Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2024-12-07 05:15:55 +00:00
parent 174d518d39
commit 5e91943846
949 changed files with 1718 additions and 5154 deletions
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
@@ -77,9 +77,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2024-10-17T17:16:51Z",
@@ -120,9 +120,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2024-02-23T21:38:57Z",
@@ -4,9 +4,7 @@
"modified": "2024-10-07T20:58:38Z",
"published": "2022-09-30T00:00:20Z",
"withdrawn": "2024-10-07T20:58:38Z",
"aliases": [
],
"aliases": [],
"summary": "Duplicate Advisory: AWS Redshift JDBC Driver fails to validate class type during object instantiation",
"details": "## Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-jc69-hjw2-fm86. This link is maintained to preserve external references.\n\n## Original Description\nIn Amazon AWS Redshift JDBC Driver (aka amazon-redshift-jdbc-driver or redshift-jdbc42) before 2.1.0.8, the Object Factory does not check the class type when instantiating an object from a class name. This issue has been fixed in version 2.1.0.8.",
"severity": [
@@ -4,9 +4,7 @@
"modified": "2024-10-07T21:00:34Z",
"published": "2022-12-20T00:30:27Z",
"withdrawn": "2024-10-07T21:00:34Z",
"aliases": [
],
"aliases": [],
"summary": "Duplicate Advisory: Apiman has insufficient checks for read permissions",
"details": "## Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-j94p-hv25-rm5g. This link is maintained to preserve external references.\n\n## Original Description\nApiman 1.5.7 through 2.2.3.Final has insufficient checks for read permissions within the Apiman Manager REST API. A malicious user may be able to find and subscribe to private APIs they do not have permission for, thus accessing API Management-protected resources they should not be allowed to access. The root cause of the issue is the Apiman project's accidental acceptance of a large contribution that was not fully compatible with the security model of Apiman versions before 3.0.0.Final. Because of this, 3.0.0.Final is not affected by the vulnerability.",
"severity": [
@@ -4,9 +4,7 @@
"modified": "2024-06-10T18:30:52Z",
"published": "2024-02-19T15:30:38Z",
"withdrawn": "2024-02-21T23:18:25Z",
"aliases": [
],
"aliases": [],
"summary": "Duplicate Advisory: SQL injection in pgjdbc",
"details": "## Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-24rp-q3w6-vc56. This link is maintained to preserve external references.\n\n## Original Description\npgjdbc, the PostgreSQL JDBC Driver, allows attacker to inject SQL if using PreferQueryMode=SIMPLE. Note this is not the default. In the default mode there is no vulnerability. A placeholder for a numeric value must be immediately preceded by a minus. There must be a second placeholder for a string value after the first placeholder; both must be on the same line. By constructing a matching string payload, the attacker can inject SQL to alter the query,bypassing the protections that parameterized queries bring against SQL Injection attacks. Versions before 42.7.2, 42.6.1, 42.5.5, 42.4.4, 42.3.9, and 42.2.8 are affected.",
"severity": [
@@ -4,9 +4,7 @@
"modified": "2024-06-10T18:30:53Z",
"published": "2024-03-26T18:32:07Z",
"withdrawn": "2024-04-05T19:30:35Z",
"aliases": [
],
"aliases": [],
"summary": "Duplicate Advisory: Grafana vulnerable to authorization bypass",
"details": "## Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-67rv-qpw2-6qrr. This link is maintained to preserve external references.\n\n## Original Description\nIt is possible for a user in a different organization from the owner of a snapshot to bypass authorization and delete a snapshot by issuing a `DELETE` request to `/api/snapshots/<key>` using its view key. This functionality is intended to only be available to individuals with the permission to write/edit to the snapshot in question, but due to a bug in the authorization logic, deletion requests issued by an unprivileged user in a different organization than the snapshot owner are treated as authorized.\n\nGrafana Labs would like to thank Ravid Mazon and Jay Chen of Palo Alto Research for discovering and disclosing this vulnerability.\n\nThis issue affects Grafana: from 9.5.0 before 9.5.18, from 10.0.0 before 10.0.13, from 10.1.0 before 10.1.9, from 10.2.0 before 10.2.6, from 10.3.0 before 10.3.5.\n\n",
"severity": [
@@ -3,9 +3,7 @@
"id": "GHSA-3mm9-2p44-rw39",
"modified": "2024-05-22T19:03:54Z",
"published": "2024-05-22T19:03:54Z",
"aliases": [
],
"aliases": [],
"summary": "Silverstripe SiteTree Creation Permission Vulnerability",
"details": "A vulnerability exists in the permission validation for SiteTree object creation. By default user permissions are not validated by the SiteTree::canCreate method, unless overridden by user code or via the configuration system.\n\nThis vulnerability will allow users, or unauthenticated guests, to create new SiteTree objects in the database. This vulnerability is present when such users are given CMS access via other means, or if there is another mechanism (such as RestfulServer module) which allows model editing and relies on model-level permission checks.\n\nThis vulnerability is restricted to the creation of draft or live pages, and does not allow users to edit, publish, or unpublish existing pages.\n\nAll users should upgrade as soon as possible.",
"severity": [
@@ -3,9 +3,7 @@
"id": "GHSA-6hh6-59j2-qrxw",
"modified": "2024-05-22T18:25:16Z",
"published": "2024-05-22T18:25:16Z",
"aliases": [
],
"aliases": [],
"summary": "Silverstripe History XSS Vulnerability",
"details": "A cross-site scripting vulnerability has been discovered in the CMS page history tab.\n\nThis vulnerability can only be exploited if a user with CMS access has posted malicious or unescaped HTML into any of the text fields on a page, and if the \"compare mode\" option is selected. The HTML will be embedded into the page unescaped.\n\nThis has been resolved by performing the text comparison in a HTML friendly way.",
"severity": [
@@ -3,9 +3,7 @@
"id": "GHSA-779c-7w4p-2c4g",
"modified": "2024-05-22T18:18:18Z",
"published": "2024-05-22T18:18:18Z",
"aliases": [
],
"aliases": [],
"summary": "Silverstripe admin XSS Vulnerability via WYSIWYG editor",
"details": "It is possible for a bad actor with access to the CMS to make use of onmouseover or onmouseout attributes in the WYSIWYG editor to embed malicious javascript.",
"severity": [
@@ -3,9 +3,7 @@
"id": "GHSA-r97r-64vp-fghm",
"modified": "2024-05-22T18:53:38Z",
"published": "2024-05-22T18:53:38Z",
"aliases": [
],
"aliases": [],
"summary": "Silverstripe XSS vulnerability via VirtualPage",
"details": "A cross-site scripting vulnerability has been discovered in the VirtualPage class.\n\nThis vulnerability can only be exploited if a user with CMS access has posted malicious or unescaped HTML into any of the textfields of a page which a VirtualPage refers to.\n\nThis has been resolved by ensuring that VirtualPage safely escapes all field content.",
"severity": [
@@ -8,9 +8,7 @@
],
"summary": "PDF.js vulnerable to arbitrary JavaScript execution upon opening a malicious PDF",
"details": "### Impact\nIf pdf.js is used to load a malicious PDF, and PDF.js is configured with `isEvalSupported` set to `true` (which is the default value), unrestricted attacker-controlled JavaScript will be executed in the context of the hosting domain.\n\n### Patches\nThe patch removes the use of `eval`:\nhttps://github.com/mozilla/pdf.js/pull/18015\n\n### Workarounds\nSet the option `isEvalSupported` to `false`. \n\n### References\nhttps://bugzilla.mozilla.org/show_bug.cgi?id=1893645",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -82,9 +80,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2024-05-07T10:25:08Z",
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
],
"affected": [],
"references": [
{
"type": "ADVISORY",
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"affected": [],
"references": [
{
"type": "ADVISORY",
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
],
"affected": [],
"references": [
{
"type": "ADVISORY",
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"affected": [],
"references": [
{
"type": "ADVISORY",
@@ -27,9 +25,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
}
],
"affected": [
],
"affected": [],
"references": [
{
"type": "ADVISORY",
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
],
"affected": [],
"references": [
{
"type": "ADVISORY",

Some files were not shown because too many files have changed in this diff Show More