From 979aaa900f99ab6816f5915598e35619b5d3c340 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 3 Oct 2024 12:32:14 +0000 Subject: [PATCH] Publish Advisories GHSA-78wr-2p64-hpwj GHSA-r7pg-v2c8-mfg3 --- .../GHSA-78wr-2p64-hpwj.json | 35 +++++++++++++++++++ .../GHSA-r7pg-v2c8-mfg3.json | 35 +++++++++++++++++++ 2 files changed, 70 insertions(+) create mode 100644 advisories/unreviewed/2024/10/GHSA-78wr-2p64-hpwj/GHSA-78wr-2p64-hpwj.json create mode 100644 advisories/unreviewed/2024/10/GHSA-r7pg-v2c8-mfg3/GHSA-r7pg-v2c8-mfg3.json diff --git a/advisories/unreviewed/2024/10/GHSA-78wr-2p64-hpwj/GHSA-78wr-2p64-hpwj.json b/advisories/unreviewed/2024/10/GHSA-78wr-2p64-hpwj/GHSA-78wr-2p64-hpwj.json new file mode 100644 index 00000000000..4869e605c12 --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-78wr-2p64-hpwj/GHSA-78wr-2p64-hpwj.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-78wr-2p64-hpwj", + "modified": "2024-10-03T12:30:48Z", + "published": "2024-10-03T12:30:48Z", + "aliases": [ + "CVE-2024-47554" + ], + "details": "Uncontrolled Resource Consumption vulnerability in Apache Commons IO.\n\nThe org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input.\n\n\nThis issue affects Apache Commons IO: from 2.0 before 2.14.0.\n\nUsers are recommended to upgrade to version 2.14.0 or later, which fixes the issue.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47554" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/6ozr91rr9cj5lm0zyhv30bsp317hk5z1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-03T12:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-r7pg-v2c8-mfg3/GHSA-r7pg-v2c8-mfg3.json b/advisories/unreviewed/2024/10/GHSA-r7pg-v2c8-mfg3/GHSA-r7pg-v2c8-mfg3.json new file mode 100644 index 00000000000..46d70da2b7e --- /dev/null +++ b/advisories/unreviewed/2024/10/GHSA-r7pg-v2c8-mfg3/GHSA-r7pg-v2c8-mfg3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r7pg-v2c8-mfg3", + "modified": "2024-10-03T12:30:48Z", + "published": "2024-10-03T12:30:48Z", + "aliases": [ + "CVE-2024-47561" + ], + "details": "Schema parsing in the Java SDK of Apache Avro 1.11.3 and previous versions allows bad actors to execute arbitrary code.\nUsers are recommended to upgrade to version 1.11.4  or 1.12.0, which fix this issue.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47561" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/c2v7mhqnmq0jmbwxqq3r5jbj1xg43h5x" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-10-03T11:15:13Z" + } +} \ No newline at end of file