Publish Advisories

GHSA-rfc4-38hf-4pmp
GHSA-mgj2-46rc-8756
GHSA-3qmg-867g-8xrq
GHSA-656f-g689-89jh
GHSA-7rvg-gjgp-95j7
GHSA-7xrv-q25v-f95m
GHSA-9hm3-chgj-45rm
GHSA-cw53-7m4g-22j6
GHSA-hhqg-994q-93m3
GHSA-hwgx-3qq3-2885
GHSA-p85h-gwrr-6mrj
GHSA-vhm9-v8x6-w764
GHSA-wv9p-64pj-gq2g
GHSA-x39v-frq9-5hh8
This commit is contained in:
advisory-database[bot]
2023-10-26 03:31:41 +00:00
parent 82c0747436
commit 3a4d516951
14 changed files with 144 additions and 0 deletions
@@ -29,6 +29,10 @@
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HMEELCREWMRT6NS7HWXLA6XFLLMO36HE/"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LKYHSZQFDNR7RSA7LHVLLIAQMVYCUGBG/"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UEJWL67XR67JAGEL2ZK22NA3BRKNMZNY/"
@@ -41,6 +45,10 @@
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VKFMKD4MJZIKFQJAAJ4VZ2FHIJ764A76/"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X6QXN4ORIVF6XBW4WWFE7VNPVC74S45Y/"
},
{
"type": "WEB",
"url": "https://security.paloaltonetworks.com/CVE-2023-0003"
@@ -25,6 +25,14 @@
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/E72T67UPDRXHIDLO3OROR25YAMN4GGW5/"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LKYHSZQFDNR7RSA7LHVLLIAQMVYCUGBG/"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X6QXN4ORIVF6XBW4WWFE7VNPVC74S45Y/"
},
{
"type": "WEB",
"url": "https://security.paloaltonetworks.com/CVE-2023-0004"
@@ -22,6 +22,10 @@
"type": "WEB",
"url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1852729"
},
{
"type": "WEB",
"url": "https://www.debian.org/security/2023/dsa-5535"
},
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2023-45/"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-43615"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GGRB5MO2KUJKYPMGXMIZH2WRH6QR5UZS/"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/O7SB7L6A56QZALDTOZ6O4X7PTC4I647R/"
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7rvg-gjgp-95j7",
"modified": "2023-10-26T03:30:26Z",
"published": "2023-10-26T03:30:26Z",
"aliases": [
"CVE-2023-31422"
],
"details": "An issue was discovered by Elastic whereby sensitive information is recorded in Kibana logs in the event of an error. The issue impacts only Kibana version 8.10.0 when logging in the JSON layout or when the pattern layout is configured to log the %meta pattern. Elastic has released Kibana 8.10.1 which resolves this issue. The error object recorded in the log contains request information, which can include sensitive data, such as authentication credentials, cookies, authorization headers, query params, request paths, and other metadata. Some examples of sensitive data which can be included in the logs are account credentials for kibana_system, kibana-metricbeat, or Kibana end-users.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31422"
},
{
"type": "WEB",
"url": "https://discuss.elastic.co/t/kibana-8-10-1-security-update/343287"
},
{
"type": "WEB",
"url": "https://www.elastic.co/community/security"
}
],
"database_specific": {
"cwe_ids": [
"CWE-532"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -24,6 +24,10 @@
{
"type": "WEB",
"url": "https://hackerone.com/reports/2092852"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LKYHSZQFDNR7RSA7LHVLLIAQMVYCUGBG/"
}
],
"database_specific": {
@@ -24,6 +24,10 @@
{
"type": "WEB",
"url": "https://hackerone.com/reports/2199818"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LKYHSZQFDNR7RSA7LHVLLIAQMVYCUGBG/"
}
],
"database_specific": {
@@ -22,6 +22,10 @@
"type": "WEB",
"url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1830820"
},
{
"type": "WEB",
"url": "https://www.debian.org/security/2023/dsa-5535"
},
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2023-45/"
@@ -22,6 +22,10 @@
"type": "WEB",
"url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1836705"
},
{
"type": "WEB",
"url": "https://www.debian.org/security/2023/dsa-5535"
},
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2023-45/"
@@ -22,6 +22,10 @@
"type": "WEB",
"url": "https://bugzilla.mozilla.org/buglist.cgi?bug_id=1836607%2C1840918%2C1848694%2C1848833%2C1850191%2C1850259%2C1852596%2C1853201%2C1854002%2C1855306%2C1855640%2C1856695"
},
{
"type": "WEB",
"url": "https://www.debian.org/security/2023/dsa-5535"
},
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2023-45/"
@@ -26,6 +26,10 @@
"type": "WEB",
"url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1836962"
},
{
"type": "WEB",
"url": "https://www.debian.org/security/2023/dsa-5535"
},
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2023-34/"
@@ -22,6 +22,10 @@
"type": "WEB",
"url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1845739"
},
{
"type": "WEB",
"url": "https://www.debian.org/security/2023/dsa-5535"
},
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2023-45/"
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wv9p-64pj-gq2g",
"modified": "2023-10-26T03:30:26Z",
"published": "2023-10-26T03:30:26Z",
"aliases": [
"CVE-2023-46667"
],
"details": "An issue was discovered in Fleet Server >= v8.10.0 and < v8.10.3 where Agent enrolment tokens are being inserted into the Fleet Servers log file in plain text. These enrolment tokens could allow someone to enrol an agent into an agent policy, and potentially use that to retrieve other secrets in the policy including for Elasticsearch and third-party services. Alternatively a threat actor could potentially enrol agents to the clusters and send arbitrary events to Elasticsearch.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46667"
},
{
"type": "WEB",
"url": "https://discuss.elastic.co/t/fleet-server-v8-10-3-security-update/344737"
},
{
"type": "WEB",
"url": "https://www.elastic.co/community/security"
}
],
"database_specific": {
"cwe_ids": [
"CWE-532"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -28,6 +28,14 @@
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/E72T67UPDRXHIDLO3OROR25YAMN4GGW5/"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LKYHSZQFDNR7RSA7LHVLLIAQMVYCUGBG/"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X6QXN4ORIVF6XBW4WWFE7VNPVC74S45Y/"
}
],
"database_specific": {