diff --git a/advisories/github-reviewed/2024/06/GHSA-3j4h-h3fp-vwww/GHSA-3j4h-h3fp-vwww.json b/advisories/github-reviewed/2024/06/GHSA-3j4h-h3fp-vwww/GHSA-3j4h-h3fp-vwww.json new file mode 100644 index 00000000000..5e0fbc40351 --- /dev/null +++ b/advisories/github-reviewed/2024/06/GHSA-3j4h-h3fp-vwww/GHSA-3j4h-h3fp-vwww.json @@ -0,0 +1,61 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3j4h-h3fp-vwww", + "modified": "2024-06-17T21:24:18Z", + "published": "2024-06-17T21:24:18Z", + "aliases": [ + "CVE-2024-34694" + ], + "summary": "LNbits improperly handles potential network and payment failures when using Eclair backend", + "details": "### Summary\n\nPaying invoices in Eclair that do not get settled within the internal timeout (about 30s) lead to a payment being considered failed, even though it may still be in flight.\n\n### Details\n\nUsing `blocking: true` on the API call will lead to a timeout error if a payment does not get settled in the 30s timeout with the error: `Ask timed out on [Actor[akka://eclair-node/user/$l#134241942]] after [30000 ms]. Message of type [fr.acinq.eclair.payment.send.PaymentInitiator$SendPaymentToNode]. A typical reason for AskTimeoutException is that the recipient actor didn't send a reply.`\nhttps://github.com/lnbits/lnbits/blob/c04c13b2f8cfbb625571a07dfddeb65ea6df8dac/lnbits/wallets/eclair.py#L138\n\nThis is considered a payment failure by parts of the code, and assumes the payment is not going to be settled after:\nhttps://github.com/lnbits/lnbits/blob/c04c13b2f8cfbb625571a07dfddeb65ea6df8dac/lnbits/wallets/eclair.py#L144\nhttps://github.com/lnbits/lnbits/blob/c04c13b2f8cfbb625571a07dfddeb65ea6df8dac/lnbits/wallets/eclair.py#L141\nhttps://github.com/lnbits/lnbits/blob/c04c13b2f8cfbb625571a07dfddeb65ea6df8dac/lnbits/wallets/eclair.py#L146\n\nThe best way to fix this is to check the payment status after an error, and when not sure, always consider a payment still in flight.\n\n### PoC\n\nA very simple way to exploit this is:\n- Create a hold invoice\n- Pay the invoice with the LNbits server backed by an Eclair node, until it times out\n- Settle the hold invoice\n\n### Impact\n\nThis vulnerability can lead to a total loss of funds for the node backend.\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [ + { + "package": { + "ecosystem": "PyPI", + "name": "lnbits" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.12.6" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/lnbits/lnbits/security/advisories/GHSA-3j4h-h3fp-vwww" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-34694" + }, + { + "type": "PACKAGE", + "url": "https://github.com/lnbits/lnbits" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-754" + ], + "severity": "HIGH", + "github_reviewed": true, + "github_reviewed_at": "2024-06-17T21:24:18Z", + "nvd_published_at": "2024-06-14T15:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-9xpj-62mm-24h2/GHSA-9xpj-62mm-24h2.json b/advisories/github-reviewed/2024/06/GHSA-9xpj-62mm-24h2/GHSA-9xpj-62mm-24h2.json similarity index 57% rename from advisories/unreviewed/2024/06/GHSA-9xpj-62mm-24h2/GHSA-9xpj-62mm-24h2.json rename to advisories/github-reviewed/2024/06/GHSA-9xpj-62mm-24h2/GHSA-9xpj-62mm-24h2.json index c1df2dbd62e..e07286f797e 100644 --- a/advisories/unreviewed/2024/06/GHSA-9xpj-62mm-24h2/GHSA-9xpj-62mm-24h2.json +++ b/advisories/github-reviewed/2024/06/GHSA-9xpj-62mm-24h2/GHSA-9xpj-62mm-24h2.json @@ -1,17 +1,36 @@ { "schema_version": "1.4.0", "id": "GHSA-9xpj-62mm-24h2", - "modified": "2024-06-14T09:31:17Z", + "modified": "2024-06-17T21:24:09Z", "published": "2024-06-14T09:31:17Z", "aliases": [ "CVE-2024-25142" ], + "summary": "Apache Airflow does not return the \"Cache-Control\" header for dynamic content", "details": "Use of Web Browser Cache Containing Sensitive Information vulnerability in Apache Airflow. \n\nAirflow did not return \"Cache-Control\" header for dynamic content, which in case of some browsers could result in potentially storing sensitive data in local cache of the browser.\n\nThis issue affects Apache Airflow: before 2.9.2.\n\nUsers are recommended to upgrade to version 2.9.2, which fixes the issue.\n\n", "severity": [ ], "affected": [ - + { + "package": { + "ecosystem": "PyPI", + "name": "apache-airflow" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.9.2" + } + ] + } + ] + } ], "references": [ { @@ -22,6 +41,14 @@ "type": "WEB", "url": "https://github.com/apache/airflow/pull/39550" }, + { + "type": "WEB", + "url": "https://github.com/apache/airflow/commit/94eb647de692a4d9555b02dce85974da5d4c04e3" + }, + { + "type": "PACKAGE", + "url": "https://github.com/apache/airflow" + }, { "type": "WEB", "url": "https://lists.apache.org/thread/cg1j28lk0fhzthk0of1g7vy7p2n1j7nr" @@ -31,9 +58,9 @@ "cwe_ids": [ "CWE-525" ], - "severity": null, - "github_reviewed": false, - "github_reviewed_at": null, + "severity": "LOW", + "github_reviewed": true, + "github_reviewed_at": "2024-06-17T21:24:09Z", "nvd_published_at": "2024-06-14T09:15:09Z" } } \ No newline at end of file