From 77b7f4e2bb688cd244a9a9b06e32274b56451250 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 13 Feb 2025 19:22:00 +0000 Subject: [PATCH] Publish Advisories GHSA-35c7-w35f-xwgh GHSA-666g-rfc5-c9jv GHSA-7fxm-f474-hf8w GHSA-99pc-69q9-jxf2 GHSA-crg9-44h2-xw35 GHSA-mp92-3jfm-3575 GHSA-q78c-gwqw-jcmc GHSA-x9w5-v3q2-3rhw GHSA-4vvc-r4p4-qgrr GHSA-5r8j-qmcm-7g7q GHSA-hm9r-7f84-25c9 GHSA-jjfh-589g-3hjx GHSA-r6cc-7wj7-gfx2 --- .../2023/10/GHSA-35c7-w35f-xwgh/GHSA-35c7-w35f-xwgh.json | 8 ++++++-- .../2023/10/GHSA-666g-rfc5-c9jv/GHSA-666g-rfc5-c9jv.json | 4 ++-- .../2023/10/GHSA-7fxm-f474-hf8w/GHSA-7fxm-f474-hf8w.json | 4 ++-- .../2023/10/GHSA-99pc-69q9-jxf2/GHSA-99pc-69q9-jxf2.json | 2 +- .../2023/10/GHSA-crg9-44h2-xw35/GHSA-crg9-44h2-xw35.json | 6 +++++- .../2023/10/GHSA-mp92-3jfm-3575/GHSA-mp92-3jfm-3575.json | 4 ++-- .../2023/10/GHSA-q78c-gwqw-jcmc/GHSA-q78c-gwqw-jcmc.json | 8 ++++++-- .../2023/10/GHSA-x9w5-v3q2-3rhw/GHSA-x9w5-v3q2-3rhw.json | 9 ++------- .../2023/11/GHSA-4vvc-r4p4-qgrr/GHSA-4vvc-r4p4-qgrr.json | 2 +- .../2023/11/GHSA-5r8j-qmcm-7g7q/GHSA-5r8j-qmcm-7g7q.json | 4 ++-- .../2023/11/GHSA-hm9r-7f84-25c9/GHSA-hm9r-7f84-25c9.json | 4 ++-- .../2023/11/GHSA-jjfh-589g-3hjx/GHSA-jjfh-589g-3hjx.json | 2 +- .../2023/11/GHSA-r6cc-7wj7-gfx2/GHSA-r6cc-7wj7-gfx2.json | 4 ++-- 13 files changed, 34 insertions(+), 27 deletions(-) diff --git a/advisories/github-reviewed/2023/10/GHSA-35c7-w35f-xwgh/GHSA-35c7-w35f-xwgh.json b/advisories/github-reviewed/2023/10/GHSA-35c7-w35f-xwgh/GHSA-35c7-w35f-xwgh.json index f78f4744f1e..ebba0da9b7a 100644 --- a/advisories/github-reviewed/2023/10/GHSA-35c7-w35f-xwgh/GHSA-35c7-w35f-xwgh.json +++ b/advisories/github-reviewed/2023/10/GHSA-35c7-w35f-xwgh/GHSA-35c7-w35f-xwgh.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-35c7-w35f-xwgh", - "modified": "2023-10-31T22:23:04Z", + "modified": "2025-02-13T19:20:48Z", "published": "2023-10-30T03:30:15Z", "aliases": [ "CVE-2021-25736" ], "summary": "Kube-proxy may unintentionally forward traffic", - "details": "Kube-proxy on Windows can unintentionally forward traffic to local processes listening on the same port (`spec.ports[*].port`) as a LoadBalancer Service when the LoadBalancer controller does not set the `status.loadBalancer.ingress[].ip` field. Clusters \nwhere the LoadBalancer controller sets the `status.loadBalancer.ingress[].ip` field are unaffected.\n\n", + "details": "Kube-proxy on Windows can unintentionally forward traffic to local processes listening on the same port (`spec.ports[*].port`) as a LoadBalancer Service when the LoadBalancer controller does not set the `status.loadBalancer.ingress[].ip` field. Clusters \nwhere the LoadBalancer controller sets the `status.loadBalancer.ingress[].ip` field are unaffected.", "severity": [ { "type": "CVSS_V3", @@ -55,6 +55,10 @@ { "type": "WEB", "url": "https://groups.google.com/g/kubernetes-security-announce/c/lIoOPObO51Q/m/O15LOazPAgAJ" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20231221-0003" } ], "database_specific": { diff --git a/advisories/github-reviewed/2023/10/GHSA-666g-rfc5-c9jv/GHSA-666g-rfc5-c9jv.json b/advisories/github-reviewed/2023/10/GHSA-666g-rfc5-c9jv/GHSA-666g-rfc5-c9jv.json index 88e94c78843..3c83274a9d3 100644 --- a/advisories/github-reviewed/2023/10/GHSA-666g-rfc5-c9jv/GHSA-666g-rfc5-c9jv.json +++ b/advisories/github-reviewed/2023/10/GHSA-666g-rfc5-c9jv/GHSA-666g-rfc5-c9jv.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-666g-rfc5-c9jv", - "modified": "2023-11-08T14:33:34Z", + "modified": "2025-02-13T19:20:39Z", "published": "2023-10-28T09:30:44Z", "aliases": [ "CVE-2023-46215" ], "summary": "Apache Airflow Celery provider Insertion of Sensitive Information into Log File vulnerability", - "details": "Insertion of Sensitive Information into Log File vulnerability in Apache Airflow Celery provider, Apache Airflow.\n\nSensitive information logged as clear text when rediss, amqp, rpc protocols are used as Celery result backend\nNote: the vulnerability is about the information exposed in the logs not about accessing the logs.\n\nThis issue affects Apache Airflow Celery provider: from 3.3.0 through 3.4.0; Apache Airflow: from 1.10.0 through 2.6.3.\n\nUsers are recommended to upgrade Airflow Celery provider to version 3.4.1 and Apache Airlfow to version 2.7.0 which fixes the issue.\n\n", + "details": "Insertion of Sensitive Information into Log File vulnerability in Apache Airflow Celery provider, Apache Airflow.\n\nSensitive information logged as clear text when rediss, amqp, rpc protocols are used as Celery result backend\nNote: the vulnerability is about the information exposed in the logs not about accessing the logs.\n\nThis issue affects Apache Airflow Celery provider: from 3.3.0 through 3.4.0; Apache Airflow: from 1.10.0 through 2.6.3.\n\nUsers are recommended to upgrade Airflow Celery provider to version 3.4.1 and Apache Airlfow to version 2.7.0 which fixes the issue.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2023/10/GHSA-7fxm-f474-hf8w/GHSA-7fxm-f474-hf8w.json b/advisories/github-reviewed/2023/10/GHSA-7fxm-f474-hf8w/GHSA-7fxm-f474-hf8w.json index 30572463614..cf2dbba9265 100644 --- a/advisories/github-reviewed/2023/10/GHSA-7fxm-f474-hf8w/GHSA-7fxm-f474-hf8w.json +++ b/advisories/github-reviewed/2023/10/GHSA-7fxm-f474-hf8w/GHSA-7fxm-f474-hf8w.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-7fxm-f474-hf8w", - "modified": "2023-11-01T14:36:22Z", + "modified": "2025-02-13T19:20:54Z", "published": "2023-10-31T21:32:35Z", "aliases": [ "CVE-2023-3676" ], "summary": "Kubernetes privilege escalation vulnerability", - "details": "A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes.\n", + "details": "A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2023/10/GHSA-99pc-69q9-jxf2/GHSA-99pc-69q9-jxf2.json b/advisories/github-reviewed/2023/10/GHSA-99pc-69q9-jxf2/GHSA-99pc-69q9-jxf2.json index 24b507c39cc..4a0ff00071f 100644 --- a/advisories/github-reviewed/2023/10/GHSA-99pc-69q9-jxf2/GHSA-99pc-69q9-jxf2.json +++ b/advisories/github-reviewed/2023/10/GHSA-99pc-69q9-jxf2/GHSA-99pc-69q9-jxf2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-99pc-69q9-jxf2", - "modified": "2023-10-30T15:14:03Z", + "modified": "2025-02-13T19:19:40Z", "published": "2023-10-26T18:30:23Z", "aliases": [ "CVE-2023-31417" diff --git a/advisories/github-reviewed/2023/10/GHSA-crg9-44h2-xw35/GHSA-crg9-44h2-xw35.json b/advisories/github-reviewed/2023/10/GHSA-crg9-44h2-xw35/GHSA-crg9-44h2-xw35.json index 31012bc4f1f..f733b869432 100644 --- a/advisories/github-reviewed/2023/10/GHSA-crg9-44h2-xw35/GHSA-crg9-44h2-xw35.json +++ b/advisories/github-reviewed/2023/10/GHSA-crg9-44h2-xw35/GHSA-crg9-44h2-xw35.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-crg9-44h2-xw35", - "modified": "2025-02-12T15:30:15Z", + "modified": "2025-02-13T19:20:36Z", "published": "2023-10-27T15:30:20Z", "aliases": [ "CVE-2023-46604" @@ -233,6 +233,10 @@ "type": "WEB", "url": "http://packetstormsecurity.com/files/175676/Apache-ActiveMQ-Unauthenticated-Remote-Code-Execution.html" }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2024/Apr/18" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2023/10/27/5" diff --git a/advisories/github-reviewed/2023/10/GHSA-mp92-3jfm-3575/GHSA-mp92-3jfm-3575.json b/advisories/github-reviewed/2023/10/GHSA-mp92-3jfm-3575/GHSA-mp92-3jfm-3575.json index d177f7f5241..b871a2d0e21 100644 --- a/advisories/github-reviewed/2023/10/GHSA-mp92-3jfm-3575/GHSA-mp92-3jfm-3575.json +++ b/advisories/github-reviewed/2023/10/GHSA-mp92-3jfm-3575/GHSA-mp92-3jfm-3575.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-mp92-3jfm-3575", - "modified": "2023-10-31T20:29:49Z", + "modified": "2025-02-13T19:21:01Z", "published": "2023-10-31T20:29:49Z", "aliases": [ "CVE-2023-43796" ], "summary": "Synapse vulnerable to leak of remote user device information", - "details": "### Impact\nCached device information of remote users can be queried from Synapse. This can be used to enumerate the remote users known to a homeserver.\n\n### Patches\nSystem administrators are encouraged to upgrade to Synapse 1.95.1 as soon as possible.\n\n### Workarounds\nThe `federation_domain_whitelist` can be used to limit federation traffic with a homeserver.\n", + "details": "### Impact\nCached device information of remote users can be queried from Synapse. This can be used to enumerate the remote users known to a homeserver.\n\n### Patches\nSystem administrators are encouraged to upgrade to Synapse 1.95.1 as soon as possible.\n\n### Workarounds\nThe `federation_domain_whitelist` can be used to limit federation traffic with a homeserver.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2023/10/GHSA-q78c-gwqw-jcmc/GHSA-q78c-gwqw-jcmc.json b/advisories/github-reviewed/2023/10/GHSA-q78c-gwqw-jcmc/GHSA-q78c-gwqw-jcmc.json index 708e534ef92..db4f72fce71 100644 --- a/advisories/github-reviewed/2023/10/GHSA-q78c-gwqw-jcmc/GHSA-q78c-gwqw-jcmc.json +++ b/advisories/github-reviewed/2023/10/GHSA-q78c-gwqw-jcmc/GHSA-q78c-gwqw-jcmc.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-q78c-gwqw-jcmc", - "modified": "2023-11-01T17:16:38Z", + "modified": "2025-02-13T19:20:56Z", "published": "2023-10-31T21:32:35Z", "aliases": [ "CVE-2023-3955" ], "summary": "Kubernetes privilege escalation vulnerability", - "details": "A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes.\n", + "details": "A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes.", "severity": [ { "type": "CVSS_V3", @@ -174,6 +174,10 @@ { "type": "WEB", "url": "https://groups.google.com/g/kubernetes-security-announce/c/JrX4bb7d83E" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20231221-0002" } ], "database_specific": { diff --git a/advisories/github-reviewed/2023/10/GHSA-x9w5-v3q2-3rhw/GHSA-x9w5-v3q2-3rhw.json b/advisories/github-reviewed/2023/10/GHSA-x9w5-v3q2-3rhw/GHSA-x9w5-v3q2-3rhw.json index 58a83216011..4e8ce8fe1f6 100644 --- a/advisories/github-reviewed/2023/10/GHSA-x9w5-v3q2-3rhw/GHSA-x9w5-v3q2-3rhw.json +++ b/advisories/github-reviewed/2023/10/GHSA-x9w5-v3q2-3rhw/GHSA-x9w5-v3q2-3rhw.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-x9w5-v3q2-3rhw", - "modified": "2024-02-28T03:30:30Z", + "modified": "2025-02-13T19:19:37Z", "published": "2023-10-26T20:53:21Z", "aliases": [ "CVE-2023-46234" ], "summary": "browserify-sign upper bound check issue in `dsaVerify` leads to a signature forgery attack", - "details": "### Summary\nAn upper bound check issue in `dsaVerify` function allows an attacker to construct signatures that can be successfully verified by any public key, thus leading to a signature forgery attack.\n\n### Details\nIn `dsaVerify` function, it checks whether the value of the signature is legal by calling function `checkValue`, namely, whether `r` and `s` are both in the interval `[1, q - 1]`. However, the second line of the `checkValue` function wrongly checks the upper bound of the passed parameters, since the value of `b.cmp(q)` can only be `0`, `1` and `-1`, and it can never be greater than `q`. \n\nIn this way, although the values of `s` cannot be `0`, an attacker can achieve the same effect as zero by setting its value to `q`, and then send `(r, s) = (1, q)` to pass the verification of any public key.\n\n### Impact\nAll places in this project that involve DSA verification of user-input signatures will be affected by this vulnerability.\n\n\n### Fix PR:\nSince the temporary private fork was deleted, here's a webarchive of the PR discussion and diff pages: [PR webarchive.zip](https://github.com/browserify/browserify-sign/files/13172957/PR.webarchive.zip)\n", + "details": "### Summary\nAn upper bound check issue in `dsaVerify` function allows an attacker to construct signatures that can be successfully verified by any public key, thus leading to a signature forgery attack.\n\n### Details\nIn `dsaVerify` function, it checks whether the value of the signature is legal by calling function `checkValue`, namely, whether `r` and `s` are both in the interval `[1, q - 1]`. However, the second line of the `checkValue` function wrongly checks the upper bound of the passed parameters, since the value of `b.cmp(q)` can only be `0`, `1` and `-1`, and it can never be greater than `q`. \n\nIn this way, although the values of `s` cannot be `0`, an attacker can achieve the same effect as zero by setting its value to `q`, and then send `(r, s) = (1, q)` to pass the verification of any public key.\n\n### Impact\nAll places in this project that involve DSA verification of user-input signatures will be affected by this vulnerability.\n\n\n### Fix PR:\nSince the temporary private fork was deleted, here's a webarchive of the PR discussion and diff pages: [PR webarchive.zip](https://github.com/browserify/browserify-sign/files/13172957/PR.webarchive.zip)", "severity": [ { "type": "CVSS_V3", @@ -20,11 +20,6 @@ "ecosystem": "npm", "name": "browserify-sign" }, - "ecosystem_specific": { - "affected_functions": [ - "(browserify-sign).Verify" - ] - }, "ranges": [ { "type": "ECOSYSTEM", diff --git a/advisories/github-reviewed/2023/11/GHSA-4vvc-r4p4-qgrr/GHSA-4vvc-r4p4-qgrr.json b/advisories/github-reviewed/2023/11/GHSA-4vvc-r4p4-qgrr/GHSA-4vvc-r4p4-qgrr.json index 99fe59c6cda..2a4b74c921b 100644 --- a/advisories/github-reviewed/2023/11/GHSA-4vvc-r4p4-qgrr/GHSA-4vvc-r4p4-qgrr.json +++ b/advisories/github-reviewed/2023/11/GHSA-4vvc-r4p4-qgrr/GHSA-4vvc-r4p4-qgrr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4vvc-r4p4-qgrr", - "modified": "2024-11-21T21:27:13Z", + "modified": "2025-02-13T19:21:06Z", "published": "2023-11-24T09:30:28Z", "aliases": [ "CVE-2023-48796" diff --git a/advisories/github-reviewed/2023/11/GHSA-5r8j-qmcm-7g7q/GHSA-5r8j-qmcm-7g7q.json b/advisories/github-reviewed/2023/11/GHSA-5r8j-qmcm-7g7q/GHSA-5r8j-qmcm-7g7q.json index 3efa3066056..3c25cfbe706 100644 --- a/advisories/github-reviewed/2023/11/GHSA-5r8j-qmcm-7g7q/GHSA-5r8j-qmcm-7g7q.json +++ b/advisories/github-reviewed/2023/11/GHSA-5r8j-qmcm-7g7q/GHSA-5r8j-qmcm-7g7q.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-5r8j-qmcm-7g7q", - "modified": "2023-11-16T19:58:31Z", + "modified": "2025-02-13T19:20:43Z", "published": "2023-11-08T09:30:25Z", "aliases": [ "CVE-2023-39913" ], "summary": "Apache UIMA Java SDK Deserialization of Untrusted Data, Improper Input Validation vulnerability", - "details": "Deserialization of Untrusted Data, Improper Input Validation vulnerability in Apache UIMA Java SDK. This issue affects Apache UIMA Java SDK before 3.5.0.\n\nUsers are recommended to upgrade to version 3.5.0, which fixes the issue.\n\nThere are several locations in the code where serialized Java objects are deserialized without verifying the data. This affects in particular:\n * the deserialization of a Java-serialized CAS, but also other binary CAS formats that include TSI information using the CasIOUtils class;\n * the CAS Editor Eclipse plugin which uses the the CasIOUtils class to load data;\n * the deserialization of a Java-serialized CAS of the Vinci Analysis Engine service which can receive using Java-serialized CAS objects over network connections;\n * the CasAnnotationViewerApplet and the CasTreeViewerApplet;\n * the checkpointing feature of the CPE module.\n\nNote that the UIMA framework by default does not start any remotely accessible services (i.e. Vinci) that would be vulnerable to this issue. A user or developer would need to make an active choice to start such a service. However, users or developers may use the CasIOUtils in their own applications and services to parse serialized CAS data. They are affected by this issue unless they ensure that the data passed to CasIOUtils is not a serialized Java object.\n\nWhen using Vinci or using CasIOUtils in own services/applications, the unrestricted deserialization of Java-serialized CAS files may allow arbitrary (remote) code execution.\n\nAs a remedy, it is possible to set up a global or context-specific ObjectInputFilter (cf. https://openjdk.org/jeps/290  and  https://openjdk.org/jeps/415 ) if running UIMA on a Java version that supports it. \n\nNote that Java 1.8 does not support the ObjectInputFilter, so there is no remedy when running on this out-of-support platform. An upgrade to a recent Java version is strongly recommended if you need to secure an UIMA version that is affected by this issue.\n\nTo mitigate the issue on a Java 9+ platform, you can configure a filter pattern through the \"jdk.serialFilter\" system property using a semicolon as a separator:\n\nTo allow deserializing Java-serialized binary CASes, add the classes:\n * org.apache.uima.cas.impl.CASCompleteSerializer\n * org.apache.uima.cas.impl.CASMgrSerializer\n * org.apache.uima.cas.impl.CASSerializer\n * java.lang.String\n\nTo allow deserializing CPE Checkpoint data, add the following classes (and any custom classes your application uses to store its checkpoints):\n * org.apache.uima.collection.impl.cpm.CheckpointData\n * org.apache.uima.util.ProcessTrace\n * org.apache.uima.util.impl.ProcessTrace_impl\n * org.apache.uima.collection.base_cpm.SynchPoint\n\nMake sure to use \"!*\" as the final component to the filter pattern to disallow deserialization of any classes not listed in the pattern.\n\nApache UIMA 3.5.0 uses tightly scoped ObjectInputFilters when reading Java-serialized data depending on the type of data being expected. Configuring a global filter is not necessary with this version.\n\n", + "details": "Deserialization of Untrusted Data, Improper Input Validation vulnerability in Apache UIMA Java SDK. This issue affects Apache UIMA Java SDK before 3.5.0.\n\nUsers are recommended to upgrade to version 3.5.0, which fixes the issue.\n\nThere are several locations in the code where serialized Java objects are deserialized without verifying the data. This affects in particular:\n * the deserialization of a Java-serialized CAS, but also other binary CAS formats that include TSI information using the CasIOUtils class;\n * the CAS Editor Eclipse plugin which uses the the CasIOUtils class to load data;\n * the deserialization of a Java-serialized CAS of the Vinci Analysis Engine service which can receive using Java-serialized CAS objects over network connections;\n * the CasAnnotationViewerApplet and the CasTreeViewerApplet;\n * the checkpointing feature of the CPE module.\n\nNote that the UIMA framework by default does not start any remotely accessible services (i.e. Vinci) that would be vulnerable to this issue. A user or developer would need to make an active choice to start such a service. However, users or developers may use the CasIOUtils in their own applications and services to parse serialized CAS data. They are affected by this issue unless they ensure that the data passed to CasIOUtils is not a serialized Java object.\n\nWhen using Vinci or using CasIOUtils in own services/applications, the unrestricted deserialization of Java-serialized CAS files may allow arbitrary (remote) code execution.\n\nAs a remedy, it is possible to set up a global or context-specific ObjectInputFilter (cf. https://openjdk.org/jeps/290  and  https://openjdk.org/jeps/415 ) if running UIMA on a Java version that supports it. \n\nNote that Java 1.8 does not support the ObjectInputFilter, so there is no remedy when running on this out-of-support platform. An upgrade to a recent Java version is strongly recommended if you need to secure an UIMA version that is affected by this issue.\n\nTo mitigate the issue on a Java 9+ platform, you can configure a filter pattern through the \"jdk.serialFilter\" system property using a semicolon as a separator:\n\nTo allow deserializing Java-serialized binary CASes, add the classes:\n * org.apache.uima.cas.impl.CASCompleteSerializer\n * org.apache.uima.cas.impl.CASMgrSerializer\n * org.apache.uima.cas.impl.CASSerializer\n * java.lang.String\n\nTo allow deserializing CPE Checkpoint data, add the following classes (and any custom classes your application uses to store its checkpoints):\n * org.apache.uima.collection.impl.cpm.CheckpointData\n * org.apache.uima.util.ProcessTrace\n * org.apache.uima.util.impl.ProcessTrace_impl\n * org.apache.uima.collection.base_cpm.SynchPoint\n\nMake sure to use \"!*\" as the final component to the filter pattern to disallow deserialization of any classes not listed in the pattern.\n\nApache UIMA 3.5.0 uses tightly scoped ObjectInputFilters when reading Java-serialized data depending on the type of data being expected. Configuring a global filter is not necessary with this version.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2023/11/GHSA-hm9r-7f84-25c9/GHSA-hm9r-7f84-25c9.json b/advisories/github-reviewed/2023/11/GHSA-hm9r-7f84-25c9/GHSA-hm9r-7f84-25c9.json index 387233ca9e2..ff8987e9ca9 100644 --- a/advisories/github-reviewed/2023/11/GHSA-hm9r-7f84-25c9/GHSA-hm9r-7f84-25c9.json +++ b/advisories/github-reviewed/2023/11/GHSA-hm9r-7f84-25c9/GHSA-hm9r-7f84-25c9.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-hm9r-7f84-25c9", - "modified": "2024-09-12T20:19:58Z", + "modified": "2025-02-13T19:21:05Z", "published": "2023-11-12T15:30:20Z", "aliases": [ "CVE-2023-47037" ], "summary": "Apache Airflow allows authenticated and DAG-view authorized users to modify some DAG run detail values when submitting notes", - "details": "Apache Airflow, versions before 2.7.3, is affected by a vulnerability that allows authenticated and DAG-view authorized Users to modify some DAG run detail values when submitting notes. This could have them alter details such as configuration parameters, start date, etc.  Users should upgrade to version 2.7.3 or later which has removed the vulnerability.\n", + "details": "Apache Airflow, versions before 2.7.3, is affected by a vulnerability that allows authenticated and DAG-view authorized Users to modify some DAG run detail values when submitting notes. This could have them alter details such as configuration parameters, start date, etc.  Users should upgrade to version 2.7.3 or later which has removed the vulnerability.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2023/11/GHSA-jjfh-589g-3hjx/GHSA-jjfh-589g-3hjx.json b/advisories/github-reviewed/2023/11/GHSA-jjfh-589g-3hjx/GHSA-jjfh-589g-3hjx.json index 704b9d7e109..b249ec4897f 100644 --- a/advisories/github-reviewed/2023/11/GHSA-jjfh-589g-3hjx/GHSA-jjfh-589g-3hjx.json +++ b/advisories/github-reviewed/2023/11/GHSA-jjfh-589g-3hjx/GHSA-jjfh-589g-3hjx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jjfh-589g-3hjx", - "modified": "2024-07-09T15:05:48Z", + "modified": "2025-02-13T19:20:46Z", "published": "2023-11-28T09:30:27Z", "aliases": [ "CVE-2023-34055" diff --git a/advisories/github-reviewed/2023/11/GHSA-r6cc-7wj7-gfx2/GHSA-r6cc-7wj7-gfx2.json b/advisories/github-reviewed/2023/11/GHSA-r6cc-7wj7-gfx2/GHSA-r6cc-7wj7-gfx2.json index 9ffd4b10eee..9f417f072b0 100644 --- a/advisories/github-reviewed/2023/11/GHSA-r6cc-7wj7-gfx2/GHSA-r6cc-7wj7-gfx2.json +++ b/advisories/github-reviewed/2023/11/GHSA-r6cc-7wj7-gfx2/GHSA-r6cc-7wj7-gfx2.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-r6cc-7wj7-gfx2", - "modified": "2023-11-03T20:42:49Z", + "modified": "2025-02-13T19:20:58Z", "published": "2023-11-03T18:30:24Z", "aliases": [ "CVE-2023-3893" ], "summary": "Kubernetes csi-proxy vulnerable to privilege escalation due to improper input validation", - "details": "Kubernetes is vulnerable to privilege escalation when a user that can create pods on Windows nodes running kubernetes-csi-proxy may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes running kubernetes-csi-proxy.\n", + "details": "Kubernetes is vulnerable to privilege escalation when a user that can create pods on Windows nodes running kubernetes-csi-proxy may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes running kubernetes-csi-proxy.", "severity": [ { "type": "CVSS_V3",