Publish Advisories

GHSA-35c7-w35f-xwgh
GHSA-666g-rfc5-c9jv
GHSA-7fxm-f474-hf8w
GHSA-99pc-69q9-jxf2
GHSA-crg9-44h2-xw35
GHSA-mp92-3jfm-3575
GHSA-q78c-gwqw-jcmc
GHSA-x9w5-v3q2-3rhw
GHSA-4vvc-r4p4-qgrr
GHSA-5r8j-qmcm-7g7q
GHSA-hm9r-7f84-25c9
GHSA-jjfh-589g-3hjx
GHSA-r6cc-7wj7-gfx2
This commit is contained in:
advisory-database[bot]
2025-02-13 19:22:00 +00:00
parent f481bf88c7
commit 77b7f4e2bb
13 changed files with 34 additions and 27 deletions
@@ -1,13 +1,13 @@
{
"schema_version": "1.4.0",
"id": "GHSA-35c7-w35f-xwgh",
"modified": "2023-10-31T22:23:04Z",
"modified": "2025-02-13T19:20:48Z",
"published": "2023-10-30T03:30:15Z",
"aliases": [
"CVE-2021-25736"
],
"summary": "Kube-proxy may unintentionally forward traffic",
"details": "Kube-proxy on Windows can unintentionally forward traffic to local processes listening on the same port (`spec.ports[*].port`) as a LoadBalancer Service when the LoadBalancer controller does not set the `status.loadBalancer.ingress[].ip` field. Clusters \nwhere the LoadBalancer controller sets the `status.loadBalancer.ingress[].ip` field are unaffected.\n\n",
"details": "Kube-proxy on Windows can unintentionally forward traffic to local processes listening on the same port (`spec.ports[*].port`) as a LoadBalancer Service when the LoadBalancer controller does not set the `status.loadBalancer.ingress[].ip` field. Clusters \nwhere the LoadBalancer controller sets the `status.loadBalancer.ingress[].ip` field are unaffected.",
"severity": [
{
"type": "CVSS_V3",
@@ -55,6 +55,10 @@
{
"type": "WEB",
"url": "https://groups.google.com/g/kubernetes-security-announce/c/lIoOPObO51Q/m/O15LOazPAgAJ"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20231221-0003"
}
],
"database_specific": {
@@ -1,13 +1,13 @@
{
"schema_version": "1.4.0",
"id": "GHSA-666g-rfc5-c9jv",
"modified": "2023-11-08T14:33:34Z",
"modified": "2025-02-13T19:20:39Z",
"published": "2023-10-28T09:30:44Z",
"aliases": [
"CVE-2023-46215"
],
"summary": "Apache Airflow Celery provider Insertion of Sensitive Information into Log File vulnerability",
"details": "Insertion of Sensitive Information into Log File vulnerability in Apache Airflow Celery provider, Apache Airflow.\n\nSensitive information logged as clear text when rediss, amqp, rpc protocols are used as Celery result backend\nNote: the vulnerability is about the information exposed in the logs not about accessing the logs.\n\nThis issue affects Apache Airflow Celery provider: from 3.3.0 through 3.4.0; Apache Airflow: from 1.10.0 through 2.6.3.\n\nUsers are recommended to upgrade Airflow Celery provider to version 3.4.1 and Apache Airlfow to version 2.7.0 which fixes the issue.\n\n",
"details": "Insertion of Sensitive Information into Log File vulnerability in Apache Airflow Celery provider, Apache Airflow.\n\nSensitive information logged as clear text when rediss, amqp, rpc protocols are used as Celery result backend\nNote: the vulnerability is about the information exposed in the logs not about accessing the logs.\n\nThis issue affects Apache Airflow Celery provider: from 3.3.0 through 3.4.0; Apache Airflow: from 1.10.0 through 2.6.3.\n\nUsers are recommended to upgrade Airflow Celery provider to version 3.4.1 and Apache Airlfow to version 2.7.0 which fixes the issue.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,13 +1,13 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7fxm-f474-hf8w",
"modified": "2023-11-01T14:36:22Z",
"modified": "2025-02-13T19:20:54Z",
"published": "2023-10-31T21:32:35Z",
"aliases": [
"CVE-2023-3676"
],
"summary": "Kubernetes privilege escalation vulnerability",
"details": "A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes.\n",
"details": "A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-99pc-69q9-jxf2",
"modified": "2023-10-30T15:14:03Z",
"modified": "2025-02-13T19:19:40Z",
"published": "2023-10-26T18:30:23Z",
"aliases": [
"CVE-2023-31417"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-crg9-44h2-xw35",
"modified": "2025-02-12T15:30:15Z",
"modified": "2025-02-13T19:20:36Z",
"published": "2023-10-27T15:30:20Z",
"aliases": [
"CVE-2023-46604"
@@ -233,6 +233,10 @@
"type": "WEB",
"url": "http://packetstormsecurity.com/files/175676/Apache-ActiveMQ-Unauthenticated-Remote-Code-Execution.html"
},
{
"type": "WEB",
"url": "http://seclists.org/fulldisclosure/2024/Apr/18"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2023/10/27/5"
@@ -1,13 +1,13 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mp92-3jfm-3575",
"modified": "2023-10-31T20:29:49Z",
"modified": "2025-02-13T19:21:01Z",
"published": "2023-10-31T20:29:49Z",
"aliases": [
"CVE-2023-43796"
],
"summary": "Synapse vulnerable to leak of remote user device information",
"details": "### Impact\nCached device information of remote users can be queried from Synapse. This can be used to enumerate the remote users known to a homeserver.\n\n### Patches\nSystem administrators are encouraged to upgrade to Synapse 1.95.1 as soon as possible.\n\n### Workarounds\nThe `federation_domain_whitelist` can be used to limit federation traffic with a homeserver.\n",
"details": "### Impact\nCached device information of remote users can be queried from Synapse. This can be used to enumerate the remote users known to a homeserver.\n\n### Patches\nSystem administrators are encouraged to upgrade to Synapse 1.95.1 as soon as possible.\n\n### Workarounds\nThe `federation_domain_whitelist` can be used to limit federation traffic with a homeserver.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,13 +1,13 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q78c-gwqw-jcmc",
"modified": "2023-11-01T17:16:38Z",
"modified": "2025-02-13T19:20:56Z",
"published": "2023-10-31T21:32:35Z",
"aliases": [
"CVE-2023-3955"
],
"summary": "Kubernetes privilege escalation vulnerability",
"details": "A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes.\n",
"details": "A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes.",
"severity": [
{
"type": "CVSS_V3",
@@ -174,6 +174,10 @@
{
"type": "WEB",
"url": "https://groups.google.com/g/kubernetes-security-announce/c/JrX4bb7d83E"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20231221-0002"
}
],
"database_specific": {
@@ -1,13 +1,13 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x9w5-v3q2-3rhw",
"modified": "2024-02-28T03:30:30Z",
"modified": "2025-02-13T19:19:37Z",
"published": "2023-10-26T20:53:21Z",
"aliases": [
"CVE-2023-46234"
],
"summary": "browserify-sign upper bound check issue in `dsaVerify` leads to a signature forgery attack",
"details": "### Summary\nAn upper bound check issue in `dsaVerify` function allows an attacker to construct signatures that can be successfully verified by any public key, thus leading to a signature forgery attack.\n\n### Details\nIn `dsaVerify` function, it checks whether the value of the signature is legal by calling function `checkValue`, namely, whether `r` and `s` are both in the interval `[1, q - 1]`. However, the second line of the `checkValue` function wrongly checks the upper bound of the passed parameters, since the value of `b.cmp(q)` can only be `0`, `1` and `-1`, and it can never be greater than `q`. \n\nIn this way, although the values of `s` cannot be `0`, an attacker can achieve the same effect as zero by setting its value to `q`, and then send `(r, s) = (1, q)` to pass the verification of any public key.\n\n### Impact\nAll places in this project that involve DSA verification of user-input signatures will be affected by this vulnerability.\n\n\n### Fix PR:\nSince the temporary private fork was deleted, here's a webarchive of the PR discussion and diff pages: [PR webarchive.zip](https://github.com/browserify/browserify-sign/files/13172957/PR.webarchive.zip)\n",
"details": "### Summary\nAn upper bound check issue in `dsaVerify` function allows an attacker to construct signatures that can be successfully verified by any public key, thus leading to a signature forgery attack.\n\n### Details\nIn `dsaVerify` function, it checks whether the value of the signature is legal by calling function `checkValue`, namely, whether `r` and `s` are both in the interval `[1, q - 1]`. However, the second line of the `checkValue` function wrongly checks the upper bound of the passed parameters, since the value of `b.cmp(q)` can only be `0`, `1` and `-1`, and it can never be greater than `q`. \n\nIn this way, although the values of `s` cannot be `0`, an attacker can achieve the same effect as zero by setting its value to `q`, and then send `(r, s) = (1, q)` to pass the verification of any public key.\n\n### Impact\nAll places in this project that involve DSA verification of user-input signatures will be affected by this vulnerability.\n\n\n### Fix PR:\nSince the temporary private fork was deleted, here's a webarchive of the PR discussion and diff pages: [PR webarchive.zip](https://github.com/browserify/browserify-sign/files/13172957/PR.webarchive.zip)",
"severity": [
{
"type": "CVSS_V3",
@@ -20,11 +20,6 @@
"ecosystem": "npm",
"name": "browserify-sign"
},
"ecosystem_specific": {
"affected_functions": [
"(browserify-sign).Verify"
]
},
"ranges": [
{
"type": "ECOSYSTEM",
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4vvc-r4p4-qgrr",
"modified": "2024-11-21T21:27:13Z",
"modified": "2025-02-13T19:21:06Z",
"published": "2023-11-24T09:30:28Z",
"aliases": [
"CVE-2023-48796"
File diff suppressed because one or more lines are too long
@@ -1,13 +1,13 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hm9r-7f84-25c9",
"modified": "2024-09-12T20:19:58Z",
"modified": "2025-02-13T19:21:05Z",
"published": "2023-11-12T15:30:20Z",
"aliases": [
"CVE-2023-47037"
],
"summary": "Apache Airflow allows authenticated and DAG-view authorized users to modify some DAG run detail values when submitting notes",
"details": "Apache Airflow, versions before 2.7.3, is affected by a vulnerability that allows authenticated and DAG-view authorized Users to modify some DAG run detail values when submitting notes. This could have them alter details such as configuration parameters, start date, etc.  Users should upgrade to version 2.7.3 or later which has removed the vulnerability.\n",
"details": "Apache Airflow, versions before 2.7.3, is affected by a vulnerability that allows authenticated and DAG-view authorized Users to modify some DAG run detail values when submitting notes. This could have them alter details such as configuration parameters, start date, etc.  Users should upgrade to version 2.7.3 or later which has removed the vulnerability.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jjfh-589g-3hjx",
"modified": "2024-07-09T15:05:48Z",
"modified": "2025-02-13T19:20:46Z",
"published": "2023-11-28T09:30:27Z",
"aliases": [
"CVE-2023-34055"
@@ -1,13 +1,13 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r6cc-7wj7-gfx2",
"modified": "2023-11-03T20:42:49Z",
"modified": "2025-02-13T19:20:58Z",
"published": "2023-11-03T18:30:24Z",
"aliases": [
"CVE-2023-3893"
],
"summary": "Kubernetes csi-proxy vulnerable to privilege escalation due to improper input validation",
"details": "Kubernetes is vulnerable to privilege escalation when a user that can create pods on Windows nodes running kubernetes-csi-proxy may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes running kubernetes-csi-proxy.\n",
"details": "Kubernetes is vulnerable to privilege escalation when a user that can create pods on Windows nodes running kubernetes-csi-proxy may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes running kubernetes-csi-proxy.",
"severity": [
{
"type": "CVSS_V3",