From 3a4d5169513f107286a0cf10fe51a99f8e0cc476 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 26 Oct 2023 03:31:41 +0000 Subject: [PATCH] Publish Advisories GHSA-rfc4-38hf-4pmp GHSA-mgj2-46rc-8756 GHSA-3qmg-867g-8xrq GHSA-656f-g689-89jh GHSA-7rvg-gjgp-95j7 GHSA-7xrv-q25v-f95m GHSA-9hm3-chgj-45rm GHSA-cw53-7m4g-22j6 GHSA-hhqg-994q-93m3 GHSA-hwgx-3qq3-2885 GHSA-p85h-gwrr-6mrj GHSA-vhm9-v8x6-w764 GHSA-wv9p-64pj-gq2g GHSA-x39v-frq9-5hh8 --- .../GHSA-rfc4-38hf-4pmp.json | 8 ++++ .../GHSA-mgj2-46rc-8756.json | 8 ++++ .../GHSA-3qmg-867g-8xrq.json | 4 ++ .../GHSA-656f-g689-89jh.json | 4 ++ .../GHSA-7rvg-gjgp-95j7.json | 42 +++++++++++++++++++ .../GHSA-7xrv-q25v-f95m.json | 4 ++ .../GHSA-9hm3-chgj-45rm.json | 4 ++ .../GHSA-cw53-7m4g-22j6.json | 4 ++ .../GHSA-hhqg-994q-93m3.json | 4 ++ .../GHSA-hwgx-3qq3-2885.json | 4 ++ .../GHSA-p85h-gwrr-6mrj.json | 4 ++ .../GHSA-vhm9-v8x6-w764.json | 4 ++ .../GHSA-wv9p-64pj-gq2g.json | 42 +++++++++++++++++++ .../GHSA-x39v-frq9-5hh8.json | 8 ++++ 14 files changed, 144 insertions(+) create mode 100644 advisories/unreviewed/2023/10/GHSA-7rvg-gjgp-95j7/GHSA-7rvg-gjgp-95j7.json create mode 100644 advisories/unreviewed/2023/10/GHSA-wv9p-64pj-gq2g/GHSA-wv9p-64pj-gq2g.json diff --git a/advisories/unreviewed/2023/02/GHSA-rfc4-38hf-4pmp/GHSA-rfc4-38hf-4pmp.json b/advisories/unreviewed/2023/02/GHSA-rfc4-38hf-4pmp/GHSA-rfc4-38hf-4pmp.json index 5e930afa525..880ee192f77 100644 --- a/advisories/unreviewed/2023/02/GHSA-rfc4-38hf-4pmp/GHSA-rfc4-38hf-4pmp.json +++ b/advisories/unreviewed/2023/02/GHSA-rfc4-38hf-4pmp/GHSA-rfc4-38hf-4pmp.json @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HMEELCREWMRT6NS7HWXLA6XFLLMO36HE/" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LKYHSZQFDNR7RSA7LHVLLIAQMVYCUGBG/" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UEJWL67XR67JAGEL2ZK22NA3BRKNMZNY/" @@ -41,6 +45,10 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VKFMKD4MJZIKFQJAAJ4VZ2FHIJ764A76/" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X6QXN4ORIVF6XBW4WWFE7VNPVC74S45Y/" + }, { "type": "WEB", "url": "https://security.paloaltonetworks.com/CVE-2023-0003" diff --git a/advisories/unreviewed/2023/04/GHSA-mgj2-46rc-8756/GHSA-mgj2-46rc-8756.json b/advisories/unreviewed/2023/04/GHSA-mgj2-46rc-8756/GHSA-mgj2-46rc-8756.json index 4ee86f3ab67..6a0fef28ba3 100644 --- a/advisories/unreviewed/2023/04/GHSA-mgj2-46rc-8756/GHSA-mgj2-46rc-8756.json +++ b/advisories/unreviewed/2023/04/GHSA-mgj2-46rc-8756/GHSA-mgj2-46rc-8756.json @@ -25,6 +25,14 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/E72T67UPDRXHIDLO3OROR25YAMN4GGW5/" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LKYHSZQFDNR7RSA7LHVLLIAQMVYCUGBG/" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X6QXN4ORIVF6XBW4WWFE7VNPVC74S45Y/" + }, { "type": "WEB", "url": "https://security.paloaltonetworks.com/CVE-2023-0004" diff --git a/advisories/unreviewed/2023/10/GHSA-3qmg-867g-8xrq/GHSA-3qmg-867g-8xrq.json b/advisories/unreviewed/2023/10/GHSA-3qmg-867g-8xrq/GHSA-3qmg-867g-8xrq.json index c28cc5131b3..78d9399d483 100644 --- a/advisories/unreviewed/2023/10/GHSA-3qmg-867g-8xrq/GHSA-3qmg-867g-8xrq.json +++ b/advisories/unreviewed/2023/10/GHSA-3qmg-867g-8xrq/GHSA-3qmg-867g-8xrq.json @@ -22,6 +22,10 @@ "type": "WEB", "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1852729" }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2023/dsa-5535" + }, { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2023-45/" diff --git a/advisories/unreviewed/2023/10/GHSA-656f-g689-89jh/GHSA-656f-g689-89jh.json b/advisories/unreviewed/2023/10/GHSA-656f-g689-89jh/GHSA-656f-g689-89jh.json index 73a3adc1ef4..54b2d4ce319 100644 --- a/advisories/unreviewed/2023/10/GHSA-656f-g689-89jh/GHSA-656f-g689-89jh.json +++ b/advisories/unreviewed/2023/10/GHSA-656f-g689-89jh/GHSA-656f-g689-89jh.json @@ -21,6 +21,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-43615" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GGRB5MO2KUJKYPMGXMIZH2WRH6QR5UZS/" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/O7SB7L6A56QZALDTOZ6O4X7PTC4I647R/" diff --git a/advisories/unreviewed/2023/10/GHSA-7rvg-gjgp-95j7/GHSA-7rvg-gjgp-95j7.json b/advisories/unreviewed/2023/10/GHSA-7rvg-gjgp-95j7/GHSA-7rvg-gjgp-95j7.json new file mode 100644 index 00000000000..967bd387168 --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-7rvg-gjgp-95j7/GHSA-7rvg-gjgp-95j7.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7rvg-gjgp-95j7", + "modified": "2023-10-26T03:30:26Z", + "published": "2023-10-26T03:30:26Z", + "aliases": [ + "CVE-2023-31422" + ], + "details": "An issue was discovered by Elastic whereby sensitive information is recorded in Kibana logs in the event of an error. The issue impacts only Kibana version 8.10.0 when logging in the JSON layout or when the pattern layout is configured to log the %meta pattern. Elastic has released Kibana 8.10.1 which resolves this issue. The error object recorded in the log contains request information, which can include sensitive data, such as authentication credentials, cookies, authorization headers, query params, request paths, and other metadata. Some examples of sensitive data which can be included in the logs are account credentials for kibana_system, kibana-metricbeat, or Kibana end-users.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31422" + }, + { + "type": "WEB", + "url": "https://discuss.elastic.co/t/kibana-8-10-1-security-update/343287" + }, + { + "type": "WEB", + "url": "https://www.elastic.co/community/security" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-7xrv-q25v-f95m/GHSA-7xrv-q25v-f95m.json b/advisories/unreviewed/2023/10/GHSA-7xrv-q25v-f95m/GHSA-7xrv-q25v-f95m.json index 68d9af95379..50ce6c21eb4 100644 --- a/advisories/unreviewed/2023/10/GHSA-7xrv-q25v-f95m/GHSA-7xrv-q25v-f95m.json +++ b/advisories/unreviewed/2023/10/GHSA-7xrv-q25v-f95m/GHSA-7xrv-q25v-f95m.json @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://hackerone.com/reports/2092852" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LKYHSZQFDNR7RSA7LHVLLIAQMVYCUGBG/" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-9hm3-chgj-45rm/GHSA-9hm3-chgj-45rm.json b/advisories/unreviewed/2023/10/GHSA-9hm3-chgj-45rm/GHSA-9hm3-chgj-45rm.json index bf9a178550d..8189a962374 100644 --- a/advisories/unreviewed/2023/10/GHSA-9hm3-chgj-45rm/GHSA-9hm3-chgj-45rm.json +++ b/advisories/unreviewed/2023/10/GHSA-9hm3-chgj-45rm/GHSA-9hm3-chgj-45rm.json @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://hackerone.com/reports/2199818" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LKYHSZQFDNR7RSA7LHVLLIAQMVYCUGBG/" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-cw53-7m4g-22j6/GHSA-cw53-7m4g-22j6.json b/advisories/unreviewed/2023/10/GHSA-cw53-7m4g-22j6/GHSA-cw53-7m4g-22j6.json index a6fc2cebe96..0cb70277249 100644 --- a/advisories/unreviewed/2023/10/GHSA-cw53-7m4g-22j6/GHSA-cw53-7m4g-22j6.json +++ b/advisories/unreviewed/2023/10/GHSA-cw53-7m4g-22j6/GHSA-cw53-7m4g-22j6.json @@ -22,6 +22,10 @@ "type": "WEB", "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1830820" }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2023/dsa-5535" + }, { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2023-45/" diff --git a/advisories/unreviewed/2023/10/GHSA-hhqg-994q-93m3/GHSA-hhqg-994q-93m3.json b/advisories/unreviewed/2023/10/GHSA-hhqg-994q-93m3/GHSA-hhqg-994q-93m3.json index c36dea89f51..84ab5ff3e73 100644 --- a/advisories/unreviewed/2023/10/GHSA-hhqg-994q-93m3/GHSA-hhqg-994q-93m3.json +++ b/advisories/unreviewed/2023/10/GHSA-hhqg-994q-93m3/GHSA-hhqg-994q-93m3.json @@ -22,6 +22,10 @@ "type": "WEB", "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1836705" }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2023/dsa-5535" + }, { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2023-45/" diff --git a/advisories/unreviewed/2023/10/GHSA-hwgx-3qq3-2885/GHSA-hwgx-3qq3-2885.json b/advisories/unreviewed/2023/10/GHSA-hwgx-3qq3-2885/GHSA-hwgx-3qq3-2885.json index d49d165ccc5..ab6351bd711 100644 --- a/advisories/unreviewed/2023/10/GHSA-hwgx-3qq3-2885/GHSA-hwgx-3qq3-2885.json +++ b/advisories/unreviewed/2023/10/GHSA-hwgx-3qq3-2885/GHSA-hwgx-3qq3-2885.json @@ -22,6 +22,10 @@ "type": "WEB", "url": "https://bugzilla.mozilla.org/buglist.cgi?bug_id=1836607%2C1840918%2C1848694%2C1848833%2C1850191%2C1850259%2C1852596%2C1853201%2C1854002%2C1855306%2C1855640%2C1856695" }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2023/dsa-5535" + }, { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2023-45/" diff --git a/advisories/unreviewed/2023/10/GHSA-p85h-gwrr-6mrj/GHSA-p85h-gwrr-6mrj.json b/advisories/unreviewed/2023/10/GHSA-p85h-gwrr-6mrj/GHSA-p85h-gwrr-6mrj.json index 143f9dffe90..6b1367c6c1b 100644 --- a/advisories/unreviewed/2023/10/GHSA-p85h-gwrr-6mrj/GHSA-p85h-gwrr-6mrj.json +++ b/advisories/unreviewed/2023/10/GHSA-p85h-gwrr-6mrj/GHSA-p85h-gwrr-6mrj.json @@ -26,6 +26,10 @@ "type": "WEB", "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1836962" }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2023/dsa-5535" + }, { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2023-34/" diff --git a/advisories/unreviewed/2023/10/GHSA-vhm9-v8x6-w764/GHSA-vhm9-v8x6-w764.json b/advisories/unreviewed/2023/10/GHSA-vhm9-v8x6-w764/GHSA-vhm9-v8x6-w764.json index 5872578b16b..acdc10476b4 100644 --- a/advisories/unreviewed/2023/10/GHSA-vhm9-v8x6-w764/GHSA-vhm9-v8x6-w764.json +++ b/advisories/unreviewed/2023/10/GHSA-vhm9-v8x6-w764/GHSA-vhm9-v8x6-w764.json @@ -22,6 +22,10 @@ "type": "WEB", "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1845739" }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2023/dsa-5535" + }, { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2023-45/" diff --git a/advisories/unreviewed/2023/10/GHSA-wv9p-64pj-gq2g/GHSA-wv9p-64pj-gq2g.json b/advisories/unreviewed/2023/10/GHSA-wv9p-64pj-gq2g/GHSA-wv9p-64pj-gq2g.json new file mode 100644 index 00000000000..cd3553f3e9f --- /dev/null +++ b/advisories/unreviewed/2023/10/GHSA-wv9p-64pj-gq2g/GHSA-wv9p-64pj-gq2g.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wv9p-64pj-gq2g", + "modified": "2023-10-26T03:30:26Z", + "published": "2023-10-26T03:30:26Z", + "aliases": [ + "CVE-2023-46667" + ], + "details": "An issue was discovered in Fleet Server >= v8.10.0 and < v8.10.3 where Agent enrolment tokens are being inserted into the Fleet Server’s log file in plain text. These enrolment tokens could allow someone to enrol an agent into an agent policy, and potentially use that to retrieve other secrets in the policy including for Elasticsearch and third-party services. Alternatively a threat actor could potentially enrol agents to the clusters and send arbitrary events to Elasticsearch.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46667" + }, + { + "type": "WEB", + "url": "https://discuss.elastic.co/t/fleet-server-v8-10-3-security-update/344737" + }, + { + "type": "WEB", + "url": "https://www.elastic.co/community/security" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-x39v-frq9-5hh8/GHSA-x39v-frq9-5hh8.json b/advisories/unreviewed/2023/10/GHSA-x39v-frq9-5hh8/GHSA-x39v-frq9-5hh8.json index 6759ef7dfe5..be4efd5b6d6 100644 --- a/advisories/unreviewed/2023/10/GHSA-x39v-frq9-5hh8/GHSA-x39v-frq9-5hh8.json +++ b/advisories/unreviewed/2023/10/GHSA-x39v-frq9-5hh8/GHSA-x39v-frq9-5hh8.json @@ -28,6 +28,14 @@ { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/E72T67UPDRXHIDLO3OROR25YAMN4GGW5/" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LKYHSZQFDNR7RSA7LHVLLIAQMVYCUGBG/" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X6QXN4ORIVF6XBW4WWFE7VNPVC74S45Y/" } ], "database_specific": {