From 510baaeb0ab94e6483a99039b9304e48d18ce6fd Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 23 Aug 2024 22:52:53 +0000 Subject: [PATCH] Publish Advisories GHSA-4mrc-w7jh-hx4j GHSA-cgxv-795x-3vqr GHSA-g8h2-j9pm-4xx2 GHSA-jg95-r9xh-xw9c GHSA-v9wr-8wrm-h6p7 --- .../GHSA-4mrc-w7jh-hx4j.json | 35 +++++++++++++-- .../GHSA-cgxv-795x-3vqr.json | 37 +++++++++++++--- .../GHSA-g8h2-j9pm-4xx2.json | 44 ++++++++++++++++--- .../GHSA-jg95-r9xh-xw9c.json | 39 +++++++++++++--- .../GHSA-v9wr-8wrm-h6p7.json | 37 +++++++++++++--- 5 files changed, 165 insertions(+), 27 deletions(-) rename advisories/{unreviewed => github-reviewed}/2024/08/GHSA-4mrc-w7jh-hx4j/GHSA-4mrc-w7jh-hx4j.json (55%) rename advisories/{unreviewed => github-reviewed}/2024/08/GHSA-cgxv-795x-3vqr/GHSA-cgxv-795x-3vqr.json (54%) rename advisories/{unreviewed => github-reviewed}/2024/08/GHSA-g8h2-j9pm-4xx2/GHSA-g8h2-j9pm-4xx2.json (53%) rename advisories/{unreviewed => github-reviewed}/2024/08/GHSA-jg95-r9xh-xw9c/GHSA-jg95-r9xh-xw9c.json (50%) rename advisories/{unreviewed => github-reviewed}/2024/08/GHSA-v9wr-8wrm-h6p7/GHSA-v9wr-8wrm-h6p7.json (54%) diff --git a/advisories/unreviewed/2024/08/GHSA-4mrc-w7jh-hx4j/GHSA-4mrc-w7jh-hx4j.json b/advisories/github-reviewed/2024/08/GHSA-4mrc-w7jh-hx4j/GHSA-4mrc-w7jh-hx4j.json similarity index 55% rename from advisories/unreviewed/2024/08/GHSA-4mrc-w7jh-hx4j/GHSA-4mrc-w7jh-hx4j.json rename to advisories/github-reviewed/2024/08/GHSA-4mrc-w7jh-hx4j/GHSA-4mrc-w7jh-hx4j.json index c78022db41d..d10959dbd1e 100644 --- a/advisories/unreviewed/2024/08/GHSA-4mrc-w7jh-hx4j/GHSA-4mrc-w7jh-hx4j.json +++ b/advisories/github-reviewed/2024/08/GHSA-4mrc-w7jh-hx4j/GHSA-4mrc-w7jh-hx4j.json @@ -1,26 +1,53 @@ { "schema_version": "1.4.0", "id": "GHSA-4mrc-w7jh-hx4j", - "modified": "2024-08-23T21:30:42Z", + "modified": "2024-08-23T22:51:35Z", "published": "2024-08-23T21:30:42Z", "aliases": [ "CVE-2024-45190" ], + "summary": "Mage AI Path Traversal vulnerability", "details": "Mage AI allows remote users with the \"Viewer\" role to leak arbitrary files from the Mage server due to a path traversal in the \"Pipeline Interaction\" request", "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P" } ], "affected": [ - + { + "package": { + "ecosystem": "PyPI", + "name": "mage-ai" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "0.9.73" + } + ] + } + ] + } ], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45190" }, + { + "type": "PACKAGE", + "url": "https://github.com/mage-ai/mage-ai" + }, { "type": "WEB", "url": "https://research.jfrog.com/vulnerabilities/mage-ai-pipeline-interaction-request-remote-arbitrary-file-leak-jfsa-2024-001039605" @@ -31,8 +58,8 @@ "CWE-35" ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-08-23T22:51:35Z", "nvd_published_at": "2024-08-23T20:15:08Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-cgxv-795x-3vqr/GHSA-cgxv-795x-3vqr.json b/advisories/github-reviewed/2024/08/GHSA-cgxv-795x-3vqr/GHSA-cgxv-795x-3vqr.json similarity index 54% rename from advisories/unreviewed/2024/08/GHSA-cgxv-795x-3vqr/GHSA-cgxv-795x-3vqr.json rename to advisories/github-reviewed/2024/08/GHSA-cgxv-795x-3vqr/GHSA-cgxv-795x-3vqr.json index a02c70952f0..eca30a8532c 100644 --- a/advisories/unreviewed/2024/08/GHSA-cgxv-795x-3vqr/GHSA-cgxv-795x-3vqr.json +++ b/advisories/github-reviewed/2024/08/GHSA-cgxv-795x-3vqr/GHSA-cgxv-795x-3vqr.json @@ -1,26 +1,53 @@ { "schema_version": "1.4.0", "id": "GHSA-cgxv-795x-3vqr", - "modified": "2024-08-23T21:30:42Z", + "modified": "2024-08-23T22:51:32Z", "published": "2024-08-23T21:30:42Z", "aliases": [ "CVE-2024-45189" ], + "summary": "Mage AI Path Traversal vulnerability", "details": "Mage AI allows remote users with the \"Viewer\" role to leak arbitrary files from the Mage server due to a path traversal in the \"Git Content\" request", "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P" } ], "affected": [ - + { + "package": { + "ecosystem": "PyPI", + "name": "mage-ai" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "0.9.73" + } + ] + } + ] + } ], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45189" }, + { + "type": "PACKAGE", + "url": "https://github.com/mage-ai/mage-ai" + }, { "type": "WEB", "url": "https://research.jfrog.com/vulnerabilities/mage-ai-git-content-request-remote-arbitrary-file-leak-jfsa-2024-001039604" @@ -28,11 +55,11 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-08-23T22:51:32Z", "nvd_published_at": "2024-08-23T20:15:08Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-g8h2-j9pm-4xx2/GHSA-g8h2-j9pm-4xx2.json b/advisories/github-reviewed/2024/08/GHSA-g8h2-j9pm-4xx2/GHSA-g8h2-j9pm-4xx2.json similarity index 53% rename from advisories/unreviewed/2024/08/GHSA-g8h2-j9pm-4xx2/GHSA-g8h2-j9pm-4xx2.json rename to advisories/github-reviewed/2024/08/GHSA-g8h2-j9pm-4xx2/GHSA-g8h2-j9pm-4xx2.json index 642cadfc65a..7c51ec0e20b 100644 --- a/advisories/unreviewed/2024/08/GHSA-g8h2-j9pm-4xx2/GHSA-g8h2-j9pm-4xx2.json +++ b/advisories/github-reviewed/2024/08/GHSA-g8h2-j9pm-4xx2/GHSA-g8h2-j9pm-4xx2.json @@ -1,17 +1,43 @@ { "schema_version": "1.4.0", "id": "GHSA-g8h2-j9pm-4xx2", - "modified": "2024-08-23T21:30:42Z", + "modified": "2024-08-23T22:52:12Z", "published": "2024-08-23T21:30:42Z", "aliases": [ "CVE-2024-40111" ], + "summary": "Automad Cross-site Scripting vulnerability", "details": "A persistent (stored) cross-site scripting (XSS) vulnerability has been identified in Automad 2.0.0-alpha.4. This vulnerability enables an attacker to inject malicious JavaScript code into the template body. The injected code is stored within the flat file CMS and is executed in the browser of any user visiting the forum.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N" + } ], "affected": [ - + { + "package": { + "ecosystem": "Packagist", + "name": "automad/automad" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "2.0.0-alpha.4" + } + ] + } + ] + } ], "references": [ { @@ -22,6 +48,10 @@ "type": "WEB", "url": "https://drive.google.com/file/d/10BVQKYo2H1-Nx3FOGteL2xww4lbZ3xlS/view?usp=sharing" }, + { + "type": "PACKAGE", + "url": "https://github.com/marcantondahmen/automad" + }, { "type": "WEB", "url": "https://github.com/w3bn00b3r/Stored-Cross-Site-Scripting-XSS---Automad-2.0.0-alpha.4" @@ -29,11 +59,11 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], - "severity": null, - "github_reviewed": false, - "github_reviewed_at": null, + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-08-23T22:52:12Z", "nvd_published_at": "2024-08-23T21:15:07Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-jg95-r9xh-xw9c/GHSA-jg95-r9xh-xw9c.json b/advisories/github-reviewed/2024/08/GHSA-jg95-r9xh-xw9c/GHSA-jg95-r9xh-xw9c.json similarity index 50% rename from advisories/unreviewed/2024/08/GHSA-jg95-r9xh-xw9c/GHSA-jg95-r9xh-xw9c.json rename to advisories/github-reviewed/2024/08/GHSA-jg95-r9xh-xw9c/GHSA-jg95-r9xh-xw9c.json index b67e16f3bc4..3ed1406117c 100644 --- a/advisories/unreviewed/2024/08/GHSA-jg95-r9xh-xw9c/GHSA-jg95-r9xh-xw9c.json +++ b/advisories/github-reviewed/2024/08/GHSA-jg95-r9xh-xw9c/GHSA-jg95-r9xh-xw9c.json @@ -1,26 +1,53 @@ { "schema_version": "1.4.0", "id": "GHSA-jg95-r9xh-xw9c", - "modified": "2024-08-23T21:30:42Z", + "modified": "2024-08-23T22:51:28Z", "published": "2024-08-23T21:30:42Z", "aliases": [ "CVE-2024-45187" ], - "details": "Guest users in the Mage AI framework that remain logged in after their accounts are deleted, are mistakenly given high privileges and specifically given access to remotely execute arbitrary code through the Mage AI terminal server", + "summary": "Mage AI incorrectly gives privileges to users with deleted accounts", + "details": "Guest users in the Mage AI framework that remain logged in after their accounts are deleted, are mistakenly given high privileges and specifically given access to remotely execute arbitrary code through the Mage AI terminal server.", "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U" } ], "affected": [ - + { + "package": { + "ecosystem": "PyPI", + "name": "mage-ai" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "0.9.73" + } + ] + } + ] + } ], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45187" }, + { + "type": "PACKAGE", + "url": "https://github.com/mage-ai/mage-ai" + }, { "type": "WEB", "url": "https://research.jfrog.com/vulnerabilities/mage-ai-deleted-users-rce-jfsa-2024-001039602" @@ -30,9 +57,9 @@ "cwe_ids": [ "CWE-266" ], - "severity": "HIGH", - "github_reviewed": false, - "github_reviewed_at": null, + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-08-23T22:51:28Z", "nvd_published_at": "2024-08-23T19:15:07Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-v9wr-8wrm-h6p7/GHSA-v9wr-8wrm-h6p7.json b/advisories/github-reviewed/2024/08/GHSA-v9wr-8wrm-h6p7/GHSA-v9wr-8wrm-h6p7.json similarity index 54% rename from advisories/unreviewed/2024/08/GHSA-v9wr-8wrm-h6p7/GHSA-v9wr-8wrm-h6p7.json rename to advisories/github-reviewed/2024/08/GHSA-v9wr-8wrm-h6p7/GHSA-v9wr-8wrm-h6p7.json index 7d05536f212..42d0faa5651 100644 --- a/advisories/unreviewed/2024/08/GHSA-v9wr-8wrm-h6p7/GHSA-v9wr-8wrm-h6p7.json +++ b/advisories/github-reviewed/2024/08/GHSA-v9wr-8wrm-h6p7/GHSA-v9wr-8wrm-h6p7.json @@ -1,26 +1,53 @@ { "schema_version": "1.4.0", "id": "GHSA-v9wr-8wrm-h6p7", - "modified": "2024-08-23T21:30:42Z", + "modified": "2024-08-23T22:51:30Z", "published": "2024-08-23T21:30:42Z", "aliases": [ "CVE-2024-45188" ], + "summary": "Mage AI Path Traversal vulnerability", "details": "Mage AI allows remote users with the \"Viewer\" role to leak arbitrary files from the Mage server due to a path traversal in the \"File Content\" request", "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P" } ], "affected": [ - + { + "package": { + "ecosystem": "PyPI", + "name": "mage-ai" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "0.9.73" + } + ] + } + ] + } ], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45188" }, + { + "type": "PACKAGE", + "url": "https://github.com/mage-ai/mage-ai" + }, { "type": "WEB", "url": "https://research.jfrog.com/vulnerabilities/mage-ai-file-content-request-remote-arbitrary-file-leak-jfsa-2024-001039603" @@ -28,11 +55,11 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-08-23T22:51:30Z", "nvd_published_at": "2024-08-23T20:15:07Z" } } \ No newline at end of file