diff --git a/advisories/github-reviewed/2024/05/GHSA-fgh3-pwmp-3qw3/GHSA-fgh3-pwmp-3qw3.json b/advisories/github-reviewed/2024/05/GHSA-fgh3-pwmp-3qw3/GHSA-fgh3-pwmp-3qw3.json index 6da7b28c510..705a6ad28b7 100644 --- a/advisories/github-reviewed/2024/05/GHSA-fgh3-pwmp-3qw3/GHSA-fgh3-pwmp-3qw3.json +++ b/advisories/github-reviewed/2024/05/GHSA-fgh3-pwmp-3qw3/GHSA-fgh3-pwmp-3qw3.json @@ -1,14 +1,19 @@ { "schema_version": "1.4.0", "id": "GHSA-fgh3-pwmp-3qw3", - "modified": "2024-05-09T13:22:54Z", + "modified": "2025-02-11T19:02:09Z", "published": "2024-05-08T15:30:42Z", "aliases": [ "CVE-2024-26579" ], "summary": "Apache Inlong Deserialization of Untrusted Data vulnerability", - "details": "Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.7.0 through 1.11.0. The attackers can bypass using malicious parameters.\n\nUsers are advised to upgrade to Apache InLong's 1.12.0 or cherry-pick [1], [2] to solve it.\n\n[1] https://github.com/apache/inlong/pull/9694 \n\n[2]  https://github.com/apache/inlong/pull/9707 ", - "severity": [], + "details": "Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.7.0 through 1.11.0. The attackers can bypass using malicious parameters.\n\nUsers are advised to upgrade to Apache InLong's 1.12.0 or cherry-pick [1], [2] to solve it.\n\n[1] https://github.com/apache/inlong/pull/9694 \n\n[2]  https://github.com/apache/inlong/pull/9707", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [ { "package": { @@ -62,13 +67,17 @@ { "type": "WEB", "url": "https://lists.apache.org/thread/d2hndtvh6bll4pkl91o2oqxyynhr54k3" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/05/09/2" } ], "database_specific": { "cwe_ids": [ "CWE-502" ], - "severity": "HIGH", + "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2024-05-08T19:57:07Z", "nvd_published_at": "2024-05-08T15:15:08Z" diff --git a/advisories/github-reviewed/2024/06/GHSA-hcr7-cqwc-q5gq/GHSA-hcr7-cqwc-q5gq.json b/advisories/github-reviewed/2024/06/GHSA-hcr7-cqwc-q5gq/GHSA-hcr7-cqwc-q5gq.json index 82dccaf7884..03dc8cfb1bb 100644 --- a/advisories/github-reviewed/2024/06/GHSA-hcr7-cqwc-q5gq/GHSA-hcr7-cqwc-q5gq.json +++ b/advisories/github-reviewed/2024/06/GHSA-hcr7-cqwc-q5gq/GHSA-hcr7-cqwc-q5gq.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-hcr7-cqwc-q5gq", - "modified": "2024-06-20T16:15:09Z", + "modified": "2025-02-11T19:01:37Z", "published": "2024-06-20T09:30:59Z", "aliases": [ "CVE-2024-34693" ], "summary": "Apache Superset server arbitrary file read ", - "details": "Improper Input Validation vulnerability in Apache Superset, allows for an authenticated attacker to create a MariaDB connection with local_infile enabled. If both the MariaDB server (off by default) and the local mysql client on the web server are set to allow for local infile, it's possible for the attacker to execute a specific MySQL/MariaDB SQL command that is able to read files from the server and insert their content on a MariaDB database table. This issue affects Apache Superset before version 3.1.3 and in version 4.0.0.\n\nUsers are recommended to upgrade to version 4.0.1 or 3.1.3, both of which fix the issue.\n\n", + "details": "Improper Input Validation vulnerability in Apache Superset, allows for an authenticated attacker to create a MariaDB connection with local_infile enabled. If both the MariaDB server (off by default) and the local mysql client on the web server are set to allow for local infile, it's possible for the attacker to execute a specific MySQL/MariaDB SQL command that is able to read files from the server and insert their content on a MariaDB database table. This issue affects Apache Superset before version 3.1.3 and in version 4.0.0.\n\nUsers are recommended to upgrade to version 4.0.1 or 3.1.3, both of which fix the issue.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2024/10/GHSA-2qw8-ppr5-m96c/GHSA-2qw8-ppr5-m96c.json b/advisories/github-reviewed/2024/10/GHSA-2qw8-ppr5-m96c/GHSA-2qw8-ppr5-m96c.json index 7f6334e351c..b209798c395 100644 --- a/advisories/github-reviewed/2024/10/GHSA-2qw8-ppr5-m96c/GHSA-2qw8-ppr5-m96c.json +++ b/advisories/github-reviewed/2024/10/GHSA-2qw8-ppr5-m96c/GHSA-2qw8-ppr5-m96c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2qw8-ppr5-m96c", - "modified": "2024-10-31T15:01:08Z", + "modified": "2025-02-11T19:01:31Z", "published": "2024-10-31T12:30:32Z", "aliases": [ "CVE-2024-43383" @@ -55,6 +55,10 @@ { "type": "WEB", "url": "https://lists.apache.org/thread/wlz1p76dxpt4rl9o29voxjd5zl7717nh" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/10/31/2" } ], "database_specific": { diff --git a/advisories/github-reviewed/2024/11/GHSA-7jqf-v358-p8g7/GHSA-7jqf-v358-p8g7.json b/advisories/github-reviewed/2024/11/GHSA-7jqf-v358-p8g7/GHSA-7jqf-v358-p8g7.json index 55dc13a8072..6e6455b0ff5 100644 --- a/advisories/github-reviewed/2024/11/GHSA-7jqf-v358-p8g7/GHSA-7jqf-v358-p8g7.json +++ b/advisories/github-reviewed/2024/11/GHSA-7jqf-v358-p8g7/GHSA-7jqf-v358-p8g7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7jqf-v358-p8g7", - "modified": "2024-11-07T17:25:56Z", + "modified": "2025-02-11T19:01:28Z", "published": "2024-11-07T09:30:42Z", "aliases": [ "CVE-2024-38286" @@ -101,6 +101,14 @@ { "type": "WEB", "url": "https://lists.apache.org/thread/wms60cvbsz3fpbz9psxtfx8r41jl6d4s" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20241101-0010" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/09/23/2" } ], "database_specific": { diff --git a/advisories/github-reviewed/2024/12/GHSA-2cx9-54hp-r698/GHSA-2cx9-54hp-r698.json b/advisories/github-reviewed/2024/12/GHSA-2cx9-54hp-r698/GHSA-2cx9-54hp-r698.json index 0be4d337ae8..e50866164d4 100644 --- a/advisories/github-reviewed/2024/12/GHSA-2cx9-54hp-r698/GHSA-2cx9-54hp-r698.json +++ b/advisories/github-reviewed/2024/12/GHSA-2cx9-54hp-r698/GHSA-2cx9-54hp-r698.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2cx9-54hp-r698", - "modified": "2024-12-09T20:45:00Z", + "modified": "2025-02-11T19:01:21Z", "published": "2024-12-09T15:31:37Z", "aliases": [ "CVE-2024-53948" @@ -9,6 +9,10 @@ "summary": "Apache Superset: Error verbosity exposes metadata in analytics databases", "details": "Generation of Error Message Containing analytics metadata Information in Apache Superset.\n\nThis issue affects Apache Superset: before 4.1.0.\n\nUsers are recommended to upgrade to version 4.1.0, which fixes the issue.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N" diff --git a/advisories/github-reviewed/2024/12/GHSA-35fc-9hrj-3585/GHSA-35fc-9hrj-3585.json b/advisories/github-reviewed/2024/12/GHSA-35fc-9hrj-3585/GHSA-35fc-9hrj-3585.json index e248025fcc9..f3de1a75c97 100644 --- a/advisories/github-reviewed/2024/12/GHSA-35fc-9hrj-3585/GHSA-35fc-9hrj-3585.json +++ b/advisories/github-reviewed/2024/12/GHSA-35fc-9hrj-3585/GHSA-35fc-9hrj-3585.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-35fc-9hrj-3585", - "modified": "2024-12-09T20:45:05Z", + "modified": "2025-02-11T19:01:24Z", "published": "2024-12-09T15:31:37Z", "aliases": [ "CVE-2024-53949" @@ -9,6 +9,10 @@ "summary": "Apache Superset: Lower privilege users are able to create Role when FAB_ADD_SECURITY_API is enabled", "details": "Improper Authorization vulnerability in Apache Superset when FAB_ADD_SECURITY_API is enabled (disabled by default). Allows for lower privilege users to use this API.\n\n issue affects Apache Superset: from 2.0.0 before 4.1.0.\n\nUsers are recommended to upgrade to version 4.1.0, which fixes the issue.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N" @@ -59,7 +63,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-285" + "CWE-285", + "CWE-863" ], "severity": "HIGH", "github_reviewed": true,