Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2024-12-01 05:17:36 +00:00
parent b979e4dca5
commit 7a03029e02
961 changed files with 1794 additions and 5382 deletions
@@ -3,9 +3,7 @@
"id": "GHSA-xm28-fw2x-fqv2",
"modified": "2021-08-04T21:19:17Z",
"published": "2019-05-31T23:08:14Z",
"aliases": [
],
"aliases": [],
"summary": "Denial of Service in foreman",
"details": "All versions of `foreman` are vulnerable to Regular Expression Denial of Service when requests to it are made with a specially crafted path.\n\n\n## Recommendation\n\nUpgrade to version 3.0.1.",
"severity": [
@@ -3,9 +3,7 @@
"id": "GHSA-xrmp-99wj-p6jc",
"modified": "2021-08-04T21:21:43Z",
"published": "2019-05-31T23:43:09Z",
"aliases": [
],
"aliases": [],
"summary": "Prototype Pollution in deap",
"details": "Versions of `deap` before 1.0.1 are vulnerable to prototype pollution.\n\n\n## Recommendation\n\nUpdate to version 1.0.1 or later.",
"severity": [
@@ -8,9 +8,7 @@
],
"summary": "Regular Expression Denial of Service (ReDoS) in lodash",
"details": "lodash prior to 4.7.11 is affected by: CWE-400: Uncontrolled Resource Consumption. The impact is: Denial of service. The component is: Date handler. The attack vector is: Attacker provides very long strings, which the library attempts to match using a regular expression. The fixed version is: 4.7.11.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -8,9 +8,7 @@
],
"summary": "Sensitive Data Exposure in seneca",
"details": "Versions of `seneca` prior to 3.9.0 are vulnerable to Sensitive Data Exposure. When a process using the package crashes all environment variables are printed. This may leak sensitive data such as access keys, especially given scenarios when log-monitoring systems store the error output.\n\n\n## Recommendation\n\nUpgrade to version 3.9.0 or later.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -8,9 +8,7 @@
],
"summary": "Cross-Site Scripting in dojo",
"details": "Versions of `dojo` prior to 1.4.2 are vulnerable to DOM-based Cross-Site Scripting (XSS). The package does not sanitize URL parameters in the `_testCommon.js` and `runner.html` test files, allowing attackers to execute arbitrary JavaScript in the victim's browser.\n\n\n## Recommendation\n\nUpgrade to version 1.4.2 or later.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -3,14 +3,10 @@
"id": "GHSA-5w65-6875-rhq8",
"modified": "2020-08-31T18:34:32Z",
"published": "2019-09-11T23:01:57Z",
"aliases": [
],
"aliases": [],
"summary": "Undefined Behavior in sailsjs-cacheman",
"details": "All versions of `sailsjs-cacheman` have a vulnerability that may lead to Undefined Behavior. The config variable is exposing to the global scope which may overwrite other variables and cause the application to misbehave.\n\n\n## Recommendation\n\nNo fix is currently available. Consider using an alternative module until a fix is made available.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -47,9 +43,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "LOW",
"github_reviewed": true,
"github_reviewed_at": "2019-09-03T23:31:41Z",
@@ -3,9 +3,7 @@
"id": "GHSA-cgjv-rghq-qhgp",
"modified": "2021-08-17T22:22:48Z",
"published": "2019-09-11T23:00:57Z",
"aliases": [
],
"aliases": [],
"summary": "Path Traversal in algo-httpserv",
"details": "Versions of `algo-httpserv` prior to 1.1.2 are vulnerable to Path Traversal. Due to insufficient input sanitization, attackers can access server files by using relative paths. \n\n\n## Recommendation\n\nUpgrade to version 1.1.2 or later.",
"severity": [
@@ -4,14 +4,10 @@
"modified": "2020-08-19T21:30:04Z",
"published": "2020-08-19T21:30:04Z",
"withdrawn": "2020-08-19T21:30:04Z",
"aliases": [
],
"aliases": [],
"summary": "Authentication Weakness in keystone",
"details": "There is an authentication weakness vulnerability in keystone before version 0.3.16. Due to a bug in the the default sign in functionality, incomplete email addresses could be matched. A correct password is still required to complete sign in.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -40,9 +36,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2019-05-29T19:21:31Z",
@@ -4,14 +4,10 @@
"modified": "2020-08-27T22:27:20Z",
"published": "2020-08-27T22:26:15Z",
"withdrawn": "2020-08-27T22:26:15Z",
"aliases": [
],
"aliases": [],
"summary": "Command Injection in dns-sync",
"details": "Withdrawn: Duplicate of GHSA-jcw8-r9xm-32c6",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -48,9 +44,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2019-05-29T19:16:35Z",
@@ -4,14 +4,10 @@
"modified": "2020-08-03T18:05:48Z",
"published": "2020-08-03T18:05:48Z",
"withdrawn": "2020-08-03T18:05:48Z",
"aliases": [
],
"aliases": [],
"summary": "Withdrawn",
"details": "Withdrawn: Duplicate of GHSA-vgrx-w6rg-8fqf",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -44,9 +40,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2019-05-31T23:18:14Z",
@@ -4,14 +4,10 @@
"modified": "2020-08-20T17:21:46Z",
"published": "2020-08-20T17:21:46Z",
"withdrawn": "2020-08-20T17:21:46Z",
"aliases": [
],
"aliases": [],
"summary": "Cross-Site Scripting in keystone",
"details": "Withdrawn: Duplicate of GHSA-7qcx-jmrc-h2rr",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -48,9 +44,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2019-08-01T22:03:28Z",
@@ -4,14 +4,10 @@
"modified": "2020-08-19T21:51:20Z",
"published": "2020-08-19T21:51:20Z",
"withdrawn": "2020-08-19T21:51:20Z",
"aliases": [
],
"aliases": [],
"summary": "SQL Injection in waterline-sequel",
"details": "Withdrawn: Duplicate of GHSA-cgpp-wm2h-6hqx",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -44,9 +40,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2019-05-29T19:20:17Z",
@@ -4,14 +4,10 @@
"modified": "2021-02-23T21:23:16Z",
"published": "2021-02-23T21:23:16Z",
"withdrawn": "2021-02-23T21:23:16Z",
"aliases": [
],
"aliases": [],
"summary": "Backdoor / Malicious code",
"details": "lita-coin 0.0.3 contains a backdoor mechanism that allows launching of hidden cryptocurrency mining operations inside the project. The code also contained a backdoor mechanism that allowed the attacker to send a cookie file back to a compromised project, and allow the attacker to execute malicious commands.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -34,9 +30,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "CRITICAL",
"github_reviewed": true,
"github_reviewed_at": "2019-08-28T16:16:58Z",
@@ -3,9 +3,7 @@
"id": "GHSA-g4m4-9q4c-mfw6",
"modified": "2024-08-21T22:30:00Z",
"published": "2024-07-16T19:32:22Z",
"aliases": [
],
"aliases": [],
"summary": "Fiona affected by CVE-2020-14152 related to madler-zlib",
"details": "### Summary\nVulnerability scan of fiona shows [CVE-2020-14152](https://nvd.nist.gov/vuln/detail/CVE-2020-14152). The vulnerability is in libjpeg, a transitive dependency of fiona (via GDAL and PROJ).\n\n### Details\nIn IJG JPEG (aka libjpeg) before 9d, jpeg_mem_available() in jmemnobs.c in djpeg does not honor the max_memory_to_use setting, possibly causing excessive memory consumption.\n\n### Impact\nfiona will not open JPEG files and is not vulnerable to attack in that way. fiona might be vulnerable to malformed PROJ grid files using JPEG compression. No such vulnerability or compromise has been demonstrated.\n",
"severity": [
@@ -7,12 +7,8 @@
"CVE-2006-6348"
],
"details": "Cross-site scripting (XSS) vulnerability in board.php in mowdBB RC-6 allows remote attackers to inject arbitrary web script or HTML via the forum_name[] parameter.",
"severity": [
],
"affected": [
],
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
@@ -32,9 +28,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -7,12 +7,8 @@
"CVE-2006-6345"
],
"details": "Directory traversal vulnerability in SAP Internet Graphics Service (IGS) 6.40 Patchlevel 16 and earlier, and 7.00 Patchlevel 6 and earlier, allows remote attackers to delete arbitrary files via directory traversal sequences in an HTTP request. NOTE: This information is based upon an initial disclosure. Details will be updated after the grace period has ended. This issue is different from CVE-2006-4133 and CVE-2006-4134.",
"severity": [
],
"affected": [
],
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
@@ -52,9 +48,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -7,12 +7,8 @@
"CVE-2006-6370"
],
"details": "SQL injection vulnerability in forum/modules/gallery/post.php in Invision Gallery 2.0.7 allows remote attackers to cause a denial of service and possibly have other impacts, as demonstrated using a \"SELECT BENCHMARK\" statement in the img parameter in a doaddcomment operation in index.php.",
"severity": [
],
"affected": [
],
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
@@ -28,9 +24,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -7,12 +7,8 @@
"CVE-2006-6402"
],
"details": "SQL injection vulnerability in mystats.php in MyStats 1.0.8 and earlier allows remote attackers to execute arbitrary SQL commands via the details parameter.",
"severity": [
],
"affected": [
],
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
@@ -7,12 +7,8 @@
"CVE-2006-6566"
],
"details": "PHP remote file inclusion vulnerability in includes/profilcp_constants.php in the Profile Control Panel (CPanel) module for mxBB 0.91c allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter.",
"severity": [
],
"affected": [
],
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
@@ -44,9 +40,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -7,12 +7,8 @@
"CVE-2006-6590"
],
"details": "PHP remote file inclusion vulnerability in usercp_menu.php in AR Memberscript allows remote attackers to execute arbitrary PHP code via a URL in the script_folder parameter.",
"severity": [
],
"affected": [
],
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
@@ -28,9 +24,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,

Some files were not shown because too many files have changed in this diff Show More