Publish Advisories

GHSA-2qp4-g3q3-f92w
GHSA-78x2-cwp9-5j42
GHSA-3f84-rpwh-47g6
GHSA-9298-4cf8-g4wj
GHSA-qjvc-p88j-j9rm
This commit is contained in:
advisory-database[bot]
2024-10-29 20:01:18 +00:00
parent d98a5d71a5
commit 1f695edbaf
5 changed files with 31 additions and 10 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2qp4-g3q3-f92w",
"modified": "2022-06-20T22:37:38Z",
"modified": "2024-10-29T20:00:54Z",
"published": "2022-02-26T00:00:43Z",
"aliases": [
"CVE-2022-24329"
@@ -66,7 +66,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-667"
"CWE-667",
"CWE-829"
],
"severity": "MODERATE",
"github_reviewed": true,
@@ -1,13 +1,13 @@
{
"schema_version": "1.4.0",
"id": "GHSA-78x2-cwp9-5j42",
"modified": "2024-09-17T16:25:26Z",
"modified": "2024-10-29T20:00:41Z",
"published": "2024-08-20T20:04:49Z",
"aliases": [
"CVE-2024-43409"
],
"summary": "Ghost's improper authentication allows access to member information and actions",
"details": "### Impact\n\nImproper authentication on some endpoints used for member actions would allow an attacker to perform member-only actions, and read member information.\n\n### Vulnerable versions\n\nThis security vulnerability is present in Ghost v4.46.0-v5.89.5.\n\nGhost(Pro) customers are automatically updated to fixed versions ahead of disclosure.\n\nIf you're a self-hoster, please follow our [update instructions](https://ghost.org/docs/update).\n\n### Patches\n\nv5.89.5 contains a fix for this issue.\n\n### Workarounds\n\nNone.\n\n### For more information\n\nIf you have any questions or comments about this advisory:\n\n* Email us at [security@ghost.org](mailto:security@ghost.org)\n",
"details": "### Impact\n\nImproper authentication on some endpoints used for member actions would allow an attacker to perform member-only actions, and read member information.\n\n### Vulnerable versions\n\nThis security vulnerability is present in Ghost v4.46.0-v5.89.5.\n\nGhost(Pro) customers are automatically updated to fixed versions ahead of disclosure.\n\nIf you're a self-hoster, please follow our [update instructions](https://ghost.org/docs/update).\n\n### Patches\n\nv5.89.5 contains a fix for this issue.\n\n### Workarounds\n\nDisable site membership in Ghost settings.\n\n### For more information\n\nIf you have any questions or comments about this advisory:\n\n* Email us at [security@ghost.org](mailto:security@ghost.org)\n",
"severity": [
{
"type": "CVSS_V3",
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3f84-rpwh-47g6",
"modified": "2024-10-29T14:33:00Z",
"modified": "2024-10-29T20:00:26Z",
"published": "2024-10-29T14:33:00Z",
"aliases": [
"CVE-2024-49769"
@@ -44,6 +44,10 @@
"type": "WEB",
"url": "https://github.com/Pylons/waitress/security/advisories/GHSA-3f84-rpwh-47g6"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49769"
},
{
"type": "WEB",
"url": "https://github.com/Pylons/waitress/issues/418"
@@ -52,6 +56,10 @@
"type": "WEB",
"url": "https://github.com/Pylons/waitress/pull/435"
},
{
"type": "WEB",
"url": "https://github.com/Pylons/waitress/commit/1ae4e894c9f76543bee06584001583fc6fa8c95c"
},
{
"type": "PACKAGE",
"url": "https://github.com/Pylons/waitress"
@@ -64,6 +72,6 @@
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2024-10-29T14:33:00Z",
"nvd_published_at": null
"nvd_published_at": "2024-10-29T15:15:12Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9298-4cf8-g4wj",
"modified": "2024-10-29T14:45:03Z",
"modified": "2024-10-29T20:00:21Z",
"published": "2024-10-29T14:45:03Z",
"aliases": [
"CVE-2024-49768"
@@ -44,6 +44,10 @@
"type": "WEB",
"url": "https://github.com/Pylons/waitress/security/advisories/GHSA-9298-4cf8-g4wj"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49768"
},
{
"type": "WEB",
"url": "https://github.com/Pylons/waitress/commit/e4359018537af376cf24bd13616d861e2fb76f65"
@@ -61,6 +65,6 @@
"severity": "CRITICAL",
"github_reviewed": true,
"github_reviewed_at": "2024-10-29T14:45:03Z",
"nvd_published_at": null
"nvd_published_at": "2024-10-29T15:15:11Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qjvc-p88j-j9rm",
"modified": "2024-10-29T14:44:36Z",
"modified": "2024-10-29T20:00:12Z",
"published": "2024-10-29T14:44:36Z",
"aliases": [
"CVE-2024-48921"
@@ -9,6 +9,10 @@
"summary": "Kyverno's PolicyException objects can be created in any namespace by default",
"details": "### Summary\nA kyverno ClusterPolicy, ie. \"disallow-privileged-containers,\" can be overridden by the creation of a PolicyException in a random namespace.\n\n### Details\nBy design, PolicyExceptions are consumed from any namespace. Administrators may not recognize that this allows users with privileges to non-kyverno namespaces to create exceptions.\n\n### PoC\n1. Administrator creates \"disallow-privileged-containers\" ClusterPolicy that applies to resources in the namespace \"ubuntu-restricted\"\n2. Cluster user creates a PolicyException object for \"disallow-privileged-containers\" in namespace \"ubuntu-restricted\"\n3. Cluster user creates a pod with a privileged container in \"ubuntu-restricted\" \n4. Cluster user escalates to root on the node from the privileged container\n\n### Impact\nAdministrators attempting to enforce cluster security through kyverno policies, but that allow less privileged users to create resources",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"
@@ -40,6 +44,10 @@
"type": "WEB",
"url": "https://github.com/kyverno/kyverno/security/advisories/GHSA-qjvc-p88j-j9rm"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48921"
},
{
"type": "PACKAGE",
"url": "https://github.com/kyverno/kyverno"
@@ -52,6 +60,6 @@
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2024-10-29T14:44:36Z",
"nvd_published_at": null
"nvd_published_at": "2024-10-29T15:15:10Z"
}
}