From 8356c9e74dc12464a0f41d53dc92afa67bbb5a2c Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 28 Feb 2024 18:40:22 +0000 Subject: [PATCH] Publish Advisories GHSA-fj69-p8f6-q97h GHSA-crv8-r5wq-gv2w GHSA-fj69-p8f6-q97h --- .../GHSA-fj69-p8f6-q97h.json | 77 +++++++++++++++++++ .../GHSA-crv8-r5wq-gv2w.json | 33 ++++++-- .../GHSA-fj69-p8f6-q97h.json | 38 --------- 3 files changed, 105 insertions(+), 43 deletions(-) create mode 100644 advisories/github-reviewed/2022/05/GHSA-fj69-p8f6-q97h/GHSA-fj69-p8f6-q97h.json rename advisories/{unreviewed => github-reviewed}/2023/08/GHSA-crv8-r5wq-gv2w/GHSA-crv8-r5wq-gv2w.json (58%) delete mode 100644 advisories/unreviewed/2022/05/GHSA-fj69-p8f6-q97h/GHSA-fj69-p8f6-q97h.json diff --git a/advisories/github-reviewed/2022/05/GHSA-fj69-p8f6-q97h/GHSA-fj69-p8f6-q97h.json b/advisories/github-reviewed/2022/05/GHSA-fj69-p8f6-q97h/GHSA-fj69-p8f6-q97h.json new file mode 100644 index 00000000000..45970ac4cd6 --- /dev/null +++ b/advisories/github-reviewed/2022/05/GHSA-fj69-p8f6-q97h/GHSA-fj69-p8f6-q97h.json @@ -0,0 +1,77 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fj69-p8f6-q97h", + "modified": "2024-02-28T18:38:31Z", + "published": "2022-05-13T01:07:02Z", + "aliases": [ + "CVE-2015-3189" + ], + "summary": "Cloud Foundry Runtime has Weak Password Recovery Mechanism for Forgotten Password", + "details": "With Cloud Foundry Runtime cf-release versions v208 or earlier, UAA Standalone versions prior to 2.2.5 and Pivotal Cloud Foundry Runtime 1.4.5 or earlier, old Password Reset Links are not expired after the user changes their current email address to a new one. This vulnerability is applicable only when using the UAA internal user store for authentication. Deployments enabled for integration via SAML or LDAP are not affected.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Maven", + "name": "org.cloudfoundry.identity:cloudfoundry-identity-server" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.2.5" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2015-3189" + }, + { + "type": "WEB", + "url": "https://github.com/cloudfoundry/uaa/commit/a79b89f6e4f66626914b029b7a15a423491f8013" + }, + { + "type": "PACKAGE", + "url": "https://github.com/cloudfoundry/uaa" + }, + { + "type": "WEB", + "url": "https://github.com/cloudfoundry/uaa/commits/2.2.5" + }, + { + "type": "WEB", + "url": "https://github.com/cloudfoundry/uaa/compare/2.2.4...2.2.5" + }, + { + "type": "WEB", + "url": "https://github.com/cloudfoundry/uaa/compare/2.2.5...2.2.6" + }, + { + "type": "WEB", + "url": "https://pivotal.io/security/cve-2015-3189" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-640" + ], + "severity": "LOW", + "github_reviewed": true, + "github_reviewed_at": "2024-02-28T18:38:31Z", + "nvd_published_at": "2017-05-25T17:29:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/08/GHSA-crv8-r5wq-gv2w/GHSA-crv8-r5wq-gv2w.json b/advisories/github-reviewed/2023/08/GHSA-crv8-r5wq-gv2w/GHSA-crv8-r5wq-gv2w.json similarity index 58% rename from advisories/unreviewed/2023/08/GHSA-crv8-r5wq-gv2w/GHSA-crv8-r5wq-gv2w.json rename to advisories/github-reviewed/2023/08/GHSA-crv8-r5wq-gv2w/GHSA-crv8-r5wq-gv2w.json index f958170db58..d2c8eaee20a 100644 --- a/advisories/unreviewed/2023/08/GHSA-crv8-r5wq-gv2w/GHSA-crv8-r5wq-gv2w.json +++ b/advisories/github-reviewed/2023/08/GHSA-crv8-r5wq-gv2w/GHSA-crv8-r5wq-gv2w.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-crv8-r5wq-gv2w", - "modified": "2023-08-28T21:31:05Z", + "modified": "2024-02-28T18:38:27Z", "published": "2023-08-22T21:30:27Z", "aliases": [ "CVE-2023-39141" ], + "summary": "webui-aria2 Path Traversal vulnerability", "details": "webui-aria2 commit 4fe2e was discovered to contain a path traversal vulnerability.", "severity": [ { @@ -14,7 +15,25 @@ } ], "affected": [ - + { + "package": { + "ecosystem": "npm", + "name": "webui-aria2" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "1.0.1" + } + ] + } + ] + } ], "references": [ { @@ -25,6 +44,10 @@ "type": "WEB", "url": "https://gist.github.com/JafarAkhondali/528fe6c548b78f454911fb866b23f66e" }, + { + "type": "PACKAGE", + "url": "https://github.com/ziahamza/webui-aria2" + }, { "type": "WEB", "url": "https://github.com/ziahamza/webui-aria2/blob/109903f0e2774cf948698cd95a01f77f33d7dd2c/node-server.js#L10" @@ -34,9 +57,9 @@ "cwe_ids": [ "CWE-22" ], - "severity": null, - "github_reviewed": false, - "github_reviewed_at": null, + "severity": "HIGH", + "github_reviewed": true, + "github_reviewed_at": "2024-02-28T18:38:27Z", "nvd_published_at": "2023-08-22T19:16:39Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-fj69-p8f6-q97h/GHSA-fj69-p8f6-q97h.json b/advisories/unreviewed/2022/05/GHSA-fj69-p8f6-q97h/GHSA-fj69-p8f6-q97h.json deleted file mode 100644 index fc58728e746..00000000000 --- a/advisories/unreviewed/2022/05/GHSA-fj69-p8f6-q97h/GHSA-fj69-p8f6-q97h.json +++ /dev/null @@ -1,38 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-fj69-p8f6-q97h", - "modified": "2022-05-13T01:07:02Z", - "published": "2022-05-13T01:07:02Z", - "aliases": [ - "CVE-2015-3189" - ], - "details": "With Cloud Foundry Runtime cf-release versions v208 or earlier, UAA Standalone versions 2.2.5 or earlier and Pivotal Cloud Foundry Runtime 1.4.5 or earlier, old Password Reset Links are not expired after the user changes their current email address to a new one. This vulnerability is applicable only when using the UAA internal user store for authentication. Deployments enabled for integration via SAML or LDAP are not affected.", - "severity": [ - { - "type": "CVSS_V3", - "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" - } - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2015-3189" - }, - { - "type": "WEB", - "url": "https://pivotal.io/security/cve-2015-3189" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-640" - ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2017-05-25T17:29:00Z" - } -} \ No newline at end of file