From 98fe17cf8001cec5f7ea0a06d0e07e6168651a71 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 13 Feb 2025 19:15:20 +0000 Subject: [PATCH] Publish Advisories GHSA-3gh6-v5v9-6v9j GHSA-5hj9-m76g-xrc8 GHSA-cgwf-w82q-5jrr GHSA-h6rp-mprm-xgcq GHSA-37gx-jqx9-fwmg GHSA-37vr-vmg4-jwpw GHSA-4265-ccf5-phj5 GHSA-4g9r-vxhx-9pgx GHSA-5jjq-8cvj-v6m9 GHSA-rmqp-mvv2-54c6 GHSA-w3w6-26f2-p474 --- .../09/GHSA-3gh6-v5v9-6v9j/GHSA-3gh6-v5v9-6v9j.json | 2 +- .../09/GHSA-5hj9-m76g-xrc8/GHSA-5hj9-m76g-xrc8.json | 4 ++-- .../09/GHSA-cgwf-w82q-5jrr/GHSA-cgwf-w82q-5jrr.json | 4 ++-- .../09/GHSA-h6rp-mprm-xgcq/GHSA-h6rp-mprm-xgcq.json | 2 +- .../02/GHSA-37gx-jqx9-fwmg/GHSA-37gx-jqx9-fwmg.json | 4 ++-- .../02/GHSA-37vr-vmg4-jwpw/GHSA-37vr-vmg4-jwpw.json | 11 ++++++++--- .../02/GHSA-4265-ccf5-phj5/GHSA-4265-ccf5-phj5.json | 4 ++-- .../02/GHSA-4g9r-vxhx-9pgx/GHSA-4g9r-vxhx-9pgx.json | 4 ++-- .../02/GHSA-5jjq-8cvj-v6m9/GHSA-5jjq-8cvj-v6m9.json | 9 +++++++-- .../02/GHSA-rmqp-mvv2-54c6/GHSA-rmqp-mvv2-54c6.json | 4 ++-- .../02/GHSA-w3w6-26f2-p474/GHSA-w3w6-26f2-p474.json | 4 ++-- 11 files changed, 31 insertions(+), 21 deletions(-) diff --git a/advisories/github-reviewed/2023/09/GHSA-3gh6-v5v9-6v9j/GHSA-3gh6-v5v9-6v9j.json b/advisories/github-reviewed/2023/09/GHSA-3gh6-v5v9-6v9j/GHSA-3gh6-v5v9-6v9j.json index e290e450f11..ff69c818bc8 100644 --- a/advisories/github-reviewed/2023/09/GHSA-3gh6-v5v9-6v9j/GHSA-3gh6-v5v9-6v9j.json +++ b/advisories/github-reviewed/2023/09/GHSA-3gh6-v5v9-6v9j/GHSA-3gh6-v5v9-6v9j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3gh6-v5v9-6v9j", - "modified": "2023-10-02T21:03:25Z", + "modified": "2025-02-13T19:12:59Z", "published": "2023-09-14T16:16:00Z", "aliases": [ "CVE-2023-36479" diff --git a/advisories/github-reviewed/2023/09/GHSA-5hj9-m76g-xrc8/GHSA-5hj9-m76g-xrc8.json b/advisories/github-reviewed/2023/09/GHSA-5hj9-m76g-xrc8/GHSA-5hj9-m76g-xrc8.json index c49e4764539..b1070547579 100644 --- a/advisories/github-reviewed/2023/09/GHSA-5hj9-m76g-xrc8/GHSA-5hj9-m76g-xrc8.json +++ b/advisories/github-reviewed/2023/09/GHSA-5hj9-m76g-xrc8/GHSA-5hj9-m76g-xrc8.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-5hj9-m76g-xrc8", - "modified": "2024-03-01T21:29:25Z", + "modified": "2025-02-13T19:13:06Z", "published": "2023-09-14T09:30:28Z", "aliases": [ "CVE-2023-41267" ], "summary": "Apache HDFS Provider error message suggested", - "details": "In the Apache Airflow HDFS Provider, versions prior to 4.1.1, a documentation info pointed users to an install incorrect pip package. As this package name was unclaimed, in theory, an attacker could claim this package and provide code that would be executed when this package was installed. The Airflow team has since taken ownership of the package (neutralizing the risk), and fixed the doc strings in version 4.1.1\n", + "details": "In the Apache Airflow HDFS Provider, versions prior to 4.1.1, a documentation info pointed users to an install incorrect pip package. As this package name was unclaimed, in theory, an attacker could claim this package and provide code that would be executed when this package was installed. The Airflow team has since taken ownership of the package (neutralizing the risk), and fixed the doc strings in version 4.1.1", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2023/09/GHSA-cgwf-w82q-5jrr/GHSA-cgwf-w82q-5jrr.json b/advisories/github-reviewed/2023/09/GHSA-cgwf-w82q-5jrr/GHSA-cgwf-w82q-5jrr.json index 9b6c08a0ded..fd9f93266a9 100644 --- a/advisories/github-reviewed/2023/09/GHSA-cgwf-w82q-5jrr/GHSA-cgwf-w82q-5jrr.json +++ b/advisories/github-reviewed/2023/09/GHSA-cgwf-w82q-5jrr/GHSA-cgwf-w82q-5jrr.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-cgwf-w82q-5jrr", - "modified": "2024-02-22T01:44:44Z", + "modified": "2025-02-13T19:13:03Z", "published": "2023-09-14T09:30:28Z", "aliases": [ "CVE-2023-42503" ], "summary": "Apache Commons Compress denial of service vulnerability", - "details": "Improper Input Validation, Uncontrolled Resource Consumption vulnerability in Apache Commons Compress in TAR parsing.This issue affects Apache Commons Compress: from 1.22 before 1.24.0.\n\nUsers are recommended to upgrade to version 1.24.0, which fixes the issue.\n\nA third party can create a malformed TAR file by manipulating file modification times headers, which when parsed with Apache Commons Compress, will cause a denial of service issue via CPU consumption.\n\nIn version 1.22 of Apache Commons Compress, support was added for file modification times with higher precision (issue # COMPRESS-612 [1]). The format for the PAX extended headers carrying this data consists of two numbers separated by a period [2], indicating seconds and subsecond precision (for example “1647221103.5998539”). The impacted fields are “atime”, “ctime”, “mtime” and “LIBARCHIVE.creationtime”. No input validation is performed prior to the parsing of header values.\n\nParsing of these numbers uses the BigDecimal [3] class from the JDK which has a publicly known algorithmic complexity issue when doing operations on large numbers, causing denial of service (see issue # JDK-6560193 [4]). A third party can manipulate file time headers in a TAR file by placing a number with a very long fraction (300,000 digits) or a number with exponent notation (such as “9e9999999”) within a file modification time header, and the parsing of files with these headers will take hours instead of seconds, leading to a denial of service via exhaustion of CPU resources. This issue is similar to CVE-2012-2098 [5].\n\n[1]: https://issues.apache.org/jira/browse/COMPRESS-612 \n[2]: https://pubs.opengroup.org/onlinepubs/9699919799/utilities/pax.html#tag_20_92_13_05 \n[3]: https://docs.oracle.com/javase/8/docs/api/java/math/BigDecimal.html \n[4]: https://bugs.openjdk.org/browse/JDK-6560193 \n[5]: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2098 \n\nOnly applications using CompressorStreamFactory class (with auto-detection of file types), TarArchiveInputStream and TarFile classes to parse TAR files are impacted. Since this code was introduced in v1.22, only that version and later versions are impacted.\n\n", + "details": "Improper Input Validation, Uncontrolled Resource Consumption vulnerability in Apache Commons Compress in TAR parsing.This issue affects Apache Commons Compress: from 1.22 before 1.24.0.\n\nUsers are recommended to upgrade to version 1.24.0, which fixes the issue.\n\nA third party can create a malformed TAR file by manipulating file modification times headers, which when parsed with Apache Commons Compress, will cause a denial of service issue via CPU consumption.\n\nIn version 1.22 of Apache Commons Compress, support was added for file modification times with higher precision (issue # COMPRESS-612 [1]). The format for the PAX extended headers carrying this data consists of two numbers separated by a period [2], indicating seconds and subsecond precision (for example “1647221103.5998539”). The impacted fields are “atime”, “ctime”, “mtime” and “LIBARCHIVE.creationtime”. No input validation is performed prior to the parsing of header values.\n\nParsing of these numbers uses the BigDecimal [3] class from the JDK which has a publicly known algorithmic complexity issue when doing operations on large numbers, causing denial of service (see issue # JDK-6560193 [4]). A third party can manipulate file time headers in a TAR file by placing a number with a very long fraction (300,000 digits) or a number with exponent notation (such as “9e9999999”) within a file modification time header, and the parsing of files with these headers will take hours instead of seconds, leading to a denial of service via exhaustion of CPU resources. This issue is similar to CVE-2012-2098 [5].\n\n[1]: https://issues.apache.org/jira/browse/COMPRESS-612 \n[2]: https://pubs.opengroup.org/onlinepubs/9699919799/utilities/pax.html#tag_20_92_13_05 \n[3]: https://docs.oracle.com/javase/8/docs/api/java/math/BigDecimal.html \n[4]: https://bugs.openjdk.org/browse/JDK-6560193 \n[5]: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2098 \n\nOnly applications using CompressorStreamFactory class (with auto-detection of file types), TarArchiveInputStream and TarFile classes to parse TAR files are impacted. Since this code was introduced in v1.22, only that version and later versions are impacted.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2023/09/GHSA-h6rp-mprm-xgcq/GHSA-h6rp-mprm-xgcq.json b/advisories/github-reviewed/2023/09/GHSA-h6rp-mprm-xgcq/GHSA-h6rp-mprm-xgcq.json index c47993c53d6..8fa6659705e 100644 --- a/advisories/github-reviewed/2023/09/GHSA-h6rp-mprm-xgcq/GHSA-h6rp-mprm-xgcq.json +++ b/advisories/github-reviewed/2023/09/GHSA-h6rp-mprm-xgcq/GHSA-h6rp-mprm-xgcq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h6rp-mprm-xgcq", - "modified": "2024-10-09T21:24:09Z", + "modified": "2025-02-13T19:13:09Z", "published": "2023-09-21T17:06:37Z", "aliases": [ "CVE-2023-42457" diff --git a/advisories/github-reviewed/2024/02/GHSA-37gx-jqx9-fwmg/GHSA-37gx-jqx9-fwmg.json b/advisories/github-reviewed/2024/02/GHSA-37gx-jqx9-fwmg/GHSA-37gx-jqx9-fwmg.json index dd5ba092d16..277b8045744 100644 --- a/advisories/github-reviewed/2024/02/GHSA-37gx-jqx9-fwmg/GHSA-37gx-jqx9-fwmg.json +++ b/advisories/github-reviewed/2024/02/GHSA-37gx-jqx9-fwmg/GHSA-37gx-jqx9-fwmg.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-37gx-jqx9-fwmg", - "modified": "2024-12-02T20:28:57Z", + "modified": "2025-02-13T19:12:56Z", "published": "2024-02-20T12:31:00Z", "aliases": [ "CVE-2023-49250" ], "summary": "Improper Certificate Validation in Apache DolphinScheduler", - "details": "Because the HttpUtils class did not verify certificates, an attacker that could perform a Man-in-the-Middle (MITM) attack on outgoing https connections could impersonate the server.\n\nThis issue affects Apache DolphinScheduler: before 3.2.1.\n\nUsers are recommended to upgrade to version 3.2.1, which fixes the issue.\n\n", + "details": "Because the HttpUtils class did not verify certificates, an attacker that could perform a Man-in-the-Middle (MITM) attack on outgoing https connections could impersonate the server.\n\nThis issue affects Apache DolphinScheduler: before 3.2.1.\n\nUsers are recommended to upgrade to version 3.2.1, which fixes the issue.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2024/02/GHSA-37vr-vmg4-jwpw/GHSA-37vr-vmg4-jwpw.json b/advisories/github-reviewed/2024/02/GHSA-37vr-vmg4-jwpw/GHSA-37vr-vmg4-jwpw.json index 50ba0638d3a..5fde843b7c2 100644 --- a/advisories/github-reviewed/2024/02/GHSA-37vr-vmg4-jwpw/GHSA-37vr-vmg4-jwpw.json +++ b/advisories/github-reviewed/2024/02/GHSA-37vr-vmg4-jwpw/GHSA-37vr-vmg4-jwpw.json @@ -1,14 +1,19 @@ { "schema_version": "1.4.0", "id": "GHSA-37vr-vmg4-jwpw", - "modified": "2024-02-09T21:53:14Z", + "modified": "2025-02-13T19:14:52Z", "published": "2024-02-09T18:31:07Z", "aliases": [ "CVE-2023-50386" ], "summary": "Apache Solr: Backup/Restore APIs allow for deployment of executables in malicious ConfigSets ", "details": "Improper Control of Dynamically-Managed Code Resources, Unrestricted Upload of File with Dangerous Type, Inclusion of Functionality from Untrusted Control Sphere vulnerability in Apache Solr.This issue affects Apache Solr from 6.0.0 through 8.11.2, from 9.0.0 before 9.4.1.\n\nIn the affected versions, Solr ConfigSets accepted Java jar and class files to be uploaded through the ConfigSets API.\nWhen backing up Solr Collections, these configSet files would be saved to disk when using the LocalFileSystemRepository (the default for backups).\nIf the backup was saved to a directory that Solr uses in its ClassPath/ClassLoaders, then the jar and class files would be available to use with any ConfigSet, trusted or untrusted.\n\nWhen Solr is run in a secure way (Authorization enabled), as is strongly suggested, this vulnerability is limited to extending the Backup permissions with the ability to add libraries.\nUsers are recommended to upgrade to version 8.11.3 or 9.4.1, which fix the issue.\nIn these versions, the following protections have been added:\n\n * Users are no longer able to upload files to a configSet that could be executed via a Java ClassLoader.\n * The Backup API restricts saving backups to directories that are used in the ClassLoader.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [ { "package": { @@ -87,7 +92,7 @@ "cwe_ids": [ "CWE-434" ], - "severity": "MODERATE", + "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2024-02-09T21:53:13Z", "nvd_published_at": "2024-02-09T18:15:08Z" diff --git a/advisories/github-reviewed/2024/02/GHSA-4265-ccf5-phj5/GHSA-4265-ccf5-phj5.json b/advisories/github-reviewed/2024/02/GHSA-4265-ccf5-phj5/GHSA-4265-ccf5-phj5.json index 49cb26571df..84e9472c932 100644 --- a/advisories/github-reviewed/2024/02/GHSA-4265-ccf5-phj5/GHSA-4265-ccf5-phj5.json +++ b/advisories/github-reviewed/2024/02/GHSA-4265-ccf5-phj5/GHSA-4265-ccf5-phj5.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-4265-ccf5-phj5", - "modified": "2024-08-27T15:27:08Z", + "modified": "2025-02-13T19:13:31Z", "published": "2024-02-19T09:30:52Z", "aliases": [ "CVE-2024-26308" ], "summary": "Apache Commons Compress: OutOfMemoryError unpacking broken Pack200 file", - "details": "Allocation of Resources Without Limits or Throttling vulnerability in Apache Commons Compress. This issue affects Apache Commons Compress: from 1.21 before 1.26.\n\nUsers are recommended to upgrade to version 1.26, which fixes the issue.\n\n", + "details": "Allocation of Resources Without Limits or Throttling vulnerability in Apache Commons Compress. This issue affects Apache Commons Compress: from 1.21 before 1.26.\n\nUsers are recommended to upgrade to version 1.26, which fixes the issue.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2024/02/GHSA-4g9r-vxhx-9pgx/GHSA-4g9r-vxhx-9pgx.json b/advisories/github-reviewed/2024/02/GHSA-4g9r-vxhx-9pgx/GHSA-4g9r-vxhx-9pgx.json index f93fb7d8c8a..12db746af6e 100644 --- a/advisories/github-reviewed/2024/02/GHSA-4g9r-vxhx-9pgx/GHSA-4g9r-vxhx-9pgx.json +++ b/advisories/github-reviewed/2024/02/GHSA-4g9r-vxhx-9pgx/GHSA-4g9r-vxhx-9pgx.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-4g9r-vxhx-9pgx", - "modified": "2025-01-24T15:53:12Z", + "modified": "2025-02-13T19:13:39Z", "published": "2024-02-19T09:30:50Z", "aliases": [ "CVE-2024-25710" ], "summary": "Apache Commons Compress: Denial of service caused by an infinite loop for a corrupted DUMP file", - "details": "Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Commons Compress. This issue affects Apache Commons Compress: from 1.3 through 1.25.0.\n\nUsers are recommended to upgrade to version 1.26.0 which fixes the issue.\n\n", + "details": "Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Apache Commons Compress. This issue affects Apache Commons Compress: from 1.3 through 1.25.0.\n\nUsers are recommended to upgrade to version 1.26.0 which fixes the issue.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2024/02/GHSA-5jjq-8cvj-v6m9/GHSA-5jjq-8cvj-v6m9.json b/advisories/github-reviewed/2024/02/GHSA-5jjq-8cvj-v6m9/GHSA-5jjq-8cvj-v6m9.json index edbfe603695..488f6955ed7 100644 --- a/advisories/github-reviewed/2024/02/GHSA-5jjq-8cvj-v6m9/GHSA-5jjq-8cvj-v6m9.json +++ b/advisories/github-reviewed/2024/02/GHSA-5jjq-8cvj-v6m9/GHSA-5jjq-8cvj-v6m9.json @@ -1,14 +1,19 @@ { "schema_version": "1.4.0", "id": "GHSA-5jjq-8cvj-v6m9", - "modified": "2024-02-20T23:58:08Z", + "modified": "2025-02-13T19:14:15Z", "published": "2024-02-19T06:30:33Z", "aliases": [ "CVE-2024-26318" ], "summary": "Cross-site Scripting in Serenity", "details": "Serenity before 6.8.0 allows XSS via an email link because LoginPage.tsx permits return URLs that do not begin with a / character.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [ { "package": { diff --git a/advisories/github-reviewed/2024/02/GHSA-rmqp-mvv2-54c6/GHSA-rmqp-mvv2-54c6.json b/advisories/github-reviewed/2024/02/GHSA-rmqp-mvv2-54c6/GHSA-rmqp-mvv2-54c6.json index 552d5a063d6..a7c32ec83a6 100644 --- a/advisories/github-reviewed/2024/02/GHSA-rmqp-mvv2-54c6/GHSA-rmqp-mvv2-54c6.json +++ b/advisories/github-reviewed/2024/02/GHSA-rmqp-mvv2-54c6/GHSA-rmqp-mvv2-54c6.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-rmqp-mvv2-54c6", - "modified": "2024-11-18T16:26:36Z", + "modified": "2025-02-13T19:12:50Z", "published": "2024-02-22T12:30:56Z", "aliases": [ "CVE-2024-22393" ], "summary": "Apache Answer Unrestricted Upload of File with Dangerous Type vulnerability", - "details": "Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer through 1.2.1.\n\nPixel Flood Attack by uploading large pixel files will cause server out of memory. A logged-in user can cause such an attack by uploading an image when posting content.\n\nUsers are recommended to upgrade to version 1.2.5, which fixes the issue.\n\n", + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer through 1.2.1.\n\nPixel Flood Attack by uploading large pixel files will cause server out of memory. A logged-in user can cause such an attack by uploading an image when posting content.\n\nUsers are recommended to upgrade to version 1.2.5, which fixes the issue.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2024/02/GHSA-w3w6-26f2-p474/GHSA-w3w6-26f2-p474.json b/advisories/github-reviewed/2024/02/GHSA-w3w6-26f2-p474/GHSA-w3w6-26f2-p474.json index c60233ad030..f92c016486f 100644 --- a/advisories/github-reviewed/2024/02/GHSA-w3w6-26f2-p474/GHSA-w3w6-26f2-p474.json +++ b/advisories/github-reviewed/2024/02/GHSA-w3w6-26f2-p474/GHSA-w3w6-26f2-p474.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-w3w6-26f2-p474", - "modified": "2024-03-15T12:30:36Z", + "modified": "2025-02-13T19:13:23Z", "published": "2024-02-20T09:30:30Z", "aliases": [ "CVE-2024-22234" ], "summary": "Broken Access Control in Spring Security With Direct Use of isFullyAuthenticated", - "details": "In Spring Security, versions 6.1.x prior to 6.1.7 and versions 6.2.x prior to 6.2.2, an application is vulnerable to broken access control when it directly uses the AuthenticationTrustResolver.isFullyAuthenticated(Authentication) method.\n\nSpecifically, an application is vulnerable if:\n\n * The application uses AuthenticationTrustResolver.isFullyAuthenticated(Authentication) directly and a null authentication parameter is passed to it resulting in an erroneous true return value.\n\n\nAn application is not vulnerable if any of the following is true:\n\n * The application does not use AuthenticationTrustResolver.isFullyAuthenticated(Authentication) directly.\n * The application does not pass null to AuthenticationTrustResolver.isFullyAuthenticated\n * The application only uses isFullyAuthenticated via Method Security https://docs.spring.io/spring-security/reference/servlet/authorization/method-security.html  or HTTP Request Security https://docs.spring.io/spring-security/reference/servlet/authorization/authorize-http-requests.html \n\n\n\n", + "details": "In Spring Security, versions 6.1.x prior to 6.1.7 and versions 6.2.x prior to 6.2.2, an application is vulnerable to broken access control when it directly uses the AuthenticationTrustResolver.isFullyAuthenticated(Authentication) method.\n\nSpecifically, an application is vulnerable if:\n\n * The application uses AuthenticationTrustResolver.isFullyAuthenticated(Authentication) directly and a null authentication parameter is passed to it resulting in an erroneous true return value.\n\n\nAn application is not vulnerable if any of the following is true:\n\n * The application does not use AuthenticationTrustResolver.isFullyAuthenticated(Authentication) directly.\n * The application does not pass null to AuthenticationTrustResolver.isFullyAuthenticated\n * The application only uses isFullyAuthenticated via Method Security https://docs.spring.io/spring-security/reference/servlet/authorization/method-security.html  or HTTP Request Security https://docs.spring.io/spring-security/reference/servlet/authorization/authorize-http-requests.html", "severity": [ { "type": "CVSS_V3",