diff --git a/advisories/github-reviewed/2024/07/GHSA-248v-346w-9cwc/GHSA-248v-346w-9cwc.json b/advisories/github-reviewed/2024/07/GHSA-248v-346w-9cwc/GHSA-248v-346w-9cwc.json new file mode 100644 index 00000000000..c6380e928d0 --- /dev/null +++ b/advisories/github-reviewed/2024/07/GHSA-248v-346w-9cwc/GHSA-248v-346w-9cwc.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-248v-346w-9cwc", + "modified": "2024-07-05T20:06:40Z", + "published": "2024-07-05T20:06:40Z", + "aliases": [ + "CVE-2024-39689" + ], + "summary": "Certifi removes GLOBALTRUST root certificate", + "details": "Certifi 2024.07.04 removes root certificates from \"GLOBALTRUST\" from the root store. These are in the process of being removed from Mozilla's trust store.\n\nGLOBALTRUST's root certificates are being removed pursuant to an investigation which identified \"long-running and unresolved compliance issues\". Conclusions of Mozilla's investigation can be found [here]( https://groups.google.com/a/mozilla.org/g/dev-security-policy/c/XpknYMPO8dI).", + "severity": [ + + ], + "affected": [ + { + "package": { + "ecosystem": "PyPI", + "name": "certifi" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2021.05.30" + }, + { + "fixed": "2024.07.04" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/certifi/python-certifi/security/advisories/GHSA-248v-346w-9cwc" + }, + { + "type": "WEB", + "url": "https://github.com/certifi/python-certifi/commit/bd8153872e9c6fc98f4023df9c2deaffea2fa463" + }, + { + "type": "PACKAGE", + "url": "https://github.com/certifi/python-certifi" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-345" + ], + "severity": "LOW", + "github_reviewed": true, + "github_reviewed_at": "2024-07-05T20:06:40Z", + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/07/GHSA-qjvf-8748-9w7h/GHSA-qjvf-8748-9w7h.json b/advisories/github-reviewed/2024/07/GHSA-qjvf-8748-9w7h/GHSA-qjvf-8748-9w7h.json new file mode 100644 index 00000000000..d2038852531 --- /dev/null +++ b/advisories/github-reviewed/2024/07/GHSA-qjvf-8748-9w7h/GHSA-qjvf-8748-9w7h.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qjvf-8748-9w7h", + "modified": "2024-07-05T20:05:15Z", + "published": "2024-07-04T00:37:45Z", + "aliases": [ + "CVE-2024-6284" + ], + "summary": "github.com/google/nftable IP addresses were encoded in the wrong byte order", + "details": "In https://github.com/google/nftables IP addresses were encoded in the wrong byte order, resulting in an nftables configuration which does not work as intended (might block or not block the desired addresses).\n\nThis issue affects:  https://pkg.go.dev/github.com/google/nftables@v0.1.0 \n\nThe bug was fixed in the next released version:  https://pkg.go.dev/github.com/google/nftables@v0.2.0", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Go", + "name": "github.com/google/nftables" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0.1.0" + }, + { + "fixed": "0.2.0" + } + ] + } + ], + "versions": [ + "0.1.0" + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6284" + }, + { + "type": "WEB", + "url": "https://github.com/crowdsecurity/cs-firewall-bouncer/issues/368" + }, + { + "type": "WEB", + "url": "https://github.com/google/nftables/issues/225" + }, + { + "type": "WEB", + "url": "https://bugs.launchpad.net/ubuntu/+source/crowdsec-firewall-bouncer/+bug/2069596" + }, + { + "type": "PACKAGE", + "url": "https://github.com/google/nftables" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-07-05T20:05:15Z", + "nvd_published_at": "2024-07-03T23:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/07/GHSA-w9mh-5x8j-9754/GHSA-w9mh-5x8j-9754.json b/advisories/github-reviewed/2024/07/GHSA-w9mh-5x8j-9754/GHSA-w9mh-5x8j-9754.json new file mode 100644 index 00000000000..8f9816b89e0 --- /dev/null +++ b/advisories/github-reviewed/2024/07/GHSA-w9mh-5x8j-9754/GHSA-w9mh-5x8j-9754.json @@ -0,0 +1,66 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w9mh-5x8j-9754", + "modified": "2024-07-05T20:06:07Z", + "published": "2024-07-05T20:06:06Z", + "aliases": [ + "CVE-2024-39691" + ], + "summary": "Malicious Matrix homeserver can leak truncated message content of messages it shouldn't have access to", + "details": "### Impact\n\nThe fix for GHSA-wm4w-7h2q-3pf7 / [CVE-2024-32000](https://www.cve.org/CVERecord?id=CVE-2024-32000) included in matrix-appservice-irc 2.0.0 relied on the Matrix homeserver-provided timestamp to determine whether a user has access to the event they're replying to when determining whether or not to include a truncated version of the original event in the IRC message. Since this value is controlled by external entities, a malicious Matrix homeserver joined to a room in which a matrix-appservice-irc bridge instance (before version 2.0.1) is present can fabricate the timestamp with the intent of tricking the bridge into leaking room messages the homeserver should not have access to.\n\n### Patches\n\nmatrix-appservice-irc 2.0.1 [drops the reliance](https://github.com/matrix-org/matrix-appservice-irc/pull/1804) on `origin_server_ts` when determining whether or not an event should be visible to a user, instead tracking the event timestamps internally.\n\n### Workarounds\n\nIt's possible to limit the amount of information leaked by setting a reply template that doesn't contain the original message. See [these lines](https://github.com/matrix-org/matrix-appservice-irc/blob/d5d67d1d3ea3f0f6962a0af2cc57b56af3ad2129/config.sample.yaml#L601-L604) in the configuration file.\n\n### References\n\n- Patch: https://github.com/matrix-org/matrix-appservice-irc/pull/1804\n\n### For more information\n\nIf you have any questions or comments about this advisory, please email us at [security at matrix.org](mailto:security@matrix.org).", + "severity": [ + + ], + "affected": [ + { + "package": { + "ecosystem": "npm", + "name": "matrix-appservice-irc" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.0.1" + } + ] + } + ], + "database_specific": { + "last_known_affected_version_range": "<= 2.0.0" + } + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/matrix-org/matrix-appservice-irc/security/advisories/GHSA-w9mh-5x8j-9754" + }, + { + "type": "WEB", + "url": "https://github.com/matrix-org/matrix-appservice-irc/pull/1804" + }, + { + "type": "WEB", + "url": "https://github.com/matrix-org/matrix-appservice-irc/commit/1835e047f269001054be4c68867797aa12372a0f" + }, + { + "type": "PACKAGE", + "url": "https://github.com/matrix-org/matrix-appservice-irc" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-280", + "CWE-755" + ], + "severity": "LOW", + "github_reviewed": true, + "github_reviewed_at": "2024-07-05T20:06:06Z", + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/07/GHSA-xr7q-jx4m-x55m/GHSA-xr7q-jx4m-x55m.json b/advisories/github-reviewed/2024/07/GHSA-xr7q-jx4m-x55m/GHSA-xr7q-jx4m-x55m.json new file mode 100644 index 00000000000..ca4265dc447 --- /dev/null +++ b/advisories/github-reviewed/2024/07/GHSA-xr7q-jx4m-x55m/GHSA-xr7q-jx4m-x55m.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xr7q-jx4m-x55m", + "modified": "2024-07-05T20:07:01Z", + "published": "2024-07-05T20:07:01Z", + "aliases": [ + + ], + "summary": "Private tokens could appear in logs if context containing gRPC metadata is logged in github.com/grpc/grpc-go", + "details": "### Impact\nThis issue represents a potential PII concern. If applications were printing or logging a context containing gRPC metadata, the affected versions will contain all the metadata, which may include private information.\n\n### Patches\nThe issue first appeared in 1.64.0 and is patched in 1.64.1 and 1.65.0\n\n### Workarounds\nIf using an affected version and upgrading is not possible, ensuring you do not log or print contexts will avoid the problem.\n", + "severity": [ + + ], + "affected": [ + { + "package": { + "ecosystem": "Go", + "name": "github.com/grpc/grpc-go" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "1.64.0" + }, + { + "fixed": "1.64.1" + } + ] + } + ], + "versions": [ + "1.64.0" + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/grpc/grpc-go/security/advisories/GHSA-xr7q-jx4m-x55m" + }, + { + "type": "PACKAGE", + "url": "https://github.com/grpc/grpc-go" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "LOW", + "github_reviewed": true, + "github_reviewed_at": "2024-07-05T20:07:01Z", + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-qjvf-8748-9w7h/GHSA-qjvf-8748-9w7h.json b/advisories/unreviewed/2024/07/GHSA-qjvf-8748-9w7h/GHSA-qjvf-8748-9w7h.json deleted file mode 100644 index 960544351d7..00000000000 --- a/advisories/unreviewed/2024/07/GHSA-qjvf-8748-9w7h/GHSA-qjvf-8748-9w7h.json +++ /dev/null @@ -1,46 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-qjvf-8748-9w7h", - "modified": "2024-07-04T00:37:45Z", - "published": "2024-07-04T00:37:45Z", - "aliases": [ - "CVE-2024-6284" - ], - "details": "In https://github.com/google/nftables  IP addresses were encoded in the wrong byte order, resulting in an nftables configuration which does not work as intended (might block or not block the desired addresses).\n\nThis issue affects:  https://pkg.go.dev/github.com/google/nftables@v0.1.0 \n\nThe bug was fixed in the next released version:  https://pkg.go.dev/github.com/google/nftables@v0.2.0", - "severity": [ - { - "type": "CVSS_V4", - "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" - } - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6284" - }, - { - "type": "WEB", - "url": "https://github.com/crowdsecurity/cs-firewall-bouncer/issues/368" - }, - { - "type": "WEB", - "url": "https://github.com/google/nftables/issues/225" - }, - { - "type": "WEB", - "url": "https://bugs.launchpad.net/ubuntu/+source/crowdsec-firewall-bouncer/+bug/2069596" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-20" - ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2024-07-03T23:15:02Z" - } -} \ No newline at end of file