From 542d810354af85a32b7444b4412848727b4fb654 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 20 May 2024 20:21:28 +0000 Subject: [PATCH] Publish Advisories GHSA-gq5r-cc4w-g8xf GHSA-cqh9-jfqr-h9jj --- .../2021/06/GHSA-gq5r-cc4w-g8xf/GHSA-gq5r-cc4w-g8xf.json | 7 ++++--- .../2024/05/GHSA-cqh9-jfqr-h9jj/GHSA-cqh9-jfqr-h9jj.json | 7 ++++--- 2 files changed, 8 insertions(+), 6 deletions(-) diff --git a/advisories/github-reviewed/2021/06/GHSA-gq5r-cc4w-g8xf/GHSA-gq5r-cc4w-g8xf.json b/advisories/github-reviewed/2021/06/GHSA-gq5r-cc4w-g8xf/GHSA-gq5r-cc4w-g8xf.json index 2d1ae51a1ff..f9c9c36624f 100644 --- a/advisories/github-reviewed/2021/06/GHSA-gq5r-cc4w-g8xf/GHSA-gq5r-cc4w-g8xf.json +++ b/advisories/github-reviewed/2021/06/GHSA-gq5r-cc4w-g8xf/GHSA-gq5r-cc4w-g8xf.json @@ -1,13 +1,14 @@ { "schema_version": "1.4.0", "id": "GHSA-gq5r-cc4w-g8xf", - "modified": "2023-08-30T18:52:39Z", + "modified": "2024-05-20T20:18:56Z", "published": "2021-06-23T17:25:08Z", + "withdrawn": "2024-05-20T20:18:56Z", "aliases": [ ], - "summary": "gosaml2 is vulnerable to NULL Pointer Dereference from malformed XML signatures", - "details": "This affects all versions less than 0.7.0 of package github.com/russellhaering/gosaml2. There is a crash on null pointer dereference caused by sending malformed XML signatures.", + "summary": "Duplicate Advisory: gosaml2 is vulnerable to NULL Pointer Dereference from malformed XML signatures", + "details": "## Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-prjq-f4q3-fvfr. This link is maintained to preserve external references.\n\n## Original Description\nThis affects all versions less than 0.7.0 of package github.com/russellhaering/gosaml2. There is a crash on null pointer dereference caused by sending malformed XML signatures.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2024/05/GHSA-cqh9-jfqr-h9jj/GHSA-cqh9-jfqr-h9jj.json b/advisories/github-reviewed/2024/05/GHSA-cqh9-jfqr-h9jj/GHSA-cqh9-jfqr-h9jj.json index b1602671482..0979fe362d6 100644 --- a/advisories/github-reviewed/2024/05/GHSA-cqh9-jfqr-h9jj/GHSA-cqh9-jfqr-h9jj.json +++ b/advisories/github-reviewed/2024/05/GHSA-cqh9-jfqr-h9jj/GHSA-cqh9-jfqr-h9jj.json @@ -1,13 +1,14 @@ { "schema_version": "1.4.0", "id": "GHSA-cqh9-jfqr-h9jj", - "modified": "2024-05-16T17:46:18Z", + "modified": "2024-05-20T20:20:22Z", "published": "2024-05-16T09:33:09Z", + "withdrawn": "2024-05-20T20:20:22Z", "aliases": [ "CVE-2024-4642" ], - "summary": "Weights and Biases (wandb) has a Server-Side Request Forgery (SSRF) vulnerability", - "details": "A Server-Side Request Forgery (SSRF) vulnerability exists in the wandb/wandb repository due to improper handling of HTTP 302 redirects. This issue allows team members with access to the 'User settings -> Webhooks' function to exploit this vulnerability to access internal HTTP(s) servers. In severe cases, such as on AWS instances, this could potentially be abused to achieve remote code execution on the victim's machine. The vulnerability is present in the latest version of the repository.", + "summary": "Withdrawn Advisory: Weights and Biases (wandb) has a Server-Side Request Forgery (SSRF) vulnerability", + "details": "## Withdrawn Advisory\nThis advisory has been withdrawn because the underlying issue existed in Weights and Biases's backend server code, not the software development kit included in the `wandb` PyPI package, as originally reported. This link is maintained to preserve external references.\n\n## Original Description\nA Server-Side Request Forgery (SSRF) vulnerability exists in the wandb/wandb repository due to improper handling of HTTP 302 redirects. This issue allows team members with access to the 'User settings -> Webhooks' function to exploit this vulnerability to access internal HTTP(s) servers. In severe cases, such as on AWS instances, this could potentially be abused to achieve remote code execution on the victim's machine. The vulnerability is present in the latest version of the repository.", "severity": [ { "type": "CVSS_V3",