Publish Advisories

GHSA-4m6j-23p2-8c54
GHSA-hx5q-v6pj-533r
GHSA-p4m5-32pr-2hqr
This commit is contained in:
advisory-database[bot]
2024-02-26 20:05:48 +00:00
parent 5888a9ee54
commit 773da8761b
3 changed files with 214 additions and 0 deletions
@@ -0,0 +1,76 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4m6j-23p2-8c54",
"modified": "2024-02-26T20:04:37Z",
"published": "2024-02-26T20:04:37Z",
"aliases": [
"CVE-2024-1735"
],
"summary": "Armeria SAML authentication bypass due to missing validation on unsigned SAML messages",
"details": "### Impact\n\nThe SAML implementation provided by `armeria-saml` currently accepts unsigned SAML messages (assertions, logout requests, etc.) as they are, rather than rejecting them by default. As a result, an attacker can forge a SAML message to authenticate themselves, despite the fact that such an unsigned SAML message should be rejected.\n\n### Patches\n\nThe vulnerability has been patched in Armeria version 1.27.2. All users who rely on `armeria-saml` older than version 1.27.2 must upgrade to 1.27.2 or later.\n\n### Workarounds\n\nThere is no known workaround for this vulnerability.\n\n### References\n\n[`SamlMessageUtil.validateSignature()`](https://github.com/line/armeria/blob/0efc776988d71be4da6e506ec8a33c2b7b43f567/saml/src/main/java/com/linecorp/armeria/server/saml/SamlMessageUtil.java#L160-L163)",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
}
],
"affected": [
{
"package": {
"ecosystem": "Maven",
"name": "com.linecorp.armeria:armeria-saml"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "1.27.2"
}
]
}
],
"database_specific": {
"last_known_affected_version_range": "<= 1.27.1"
}
}
],
"references": [
{
"type": "WEB",
"url": "https://github.com/line/armeria/security/advisories/GHSA-4m6j-23p2-8c54"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1735"
},
{
"type": "WEB",
"url": "https://github.com/line/armeria/commit/b2aa9f49b46a7b0e03d8b8d753809cd1e8e2016c"
},
{
"type": "PACKAGE",
"url": "https://github.com/line/armeria"
},
{
"type": "WEB",
"url": "https://github.com/line/armeria/blob/0efc776988d71be4da6e506ec8a33c2b7b43f567/saml/src/main/java/com/linecorp/armeria/server/saml/SamlMessageUtil.java#L160-L163"
},
{
"type": "WEB",
"url": "https://github.com/line/armeria/releases/tag/armeria-1.27.2"
}
],
"database_specific": {
"cwe_ids": [
"CWE-304"
],
"severity": "CRITICAL",
"github_reviewed": true,
"github_reviewed_at": "2024-02-26T20:04:37Z",
"nvd_published_at": "2024-02-26T16:27:53Z"
}
}
@@ -0,0 +1,76 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hx5q-v6pj-533r",
"modified": "2024-02-26T20:04:50Z",
"published": "2024-02-26T20:04:50Z",
"aliases": [
],
"summary": "SAML authentication bypass due to missing validation on unsigned SAML messages",
"details": "### Impact\n\nWhen SAML is used as the authentication mechanism, Central Dogma accepts unsigned SAML messages (assertions, logout requests, etc.) as they are, rather than rejecting them by default. As a result, an attacker can forge a SAML message to authenticate themselves, despite the fact that such an unsigned SAML message should be rejected.\n\n### Patches\n\nThe vulnerability has been patched in Central Dogma 0.64.3 by updating its Armeria dependency to 1.27.2. All users who use SAML as the authentication mechanism must upgrade from 0.64.3 or later.\n\n### Workarounds\n\nA user can manually upgrade the `armeria-saml` module with the one from Armeria 1.27.2 or later, either by replacing the JAR in the Central Dogma distribution or by updating the dependency tree of the build.\n\n### References\n\n[`SamlMessageUtil.validateSignature()`](https://github.com/line/armeria/blob/0efc776988d71be4da6e506ec8a33c2b7b43f567/saml/src/main/java/com/linecorp/armeria/server/saml/SamlMessageUtil.java#L160-L163)",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
}
],
"affected": [
{
"package": {
"ecosystem": "Maven",
"name": "com.linecorp.centraldogma:centraldogma-server-auth-saml"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "0.64.3"
}
]
}
],
"database_specific": {
"last_known_affected_version_range": "<= 0.64.2"
}
}
],
"references": [
{
"type": "WEB",
"url": "https://github.com/line/armeria/security/advisories/GHSA-4m6j-23p2-8c54"
},
{
"type": "WEB",
"url": "https://github.com/line/centraldogma/security/advisories/GHSA-hx5q-v6pj-533r"
},
{
"type": "WEB",
"url": "https://github.com/line/centraldogma/commit/16903426be2e954c050b3ee47b8c38ee3218f0eb"
},
{
"type": "WEB",
"url": "https://github.com/line/centraldogma/commit/16903426be2e954c050b3ee47b8c38ee3218f0ebxz"
},
{
"type": "PACKAGE",
"url": "https://github.com/line/centraldogma"
},
{
"type": "WEB",
"url": "https://github.com/line/centraldogma/releases/tag/centraldogma-0.64.3"
}
],
"database_specific": {
"cwe_ids": [
"CWE-1395"
],
"severity": "CRITICAL",
"github_reviewed": true,
"github_reviewed_at": "2024-02-26T20:04:50Z",
"nvd_published_at": null
}
}
@@ -0,0 +1,62 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p4m5-32pr-2hqr",
"modified": "2024-02-26T20:04:19Z",
"published": "2024-02-26T20:04:19Z",
"aliases": [
],
"summary": "PyPop C extensions possible vulnerability: missing arguments and redundant null pointers",
"details": "### Impact\nCode scanning revealed possible vulnerability in C extensions for PyPop: incorrect function calls (missing arguments or wrongly typed arguments) and redundant null pointers.\n\n### Patches\nThe problem has been patched and fixed in the latest release of PyPop: 1.0.2. Please upgrade your PyPop installation via:\n\n```\npip install -U pypop-genomics\n```\n\n### Workarounds\nNo. Upgrade to the latest package: 1.0.2.\n\n### References\nN/A\n",
"severity": [
],
"affected": [
{
"package": {
"ecosystem": "PyPI",
"name": "pypop-genomics"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "1.0.2"
}
]
}
]
}
],
"references": [
{
"type": "WEB",
"url": "https://github.com/alexlancaster/pypop/security/advisories/GHSA-p4m5-32pr-2hqr"
},
{
"type": "WEB",
"url": "https://github.com/alexlancaster/pypop/commit/2e5c495dd7684f67f6682e80e324351039a28262"
},
{
"type": "PACKAGE",
"url": "https://github.com/alexlancaster/pypop"
},
{
"type": "WEB",
"url": "https://github.com/alexlancaster/pypop/releases/tag/v1.0.2"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "LOW",
"github_reviewed": true,
"github_reviewed_at": "2024-02-26T20:04:19Z",
"nvd_published_at": null
}
}