diff --git a/advisories/github-reviewed/2022/02/GHSA-2qp4-g3q3-f92w/GHSA-2qp4-g3q3-f92w.json b/advisories/github-reviewed/2022/02/GHSA-2qp4-g3q3-f92w/GHSA-2qp4-g3q3-f92w.json index c659c23cd26..79eaf8809ec 100644 --- a/advisories/github-reviewed/2022/02/GHSA-2qp4-g3q3-f92w/GHSA-2qp4-g3q3-f92w.json +++ b/advisories/github-reviewed/2022/02/GHSA-2qp4-g3q3-f92w/GHSA-2qp4-g3q3-f92w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2qp4-g3q3-f92w", - "modified": "2022-06-20T22:37:38Z", + "modified": "2024-10-29T20:00:54Z", "published": "2022-02-26T00:00:43Z", "aliases": [ "CVE-2022-24329" @@ -66,7 +66,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-667" + "CWE-667", + "CWE-829" ], "severity": "MODERATE", "github_reviewed": true, diff --git a/advisories/github-reviewed/2024/08/GHSA-78x2-cwp9-5j42/GHSA-78x2-cwp9-5j42.json b/advisories/github-reviewed/2024/08/GHSA-78x2-cwp9-5j42/GHSA-78x2-cwp9-5j42.json index e13fed038e9..2a4df79cd6c 100644 --- a/advisories/github-reviewed/2024/08/GHSA-78x2-cwp9-5j42/GHSA-78x2-cwp9-5j42.json +++ b/advisories/github-reviewed/2024/08/GHSA-78x2-cwp9-5j42/GHSA-78x2-cwp9-5j42.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-78x2-cwp9-5j42", - "modified": "2024-09-17T16:25:26Z", + "modified": "2024-10-29T20:00:41Z", "published": "2024-08-20T20:04:49Z", "aliases": [ "CVE-2024-43409" ], "summary": "Ghost's improper authentication allows access to member information and actions", - "details": "### Impact\n\nImproper authentication on some endpoints used for member actions would allow an attacker to perform member-only actions, and read member information.\n\n### Vulnerable versions\n\nThis security vulnerability is present in Ghost v4.46.0-v5.89.5.\n\nGhost(Pro) customers are automatically updated to fixed versions ahead of disclosure.\n\nIf you're a self-hoster, please follow our [update instructions](https://ghost.org/docs/update).\n\n### Patches\n\nv5.89.5 contains a fix for this issue.\n\n### Workarounds\n\nNone.\n\n### For more information\n\nIf you have any questions or comments about this advisory:\n\n* Email us at [security@ghost.org](mailto:security@ghost.org)\n", + "details": "### Impact\n\nImproper authentication on some endpoints used for member actions would allow an attacker to perform member-only actions, and read member information.\n\n### Vulnerable versions\n\nThis security vulnerability is present in Ghost v4.46.0-v5.89.5.\n\nGhost(Pro) customers are automatically updated to fixed versions ahead of disclosure.\n\nIf you're a self-hoster, please follow our [update instructions](https://ghost.org/docs/update).\n\n### Patches\n\nv5.89.5 contains a fix for this issue.\n\n### Workarounds\n\nDisable site membership in Ghost settings.\n\n### For more information\n\nIf you have any questions or comments about this advisory:\n\n* Email us at [security@ghost.org](mailto:security@ghost.org)\n", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2024/10/GHSA-3f84-rpwh-47g6/GHSA-3f84-rpwh-47g6.json b/advisories/github-reviewed/2024/10/GHSA-3f84-rpwh-47g6/GHSA-3f84-rpwh-47g6.json index 3e1138353ff..b20955efc8e 100644 --- a/advisories/github-reviewed/2024/10/GHSA-3f84-rpwh-47g6/GHSA-3f84-rpwh-47g6.json +++ b/advisories/github-reviewed/2024/10/GHSA-3f84-rpwh-47g6/GHSA-3f84-rpwh-47g6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3f84-rpwh-47g6", - "modified": "2024-10-29T14:33:00Z", + "modified": "2024-10-29T20:00:26Z", "published": "2024-10-29T14:33:00Z", "aliases": [ "CVE-2024-49769" @@ -44,6 +44,10 @@ "type": "WEB", "url": "https://github.com/Pylons/waitress/security/advisories/GHSA-3f84-rpwh-47g6" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49769" + }, { "type": "WEB", "url": "https://github.com/Pylons/waitress/issues/418" @@ -52,6 +56,10 @@ "type": "WEB", "url": "https://github.com/Pylons/waitress/pull/435" }, + { + "type": "WEB", + "url": "https://github.com/Pylons/waitress/commit/1ae4e894c9f76543bee06584001583fc6fa8c95c" + }, { "type": "PACKAGE", "url": "https://github.com/Pylons/waitress" @@ -64,6 +72,6 @@ "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2024-10-29T14:33:00Z", - "nvd_published_at": null + "nvd_published_at": "2024-10-29T15:15:12Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2024/10/GHSA-9298-4cf8-g4wj/GHSA-9298-4cf8-g4wj.json b/advisories/github-reviewed/2024/10/GHSA-9298-4cf8-g4wj/GHSA-9298-4cf8-g4wj.json index 77d2f0a06a9..c5639817eb9 100644 --- a/advisories/github-reviewed/2024/10/GHSA-9298-4cf8-g4wj/GHSA-9298-4cf8-g4wj.json +++ b/advisories/github-reviewed/2024/10/GHSA-9298-4cf8-g4wj/GHSA-9298-4cf8-g4wj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9298-4cf8-g4wj", - "modified": "2024-10-29T14:45:03Z", + "modified": "2024-10-29T20:00:21Z", "published": "2024-10-29T14:45:03Z", "aliases": [ "CVE-2024-49768" @@ -44,6 +44,10 @@ "type": "WEB", "url": "https://github.com/Pylons/waitress/security/advisories/GHSA-9298-4cf8-g4wj" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49768" + }, { "type": "WEB", "url": "https://github.com/Pylons/waitress/commit/e4359018537af376cf24bd13616d861e2fb76f65" @@ -61,6 +65,6 @@ "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2024-10-29T14:45:03Z", - "nvd_published_at": null + "nvd_published_at": "2024-10-29T15:15:11Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2024/10/GHSA-qjvc-p88j-j9rm/GHSA-qjvc-p88j-j9rm.json b/advisories/github-reviewed/2024/10/GHSA-qjvc-p88j-j9rm/GHSA-qjvc-p88j-j9rm.json index 38292245608..2f6802cb86d 100644 --- a/advisories/github-reviewed/2024/10/GHSA-qjvc-p88j-j9rm/GHSA-qjvc-p88j-j9rm.json +++ b/advisories/github-reviewed/2024/10/GHSA-qjvc-p88j-j9rm/GHSA-qjvc-p88j-j9rm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qjvc-p88j-j9rm", - "modified": "2024-10-29T14:44:36Z", + "modified": "2024-10-29T20:00:12Z", "published": "2024-10-29T14:44:36Z", "aliases": [ "CVE-2024-48921" @@ -9,6 +9,10 @@ "summary": "Kyverno's PolicyException objects can be created in any namespace by default", "details": "### Summary\nA kyverno ClusterPolicy, ie. \"disallow-privileged-containers,\" can be overridden by the creation of a PolicyException in a random namespace.\n\n### Details\nBy design, PolicyExceptions are consumed from any namespace. Administrators may not recognize that this allows users with privileges to non-kyverno namespaces to create exceptions.\n\n### PoC\n1. Administrator creates \"disallow-privileged-containers\" ClusterPolicy that applies to resources in the namespace \"ubuntu-restricted\"\n2. Cluster user creates a PolicyException object for \"disallow-privileged-containers\" in namespace \"ubuntu-restricted\"\n3. Cluster user creates a pod with a privileged container in \"ubuntu-restricted\" \n4. Cluster user escalates to root on the node from the privileged container\n\n### Impact\nAdministrators attempting to enforce cluster security through kyverno policies, but that allow less privileged users to create resources", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N" @@ -40,6 +44,10 @@ "type": "WEB", "url": "https://github.com/kyverno/kyverno/security/advisories/GHSA-qjvc-p88j-j9rm" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48921" + }, { "type": "PACKAGE", "url": "https://github.com/kyverno/kyverno" @@ -52,6 +60,6 @@ "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2024-10-29T14:44:36Z", - "nvd_published_at": null + "nvd_published_at": "2024-10-29T15:15:10Z" } } \ No newline at end of file