From 44813b8370a9abd94510e61f76bec951fadc5b15 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 23 Dec 2024 18:32:14 +0000 Subject: [PATCH] Publish Advisories GHSA-f9mp-9f6r-9536 GHSA-29rx-6chj-44xc GHSA-2q2v-7x59-8w6v GHSA-482h-984g-m9qw GHSA-85h7-g6vm-p392 GHSA-g7gx-qmj4-gxrc GHSA-mrm7-vh23-g98v GHSA-wxhc-3989-9jq8 GHSA-xqq2-v4rf-49qr GHSA-6c2p-rqx3-w4px GHSA-77pm-w3hx-f8mj GHSA-vq94-9pfv-ccqr --- .../GHSA-f9mp-9f6r-9536.json | 4 +- .../GHSA-29rx-6chj-44xc.json | 15 +++-- .../GHSA-2q2v-7x59-8w6v.json | 15 +++-- .../GHSA-482h-984g-m9qw.json | 15 +++-- .../GHSA-85h7-g6vm-p392.json | 15 +++-- .../GHSA-g7gx-qmj4-gxrc.json | 15 +++-- .../GHSA-mrm7-vh23-g98v.json | 15 +++-- .../GHSA-wxhc-3989-9jq8.json | 15 +++-- .../GHSA-xqq2-v4rf-49qr.json | 15 +++-- .../GHSA-6c2p-rqx3-w4px.json | 35 +++++++++++ .../GHSA-77pm-w3hx-f8mj.json | 63 +++++++++++++++++++ .../GHSA-vq94-9pfv-ccqr.json | 40 ++++++++++++ 12 files changed, 229 insertions(+), 33 deletions(-) create mode 100644 advisories/unreviewed/2024/12/GHSA-6c2p-rqx3-w4px/GHSA-6c2p-rqx3-w4px.json create mode 100644 advisories/unreviewed/2024/12/GHSA-77pm-w3hx-f8mj/GHSA-77pm-w3hx-f8mj.json create mode 100644 advisories/unreviewed/2024/12/GHSA-vq94-9pfv-ccqr/GHSA-vq94-9pfv-ccqr.json diff --git a/advisories/unreviewed/2024/03/GHSA-f9mp-9f6r-9536/GHSA-f9mp-9f6r-9536.json b/advisories/unreviewed/2024/03/GHSA-f9mp-9f6r-9536/GHSA-f9mp-9f6r-9536.json index 233fdf64fc4..9b5f4e3c690 100644 --- a/advisories/unreviewed/2024/03/GHSA-f9mp-9f6r-9536/GHSA-f9mp-9f6r-9536.json +++ b/advisories/unreviewed/2024/03/GHSA-f9mp-9f6r-9536/GHSA-f9mp-9f6r-9536.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-29rx-6chj-44xc/GHSA-29rx-6chj-44xc.json b/advisories/unreviewed/2024/05/GHSA-29rx-6chj-44xc/GHSA-29rx-6chj-44xc.json index b6ed1cceb8e..79dd2dd0737 100644 --- a/advisories/unreviewed/2024/05/GHSA-29rx-6chj-44xc/GHSA-29rx-6chj-44xc.json +++ b/advisories/unreviewed/2024/05/GHSA-29rx-6chj-44xc/GHSA-29rx-6chj-44xc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-29rx-6chj-44xc", - "modified": "2024-05-21T15:31:41Z", + "modified": "2024-12-23T18:30:47Z", "published": "2024-05-21T15:31:41Z", "aliases": [ "CVE-2021-47291" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: fix another slab-out-of-bounds in fib6_nh_flush_exceptions\n\nWhile running the self-tests on a KASAN enabled kernel, I observed a\nslab-out-of-bounds splat very similar to the one reported in\ncommit 821bbf79fe46 (\"ipv6: Fix KASAN: slab-out-of-bounds Read in\n fib6_nh_flush_exceptions\").\n\nWe additionally need to take care of fib6_metrics initialization\nfailure when the caller provides an nh.\n\nThe fix is similar, explicitly free the route instead of calling\nfib6_info_release on a half-initialized object.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T15:15:17Z" diff --git a/advisories/unreviewed/2024/05/GHSA-2q2v-7x59-8w6v/GHSA-2q2v-7x59-8w6v.json b/advisories/unreviewed/2024/05/GHSA-2q2v-7x59-8w6v/GHSA-2q2v-7x59-8w6v.json index 951e142f0ac..0e8ed37f37a 100644 --- a/advisories/unreviewed/2024/05/GHSA-2q2v-7x59-8w6v/GHSA-2q2v-7x59-8w6v.json +++ b/advisories/unreviewed/2024/05/GHSA-2q2v-7x59-8w6v/GHSA-2q2v-7x59-8w6v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2q2v-7x59-8w6v", - "modified": "2024-06-27T12:30:45Z", + "modified": "2024-12-23T18:30:47Z", "published": "2024-05-01T15:30:35Z", "aliases": [ "CVE-2024-27046" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfp: flower: handle acti_netdevs allocation failure\n\nThe kmalloc_array() in nfp_fl_lag_do_work() will return null, if\nthe physical memory has run out. As a result, if we dereference\nthe acti_netdevs, the null pointer dereference bugs will happen.\n\nThis patch adds a check to judge whether allocation failure occurs.\nIf it happens, the delayed work will be rescheduled and try again.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -60,8 +65,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-01T13:15:49Z" diff --git a/advisories/unreviewed/2024/05/GHSA-482h-984g-m9qw/GHSA-482h-984g-m9qw.json b/advisories/unreviewed/2024/05/GHSA-482h-984g-m9qw/GHSA-482h-984g-m9qw.json index 46ff0a27047..4ab9bf55f52 100644 --- a/advisories/unreviewed/2024/05/GHSA-482h-984g-m9qw/GHSA-482h-984g-m9qw.json +++ b/advisories/unreviewed/2024/05/GHSA-482h-984g-m9qw/GHSA-482h-984g-m9qw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-482h-984g-m9qw", - "modified": "2024-05-21T15:31:42Z", + "modified": "2024-12-23T18:30:47Z", "published": "2024-05-21T15:31:42Z", "aliases": [ "CVE-2021-47298" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf, sockmap: Fix potential memory leak on unlikely error case\n\nIf skb_linearize is needed and fails we could leak a msg on the error\nhandling. To fix ensure we kfree the msg block before returning error.\nFound during code review.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T15:15:17Z" diff --git a/advisories/unreviewed/2024/05/GHSA-85h7-g6vm-p392/GHSA-85h7-g6vm-p392.json b/advisories/unreviewed/2024/05/GHSA-85h7-g6vm-p392/GHSA-85h7-g6vm-p392.json index 9e53dd3967c..12f469e35ac 100644 --- a/advisories/unreviewed/2024/05/GHSA-85h7-g6vm-p392/GHSA-85h7-g6vm-p392.json +++ b/advisories/unreviewed/2024/05/GHSA-85h7-g6vm-p392/GHSA-85h7-g6vm-p392.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-85h7-g6vm-p392", - "modified": "2024-05-21T15:31:41Z", + "modified": "2024-12-23T18:30:47Z", "published": "2024-05-21T15:31:41Z", "aliases": [ "CVE-2021-47289" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nACPI: fix NULL pointer dereference\n\nCommit 71f642833284 (\"ACPI: utils: Fix reference counting in\nfor_each_acpi_dev_match()\") started doing \"acpi_dev_put()\" on a pointer\nthat was possibly NULL. That fails miserably, because that helper\ninline function is not set up to handle that case.\n\nJust make acpi_dev_put() silently accept a NULL pointer, rather than\ncalling down to put_device() with an invalid offset off that NULL\npointer.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T15:15:16Z" diff --git a/advisories/unreviewed/2024/05/GHSA-g7gx-qmj4-gxrc/GHSA-g7gx-qmj4-gxrc.json b/advisories/unreviewed/2024/05/GHSA-g7gx-qmj4-gxrc/GHSA-g7gx-qmj4-gxrc.json index 248cfedb26e..d81ba62831b 100644 --- a/advisories/unreviewed/2024/05/GHSA-g7gx-qmj4-gxrc/GHSA-g7gx-qmj4-gxrc.json +++ b/advisories/unreviewed/2024/05/GHSA-g7gx-qmj4-gxrc/GHSA-g7gx-qmj4-gxrc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-g7gx-qmj4-gxrc", - "modified": "2024-05-21T15:31:41Z", + "modified": "2024-12-23T18:30:47Z", "published": "2024-05-21T15:31:41Z", "aliases": [ "CVE-2021-47287" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndriver core: auxiliary bus: Fix memory leak when driver_register() fail\n\nIf driver_register() returns with error we need to free the memory\nallocated for auxdrv->driver.name before returning from\n__auxiliary_driver_register()", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T15:15:16Z" diff --git a/advisories/unreviewed/2024/05/GHSA-mrm7-vh23-g98v/GHSA-mrm7-vh23-g98v.json b/advisories/unreviewed/2024/05/GHSA-mrm7-vh23-g98v/GHSA-mrm7-vh23-g98v.json index 11b80303160..ba79a8510cb 100644 --- a/advisories/unreviewed/2024/05/GHSA-mrm7-vh23-g98v/GHSA-mrm7-vh23-g98v.json +++ b/advisories/unreviewed/2024/05/GHSA-mrm7-vh23-g98v/GHSA-mrm7-vh23-g98v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mrm7-vh23-g98v", - "modified": "2024-05-21T15:31:41Z", + "modified": "2024-12-23T18:30:47Z", "published": "2024-05-21T15:31:41Z", "aliases": [ "CVE-2021-47292" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nio_uring: fix memleak in io_init_wq_offload()\n\nI got memory leak report when doing fuzz test:\n\nBUG: memory leak\nunreferenced object 0xffff888107310a80 (size 96):\ncomm \"syz-executor.6\", pid 4610, jiffies 4295140240 (age 20.135s)\nhex dump (first 32 bytes):\n01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n00 00 00 00 ad 4e ad de ff ff ff ff 00 00 00 00 .....N..........\nbacktrace:\n[<000000001974933b>] kmalloc include/linux/slab.h:591 [inline]\n[<000000001974933b>] kzalloc include/linux/slab.h:721 [inline]\n[<000000001974933b>] io_init_wq_offload fs/io_uring.c:7920 [inline]\n[<000000001974933b>] io_uring_alloc_task_context+0x466/0x640 fs/io_uring.c:7955\n[<0000000039d0800d>] __io_uring_add_tctx_node+0x256/0x360 fs/io_uring.c:9016\n[<000000008482e78c>] io_uring_add_tctx_node fs/io_uring.c:9052 [inline]\n[<000000008482e78c>] __do_sys_io_uring_enter fs/io_uring.c:9354 [inline]\n[<000000008482e78c>] __se_sys_io_uring_enter fs/io_uring.c:9301 [inline]\n[<000000008482e78c>] __x64_sys_io_uring_enter+0xabc/0xc20 fs/io_uring.c:9301\n[<00000000b875f18f>] do_syscall_x64 arch/x86/entry/common.c:50 [inline]\n[<00000000b875f18f>] do_syscall_64+0x3b/0x90 arch/x86/entry/common.c:80\n[<000000006b0a8484>] entry_SYSCALL_64_after_hwframe+0x44/0xae\n\nCPU0 CPU1\nio_uring_enter io_uring_enter\nio_uring_add_tctx_node io_uring_add_tctx_node\n__io_uring_add_tctx_node __io_uring_add_tctx_node\nio_uring_alloc_task_context io_uring_alloc_task_context\nio_init_wq_offload io_init_wq_offload\nhash = kzalloc hash = kzalloc\nctx->hash_map = hash ctx->hash_map = hash <- one of the hash is leaked\n\nWhen calling io_uring_enter() in parallel, the 'hash_map' will be leaked,\nadd uring_lock to protect 'hash_map'.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T15:15:17Z" diff --git a/advisories/unreviewed/2024/05/GHSA-wxhc-3989-9jq8/GHSA-wxhc-3989-9jq8.json b/advisories/unreviewed/2024/05/GHSA-wxhc-3989-9jq8/GHSA-wxhc-3989-9jq8.json index 949c5b20d17..d4fe6a2b642 100644 --- a/advisories/unreviewed/2024/05/GHSA-wxhc-3989-9jq8/GHSA-wxhc-3989-9jq8.json +++ b/advisories/unreviewed/2024/05/GHSA-wxhc-3989-9jq8/GHSA-wxhc-3989-9jq8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wxhc-3989-9jq8", - "modified": "2024-05-21T15:31:41Z", + "modified": "2024-12-23T18:30:47Z", "published": "2024-05-21T15:31:41Z", "aliases": [ "CVE-2021-47288" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: ngene: Fix out-of-bounds bug in ngene_command_config_free_buf()\n\nFix an 11-year old bug in ngene_command_config_free_buf() while\naddressing the following warnings caught with -Warray-bounds:\n\narch/alpha/include/asm/string.h:22:16: warning: '__builtin_memcpy' offset [12, 16] from the object at 'com' is out of the bounds of referenced subobject 'config' with type 'unsigned char' at offset 10 [-Warray-bounds]\narch/x86/include/asm/string_32.h:182:25: warning: '__builtin_memcpy' offset [12, 16] from the object at 'com' is out of the bounds of referenced subobject 'config' with type 'unsigned char' at offset 10 [-Warray-bounds]\n\nThe problem is that the original code is trying to copy 6 bytes of\ndata into a one-byte size member _config_ of the wrong structue\nFW_CONFIGURE_BUFFERS, in a single call to memcpy(). This causes a\nlegitimate compiler warning because memcpy() overruns the length\nof &com.cmd.ConfigureBuffers.config. It seems that the right\nstructure is FW_CONFIGURE_FREE_BUFFERS, instead, because it contains\n6 more members apart from the header _hdr_. Also, the name of\nthe function ngene_command_config_free_buf() suggests that the actual\nintention is to ConfigureFreeBuffers, instead of ConfigureBuffers\n(which takes place in the function ngene_command_config_buf(), above).\n\nFix this by enclosing those 6 members of struct FW_CONFIGURE_FREE_BUFFERS\ninto new struct config, and use &com.cmd.ConfigureFreeBuffers.config as\nthe destination address, instead of &com.cmd.ConfigureBuffers.config,\nwhen calling memcpy().\n\nThis also helps with the ongoing efforts to globally enable\n-Warray-bounds and get us closer to being able to tighten the\nFORTIFY_SOURCE routines on memcpy().", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T15:15:16Z" diff --git a/advisories/unreviewed/2024/05/GHSA-xqq2-v4rf-49qr/GHSA-xqq2-v4rf-49qr.json b/advisories/unreviewed/2024/05/GHSA-xqq2-v4rf-49qr/GHSA-xqq2-v4rf-49qr.json index 843fd456f26..e2b1be0a09a 100644 --- a/advisories/unreviewed/2024/05/GHSA-xqq2-v4rf-49qr/GHSA-xqq2-v4rf-49qr.json +++ b/advisories/unreviewed/2024/05/GHSA-xqq2-v4rf-49qr/GHSA-xqq2-v4rf-49qr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xqq2-v4rf-49qr", - "modified": "2024-05-21T15:31:41Z", + "modified": "2024-12-23T18:30:47Z", "published": "2024-05-21T15:31:41Z", "aliases": [ "CVE-2021-47290" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: target: Fix NULL dereference on XCOPY completion\n\nCPU affinity control added with commit 39ae3edda325 (\"scsi: target: core:\nMake completion affinity configurable\") makes target_complete_cmd() queue\nwork on a CPU based on se_tpg->se_tpg_wwn->cmd_compl_affinity state.\n\nLIO's EXTENDED COPY worker is a special case in that read/write cmds are\ndispatched using the global xcopy_pt_tpg, which carries a NULL se_tpg_wwn\npointer following initialization in target_xcopy_setup_pt().\n\nThe NULL xcopy_pt_tpg->se_tpg_wwn pointer is dereferenced on completion of\nany EXTENDED COPY initiated read/write cmds. E.g using the libiscsi\nSCSI.ExtendedCopy.Simple test:\n\n BUG: kernel NULL pointer dereference, address: 00000000000001a8\n RIP: 0010:target_complete_cmd+0x9d/0x130 [target_core_mod]\n Call Trace:\n fd_execute_rw+0x148/0x42a [target_core_file]\n ? __dynamic_pr_debug+0xa7/0xe0\n ? target_check_reservation+0x5b/0x940 [target_core_mod]\n __target_execute_cmd+0x1e/0x90 [target_core_mod]\n transport_generic_new_cmd+0x17c/0x330 [target_core_mod]\n target_xcopy_issue_pt_cmd+0x9/0x60 [target_core_mod]\n target_xcopy_read_source.isra.7+0x10b/0x1b0 [target_core_mod]\n ? target_check_fua+0x40/0x40 [target_core_mod]\n ? transport_complete_task_attr+0x130/0x130 [target_core_mod]\n target_xcopy_do_work+0x61f/0xc00 [target_core_mod]\n\nThis fix makes target_complete_cmd() queue work on se_cmd->cpuid if\nse_tpg_wwn is NULL.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T15:15:17Z" diff --git a/advisories/unreviewed/2024/12/GHSA-6c2p-rqx3-w4px/GHSA-6c2p-rqx3-w4px.json b/advisories/unreviewed/2024/12/GHSA-6c2p-rqx3-w4px/GHSA-6c2p-rqx3-w4px.json new file mode 100644 index 00000000000..9e743b85ce1 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-6c2p-rqx3-w4px/GHSA-6c2p-rqx3-w4px.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6c2p-rqx3-w4px", + "modified": "2024-12-23T18:30:47Z", + "published": "2024-12-23T18:30:47Z", + "aliases": [ + "CVE-2024-40896" + ], + "details": "In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting \"checked\"). This makes classic XXE attacks possible.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-40896" + }, + { + "type": "WEB", + "url": "https://gitlab.gnome.org/GNOME/libxml2/-/commit/1a8932303969907f6572b1b6aac4081c56adb5c6" + }, + { + "type": "WEB", + "url": "https://gitlab.gnome.org/GNOME/libxml2/-/issues/761" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-611" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-23T17:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-77pm-w3hx-f8mj/GHSA-77pm-w3hx-f8mj.json b/advisories/unreviewed/2024/12/GHSA-77pm-w3hx-f8mj/GHSA-77pm-w3hx-f8mj.json new file mode 100644 index 00000000000..8b45e96bf75 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-77pm-w3hx-f8mj/GHSA-77pm-w3hx-f8mj.json @@ -0,0 +1,63 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-77pm-w3hx-f8mj", + "modified": "2024-12-23T18:30:47Z", + "published": "2024-12-23T18:30:47Z", + "aliases": [ + "CVE-2024-23945" + ], + "details": "Signing cookies is an application security feature that adds a digital signature to cookie data to verify its authenticity and integrity. The signature helps prevent malicious actors from modifying the cookie value, which can lead to security vulnerabilities and exploitation. Apache Hive’s service component accidentally exposes the signed cookie to the end user when there is a mismatch in signature between the current and expected cookie. Exposing the correct cookie signature can lead to further exploitation.\n\nThe vulnerable CookieSigner logic was introduced in Apache Hive by HIVE-9710 (1.2.0) and in Apache Spark by SPARK-14987 (2.0.0). The affected components are the following:\n* org.apache.hive:hive-service\n* org.apache.spark:spark-hive-thriftserver_2.11\n* org.apache.spark:spark-hive-thriftserver_2.12", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23945" + }, + { + "type": "WEB", + "url": "https://github.com/apache/hive/commit/7638cb1a3b07713cc490aa2909a37037f89e08b4" + }, + { + "type": "WEB", + "url": "https://github.com/apache/spark/commit/cf59b1f51c16301f689b4e0f17ba4dbd140e1b19" + }, + { + "type": "WEB", + "url": "https://github.com/apache/hive" + }, + { + "type": "WEB", + "url": "https://github.com/apache/spark" + }, + { + "type": "WEB", + "url": "https://issues.apache.org/jira/browse/HIVE-9710" + }, + { + "type": "WEB", + "url": "https://issues.apache.org/jira/browse/SPARK-14987" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/59r4mv7glrxpwkkdjvjbdljfpx3f5zzc" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/5o2ljnzrv8zvhjw9vy7b4rwjpc32hgfc" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/12/23/2" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-209" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-23T16:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-vq94-9pfv-ccqr/GHSA-vq94-9pfv-ccqr.json b/advisories/unreviewed/2024/12/GHSA-vq94-9pfv-ccqr/GHSA-vq94-9pfv-ccqr.json new file mode 100644 index 00000000000..88ed5f12aeb --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-vq94-9pfv-ccqr/GHSA-vq94-9pfv-ccqr.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vq94-9pfv-ccqr", + "modified": "2024-12-23T18:30:47Z", + "published": "2024-12-23T18:30:47Z", + "aliases": [ + "CVE-2024-45387" + ], + "details": "An SQL injection vulnerability in Traffic Ops in Apache Traffic Control <= 8.0.1, >= 8.0.0 allows a privileged user with role \"admin\", \"federation\", \"operations\", \"portal\", or \"steering\" to execute arbitrary SQL against the database by sending a specially-crafted PUT request.\n\nUsers are recommended to upgrade to version Apache Traffic Control 8.0.2 if you run an affected version of Traffic Ops.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45387" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/t38nk5n7t8w3pb66z7z4pqfzt4443trr" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/12/23/3" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-23T16:15:06Z" + } +} \ No newline at end of file