diff --git a/advisories/github-reviewed/2024/03/GHSA-26w3-q4j8-4xjp/GHSA-26w3-q4j8-4xjp.json b/advisories/github-reviewed/2024/03/GHSA-26w3-q4j8-4xjp/GHSA-26w3-q4j8-4xjp.json index 691256bd370..58221f43f25 100644 --- a/advisories/github-reviewed/2024/03/GHSA-26w3-q4j8-4xjp/GHSA-26w3-q4j8-4xjp.json +++ b/advisories/github-reviewed/2024/03/GHSA-26w3-q4j8-4xjp/GHSA-26w3-q4j8-4xjp.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-26w3-q4j8-4xjp", - "modified": "2024-03-14T21:44:29Z", + "modified": "2025-02-11T19:03:36Z", "published": "2024-03-06T15:29:11Z", "aliases": [ "CVE-2024-27288" ], "summary": "1Panel open source panel project has an unauthorized vulnerability.", - "details": "### Impact\n\nThe steps are as follows:\n\n1. Access https://IP:PORT/ in the browser, which prompts the user to access with a secure entry point.\n![image](https://github.com/1Panel-dev/1Panel/assets/46734380/8dc7d81c-6cc3-4b5d-a1d4-d3c5ed2de005)\n\n2. Use Burp to intercept:\n![image](https://github.com/1Panel-dev/1Panel/assets/46734380/f8e93d08-1b66-4434-8923-2e8e3dedebe3)\n\nWhen opening the browser and entering the URL (allowing the first intercepted packet through Burp), the following is displayed:\n![image](https://github.com/1Panel-dev/1Panel/assets/46734380/118c0102-7c89-404d-834a-88a644482afc)\n\nIt is found that in this situation, we can access the console page (although no data is returned and no modification operations can be performed).\"\n\nAffected versions: <= 1.10.0-lts\n\n### Patches\n\nThe vulnerability has been fixed in v1.10.1-lts.\n\n### Workarounds\n\nIt is recommended to upgrade the version to 1.10.1-lts.\n\n### References\n\nIf you have any questions or comments about this advisory:\n\nOpen an issue in https://github.com/1Panel-dev/1Panel\nEmail us at wanghe@fit2cloud.com\n", + "details": "### Impact\n\nThe steps are as follows:\n\n1. Access https://IP:PORT/ in the browser, which prompts the user to access with a secure entry point.\n![image](https://github.com/1Panel-dev/1Panel/assets/46734380/8dc7d81c-6cc3-4b5d-a1d4-d3c5ed2de005)\n\n2. Use Burp to intercept:\n![image](https://github.com/1Panel-dev/1Panel/assets/46734380/f8e93d08-1b66-4434-8923-2e8e3dedebe3)\n\nWhen opening the browser and entering the URL (allowing the first intercepted packet through Burp), the following is displayed:\n![image](https://github.com/1Panel-dev/1Panel/assets/46734380/118c0102-7c89-404d-834a-88a644482afc)\n\nIt is found that in this situation, we can access the console page (although no data is returned and no modification operations can be performed).\"\n\nAffected versions: <= 1.10.0-lts\n\n### Patches\n\nThe vulnerability has been fixed in v1.10.1-lts.\n\n### Workarounds\n\nIt is recommended to upgrade the version to 1.10.1-lts.\n\n### References\n\nIf you have any questions or comments about this advisory:\n\nOpen an issue in https://github.com/1Panel-dev/1Panel\nEmail us at wanghe@fit2cloud.com", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2024/04/GHSA-2522-mrjc-m688/GHSA-2522-mrjc-m688.json b/advisories/github-reviewed/2024/04/GHSA-2522-mrjc-m688/GHSA-2522-mrjc-m688.json index ffde3239a38..a15c54078ae 100644 --- a/advisories/github-reviewed/2024/04/GHSA-2522-mrjc-m688/GHSA-2522-mrjc-m688.json +++ b/advisories/github-reviewed/2024/04/GHSA-2522-mrjc-m688/GHSA-2522-mrjc-m688.json @@ -1,14 +1,19 @@ { "schema_version": "1.4.0", "id": "GHSA-2522-mrjc-m688", - "modified": "2024-05-02T14:46:46Z", + "modified": "2025-02-11T19:03:13Z", "published": "2024-04-18T09:30:44Z", "aliases": [ "CVE-2024-31869" ], "summary": "Apache Airflow: Sensitive configuration for providers displayed when \"non-sensitive-only\" config used", "details": "Airflow versions 2.7.0 through 2.8.4 have a vulnerability that allows an authenticated user to see sensitive provider configuration via the \"configuration\" UI page when \"non-sensitive-only\" was set as \"webserver.expose_config\" configuration (The celery provider is the only community provider currently that has sensitive configurations). You should migrate to Airflow 2.9 or change your \"expose_config\" configuration to False as a workaround. This is similar, but different to CVE-2023-46288 https://github.com/advisories/GHSA-9qqg-mh7c-chfq which concerned API, not UI configuration page.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2024/04/GHSA-27jx-ffw8-xrqv/GHSA-27jx-ffw8-xrqv.json b/advisories/github-reviewed/2024/04/GHSA-27jx-ffw8-xrqv/GHSA-27jx-ffw8-xrqv.json index 507e4eb3a4d..30cfdca8b85 100644 --- a/advisories/github-reviewed/2024/04/GHSA-27jx-ffw8-xrqv/GHSA-27jx-ffw8-xrqv.json +++ b/advisories/github-reviewed/2024/04/GHSA-27jx-ffw8-xrqv/GHSA-27jx-ffw8-xrqv.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-27jx-ffw8-xrqv", - "modified": "2024-04-23T03:31:28Z", + "modified": "2025-02-11T19:03:30Z", "published": "2024-04-04T15:30:34Z", "aliases": [ "CVE-2024-3116" ], "summary": "pgAdmin Remote Code Execution (RCE) vulnerability", - "details": "pgAdmin <= 8.4 is affected by a Remote Code Execution (RCE) vulnerability through the validate binary path API. This vulnerability allows attackers to execute arbitrary code on the server hosting PGAdmin, posing a severe risk to the database management system's integrity and the security of the underlying data.\n", + "details": "pgAdmin <= 8.4 is affected by a Remote Code Execution (RCE) vulnerability through the validate binary path API. This vulnerability allows attackers to execute arbitrary code on the server hosting PGAdmin, posing a severe risk to the database management system's integrity and the security of the underlying data.", "severity": [ { "type": "CVSS_V3", @@ -59,6 +59,10 @@ { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GIF5T34JTTYRGIN5YPT366BDFG6452A2" + }, + { + "type": "WEB", + "url": "https://www.vicarius.io/vsociety/posts/remote-code-execution-vulnerability-in-pgadmin-cve-2024-3116" } ], "database_specific": { diff --git a/advisories/github-reviewed/2024/04/GHSA-6m9h-2pr2-9j8f/GHSA-6m9h-2pr2-9j8f.json b/advisories/github-reviewed/2024/04/GHSA-6m9h-2pr2-9j8f/GHSA-6m9h-2pr2-9j8f.json index 88e21b818ad..3ad40e1ce39 100644 --- a/advisories/github-reviewed/2024/04/GHSA-6m9h-2pr2-9j8f/GHSA-6m9h-2pr2-9j8f.json +++ b/advisories/github-reviewed/2024/04/GHSA-6m9h-2pr2-9j8f/GHSA-6m9h-2pr2-9j8f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6m9h-2pr2-9j8f", - "modified": "2024-07-24T15:12:00Z", + "modified": "2025-02-11T19:02:38Z", "published": "2024-04-18T16:44:16Z", "aliases": [ "CVE-2024-30257" @@ -11,7 +11,7 @@ "severity": [ { "type": "CVSS_V3", - "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:L" + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" }, { "type": "CVSS_V4", diff --git a/advisories/github-reviewed/2024/04/GHSA-m65c-wmw9-vmpp/GHSA-m65c-wmw9-vmpp.json b/advisories/github-reviewed/2024/04/GHSA-m65c-wmw9-vmpp/GHSA-m65c-wmw9-vmpp.json index 022a69b3181..beebd491329 100644 --- a/advisories/github-reviewed/2024/04/GHSA-m65c-wmw9-vmpp/GHSA-m65c-wmw9-vmpp.json +++ b/advisories/github-reviewed/2024/04/GHSA-m65c-wmw9-vmpp/GHSA-m65c-wmw9-vmpp.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-m65c-wmw9-vmpp", - "modified": "2024-05-02T14:45:32Z", + "modified": "2025-02-11T19:03:17Z", "published": "2024-04-09T12:30:47Z", "aliases": [ "CVE-2024-31863" ], "summary": "Apache Zeppelin: Replacing other users notebook, bypassing any permissions", - "details": "Authentication Bypass by Spoofing vulnerability by replacing to exsiting notes in Apache Zeppelin. This issue affects Apache Zeppelin: from 0.10.1 before 0.11.0.\n\nUsers are recommended to upgrade to version 0.11.0, which fixes the issue.\n\n", + "details": "Authentication Bypass by Spoofing vulnerability by replacing to exsiting notes in Apache Zeppelin. This issue affects Apache Zeppelin: from 0.10.1 before 0.11.0.\n\nUsers are recommended to upgrade to version 0.11.0, which fixes the issue.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2024/05/GHSA-gj5m-m88j-v7c3/GHSA-gj5m-m88j-v7c3.json b/advisories/github-reviewed/2024/05/GHSA-gj5m-m88j-v7c3/GHSA-gj5m-m88j-v7c3.json index eb3d70b0393..f1c0634171b 100644 --- a/advisories/github-reviewed/2024/05/GHSA-gj5m-m88j-v7c3/GHSA-gj5m-m88j-v7c3.json +++ b/advisories/github-reviewed/2024/05/GHSA-gj5m-m88j-v7c3/GHSA-gj5m-m88j-v7c3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gj5m-m88j-v7c3", - "modified": "2024-05-03T17:47:07Z", + "modified": "2025-02-11T19:03:08Z", "published": "2024-05-02T09:30:48Z", "aliases": [ "CVE-2024-32114" @@ -11,7 +11,7 @@ "severity": [ { "type": "CVSS_V3", - "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:H" + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } ], "affected": [