Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2024-12-06 05:08:53 +00:00
parent e96ed372c7
commit 94ba8290a1
969 changed files with 2208 additions and 6624 deletions
@@ -3,9 +3,7 @@
"id": "GHSA-m836-gxwq-j2pm",
"modified": "2021-10-27T18:58:30Z",
"published": "2021-10-28T16:27:03Z",
"aliases": [
],
"aliases": [],
"summary": "Improper Access Control in github.com/treeverse/lakefs",
"details": "### Impact\n\n1. [medium] A user with write permissions to a portion of a repository may use the S3 gateway to copy any object in the repository if they know its name.\n1. [medium] A user with permission to write any one of tags, branches, or commits on a repository may write all of them.\n1. [low] A user with permission to read any one of tags, branches, or commits on a repository may read all of them.\n1. [low] A user allowed to list objects in a repository _or_ read repository meta-data may retrieve graveler information about the location on underlying storage of all objects stored in any commit that they can view. If the user additionally has the capability to read underlying storage, they will be able to retrieve metadata associated with all objects in that commit.\n\n### For more information\n\nIf you have any questions or comments about this advisory please:\n* Email us at security@treeverse.io.\n* Open an issue on https://github.com/treeverse/lakeFS/issues/new.\n",
"severity": [
@@ -3,14 +3,10 @@
"id": "GHSA-73qr-pfmq-6rp8",
"modified": "2022-09-07T22:16:29Z",
"published": "2021-11-04T16:22:28Z",
"aliases": [
],
"aliases": [],
"summary": "Embedded malware in coa",
"details": "The npm package `coa` had versions published with malicious code. Users of affected versions (2.0.3 and above) should downgrade to 2.0.2 as soon as possible and check their systems for suspicious activity. See [this issue](https://github.com/veged/coa/issues/99) for details as they unfold.\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -3,14 +3,10 @@
"id": "GHSA-g2q5-5433-rhrf",
"modified": "2022-09-07T22:17:03Z",
"published": "2021-11-04T16:24:44Z",
"aliases": [
],
"aliases": [],
"summary": "Embedded malware in rc",
"details": "The npm package `rc` had versions published with malicious code. Users of affected versions (1.2.9, 1.3.9, and 2.3.9) should downgrade to 1.2.8 as soon as possible and check their systems for suspicious activity.\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer. The package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -8,9 +8,7 @@
],
"summary": "MoinMoin has multiple vulnerabilities related to superuser list, xmlrpc and OpenID configuration",
"details": "Unspecified vulnerability in MoinMoin 1.5.x through 1.7.x, 1.8.x before 1.8.7, and 1.9.x before 1.9.2 has unknown impact and attack vectors, related to configurations that have a non-empty superuser list, the xmlrpc action enabled, the SyncPages action enabled, or OpenID configured.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -130,9 +128,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-04-29T11:24:59Z",
@@ -8,9 +8,7 @@
],
"summary": "MoinMoin improper sanitizes user profiles",
"details": "MoinMoin before 1.8.7 and 1.9.x before 1.9.2 does not properly sanitize user profiles, which has unspecified impact and attack vectors.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -106,9 +104,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2024-04-29T11:36:09Z",
@@ -8,9 +8,7 @@
],
"summary": "Apache Struts Multiple Cross-site Scripting Vulnerabilities",
"details": "Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.0.14 and 2.2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) lastName parameter to `struts2-showcase/person/editPerson.action`, or the (3) clientName parameter to `struts2-rest-showcase/orders`.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -8,9 +8,7 @@
],
"summary": "Apache QPID Allows Remote Authentication Bypass",
"details": "Apache QPID 0.14, 0.16, and earlier uses a NullAuthenticator mechanism to authenticate catch-up shadow connections to AMQP brokers, which allows remote attackers to bypass authentication.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -4,9 +4,7 @@
"modified": "2024-05-21T14:43:32Z",
"published": "2024-03-21T21:31:15Z",
"withdrawn": "2024-05-21T14:43:32Z",
"aliases": [
],
"aliases": [],
"summary": "Duplicate Advisory: Cross-Site Request Forgery in Gradio",
"details": "## Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-48cq-79qq-6f7x. this link is maintained to preserve external references.\n\n## Original Description\nA Cross-Site Request Forgery gives attackers the ability to upload many large files to a victim, if they are running Gradio locally. To resolve this a PR tightening the CORS rules around Gradio applications has been submitted. In particular, it checks to see if the host header is localhost (or one of its aliases) and if so, it requires the origin header (if present) to be localhost (or one of its aliases) as well.\n\n",
"severity": [
@@ -8,9 +8,7 @@
],
"summary": "NATS server TLS missing ciphersuite settings when CLI flags used",
"details": "(This advisory is canonically <https://advisories.nats.io/CVE/CVE-2021-32026.txt>)\n\n### Problem Description\n\nThe NATS server by default uses a restricted set of modern ciphersuites for TLS. This selection can be overridden through configuration. The defaults include just RSA and ECDSA with either AES/GCM with a SHA2 digest or ChaCha20/Poly1305.\n\nThe configuration system allows for extensive use of CLI options to override configuration settings. When using these to set a key/cert for TLS, the restricted ciphersuite settings were lost, enabling all ciphersuites supported by Go by default.\n\nNone of these additional ciphersuites are broken, so the NATS maintainers have fixed this in public git and the next release is not being hurried, nor is this security advisory embargoed.\n\n\n### Affected versions\n\nNATS Server:\n * All versions prior to 2.2.3\n * fixed with nats-io/nats-server commit ffccc2e1bd (2021-04-29)\n\n\n### Impact\n\nIf a server administrator chooses to start the nats-server with TLS configuration parameters provided on the command-line, then clients can negotiate TLS ciphersuites which were not expected.\n\n\n### Workaround\n\nUse a configuration file to set the TLS parameters instead of command-line options.\n\n\n### Solution\n\nUpgrade the NATS server.\n\n\n### Credits\n\nThis issue was identified and reported by SimCorp.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -55,9 +53,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "LOW",
"github_reviewed": true,
"github_reviewed_at": "2024-05-14T22:03:51Z",
@@ -3,9 +3,7 @@
"id": "GHSA-v84h-653v-4pq9",
"modified": "2024-05-21T15:39:20Z",
"published": "2024-05-03T17:34:21Z",
"aliases": [
],
"aliases": [],
"summary": "Some CORS middleware allow untrusted origins",
"details": "### Impact\n\nSome CORS middleware (more specifically those created by specifying two or more origin patterns whose hosts share a proper suffix) incorrectly allow some untrusted origins, thereby opening the door to cross-origin attacks from the untrusted origins in question.\n\nFor example, specifying origin patterns `https://foo.com` and `https://bar.com` (in that order) would yield a middleware that would incorrectly allow untrusted origin `https://barfoo.com`.\n\n### Patches\n\nPatched in v0.9.0.\n\n### Workarounds\n\nNone.\n",
"severity": [
@@ -57,9 +55,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "CRITICAL",
"github_reviewed": true,
"github_reviewed_at": "2024-05-03T17:34:21Z",
@@ -3,9 +3,7 @@
"id": "GHSA-vhxv-fg4m-p2w8",
"modified": "2024-05-21T15:38:55Z",
"published": "2024-05-03T17:34:17Z",
"aliases": [
],
"aliases": [],
"summary": "Some CORS middleware allow untrusted origins",
"details": "### Impact\n\nSome CORS middleware (more specifically those created by specifying two or more origin patterns whose hosts share a proper suffix) incorrectly allow some untrusted origins, thereby opening the door to cross-origin attacks from the untrusted origins in question.\n\nFor example, specifying origin patterns `https://foo.com` and `https://bar.com` (in that order) would yield a middleware that would incorrectly allow untrusted origin `https://barfoo.com`.\n\n### Patches\n\nPatched in v0.1.3.\n\n### Workarounds\n\nNone.",
"severity": [
@@ -54,9 +52,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "CRITICAL",
"github_reviewed": true,
"github_reviewed_at": "2024-05-03T17:34:17Z",
File diff suppressed because one or more lines are too long
@@ -3,9 +3,7 @@
"id": "GHSA-cxww-7g56-2vh6",
"modified": "2024-09-04T18:08:32Z",
"published": "2024-09-03T20:55:34Z",
"aliases": [
],
"aliases": [],
"summary": "@actions/download-artifact has an Arbitrary File Write via artifact extraction",
"details": "### Impact\n\nVersions of `actions/download-artifact` before 4.1.7 are vulnerable to arbitrary file write when downloading and extracting a specifically crafted artifact that contains path traversal filenames.\n\n### Patches\n\nUpgrade to version 4.1.7 or higher. Alternatively use 'v4' tag which points to the latest and secure version.\n\n### References\n\n- https://snyk.io/research/zip-slip-vulnerability\n- https://github.com/actions/download-artifact/releases/tag/v4.1.7\n\n### CVE\n\nCVE-2024-42471\n\n### Credits\n\nJustin Taft from Google",
"severity": [
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
],
"affected": [],
"references": [
{
"type": "ADVISORY",
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
}
],
"affected": [
],
"affected": [],
"references": [
{
"type": "ADVISORY",
@@ -39,9 +37,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L"
}
],
"affected": [
],
"affected": [],
"references": [
{
"type": "ADVISORY",
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L"
}
],
"affected": [
],
"affected": [],
"references": [
{
"type": "ADVISORY",
@@ -7,12 +7,8 @@
"CVE-2012-3259"
],
"details": "Unspecified vulnerability in a SOAP feature in HP SiteScope 11.10 through 11.12 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1461.",
"severity": [
],
"affected": [
],
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
@@ -28,9 +24,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -7,12 +7,8 @@
"CVE-2012-0714"
],
"details": "Cross-site request forgery (CSRF) vulnerability in IBM Maximo Asset Management 6.2 through 7.5, as used in SmartCloud Control Desk, Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB), allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.",
"severity": [
],
"affected": [
],
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
@@ -7,12 +7,8 @@
"CVE-2011-5210"
],
"details": "Directory traversal vulnerability in admin/preview.php in Limny 3.0.0 allows remote attackers to read arbitrary files via a ..%2F (encoded dot dot slash) in the theme parameter.",
"severity": [
],
"affected": [
],
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",

Some files were not shown because too many files have changed in this diff Show More