Publish Advisories

GHSA-5x96-j797-5qqw
GHSA-5xfg-wv98-264m
GHSA-r23h-3jmw-q7hr
This commit is contained in:
advisory-database[bot]
2024-04-24 20:03:58 +00:00
parent 7a0e40a8cf
commit 4095f3eeb2
3 changed files with 269 additions and 0 deletions
@@ -0,0 +1,123 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5x96-j797-5qqw",
"modified": "2024-04-24T20:02:08Z",
"published": "2024-04-24T20:02:08Z",
"aliases": [
"CVE-2020-8566"
],
"summary": "Sensitive Information leak via Log File in Kubernetes",
"details": "In Kubernetes clusters using Ceph RBD as a storage provisioner, with logging level of at least 4, Ceph RBD admin secrets can be written to logs. This occurs in kube-controller-manager's logs during provisioning of Ceph RBD persistent claims. This affects < v1.19.3, < v1.18.10, < v1.17.13.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [
{
"package": {
"ecosystem": "Go",
"name": "github.com/kubernetes/kubernetes"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "1.17.13"
}
]
}
]
},
{
"package": {
"ecosystem": "Go",
"name": "github.com/kubernetes/kubernetes"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "1.18.0"
},
{
"fixed": "1.18.10"
}
]
}
]
},
{
"package": {
"ecosystem": "Go",
"name": "github.com/kubernetes/kubernetes"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "1.19.0"
},
{
"fixed": "1.19.3"
}
]
}
]
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2020-8566"
},
{
"type": "WEB",
"url": "https://github.com/kubernetes/kubernetes/issues/95624"
},
{
"type": "WEB",
"url": "https://github.com/kubernetes/kubernetes/pull/95245"
},
{
"type": "WEB",
"url": "https://github.com/kubernetes/kubernetes/pull/95245/commits/e91ec4fad3366d2dee020919f7c2a0d7b52fd3ea"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=1886640"
},
{
"type": "PACKAGE",
"url": "https://github.com/kubernetes/kubernetes"
},
{
"type": "WEB",
"url": "https://groups.google.com/g/kubernetes-announce/c/ScdmyORnPDk"
},
{
"type": "WEB",
"url": "https://groups.google.com/g/kubernetes-security-discuss/c/vm-HcrFUOCs/m/36utxAM5CwAJ"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20210122-0006"
}
],
"database_specific": {
"cwe_ids": [
"CWE-532"
],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-04-24T20:02:08Z",
"nvd_published_at": null
}
}
@@ -0,0 +1,85 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5xfg-wv98-264m",
"modified": "2024-04-24T20:02:21Z",
"published": "2024-04-24T20:02:20Z",
"aliases": [
"CVE-2020-8563"
],
"summary": "Sensitive Information leak via Log File in Kubernetes",
"details": "In Kubernetes clusters using VSphere as a cloud provider, with a logging level set to 4 or above, VSphere cloud credentials will be leaked in the cloud controller manager's log. This affects < v1.19.3.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N"
}
],
"affected": [
{
"package": {
"ecosystem": "Go",
"name": "github.com/kubernetes/kubernetes"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "1.19.3"
}
]
}
]
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2020-8563"
},
{
"type": "WEB",
"url": "https://github.com/kubernetes/kubernetes/issues/95621"
},
{
"type": "WEB",
"url": "https://github.com/kubernetes/kubernetes/pull/95236"
},
{
"type": "WEB",
"url": "https://github.com/kubernetes/kubernetes/pull/95236/commits/247f6dd09299bc7893c1e0affea11c0255025b96"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=1886635"
},
{
"type": "PACKAGE",
"url": "https://github.com/kubernetes/kubernetes"
},
{
"type": "WEB",
"url": "https://groups.google.com/g/kubernetes-announce/c/ScdmyORnPDk"
},
{
"type": "WEB",
"url": "https://groups.google.com/g/kubernetes-security-discuss/c/vm-HcrFUOCs/m/36utxAM5CwAJ"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20210122-0006"
}
],
"database_specific": {
"cwe_ids": [
"CWE-532"
],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-04-24T20:02:20Z",
"nvd_published_at": null
}
}
@@ -0,0 +1,61 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r23h-3jmw-q7hr",
"modified": "2024-04-24T20:01:46Z",
"published": "2024-04-24T20:01:46Z",
"aliases": [
"CVE-2020-10937"
],
"summary": "Access Restriction Bypass in go-ipfs",
"details": "An issue was discovered in IPFS (aka go-ipfs) 0.4.23. An attacker can generate ephemeral identities (Sybils) and leverage the IPFS connection management reputation system to poison other nodes' routing tables, eclipsing the nodes that are the target of the attack from the rest of the network. Later versions, in particular go-ipfs 0.7, mitigate this.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
{
"package": {
"ecosystem": "Go",
"name": "github.com/ipfs/go-ipfs"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "0.7.0"
}
]
}
]
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2020-10937"
},
{
"type": "WEB",
"url": "https://blog.ipfs.io/2020-10-30-dht-hardening"
},
{
"type": "WEB",
"url": "https://graz.pure.elsevier.com/en/publications/total-eclipse-of-the-heart-disrupting-the-interplanetary-file-sys"
}
],
"database_specific": {
"cwe_ids": [
"CWE-284"
],
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2024-04-24T20:01:46Z",
"nvd_published_at": null
}
}