mirror of
https://github.com/netbirdio/advisory-database.git
synced 2026-05-22 18:04:22 -07:00
Publish Advisories
GHSA-35c7-w35f-xwgh GHSA-666g-rfc5-c9jv GHSA-7fxm-f474-hf8w GHSA-99pc-69q9-jxf2 GHSA-crg9-44h2-xw35 GHSA-mp92-3jfm-3575 GHSA-q78c-gwqw-jcmc GHSA-x9w5-v3q2-3rhw GHSA-4vvc-r4p4-qgrr GHSA-5r8j-qmcm-7g7q GHSA-hm9r-7f84-25c9 GHSA-jjfh-589g-3hjx GHSA-r6cc-7wj7-gfx2
This commit is contained in:
@@ -1,13 +1,13 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-35c7-w35f-xwgh",
|
||||
"modified": "2023-10-31T22:23:04Z",
|
||||
"modified": "2025-02-13T19:20:48Z",
|
||||
"published": "2023-10-30T03:30:15Z",
|
||||
"aliases": [
|
||||
"CVE-2021-25736"
|
||||
],
|
||||
"summary": "Kube-proxy may unintentionally forward traffic",
|
||||
"details": "Kube-proxy on Windows can unintentionally forward traffic to local processes listening on the same port (`spec.ports[*].port`) as a LoadBalancer Service when the LoadBalancer controller does not set the `status.loadBalancer.ingress[].ip` field. Clusters \nwhere the LoadBalancer controller sets the `status.loadBalancer.ingress[].ip` field are unaffected.\n\n",
|
||||
"details": "Kube-proxy on Windows can unintentionally forward traffic to local processes listening on the same port (`spec.ports[*].port`) as a LoadBalancer Service when the LoadBalancer controller does not set the `status.loadBalancer.ingress[].ip` field. Clusters \nwhere the LoadBalancer controller sets the `status.loadBalancer.ingress[].ip` field are unaffected.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
@@ -55,6 +55,10 @@
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://groups.google.com/g/kubernetes-security-announce/c/lIoOPObO51Q/m/O15LOazPAgAJ"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.netapp.com/advisory/ntap-20231221-0003"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
|
||||
@@ -1,13 +1,13 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-666g-rfc5-c9jv",
|
||||
"modified": "2023-11-08T14:33:34Z",
|
||||
"modified": "2025-02-13T19:20:39Z",
|
||||
"published": "2023-10-28T09:30:44Z",
|
||||
"aliases": [
|
||||
"CVE-2023-46215"
|
||||
],
|
||||
"summary": "Apache Airflow Celery provider Insertion of Sensitive Information into Log File vulnerability",
|
||||
"details": "Insertion of Sensitive Information into Log File vulnerability in Apache Airflow Celery provider, Apache Airflow.\n\nSensitive information logged as clear text when rediss, amqp, rpc protocols are used as Celery result backend\nNote: the vulnerability is about the information exposed in the logs not about accessing the logs.\n\nThis issue affects Apache Airflow Celery provider: from 3.3.0 through 3.4.0; Apache Airflow: from 1.10.0 through 2.6.3.\n\nUsers are recommended to upgrade Airflow Celery provider to version 3.4.1 and Apache Airlfow to version 2.7.0 which fixes the issue.\n\n",
|
||||
"details": "Insertion of Sensitive Information into Log File vulnerability in Apache Airflow Celery provider, Apache Airflow.\n\nSensitive information logged as clear text when rediss, amqp, rpc protocols are used as Celery result backend\nNote: the vulnerability is about the information exposed in the logs not about accessing the logs.\n\nThis issue affects Apache Airflow Celery provider: from 3.3.0 through 3.4.0; Apache Airflow: from 1.10.0 through 2.6.3.\n\nUsers are recommended to upgrade Airflow Celery provider to version 3.4.1 and Apache Airlfow to version 2.7.0 which fixes the issue.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
|
||||
@@ -1,13 +1,13 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-7fxm-f474-hf8w",
|
||||
"modified": "2023-11-01T14:36:22Z",
|
||||
"modified": "2025-02-13T19:20:54Z",
|
||||
"published": "2023-10-31T21:32:35Z",
|
||||
"aliases": [
|
||||
"CVE-2023-3676"
|
||||
],
|
||||
"summary": "Kubernetes privilege escalation vulnerability",
|
||||
"details": "A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes.\n",
|
||||
"details": "A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-99pc-69q9-jxf2",
|
||||
"modified": "2023-10-30T15:14:03Z",
|
||||
"modified": "2025-02-13T19:19:40Z",
|
||||
"published": "2023-10-26T18:30:23Z",
|
||||
"aliases": [
|
||||
"CVE-2023-31417"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-crg9-44h2-xw35",
|
||||
"modified": "2025-02-12T15:30:15Z",
|
||||
"modified": "2025-02-13T19:20:36Z",
|
||||
"published": "2023-10-27T15:30:20Z",
|
||||
"aliases": [
|
||||
"CVE-2023-46604"
|
||||
@@ -233,6 +233,10 @@
|
||||
"type": "WEB",
|
||||
"url": "http://packetstormsecurity.com/files/175676/Apache-ActiveMQ-Unauthenticated-Remote-Code-Execution.html"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://seclists.org/fulldisclosure/2024/Apr/18"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://www.openwall.com/lists/oss-security/2023/10/27/5"
|
||||
|
||||
@@ -1,13 +1,13 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-mp92-3jfm-3575",
|
||||
"modified": "2023-10-31T20:29:49Z",
|
||||
"modified": "2025-02-13T19:21:01Z",
|
||||
"published": "2023-10-31T20:29:49Z",
|
||||
"aliases": [
|
||||
"CVE-2023-43796"
|
||||
],
|
||||
"summary": "Synapse vulnerable to leak of remote user device information",
|
||||
"details": "### Impact\nCached device information of remote users can be queried from Synapse. This can be used to enumerate the remote users known to a homeserver.\n\n### Patches\nSystem administrators are encouraged to upgrade to Synapse 1.95.1 as soon as possible.\n\n### Workarounds\nThe `federation_domain_whitelist` can be used to limit federation traffic with a homeserver.\n",
|
||||
"details": "### Impact\nCached device information of remote users can be queried from Synapse. This can be used to enumerate the remote users known to a homeserver.\n\n### Patches\nSystem administrators are encouraged to upgrade to Synapse 1.95.1 as soon as possible.\n\n### Workarounds\nThe `federation_domain_whitelist` can be used to limit federation traffic with a homeserver.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
|
||||
@@ -1,13 +1,13 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-q78c-gwqw-jcmc",
|
||||
"modified": "2023-11-01T17:16:38Z",
|
||||
"modified": "2025-02-13T19:20:56Z",
|
||||
"published": "2023-10-31T21:32:35Z",
|
||||
"aliases": [
|
||||
"CVE-2023-3955"
|
||||
],
|
||||
"summary": "Kubernetes privilege escalation vulnerability",
|
||||
"details": "A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes.\n",
|
||||
"details": "A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
@@ -174,6 +174,10 @@
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://groups.google.com/g/kubernetes-security-announce/c/JrX4bb7d83E"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.netapp.com/advisory/ntap-20231221-0002"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
|
||||
@@ -1,13 +1,13 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-x9w5-v3q2-3rhw",
|
||||
"modified": "2024-02-28T03:30:30Z",
|
||||
"modified": "2025-02-13T19:19:37Z",
|
||||
"published": "2023-10-26T20:53:21Z",
|
||||
"aliases": [
|
||||
"CVE-2023-46234"
|
||||
],
|
||||
"summary": "browserify-sign upper bound check issue in `dsaVerify` leads to a signature forgery attack",
|
||||
"details": "### Summary\nAn upper bound check issue in `dsaVerify` function allows an attacker to construct signatures that can be successfully verified by any public key, thus leading to a signature forgery attack.\n\n### Details\nIn `dsaVerify` function, it checks whether the value of the signature is legal by calling function `checkValue`, namely, whether `r` and `s` are both in the interval `[1, q - 1]`. However, the second line of the `checkValue` function wrongly checks the upper bound of the passed parameters, since the value of `b.cmp(q)` can only be `0`, `1` and `-1`, and it can never be greater than `q`. \n\nIn this way, although the values of `s` cannot be `0`, an attacker can achieve the same effect as zero by setting its value to `q`, and then send `(r, s) = (1, q)` to pass the verification of any public key.\n\n### Impact\nAll places in this project that involve DSA verification of user-input signatures will be affected by this vulnerability.\n\n\n### Fix PR:\nSince the temporary private fork was deleted, here's a webarchive of the PR discussion and diff pages: [PR webarchive.zip](https://github.com/browserify/browserify-sign/files/13172957/PR.webarchive.zip)\n",
|
||||
"details": "### Summary\nAn upper bound check issue in `dsaVerify` function allows an attacker to construct signatures that can be successfully verified by any public key, thus leading to a signature forgery attack.\n\n### Details\nIn `dsaVerify` function, it checks whether the value of the signature is legal by calling function `checkValue`, namely, whether `r` and `s` are both in the interval `[1, q - 1]`. However, the second line of the `checkValue` function wrongly checks the upper bound of the passed parameters, since the value of `b.cmp(q)` can only be `0`, `1` and `-1`, and it can never be greater than `q`. \n\nIn this way, although the values of `s` cannot be `0`, an attacker can achieve the same effect as zero by setting its value to `q`, and then send `(r, s) = (1, q)` to pass the verification of any public key.\n\n### Impact\nAll places in this project that involve DSA verification of user-input signatures will be affected by this vulnerability.\n\n\n### Fix PR:\nSince the temporary private fork was deleted, here's a webarchive of the PR discussion and diff pages: [PR webarchive.zip](https://github.com/browserify/browserify-sign/files/13172957/PR.webarchive.zip)",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
@@ -20,11 +20,6 @@
|
||||
"ecosystem": "npm",
|
||||
"name": "browserify-sign"
|
||||
},
|
||||
"ecosystem_specific": {
|
||||
"affected_functions": [
|
||||
"(browserify-sign).Verify"
|
||||
]
|
||||
},
|
||||
"ranges": [
|
||||
{
|
||||
"type": "ECOSYSTEM",
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-4vvc-r4p4-qgrr",
|
||||
"modified": "2024-11-21T21:27:13Z",
|
||||
"modified": "2025-02-13T19:21:06Z",
|
||||
"published": "2023-11-24T09:30:28Z",
|
||||
"aliases": [
|
||||
"CVE-2023-48796"
|
||||
|
||||
File diff suppressed because one or more lines are too long
@@ -1,13 +1,13 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-hm9r-7f84-25c9",
|
||||
"modified": "2024-09-12T20:19:58Z",
|
||||
"modified": "2025-02-13T19:21:05Z",
|
||||
"published": "2023-11-12T15:30:20Z",
|
||||
"aliases": [
|
||||
"CVE-2023-47037"
|
||||
],
|
||||
"summary": "Apache Airflow allows authenticated and DAG-view authorized users to modify some DAG run detail values when submitting notes",
|
||||
"details": "Apache Airflow, versions before 2.7.3, is affected by a vulnerability that allows authenticated and DAG-view authorized Users to modify some DAG run detail values when submitting notes. This could have them alter details such as configuration parameters, start date, etc. Users should upgrade to version 2.7.3 or later which has removed the vulnerability.\n",
|
||||
"details": "Apache Airflow, versions before 2.7.3, is affected by a vulnerability that allows authenticated and DAG-view authorized Users to modify some DAG run detail values when submitting notes. This could have them alter details such as configuration parameters, start date, etc. Users should upgrade to version 2.7.3 or later which has removed the vulnerability.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-jjfh-589g-3hjx",
|
||||
"modified": "2024-07-09T15:05:48Z",
|
||||
"modified": "2025-02-13T19:20:46Z",
|
||||
"published": "2023-11-28T09:30:27Z",
|
||||
"aliases": [
|
||||
"CVE-2023-34055"
|
||||
|
||||
@@ -1,13 +1,13 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-r6cc-7wj7-gfx2",
|
||||
"modified": "2023-11-03T20:42:49Z",
|
||||
"modified": "2025-02-13T19:20:58Z",
|
||||
"published": "2023-11-03T18:30:24Z",
|
||||
"aliases": [
|
||||
"CVE-2023-3893"
|
||||
],
|
||||
"summary": "Kubernetes csi-proxy vulnerable to privilege escalation due to improper input validation",
|
||||
"details": "Kubernetes is vulnerable to privilege escalation when a user that can create pods on Windows nodes running kubernetes-csi-proxy may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes running kubernetes-csi-proxy.\n",
|
||||
"details": "Kubernetes is vulnerable to privilege escalation when a user that can create pods on Windows nodes running kubernetes-csi-proxy may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes running kubernetes-csi-proxy.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
|
||||
Reference in New Issue
Block a user