Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2024-04-10 18:41:34 +00:00
parent 90cf0ad854
commit 3629ab10a3
995 changed files with 35506 additions and 461 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5964-pq8r-4q62",
"modified": "2023-01-14T05:30:14Z",
"modified": "2024-04-09T14:17:43Z",
"published": "2022-05-17T05:07:14Z",
"aliases": [
"CVE-2012-4399"
@@ -9,7 +9,10 @@
"summary": "CakePHPallows remote attackers to read arbitrary files via XML data containing external entity references",
"details": "The Xml class in CakePHP 2.1.x before 2.1.5 and 2.2.x before 2.2.1 allows remote attackers to read arbitrary files via XML data containing external entity references, aka an XML external entity (XXE) injection attack.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
{
@@ -91,9 +94,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-611"
],
"severity": "MODERATE",
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2023-01-14T05:30:14Z",
"nvd_published_at": "2012-10-09T23:55:00Z"
@@ -0,0 +1,78 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5xv2-q475-rwrh",
"modified": "2024-04-09T14:24:53Z",
"published": "2022-05-17T05:13:13Z",
"aliases": [
"CVE-2012-3503"
],
"summary": "Katello uses hard coded credential",
"details": "The installation script in Katello 1.0 and earlier does not properly generate the `Application.config.secret_token` value, which causes each default installation to have the same secret token, and allows remote attackers to authenticate to the CloudForms System Engine web interface as an arbitrary user by creating a cookie using the default `secret_token`.",
"severity": [
],
"affected": [
{
"package": {
"ecosystem": "RubyGems",
"name": "katello"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.0"
}
]
}
]
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2012-3503"
},
{
"type": "WEB",
"url": "https://github.com/Katello/katello/pull/499"
},
{
"type": "WEB",
"url": "https://github.com/Katello/katello/commit/7c256fef9d75029d0ffff58ff1dcda915056d3a3"
},
{
"type": "PACKAGE",
"url": "https://github.com/Katello/katello"
},
{
"type": "WEB",
"url": "https://web.archive.org/web/20140806122239/http://secunia.com/advisories/50344"
},
{
"type": "WEB",
"url": "https://web.archive.org/web/20200229120740/http://www.securityfocus.com/bid/55140"
},
{
"type": "WEB",
"url": "http://rhn.redhat.com/errata/RHSA-2012-1186.html"
},
{
"type": "WEB",
"url": "http://rhn.redhat.com/errata/RHSA-2012-1187.html"
}
],
"database_specific": {
"cwe_ids": [
"CWE-798"
],
"severity": "LOW",
"github_reviewed": true,
"github_reviewed_at": "2024-04-09T14:24:53Z",
"nvd_published_at": "2012-08-25T10:29:00Z"
}
}
@@ -0,0 +1,70 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6mmf-v5q7-vw2w",
"modified": "2024-04-08T18:51:18Z",
"published": "2022-05-24T19:21:10Z",
"aliases": [
"CVE-2021-44144"
],
"summary": "Asterix Heap-based Buffer Overflow",
"details": "Croatia Control Asterix 2.8.1 has a heap-based buffer over-read, with additional details to be disclosed at a later date.",
"severity": [
],
"affected": [
{
"package": {
"ecosystem": "PyPI",
"name": "asterix_decoder"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "0.7.2"
}
]
}
]
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-44144"
},
{
"type": "WEB",
"url": "https://github.com/CroatiaControlLtd/asterix/issues/183"
},
{
"type": "WEB",
"url": "https://github.com/CroatiaControlLtd/asterix/commit/3f765d387d239ccc44e278a2ffa600fb6a6587f9"
},
{
"type": "PACKAGE",
"url": "https://github.com/CroatiaControlLtd/asterix"
},
{
"type": "WEB",
"url": "https://github.com/CroatiaControlLtd/asterix/blob/daf33de522d1cdab0e941c025b89e18a0d4d42c6/README.md?plain=1#L7"
},
{
"type": "WEB",
"url": "https://web.archive.org/web/20221207104133/https://huntr.dev/bounties/1-other-CroatiaControlLtd/asterix"
}
],
"database_specific": {
"cwe_ids": [
"CWE-125"
],
"severity": "CRITICAL",
"github_reviewed": true,
"github_reviewed_at": "2024-04-08T18:51:18Z",
"nvd_published_at": "2021-11-22T21:15:00Z"
}
}
@@ -1,15 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7pg4-5233-82jv",
"modified": "2024-01-12T18:22:11Z",
"modified": "2024-04-09T14:07:57Z",
"published": "2022-05-17T04:56:50Z",
"aliases": [
"CVE-2012-3363"
],
"summary": "Zend Framework XXE Vulnerability",
"details": "`Zend_XmlRpc` in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 does not properly handle SimpleXMLElement classes, which allows remote attackers to read arbitrary files or create TCP connections via an external entity reference in a DOCTYPE element in an XML-RPC request, aka an XML external entity (XXE) injection attack.",
"details": "`Zend_XmlRpc` in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 does not properly handle `SimpleXMLElement` classes, which allows remote attackers to read arbitrary files or create TCP connections via an external entity reference in a DOCTYPE element in an XML-RPC request, aka an XML external entity (XXE) injection attack.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
}
],
"affected": [
{
@@ -22,7 +25,7 @@
"type": "ECOSYSTEM",
"events": [
{
"introduced": "1.0"
"introduced": "1.0.0"
},
{
"fixed": "1.11.12"
@@ -111,13 +114,17 @@
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2012/06/27/2"
},
{
"type": "WEB",
"url": "http://www.securitytracker.com/id?1027208"
}
],
"database_specific": {
"cwe_ids": [
"CWE-611"
],
"severity": "MODERATE",
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2024-01-12T18:22:11Z",
"nvd_published_at": "2013-02-13T17:55:00Z"
@@ -1,11 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8q95-jj7p-x93x",
"modified": "2022-05-13T01:34:31Z",
"modified": "2024-04-08T18:57:43Z",
"published": "2022-05-13T01:34:31Z",
"aliases": [
"CVE-2018-14636"
],
"summary": "Openstack Neutron vulnerable to eavesdropping on private traffic",
"details": "Live-migrated instances are briefly able to inspect traffic for other instances on the same hypervisor. This brief window could be extended indefinitely if the instance's port is set administratively down prior to live-migration and kept down after the migration is complete. This is possible due to the Open vSwitch integration bridge being connected to the instance during migration. When connected to the integration bridge, all traffic for instances using the same Open vSwitch instance would potentially be visible to the migrated guest, as the required Open vSwitch VLAN filters are only applied post-migration. Versions of openstack-neutron before 13.0.0.0b2, 12.0.3, 11.0.5 are vulnerable.",
"severity": [
{
@@ -14,7 +15,66 @@
}
],
"affected": [
{
"package": {
"ecosystem": "PyPI",
"name": "neutron"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "13.0.0.0b1"
},
{
"fixed": "13.0.0.0b2"
}
]
}
],
"versions": [
"13.0.0.0b1"
]
},
{
"package": {
"ecosystem": "PyPI",
"name": "neutron"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "12.0.0"
},
{
"fixed": "12.0.3"
}
]
}
]
},
{
"package": {
"ecosystem": "PyPI",
"name": "neutron"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "11.0.0"
},
{
"fixed": "11.0.5"
}
]
}
]
}
],
"references": [
{
@@ -32,6 +92,10 @@
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14636"
},
{
"type": "PACKAGE",
"url": "https://github.com/openstack/neutron"
}
],
"database_specific": {
@@ -39,8 +103,8 @@
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"github_reviewed": true,
"github_reviewed_at": "2024-04-08T18:57:43Z",
"nvd_published_at": "2018-09-10T19:29:00Z"
}
}
@@ -1,11 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9773-3fqg-8w25",
"modified": "2022-05-13T01:07:34Z",
"modified": "2024-04-08T18:55:25Z",
"published": "2022-05-13T01:07:34Z",
"aliases": [
"CVE-2019-9735"
],
"summary": "OpenStack Neutron's unsupported dport option prevents applying security groups",
"details": "An issue was discovered in the iptables firewall module in OpenStack Neutron before 10.0.8, 11.x before 11.0.7, 12.x before 12.0.6, and 13.x before 13.0.3. By setting a destination port in a security group rule along with a protocol that doesn't support that option (for example, VRRP), an authenticated user may block further application of security group rules for instances from any project/tenant on the compute hosts to which it's applied. (Only deployments using the iptables security group driver are affected.)",
"severity": [
{
@@ -14,7 +15,82 @@
}
],
"affected": [
{
"package": {
"ecosystem": "PyPI",
"name": "neutron"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "10.0.8"
}
]
}
]
},
{
"package": {
"ecosystem": "PyPI",
"name": "neutron"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "11.0.0"
},
{
"fixed": "11.0.7"
}
]
}
]
},
{
"package": {
"ecosystem": "PyPI",
"name": "neutron"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "12.0.0"
},
{
"fixed": "12.0.6"
}
]
}
]
},
{
"package": {
"ecosystem": "PyPI",
"name": "neutron"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "13.0.0"
},
{
"fixed": "13.0.3"
}
]
}
]
}
],
"references": [
{
@@ -33,6 +109,10 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2019:0935"
},
{
"type": "PACKAGE",
"url": "https://github.com/openstack/neutron"
},
{
"type": "WEB",
"url": "https://launchpad.net/bugs/1818385"
@@ -49,6 +129,10 @@
"type": "WEB",
"url": "https://usn.ubuntu.com/4036-1"
},
{
"type": "WEB",
"url": "https://web.archive.org/web/20201208185619/http://www.securityfocus.com/bid/107390"
},
{
"type": "WEB",
"url": "https://www.debian.org/security/2019/dsa-4409"
@@ -56,10 +140,6 @@
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2019/03/18/2"
},
{
"type": "WEB",
"url": "http://www.securityfocus.com/bid/107390"
}
],
"database_specific": {
@@ -67,8 +147,8 @@
"CWE-755"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"github_reviewed": true,
"github_reviewed_at": "2024-04-08T18:55:25Z",
"nvd_published_at": "2019-03-13T02:29:00Z"
}
}
@@ -1,27 +1,58 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f889-wfwm-6p7m",
"modified": "2022-05-17T04:50:52Z",
"modified": "2024-04-08T19:04:48Z",
"published": "2022-05-17T04:50:52Z",
"aliases": [
"CVE-2013-4477"
],
"summary": "OpenStack Identity Keystone Privilege Escalation vulnerability",
"details": "The LDAP backend in OpenStack Identity (Keystone) Grizzly and Havana, when removing a role on a tenant for a user who does not have that role, adds the role to the user, which allows local users to gain privileges.",
"severity": [
],
"affected": [
{
"package": {
"ecosystem": "PyPI",
"name": "keystone"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "8.0.0a0"
}
]
}
]
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2013-4477"
},
{
"type": "WEB",
"url": "https://github.com/openstack/keystone/commit/b17e7bec768bd53d3977352486378698a3db3cfa"
},
{
"type": "WEB",
"url": "https://github.com/openstack/keystone/commit/c6800ca1ac984c879e75826df6694d6199444ea0"
},
{
"type": "WEB",
"url": "https://bugs.launchpad.net/keystone/+bug/1242855"
},
{
"type": "PACKAGE",
"url": "https://github.com/openstack/keystone"
},
{
"type": "WEB",
"url": "http://rhn.redhat.com/errata/RHSA-2014-0113.html"
@@ -40,8 +71,8 @@
],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"github_reviewed": true,
"github_reviewed_at": "2024-04-08T19:04:48Z",
"nvd_published_at": "2013-11-02T19:55:00Z"
}
}
@@ -1,11 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j6jq-3q8p-xgg6",
"modified": "2022-05-17T02:53:10Z",
"modified": "2024-04-08T19:00:08Z",
"published": "2022-05-17T02:53:10Z",
"aliases": [
"CVE-2017-7266"
],
"summary": "Netflix Security Monkey Open Redirect vulnerability",
"details": "Netflix Security Monkey before 0.8.0 has an Open Redirect. The logout functionality accepted the \"next\" parameter which then redirects to any domain irrespective of the Host header.",
"severity": [
{
@@ -14,7 +15,25 @@
}
],
"affected": [
{
"package": {
"ecosystem": "PyPI",
"name": "security_monkey"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "0.8.0"
}
]
}
]
}
],
"references": [
{
@@ -29,13 +48,17 @@
"type": "WEB",
"url": "https://github.com/Netflix/security_monkey/commit/3b4da13efabb05970c80f464a50d3c1c12262466"
},
{
"type": "PACKAGE",
"url": "https://github.com/Netflix/security_monkey"
},
{
"type": "WEB",
"url": "https://github.com/Netflix/security_monkey/releases/tag/v0.8.0"
},
{
"type": "WEB",
"url": "http://www.securityfocus.com/bid/97088"
"url": "https://web.archive.org/web/20201220170714/http://www.securityfocus.com/bid/97088"
}
],
"database_specific": {
@@ -43,8 +66,8 @@
"CWE-601"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"github_reviewed": true,
"github_reviewed_at": "2024-04-08T19:00:08Z",
"nvd_published_at": "2017-03-26T05:59:00Z"
}
}
@@ -1,11 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jr9m-v5qh-mh2j",
"modified": "2022-05-13T01:07:34Z",
"modified": "2024-04-08T18:54:13Z",
"published": "2022-05-13T01:07:34Z",
"aliases": [
"CVE-2019-10876"
],
"summary": "OpenStack Neutron overlapping security group rules prevents compute node network configuration",
"details": "An issue was discovered in OpenStack Neutron 11.x before 11.0.7, 12.x before 12.0.6, and 13.x before 13.0.3. By creating two security groups with separate/overlapping port ranges, an authenticated user may prevent Neutron from being able to configure networks on any compute nodes where those security groups are present, because of an Open vSwitch (OVS) firewall KeyError. All Neutron deployments utilizing neutron-openvswitch-agent are affected.",
"severity": [
{
@@ -14,7 +15,63 @@
}
],
"affected": [
{
"package": {
"ecosystem": "PyPI",
"name": "neutron"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "11.0.0"
},
{
"fixed": "11.0.7"
}
]
}
]
},
{
"package": {
"ecosystem": "PyPI",
"name": "neutron"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "12.0.0"
},
{
"fixed": "12.0.6"
}
]
}
]
},
{
"package": {
"ecosystem": "PyPI",
"name": "neutron"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "13.0.0"
},
{
"fixed": "13.0.3"
}
]
}
]
}
],
"references": [
{
@@ -33,6 +90,10 @@
"type": "WEB",
"url": "https://bugs.launchpad.net/ossa/+bug/1813007"
},
{
"type": "PACKAGE",
"url": "https://github.com/openstack/neutron"
},
{
"type": "WEB",
"url": "https://review.openstack.org/#/q/topic:bug/1813007"
@@ -51,8 +112,8 @@
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"github_reviewed": true,
"github_reviewed_at": "2024-04-08T18:54:13Z",
"nvd_published_at": "2019-04-05T05:29:00Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pjqh-2jcc-5j84",
"modified": "2022-06-30T21:14:06Z",
"modified": "2024-04-05T18:51:08Z",
"published": "2022-05-13T01:12:09Z",
"aliases": [
"CVE-2017-8028"
@@ -18,7 +18,7 @@
{
"package": {
"ecosystem": "Maven",
"name": "org.springframework.amqp:spring-amqp"
"name": "org.springframework.ldap:spring-ldap-core"
},
"ranges": [
{
@@ -43,10 +43,18 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2017-8028"
},
{
"type": "WEB",
"url": "https://github.com/spring-projects/spring-ldap/commit/08e8ae289bbd1b581986c7238604a147119c1336"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2018:0319"
},
{
"type": "PACKAGE",
"url": "https://github.com/spring-projects/spring-ldap"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2017/11/msg00026.html"
@@ -1,11 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x634-34m9-96mp",
"modified": "2022-05-13T01:07:33Z",
"modified": "2024-04-08T18:53:05Z",
"published": "2022-05-13T01:07:33Z",
"aliases": [
"CVE-2018-14635"
],
"summary": "OpensStack Neutron Denial of Service Vulnerability",
"details": "When using the Linux bridge ml2 driver, non-privileged tenants are able to create and attach ports without specifying an IP address, bypassing IP address validation. A potential denial of service could occur if an IP address, conflicting with existing guests or routers, is then assigned from outside of the allowed allocation pool. Versions of openstack-neutron before 13.0.0.0b2, 12.0.3 and 11.0.5 are vulnerable.",
"severity": [
{
@@ -14,13 +15,76 @@
}
],
"affected": [
{
"package": {
"ecosystem": "PyPI",
"name": "neutron"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "13.0.0.0b1"
},
{
"fixed": "13.0.0.0b2"
}
]
}
],
"versions": [
"13.0.0.0b1"
]
},
{
"package": {
"ecosystem": "PyPI",
"name": "neutron"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "12.0.0"
},
{
"fixed": "12.0.3"
}
]
}
]
},
{
"package": {
"ecosystem": "PyPI",
"name": "neutron"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "11.0.0"
},
{
"fixed": "11.0.5"
}
]
}
]
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2018-14635"
},
{
"type": "WEB",
"url": "https://github.com/openstack/neutron/commit/54aa6e81cb17b33ce4d5d469cc11dec2869c762d"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2018:2710"
@@ -48,6 +112,10 @@
{
"type": "WEB",
"url": "https://git.openstack.org/cgit/openstack/neutron/commit/?id=54aa6e81cb17b33ce4d5d469cc11dec2869c762d"
},
{
"type": "PACKAGE",
"url": "https://github.com/openstack/neutron"
}
],
"database_specific": {
@@ -55,8 +123,8 @@
"CWE-20"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"github_reviewed": true,
"github_reviewed_at": "2024-04-08T18:53:04Z",
"nvd_published_at": "2018-09-10T19:29:00Z"
}
}
@@ -1,17 +1,55 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xc7w-jvhx-p6q9",
"modified": "2022-05-14T02:52:42Z",
"modified": "2024-04-08T18:58:55Z",
"published": "2022-05-14T02:52:42Z",
"aliases": [
"CVE-2014-3225"
],
"summary": "Cobbler Path Traversal vulnerability",
"details": "Absolute path traversal vulnerability in the web interface in Cobbler 2.4.x through 2.6.x allows remote authenticated users to read arbitrary files via the Kickstart field in a profile.",
"severity": [
],
"affected": [
{
"package": {
"ecosystem": "PyPI",
"name": "cobbler"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "2.6.0"
},
{
"fixed": "2.6.4"
}
]
}
]
},
{
"package": {
"ecosystem": "PyPI",
"name": "cobbler"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "2.4.0"
},
{
"fixed": "2.4.7"
}
]
}
]
}
],
"references": [
{
@@ -22,6 +60,18 @@
"type": "WEB",
"url": "https://github.com/cobbler/cobbler/issues/939"
},
{
"type": "WEB",
"url": "https://github.com/cobbler/cobbler/commit/8232c0e88ec7382d3f8d3bf48c81a4a91ac4325d"
},
{
"type": "WEB",
"url": "https://github.com/cobbler/cobbler/commit/f757e3096fcd32397609ca38efb01f19d16dd634"
},
{
"type": "PACKAGE",
"url": "https://github.com/cobbler/cobbler"
},
{
"type": "WEB",
"url": "https://www.youtube.com/watch?v=vuBaoQUFEYQ&feature=youtu.be"
@@ -60,8 +110,8 @@
"CWE-22"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"github_reviewed": true,
"github_reviewed_at": "2024-04-08T18:58:54Z",
"nvd_published_at": "2014-05-14T00:55:00Z"
}
}
File diff suppressed because one or more lines are too long
@@ -1,11 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7pf9-7cff-f854",
"modified": "2022-09-08T00:00:30Z",
"modified": "2024-04-08T19:03:02Z",
"published": "2022-09-02T00:01:01Z",
"aliases": [
"CVE-2022-2806"
],
"summary": "sosreport Exposure of Sensitive Information vulnerability",
"details": "It was found that the ovirt-log-collector/sosreport collects the RHV admin password unfiltered. Fixed in: sos-4.2-20.el8_6, ovirt-log-collector-4.4.7-2.el8ev",
"severity": [
{
@@ -14,7 +15,25 @@
}
],
"affected": [
{
"package": {
"ecosystem": "PyPI",
"name": "sosreport"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "4.4"
}
]
}
]
}
],
"references": [
{
@@ -24,15 +43,23 @@
{
"type": "WEB",
"url": "https://github.com/sosreport/sos/pull/2947"
},
{
"type": "WEB",
"url": "https://github.com/sosreport/sos/commit/5fd872c64c53af37015f366295e0c2418c969757"
},
{
"type": "PACKAGE",
"url": "https://github.com/sosreport/sos"
}
],
"database_specific": {
"cwe_ids": [
"CWE-200"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"github_reviewed": true,
"github_reviewed_at": "2024-04-08T19:03:02Z",
"nvd_published_at": "2022-09-01T21:15:00Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9jjw-hf72-3mxw",
"modified": "2022-10-07T07:22:33Z",
"modified": "2024-04-09T14:24:23Z",
"published": "2022-10-07T07:22:33Z",
"aliases": [
"CVE-2020-26269"
@@ -11,7 +11,7 @@
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
}
],
"affected": [
@@ -111,7 +111,7 @@
"cwe_ids": [
"CWE-125"
],
"severity": "HIGH",
"severity": "CRITICAL",
"github_reviewed": true,
"github_reviewed_at": "2022-10-07T07:22:33Z",
"nvd_published_at": "2020-12-10T23:15:00Z"
@@ -1,13 +1,13 @@
{
"schema_version": "1.4.0",
"id": "GHSA-894q-wpg5-mf2h",
"modified": "2022-12-13T19:32:22Z",
"modified": "2024-04-08T17:20:47Z",
"published": "2022-12-10T12:30:18Z",
"aliases": [
"CVE-2022-4396"
],
"summary": "pyRdfa3 Cross-site Scripting vulnerability",
"details": "A vulnerability was found in RDFlib pyrdfa3 and classified as problematic. This issue affects the function _get_option of the file pyRdfa/__init__.py. The manipulation leads to cross site scripting. The attack may be initiated remotely. The name of the patch is ffd1d62dd50d5f4190013b39cedcdfbd81f3ce3e. It is recommended to apply a patch to fix this issue. The identifier VDB-215249 was assigned to this vulnerability. \n\nNOTE: RDFlib is no longer being developed and is looking for a new maintainer \nhttps://github.com/RDFLib/pyrdfa3/issues/38",
"details": "A vulnerability was found in RDFlib pyrdfa3 and classified as problematic. This issue affects the function `_get_option` of the file `pyRdfa/__init__.py`. The manipulation leads to cross site scripting. The attack may be initiated remotely. The name of the patch is ffd1d62dd50d5f4190013b39cedcdfbd81f3ce3e. It is recommended to apply a patch to fix this issue. The identifier VDB-215249 was assigned to this vulnerability.",
"severity": [
{
"type": "CVSS_V3",
@@ -28,11 +28,14 @@
"introduced": "0"
},
{
"last_affected": "3.5.3"
"fixed": "3.6.2"
}
]
}
]
],
"database_specific": {
"last_known_affected_version_range": "<= 3.5.3"
}
}
],
"references": [
@@ -63,6 +66,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-707",
"CWE-79"
],
"severity": "MODERATE",
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5cx2-vq3h-x52c",
"modified": "2023-05-24T18:34:30Z",
"modified": "2024-04-08T15:35:54Z",
"published": "2023-04-24T18:30:30Z",
"aliases": [
"CVE-2023-27524"
@@ -54,11 +54,11 @@
},
{
"type": "WEB",
"url": "http://packetstormsecurity.com/files/172522/Apache-Superset-2.0.0-Authentication-Bypass.html"
"url": "https://packetstormsecurity.com/files/172522/Apache-Superset-2.0.0-Authentication-Bypass.html"
},
{
"type": "WEB",
"url": "http://packetstormsecurity.com/files/175094/Apache-Superset-2.0.0-Remote-Code-Execution.html"
"url": "https://packetstormsecurity.com/files/175094/Apache-Superset-2.0.0-Remote-Code-Execution.html"
},
{
"type": "WEB",
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rggv-cv7r-mw98",
"modified": "2024-03-29T15:30:27Z",
"modified": "2024-04-07T00:30:32Z",
"published": "2024-02-26T20:13:46Z",
"aliases": [
"CVE-2024-22201"
@@ -199,6 +199,10 @@
"type": "PACKAGE",
"url": "https://github.com/jetty/jetty.project"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00002.html"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20240329-0001"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7w75-32cg-r6g2",
"modified": "2024-04-03T00:30:55Z",
"modified": "2024-04-06T06:31:08Z",
"published": "2024-03-13T18:31:34Z",
"aliases": [
"CVE-2024-24549"
@@ -218,6 +218,10 @@
"type": "WEB",
"url": "https://lists.apache.org/thread/4c50rmomhbbsdgfjsgwlb51xdwfjdcvg"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00001.html"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20240402-0002"
@@ -1,17 +1,39 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9mg4-v392-8j68",
"modified": "2024-03-19T15:30:34Z",
"modified": "2024-04-08T16:46:04Z",
"published": "2024-03-19T15:30:34Z",
"aliases": [
"CVE-2023-50966"
],
"summary": "erlang-jose vulnerable to denial of service via large p2c value",
"details": "erlang-jose (aka JOSE for Erlang and Elixir) through 1.11.6 allow attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value in a JOSE header.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
}
],
"affected": [
{
"package": {
"ecosystem": "Hex",
"name": "erlang-jose"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "1.11.7"
}
]
}
]
}
],
"references": [
{
@@ -20,10 +42,14 @@
},
{
"type": "WEB",
"url": "https://github.com/P3ngu1nW/CVE_Request/blob/main/erlang-jose.md"
"url": "https://github.com/potatosalad/erlang-jose/commit/718d213f07b08056737923f8063d5df56dcb66ae"
},
{
"type": "WEB",
"url": "https://github.com/P3ngu1nW/CVE_Request/blob/main/erlang-jose.md"
},
{
"type": "PACKAGE",
"url": "https://github.com/potatosalad/erlang-jose"
},
{
@@ -33,11 +59,11 @@
],
"database_specific": {
"cwe_ids": [
"CWE-400"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-04-08T16:46:03Z",
"nvd_published_at": "2024-03-19T15:15:07Z"
}
}

Some files were not shown because too many files have changed in this diff Show More