diff --git a/advisories/github-reviewed/2024/01/GHSA-5h86-8mv2-jq9f/GHSA-5h86-8mv2-jq9f.json b/advisories/github-reviewed/2024/01/GHSA-5h86-8mv2-jq9f/GHSA-5h86-8mv2-jq9f.json index d62bd8d45e3..18187b7a44e 100644 --- a/advisories/github-reviewed/2024/01/GHSA-5h86-8mv2-jq9f/GHSA-5h86-8mv2-jq9f.json +++ b/advisories/github-reviewed/2024/01/GHSA-5h86-8mv2-jq9f/GHSA-5h86-8mv2-jq9f.json @@ -60,6 +60,10 @@ "type": "PACKAGE", "url": "https://github.com/aio-libs/aiohttp" }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/aiohttp/PYSEC-2024-24.yaml" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XXWVZIVAYWEBHNRIILZVB3R3SDQNNAA7/" diff --git a/advisories/github-reviewed/2024/01/GHSA-6p78-f7h9-6838/GHSA-6p78-f7h9-6838.json b/advisories/github-reviewed/2024/01/GHSA-6p78-f7h9-6838/GHSA-6p78-f7h9-6838.json index 9802d912477..f16a006ecde 100644 --- a/advisories/github-reviewed/2024/01/GHSA-6p78-f7h9-6838/GHSA-6p78-f7h9-6838.json +++ b/advisories/github-reviewed/2024/01/GHSA-6p78-f7h9-6838/GHSA-6p78-f7h9-6838.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6p78-f7h9-6838", - "modified": "2024-01-30T18:42:48Z", + "modified": "2024-02-05T23:06:18Z", "published": "2024-01-30T09:30:34Z", "aliases": [ "CVE-2023-36260" @@ -9,7 +9,10 @@ "summary": "Craft CMS Feed-Me", "details": "An issue discovered in Craft CMS version 4.6.1.1 allows remote attackers to cause a denial of service (DoS) via crafted string to Feed-Me Name and Feed-Me URL fields due to saving a feed using an Asset element type with no volume selected.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ { @@ -41,6 +44,10 @@ "type": "WEB", "url": "https://github.com/craftcms/feed-me/commit/b5d6ede51848349bd91bc95fec288b6793f15e28" }, + { + "type": "WEB", + "url": "https://github.com/craftcms/feed-me/commit/b5d6ede51848349bd91bc95fec288b6793f15e28%29" + }, { "type": "PACKAGE", "url": "https://github.com/craftcms/feed-me" @@ -56,9 +63,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-74" ], - "severity": "MODERATE", + "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2024-01-30T18:42:48Z", "nvd_published_at": "2024-01-30T09:15:47Z" diff --git a/advisories/github-reviewed/2024/01/GHSA-v89q-c273-3p42/GHSA-v89q-c273-3p42.json b/advisories/github-reviewed/2024/01/GHSA-v89q-c273-3p42/GHSA-v89q-c273-3p42.json index d8660812c5a..d53cf9d7101 100644 --- a/advisories/github-reviewed/2024/01/GHSA-v89q-c273-3p42/GHSA-v89q-c273-3p42.json +++ b/advisories/github-reviewed/2024/01/GHSA-v89q-c273-3p42/GHSA-v89q-c273-3p42.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v89q-c273-3p42", - "modified": "2024-01-30T18:42:40Z", + "modified": "2024-02-05T23:06:29Z", "published": "2024-01-30T09:30:34Z", "aliases": [ "CVE-2023-36259" @@ -9,7 +9,10 @@ "summary": "Craft CMS Audit Plugin Cross Site Scripting vulnerability", "details": "Cross Site Scripting (XSS) vulnerability in Craft CMS Audit Plugin before version 3.0.2 allows attackers to execute arbitrary code during user creation.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } ], "affected": [ { @@ -56,7 +59,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": true, diff --git a/advisories/github-reviewed/2024/02/GHSA-6845-xw22-ffxv/GHSA-6845-xw22-ffxv.json b/advisories/github-reviewed/2024/02/GHSA-6845-xw22-ffxv/GHSA-6845-xw22-ffxv.json index ed7aec0c9c2..045c42009f7 100644 --- a/advisories/github-reviewed/2024/02/GHSA-6845-xw22-ffxv/GHSA-6845-xw22-ffxv.json +++ b/advisories/github-reviewed/2024/02/GHSA-6845-xw22-ffxv/GHSA-6845-xw22-ffxv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6845-xw22-ffxv", - "modified": "2024-02-05T19:21:52Z", + "modified": "2024-02-05T23:06:50Z", "published": "2024-02-05T19:21:52Z", "aliases": [ "CVE-2024-24559" @@ -9,7 +9,10 @@ "summary": "Vyper sha3 codegen bug", "details": "### Summary\nThere is an error in the stack management when compiling the `IR` for `sha3_64`. Concretely, the `height` variable is miscalculated.\nThe vulnerability can't be triggered without writing the `IR` by hand. That is, it cannot be triggered from regular vyper code, it can only be triggered by using the `fang` binary directly (this binary used to be called `vyper-ir` prior to v0.3.4).\n\n### Details\nTo compile `sha3_64`, the `arg[0]` and `arg[1]` have to be compiled:\nhttps://github.com/vyperlang/vyper/blob/c150fc49ee9375a930d177044559b83cb95f7963/vyper/ir/compile_ir.py#L585-L586\n\nAs can be seen, after compiling the 0th arg, the `height` variable isn't increased. If new `withargs` are defined in the inner scope, they are manipulated correctly, because both their `height` is off and also the global `height` is off and thus their placement on the stack is computed correctly.\n\n`sha3_64` is used for retrieval in mappings. No flow that would cache the `key` was found, the issue shouldn't be possible to trigger when compiling the compiler-generated `IR`.\n\n### PoC\nSuppose the following hand-written IR:\n```lisp\n(with _loc\n\t(with val 1 \n\t\t(with key 2 \n\t\t\t(sha3_64 val key))) \n\t\t\t\t(seq \n\t\t\t\t\t(sstore _loc \n\t\t\t\t\t(with x (sload _loc) \n\t\t\t\t\t\t(with ans (add x 1) (seq (assert (ge ans x)) ans))))))\n```\nafter compilation:\n```\nthe generated bytecode: 6001600281806020525f5260405f2090509050805460018101818110610026579050815550005b5f80fd\n\n0000 60 PUSH1 0x01\n0002 60 PUSH1 0x02\n0004 81 DUP2\n0005 80 DUP1 *********** bad code here!!!!!!\n0006 60 PUSH1 0x20\n0008 52 MSTORE\n```\n\nIt can be seen that the second `DUP` will dup the item on the top of the stack which is incorrect.\n\n### Impact\nVersions v0.2.0-v0.3.10 were evaluated, and access of the variable with the invalid height is not reachable from IR generated by the vyper front-end. Because the issue isn't triggered during normal compilation of vyper code, the impact is considered low.\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ { @@ -37,6 +40,10 @@ "type": "WEB", "url": "https://github.com/vyperlang/vyper/security/advisories/GHSA-6845-xw22-ffxv" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24559" + }, { "type": "PACKAGE", "url": "https://github.com/vyperlang/vyper" @@ -48,11 +55,11 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-327" ], "severity": "LOW", "github_reviewed": true, "github_reviewed_at": "2024-02-05T19:21:52Z", - "nvd_published_at": null + "nvd_published_at": "2024-02-05T21:15:12Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2024/02/GHSA-vh73-q3rw-qx7w/GHSA-vh73-q3rw-qx7w.json b/advisories/github-reviewed/2024/02/GHSA-vh73-q3rw-qx7w/GHSA-vh73-q3rw-qx7w.json similarity index 63% rename from advisories/unreviewed/2024/02/GHSA-vh73-q3rw-qx7w/GHSA-vh73-q3rw-qx7w.json rename to advisories/github-reviewed/2024/02/GHSA-vh73-q3rw-qx7w/GHSA-vh73-q3rw-qx7w.json index 7b2f6c0810f..dbbc49601b2 100644 --- a/advisories/unreviewed/2024/02/GHSA-vh73-q3rw-qx7w/GHSA-vh73-q3rw-qx7w.json +++ b/advisories/github-reviewed/2024/02/GHSA-vh73-q3rw-qx7w/GHSA-vh73-q3rw-qx7w.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-vh73-q3rw-qx7w", - "modified": "2024-02-05T21:30:31Z", + "modified": "2024-02-05T23:06:56Z", "published": "2024-02-05T21:30:31Z", "aliases": [ "CVE-2024-1052" ], + "summary": "Boundary vulnerable to session hijacking through TLS certificate tampering", "details": "Boundary and Boundary Enterprise (“Boundary”) is vulnerable to session hijacking through TLS certificate tampering. An attacker with privileges to enumerate active or pending sessions, obtain a private key pertaining to a session, and obtain a valid trust on first use (TOFU) token may craft a TLS certificate to hijack an active session and gain access to the underlying service or application.", "severity": [ { @@ -14,7 +15,25 @@ } ], "affected": [ - + { + "package": { + "ecosystem": "Go", + "name": "github.com/hashicorp/boundary" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0.8.0" + }, + { + "fixed": "0.15.0" + } + ] + } + ] + } ], "references": [ { @@ -24,6 +43,10 @@ { "type": "WEB", "url": "https://discuss.hashicorp.com/t/hcsec-2024-02-boundary-vulnerable-to-session-hijacking-through-tls-certificate-tampering/62458" + }, + { + "type": "PACKAGE", + "url": "https://github.com/hashicorp/boundary" } ], "database_specific": { @@ -31,8 +54,8 @@ "CWE-295" ], "severity": "HIGH", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-02-05T23:06:56Z", "nvd_published_at": "2024-02-05T21:15:11Z" } } \ No newline at end of file