From a31673cd133e0ab6d01e314afeeb2ecce8c6c6d9 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 24 Jul 2024 15:00:30 +0000 Subject: [PATCH] Publish Advisories GHSA-8gj9-r4hv-3jjw GHSA-c2hf-vcmr-qjrf GHSA-8gj9-r4hv-3jjw --- .../GHSA-8gj9-r4hv-3jjw.json | 69 +++++++++++++++++++ .../GHSA-c2hf-vcmr-qjrf.json | 58 ++++++++++++++-- .../GHSA-8gj9-r4hv-3jjw.json | 35 ---------- 3 files changed, 121 insertions(+), 41 deletions(-) create mode 100644 advisories/github-reviewed/2024/07/GHSA-8gj9-r4hv-3jjw/GHSA-8gj9-r4hv-3jjw.json rename advisories/{unreviewed => github-reviewed}/2024/07/GHSA-c2hf-vcmr-qjrf/GHSA-c2hf-vcmr-qjrf.json (55%) delete mode 100644 advisories/unreviewed/2024/07/GHSA-8gj9-r4hv-3jjw/GHSA-8gj9-r4hv-3jjw.json diff --git a/advisories/github-reviewed/2024/07/GHSA-8gj9-r4hv-3jjw/GHSA-8gj9-r4hv-3jjw.json b/advisories/github-reviewed/2024/07/GHSA-8gj9-r4hv-3jjw/GHSA-8gj9-r4hv-3jjw.json new file mode 100644 index 00000000000..3019ad7b407 --- /dev/null +++ b/advisories/github-reviewed/2024/07/GHSA-8gj9-r4hv-3jjw/GHSA-8gj9-r4hv-3jjw.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8gj9-r4hv-3jjw", + "modified": "2024-07-24T14:59:48Z", + "published": "2024-07-24T09:30:40Z", + "aliases": [ + "CVE-2024-39676" + ], + "summary": "Apache Pinot: Unauthorized endpoint exposed sensitive information", + "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Pinot.\n\nThis issue affects Apache Pinot: from 0.1 before 1.0.0.\n\nUsers are recommended to upgrade to version 1.0.0 and configure RBAC, which fixes the issue.\n\nDetails: \n\nWhen using a request to path `/appconfigs` to the controller, it can lead to the disclosure of sensitive information such as system information (e.g. arch, os version), environment information (e.g. maxHeapSize) and Pinot configurations (e.g. zookeeper path). This issue was addressed by the Role-based Access Control https://docs.pinot.apache.org/operators/tutorials/authentication/basic-auth-access-control , so that `/appConfigs` and all other APIs can be access controlled. Only authorized users have access to it. Note the user needs to add the admin role accordingly to the RBAC guide to control access to this endpoint, and in the future version of Pinot, a default admin role is planned to be added.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Maven", + "name": "org.apache.pinot:pinot-controller" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0.1" + }, + { + "fixed": "1.0.0" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39676" + }, + { + "type": "WEB", + "url": "https://docs.pinot.apache.org/operators/tutorials/authentication/basic-auth-access-control" + }, + { + "type": "PACKAGE", + "url": "https://github.com/apache/pinot" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/hsm0b2w8qr0sqy4rj1mfnnw286tslpzc" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "HIGH", + "github_reviewed": true, + "github_reviewed_at": "2024-07-24T14:59:48Z", + "nvd_published_at": "2024-07-24T08:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-c2hf-vcmr-qjrf/GHSA-c2hf-vcmr-qjrf.json b/advisories/github-reviewed/2024/07/GHSA-c2hf-vcmr-qjrf/GHSA-c2hf-vcmr-qjrf.json similarity index 55% rename from advisories/unreviewed/2024/07/GHSA-c2hf-vcmr-qjrf/GHSA-c2hf-vcmr-qjrf.json rename to advisories/github-reviewed/2024/07/GHSA-c2hf-vcmr-qjrf/GHSA-c2hf-vcmr-qjrf.json index 6b305b0fb94..f975174dc06 100644 --- a/advisories/unreviewed/2024/07/GHSA-c2hf-vcmr-qjrf/GHSA-c2hf-vcmr-qjrf.json +++ b/advisories/github-reviewed/2024/07/GHSA-c2hf-vcmr-qjrf/GHSA-c2hf-vcmr-qjrf.json @@ -1,35 +1,81 @@ { "schema_version": "1.4.0", "id": "GHSA-c2hf-vcmr-qjrf", - "modified": "2024-07-23T18:31:07Z", + "modified": "2024-07-24T14:59:02Z", "published": "2024-07-23T18:31:07Z", "aliases": [ "CVE-2024-41178" ], + "summary": "Apache Arrow Rust Object Store: AWS WebIdentityToken exposure in log files", "details": "Exposure of temporary credentials in logs in Apache Arrow Rust Object Store (`object_store` crate), version 0.10.1 and earlier on all platforms using AWS WebIdentityTokens. \n\nOn certain error conditions, the logs may contain the OIDC token passed to AssumeRoleWithWebIdentity https://docs.aws.amazon.com/STS/latest/APIReference/API_AssumeRoleWithWebIdentity.html . This allows someone with access to the logs to impersonate that identity, including performing their own calls to AssumeRoleWithWebIdentity, until the OIDC token expires. Typically OIDC tokens are valid for up to an hour, although this will vary depending on the issuer.\n\nUsers are recommended to use a different AWS authentication mechanism, disable logging or upgrade to version 0.10.2, which fixes this issue.\n\nDetails:\n\nWhen using AWS WebIdentityTokens with the object_store crate, in the event of a failure and automatic retry, the underlying reqwest error, including the full URL with the credentials, potentially in the parameters, is written to the logs. \n\nThanks to Paul Hatcherian for reporting this vulnerability", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:L/SA:N" + } ], "affected": [ - + { + "package": { + "ecosystem": "crates.io", + "name": "object_store" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0.5.0" + }, + { + "fixed": "0.10.2" + } + ] + } + ] + } ], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41178" }, + { + "type": "WEB", + "url": "https://github.com/apache/arrow-rs/pull/6074" + }, + { + "type": "WEB", + "url": "https://github.com/apache/arrow-rs/commit/4978e32654235f569062f2cad6c7361e410f1254" + }, + { + "type": "PACKAGE", + "url": "https://github.com/apache/arrow-rs" + }, { "type": "WEB", "url": "https://lists.apache.org/thread/3t0povdppnt2czv6crlsqhvyko93kcrg" + }, + { + "type": "WEB", + "url": "https://rustsec.org/advisories/RUSTSEC-2024-0358.html" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/07/23/3" } ], "database_specific": { "cwe_ids": [ "CWE-532" ], - "severity": null, - "github_reviewed": false, - "github_reviewed_at": null, + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-07-24T14:59:02Z", "nvd_published_at": "2024-07-23T17:15:12Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2024/07/GHSA-8gj9-r4hv-3jjw/GHSA-8gj9-r4hv-3jjw.json b/advisories/unreviewed/2024/07/GHSA-8gj9-r4hv-3jjw/GHSA-8gj9-r4hv-3jjw.json deleted file mode 100644 index 5cd9692483a..00000000000 --- a/advisories/unreviewed/2024/07/GHSA-8gj9-r4hv-3jjw/GHSA-8gj9-r4hv-3jjw.json +++ /dev/null @@ -1,35 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-8gj9-r4hv-3jjw", - "modified": "2024-07-24T09:30:40Z", - "published": "2024-07-24T09:30:40Z", - "aliases": [ - "CVE-2024-39676" - ], - "details": "Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Pinot.\n\nThis issue affects Apache Pinot: from 0.1 before 1.0.0.\n\nUsers are recommended to upgrade to version 1.0.0 and configure RBAC, which fixes the issue.\n\nDetails: \n\nWhen using a request to path “/appconfigs” to the controller, it can lead to the disclosure of sensitive information such as system information (e.g. arch, os version), environment information (e.g. maxHeapSize) and Pinot configurations (e.g. zookeeper path). This issue was addressed by the Role-based Access Control https://docs.pinot.apache.org/operators/tutorials/authentication/basic-auth-access-control , so that /appConfigs` and all other APIs can be access controlled. Only authorized users have access to it. Note the user needs to add the admin role accordingly to the RBAC guide to control access to this endpoint, and in the future version of Pinot, a default admin role is planned to be added.\n\n", - "severity": [ - - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39676" - }, - { - "type": "WEB", - "url": "https://lists.apache.org/thread/hsm0b2w8qr0sqy4rj1mfnnw286tslpzc" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-200" - ], - "severity": null, - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2024-07-24T08:15:02Z" - } -} \ No newline at end of file