Publish Advisories

GHSA-3xq2-w6j4-c99r
GHSA-5777-rcjj-9p22
GHSA-3xq2-w6j4-c99r
This commit is contained in:
advisory-database[bot]
2024-09-16 20:21:19 +00:00
parent 05d1792faf
commit 9821b41a36
3 changed files with 118 additions and 39 deletions
@@ -0,0 +1,87 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3xq2-w6j4-c99r",
"modified": "2024-09-16T20:19:35Z",
"published": "2024-09-16T14:37:28Z",
"aliases": [
"CVE-2024-22399"
],
"summary": "Apache Seata Deserialization of Untrusted Data vulnerability",
"details": "Deserialization of Untrusted Data vulnerability in Apache Seata. \n\nWhen developers disable authentication on the Seata-Server and do not use the Seata client SDK dependencies, they may construct uncontrolled serialized malicious requests by directly sending bytecode based on the Seata private protocol.\n\nThis issue affects Apache Seata: 2.0.0, from 1.0.0 through 1.8.0.\n\nUsers are recommended to upgrade to version 2.1.0/1.8.1, which fixes the issue.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
}
],
"affected": [
{
"package": {
"ecosystem": "Maven",
"name": "org.apache.seata:seata-core"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "2.0.0"
},
{
"fixed": "2.1.0"
}
]
}
],
"versions": [
"2.0.0"
]
},
{
"package": {
"ecosystem": "Maven",
"name": "org.apache.seata:seata-core"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "1.0.0"
},
{
"fixed": "1.8.1"
}
]
}
]
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22399"
},
{
"type": "PACKAGE",
"url": "https://github.com/apache/incubator-seata"
},
{
"type": "WEB",
"url": "https://lists.apache.org/thread/91nzzlxyj4nmks85gbzwkkjtbmnmlkc4"
}
],
"database_specific": {
"cwe_ids": [
"CWE-502"
],
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2024-09-16T20:18:41Z",
"nvd_published_at": "2024-09-16T12:15:02Z"
}
}
@@ -1,26 +1,53 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5777-rcjj-9p22",
"modified": "2024-09-16T15:32:46Z",
"modified": "2024-09-16T20:20:49Z",
"published": "2024-09-16T15:32:46Z",
"aliases": [
"CVE-2024-39772"
],
"summary": "Mattermost Desktop App fails to safeguard screen capture functionality",
"details": "Mattermost Desktop App versions <=5.8.0 fail to safeguard screen capture functionality which allows an attacker to silently capture high-quality screenshots via JavaScript APIs.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
}
],
"affected": [
{
"package": {
"ecosystem": "npm",
"name": "mattermost-desktop"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "5.9.0"
}
]
}
]
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39772"
},
{
"type": "PACKAGE",
"url": "https://github.com/mattermost/desktop"
},
{
"type": "WEB",
"url": "https://mattermost.com/security-updates"
@@ -31,8 +58,8 @@
"CWE-284"
],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"github_reviewed": true,
"github_reviewed_at": "2024-09-16T20:20:49Z",
"nvd_published_at": "2024-09-16T15:15:16Z"
}
}
@@ -1,35 +0,0 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3xq2-w6j4-c99r",
"modified": "2024-09-16T14:37:28Z",
"published": "2024-09-16T14:37:28Z",
"aliases": [
"CVE-2024-22399"
],
"details": "Deserialization of Untrusted Data vulnerability in Apache Seata. \n\nWhen developers disable authentication on the Seata-Server and do not use the Seata client SDK dependencies, they may construct uncontrolled serialized malicious requests by directly sending bytecode based on the Seata private protocol.\n\nThis issue affects Apache Seata: 2.0.0, from 1.0.0 through 1.8.0.\n\nUsers are recommended to upgrade to version 2.1.0/1.8.1, which fixes the issue.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22399"
},
{
"type": "WEB",
"url": "https://lists.apache.org/thread/91nzzlxyj4nmks85gbzwkkjtbmnmlkc4"
}
],
"database_specific": {
"cwe_ids": [
"CWE-502"
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-16T12:15:02Z"
}
}