mirror of
https://github.com/netbirdio/advisory-database.git
synced 2026-05-22 18:04:22 -07:00
Advisory Database Sync
This commit is contained in:
@@ -3,14 +3,10 @@
|
||||
"id": "GHSA-8xqr-4cpm-wx7g",
|
||||
"modified": "2020-08-31T18:31:14Z",
|
||||
"published": "2019-05-31T23:47:27Z",
|
||||
"aliases": [
|
||||
|
||||
],
|
||||
"aliases": [],
|
||||
"summary": "Cross-Site Scripting in react-svg",
|
||||
"details": "Versions of `react-svg` before 2.2.18 are vulnerable to cross-site scripting (xss). This is due to the fact that scripts found in SVG files are run by default.\n\n\n## Recommendation\n\nUpdate to version 2.2.18 or later.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"severity": [],
|
||||
"affected": [
|
||||
{
|
||||
"package": {
|
||||
|
||||
@@ -3,14 +3,10 @@
|
||||
"id": "GHSA-j4mr-9xw3-c9jx",
|
||||
"modified": "2020-08-31T18:31:43Z",
|
||||
"published": "2019-05-31T23:47:01Z",
|
||||
"aliases": [
|
||||
|
||||
],
|
||||
"aliases": [],
|
||||
"summary": "Out-of-bounds Read in base64-url",
|
||||
"details": "Versions of `base64-url` before 2.0.0 are vulnerable to out-of-bounds read as it allocates uninitialized Buffers when number is passed in input.\n\n\n## Recommendation\n\nUpdate to version 2.0.0 or later.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"severity": [],
|
||||
"affected": [
|
||||
{
|
||||
"package": {
|
||||
|
||||
@@ -3,14 +3,10 @@
|
||||
"id": "GHSA-vmhw-fhj6-m3g5",
|
||||
"modified": "2020-08-31T18:31:33Z",
|
||||
"published": "2019-05-31T23:46:33Z",
|
||||
"aliases": [
|
||||
|
||||
],
|
||||
"aliases": [],
|
||||
"summary": "Path Traversal in angular-http-server",
|
||||
"details": "Versions of `angular-http-server` before 1.4.4 are vulnerable to path traversal.\n\n\n## Recommendation\n\nUpdate to version 1.4.4 or later.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"severity": [],
|
||||
"affected": [
|
||||
{
|
||||
"package": {
|
||||
|
||||
@@ -3,14 +3,10 @@
|
||||
"id": "GHSA-28xh-wpgr-7fm8",
|
||||
"modified": "2020-08-31T18:31:51Z",
|
||||
"published": "2019-06-20T15:35:49Z",
|
||||
"aliases": [
|
||||
|
||||
],
|
||||
"aliases": [],
|
||||
"summary": "Command Injection in open",
|
||||
"details": "Versions of `open` before 6.0.0 are vulnerable to command injection when unsanitized user input is passed in.\n\nThe package does come with the following warning in the readme:\n\n```\nThe same care should be taken when calling open as if you were calling child_process.exec directly. If it is an executable it will run in a new shell.\n```\n\n\n## Recommendation\n\n`open` is now the deprecated `opn` package. Upgrading to the latest version is likely have unwanted effects since it now has a very different API but will prevent this vulnerability.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"severity": [],
|
||||
"affected": [
|
||||
{
|
||||
"package": {
|
||||
|
||||
@@ -3,9 +3,7 @@
|
||||
"id": "GHSA-4vmm-mhcq-4x9j",
|
||||
"modified": "2021-08-16T16:06:38Z",
|
||||
"published": "2019-06-14T16:15:14Z",
|
||||
"aliases": [
|
||||
|
||||
],
|
||||
"aliases": [],
|
||||
"summary": "Sandbox Bypass Leading to Arbitrary Code Execution in constantinople",
|
||||
"details": "Versions of `constantinople` prior to 3.1.1 are vulnerable to a sandbox bypass which can lead to arbitrary code execution.\n\n\n## Recommendation\n\nUpdate to version 3.1.1 or later.",
|
||||
"severity": [
|
||||
@@ -54,9 +52,7 @@
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"cwe_ids": [],
|
||||
"severity": "CRITICAL",
|
||||
"github_reviewed": true,
|
||||
"github_reviewed_at": "2019-06-14T16:14:40Z",
|
||||
|
||||
@@ -3,14 +3,10 @@
|
||||
"id": "GHSA-57cf-349j-352g",
|
||||
"modified": "2020-08-31T18:31:27Z",
|
||||
"published": "2019-06-12T16:37:00Z",
|
||||
"aliases": [
|
||||
|
||||
],
|
||||
"aliases": [],
|
||||
"summary": "Out-of-bounds Read in npmconf",
|
||||
"details": "Versions of `npmconf` before 2.1.3 allocate and write to disk uninitialized memory contents when a typed number is passed as input on Node.js 4.x.\n\n\n## Recommendation\n\nUpdate to version 2.1.3 or later. Consider switching to another config storage mechanism, as npmconf is deprecated and should not be used.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"severity": [],
|
||||
"affected": [
|
||||
{
|
||||
"package": {
|
||||
|
||||
@@ -3,14 +3,10 @@
|
||||
"id": "GHSA-73cw-jxmm-qpgh",
|
||||
"modified": "2020-08-31T18:31:31Z",
|
||||
"published": "2019-06-11T16:40:48Z",
|
||||
"aliases": [
|
||||
|
||||
],
|
||||
"aliases": [],
|
||||
"summary": "Path Traversal in localhost-now",
|
||||
"details": "All versions of `localhost-now` are vulnerable to path traversal. This vulnerability is a bypass to the path traversal fix introduced in version 1.0.2\n\nProof of concept:\n\n```\n$ curl -v --path-as-is \"http://IP:5432/..././..././..././..././..././..././..././..././..././..././etc/passwd\" \n```\n\n\n## Recommendation\n\nNo fix is currently available for this vulnerability. It is our recommendation to not install or use this module until a fix is available.\n ",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"severity": [],
|
||||
"affected": [
|
||||
{
|
||||
"package": {
|
||||
|
||||
@@ -3,14 +3,10 @@
|
||||
"id": "GHSA-8f93-rv4p-x4jw",
|
||||
"modified": "2020-08-31T18:31:48Z",
|
||||
"published": "2019-06-12T16:36:52Z",
|
||||
"aliases": [
|
||||
|
||||
],
|
||||
"aliases": [],
|
||||
"summary": "SQL Injection in sql",
|
||||
"details": "All versions of `sql` are vulnerable to sql injection as it does not properly escape parameters when building SQL queries.\n\n\n## Recommendation\n\nNo fix is currently available for this vulnerability. It is our recommendation to not install or use this module until a fix is available.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"severity": [],
|
||||
"affected": [
|
||||
{
|
||||
"package": {
|
||||
|
||||
@@ -3,14 +3,10 @@
|
||||
"id": "GHSA-g74r-ffvr-5q9f",
|
||||
"modified": "2020-08-31T18:29:17Z",
|
||||
"published": "2019-06-03T17:26:44Z",
|
||||
"aliases": [
|
||||
|
||||
],
|
||||
"aliases": [],
|
||||
"summary": "Memory Exposure in concat-stream",
|
||||
"details": "Versions of `concat-stream` before 1.5.2 are vulnerable to memory exposure if userp provided input is passed into `write()`\n\nVersions <1.3.0 are not affected due to not using unguarded Buffer constructor.\n\n\n\n## Recommendation\n\nUpdate to version 1.5.2, 1.4.11, 1.3.2 or later.\n\nIf you are unable to update make sure user provided input into the `write()` function is not a number.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"severity": [],
|
||||
"affected": [
|
||||
{
|
||||
"package": {
|
||||
|
||||
@@ -3,9 +3,7 @@
|
||||
"id": "GHSA-mxjr-xmcg-fg7w",
|
||||
"modified": "2021-08-17T15:41:58Z",
|
||||
"published": "2019-06-27T17:25:21Z",
|
||||
"aliases": [
|
||||
|
||||
],
|
||||
"aliases": [],
|
||||
"summary": "Arbitrary Code Injection in mobile-icon-resizer",
|
||||
"details": "mobile-icon-resizer resizes large images for use as icons for iOS and Android.\n\nmobile-icon-resizer has a code execution vulnerability in versions before 0.4.3.\n\nmobile-icon-resizer takes an options object as an argument to define the resulting icons as such:\n```\nvar options = {\n config: './config.js'\n}\nresize(options, function(err){});\n```\nconfig.js would need to be a file on the filesystem and look something like:\n```\nvar config = {\n iOS: {\n \"images\": [\n /* iOS image definitions are not vulnerable */\n ]\n },\n android: {\n \"images\" : [\n {\n \"baseRatio\" : \"console.log('Executing script as baseRatio property')\",\n \"folder\" : \"drawable-ldpi\"\n },\n {\n \"ratio\" : \"console.log('Executing script as ratio property')\",\n \"folder\" : \"drawable-mdpi\"\n },\n /* other android image defintiions ... */\n ]\n }\n};\n\nexports = module.exports = config;\n```\nThe parameters `ratio` and `baseRatio` are passed directly to `eval()`, thus allowing dynamic javascript payloads to be executed.\n\n\n## Recommendation\n\nUpdate to version 0.4.3 or later.",
|
||||
"severity": [
|
||||
|
||||
@@ -3,14 +3,10 @@
|
||||
"id": "GHSA-g8m7-qhv7-9h5x",
|
||||
"modified": "2021-09-22T18:35:22Z",
|
||||
"published": "2019-07-05T21:07:14Z",
|
||||
"aliases": [
|
||||
|
||||
],
|
||||
"aliases": [],
|
||||
"summary": "Path Traversal in serve-here.js",
|
||||
"details": "Versions of `serve-here.js` prior to 1.2.0 are vulnerable to Path Traversal. The package fails to sanitize URLs, allowing attackers to access server files outside of the served folder using relative paths.\n\n\n## Recommendation\n\nUpgrade to version 1.2.0 or later.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"severity": [],
|
||||
"affected": [
|
||||
{
|
||||
"package": {
|
||||
|
||||
@@ -3,9 +3,7 @@
|
||||
"id": "GHSA-65p8-3hm4-h9h8",
|
||||
"modified": "2021-08-17T21:23:49Z",
|
||||
"published": "2019-08-23T00:04:48Z",
|
||||
"aliases": [
|
||||
|
||||
],
|
||||
"aliases": [],
|
||||
"summary": "Denial of Service in rgb2hex",
|
||||
"details": "All versions of `rgb2hex` are vulnerable to Regular Expression Denial of Service (ReDoS) when an attacker can pass in a specially crafted invalid color value.\n\n\n## Recommendation\n\nUpdate to version 0.1.6 or later.",
|
||||
"severity": [
|
||||
|
||||
@@ -3,9 +3,7 @@
|
||||
"id": "GHSA-rch7-f4h5-x9rj",
|
||||
"modified": "2021-08-17T21:32:42Z",
|
||||
"published": "2019-08-23T00:04:52Z",
|
||||
"aliases": [
|
||||
|
||||
],
|
||||
"aliases": [],
|
||||
"summary": "Identity Spoofing in libp2p-secio",
|
||||
"details": "Affected versions of `libp2p-secio` does not correctly verify that the `PeerId` of `DstPeer` matches the `PeerId` discovered in the crypto handshake, resulting in a high severity identity spoofing vulnerability. \n\n\n## Recommendation\n\nUpdate to version 0.9.0 or later.",
|
||||
"severity": [
|
||||
|
||||
@@ -4,14 +4,10 @@
|
||||
"modified": "2020-08-19T22:06:03Z",
|
||||
"published": "2020-08-19T22:06:03Z",
|
||||
"withdrawn": "2020-08-19T22:06:03Z",
|
||||
"aliases": [
|
||||
|
||||
],
|
||||
"aliases": [],
|
||||
"summary": "Regular Expression Denial of Service in is-my-json-valid",
|
||||
"details": "Withdrawn: Duplicate of GHSA-f522-ffg8-j8r6",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"severity": [],
|
||||
"affected": [
|
||||
{
|
||||
"package": {
|
||||
@@ -63,9 +59,7 @@
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"cwe_ids": [],
|
||||
"severity": "LOW",
|
||||
"github_reviewed": true,
|
||||
"github_reviewed_at": "2019-06-12T16:28:24Z",
|
||||
|
||||
@@ -4,14 +4,10 @@
|
||||
"modified": "2020-08-19T22:28:51Z",
|
||||
"published": "2020-08-19T22:28:51Z",
|
||||
"withdrawn": "2020-08-19T22:28:51Z",
|
||||
"aliases": [
|
||||
|
||||
],
|
||||
"aliases": [],
|
||||
"summary": "Command Injection in macaddress",
|
||||
"details": "Withdrawn: Duplicate of GHSA-pp57-mqmh-44h7",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"severity": [],
|
||||
"affected": [
|
||||
{
|
||||
"package": {
|
||||
@@ -40,9 +36,7 @@
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"cwe_ids": [],
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": true,
|
||||
"github_reviewed_at": "2019-06-12T16:32:29Z",
|
||||
|
||||
@@ -4,14 +4,10 @@
|
||||
"modified": "2020-08-19T22:15:57Z",
|
||||
"published": "2020-08-19T22:15:57Z",
|
||||
"withdrawn": "2020-08-19T22:15:57Z",
|
||||
"aliases": [
|
||||
|
||||
],
|
||||
"aliases": [],
|
||||
"summary": "Denial of Service in https-proxy-agent",
|
||||
"details": "Withdrawn: Duplicate of GHSA-8g7p-74h8-hg48",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"severity": [],
|
||||
"affected": [
|
||||
{
|
||||
"package": {
|
||||
@@ -40,9 +36,7 @@
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"cwe_ids": [],
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": true,
|
||||
"github_reviewed_at": "2019-06-03T17:15:10Z",
|
||||
|
||||
@@ -4,14 +4,10 @@
|
||||
"modified": "2020-08-03T18:22:36Z",
|
||||
"published": "2020-08-03T18:22:36Z",
|
||||
"withdrawn": "2020-08-03T18:22:36Z",
|
||||
"aliases": [
|
||||
|
||||
],
|
||||
"aliases": [],
|
||||
"summary": "Withdrawn",
|
||||
"details": "Withdrawn: duplicate of GHSA-2m39-62fm-q8r3",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"severity": [],
|
||||
"affected": [
|
||||
{
|
||||
"package": {
|
||||
@@ -66,9 +62,7 @@
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"cwe_ids": [],
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": true,
|
||||
"github_reviewed_at": "2019-06-03T17:13:33Z",
|
||||
|
||||
@@ -4,14 +4,10 @@
|
||||
"modified": "2021-02-24T19:33:17Z",
|
||||
"published": "2021-02-24T19:33:17Z",
|
||||
"withdrawn": "2021-02-24T19:33:17Z",
|
||||
"aliases": [
|
||||
|
||||
],
|
||||
"aliases": [],
|
||||
"summary": "Unencrypted passwords",
|
||||
"details": "A vulnerability found in Apache NIFI before v0.4.0-RC2. Passwords of InvokeHTTP weren?t encrypted.",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"severity": [],
|
||||
"affected": [
|
||||
{
|
||||
"package": {
|
||||
@@ -40,9 +36,7 @@
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
],
|
||||
"cwe_ids": [],
|
||||
"severity": "LOW",
|
||||
"github_reviewed": true,
|
||||
"github_reviewed_at": "2019-10-25T17:13:12Z",
|
||||
|
||||
@@ -3,9 +3,7 @@
|
||||
"id": "GHSA-q5fm-55c2-v6j9",
|
||||
"modified": "2024-08-21T22:30:04Z",
|
||||
"published": "2024-07-16T19:32:45Z",
|
||||
"aliases": [
|
||||
|
||||
],
|
||||
"aliases": [],
|
||||
"summary": "Fiona affected by CVE-2023-45853 related to MiniZip madler-zlib",
|
||||
"details": "### Summary\nVulnerability scan of fiona shows [CVE-2023-45853](https://nvd.nist.gov/vuln/detail/CVE-2023-45853). The vulnerability is in GDAL, a dependency of fiona.\n\n### Details\nFiona depends on GDAL and GDAL has a port of minizip. MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. The GDAL project has addressed the CVE in version 3.8.0. See https://lists.osgeo.org/pipermail/gdal-dev/2023-November/057881.html.\n\nThe Fiona version 1.9.6 wheels on PyPI include GDAL version 3.6.4 and thus could be vulnerable. All of the Fiona 1.10 pre-release wheels in PyPI include GDAL version 3.8.4 and are not vulnerable.\n\n### Impact\nSystems which use GDAL versions prior to 3.8.0 to open unchecked zip files, whether in combination with fiona or not, could be susceptible to buffer overflows.",
|
||||
"severity": [
|
||||
|
||||
@@ -3,14 +3,10 @@
|
||||
"id": "GHSA-fpgj-cr28-fvpx",
|
||||
"modified": "2024-08-21T18:33:17Z",
|
||||
"published": "2024-08-21T18:33:17Z",
|
||||
"aliases": [
|
||||
|
||||
],
|
||||
"aliases": [],
|
||||
"summary": "CWA-2024-006: wasmd non-deterministic module_query_safe query",
|
||||
"details": "**Component:** wasmd\n**Criticality:** Medium ([ACMv1](https://github.com/interchainio/security/blob/main/resources/CLASSIFICATION_MATRIX.md): I:Moderate; L:Likely)\n**Patched versions:** wasmd 0.53.0\n\nSee [CWA-2024-006](https://github.com/CosmWasm/advisories/blob/main/CWAs/CWA-2024-006.md) for more details.\n",
|
||||
"severity": [
|
||||
|
||||
],
|
||||
"severity": [],
|
||||
"affected": [
|
||||
{
|
||||
"package": {
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user