From 8734b0c6b859484473c84cc7e6ccc33ed625fb54 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 5 Jul 2024 20:09:24 +0000 Subject: [PATCH] Publish Advisories GHSA-fqpg-rq76-99pq GHSA-m9gv-6p22-qgmj GHSA-p9cg-vqcc-grcx --- .../GHSA-fqpg-rq76-99pq.json | 50 +++++++ .../GHSA-m9gv-6p22-qgmj.json | 138 ++++++++++++++++++ .../GHSA-p9cg-vqcc-grcx.json | 95 ++++++++++++ 3 files changed, 283 insertions(+) create mode 100644 advisories/github-reviewed/2024/07/GHSA-fqpg-rq76-99pq/GHSA-fqpg-rq76-99pq.json create mode 100644 advisories/github-reviewed/2024/07/GHSA-m9gv-6p22-qgmj/GHSA-m9gv-6p22-qgmj.json create mode 100644 advisories/github-reviewed/2024/07/GHSA-p9cg-vqcc-grcx/GHSA-p9cg-vqcc-grcx.json diff --git a/advisories/github-reviewed/2024/07/GHSA-fqpg-rq76-99pq/GHSA-fqpg-rq76-99pq.json b/advisories/github-reviewed/2024/07/GHSA-fqpg-rq76-99pq/GHSA-fqpg-rq76-99pq.json new file mode 100644 index 00000000000..2054474c211 --- /dev/null +++ b/advisories/github-reviewed/2024/07/GHSA-fqpg-rq76-99pq/GHSA-fqpg-rq76-99pq.json @@ -0,0 +1,50 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fqpg-rq76-99pq", + "modified": "2024-07-05T20:08:27Z", + "published": "2024-07-05T20:08:26Z", + "aliases": [ + + ], + "summary": "Panic in Pipeline when PgConn is busy or closed in github.com/jackc/pgx", + "details": "Pipeline can panic when PgConn is busy or closed.", + "severity": [ + + ], + "affected": [ + { + "package": { + "ecosystem": "Go", + "name": "github.com/jackc/pgx/v5" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "5.5.2" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/jackc/pgx/commit/dfd198003a03dbb96e4607b0d3a0bb9a7398ccb7" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-07-05T20:08:26Z", + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/07/GHSA-m9gv-6p22-qgmj/GHSA-m9gv-6p22-qgmj.json b/advisories/github-reviewed/2024/07/GHSA-m9gv-6p22-qgmj/GHSA-m9gv-6p22-qgmj.json new file mode 100644 index 00000000000..597bac78743 --- /dev/null +++ b/advisories/github-reviewed/2024/07/GHSA-m9gv-6p22-qgmj/GHSA-m9gv-6p22-qgmj.json @@ -0,0 +1,138 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m9gv-6p22-qgmj", + "modified": "2024-07-05T20:08:44Z", + "published": "2024-07-05T20:08:44Z", + "aliases": [ + "CVE-2024-39325" + ], + "summary": "ai-controller-frontend payment status in basket isn't reset", + "details": "### Impact\nPayment status in basket isn't reset\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "aimeos/ai-controller-frontend" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2023.04.1" + }, + { + "fixed": "2023.10.9" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "aimeos/ai-controller-frontend" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2022.04.1" + }, + { + "fixed": "2022.10.8" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "aimeos/ai-controller-frontend" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2021.04.1" + }, + { + "fixed": "2021.10.8" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "aimeos/ai-controller-frontend" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2020.10.15" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/aimeos/ai-controller-frontend/security/advisories/GHSA-m9gv-6p22-qgmj" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39325" + }, + { + "type": "WEB", + "url": "https://github.com/aimeos/ai-controller-frontend/commit/16b8837d2466e3665b3c826ce87934b01a847268" + }, + { + "type": "WEB", + "url": "https://github.com/aimeos/ai-controller-frontend/commit/24a57001e56759d1582d2a0080fc1ca3ba328630" + }, + { + "type": "WEB", + "url": "https://github.com/aimeos/ai-controller-frontend/commit/28549808e0f6432a34cd3fb95556deeb86ca276d" + }, + { + "type": "WEB", + "url": "https://github.com/aimeos/ai-controller-frontend/commit/b1960c0b6e5ee93111a5360c9ce949b3e7528cf7" + }, + { + "type": "WEB", + "url": "https://github.com/aimeos/ai-controller-frontend/commit/dafa072783bb692f111ed092d9d2932c113eb855" + }, + { + "type": "PACKAGE", + "url": "https://github.com/aimeos/ai-controller-frontend" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-841" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-07-05T20:08:44Z", + "nvd_published_at": "2024-07-02T21:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/07/GHSA-p9cg-vqcc-grcx/GHSA-p9cg-vqcc-grcx.json b/advisories/github-reviewed/2024/07/GHSA-p9cg-vqcc-grcx/GHSA-p9cg-vqcc-grcx.json new file mode 100644 index 00000000000..bc3dce049d1 --- /dev/null +++ b/advisories/github-reviewed/2024/07/GHSA-p9cg-vqcc-grcx/GHSA-p9cg-vqcc-grcx.json @@ -0,0 +1,95 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p9cg-vqcc-grcx", + "modified": "2024-07-05T20:07:54Z", + "published": "2024-07-05T20:07:54Z", + "aliases": [ + "CVE-2024-39687" + ], + "summary": "Server Side Request Forgery (SSRF) attack in Fedify", + "details": "### Summary\n \nAt present, when Fedify needs to retrieve an object or activity from a remote activitypub server, it makes a HTTP request to the `@id` or other resources present within the activity it has received from the web. This activity could reference an `@id` that points to an internal IP address, allowing an attacker to send request to resources internal to the fedify server's network.\n\nThis applies to not just resolution of documents containing activities or objects, but also to media URLs as well.\n\nSpecifically this is a [Server Side Request Forgery attack](https://owasp.org/www-community/attacks/Server_Side_Request_Forgery). You can learn more about SSRF attacks via [CWE-918](https://cwe.mitre.org/data/definitions/918.html)\n\n### Details\n\nWhen Fedify makes a request at runtime via the DocLoader [1] [2], the `fetch` API does not first check the URI's to assert that it resolve to a public IP address. Additionally, any downstream software of Fedify that may fetch data from URIs contained within Activities or Objects maybe be at risk of requesting non-public resources, and storing those, exposing non-public information to the public.\n\nAdditionally, in many cases the URIs are not asserted to be either strictly HTTPS or HTTP protocols, which could lead to further attacks, and there is no check that the URI contains a `hostname` part. Whilst the [`fetch()` specification](https://fetch.spec.whatwg.org/) may provide some safety here, along with underlying fetch implementations, there is still potential for attacks through using `data:` URIs, or just attacking some other protocol entirely, e.g., FTP or CalDav.\n\n[1] https://github.com/dahlia/fedify/blob/main/runtime/docloader.ts#L141\n[2] https://github.com/dahlia/fedify/blob/main/runtime/docloader.ts#L175\n\n#### Deno-specific Attack Vectors\n\nIn Deno specifically, the `fetch()` API allows [accessing local filesystem](https://docs.deno.com/deploy/api/runtime-fetch/), I'm not sure how Deno's [Permissions model](https://docs.deno.com/runtime/manual/runtime/permission_apis/) may prevent attacks utilising `file:` URIs.\n \n> Fetch also supports fetching from file URLs to retrieve static files. For more info on static files, see the [filesystem API documentation](https://docs.deno.com/deploy/api/runtime-fs).\n\n#### ActivityPub Security Considerations\n\nThis is also noted in the ActivityPub spec in [Section B.3 Security Considerations](https://www.w3.org/TR/activitypub/#security-localhost), however, there it is more limited in scope.\n\n#### Other Implementations\n\nIt may be acceptable to allow a server operator to allow access to given non-public IP addresses, for instance [in Mastodon](https://github.com/mastodon/mastodon/blob/092bb8a27af9ee87ff9ebabaf354477470ea3a94/app/lib/request.rb#L330) they allow requests to non-public IP addresses, i.e., localhost in development and those in the `ALLOWED_PRIVATE_ADDRESSES` environment variable.\n\n### PoC\n\nI'm not sure a PoC is necessary given this is a reasonably well known vulnerability vector.\n\n### Impact\n\nThis impacts server operates, as resources that are internal to their network may find themselves being improperly accessed or potentially even attacked or exposed to the public.\n\n### Notes for resolution:\n\nWhen implementing public IP address validation, be careful of [CWE-1389](https://cwe.mitre.org/data/definitions/1389.html) and [CWE-1286](https://cwe.mitre.org/data/definitions/1286.html) both of which [recently](https://github.com/advisories/GHSA-78xj-cgh5-2h22) caused a CVE to be filed against the popular node.js `ip` package, although this package was not originally intended for security purposes.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:L" + } + ], + "affected": [ + { + "package": { + "ecosystem": "npm", + "name": "@fedify/fedify" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.9.2" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "npm", + "name": "@fedify/fedify" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0.10.0" + }, + { + "fixed": "0.11.1" + } + ] + } + ], + "versions": [ + "0.10.0" + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/dahlia/fedify/security/advisories/GHSA-p9cg-vqcc-grcx" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39687" + }, + { + "type": "WEB", + "url": "https://github.com/dahlia/fedify/commit/30f9cf4a175704a04c874f3ea88414c5f1e00b28" + }, + { + "type": "WEB", + "url": "https://github.com/dahlia/fedify/commit/c641e976089dd913f649889c1bfb016df04e86ba" + }, + { + "type": "PACKAGE", + "url": "https://github.com/dahlia/fedify" + }, + { + "type": "WEB", + "url": "https://github.com/dahlia/fedify/releases/tag/0.11.1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "HIGH", + "github_reviewed": true, + "github_reviewed_at": "2024-07-05T20:07:54Z", + "nvd_published_at": "2024-07-05T18:15:32Z" + } +} \ No newline at end of file