From a1ad5c190d059fba0d32f1af717153da9795f974 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 14 May 2024 21:32:50 +0000 Subject: [PATCH] Publish Advisories GHSA-479j-jf2p-38pg GHSA-4jp4-3c62-r8jv GHSA-4xw6-hj5p-4j79 GHSA-9xgv-6v35-mmcj GHSA-c8w9-83vg-r8vv GHSA-cc77-5vw4-7pwg GHSA-g6x3-55qv-x6p2 GHSA-h737-q6g6-8wr6 GHSA-j4mh-9wq6-8rg6 GHSA-j6mr-cm6x-h6jg GHSA-pwrj-f53c-f89j GHSA-wxx2-gqvv-34hx GHSA-274c-rx2j-2v3x GHSA-274c-rx2j-2v3x --- .../GHSA-479j-jf2p-38pg.json | 43 +++++- .../GHSA-4jp4-3c62-r8jv.json | 39 ++++- .../GHSA-4xw6-hj5p-4j79.json | 39 ++++- .../GHSA-9xgv-6v35-mmcj.json | 47 +++++- .../GHSA-c8w9-83vg-r8vv.json | 43 +++++- .../GHSA-cc77-5vw4-7pwg.json | 47 +++++- .../GHSA-g6x3-55qv-x6p2.json | 43 +++++- .../GHSA-h737-q6g6-8wr6.json | 39 ++++- .../GHSA-j4mh-9wq6-8rg6.json | 43 +++++- .../GHSA-j6mr-cm6x-h6jg.json | 35 ++++- .../GHSA-pwrj-f53c-f89j.json | 45 +++++- .../GHSA-wxx2-gqvv-34hx.json | 39 ++++- .../GHSA-274c-rx2j-2v3x.json | 143 ++++++++++++++++++ .../GHSA-274c-rx2j-2v3x.json | 46 ------ 14 files changed, 596 insertions(+), 95 deletions(-) rename advisories/{unreviewed => github-reviewed}/2022/05/GHSA-479j-jf2p-38pg/GHSA-479j-jf2p-38pg.json (58%) rename advisories/{unreviewed => github-reviewed}/2022/05/GHSA-4jp4-3c62-r8jv/GHSA-4jp4-3c62-r8jv.json (57%) rename advisories/{unreviewed => github-reviewed}/2022/05/GHSA-4xw6-hj5p-4j79/GHSA-4xw6-hj5p-4j79.json (58%) rename advisories/{unreviewed => github-reviewed}/2022/05/GHSA-9xgv-6v35-mmcj/GHSA-9xgv-6v35-mmcj.json (50%) rename advisories/{unreviewed => github-reviewed}/2022/05/GHSA-c8w9-83vg-r8vv/GHSA-c8w9-83vg-r8vv.json (63%) rename advisories/{unreviewed => github-reviewed}/2022/05/GHSA-cc77-5vw4-7pwg/GHSA-cc77-5vw4-7pwg.json (60%) rename advisories/{unreviewed => github-reviewed}/2022/05/GHSA-g6x3-55qv-x6p2/GHSA-g6x3-55qv-x6p2.json (64%) rename advisories/{unreviewed => github-reviewed}/2022/05/GHSA-h737-q6g6-8wr6/GHSA-h737-q6g6-8wr6.json (57%) rename advisories/{unreviewed => github-reviewed}/2022/05/GHSA-j4mh-9wq6-8rg6/GHSA-j4mh-9wq6-8rg6.json (60%) rename advisories/{unreviewed => github-reviewed}/2022/05/GHSA-j6mr-cm6x-h6jg/GHSA-j6mr-cm6x-h6jg.json (64%) rename advisories/{unreviewed => github-reviewed}/2022/05/GHSA-pwrj-f53c-f89j/GHSA-pwrj-f53c-f89j.json (53%) rename advisories/{unreviewed => github-reviewed}/2022/05/GHSA-wxx2-gqvv-34hx/GHSA-wxx2-gqvv-34hx.json (62%) create mode 100644 advisories/github-reviewed/2023/01/GHSA-274c-rx2j-2v3x/GHSA-274c-rx2j-2v3x.json delete mode 100644 advisories/unreviewed/2023/01/GHSA-274c-rx2j-2v3x/GHSA-274c-rx2j-2v3x.json diff --git a/advisories/unreviewed/2022/05/GHSA-479j-jf2p-38pg/GHSA-479j-jf2p-38pg.json b/advisories/github-reviewed/2022/05/GHSA-479j-jf2p-38pg/GHSA-479j-jf2p-38pg.json similarity index 58% rename from advisories/unreviewed/2022/05/GHSA-479j-jf2p-38pg/GHSA-479j-jf2p-38pg.json rename to advisories/github-reviewed/2022/05/GHSA-479j-jf2p-38pg/GHSA-479j-jf2p-38pg.json index 70436b6ed2b..aaa3abc95a0 100644 --- a/advisories/unreviewed/2022/05/GHSA-479j-jf2p-38pg/GHSA-479j-jf2p-38pg.json +++ b/advisories/github-reviewed/2022/05/GHSA-479j-jf2p-38pg/GHSA-479j-jf2p-38pg.json @@ -1,27 +1,62 @@ { "schema_version": "1.4.0", "id": "GHSA-479j-jf2p-38pg", - "modified": "2022-05-17T03:05:47Z", + "modified": "2024-05-14T21:32:14Z", "published": "2022-05-17T03:05:47Z", "aliases": [ "CVE-2014-5356" ], + "summary": "OpenStack Glance improper validation of the image_size_cap configuration option", "details": "OpenStack Image Registry and Delivery Service (Glance) before 2013.2.4, 2014.x before 2014.1.3, and Juno before Juno-3, when using the V2 API, does not properly enforce the image_size_cap configuration option, which allows remote authenticated users to cause a denial of service (disk consumption) by uploading a large image.", "severity": [ ], "affected": [ - + { + "package": { + "ecosystem": "PyPI", + "name": "glance" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "11.0.0a0" + } + ] + } + ] + } ], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2014-5356" }, + { + "type": "WEB", + "url": "https://github.com/openstack/glance/commit/12f43cfed5a47cd16f08b7dad2424da0fc362e47" + }, + { + "type": "WEB", + "url": "https://github.com/openstack/glance/commit/31a4d1852a0c27bac5757c192f300f051229a312" + }, + { + "type": "WEB", + "url": "https://github.com/openstack/glance/commit/92ab00fca6926eaf3f7f92a955a5e07140063718" + }, { "type": "WEB", "url": "https://bugs.launchpad.net/glance/+bug/1315321" }, + { + "type": "PACKAGE", + "url": "https://github.com/openstack/glance" + }, { "type": "WEB", "url": "http://rhn.redhat.com/errata/RHSA-2014-1337.html" @@ -52,8 +87,8 @@ ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-05-14T21:32:14Z", "nvd_published_at": "2014-08-25T14:55:00Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-4jp4-3c62-r8jv/GHSA-4jp4-3c62-r8jv.json b/advisories/github-reviewed/2022/05/GHSA-4jp4-3c62-r8jv/GHSA-4jp4-3c62-r8jv.json similarity index 57% rename from advisories/unreviewed/2022/05/GHSA-4jp4-3c62-r8jv/GHSA-4jp4-3c62-r8jv.json rename to advisories/github-reviewed/2022/05/GHSA-4jp4-3c62-r8jv/GHSA-4jp4-3c62-r8jv.json index 44206c9843d..66d64bd6093 100644 --- a/advisories/unreviewed/2022/05/GHSA-4jp4-3c62-r8jv/GHSA-4jp4-3c62-r8jv.json +++ b/advisories/github-reviewed/2022/05/GHSA-4jp4-3c62-r8jv/GHSA-4jp4-3c62-r8jv.json @@ -1,27 +1,58 @@ { "schema_version": "1.4.0", "id": "GHSA-4jp4-3c62-r8jv", - "modified": "2022-05-17T03:09:50Z", + "modified": "2024-05-14T21:32:17Z", "published": "2022-05-17T03:09:50Z", "aliases": [ "CVE-2015-1881" ], + "summary": "OpenStack Glance Denial of service by creating a large number of images ", "details": "OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authenticated users to cause a denial of service (disk consumption) by creating a large number of images using the task v2 API and then deleting them, a different vulnerability than CVE-2014-9684.", "severity": [ ], "affected": [ - + { + "package": { + "ecosystem": "PyPI", + "name": "glance" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "11.0.0a0" + } + ] + } + ] + } ], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2015-1881" }, + { + "type": "WEB", + "url": "https://github.com/openstack/glance/commit/25a722e614eacc47e4658f0bca6343fa52f7d03f" + }, + { + "type": "WEB", + "url": "https://github.com/openstack/glance/commit/78b5b0a9575cd5e9c4543ec0e8fd6072af1f0ebb" + }, { "type": "WEB", "url": "https://bugs.launchpad.net/glance/+bug/1420696" }, + { + "type": "PACKAGE", + "url": "https://github.com/openstack/glance" + }, { "type": "WEB", "url": "http://lists.openstack.org/pipermail/openstack-announce/2015-February/000336.html" @@ -40,8 +71,8 @@ ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-05-14T21:32:17Z", "nvd_published_at": "2015-02-24T15:59:00Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-4xw6-hj5p-4j79/GHSA-4xw6-hj5p-4j79.json b/advisories/github-reviewed/2022/05/GHSA-4xw6-hj5p-4j79/GHSA-4xw6-hj5p-4j79.json similarity index 58% rename from advisories/unreviewed/2022/05/GHSA-4xw6-hj5p-4j79/GHSA-4xw6-hj5p-4j79.json rename to advisories/github-reviewed/2022/05/GHSA-4xw6-hj5p-4j79/GHSA-4xw6-hj5p-4j79.json index daafc29231b..f6df2ebe896 100644 --- a/advisories/unreviewed/2022/05/GHSA-4xw6-hj5p-4j79/GHSA-4xw6-hj5p-4j79.json +++ b/advisories/github-reviewed/2022/05/GHSA-4xw6-hj5p-4j79/GHSA-4xw6-hj5p-4j79.json @@ -1,27 +1,58 @@ { "schema_version": "1.4.0", "id": "GHSA-4xw6-hj5p-4j79", - "modified": "2022-05-17T04:50:15Z", + "modified": "2024-05-14T21:32:23Z", "published": "2022-05-17T04:50:15Z", "aliases": [ "CVE-2014-1948" ], + "summary": "OpenStack Glance sensitive information disclosure via logs", "details": "OpenStack Image Registry and Delivery Service (Glance) 2013.2 through 2013.2.1 and Icehouse before icehouse-2 logs a URL containing the Swift store backend password when authentication fails and WARNING level logging is enabled, which allows local users to obtain sensitive information by reading the log.", "severity": [ ], "affected": [ - + { + "package": { + "ecosystem": "PyPI", + "name": "glance" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "11.0.0a0" + } + ] + } + ] + } ], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2014-1948" }, + { + "type": "WEB", + "url": "https://github.com/openstack/glance/commit/108f0e04ad2ed3dc287f1b71b987a7e9d66072ba" + }, + { + "type": "WEB", + "url": "https://github.com/openstack/glance/commit/f6e41e9c0ff3aa9ee57b8c8ed8c789f1aff019bc" + }, { "type": "WEB", "url": "https://bugs.launchpad.net/glance/+bug/1275062" }, + { + "type": "PACKAGE", + "url": "https://github.com/openstack/glance" + }, { "type": "WEB", "url": "http://rhn.redhat.com/errata/RHSA-2014-0229.html" @@ -44,8 +75,8 @@ ], "severity": "LOW", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-05-14T21:32:23Z", "nvd_published_at": "2014-02-14T15:55:00Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-9xgv-6v35-mmcj/GHSA-9xgv-6v35-mmcj.json b/advisories/github-reviewed/2022/05/GHSA-9xgv-6v35-mmcj/GHSA-9xgv-6v35-mmcj.json similarity index 50% rename from advisories/unreviewed/2022/05/GHSA-9xgv-6v35-mmcj/GHSA-9xgv-6v35-mmcj.json rename to advisories/github-reviewed/2022/05/GHSA-9xgv-6v35-mmcj/GHSA-9xgv-6v35-mmcj.json index 67a5af67986..4c0ea5c5da8 100644 --- a/advisories/unreviewed/2022/05/GHSA-9xgv-6v35-mmcj/GHSA-9xgv-6v35-mmcj.json +++ b/advisories/github-reviewed/2022/05/GHSA-9xgv-6v35-mmcj/GHSA-9xgv-6v35-mmcj.json @@ -1,27 +1,66 @@ { "schema_version": "1.4.0", "id": "GHSA-9xgv-6v35-mmcj", - "modified": "2022-05-14T02:10:10Z", + "modified": "2024-05-14T21:30:51Z", "published": "2022-05-14T02:10:10Z", "aliases": [ "CVE-2013-2161" ], + "summary": "OpenStack Swift Unchecked user input in XML responses", "details": "XML injection vulnerability in account/utils.py in OpenStack Swift Folsom, Grizzly, and Havana allows attackers to trigger invalid or spoofed Swift responses via an account name.", "severity": [ ], "affected": [ - + { + "package": { + "ecosystem": "PyPI", + "name": "swift" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.9.0" + } + ] + } + ] + } ], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2013-2161" }, + { + "type": "WEB", + "url": "https://github.com/openstack/swift/commit/6659382c4fa348e1ebbce2424968dd7267ea1db1" + }, + { + "type": "WEB", + "url": "https://github.com/openstack/swift/commit/8f9b135e0a16478a628f20224ce5babe62d4aaba" + }, { "type": "WEB", "url": "https://bugs.launchpad.net/swift/+bug/1183884" }, + { + "type": "PACKAGE", + "url": "https://github.com/openstack/swift" + }, + { + "type": "WEB", + "url": "http://github.com/openstack/swift/commit/4eed6bf5b5028409f730be97ddcfb6bfa893c976" + }, + { + "type": "WEB", + "url": "http://github.com/openstack/swift/commit/92d7eadd328797d392758c79e258c8455874c80e" + }, { "type": "WEB", "url": "http://lists.opensuse.org/opensuse-updates/2013-07/msg00021.html" @@ -44,8 +83,8 @@ "CWE-94" ], "severity": "HIGH", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-05-14T21:30:51Z", "nvd_published_at": "2013-08-20T22:55:00Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-c8w9-83vg-r8vv/GHSA-c8w9-83vg-r8vv.json b/advisories/github-reviewed/2022/05/GHSA-c8w9-83vg-r8vv/GHSA-c8w9-83vg-r8vv.json similarity index 63% rename from advisories/unreviewed/2022/05/GHSA-c8w9-83vg-r8vv/GHSA-c8w9-83vg-r8vv.json rename to advisories/github-reviewed/2022/05/GHSA-c8w9-83vg-r8vv/GHSA-c8w9-83vg-r8vv.json index f203f69ae62..91fd7bec550 100644 --- a/advisories/unreviewed/2022/05/GHSA-c8w9-83vg-r8vv/GHSA-c8w9-83vg-r8vv.json +++ b/advisories/github-reviewed/2022/05/GHSA-c8w9-83vg-r8vv/GHSA-c8w9-83vg-r8vv.json @@ -1,23 +1,54 @@ { "schema_version": "1.4.0", "id": "GHSA-c8w9-83vg-r8vv", - "modified": "2022-05-17T01:36:25Z", + "modified": "2024-05-14T21:32:11Z", "published": "2022-05-17T01:36:25Z", "aliases": [ "CVE-2013-1840" ], + "summary": "OpenStack Glance is vulnerable to Exposure of Sensitive Information", "details": "The v1 API in OpenStack Glance Essex (2012.1), Folsom (2012.2), and Grizzly, when using the single-tenant Swift or S3 store, reports the location field, which allows remote authenticated users to obtain the operator's backend credentials via a request for a cached image.", "severity": [ ], "affected": [ - + { + "package": { + "ecosystem": "PyPI", + "name": "glance" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "11.0.0a0" + } + ] + } + ] + } ], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2013-1840" }, + { + "type": "WEB", + "url": "https://github.com/openstack/glance/commit/74b067df9726f9cf3e6e17e248719794a6ee0745" + }, + { + "type": "WEB", + "url": "https://github.com/openstack/glance/commit/dd849a9be540bedd4fd904cc0b86ccd9c3e34af2" + }, + { + "type": "WEB", + "url": "https://github.com/openstack/glance/commit/e75764eee34915f8bc5b664ac18e47a556c9d3dd" + }, { "type": "WEB", "url": "https://bugs.launchpad.net/glance/+bug/1135541" @@ -26,6 +57,10 @@ "type": "WEB", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/82878" }, + { + "type": "PACKAGE", + "url": "https://github.com/openstack/glance" + }, { "type": "WEB", "url": "https://review.openstack.org/#/c/24437" @@ -68,8 +103,8 @@ "CWE-200" ], "severity": "LOW", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-05-14T21:32:10Z", "nvd_published_at": "2013-03-22T21:55:00Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-cc77-5vw4-7pwg/GHSA-cc77-5vw4-7pwg.json b/advisories/github-reviewed/2022/05/GHSA-cc77-5vw4-7pwg/GHSA-cc77-5vw4-7pwg.json similarity index 60% rename from advisories/unreviewed/2022/05/GHSA-cc77-5vw4-7pwg/GHSA-cc77-5vw4-7pwg.json rename to advisories/github-reviewed/2022/05/GHSA-cc77-5vw4-7pwg/GHSA-cc77-5vw4-7pwg.json index 09eac5dec2a..3f0299fe7a7 100644 --- a/advisories/unreviewed/2022/05/GHSA-cc77-5vw4-7pwg/GHSA-cc77-5vw4-7pwg.json +++ b/advisories/github-reviewed/2022/05/GHSA-cc77-5vw4-7pwg/GHSA-cc77-5vw4-7pwg.json @@ -1,17 +1,36 @@ { "schema_version": "1.4.0", "id": "GHSA-cc77-5vw4-7pwg", - "modified": "2022-05-14T03:59:19Z", + "modified": "2024-05-14T21:30:46Z", "published": "2022-05-14T03:59:19Z", "aliases": [ "CVE-2015-1856" ], + "summary": "OpenStack Swift Unauthorized delete of versioned Swift object", "details": "OpenStack Object Storage (Swift) before 2.3.0, when allow_version is configured, allows remote authenticated users to delete the latest version of an object by leveraging listing access to the x-versions-location container.", "severity": [ ], "affected": [ - + { + "package": { + "ecosystem": "PyPI", + "name": "swift" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.3.0" + } + ] + } + ] + } ], "references": [ { @@ -22,6 +41,26 @@ "type": "WEB", "url": "https://bugs.launchpad.net/swift/+bug/1430645" }, + { + "type": "WEB", + "url": "https://git.openstack.org/cgit/openstack/swift/commit/?id=5bb7c286ebb4a54e4d2bd5a02845644d1c651183" + }, + { + "type": "WEB", + "url": "https://git.openstack.org/cgit/openstack/swift/commit/?id=85afe9316570855c87ea731d0627f6f8f2b73264" + }, + { + "type": "WEB", + "url": "https://git.openstack.org/cgit/openstack/swift/commit/?id=dd9d97458ea007024220a78dba8dd663e8b425d7" + }, + { + "type": "WEB", + "url": "https://git.openstack.org/cgit/openstack/swift/commit/?id=f6525758ab2456d688430699338993439597a789" + }, + { + "type": "PACKAGE", + "url": "https://github.com/openstack/swift" + }, { "type": "WEB", "url": "http://lists.fedoraproject.org/pipermail/package-announce/2015-August/163113.html" @@ -68,8 +107,8 @@ ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-05-14T21:30:46Z", "nvd_published_at": "2015-04-17T17:59:00Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-g6x3-55qv-x6p2/GHSA-g6x3-55qv-x6p2.json b/advisories/github-reviewed/2022/05/GHSA-g6x3-55qv-x6p2/GHSA-g6x3-55qv-x6p2.json similarity index 64% rename from advisories/unreviewed/2022/05/GHSA-g6x3-55qv-x6p2/GHSA-g6x3-55qv-x6p2.json rename to advisories/github-reviewed/2022/05/GHSA-g6x3-55qv-x6p2/GHSA-g6x3-55qv-x6p2.json index 62f63b0215c..636c5515665 100644 --- a/advisories/unreviewed/2022/05/GHSA-g6x3-55qv-x6p2/GHSA-g6x3-55qv-x6p2.json +++ b/advisories/github-reviewed/2022/05/GHSA-g6x3-55qv-x6p2/GHSA-g6x3-55qv-x6p2.json @@ -1,23 +1,54 @@ { "schema_version": "1.4.0", "id": "GHSA-g6x3-55qv-x6p2", - "modified": "2022-05-17T01:13:59Z", + "modified": "2024-05-14T21:30:43Z", "published": "2022-05-17T01:13:59Z", "aliases": [ "CVE-2014-7960" ], + "summary": "OpenStack Swift metadata constraints are not correctly enforced", "details": "OpenStack Object Storage (Swift) before 2.2.0 allows remote authenticated users to bypass the max_meta_count and other metadata constraints via multiple crafted requests which exceed the limit when combined.", "severity": [ ], "affected": [ - + { + "package": { + "ecosystem": "PyPI", + "name": "swift" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.2.0" + } + ] + } + ] + } ], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2014-7960" }, + { + "type": "WEB", + "url": "https://github.com/openstack/swift/commit/06800cbe446ce4c937a57b69517b55c3bba9b6e1" + }, + { + "type": "WEB", + "url": "https://github.com/openstack/swift/commit/2c4622a28ea04e1c6b2382189b0a1f6cccdc9c0f" + }, + { + "type": "WEB", + "url": "https://github.com/openstack/swift/commit/5b2c27a5874c2b5b0a333e4955b03544f6a8119f" + }, { "type": "WEB", "url": "https://bugs.launchpad.net/swift/+bug/1365350" @@ -26,6 +57,10 @@ "type": "WEB", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/96901" }, + { + "type": "PACKAGE", + "url": "https://github.com/openstack/swift" + }, { "type": "WEB", "url": "http://lists.opensuse.org/opensuse-security-announce/2015-10/msg00025.html" @@ -68,8 +103,8 @@ ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-05-14T21:30:43Z", "nvd_published_at": "2014-10-17T15:55:00Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-h737-q6g6-8wr6/GHSA-h737-q6g6-8wr6.json b/advisories/github-reviewed/2022/05/GHSA-h737-q6g6-8wr6/GHSA-h737-q6g6-8wr6.json similarity index 57% rename from advisories/unreviewed/2022/05/GHSA-h737-q6g6-8wr6/GHSA-h737-q6g6-8wr6.json rename to advisories/github-reviewed/2022/05/GHSA-h737-q6g6-8wr6/GHSA-h737-q6g6-8wr6.json index b84d4617232..29cb264754e 100644 --- a/advisories/unreviewed/2022/05/GHSA-h737-q6g6-8wr6/GHSA-h737-q6g6-8wr6.json +++ b/advisories/github-reviewed/2022/05/GHSA-h737-q6g6-8wr6/GHSA-h737-q6g6-8wr6.json @@ -1,27 +1,58 @@ { "schema_version": "1.4.0", "id": "GHSA-h737-q6g6-8wr6", - "modified": "2022-05-17T03:10:45Z", + "modified": "2024-05-14T21:32:19Z", "published": "2022-05-17T03:10:45Z", "aliases": [ "CVE-2014-9684" ], + "summary": "OpenStack Glance Denial of service by creating a large number of images", "details": "OpenStack Image Registry and Delivery Service (Glance) 2014.2 through 2014.2.2 does not properly remove images, which allows remote authenticated users to cause a denial of service (disk consumption) by creating a large number of images using the task v2 API and then deleting them before the uploads finish, a different vulnerability than CVE-2015-1881.", "severity": [ ], "affected": [ - + { + "package": { + "ecosystem": "PyPI", + "name": "glance" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "11.0.0a0" + } + ] + } + ] + } ], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2014-9684" }, + { + "type": "WEB", + "url": "https://github.com/openstack/glance/commit/7858d4d95154c8596720365e465cca7858cfec5c" + }, + { + "type": "WEB", + "url": "https://github.com/openstack/glance/commit/a880c8e762e94b70c1e5d5692a3defcde734a601" + }, { "type": "WEB", "url": "https://bugs.launchpad.net/glance/+bug/1371118" }, + { + "type": "PACKAGE", + "url": "https://github.com/openstack/glance" + }, { "type": "WEB", "url": "http://lists.openstack.org/pipermail/openstack-announce/2015-February/000336.html" @@ -40,8 +71,8 @@ ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-05-14T21:32:19Z", "nvd_published_at": "2015-02-24T15:59:00Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-j4mh-9wq6-8rg6/GHSA-j4mh-9wq6-8rg6.json b/advisories/github-reviewed/2022/05/GHSA-j4mh-9wq6-8rg6/GHSA-j4mh-9wq6-8rg6.json similarity index 60% rename from advisories/unreviewed/2022/05/GHSA-j4mh-9wq6-8rg6/GHSA-j4mh-9wq6-8rg6.json rename to advisories/github-reviewed/2022/05/GHSA-j4mh-9wq6-8rg6/GHSA-j4mh-9wq6-8rg6.json index db24b55c163..738bafeea01 100644 --- a/advisories/unreviewed/2022/05/GHSA-j4mh-9wq6-8rg6/GHSA-j4mh-9wq6-8rg6.json +++ b/advisories/github-reviewed/2022/05/GHSA-j4mh-9wq6-8rg6/GHSA-j4mh-9wq6-8rg6.json @@ -1,23 +1,54 @@ { "schema_version": "1.4.0", "id": "GHSA-j4mh-9wq6-8rg6", - "modified": "2022-05-17T03:28:28Z", + "modified": "2024-05-14T21:32:21Z", "published": "2022-05-17T03:28:28Z", "aliases": [ "CVE-2014-9623" ], + "summary": "OpenStack Glance Bypass the storage quota and Denial of service ", "details": "OpenStack Glance 2014.2.x through 2014.2.1, 2014.1.3, and earlier allows remote authenticated users to bypass the storage quota and cause a denial of service (disk consumption) by deleting an image in the saving state.", "severity": [ ], "affected": [ - + { + "package": { + "ecosystem": "PyPI", + "name": "glance" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "11.0.0a0" + } + ] + } + ] + } ], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2014-9623" }, + { + "type": "WEB", + "url": "https://github.com/openstack/glance/commit/0dc8fbb3479a53c5bba8475d14f4c7206904c5ea" + }, + { + "type": "WEB", + "url": "https://github.com/openstack/glance/commit/7d5d8657fd70b20518610b3c6f8e41e16c72fa31" + }, + { + "type": "WEB", + "url": "https://github.com/openstack/glance/commit/f1260cc771ee068651aa62b972bef49d9af81eb0" + }, { "type": "WEB", "url": "https://bugs.launchpad.net/glance/+bug/1383973" @@ -26,6 +57,10 @@ "type": "WEB", "url": "https://bugs.launchpad.net/glance/+bug/1398830" }, + { + "type": "PACKAGE", + "url": "https://github.com/openstack/glance" + }, { "type": "WEB", "url": "https://security.openstack.org/ossa/OSSA-2015-003.html" @@ -60,8 +95,8 @@ ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-05-14T21:32:21Z", "nvd_published_at": "2015-01-23T15:59:00Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-j6mr-cm6x-h6jg/GHSA-j6mr-cm6x-h6jg.json b/advisories/github-reviewed/2022/05/GHSA-j6mr-cm6x-h6jg/GHSA-j6mr-cm6x-h6jg.json similarity index 64% rename from advisories/unreviewed/2022/05/GHSA-j6mr-cm6x-h6jg/GHSA-j6mr-cm6x-h6jg.json rename to advisories/github-reviewed/2022/05/GHSA-j6mr-cm6x-h6jg/GHSA-j6mr-cm6x-h6jg.json index 8f564dadd85..be30d1060ac 100644 --- a/advisories/unreviewed/2022/05/GHSA-j6mr-cm6x-h6jg/GHSA-j6mr-cm6x-h6jg.json +++ b/advisories/github-reviewed/2022/05/GHSA-j6mr-cm6x-h6jg/GHSA-j6mr-cm6x-h6jg.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-j6mr-cm6x-h6jg", - "modified": "2022-05-17T02:52:29Z", + "modified": "2024-05-14T21:32:12Z", "published": "2022-05-17T02:52:29Z", "aliases": [ "CVE-2017-7200" ], + "summary": "OpenStack Glance Server-Side Request Forgery (SSRF)", "details": "An SSRF issue was discovered in OpenStack Glance before Newton. The 'copy_from' feature in the Image Service API v1 allowed an attacker to perform masked network port scans. With v1, it is possible to create images with a URL such as 'http://localhost:22'. This could then allow an attacker to enumerate internal network details while appearing masked, since the scan would appear to originate from the Glance Image service.", "severity": [ { @@ -14,13 +15,35 @@ } ], "affected": [ - + { + "package": { + "ecosystem": "PyPI", + "name": "glance" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "11.0.0a0" + } + ] + } + ] + } ], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2017-7200" }, + { + "type": "WEB", + "url": "https://github.com/openstack/glance/commit/b1ac90f7914d91b25144cc4063fa994fb5019ee3" + }, { "type": "WEB", "url": "https://bugs.launchpad.net/ossn/+bug/1153614" @@ -29,6 +52,10 @@ "type": "WEB", "url": "https://bugs.launchpad.net/ossn/+bug/1606495" }, + { + "type": "PACKAGE", + "url": "https://github.com/openstack/glance" + }, { "type": "WEB", "url": "https://wiki.openstack.org/wiki/OSSN/OSSN-0078" @@ -43,8 +70,8 @@ "CWE-918" ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-05-14T21:32:12Z", "nvd_published_at": "2017-03-21T06:59:00Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-pwrj-f53c-f89j/GHSA-pwrj-f53c-f89j.json b/advisories/github-reviewed/2022/05/GHSA-pwrj-f53c-f89j/GHSA-pwrj-f53c-f89j.json similarity index 53% rename from advisories/unreviewed/2022/05/GHSA-pwrj-f53c-f89j/GHSA-pwrj-f53c-f89j.json rename to advisories/github-reviewed/2022/05/GHSA-pwrj-f53c-f89j/GHSA-pwrj-f53c-f89j.json index 3fbb94c7c87..cedcfde6f75 100644 --- a/advisories/unreviewed/2022/05/GHSA-pwrj-f53c-f89j/GHSA-pwrj-f53c-f89j.json +++ b/advisories/github-reviewed/2022/05/GHSA-pwrj-f53c-f89j/GHSA-pwrj-f53c-f89j.json @@ -1,27 +1,62 @@ { "schema_version": "1.4.0", "id": "GHSA-pwrj-f53c-f89j", - "modified": "2022-05-14T01:37:00Z", + "modified": "2024-05-14T21:32:09Z", "published": "2022-05-14T01:37:00Z", "aliases": [ "CVE-2015-1195" ], - "details": "The V2 API in OpenStack Image Registry and Delivery Service (Glance) before 2014.1.4 and 2014.2.x before 2014.2.2 allows remote authenticated users to read or delete arbitrary files via a full pathname in a filesystem: URL in the image location property. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-9493.", + "summary": "OpenStack Glance v2 API unrestricted path traversal through filesystem:// scheme", + "details": "The V2 API in OpenStack Image Registry and Delivery Service (Glance) before 2014.1.4 and 2014.2.x before 2014.2.2 allows remote authenticated users to read or delete arbitrary files via a full pathname in a `filesystem://` URL in the image location property. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-9493.", "severity": [ ], "affected": [ - + { + "package": { + "ecosystem": "PyPI", + "name": "glance" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "11.0.0a0" + } + ] + } + ] + } ], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2015-1195" }, + { + "type": "WEB", + "url": "https://github.com/openstack/glance/commit/5191ed1879c5fd5b2694f922bcedec232f461088" + }, + { + "type": "WEB", + "url": "https://github.com/openstack/glance/commit/7d3a1db33ccbd25b9fc7326ce3468eabd2a41a99" + }, + { + "type": "WEB", + "url": "https://github.com/openstack/glance/commit/a2d986b976e9325a272e2d422465165315d19fe6" + }, { "type": "WEB", "url": "https://bugs.launchpad.net/ossa/+bug/1408663" }, + { + "type": "PACKAGE", + "url": "https://github.com/openstack/glance" + }, { "type": "WEB", "url": "http://lists.openstack.org/pipermail/openstack-announce/2015-January/000325.html" @@ -52,8 +87,8 @@ "CWE-22" ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-05-14T21:32:09Z", "nvd_published_at": "2015-01-21T18:59:00Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-wxx2-gqvv-34hx/GHSA-wxx2-gqvv-34hx.json b/advisories/github-reviewed/2022/05/GHSA-wxx2-gqvv-34hx/GHSA-wxx2-gqvv-34hx.json similarity index 62% rename from advisories/unreviewed/2022/05/GHSA-wxx2-gqvv-34hx/GHSA-wxx2-gqvv-34hx.json rename to advisories/github-reviewed/2022/05/GHSA-wxx2-gqvv-34hx/GHSA-wxx2-gqvv-34hx.json index 9ff18bee972..e6835d67943 100644 --- a/advisories/unreviewed/2022/05/GHSA-wxx2-gqvv-34hx/GHSA-wxx2-gqvv-34hx.json +++ b/advisories/github-reviewed/2022/05/GHSA-wxx2-gqvv-34hx/GHSA-wxx2-gqvv-34hx.json @@ -1,27 +1,58 @@ { "schema_version": "1.4.0", "id": "GHSA-wxx2-gqvv-34hx", - "modified": "2022-05-17T04:58:58Z", + "modified": "2024-05-14T21:30:35Z", "published": "2022-05-17T04:58:58Z", "aliases": [ "CVE-2013-4155" ], + "summary": "OpenStack Swift allows authenticated users to cause a denial of service", "details": "OpenStack Swift before 1.9.1 in Folsom, Grizzly, and Havana allows authenticated users to cause a denial of service (\"superfluous\" tombstone consumption and Swift cluster slowdown) via a DELETE request with a timestamp that is older than expected.", "severity": [ ], "affected": [ - + { + "package": { + "ecosystem": "PyPI", + "name": "swift" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.9.1" + } + ] + } + ] + } ], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2013-4155" }, + { + "type": "WEB", + "url": "https://github.com/openstack/swift/commit/1f4ec235cdfd8c868f2d6458532f9dc32c00b8ca" + }, + { + "type": "WEB", + "url": "https://github.com/openstack/swift/commit/6b9806e0e8cbec60c0a3ece0bd516e0502827515" + }, { "type": "WEB", "url": "https://bugs.launchpad.net/swift/+bug/1196932" }, + { + "type": "PACKAGE", + "url": "https://github.com/openstack/swift" + }, { "type": "WEB", "url": "https://review.openstack.org/#/c/40643" @@ -56,8 +87,8 @@ "CWE-119" ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-05-14T21:30:35Z", "nvd_published_at": "2013-08-20T22:55:00Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2023/01/GHSA-274c-rx2j-2v3x/GHSA-274c-rx2j-2v3x.json b/advisories/github-reviewed/2023/01/GHSA-274c-rx2j-2v3x/GHSA-274c-rx2j-2v3x.json new file mode 100644 index 00000000000..25b5f7eeff1 --- /dev/null +++ b/advisories/github-reviewed/2023/01/GHSA-274c-rx2j-2v3x/GHSA-274c-rx2j-2v3x.json @@ -0,0 +1,143 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-274c-rx2j-2v3x", + "modified": "2024-05-14T21:30:33Z", + "published": "2023-01-18T18:30:16Z", + "aliases": [ + "CVE-2022-47950" + ], + "summary": "OpenStack Swift XML external entities (XXE) Injection", + "details": "An issue was discovered in OpenStack Swift before 2.28.1, 2.29.x before 2.29.2, and 2.30.0. By supplying crafted XML files, an authenticated user may coerce the S3 API into returning arbitrary file contents from the host server, resulting in unauthorized read access to potentially sensitive data. This impacts both s3api deployments (Rocky or later), and swift3 deployments (Queens and earlier, no longer actively developed).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "PyPI", + "name": "swift" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.28.1" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "PyPI", + "name": "swift" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.29.0" + }, + { + "fixed": "2.29.2" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "PyPI", + "name": "swift" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.30.0" + }, + { + "fixed": "2.30.1" + } + ] + } + ], + "versions": [ + "2.30.0" + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-47950" + }, + { + "type": "WEB", + "url": "https://github.com/openstack/swift/commit/12e54391861e7d182d58f89fb88b027e65842640" + }, + { + "type": "WEB", + "url": "https://github.com/openstack/swift/commit/7d13d1a82e1f5d01205a13184907501b4fcbe2b0" + }, + { + "type": "WEB", + "url": "https://github.com/openstack/swift/commit/8dd96470a859dc7b189404fb67bd3899ae9c617f" + }, + { + "type": "WEB", + "url": "https://github.com/openstack/swift/commit/b8467e190f6fc67fd8fb6a8c5e32b2aa6a10fd8e" + }, + { + "type": "WEB", + "url": "https://github.com/openstack/swift/commit/baa98848451b5c234443a068691e12841a5a8383" + }, + { + "type": "WEB", + "url": "https://github.com/openstack/swift/commit/c834e7a53d5a33a3fd13ffd954e6f4f4ee953dfc" + }, + { + "type": "WEB", + "url": "https://github.com/openstack/swift/commit/d8d04ef43c90079d436b2e49617b4425ba39c28e" + }, + { + "type": "WEB", + "url": "https://github.com/openstack/swift/commit/f10672514217adadfc776d9ea2ffb20a37ce073b" + }, + { + "type": "PACKAGE", + "url": "https://github.com/openstack/swift" + }, + { + "type": "WEB", + "url": "https://launchpad.net/bugs/1998625" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2023/01/msg00021.html" + }, + { + "type": "WEB", + "url": "https://security.openstack.org/ossa/OSSA-2023-001.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-552", + "CWE-611" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-05-14T21:30:33Z", + "nvd_published_at": "2023-01-18T17:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/01/GHSA-274c-rx2j-2v3x/GHSA-274c-rx2j-2v3x.json b/advisories/unreviewed/2023/01/GHSA-274c-rx2j-2v3x/GHSA-274c-rx2j-2v3x.json deleted file mode 100644 index 2491976ef34..00000000000 --- a/advisories/unreviewed/2023/01/GHSA-274c-rx2j-2v3x/GHSA-274c-rx2j-2v3x.json +++ /dev/null @@ -1,46 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-274c-rx2j-2v3x", - "modified": "2023-01-25T21:30:18Z", - "published": "2023-01-18T18:30:16Z", - "aliases": [ - "CVE-2022-47950" - ], - "details": "An issue was discovered in OpenStack Swift before 2.28.1, 2.29.x before 2.29.2, and 2.30.0. By supplying crafted XML files, an authenticated user may coerce the S3 API into returning arbitrary file contents from the host server, resulting in unauthorized read access to potentially sensitive data. This impacts both s3api deployments (Rocky or later), and swift3 deployments (Queens and earlier, no longer actively developed).", - "severity": [ - { - "type": "CVSS_V3", - "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" - } - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-47950" - }, - { - "type": "WEB", - "url": "https://launchpad.net/bugs/1998625" - }, - { - "type": "WEB", - "url": "https://lists.debian.org/debian-lts-announce/2023/01/msg00021.html" - }, - { - "type": "WEB", - "url": "https://security.openstack.org/ossa/OSSA-2023-001.html" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-552" - ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2023-01-18T17:15:00Z" - } -} \ No newline at end of file