Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2024-12-02 05:11:17 +00:00
parent edb3638c88
commit 3a53f7a83f
931 changed files with 1630 additions and 4890 deletions
@@ -8,9 +8,7 @@
],
"summary": "actionpack Improper Input Validation vulnerability",
"details": "`actionpack/lib/action_view/template/text.rb` in Action View in Ruby on Rails 3.x before 3.2.17 converts MIME type strings to symbols during use of the `:text` option to the `render` method, which allows remote attackers to cause a denial of service (memory consumption) by including these strings in headers.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -3,9 +3,7 @@
"id": "GHSA-226w-6hhj-69hp",
"modified": "2021-09-30T20:06:59Z",
"published": "2020-09-03T19:06:52Z",
"aliases": [
],
"aliases": [],
"summary": "Malicious Package in cal_rd",
"details": "Version 0.1.1 of `rc_cal` contained malicious code. The code when executed in the browser would enumerate password, cvc, cardnumber fields from forms and send the extracted values to `https://js-metrics.com/minjs.php?pl=`\n\n\n\n## Recommendation\n\nRemove the package from your environment. It's also recommended to evaluate your application to determine whether or not user data was compromised.",
"severity": [
@@ -3,14 +3,10 @@
"id": "GHSA-2m96-9w4j-wgv7",
"modified": "2020-08-31T18:46:06Z",
"published": "2020-09-03T18:06:00Z",
"aliases": [
],
"aliases": [],
"summary": "Prototype Pollution in lodash.merge",
"details": "Versions of `lodash.merge` before 4.6.1 are vulnerable to Prototype Pollution. The function 'merge' may allow a malicious user to modify the prototype of `Object` via `__proto__` causing the addition or modification of an existing property that will exist on all objects.\n\n\n\n\n## Recommendation\n\nUpdate to version 4.6.1 or later.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -3,14 +3,10 @@
"id": "GHSA-2mvq-xp48-4c77",
"modified": "2021-09-29T18:37:04Z",
"published": "2020-09-03T20:35:29Z",
"aliases": [
],
"aliases": [],
"summary": "Denial of Service in subtext",
"details": "All versions of `subtext` are vulnerable to Denial of Service (DoS). The package fails to enforce the `maxBytes` configuration for payloads with chunked encoding that are written to the file system. This allows attackers to send requests with arbitrary payload sizes, which may exhaust system resources leading to Denial of Service.\n\n\n## Recommendation\n\nThis package is not actively maintained and has been moved to `@hapi/subtext` where version 6.1.2.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -3,9 +3,7 @@
"id": "GHSA-377f-vvrc-9wgg",
"modified": "2021-09-30T20:07:38Z",
"published": "2020-09-03T19:09:07Z",
"aliases": [
],
"aliases": [],
"summary": "Malicious Package in zemen",
"details": "Version 0.0.5 of `zemen` contained malicious code. The code when executed in the browser would enumerate password, cvc, cardnumber fields from forms and send the extracted values to `https://js-metrics.com/minjs.php?pl=`\n\n\n\n## Recommendation\n\nRemove the package from your environment. It's also recommended to evaluate your application to determine whether or not user data was compromised.",
"severity": [
@@ -3,9 +3,7 @@
"id": "GHSA-38vq-cjh5-vw7x",
"modified": "2021-09-30T20:04:09Z",
"published": "2020-09-03T18:13:41Z",
"aliases": [
],
"aliases": [],
"summary": "Malicious Package in nodes.js",
"details": "All versions of `nodes.js ` contain malicious code. The package searches and installs globally thousands of packages based on keywords `node`, `react`, `react-native`, `vue`, `angular` and `babel` to fill the system's memory.\n\n\n## Recommendation\n\nRemove the package from your environment and validate what packages are installed.",
"severity": [
@@ -3,9 +3,7 @@
"id": "GHSA-3f97-rj68-2pjf",
"modified": "2021-09-29T20:57:28Z",
"published": "2020-09-03T21:48:35Z",
"aliases": [
],
"aliases": [],
"summary": "Malicious Package in buffe2-xor",
"details": "Version 2.0.2 contained malicious code. The package targeted the Ethereum cryptocurrency and performed transactions to wallets not controlled by the user.\n\n\n## Recommendation\n\nRemove the package from your environment. Ensure no Ethereum funds were compromised.",
"severity": [
@@ -3,14 +3,10 @@
"id": "GHSA-46fh-8fc5-xcwx",
"modified": "2020-08-31T18:46:13Z",
"published": "2020-09-03T18:09:16Z",
"aliases": [
],
"aliases": [],
"summary": "Prototype Pollution in lodash.defaultsdeep",
"details": "Versions of `lodash.defaultsdeep` before 4.6.1 are vulnerable to Prototype Pollution. The function 'defaultsDeep' may allow a malicious user to modify the prototype of `Object` via `__proto__` causing the addition or modification of an existing property that will exist on all objects.\n\n\n\n\n## Recommendation\n\nUpdate to version 4.6.1 or later.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -3,9 +3,7 @@
"id": "GHSA-4hm7-73ch-vm59",
"modified": "2021-09-29T20:58:16Z",
"published": "2020-09-03T21:49:43Z",
"aliases": [
],
"aliases": [],
"summary": "Malicious Package in buffer-8or",
"details": "Version 2.0.2 contained malicious code. The package targeted the Ethereum cryptocurrency and performed transactions to wallets not controlled by the user.\n\n\n## Recommendation\n\nRemove the package from your environment. Ensure no Ethereum funds were compromised.",
"severity": [
@@ -3,14 +3,10 @@
"id": "GHSA-4vvp-x9h2-x2vf",
"modified": "2020-08-31T18:48:53Z",
"published": "2020-09-03T20:26:39Z",
"aliases": [
],
"aliases": [],
"summary": "Path Traversal in public",
"details": "All versions of `public` are vulnerable to Path Traversal. This vulnerability allows an attacker to access files outside the webroot since it allows symlink navigation in the URL.\n\n\n## Recommendation\n\nNo fix is currently available. Do not use `public` in production or consider using an alternative module until a fix is made available.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -3,14 +3,10 @@
"id": "GHSA-4x7w-frcq-v4m3",
"modified": "2020-08-31T18:49:56Z",
"published": "2020-09-03T20:38:47Z",
"aliases": [
],
"aliases": [],
"summary": "Path Traversal in @wturyn/swagger-injector",
"details": "All versions of `@wturyn/swagger-injector` are vulnerable to Path Traversal. The package fails to sanitize URLs, allowing attackers to access server files outside of the configured `dist` folder using relative paths.\n\n\n## Recommendation\n\nNo fix is currently available. Consider using an alternative package until a fix is made available.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -3,9 +3,7 @@
"id": "GHSA-4xg9-g7qj-jhg4",
"modified": "2021-09-29T20:33:40Z",
"published": "2020-09-03T20:46:36Z",
"aliases": [
],
"aliases": [],
"summary": "Malicious Package in comander",
"details": "All versions of `comander` contains malicious code . The package is malware designed to take advantage of users making a mistake when typing the name of a module to install. Upon require the package attempts to start a cryptocurrency miner using coin-hive.\n\n\n## Recommendation\n\nRemove the package from your environment and verify whether your system is running the cryptocurrency miner.",
"severity": [
@@ -3,14 +3,10 @@
"id": "GHSA-5947-m4fg-xhqg",
"modified": "2020-08-31T18:46:11Z",
"published": "2020-09-03T18:08:10Z",
"aliases": [
],
"aliases": [],
"summary": "Prototype Pollution in lodash.mergewith",
"details": "Versions of `lodash.mergewith` before 4.6.1 are vulnerable to Prototype Pollution. The function 'mergeWith' may allow a malicious user to modify the prototype of `Object` via `__proto__` causing the addition or modification of an existing property that will exist on all objects.\n\n\n\n\n## Recommendation\n\nUpdate to version 4.6.1 or later.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -3,9 +3,7 @@
"id": "GHSA-5ggx-g294-qj3q",
"modified": "2021-09-29T20:57:42Z",
"published": "2020-09-03T21:47:29Z",
"aliases": [
],
"aliases": [],
"summary": "Malicious Package in buffeb-xor",
"details": "Version 2.0.2 contained malicious code. The package targeted the Ethereum cryptocurrency and performed transactions to wallets not controlled by the user.\n\n\n## Recommendation\n\nRemove the package from your environment. Ensure no Ethereum funds were compromised.",
"severity": [
@@ -3,9 +3,7 @@
"id": "GHSA-5jgp-pg4f-q8vj",
"modified": "2021-09-30T20:27:21Z",
"published": "2020-09-03T19:55:42Z",
"aliases": [
],
"aliases": [],
"summary": "Malicious Package in node-ftp",
"details": "This package contained malicious code. The package uploaded system information such as OS and hostname to a remote server.\n\n\n## Recommendation\n\nRemove the package from your environment. There are no indications of further compromise.",
"severity": [
@@ -3,9 +3,7 @@
"id": "GHSA-5mm9-55c9-p5r7",
"modified": "2021-09-30T20:26:48Z",
"published": "2020-09-03T19:53:31Z",
"aliases": [
],
"aliases": [],
"summary": "Malicious Package in mogoose",
"details": "This package contained malicious code. The package uploaded system information such as OS and hostname to a remote server.\n\n\n## Recommendation\n\nRemove the package from your environment. There are no indications of further compromise.",
"severity": [
@@ -3,14 +3,10 @@
"id": "GHSA-5mrr-rgp6-x4gr",
"modified": "2020-08-31T18:48:01Z",
"published": "2020-09-03T19:39:05Z",
"aliases": [
],
"aliases": [],
"summary": "Command Injection in marsdb",
"details": "All versions of `marsdb` are vulnerable to Command Injection. In the `DocumentMatcher` class, selectors on `$where` clauses are passed to a Function constructor unsanitized. This allows attackers to run arbitrary commands in the system when the function is executed.\n\n\n## Recommendation\n\nNo fix is currently available. Consider using an alternative package until a fix is made available.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -3,9 +3,7 @@
"id": "GHSA-6584-gfwm-3vc3",
"modified": "2021-09-29T20:54:03Z",
"published": "2020-09-03T21:43:01Z",
"aliases": [
],
"aliases": [],
"summary": "Malicious Package in budfer-xor",
"details": "Version 2.0.2 contained malicious code. The package targeted the Ethereum cryptocurrency and performed transactions to wallets not controlled by the user.\n\n\n## Recommendation\n\nRemove the package from your environment. Ensure no Ethereum funds were compromised.",
"severity": [
@@ -3,9 +3,7 @@
"id": "GHSA-69r6-7h4f-9p7q",
"modified": "2021-09-29T20:32:46Z",
"published": "2020-09-03T20:41:01Z",
"aliases": [
],
"aliases": [],
"summary": "Malicious Package in discord.js-user",
"details": "All versions of `discord.js-user` contain malicious code. The package uploads the user's Discord token to a remote server.\n\n\n## Recommendation\n\nRemove the package from your environment. Ensure any compromised tokens are invalidated.",
"severity": [
@@ -3,9 +3,7 @@
"id": "GHSA-6xg2-cf6h-x4v8",
"modified": "2021-09-29T20:58:54Z",
"published": "2020-09-03T21:53:05Z",
"aliases": [
],
"aliases": [],
"summary": "Malicious Package in buffer-por",
"details": "Version 2.0.2 contained malicious code. The package targeted the Ethereum cryptocurrency and performed transactions to wallets not controlled by the user.\n\n\n## Recommendation\n\nRemove the package from your environment. Ensure no Ethereum funds were compromised.",
"severity": [

Some files were not shown because too many files have changed in this diff Show More