diff --git a/advisories/github-reviewed/2024/04/GHSA-9f8c-pfvv-p4gm/GHSA-9f8c-pfvv-p4gm.json b/advisories/github-reviewed/2024/04/GHSA-9f8c-pfvv-p4gm/GHSA-9f8c-pfvv-p4gm.json new file mode 100644 index 00000000000..c4e9e99fb99 --- /dev/null +++ b/advisories/github-reviewed/2024/04/GHSA-9f8c-pfvv-p4gm/GHSA-9f8c-pfvv-p4gm.json @@ -0,0 +1,61 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9f8c-pfvv-p4gm", + "modified": "2024-04-24T20:56:50Z", + "published": "2024-04-24T20:56:50Z", + "aliases": [ + "CVE-2021-3382" + ], + "summary": "Buffer Overflow in gitea", + "details": "Stack buffer overflow vulnerability in gitea 1.9.0 through 1.13.1 allows remote attackers to cause a denial of service (crash) via vectors related to a file path.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Go", + "name": "github.com/go-gitea/gitea" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "1.9.0" + }, + { + "fixed": "1.13.2" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-3382" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/pull/14390" + }, + { + "type": "PACKAGE", + "url": "https://github.com/go-gitea/gitea" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": true, + "github_reviewed_at": "2024-04-24T20:56:50Z", + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/04/GHSA-r7h7-chh4-5rvm/GHSA-r7h7-chh4-5rvm.json b/advisories/github-reviewed/2024/04/GHSA-r7h7-chh4-5rvm/GHSA-r7h7-chh4-5rvm.json new file mode 100644 index 00000000000..54a58e0bca7 --- /dev/null +++ b/advisories/github-reviewed/2024/04/GHSA-r7h7-chh4-5rvm/GHSA-r7h7-chh4-5rvm.json @@ -0,0 +1,65 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r7h7-chh4-5rvm", + "modified": "2024-04-24T20:56:53Z", + "published": "2024-04-24T20:56:53Z", + "aliases": [ + "CVE-2020-28991" + ], + "summary": "Improper Access Control in Gitea", + "details": "Gitea 0.9.99 through 1.12.x before 1.12.6 does not prevent a git protocol path that specifies a TCP port number and also contains newlines (with URL encoding) in ParseRemoteAddr in modules/auth/repo_form.go.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Go", + "name": "github.com/go-gitea/gitea" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0.9.99" + }, + { + "fixed": "1.12.6" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-28991" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/pull/13525" + }, + { + "type": "PACKAGE", + "url": "https://github.com/go-gitea/gitea" + }, + { + "type": "WEB", + "url": "https://github.com/go-gitea/gitea/releases/tag/v1.12.6" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "CRITICAL", + "github_reviewed": true, + "github_reviewed_at": "2024-04-24T20:56:53Z", + "nvd_published_at": null + } +} \ No newline at end of file