12/GHSA-g49j-j489-3xpf/GHSA-g49j-j489-3xpf.json index 95df077feab..1e506054aaf 100644 --- a/advisories/github-reviewed/2023/12/GHSA-g49j-j489-3xpf/GHSA-g49j-j489-3xpf.json +++ b/advisories/github-reviewed/2023/12/GHSA-g49j-j489-3xpf/GHSA-g49j-j489-3xpf.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-g49j-j489-3xpf", - "modified": "2023-12-19T21:10:36Z", + "modified": "2025-02-13T19:28:17Z", "published": "2023-12-19T12:30:19Z", "aliases": [ "CVE-2023-49734" ], "summary": "Apache Superset incorrect write permissions vulnerability", - "details": "An authenticated Gamma user has the ability to create a dashboard and add charts to it, this user would automatically become one of the owners of the charts allowing him to incorrectly have write permissions to these charts.This issue affects Apache Superset: before 2.1.3, from 3.0.0 before 3.0.2.\n\nUsers are recommended to upgrade to version 3.0.2 or 2.1.3, which fixes the issue.\n\n", + "details": "An authenticated Gamma user has the ability to create a dashboard and add charts to it, this user would automatically become one of the owners of the charts allowing him to incorrectly have write permissions to these charts.This issue affects Apache Superset: before 2.1.3, from 3.0.0 before 3.0.2.\n\nUsers are recommended to upgrade to version 3.0.2 or 2.1.3, which fixes the issue.", "severity": [ { "type": "CVSS_V3",