Publish Advisories

GHSA-36xr-4x2f-cfj9
GHSA-ff2w-wm48-jhqj
GHSA-m43p-55rf-8c2j
GHSA-vjqc-g788-f378
GHSA-36xr-4x2f-cfj9
GHSA-m43p-55rf-8c2j
This commit is contained in:
advisory-database[bot]
2024-02-21 00:23:17 +00:00
parent 5a419eba41
commit 657497cc08
6 changed files with 323 additions and 81 deletions
@@ -0,0 +1,147 @@
{
"schema_version": "1.4.0",
"id": "GHSA-36xr-4x2f-cfj9",
"modified": "2024-02-21T00:22:48Z",
"published": "2024-02-20T15:31:06Z",
"aliases": [
"CVE-2024-22369"
],
"summary": "Deserialization of Untrusted Data in Apache Camel SQL",
"details": "Deserialization of Untrusted Data vulnerability in Apache Camel SQL Component. This issue affects Apache Camel: from 3.0.0 before 3.21.4, from 3.22.0 before 3.22.1, from 4.0.0 before 4.0.4, from 4.1.0 before 4.4.0.\n\nUsers are recommended to upgrade to version 4.4.0, which fixes the issue. If users are on the 4.0.x LTS releases stream, then they are suggested to upgrade to 4.0.4. If users are on 3.x, they are suggested to move to 3.21.4 or 3.22.1\n\n",
"severity": [
],
"affected": [
{
"package": {
"ecosystem": "Maven",
"name": "org.apache.camel:camel-sql"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "3.0.0"
},
{
"fixed": "3.21.4"
}
]
}
]
},
{
"package": {
"ecosystem": "Maven",
"name": "org.apache.camel:camel-sql"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "3.22.0"
},
{
"fixed": "3.22.1"
}
]
}
]
},
{
"package": {
"ecosystem": "Maven",
"name": "org.apache.camel:camel-sql"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "4.0.0"
},
{
"fixed": "4.0.4"
}
]
}
]
},
{
"package": {
"ecosystem": "Maven",
"name": "org.apache.camel:camel-sql"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "4.1.0"
},
{
"fixed": "4.4.0"
}
]
}
]
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22369"
},
{
"type": "WEB",
"url": "https://github.com/apache/camel/pull/12706"
},
{
"type": "WEB",
"url": "https://github.com/apache/camel/pull/12707"
},
{
"type": "WEB",
"url": "https://github.com/apache/camel/pull/12708"
},
{
"type": "WEB",
"url": "https://github.com/apache/camel/pull/12709"
},
{
"type": "WEB",
"url": "https://github.com/apache/camel/pull/12716"
},
{
"type": "WEB",
"url": "https://github.com/apache/camel/pull/12717"
},
{
"type": "WEB",
"url": "https://github.com/apache/camel/pull/12718"
},
{
"type": "WEB",
"url": "https://github.com/apache/camel/pull/12719"
},
{
"type": "WEB",
"url": "https://github.com/apache/camel/pull/12789"
},
{
"type": "WEB",
"url": "https://lists.apache.org/thread/3dko781dy2gy5l3fs48p56fgp429yb0f"
}
],
"database_specific": {
"cwe_ids": [
"CWE-502"
],
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2024-02-21T00:22:48Z",
"nvd_published_at": "2024-02-20T15:15:10Z"
}
}
@@ -1,17 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-ff2w-wm48-jhqj",
"modified": "2024-02-20T15:31:03Z",
"modified": "2024-02-21T00:21:46Z",
"published": "2024-02-20T12:31:00Z",
"aliases": [
"CVE-2023-51770"
],
"summary": "Arbitrary File Read Vulnerability in Apache Dolphinscheduler",
"details": "Arbitrary File Read Vulnerability in Apache Dolphinscheduler.\n\nThis issue affects Apache DolphinScheduler: before 3.2.1. \n\nWe recommend users to upgrade Apache DolphinScheduler to version 3.2.1, which fixes the issue.",
"severity": [
],
"affected": [
{
"package": {
"ecosystem": "Maven",
"name": "org.apache.dolphinscheduler:dolphinscheduler"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "3.2.1"
}
]
}
]
}
],
"references": [
{
@@ -22,6 +41,10 @@
"type": "WEB",
"url": "https://github.com/apache/dolphinscheduler/pull/15433"
},
{
"type": "PACKAGE",
"url": "https://github.com/apache/dolphinscheduler"
},
{
"type": "WEB",
"url": "https://lists.apache.org/thread/4t8bdjqnfhldh73gy9p0whlgvnnbtn7g"
@@ -39,9 +62,9 @@
"cwe_ids": [
"CWE-94"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2024-02-21T00:21:46Z",
"nvd_published_at": "2024-02-20T10:15:08Z"
}
}
@@ -0,0 +1,119 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m43p-55rf-8c2j",
"modified": "2024-02-21T00:22:04Z",
"published": "2024-02-20T15:31:06Z",
"aliases": [
"CVE-2024-23114"
],
"summary": "Deserialization of Untrusted Data in Apache Camel CassandraQL",
"details": "Deserialization of Untrusted Data vulnerability in Apache Camel CassandraQL Component AggregationRepository which is vulnerable to unsafe deserialization. Under specific conditions it is possible to deserialize malicious payload.This issue affects Apache Camel: from 3.0.0 before 3.21.4, from 3.22.0 before 3.22.1, from 4.0.0 before 4.0.4, from 4.1.0 before 4.4.0.\n\nUsers are recommended to upgrade to version 4.4.0, which fixes the issue. If users are on the 4.0.x LTS releases stream, then they are suggested to upgrade to 4.0.4. If users are on 3.x, they are suggested to move to 3.21.4 or 3.22.1\n\n",
"severity": [
],
"affected": [
{
"package": {
"ecosystem": "Maven",
"name": "org.apache.camel:camel-cassandraql"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "3.0.0"
},
{
"fixed": "3.21.4"
}
]
}
]
},
{
"package": {
"ecosystem": "Maven",
"name": "org.apache.camel:camel-cassandraql"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "3.22.0"
},
{
"fixed": "3.22.1"
}
]
}
]
},
{
"package": {
"ecosystem": "Maven",
"name": "org.apache.camel:camel-cassandraql"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "4.0.0"
},
{
"fixed": "4.0.4"
}
]
}
]
},
{
"package": {
"ecosystem": "Maven",
"name": "org.apache.camel:camel-cassandraql"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "4.1.0"
},
{
"fixed": "4.4.0"
}
]
}
]
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23114"
},
{
"type": "WEB",
"url": "https://camel.apache.org/security/CVE-2024-23114.html"
},
{
"type": "PACKAGE",
"url": "https://github.com/apache/camel"
},
{
"type": "WEB",
"url": "https://issues.apache.org/jira/browse/CAMEL-20306"
}
],
"database_specific": {
"cwe_ids": [
"CWE-502"
],
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2024-02-21T00:22:04Z",
"nvd_published_at": "2024-02-20T15:15:10Z"
}
}
@@ -1,17 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vjqc-g788-f378",
"modified": "2024-02-20T15:31:03Z",
"modified": "2024-02-21T00:21:28Z",
"published": "2024-02-20T12:31:00Z",
"aliases": [
"CVE-2023-50270"
],
"details": "Session Fixation Apache DolphinScheduler before version 3.2.0, which session is still valid after the password change.\n\nUsers are recommended to upgrade to version 3.2.1, which fixes this issue.",
"summary": "Session Fixation Apache DolphinScheduler",
"details": "Session Fixation Apache DolphinScheduler before version 3.2.1, which session is still valid after the password change.\n\nUsers are recommended to upgrade to version 3.2.1, which fixes this issue.",
"severity": [
],
"affected": [
{
"package": {
"ecosystem": "Maven",
"name": "org.apache.dolphinscheduler:dolphinscheduler"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "3.2.1"
}
]
}
]
}
],
"references": [
{
@@ -22,6 +41,10 @@
"type": "WEB",
"url": "https://github.com/apache/dolphinscheduler/pull/15219"
},
{
"type": "PACKAGE",
"url": "https://github.com/apache/dolphinscheduler"
},
{
"type": "WEB",
"url": "https://lists.apache.org/thread/94prw8hyk60vvw7s6cs3tr708qzqlwl6"
@@ -39,9 +62,9 @@
"cwe_ids": [
"CWE-613"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-02-21T00:21:28Z",
"nvd_published_at": "2024-02-20T10:15:08Z"
}
}
@@ -1,35 +0,0 @@
{
"schema_version": "1.4.0",
"id": "GHSA-36xr-4x2f-cfj9",
"modified": "2024-02-20T15:31:06Z",
"published": "2024-02-20T15:31:06Z",
"aliases": [
"CVE-2024-22369"
],
"details": "Deserialization of Untrusted Data vulnerability in Apache Camel SQL ComponentThis issue affects Apache Camel: from 3.0.0 before 3.21.4, from 3.22.0 before 3.22.1, from 4.0.0 before 4.0.4, from 4.1.0 before 4.4.0.\n\nUsers are recommended to upgrade to version 4.4.0, which fixes the issue. If users are on the 4.0.x LTS releases stream, then they are suggested to upgrade to 4.0.4. If users are on 3.x, they are suggested to move to 3.21.4 or 3.22.1\n\n",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22369"
},
{
"type": "WEB",
"url": "https://lists.apache.org/thread/3dko781dy2gy5l3fs48p56fgp429yb0f"
}
],
"database_specific": {
"cwe_ids": [
"CWE-502"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-20T15:15:10Z"
}
}
@@ -1,35 +0,0 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m43p-55rf-8c2j",
"modified": "2024-02-20T15:31:06Z",
"published": "2024-02-20T15:31:06Z",
"aliases": [
"CVE-2024-23114"
],
"details": "Deserialization of Untrusted Data vulnerability in Apache Camel CassandraQL Component AggregationRepository which is vulnerable to unsafe deserialization. Under specific conditions it is possible to deserialize malicious payload.This issue affects Apache Camel: from 3.0.0 before 3.21.4, from 3.22.0 before 3.22.1, from 4.0.0 before 4.0.4, from 4.1.0 before 4.4.0.\n\nUsers are recommended to upgrade to version 4.4.0, which fixes the issue. If users are on the 4.0.x LTS releases stream, then they are suggested to upgrade to 4.0.4. If users are on 3.x, they are suggested to move to 3.21.4 or 3.22.1\n\n",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23114"
},
{
"type": "WEB",
"url": "https://camel.apache.org/security/CVE-2024-23114.html"
}
],
"database_specific": {
"cwe_ids": [
"CWE-502"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-02-20T15:15:10Z"
}
}