Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2024-11-28 05:11:50 +00:00
parent 069aea0412
commit 269930bbd1
902 changed files with 1859 additions and 5577 deletions
@@ -3,9 +3,7 @@
"id": "GHSA-v7x3-7hw7-pcjg",
"modified": "2022-08-11T13:20:10Z",
"published": "2019-10-21T16:02:33Z",
"aliases": [
],
"aliases": [],
"summary": "Renovate vulnerable to leakage of temporary repository tokens into Pull Request comments",
"details": "### Impact\n\nTemporary repository tokens were leaked into Pull Requests comments in during certain Go Modules update failure scenarios.\n\n### Patches\n\nThe problem has been patched. Self-hosted users should upgrade to v19.38.7 or later.\n\n### Workarounds\n\nDisable Go Modules support.\n\n### References\n\nBlog post: https://renovatebot.com/blog/go-modules-vulnerability-disclosure\n\n### For more information\n\nIf you have any questions or comments about this advisory:\n* Open an issue in [Renovate](http://github.com/renovatebot/renovate)\n",
"severity": [
@@ -3,14 +3,10 @@
"id": "GHSA-36rh-ggpr-j3gj",
"modified": "2022-08-11T13:19:15Z",
"published": "2020-09-14T16:38:40Z",
"aliases": [
],
"aliases": [],
"summary": "Renovate vulnerable to Azure DevOps token leakage in logs",
"details": "### Impact\n\nApplies to Azure DevOps users only. The bot's token may be exposed in server or pipeline logs due to the `http.extraheader=AUTHORIZATION` parameter being logged without redaction. It is recommended that Azure DevOps users revoke their existing bot credentials and generate new ones after upgrading if there's a potential that logs have been saved to a location that others can view.\n\n### Patches\n\nFixed in \n\n### Workarounds\n\nDo not share Renovate logs with anyone who cannot be trusted with access to the token.\n",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -43,9 +39,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2020-09-14T16:38:10Z",
@@ -3,9 +3,7 @@
"id": "GHSA-5v7r-jg9r-vq44",
"modified": "2021-09-29T20:08:01Z",
"published": "2020-09-03T21:19:46Z",
"aliases": [
],
"aliases": [],
"summary": "Insecure Cryptography Algorithm in simple-crypto-js",
"details": "Versions of `simple-crypto-js` prior to 2.3.0 use AES-CBC with PKCS#7 padding, which is vulnerable to padding oracle attacks. This may allow attackers to break the encryption and access sensitive data.\n\n\n## Recommendation\n\nUpgrade to version 2.3.0 or later.",
"severity": [
@@ -8,9 +8,7 @@
],
"summary": "XML External Entity Reference in org.picketlink:picketlink-common",
"details": "The org.picketlink.common.util.DocumentUtil.getDocumentBuilderFactory method in PicketLink, as used in Red Hat JBoss Enterprise Application Platform (JBEAP) 5.2.0 and 6.2.4, expands entity references, which allows remote attackers to read arbitrary code and possibly have other unspecified impact via unspecified vectors, related to an XML External Entity (XXE) issue.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -8,9 +8,7 @@
],
"summary": "Puppet Privilege Escallation",
"details": "The change_user method in the SUIDManager (lib/puppet/util/suidmanager.rb) in Puppet 2.6.x before 2.6.14 and 2.7.x before 2.7.11, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x before 2.0.3 does not properly manage group privileges, which allows local users to gain privileges via vectors related to (1) the change_user not dropping supplementary groups in certain conditions, (2) changes to the eguid without associated changes to the egid, or (3) the addition of the real gid to supplementary groups.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -8,9 +8,7 @@
],
"summary": "Puppet uses predictable filenames, allowing arbitrary file overwrite",
"details": "Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 uses predictable file names when installing Mac OS X packages from a remote source, which allows local users to overwrite arbitrary files or install arbitrary packages via a symlink attack on a temporary file in /tmp.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -8,9 +8,7 @@
],
"summary": "Zope DocumentTemplate package allows unauthenticated write",
"details": "The DocumentTemplate package in Zope 2.2 and earlier allows a remote attacker to modify DTMLDocuments or DTMLMethods without authorization.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -62,9 +62,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2022-11-01T23:02:42Z",
@@ -88,9 +88,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2022-11-01T23:35:47Z",
@@ -8,9 +8,7 @@
],
"summary": "Apache Tomcat Discloses MS-DOS Pathname",
"details": "Apache Tomcat 4.0.3, when running on Windows, allows remote attackers to obtain sensitive information via a request for a file that contains an MS-DOS device name such as lpt9, which leaks the pathname in an error message, as demonstrated by `lpt9.xtp` using Nikto.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -73,9 +73,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2022-10-12T20:03:06Z",
@@ -3,14 +3,10 @@
"id": "GHSA-9gp7-6833-wv89",
"modified": "2022-10-06T23:18:35Z",
"published": "2022-10-06T23:18:35Z",
"aliases": [
],
"aliases": [],
"summary": "etcd having a negative value for cluster node size results in an index out-of-bound panic during service discovery",
"details": "### Vulnerability type\nData Validation\n\n### Detail\nWhen an etcd instance attempts to perform service discovery, if a cluster size is provided as a negative value, the etcd instance will panic without recovery.\n\n### References\nFind out more on this vulnerability in the [security audit report](https://github.com/etcd-io/etcd/blob/master/security/SECURITY_AUDIT.pdf)\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Contact the [etcd security committee](https://github.com/etcd-io/etcd/blob/master/security/security-release-process.md#product-security-committee-psc)",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -62,9 +58,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "LOW",
"github_reviewed": true,
"github_reviewed_at": "2022-10-06T23:18:35Z",
@@ -3,14 +3,10 @@
"id": "GHSA-h8g9-6gvh-5mrc",
"modified": "2022-10-06T23:12:38Z",
"published": "2022-10-06T23:12:38Z",
"aliases": [
],
"aliases": [],
"summary": "etcd vulnerable to TOCTOU of gateway endpoint authentication",
"details": "### Vulnerability type\nAuthentication\n\n### Workarounds\nRefer to the [gateway documentation](https://github.com/etcd-io/etcd/blob/master/Documentation/op-guide/gateway.md). The vulnerability was spotted due to unclear documentation of how the gateway handles endpoints validation. \n\n### Detail\nThe gateway only authenticates endpoints detected from DNS SRV records, and it only authenticates the detected endpoints once. Therefore, if an endpoint changes its authentication settings, the gateway will continue to assume the endpoint is still authenticated. The auditors has noted that appropriate documentation of this validation functionality plus deprecation of this misleading functionality is an acceptable path forward.\n\n### References\nFind out more on this vulnerability in the [security audit report](https://github.com/etcd-io/etcd/blob/master/security/SECURITY_AUDIT.pdf)\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Contact the [etcd security committee](https://github.com/etcd-io/etcd/blob/master/security/security-release-process.md#product-security-committee-psc)",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -3,14 +3,10 @@
"id": "GHSA-g86j-hwg9-77q5",
"modified": "2022-12-27T15:25:51Z",
"published": "2022-12-27T15:25:51Z",
"aliases": [
],
"aliases": [],
"summary": "SentinelOne impersonated via PyPI packages",
"details": "In December 2022, threat actors impersonated SentinelOne by uploading fake software development kits (SDKs) onto PyPI. The SDKs contain fully functional SentinelOne clients, but the packages also contained malicious backdoors that are only executed when called on programmatically, as opposed to during installation. The packages have since been taken down from PyPI.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -89,9 +85,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2022-12-27T15:25:51Z",
@@ -7,12 +7,8 @@
"CVE-2003-0297"
],
"details": "c-client IMAP Client, as used in imap-2002b and Pine 4.53, allows remote malicious IMAP servers to cause a denial of service (crash) and possibly execute arbitrary code via certain large (1) literal and (2) mailbox size values that cause either integer signedness errors or integer overflow errors.",
"severity": [
],
"affected": [
],
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,9 +32,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -7,12 +7,8 @@
"CVE-2003-0232"
],
"details": "Microsoft SQL Server 7, 2000, and MSDE allows local users to execute arbitrary code via a certain request to the Local Procedure Calls (LPC) port that leads to a buffer overflow.",
"severity": [
],
"affected": [
],
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
@@ -36,9 +32,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -7,12 +7,8 @@
"CVE-2003-0270"
],
"details": "The administration capability for Apple AirPort 802.11 wireless access point devices uses weak encryption (XOR with a fixed key) for protecting authentication credentials, which could allow remote attackers to obtain administrative access via sniffing when the capability is available via Ethernet or non-WEP connections.",
"severity": [
],
"affected": [
],
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
@@ -40,9 +36,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -7,12 +7,8 @@
"CVE-2003-0193"
],
"details": "msxlsview.sh in xlsview for catdoc 0.91 and earlier allows local users to overwrite arbitrary files via a symlink attack on predictable temporary file names (\"word$$.html\").",
"severity": [
],
"affected": [
],
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
@@ -48,9 +44,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -7,12 +7,8 @@
"CVE-2003-0207"
],
"details": "ps2epsi creates insecure temporary files when calling ghostscript, which allows local attackers to overwrite arbitrary files.",
"severity": [
],
"affected": [
],
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
@@ -24,9 +20,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -7,12 +7,8 @@
"CVE-2003-0292"
],
"details": "Cross-site scripting (XSS) vulnerability in Inktomi Traffic-Server 5.5.1 allows remote attackers to insert arbitrary web script or HTML into an error page that appears to come from the domain that the client is visiting, aka \"Man-in-the-Middle\" XSS.",
"severity": [
],
"affected": [
],
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
@@ -28,9 +24,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,

Some files were not shown because too many files have changed in this diff Show More