mirror of
https://github.com/netbirdio/advisory-database.git
synced 2026-05-22 18:04:22 -07:00
Publish Advisories
GHSA-833m-37f7-jq55 GHSA-c85r-fwc7-45vc GHSA-r8f4-hv23-6qp6 GHSA-64jq-m7rq-768h GHSA-6gr4-52w6-vmqx GHSA-q6c7-56cq-g2wm GHSA-h4h5-9833-v2p4 GHSA-443j-grxv-2pgv
This commit is contained in:
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-833m-37f7-jq55",
|
||||
"modified": "2024-02-08T18:46:23Z",
|
||||
"modified": "2024-10-16T17:25:51Z",
|
||||
"published": "2024-02-08T18:46:23Z",
|
||||
"aliases": [
|
||||
"CVE-2023-32192"
|
||||
@@ -40,6 +40,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/rancher/apiserver/security/advisories/GHSA-833m-37f7-jq55"
|
||||
},
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32192"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/rancher/apiserver/commit/4df268e250f625fa323349062636496e0aeff4e4"
|
||||
@@ -64,6 +68,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/rancher/apiserver/commit/a3b9e3721c1b558ee63aec9594e37c223a5c8437"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://bugzilla.suse.com/show_bug.cgi?id=CVE-2023-32192"
|
||||
},
|
||||
{
|
||||
"type": "PACKAGE",
|
||||
"url": "https://github.com/rancher/apiserver"
|
||||
@@ -76,6 +84,6 @@
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": true,
|
||||
"github_reviewed_at": "2024-02-08T18:46:23Z",
|
||||
"nvd_published_at": null
|
||||
"nvd_published_at": "2024-10-16T13:15:12Z"
|
||||
}
|
||||
}
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-c85r-fwc7-45vc",
|
||||
"modified": "2024-07-08T20:16:25Z",
|
||||
"modified": "2024-10-16T17:25:46Z",
|
||||
"published": "2024-02-08T18:43:28Z",
|
||||
"aliases": [
|
||||
"CVE-2023-32194"
|
||||
@@ -82,6 +82,14 @@
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/rancher/rancher/security/advisories/GHSA-c85r-fwc7-45vc"
|
||||
},
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32194"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://bugzilla.suse.com/show_bug.cgi?id=CVE-2023-32194"
|
||||
},
|
||||
{
|
||||
"type": "PACKAGE",
|
||||
"url": "https://github.com/rancher/rancher"
|
||||
@@ -94,6 +102,6 @@
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": true,
|
||||
"github_reviewed_at": "2024-02-08T18:43:28Z",
|
||||
"nvd_published_at": null
|
||||
"nvd_published_at": "2024-10-16T13:15:12Z"
|
||||
}
|
||||
}
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-r8f4-hv23-6qp6",
|
||||
"modified": "2024-02-08T18:45:49Z",
|
||||
"modified": "2024-10-16T17:25:49Z",
|
||||
"published": "2024-02-08T18:45:49Z",
|
||||
"aliases": [
|
||||
"CVE-2023-32193"
|
||||
@@ -40,6 +40,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/rancher/norman/security/advisories/GHSA-r8f4-hv23-6qp6"
|
||||
},
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32193"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/rancher/norman/commit/3bb70b772b52297feac64f5fdeb1b13c06c37e39"
|
||||
@@ -60,6 +64,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/rancher/norman/commit/cb54924f25c7666511a913cd41834299ef22dba4"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://bugzilla.suse.com/show_bug.cgi?id=CVE-2023-32193"
|
||||
},
|
||||
{
|
||||
"type": "PACKAGE",
|
||||
"url": "https://github.com/rancher/norman"
|
||||
@@ -72,6 +80,6 @@
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": true,
|
||||
"github_reviewed_at": "2024-02-08T18:45:49Z",
|
||||
"nvd_published_at": null
|
||||
"nvd_published_at": "2024-10-16T13:15:12Z"
|
||||
}
|
||||
}
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-64jq-m7rq-768h",
|
||||
"modified": "2024-07-08T21:17:37Z",
|
||||
"modified": "2024-10-16T17:26:07Z",
|
||||
"published": "2024-06-17T22:30:51Z",
|
||||
"aliases": [
|
||||
"CVE-2023-32196"
|
||||
@@ -63,6 +63,14 @@
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/rancher/rancher/security/advisories/GHSA-64jq-m7rq-768h"
|
||||
},
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32196"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://bugzilla.suse.com/show_bug.cgi?id=CVE-2023-32196"
|
||||
},
|
||||
{
|
||||
"type": "PACKAGE",
|
||||
"url": "https://github.com/rancher/rancher"
|
||||
@@ -72,9 +80,9 @@
|
||||
"cwe_ids": [
|
||||
"CWE-269"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": true,
|
||||
"github_reviewed_at": "2024-06-17T22:30:51Z",
|
||||
"nvd_published_at": null
|
||||
"nvd_published_at": "2024-10-16T13:15:13Z"
|
||||
}
|
||||
}
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-6gr4-52w6-vmqx",
|
||||
"modified": "2024-07-05T21:40:58Z",
|
||||
"modified": "2024-10-16T17:26:10Z",
|
||||
"published": "2024-06-17T22:30:48Z",
|
||||
"aliases": [
|
||||
"CVE-2023-32191"
|
||||
@@ -59,6 +59,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/rancher/rke/security/advisories/GHSA-6gr4-52w6-vmqx"
|
||||
},
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32191"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/rancher/rke/commit/cf49199481a1891909acb1384eed73a5c987d5bd"
|
||||
@@ -67,6 +71,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/rancher/rke/commit/f7485b8dce376db0fc15a7c3ceb3de7029c8d0cf"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://bugzilla.suse.com/show_bug.cgi?id=CVE-2023-32191"
|
||||
},
|
||||
{
|
||||
"type": "PACKAGE",
|
||||
"url": "https://github.com/rancher/rke"
|
||||
@@ -74,11 +82,11 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
"CWE-922"
|
||||
],
|
||||
"severity": "CRITICAL",
|
||||
"github_reviewed": true,
|
||||
"github_reviewed_at": "2024-06-17T22:30:48Z",
|
||||
"nvd_published_at": null
|
||||
"nvd_published_at": "2024-10-16T13:15:12Z"
|
||||
}
|
||||
}
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-q6c7-56cq-g2wm",
|
||||
"modified": "2024-07-08T21:17:00Z",
|
||||
"modified": "2024-10-16T17:26:04Z",
|
||||
"published": "2024-06-17T22:30:52Z",
|
||||
"aliases": [
|
||||
"CVE-2024-22032"
|
||||
@@ -63,6 +63,14 @@
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/rancher/rancher/security/advisories/GHSA-q6c7-56cq-g2wm"
|
||||
},
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22032"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://bugzilla.suse.com/show_bug.cgi?id=CVE-2024-22032"
|
||||
},
|
||||
{
|
||||
"type": "PACKAGE",
|
||||
"url": "https://github.com/rancher/rancher"
|
||||
@@ -73,9 +81,9 @@
|
||||
"CWE-200",
|
||||
"CWE-256"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": true,
|
||||
"github_reviewed_at": "2024-06-17T22:30:52Z",
|
||||
"nvd_published_at": null
|
||||
"nvd_published_at": "2024-10-16T14:15:05Z"
|
||||
}
|
||||
}
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-h4h5-9833-v2p4",
|
||||
"modified": "2024-10-09T22:15:40Z",
|
||||
"modified": "2024-10-16T17:26:13Z",
|
||||
"published": "2024-09-26T21:13:08Z",
|
||||
"aliases": [
|
||||
"CVE-2024-22030"
|
||||
@@ -78,6 +78,14 @@
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/rancher/rancher/security/advisories/GHSA-h4h5-9833-v2p4"
|
||||
},
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22030"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://bugzilla.suse.com/show_bug.cgi?id=CVE-2024-22030"
|
||||
},
|
||||
{
|
||||
"type": "PACKAGE",
|
||||
"url": "https://github.com/rancher/rancher"
|
||||
@@ -97,11 +105,11 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
"CWE-295"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": true,
|
||||
"github_reviewed_at": "2024-09-26T21:13:08Z",
|
||||
"nvd_published_at": null
|
||||
"nvd_published_at": "2024-10-16T14:15:04Z"
|
||||
}
|
||||
}
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-443j-grxv-2pgv",
|
||||
"modified": "2024-10-14T21:17:12Z",
|
||||
"modified": "2024-10-16T17:24:49Z",
|
||||
"published": "2024-10-14T18:30:25Z",
|
||||
"aliases": [
|
||||
"CVE-2023-50780"
|
||||
@@ -9,6 +9,10 @@
|
||||
"summary": "Apache ActiveMQ Artemis: Authenticated users could perform RCE via Jolokia MBeans",
|
||||
"details": "Apache ActiveMQ Artemis allows access to diagnostic information and controls through MBeans, which are also exposed through the authenticated Jolokia endpoint. Before version 2.29.0, this also included the Log4J2 MBean. This MBean is not meant for exposure to non-administrative users. This could eventually allow an authenticated attacker to write arbitrary files to the filesystem and indirectly achieve RCE.\n\n\nUsers are recommended to upgrade to version 2.29.0 or later, which fixes the issue.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
|
||||
},
|
||||
{
|
||||
"type": "CVSS_V4",
|
||||
"score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
|
||||
|
||||
Reference in New Issue
Block a user