Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2024-12-02 05:16:30 +00:00
parent 71feb077fc
commit 1d2f40d2c8
889 changed files with 1748 additions and 5244 deletions
@@ -8,9 +8,7 @@
],
"summary": "Cross-Site Scripting in emojione",
"details": "Affected versions of `emojione` are vulnerable to cross-site scripting when user input is passed into the `toShort()`, `shortnameToImage()`, `unicodeToImage()`, and `toImage()` functions.\n\n\n\n## Recommendation\n\nUpdate to version 1.3.1 or later.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -8,9 +8,7 @@
],
"summary": "pullit vulnerable to command injection",
"details": "Versions of `pullit` prior to 1.4.0 are vulnerable to Command Injection. The package does not validate input on git branch names and concatenates it to an exec call, allowing attackers to run arbitrary commands in the system.\n\n## Recommendation\n\nUpgrade to version 1.4.0 or later.\n\n## Credits\n\nThis vulnerability was discovered by @lirantal",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -3,14 +3,10 @@
"id": "GHSA-243q-g9j3-qf6r",
"modified": "2021-06-24T19:31:03Z",
"published": "2021-06-28T18:21:01Z",
"aliases": [
],
"aliases": [],
"summary": "non-admin users can create integration role with administrator role",
"details": "### Impact\nnon-admin users can create integration role with administrator role\n\n### Patches\nWe recommend updating to the current version 6.4.1.1. You can get the update to 6.4.1.1 regularly via the Auto-Updater or directly via the download overview.\n\nhttps://www.shopware.com/en/download/#shopware-6\n\n### Workarounds\nFor older versions of 6.1, 6.2, and 6.3 corresponding security measures are also available via a plugin. For the full range of functions, we recommend updating to the latest Shopware version.\n\nhttps://store.shopware.com/en/detail/index/sArticle/518463/number/Swag136939272659\n",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -64,9 +60,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2021-06-24T19:31:03Z",
@@ -3,9 +3,7 @@
"id": "GHSA-6rg3-8h8x-5xfv",
"modified": "2021-10-05T17:24:11Z",
"published": "2021-06-23T18:04:50Z",
"aliases": [
],
"aliases": [],
"summary": "Unchecked hostname resolution could allow access to local network resources by users outside the local network",
"details": "### Impact\nA newly implemented route allowing users to download files from remote endpoints was not properly verifying the destination hostname for user provided URLs. This would allow malicious users to potentially access resources on local networks that would otherwise be inaccessible.\n\nThis vulnerability requires valid authentication credentials and is therefore **not exploitable by unauthenticated users**. If you are running an instance for yourself or other trusted individuals this impact is unlikely to be of major concern to you. However, you should still upgrade for security sake.\n\n### Patches\nUsers should upgrade to the latest version of Wings.\n\n### Workarounds\nThere is no workaround available that does not involve modifying Panel or Wings code.\n",
"severity": [
@@ -3,9 +3,7 @@
"id": "GHSA-7r96-8g3x-g36m",
"modified": "2022-01-04T19:36:52Z",
"published": "2021-06-28T17:16:56Z",
"aliases": [
],
"aliases": [],
"summary": "Improper Verification of Cryptographic Signature",
"details": "### Impact\nThe `verifyWithMessage` method of `tEnvoyNaClSigningKey` always returns `true` for any signature of a SHA-512 hash matching the SHA-512 hash of the message even if the signature is invalid.\n\n### Patches\nUpgrade to `v7.0.3` immediately to resolve this issue. Since the vulnerability lies within the verification method, the previous signatures are still valid. We highly recommend reverifying any signatures that were previously verified with the vulnerable `verifyWithMessage` method.\n\n### Workarounds\nIn `tenvoy.js` under the `verifyWithMessage` method definition within the `tEnvoyNaClSigningKey` class, ensure that the return statement call to `this.verify` ends in `.verified`. For example, the return statement should start with `return this.verify(signed, password).verified && ` instead of `return this.verify(signed, password) && `.\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in [github.com/TogaTech/tEnvoy](https://github.com/TogaTech/tEnvoy)\n",
"severity": [
@@ -3,9 +3,7 @@
"id": "GHSA-8vfw-v2jv-9hwc",
"modified": "2021-06-24T19:39:30Z",
"published": "2021-06-28T16:52:45Z",
"aliases": [
],
"aliases": [],
"summary": "Reflected cross-site scripting in development mode handler in Vaadin",
"details": "URL encoding error in development mode handler in `com.vaadin:flow-server` versions 2.0.0 through 2.6.1 (Vaadin 14.0.0 through 14.6.1), 3.0.0 through 6.0.9 (Vaadin 15.0.0 through 19.0.8) allows local user to execute arbitrary JavaScript code by opening crafted URL in browser.\n\n- https://vaadin.com/security/cve-2021-33604",
"severity": [
@@ -3,14 +3,10 @@
"id": "GHSA-g7w8-pp9w-7p32",
"modified": "2021-10-05T17:26:03Z",
"published": "2021-06-28T16:57:32Z",
"aliases": [
],
"aliases": [],
"summary": "Creation of order credits was not validated by acl in admin orders",
"details": "### Impact\nCreation of order credits was not validated by ACL in admin orders\n\n### Patches\nWe recommend updating to the current version 6.4.1.1. You can get the update to 6.4.1.1 regularly via the Auto-Updater or directly via the download overview.\n\nhttps://www.shopware.com/en/download/#shopware-6\n\n### Workarounds\nFor older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available via a plugin. For the full range of functions, we recommend updating to the latest Shopware version.\n\nhttps://store.shopware.com/en/detail/index/sArticle/518463/number/Swag136939272659",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -3,14 +3,10 @@
"id": "GHSA-gpmh-g94g-qrhr",
"modified": "2021-06-24T19:20:56Z",
"published": "2021-06-28T18:20:53Z",
"aliases": [
],
"aliases": [],
"summary": "Internal hidden fields are visible on to many associations in admin api",
"details": "### Impact\nThe admin api has exposed some internal hidden fields when an association has been loaded with a to many reference\n\n### Patches\nWe recommend updating to the current version 6.4.1.1. You can get the update to 6.4.1.1 regularly via the Auto-Updater or directly via the download overview.\n\nhttps://www.shopware.com/en/download/#shopware-6\n\n### Workarounds\nFor older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available via a plugin. For the full range of functions, we recommend updating to the latest Shopware version.\n\nhttps://store.shopware.com/en/detail/index/sArticle/518463/number/Swag136939272659\n",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -64,9 +60,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2021-06-24T19:20:56Z",
File diff suppressed because one or more lines are too long
@@ -3,9 +3,7 @@
"id": "GHSA-vrf2-xghr-j52v",
"modified": "2021-10-05T17:26:41Z",
"published": "2021-06-28T18:20:42Z",
"aliases": [
],
"aliases": [],
"summary": "Private files publicly accessible with Cloud Storage providers",
"details": "### Impact\n\nPrivate files publicly accessible with Cloud Storage providers when the hashed URL is known\n\n### Patches\n\nWe recommend first changing your configuration to set the correct visibility according to the documentation. The visibility must be at the same level as `type`.\n\nWhen the Storage is saved on Amazon AWS we recommending disabling public access to the bucket containing the private files: https://docs.aws.amazon.com/AmazonS3/latest/userguide/access-control-block-public-access.html\n\nOtherwise, update to Shopware 6.4.1.1 or install or update the Security plugin (https://store.shopware.com/en/detail/index/sArticle/518463/number/Swag136939272659) and run the command `./bin/console s3:set-visibility` to correct your cloud file visibilities \n",
"severity": [
@@ -3,14 +3,10 @@
"id": "GHSA-wq3r-jwrq-xg6w",
"modified": "2021-06-24T18:04:47Z",
"published": "2021-06-28T16:57:23Z",
"aliases": [
],
"aliases": [],
"summary": "Canceling of orders not related to the logged-in user",
"details": "### Impact\nCanceling of orders not related to the logged-in user\n\n### Patches\nWe recommend updating to the current version 6.4.1.1. You can get the update to 6.4.1.1 regularly via the Auto-Updater or directly via the download overview.\n\nhttps://www.shopware.com/en/download/#shopware-6\n\n### Workarounds\nFor older versions of 6.1, 6.2, and 6.3, corresponding security measures are also available via a plugin. For the full range of functions, we recommend updating to the latest Shopware version.\n\nhttps://store.shopware.com/en/detail/index/sArticle/518463/number/Swag136939272659\n",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -72,9 +68,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2021-06-24T18:04:47Z",
@@ -3,9 +3,7 @@
"id": "GHSA-7qfm-6m33-rgg9",
"modified": "2021-06-28T19:08:40Z",
"published": "2021-08-13T15:21:59Z",
"aliases": [
],
"aliases": [],
"summary": "XML External Entity Reference",
"details": "An issue was discovered in service-api before 4.3.12 and 5.x before 5.1.1 for Report Portal. It allows XXE, with resultant secrets disclosure and SSRF, via JUnit XML launch import.",
"severity": [
@@ -3,14 +3,10 @@
"id": "GHSA-rc7p-gmvh-xfx2",
"modified": "2021-08-02T17:18:32Z",
"published": "2021-08-02T17:19:52Z",
"aliases": [
],
"aliases": [],
"summary": "Attack on Kubernetes via Misconfigured Argo Workflows",
"details": "### Impact\n\nUsers running using the Argo Server with `--auth-mode=server` (which is the default < v3.0.0) AND have exposed their UI to the Internet may allow remote users to execute arbitrary code on their cluster, e.g. crypto-mining.\n\n### Resolution\n\n* Do not expose your user interface to the Internet. \n* Change configuration. `--auth-mode=client`. \n\nFor users using an older 2.x version of Argo Server, consider upgrading to Argo Server version 3.x or later.\n",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -43,9 +39,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2021-07-22T20:25:42Z",
@@ -8,9 +8,7 @@
],
"summary": "Access Restriction Bypass in Docker",
"details": "Docker 1.3.0 through 1.3.1 allows remote attackers to modify the default run profile of image containers and possibly bypass the container by applying unspecified security options to an image.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -3,14 +3,10 @@
"id": "GHSA-57q7-rxqq-7vgp",
"modified": "2021-05-18T21:39:10Z",
"published": "2022-02-15T01:57:18Z",
"aliases": [
],
"aliases": [],
"summary": "On Windows, `git-sizer` might run a `git` executable within the repository being analyzed",
"details": "### Impact\nOn Windows, if `git-sizer` is run against a non-bare repository, and that repository has an executable called `git.exe`, `git.bat`, etc., then that executable might be run by `git-sizer` rather than the system `git` executable. An attacker could try to use social engineering to get a victim to run `git-sizer` against a hostile repository and thereby get the victim to run arbitrary code.\n\nOn Linux or other Unix-derived platforms, a similar problem could occur if the user's `PATH` has the current directory before the path to the standard `git` executable, but this is would be a very unusual configuration that has been known for decades to lead to all kinds of security problems.\n\n### Patches\nUsers should update to git-sizer v1.4.0\n\n### Workarounds\nIf you are on Windows, then either\n* Don't run `git-sizer` against a repository that might contain hostile code, or, if you must…\n* Run `git-sizer` against a bare clone of the hostile repository, or, if that is not possible…\n* Make sure that the hostile repository doesn't have an executable in its top-level directory before running `git-sizer`.\n\nIf you are on Linux or other Unix-based system, then (for myriad reasons!) don't add the current directory to your `PATH`.\n\n### References\n* [Command PATH security in Go](https://blog.golang.org/path-security)\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in [the `git-sizer` project](https://github.com/github/git-sizer).\n* Email us at [GitHub support](mailto:support@github.com).",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -46,9 +42,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2021-05-18T21:39:10Z",
@@ -3,9 +3,7 @@
"id": "GHSA-fm35-jgg3-3grx",
"modified": "2022-03-18T17:54:38Z",
"published": "2022-03-18T17:54:38Z",
"aliases": [
],
"aliases": [],
"summary": "NaN/INF in serverbound movement packets can crash clients and servers",
"details": "### Impact\nA malicious client may send a `MovePlayerPacket` to the server whose position or rotation contains NaN or INF. Since neither the server nor vanilla client handles this properly, a number of interesting side effects come into play.\n\n- The server may crash in various ways if this exploit is used, because some mathematical operations on NaN/INF generate PHP warnings, which are converted into exceptions.\n- Clients may not be able to see other clients who have a NaN/INF rotation.\n- Clients may also crash in such cases.\n\n### Patches\nA patch for this was included in the 3.18.1 release: https://github.com/pmmp/PocketMine-MP/commit/fb20bb38327b4c08ee3976640cd0dd547388a638\n\n### Workarounds\nWorkarounds could be implemented as plugins using `DataPacketReceiveEvent` to block any inbound movement packets containing bogus values.\n\n### For more information\nIf you have any questions or comments about this advisory:\n\n- Open an issue in [pmmp/PocketMine-MP](https://github.com/pmmp/PocketMine-MP)\n- Email us at [team@pmmp.io](mailto:team@pmmp.io)",
"severity": [
@@ -8,9 +8,7 @@
],
"summary": "Robocode Arbitrary Code Execution",
"details": "The Event Dispatch Thread in Robocode before 1.5.1 allows remote attackers to execute arbitrary Java code by using a robot to invoke the `SwingUtilities.invokeLater` method.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -3,9 +3,7 @@
"id": "GHSA-8cwq-4cmf-px73",
"modified": "2022-08-18T19:19:21Z",
"published": "2022-08-18T19:19:21Z",
"aliases": [
],
"aliases": [],
"summary": "PocketMine-MP invalid skin geometry JSON data leading to server crash",
"details": "### Impact\n`pocketmine\\entity\\Skin` doesn't correctly handle errors produced by `adhocore/json-comment`, which throws `RuntimeException` rather than returning `false` as PocketMine-MP expects.\n\nThis leads to a server crash if the skin geometry data is invalid for some reason (e.g. a syntax error).\n\n### Patches\nc9626c610b8f6810c8c987559c9197b2a291f0bb\n\n### Workarounds\nA plugin could handle `LoginPacket` and `PlayerSkinPacket` to verify the skin geometry data can be parsed correctly, so that the error condition in the core code is never reached.\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Email us at [security@pmmp.io](mailto:security@example.com)\n",
"severity": [
@@ -50,9 +48,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2022-08-18T19:19:21Z",
@@ -4,9 +4,7 @@
"modified": "2022-09-23T16:29:56Z",
"published": "2022-09-02T00:01:02Z",
"withdrawn": "2022-09-23T16:29:56Z",
"aliases": [
],
"aliases": [],
"summary": "Duplicate Advisory: Keycloak vulnerable to Cross-Site Scripting (XSS)",
"details": "## Duplicate Advisory\nThis advisory is a duplicate of [GHSA-w9mf-83w3-fv49](https://github.com/advisories/GHSA-w9mf-83w3-fv49). This link is maintained to preserve external references.\n\n## Original Description\nA stored Cross-site scripting (XSS) vulnerability was found in keycloak as shipped in Red Hat Single Sign-On 7. This flaw allows a privileged attacker to execute malicious scripts in the admin console, abusing the default roles functionality.",
"severity": [
@@ -3,9 +3,7 @@
"id": "GHSA-468j-6jrc-2rjx",
"modified": "2024-05-27T19:09:53Z",
"published": "2024-05-27T19:09:53Z",
"aliases": [
],
"aliases": [],
"summary": "silverstripe/framework vulnerable to Cross-site Scripting In `OptionsetField` and `CheckboxSetField`",
"details": "List of key / value pairs assigned to `OptionsetField` or `CheckboxSetField` do not have a default casting assigned to them. The effect of this is a potential XSS vulnerability in lists where either key or value contain unescaped HTML.\n\n",
"severity": [

Some files were not shown because too many files have changed in this diff Show More