diff --git a/advisories/github-reviewed/2021/09/GHSA-4qw8-pgpr-p9mq/GHSA-4qw8-pgpr-p9mq.json b/advisories/github-reviewed/2021/09/GHSA-4qw8-pgpr-p9mq/GHSA-4qw8-pgpr-p9mq.json index b159f99e630..a9c88140f96 100644 --- a/advisories/github-reviewed/2021/09/GHSA-4qw8-pgpr-p9mq/GHSA-4qw8-pgpr-p9mq.json +++ b/advisories/github-reviewed/2021/09/GHSA-4qw8-pgpr-p9mq/GHSA-4qw8-pgpr-p9mq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4qw8-pgpr-p9mq", - "modified": "2021-09-15T18:30:14Z", + "modified": "2023-11-27T21:44:31Z", "published": "2021-09-07T22:56:43Z", "aliases": [ "CVE-2019-10095" @@ -44,10 +44,18 @@ "type": "PACKAGE", "url": "https://github.com/apache/zeppelin" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/rd56389ba9cab30a6c976b9a4a6df0f85cbe8fba6a60a3cf6e3ba716b%40%3Cusers.zeppelin.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/rd56389ba9cab30a6c976b9a4a6df0f85cbe8fba6a60a3cf6e3ba716b@%3Cusers.zeppelin.apache.org%3E" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/rdf06e8423833b3daadc30c56a2ff47c48920864d5199476daa897208%40%3Cannounce.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/rdf06e8423833b3daadc30c56a2ff47c48920864d5199476daa897208%40%3Cusers.zeppelin.apache.org%3E" @@ -60,6 +68,10 @@ "type": "WEB", "url": "https://lists.apache.org/thread.html/rdf06e8423833b3daadc30c56a2ff47c48920864d5199476daa897208@%3Cusers.zeppelin.apache.org%3E" }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202311-04" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2021/09/02/1" @@ -70,7 +82,7 @@ "CWE-77", "CWE-78" ], - "severity": "HIGH", + "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2021-09-03T20:16:11Z", "nvd_published_at": "2021-09-02T17:15:00Z" diff --git a/advisories/github-reviewed/2021/09/GHSA-87p2-cvhq-q4mv/GHSA-87p2-cvhq-q4mv.json b/advisories/github-reviewed/2021/09/GHSA-87p2-cvhq-q4mv/GHSA-87p2-cvhq-q4mv.json index 1e04e0f4d63..ba0b34febe1 100644 --- a/advisories/github-reviewed/2021/09/GHSA-87p2-cvhq-q4mv/GHSA-87p2-cvhq-q4mv.json +++ b/advisories/github-reviewed/2021/09/GHSA-87p2-cvhq-q4mv/GHSA-87p2-cvhq-q4mv.json @@ -44,6 +44,10 @@ "type": "PACKAGE", "url": "https://github.com/apache/zeppelin" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r768800925d6407a6a87ccae0ec98776b7bda50c0e3ed3d0130dad028%40%3Cannounce.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/r768800925d6407a6a87ccae0ec98776b7bda50c0e3ed3d0130dad028%40%3Cusers.zeppelin.apache.org%3E" @@ -56,10 +60,18 @@ "type": "WEB", "url": "https://lists.apache.org/thread.html/r768800925d6407a6a87ccae0ec98776b7bda50c0e3ed3d0130dad028@%3Cusers.zeppelin.apache.org%3E" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r99529e175a7c1c9a26bd41a02802c8af7aa97319fe561874627eb999%40%3Cusers.zeppelin.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/r99529e175a7c1c9a26bd41a02802c8af7aa97319fe561874627eb999@%3Cusers.zeppelin.apache.org%3E" }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202311-04" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2021/09/02/2" diff --git a/advisories/github-reviewed/2021/09/GHSA-mf7q-gw5f-q8jj/GHSA-mf7q-gw5f-q8jj.json b/advisories/github-reviewed/2021/09/GHSA-mf7q-gw5f-q8jj/GHSA-mf7q-gw5f-q8jj.json index 93a4ad27956..303a88934a5 100644 --- a/advisories/github-reviewed/2021/09/GHSA-mf7q-gw5f-q8jj/GHSA-mf7q-gw5f-q8jj.json +++ b/advisories/github-reviewed/2021/09/GHSA-mf7q-gw5f-q8jj/GHSA-mf7q-gw5f-q8jj.json @@ -44,10 +44,18 @@ "type": "PACKAGE", "url": "https://github.com/apache/zeppelin" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r31012f2c8e39a5e12e14c1de030012cb8b51c037d953d73b291b7b50%40%3Cusers.zeppelin.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/r31012f2c8e39a5e12e14c1de030012cb8b51c037d953d73b291b7b50@%3Cusers.zeppelin.apache.org%3E" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r90590aa5ea788128ecc2e822e1e64d5200b4cb92b06707b38da4cb3d%40%3Cannounce.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/r90590aa5ea788128ecc2e822e1e64d5200b4cb92b06707b38da4cb3d%40%3Cusers.zeppelin.apache.org%3E" @@ -60,6 +68,10 @@ "type": "WEB", "url": "https://lists.apache.org/thread.html/r90590aa5ea788128ecc2e822e1e64d5200b4cb92b06707b38da4cb3d@%3Cusers.zeppelin.apache.org%3E" }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202311-04" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2021/09/02/3" diff --git a/advisories/github-reviewed/2023/11/GHSA-j72f-h752-mx4w/GHSA-j72f-h752-mx4w.json b/advisories/github-reviewed/2023/11/GHSA-j72f-h752-mx4w/GHSA-j72f-h752-mx4w.json index 998f7f5d6d7..5b2b5a16e13 100644 --- a/advisories/github-reviewed/2023/11/GHSA-j72f-h752-mx4w/GHSA-j72f-h752-mx4w.json +++ b/advisories/github-reviewed/2023/11/GHSA-j72f-h752-mx4w/GHSA-j72f-h752-mx4w.json @@ -1,10 +1,10 @@ { "schema_version": "1.4.0", "id": "GHSA-j72f-h752-mx4w", - "modified": "2023-11-23T00:28:13Z", + "modified": "2023-11-27T21:44:44Z", "published": "2023-11-23T00:28:13Z", "aliases": [ - + "CVE-2023-48708" ], "summary": "Insertion of Sensitive Information into Log", "details": "### Impact\nIf successful login attempts are recorded, the raw tokens are stored in the log table.\nIf a malicious person somehow views the data in the log table, he or she can obtain a raw token, which can then be used to send a request with that user's authority.\n\nWhen you (1) **use the following authentiactors**,\n- [AccessTokens](https://codeigniter4.github.io/shield/references/authentication/tokens/) (`tokens`)\n- [JWT](https://codeigniter4.github.io/shield/addons/jwt/) (`jwt`)\n- [HmacSha256](https://codeigniter4.github.io/shield/references/authentication/hmac/) (`hmac`)\n\nand you (2) **log successful login attempts**, the raw tokens are stored.\n\n### Patches\nUpgrade to Shield v1.0.0-beta.8 or later.\n\n### Workarounds\nDisable logging for successful login attempts by the configuration files.\n\n- AccessTokens or HmacSha256\n - Set `Config\\AuthToken::$recordLoginAttempt` to `Auth::RECORD_LOGIN_ATTEMPT_FAILURE` or `Auth::RECORD_LOGIN_ATTEMPT_NONE`\n- JWT\n - Set `Config\\AuthJWT::$recordLoginAttempt` to `Auth::RECORD_LOGIN_ATTEMPT_FAILURE` or `Auth::RECORD_LOGIN_ATTEMPT_NONE`\n\n### References\n- https://codeigniter4.github.io/shield/getting_started/authenticators/\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue or discussion in [codeigniter4/shield](https://github.com/codeigniter4/shield)\n* Email us at [security@codeigniter.com](mailto:security@codeigniter.com)\n", @@ -40,10 +40,18 @@ "type": "WEB", "url": "https://github.com/codeigniter4/shield/security/advisories/GHSA-j72f-h752-mx4w" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48708" + }, { "type": "WEB", "url": "https://github.com/codeigniter4/shield/commit/7e84c3fb3411294f70890819bfe51781bb9dc8e4" }, + { + "type": "WEB", + "url": "https://codeigniter4.github.io/shield/getting_started/authenticators/" + }, { "type": "PACKAGE", "url": "https://github.com/codeigniter4/shield" @@ -56,6 +64,6 @@ "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2023-11-23T00:28:13Z", - "nvd_published_at": null + "nvd_published_at": "2023-11-24T18:15:07Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2023/11/GHSA-v427-c49j-8w6x/GHSA-v427-c49j-8w6x.json b/advisories/github-reviewed/2023/11/GHSA-v427-c49j-8w6x/GHSA-v427-c49j-8w6x.json index 1ebae32720e..2ba496ea079 100644 --- a/advisories/github-reviewed/2023/11/GHSA-v427-c49j-8w6x/GHSA-v427-c49j-8w6x.json +++ b/advisories/github-reviewed/2023/11/GHSA-v427-c49j-8w6x/GHSA-v427-c49j-8w6x.json @@ -1,10 +1,10 @@ { "schema_version": "1.4.0", "id": "GHSA-v427-c49j-8w6x", - "modified": "2023-11-23T00:28:14Z", + "modified": "2023-11-27T21:44:37Z", "published": "2023-11-23T00:28:14Z", "aliases": [ - + "CVE-2023-48707" ], "summary": "Cleartext Storage of Sensitive Information in HMAC SHA256 Authentication", "details": "### Impact\n**secretKey**, an important key for HMAC SHA256 authentication, was stored in the database in raw form.\n\nIf a malicious person somehow had access to the data in the database, they could use the key and secretKey for HMAC SHA256 authentication to send requests impersonating that person.\n\n### Patches\nUpgrade to Shield v1.0.0-beta.8 or later.\n\nAfter upgrading, all existing secret keys must be encrypted.\nSee https://github.com/codeigniter4/shield/blob/develop/UPGRADING.md for details.\n\n### Workarounds\nNone.\n\n### References\n- https://codeigniter4.github.io/shield/references/authentication/hmac/\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue or discussion in [codeigniter4/shield](https://github.com/codeigniter4/shield)\n* Email us at [security@codeigniter.com](mailto:security@codeigniter.com)\n", @@ -40,6 +40,10 @@ "type": "WEB", "url": "https://github.com/codeigniter4/shield/security/advisories/GHSA-v427-c49j-8w6x" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48707" + }, { "type": "WEB", "url": "https://github.com/codeigniter4/shield/commit/f77c6ae20275ac1245330a2b9a523bf7e6f6202f" @@ -56,6 +60,6 @@ "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2023-11-23T00:28:14Z", - "nvd_published_at": null + "nvd_published_at": "2023-11-24T18:15:07Z" } } \ No newline at end of file