From 53e1376caa366c0fdfc86640ae165ec2546b348c Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 17 Jan 2025 16:29:55 +0000 Subject: [PATCH] Publish Advisories GHSA-4h8f-2wvx-gg5w GHSA-8vq4-8hfp-29xh GHSA-fcr8-4r9f-r66m GHSA-8vq4-8hfp-29xh --- .../GHSA-4h8f-2wvx-gg5w.json | 21 +----- .../GHSA-8vq4-8hfp-29xh.json | 65 +++++++++++++++++ .../GHSA-fcr8-4r9f-r66m.json | 70 +++++++++++++++++++ .../GHSA-8vq4-8hfp-29xh.json | 29 -------- 4 files changed, 136 insertions(+), 49 deletions(-) create mode 100644 advisories/github-reviewed/2025/01/GHSA-8vq4-8hfp-29xh/GHSA-8vq4-8hfp-29xh.json create mode 100644 advisories/github-reviewed/2025/01/GHSA-fcr8-4r9f-r66m/GHSA-fcr8-4r9f-r66m.json delete mode 100644 advisories/unreviewed/2025/01/GHSA-8vq4-8hfp-29xh/GHSA-8vq4-8hfp-29xh.json diff --git a/advisories/github-reviewed/2024/05/GHSA-4h8f-2wvx-gg5w/GHSA-4h8f-2wvx-gg5w.json b/advisories/github-reviewed/2024/05/GHSA-4h8f-2wvx-gg5w/GHSA-4h8f-2wvx-gg5w.json index 474decd906a..7ebe9b62a69 100644 --- a/advisories/github-reviewed/2024/05/GHSA-4h8f-2wvx-gg5w/GHSA-4h8f-2wvx-gg5w.json +++ b/advisories/github-reviewed/2024/05/GHSA-4h8f-2wvx-gg5w/GHSA-4h8f-2wvx-gg5w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4h8f-2wvx-gg5w", - "modified": "2024-06-14T15:31:24Z", + "modified": "2025-01-17T16:27:53Z", "published": "2024-05-03T18:30:37Z", "aliases": [ "CVE-2024-34447" @@ -67,25 +67,6 @@ } ] }, - { - "package": { - "ecosystem": "Maven", - "name": "org.bouncycastle:bcprov-jdk13" - }, - "ranges": [ - { - "type": "ECOSYSTEM", - "events": [ - { - "introduced": "1.61" - }, - { - "fixed": "1.78" - } - ] - } - ] - }, { "package": { "ecosystem": "Maven", diff --git a/advisories/github-reviewed/2025/01/GHSA-8vq4-8hfp-29xh/GHSA-8vq4-8hfp-29xh.json b/advisories/github-reviewed/2025/01/GHSA-8vq4-8hfp-29xh/GHSA-8vq4-8hfp-29xh.json new file mode 100644 index 00000000000..02e1ed675ac --- /dev/null +++ b/advisories/github-reviewed/2025/01/GHSA-8vq4-8hfp-29xh/GHSA-8vq4-8hfp-29xh.json @@ -0,0 +1,65 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8vq4-8hfp-29xh", + "modified": "2025-01-17T16:28:34Z", + "published": "2025-01-17T00:30:48Z", + "aliases": [ + "CVE-2024-48460" + ], + "summary": "Eugeny Tabby Sends Password Despite Host Key Verification Failure", + "details": "An issue in Eugeny Tabby 1.0.213 allows a remote attacker to obtain sensitive information via the server and sends the SSH username and password even when the host key verification fails.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P" + } + ], + "affected": [ + { + "package": { + "ecosystem": "npm", + "name": "tabby-ssh" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.0.214" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48460" + }, + { + "type": "WEB", + "url": "https://github.com/Eugeny/tabby/issues/9955" + }, + { + "type": "WEB", + "url": "https://github.com/Eugeny/tabby/commit/1c077147acd0a6ec9f8ee80d83a3e9688fbb9444" + }, + { + "type": "PACKAGE", + "url": "https://github.com/Eugeny/tabby" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "HIGH", + "github_reviewed": true, + "github_reviewed_at": "2025-01-17T16:28:34Z", + "nvd_published_at": "2025-01-16T22:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2025/01/GHSA-fcr8-4r9f-r66m/GHSA-fcr8-4r9f-r66m.json b/advisories/github-reviewed/2025/01/GHSA-fcr8-4r9f-r66m/GHSA-fcr8-4r9f-r66m.json new file mode 100644 index 00000000000..c8ed5921fa5 --- /dev/null +++ b/advisories/github-reviewed/2025/01/GHSA-fcr8-4r9f-r66m/GHSA-fcr8-4r9f-r66m.json @@ -0,0 +1,70 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fcr8-4r9f-r66m", + "modified": "2025-01-17T16:29:16Z", + "published": "2025-01-17T16:29:16Z", + "aliases": [], + "summary": "nbgrader's `frame-ancestors: self` grants all users access to formgrader", + "details": "### Impact\n\nEnabling frame-ancestors: 'self' grants any JupyterHub user the ability to extract formgrader content by sending malicious links to users with access to formgrader, at least when using the default JupyterHub configuration of `enable_subdomains = False`.\n\n#1915 disables a protection which would allow user Alice to craft a page embedding formgrader in an IFrame. If Bob visits that page, his credentials will be sent and the formgrader page loaded. Because Alice's page is on the same Origin as the formgrader iframe, Javasript on Alice's page has _full access_ to the contents of the page served by formgrader using Bob's credentials.\n\n### Workarounds\n\n- Disable `frame-ancestors: self`, or\n- enable per-user and per-service subdomains with `JupyterHub.enable_subdomains = True` (then even if embedding in an IFrame is allowed, the host page does not have access to the contents of the frame).\n\n### References\n\nJupyterHub documentation on why and when `frame-ancestors: self` is insecure, and why it was disabled by default: https://jupyterhub.readthedocs.io/en/stable/explanation/websecurity.html#:~:text=frame-ancestors", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "PyPI", + "name": "nbgrader" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0.9.4" + }, + { + "fixed": "0.9.5" + } + ] + } + ], + "versions": [ + "0.9.4" + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/jupyter/nbgrader/security/advisories/GHSA-fcr8-4r9f-r66m" + }, + { + "type": "WEB", + "url": "https://github.com/jupyter/nbgrader/pull/1915" + }, + { + "type": "WEB", + "url": "https://github.com/jupyter/nbgrader/commit/73e137511ac1dc02e95790d4fd6d4d88dab42325" + }, + { + "type": "PACKAGE", + "url": "https://github.com/jupyter/nbgrader" + }, + { + "type": "WEB", + "url": "https://jupyterhub.readthedocs.io/en/stable/explanation/websecurity.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1021" + ], + "severity": "HIGH", + "github_reviewed": true, + "github_reviewed_at": "2025-01-17T16:29:16Z", + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-8vq4-8hfp-29xh/GHSA-8vq4-8hfp-29xh.json b/advisories/unreviewed/2025/01/GHSA-8vq4-8hfp-29xh/GHSA-8vq4-8hfp-29xh.json deleted file mode 100644 index 2cd5267b974..00000000000 --- a/advisories/unreviewed/2025/01/GHSA-8vq4-8hfp-29xh/GHSA-8vq4-8hfp-29xh.json +++ /dev/null @@ -1,29 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-8vq4-8hfp-29xh", - "modified": "2025-01-17T00:30:48Z", - "published": "2025-01-17T00:30:48Z", - "aliases": [ - "CVE-2024-48460" - ], - "details": "An issue in Eugeny Tabby 1.0.213 allows a remote attacker to obtain sensitive information via the server and sends the SSH username and password even when the host key verification fails.", - "severity": [], - "affected": [], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48460" - }, - { - "type": "WEB", - "url": "https://github.com/Eugeny/tabby/issues/9955" - } - ], - "database_specific": { - "cwe_ids": [], - "severity": null, - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2025-01-16T22:15:39Z" - } -} \ No newline at end of file