Publish Advisories

GHSA-4qw8-pgpr-p9mq
GHSA-87p2-cvhq-q4mv
GHSA-mf7q-gw5f-q8jj
GHSA-j72f-h752-mx4w
GHSA-v427-c49j-8w6x
This commit is contained in:
advisory-database[bot]
2023-11-27 21:45:26 +00:00
parent 45a858cbe3
commit 5e434a0e3a
5 changed files with 56 additions and 8 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4qw8-pgpr-p9mq",
"modified": "2021-09-15T18:30:14Z",
"modified": "2023-11-27T21:44:31Z",
"published": "2021-09-07T22:56:43Z",
"aliases": [
"CVE-2019-10095"
@@ -44,10 +44,18 @@
"type": "PACKAGE",
"url": "https://github.com/apache/zeppelin"
},
{
"type": "WEB",
"url": "https://lists.apache.org/thread.html/rd56389ba9cab30a6c976b9a4a6df0f85cbe8fba6a60a3cf6e3ba716b%40%3Cusers.zeppelin.apache.org%3E"
},
{
"type": "WEB",
"url": "https://lists.apache.org/thread.html/rd56389ba9cab30a6c976b9a4a6df0f85cbe8fba6a60a3cf6e3ba716b@%3Cusers.zeppelin.apache.org%3E"
},
{
"type": "WEB",
"url": "https://lists.apache.org/thread.html/rdf06e8423833b3daadc30c56a2ff47c48920864d5199476daa897208%40%3Cannounce.apache.org%3E"
},
{
"type": "WEB",
"url": "https://lists.apache.org/thread.html/rdf06e8423833b3daadc30c56a2ff47c48920864d5199476daa897208%40%3Cusers.zeppelin.apache.org%3E"
@@ -60,6 +68,10 @@
"type": "WEB",
"url": "https://lists.apache.org/thread.html/rdf06e8423833b3daadc30c56a2ff47c48920864d5199476daa897208@%3Cusers.zeppelin.apache.org%3E"
},
{
"type": "WEB",
"url": "https://security.gentoo.org/glsa/202311-04"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2021/09/02/1"
@@ -70,7 +82,7 @@
"CWE-77",
"CWE-78"
],
"severity": "HIGH",
"severity": "CRITICAL",
"github_reviewed": true,
"github_reviewed_at": "2021-09-03T20:16:11Z",
"nvd_published_at": "2021-09-02T17:15:00Z"
@@ -44,6 +44,10 @@
"type": "PACKAGE",
"url": "https://github.com/apache/zeppelin"
},
{
"type": "WEB",
"url": "https://lists.apache.org/thread.html/r768800925d6407a6a87ccae0ec98776b7bda50c0e3ed3d0130dad028%40%3Cannounce.apache.org%3E"
},
{
"type": "WEB",
"url": "https://lists.apache.org/thread.html/r768800925d6407a6a87ccae0ec98776b7bda50c0e3ed3d0130dad028%40%3Cusers.zeppelin.apache.org%3E"
@@ -56,10 +60,18 @@
"type": "WEB",
"url": "https://lists.apache.org/thread.html/r768800925d6407a6a87ccae0ec98776b7bda50c0e3ed3d0130dad028@%3Cusers.zeppelin.apache.org%3E"
},
{
"type": "WEB",
"url": "https://lists.apache.org/thread.html/r99529e175a7c1c9a26bd41a02802c8af7aa97319fe561874627eb999%40%3Cusers.zeppelin.apache.org%3E"
},
{
"type": "WEB",
"url": "https://lists.apache.org/thread.html/r99529e175a7c1c9a26bd41a02802c8af7aa97319fe561874627eb999@%3Cusers.zeppelin.apache.org%3E"
},
{
"type": "WEB",
"url": "https://security.gentoo.org/glsa/202311-04"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2021/09/02/2"
@@ -44,10 +44,18 @@
"type": "PACKAGE",
"url": "https://github.com/apache/zeppelin"
},
{
"type": "WEB",
"url": "https://lists.apache.org/thread.html/r31012f2c8e39a5e12e14c1de030012cb8b51c037d953d73b291b7b50%40%3Cusers.zeppelin.apache.org%3E"
},
{
"type": "WEB",
"url": "https://lists.apache.org/thread.html/r31012f2c8e39a5e12e14c1de030012cb8b51c037d953d73b291b7b50@%3Cusers.zeppelin.apache.org%3E"
},
{
"type": "WEB",
"url": "https://lists.apache.org/thread.html/r90590aa5ea788128ecc2e822e1e64d5200b4cb92b06707b38da4cb3d%40%3Cannounce.apache.org%3E"
},
{
"type": "WEB",
"url": "https://lists.apache.org/thread.html/r90590aa5ea788128ecc2e822e1e64d5200b4cb92b06707b38da4cb3d%40%3Cusers.zeppelin.apache.org%3E"
@@ -60,6 +68,10 @@
"type": "WEB",
"url": "https://lists.apache.org/thread.html/r90590aa5ea788128ecc2e822e1e64d5200b4cb92b06707b38da4cb3d@%3Cusers.zeppelin.apache.org%3E"
},
{
"type": "WEB",
"url": "https://security.gentoo.org/glsa/202311-04"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2021/09/02/3"
@@ -1,10 +1,10 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j72f-h752-mx4w",
"modified": "2023-11-23T00:28:13Z",
"modified": "2023-11-27T21:44:44Z",
"published": "2023-11-23T00:28:13Z",
"aliases": [
"CVE-2023-48708"
],
"summary": "Insertion of Sensitive Information into Log",
"details": "### Impact\nIf successful login attempts are recorded, the raw tokens are stored in the log table.\nIf a malicious person somehow views the data in the log table, he or she can obtain a raw token, which can then be used to send a request with that user's authority.\n\nWhen you (1) **use the following authentiactors**,\n- [AccessTokens](https://codeigniter4.github.io/shield/references/authentication/tokens/) (`tokens`)\n- [JWT](https://codeigniter4.github.io/shield/addons/jwt/) (`jwt`)\n- [HmacSha256](https://codeigniter4.github.io/shield/references/authentication/hmac/) (`hmac`)\n\nand you (2) **log successful login attempts**, the raw tokens are stored.\n\n### Patches\nUpgrade to Shield v1.0.0-beta.8 or later.\n\n### Workarounds\nDisable logging for successful login attempts by the configuration files.\n\n- AccessTokens or HmacSha256\n - Set `Config\\AuthToken::$recordLoginAttempt` to `Auth::RECORD_LOGIN_ATTEMPT_FAILURE` or `Auth::RECORD_LOGIN_ATTEMPT_NONE`\n- JWT\n - Set `Config\\AuthJWT::$recordLoginAttempt` to `Auth::RECORD_LOGIN_ATTEMPT_FAILURE` or `Auth::RECORD_LOGIN_ATTEMPT_NONE`\n\n### References\n- https://codeigniter4.github.io/shield/getting_started/authenticators/\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue or discussion in [codeigniter4/shield](https://github.com/codeigniter4/shield)\n* Email us at [security@codeigniter.com](mailto:security@codeigniter.com)\n",
@@ -40,10 +40,18 @@
"type": "WEB",
"url": "https://github.com/codeigniter4/shield/security/advisories/GHSA-j72f-h752-mx4w"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48708"
},
{
"type": "WEB",
"url": "https://github.com/codeigniter4/shield/commit/7e84c3fb3411294f70890819bfe51781bb9dc8e4"
},
{
"type": "WEB",
"url": "https://codeigniter4.github.io/shield/getting_started/authenticators/"
},
{
"type": "PACKAGE",
"url": "https://github.com/codeigniter4/shield"
@@ -56,6 +64,6 @@
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2023-11-23T00:28:13Z",
"nvd_published_at": null
"nvd_published_at": "2023-11-24T18:15:07Z"
}
}
@@ -1,10 +1,10 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v427-c49j-8w6x",
"modified": "2023-11-23T00:28:14Z",
"modified": "2023-11-27T21:44:37Z",
"published": "2023-11-23T00:28:14Z",
"aliases": [
"CVE-2023-48707"
],
"summary": "Cleartext Storage of Sensitive Information in HMAC SHA256 Authentication",
"details": "### Impact\n**secretKey**, an important key for HMAC SHA256 authentication, was stored in the database in raw form.\n\nIf a malicious person somehow had access to the data in the database, they could use the key and secretKey for HMAC SHA256 authentication to send requests impersonating that person.\n\n### Patches\nUpgrade to Shield v1.0.0-beta.8 or later.\n\nAfter upgrading, all existing secret keys must be encrypted.\nSee https://github.com/codeigniter4/shield/blob/develop/UPGRADING.md for details.\n\n### Workarounds\nNone.\n\n### References\n- https://codeigniter4.github.io/shield/references/authentication/hmac/\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue or discussion in [codeigniter4/shield](https://github.com/codeigniter4/shield)\n* Email us at [security@codeigniter.com](mailto:security@codeigniter.com)\n",
@@ -40,6 +40,10 @@
"type": "WEB",
"url": "https://github.com/codeigniter4/shield/security/advisories/GHSA-v427-c49j-8w6x"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48707"
},
{
"type": "WEB",
"url": "https://github.com/codeigniter4/shield/commit/f77c6ae20275ac1245330a2b9a523bf7e6f6202f"
@@ -56,6 +60,6 @@
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2023-11-23T00:28:14Z",
"nvd_published_at": null
"nvd_published_at": "2023-11-24T18:15:07Z"
}
}