Publish Advisories

GHSA-j8xg-fqg3-53r7
GHSA-mpv3-g8m3-3fjc
GHSA-4pvw-g9fx-594r
GHSA-4q2q-q5pw-2342
GHSA-86pw-4rqp-6x7v
GHSA-cgcv-5272-97pr
GHSA-cggh-pq45-6h9x
GHSA-gpq8-963w-8qc9
GHSA-pmhc-2g4f-85cg
GHSA-pq67-9jf9-hc3c
GHSA-q8cm-3v62-jj79
GHSA-qc2g-gmh6-95p4
GHSA-r5pv-7g89-cxmc
GHSA-2wrp-6fg6-hmc5
GHSA-6623-c6mr-6737
GHSA-79vv-vp32-gpp7
GHSA-cvqr-mwh6-2vc6
GHSA-g64r-xf39-q4p5
GHSA-g9qx-25vj-rf53
GHSA-m4v8-wqvr-p9f7
GHSA-mr82-8j83-vxmv
This commit is contained in:
advisory-database[bot]
2025-02-13 19:02:39 +00:00
parent 66683b16f8
commit a3ad8d4273
21 changed files with 49 additions and 46 deletions
@@ -1,13 +1,13 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j8xg-fqg3-53r7",
"modified": "2024-06-21T21:33:53Z",
"modified": "2025-02-13T19:00:43Z",
"published": "2023-06-22T06:30:18Z",
"aliases": [
"CVE-2023-26115"
],
"summary": "word-wrap vulnerable to Regular Expression Denial of Service",
"details": "All versions of the package word-wrap are vulnerable to Regular Expression Denial of Service (ReDoS) due to the usage of an insecure regular expression within the result variable.\n",
"details": "All versions of the package word-wrap are vulnerable to Regular Expression Denial of Service (ReDoS) due to the usage of an insecure regular expression within the result variable.",
"severity": [
{
"type": "CVSS_V3",
@@ -20,11 +20,6 @@
"ecosystem": "npm",
"name": "word-wrap"
},
"ecosystem_specific": {
"affected_functions": [
"(word-wrap)"
]
},
"ranges": [
{
"type": "ECOSYSTEM",
@@ -1,13 +1,13 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mpv3-g8m3-3fjc",
"modified": "2023-06-23T21:38:39Z",
"modified": "2025-02-13T19:00:46Z",
"published": "2023-06-22T21:30:49Z",
"aliases": [
"CVE-2023-3128"
],
"summary": "Grafana vulnerable to Authentication Bypass by Spoofing",
"details": "Grafana is validating Azure AD accounts based on the email claim. \n\nOn Azure AD, the profile email field is not unique and can be easily modified. \n\nThis leads to account takeover and authentication bypass when Azure AD OAuth is configured with a multi-tenant app. \n\n",
"details": "Grafana is validating Azure AD accounts based on the email claim. \n\nOn Azure AD, the profile email field is not unique and can be easily modified. \n\nThis leads to account takeover and authentication bypass when Azure AD OAuth is configured with a multi-tenant app.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,13 +1,13 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4pvw-g9fx-594r",
"modified": "2023-08-03T17:39:56Z",
"modified": "2025-02-13T19:02:06Z",
"published": "2023-07-25T18:30:32Z",
"aliases": [
"CVE-2023-38435"
],
"summary": "Cross-site Scripting in healthcheck webconsole plugin",
"details": "\nAn improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Apache Felix Healthcheck Webconsole Plugin version 2.0.2 and prior may allow an attacker to perform a reflected cross-site scripting (XSS) attack.\n\nUpgrade to Apache Felix Healthcheck Webconsole Plugin 2.1.0 or higher.",
"details": "An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Apache Felix Healthcheck Webconsole Plugin version 2.0.2 and prior may allow an attacker to perform a reflected cross-site scripting (XSS) attack.\n\nUpgrade to Apache Felix Healthcheck Webconsole Plugin 2.1.0 or higher.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,13 +1,13 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4q2q-q5pw-2342",
"modified": "2023-07-25T16:38:48Z",
"modified": "2025-02-13T19:00:55Z",
"published": "2023-07-13T09:30:28Z",
"aliases": [
"CVE-2023-37415"
],
"summary": "Apache Airflow Apache Hive Provider Improper Input Validation vulnerability",
"details": "Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Apache Hive Provider.\n\nPatching on top of CVE-2023-35797\nBefore 6.1.2 the proxy_user option can also inject semicolon.\n\nThis issue affects Apache Airflow Apache Hive Provider: before 6.1.2.\n\nIt is recommended updating provider version to 6.1.2 in order to avoid this vulnerability.\n\n",
"details": "Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Apache Hive Provider.\n\nPatching on top of CVE-2023-35797\nBefore 6.1.2 the proxy_user option can also inject semicolon.\n\nThis issue affects Apache Airflow Apache Hive Provider: before 6.1.2.\n\nIt is recommended updating provider version to 6.1.2 in order to avoid this vulnerability.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,13 +1,13 @@
{
"schema_version": "1.4.0",
"id": "GHSA-86pw-4rqp-6x7v",
"modified": "2023-08-03T17:55:50Z",
"modified": "2025-02-13T19:01:45Z",
"published": "2023-07-25T09:30:17Z",
"aliases": [
"CVE-2023-34189"
],
"summary": "Apache InLong: General user can delete and update process",
"details": "Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0. The attacker could use general users to delete and update the process, which only the admin can operate occurrences. \n\nUsers are advised to upgrade to Apache InLong's 1.8.0 or cherry-pick https://github.com/apache/inlong/pull/8109  to solve it.\n\n",
"details": "Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0. The attacker could use general users to delete and update the process, which only the admin can operate occurrences. \n\nUsers are advised to upgrade to Apache InLong's 1.8.0 or cherry-pick https://github.com/apache/inlong/pull/8109  to solve it.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,13 +1,13 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cgcv-5272-97pr",
"modified": "2023-07-07T16:29:50Z",
"modified": "2025-02-13T19:01:03Z",
"published": "2023-07-03T21:30:57Z",
"aliases": [
"CVE-2023-2728"
],
"summary": "Kubernetes mountable secrets policy bypass",
"details": "Users may be able to launch containers that bypass the mountable secrets policy enforced by the ServiceAccount admission plugin when using ephemeral containers. The policy ensures pods running with a service account may only reference secrets specified in the service accounts secrets field. Kubernetes clusters are only affected if the ServiceAccount admission plugin and the `kubernetes.io/enforce-mountable-secrets` annotation are used together with ephemeral containers.\n\n",
"details": "Users may be able to launch containers that bypass the mountable secrets policy enforced by the ServiceAccount admission plugin when using ephemeral containers. The policy ensures pods running with a service account may only reference secrets specified in the service accounts secrets field. Kubernetes clusters are only affected if the ServiceAccount admission plugin and the `kubernetes.io/enforce-mountable-secrets` annotation are used together with ephemeral containers.",
"severity": [
{
"type": "CVSS_V3",
@@ -129,6 +129,10 @@
"type": "WEB",
"url": "https://groups.google.com/g/kubernetes-security-announce/c/vPWYJ_L84m8"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20230803-0004"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2023/07/06/3"
@@ -1,13 +1,13 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cggh-pq45-6h9x",
"modified": "2024-06-24T21:25:02Z",
"modified": "2025-02-13T19:00:49Z",
"published": "2023-07-01T00:30:46Z",
"aliases": [
"CVE-2023-30589"
],
"summary": "llhttp vulnerable to HTTP request smuggling",
"details": "The llhttp parser in the http module in Node v20.2.0 does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Smuggling (HRS).\n\nThe CR character (without LF) is sufficient to delimit HTTP header fields in the llhttp parser. According to RFC7230 section 3, only the CRLF sequence should delimit each header-field. This impacts all Node.js active versions: v16, v18, and, v20\n",
"details": "The llhttp parser in the http module in Node v20.2.0 does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Smuggling (HRS).\n\nThe CR character (without LF) is sufficient to delimit HTTP header fields in the llhttp parser. According to RFC7230 section 3, only the CRLF sequence should delimit each header-field. This impacts all Node.js active versions: v16, v18, and, v20",
"severity": [
{
"type": "CVSS_V3",
@@ -1,13 +1,13 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gpq8-963w-8qc9",
"modified": "2023-07-20T14:54:54Z",
"modified": "2025-02-13T19:00:52Z",
"published": "2023-07-12T12:31:36Z",
"aliases": [
"CVE-2023-37582"
],
"summary": "RocketMQ NameServer component Code Injection vulnerability",
"details": "The RocketMQ NameServer component still has a remote command execution vulnerability as the CVE-2023-33246 issue was not completely fixed in version 5.1.1. \n\nWhen NameServer address are leaked on the extranet and lack permission verification, an attacker can exploit this vulnerability by using the update configuration function on the NameServer component to execute commands as the system users that RocketMQ is running as. \n\nIt is recommended for users to upgrade their NameServer version to 5.1.2 or above for RocketMQ 5.x or 4.9.7 or above for RocketMQ 4.x to prevent these attacks.\n",
"details": "The RocketMQ NameServer component still has a remote command execution vulnerability as the CVE-2023-33246 issue was not completely fixed in version 5.1.1. \n\nWhen NameServer address are leaked on the extranet and lack permission verification, an attacker can exploit this vulnerability by using the update configuration function on the NameServer component to execute commands as the system users that RocketMQ is running as. \n\nIt is recommended for users to upgrade their NameServer version to 5.1.2 or above for RocketMQ 5.x or 4.9.7 or above for RocketMQ 4.x to prevent these attacks.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,13 +1,13 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pmhc-2g4f-85cg",
"modified": "2024-10-02T21:39:09Z",
"modified": "2025-02-13T19:01:43Z",
"published": "2023-07-24T21:30:39Z",
"aliases": [
"CVE-2023-34478"
],
"summary": "Path Traversal in Apache Shiro",
"details": "Apache Shiro, before 1.12.0 or 2.0.0-alpha-3, may be susceptible to a path traversal attack that results in an authentication bypass when used together with APIs or other web frameworks that route requests based on non-normalized requests.\n\nMitigation: Update to Apache Shiro 1.12.0+ or 2.0.0-alpha-3+\n",
"details": "Apache Shiro, before 1.12.0 or 2.0.0-alpha-3, may be susceptible to a path traversal attack that results in an authentication bypass when used together with APIs or other web frameworks that route requests based on non-normalized requests.\n\nMitigation: Update to Apache Shiro 1.12.0+ or 2.0.0-alpha-3+",
"severity": [
{
"type": "CVSS_V3",
@@ -1,13 +1,13 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pq67-9jf9-hc3c",
"modified": "2024-10-02T21:39:49Z",
"modified": "2025-02-13T19:01:49Z",
"published": "2023-07-25T09:30:18Z",
"aliases": [
"CVE-2023-34434"
],
"summary": "JDBC URL bypassing by allowLoadLocalInfileInPath param",
"details": "Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0. \n\nThe attacker could bypass the current logic and achieve arbitrary file reading. To solve it, users are advised to upgrade to Apache InLong's 1.8.0 or cherry-pick https://github.com/apache/inlong/pull/8130 .\n\n",
"details": "Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0. \n\nThe attacker could bypass the current logic and achieve arbitrary file reading. To solve it, users are advised to upgrade to Apache InLong's 1.8.0 or cherry-pick https://github.com/apache/inlong/pull/8130 .",
"severity": [
{
"type": "CVSS_V3",
File diff suppressed because one or more lines are too long
@@ -1,13 +1,13 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qc2g-gmh6-95p4",
"modified": "2023-07-05T22:46:57Z",
"modified": "2025-02-13T19:00:59Z",
"published": "2023-07-03T21:30:57Z",
"aliases": [
"CVE-2023-2727"
],
"summary": "kube-apiserver vulnerable to policy bypass",
"details": "Users may be able to launch containers using images that are restricted by ImagePolicyWebhook when using ephemeral containers. Kubernetes clusters are only affected if the ImagePolicyWebhook admission plugin is used together with ephemeral containers.\n\n",
"details": "Users may be able to launch containers using images that are restricted by ImagePolicyWebhook when using ephemeral containers. Kubernetes clusters are only affected if the ImagePolicyWebhook admission plugin is used together with ephemeral containers.",
"severity": [
{
"type": "CVSS_V3",
@@ -129,6 +129,10 @@
"type": "WEB",
"url": "https://groups.google.com/g/kubernetes-security-announce/c/vPWYJ_L84m8"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20230803-0004"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2023/07/06/2"
@@ -1,13 +1,13 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r5pv-7g89-cxmc",
"modified": "2024-10-02T21:40:22Z",
"modified": "2025-02-13T19:01:55Z",
"published": "2023-07-25T09:30:18Z",
"aliases": [
"CVE-2023-35088"
],
"summary": "SQL injection in audit endpoint",
"details": "Improper Neutralization of Special Elements Used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0. \nIn the toAuditCkSql method, the groupId, streamId, auditId, and dt are directly concatenated into the SQL query statement, which may lead to SQL injection attacks.\nUsers are advised to upgrade to Apache InLong's 1.8.0 or cherry-pick [1] to solve it.\n\n[1] https://github.com/apache/inlong/pull/8198 \n\n",
"details": "Improper Neutralization of Special Elements Used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0. \nIn the toAuditCkSql method, the groupId, streamId, auditId, and dt are directly concatenated into the SQL query statement, which may lead to SQL injection attacks.\nUsers are advised to upgrade to Apache InLong's 1.8.0 or cherry-pick [1] to solve it.\n\n[1] https://github.com/apache/inlong/pull/8198",
"severity": [
{
"type": "CVSS_V3",
@@ -1,13 +1,13 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2wrp-6fg6-hmc5",
"modified": "2024-08-27T18:36:46Z",
"modified": "2025-02-13T19:00:56Z",
"published": "2024-04-16T06:30:28Z",
"aliases": [
"CVE-2024-22262"
],
"summary": "Spring Framework URL Parsing with Host Validation",
"details": "Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/definitions/601.html  attack or to a SSRF attack if the URL is used after passing validation checks.\n\nThis is the same as CVE-2024-22259 https://spring.io/security/cve-2024-22259  and CVE-2024-22243 https://spring.io/security/cve-2024-22243 , but with different input.\n\n",
"details": "Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/definitions/601.html  attack or to a SSRF attack if the URL is used after passing validation checks.\n\nThis is the same as CVE-2024-22259 https://spring.io/security/cve-2024-22259  and CVE-2024-22243 https://spring.io/security/cve-2024-22243 , but with different input.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,13 +1,13 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6623-c6mr-6737",
"modified": "2024-05-02T19:03:17Z",
"modified": "2025-02-13T19:01:48Z",
"published": "2024-04-09T12:30:47Z",
"aliases": [
"CVE-2024-31862"
],
"summary": "Apache Zeppelin: Denial of service with invalid notebook name",
"details": "Improper Input Validation vulnerability in Apache Zeppelin when creating a new note from Zeppelin's UI. This issue affects Apache Zeppelin from 0.10.1 before 0.11.0.\n\nUsers are recommended to upgrade to version 0.11.0, which fixes the issue.\n\n",
"details": "Improper Input Validation vulnerability in Apache Zeppelin when creating a new note from Zeppelin's UI. This issue affects Apache Zeppelin from 0.10.1 before 0.11.0.\n\nUsers are recommended to upgrade to version 0.11.0, which fixes the issue.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,13 +1,13 @@
{
"schema_version": "1.4.0",
"id": "GHSA-79vv-vp32-gpp7",
"modified": "2024-11-18T16:26:39Z",
"modified": "2025-02-13T19:01:30Z",
"published": "2024-04-12T09:33:40Z",
"aliases": [
"CVE-2024-27309"
],
"summary": "Apache Kafka: Potential incorrect access control during migration from ZK mode to KRaft mode",
"details": "While an Apache Kafka cluster is being migrated from ZooKeeper mode to KRaft mode, in some cases ACLs will not be correctly enforced.\n\nTwo preconditions are needed to trigger the bug:\n1. The administrator decides to remove an ACL\n2. The resource associated with the removed ACL continues to have two or more other ACLs associated with it after the removal.\n\nWhen those two preconditions are met, Kafka will treat the resource as if it had only one ACL associated with it after the removal, rather than the two or more that would be correct.\n\nThe incorrect condition is cleared by removing all brokers in ZK mode, or by adding a new ACL to the affected resource. Once the migration is completed, there is no metadata loss (the ACLs all remain).\n\nThe full impact depends on the ACLs in use. If only ALLOW ACLs were configured during the migration, the impact would be limited to availability impact. if DENY ACLs were configured, the impact could include confidentiality and integrity impact depending on the ACLs configured, as the DENY ACLs might be ignored due to this vulnerability during the migration period.\n\n",
"details": "While an Apache Kafka cluster is being migrated from ZooKeeper mode to KRaft mode, in some cases ACLs will not be correctly enforced.\n\nTwo preconditions are needed to trigger the bug:\n1. The administrator decides to remove an ACL\n2. The resource associated with the removed ACL continues to have two or more other ACLs associated with it after the removal.\n\nWhen those two preconditions are met, Kafka will treat the resource as if it had only one ACL associated with it after the removal, rather than the two or more that would be correct.\n\nThe incorrect condition is cleared by removing all brokers in ZK mode, or by adding a new ACL to the affected resource. Once the migration is completed, there is no metadata loss (the ACLs all remain).\n\nThe full impact depends on the ACLs in use. If only ALLOW ACLs were configured during the migration, the impact would be limited to availability impact. if DENY ACLs were configured, the impact could include confidentiality and integrity impact depending on the ACLs configured, as the DENY ACLs might be ignored due to this vulnerability during the migration period.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,13 +1,13 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cvqr-mwh6-2vc6",
"modified": "2024-05-02T14:53:08Z",
"modified": "2025-02-13T19:00:40Z",
"published": "2024-04-21T18:30:36Z",
"aliases": [
"CVE-2024-29217"
],
"summary": "Apache Answer: XSS vulnerability when changing personal website",
"details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'/`XSS`) vulnerability in Apache Answer.This issue affects Apache Answer: before 1.3.0.\n\nXSS attack when user changes personal website. A logged-in user, when modifying their personal website, can input malicious code in the website to create such an attack.\nUsers are recommended to upgrade to version [1.3.0], which fixes the issue.\n\n",
"details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'/`XSS`) vulnerability in Apache Answer.This issue affects Apache Answer: before 1.3.0.\n\nXSS attack when user changes personal website. A logged-in user, when modifying their personal website, can input malicious code in the website to create such an attack.\nUsers are recommended to upgrade to version [1.3.0], which fixes the issue.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g64r-xf39-q4p5",
"modified": "2024-05-02T19:00:12Z",
"modified": "2025-02-13T19:01:59Z",
"published": "2024-04-09T09:31:12Z",
"aliases": [
"CVE-2024-31860"
@@ -1,13 +1,13 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g9qx-25vj-rf53",
"modified": "2024-11-01T18:36:45Z",
"modified": "2025-02-13T19:01:24Z",
"published": "2024-04-12T15:37:22Z",
"aliases": [
"CVE-2024-31391"
],
"summary": "Apache Solr Operator liveness and readiness probes may leak basic auth credentials",
"details": "Insertion of Sensitive Information into Log File vulnerability in the Apache Solr Operator.\n\nThis issue affects all versions of the Apache Solr Operator from 0.3.0 through 0.8.0.\n\nWhen asked to bootstrap Solr security, the operator will enable basic authentication and create several accounts for accessing Solr: including the \"solr\" and \"admin\" accounts for use by end-users, and a \"k8s-oper\" account which the operator uses for its own requests to Solr.\nOne common source of these operator requests is healthchecks: liveness, readiness, and startup probes are all used to determine Solr's health and ability to receive traffic.\nBy default, the operator configures the Solr APIs used for these probes to be exempt from authentication, but users may specifically request that authentication be required on probe endpoints as well.\nWhenever one of these probes would fail, if authentication was in use, the Solr Operator would create a Kubernetes \"event\" containing the username and password of the \"k8s-oper\" account.\n\nWithin the affected version range, this vulnerability affects any solrcloud resource which (1) bootstrapped security through use of the `.solrOptions.security.authenticationType=basic` option, and (2) required authentication be used on probes by setting `.solrOptions.security.probesRequireAuth=true`.\n\nUsers are recommended to upgrade to Solr Operator version 0.8.1, which fixes this issue by ensuring that probes no longer print the credentials used for Solr requests.  Users may also mitigate the vulnerability by disabling authentication on their healthcheck probes using the setting `.solrOptions.security.probesRequireAuth=false`.\n",
"details": "Insertion of Sensitive Information into Log File vulnerability in the Apache Solr Operator.\n\nThis issue affects all versions of the Apache Solr Operator from 0.3.0 through 0.8.0.\n\nWhen asked to bootstrap Solr security, the operator will enable basic authentication and create several accounts for accessing Solr: including the \"solr\" and \"admin\" accounts for use by end-users, and a \"k8s-oper\" account which the operator uses for its own requests to Solr.\nOne common source of these operator requests is healthchecks: liveness, readiness, and startup probes are all used to determine Solr's health and ability to receive traffic.\nBy default, the operator configures the Solr APIs used for these probes to be exempt from authentication, but users may specifically request that authentication be required on probe endpoints as well.\nWhenever one of these probes would fail, if authentication was in use, the Solr Operator would create a Kubernetes \"event\" containing the username and password of the \"k8s-oper\" account.\n\nWithin the affected version range, this vulnerability affects any solrcloud resource which (1) bootstrapped security through use of the `.solrOptions.security.authenticationType=basic` option, and (2) required authentication be used on probes by setting `.solrOptions.security.probesRequireAuth=true`.\n\nUsers are recommended to upgrade to Solr Operator version 0.8.1, which fixes this issue by ensuring that probes no longer print the credentials used for Solr requests.  Users may also mitigate the vulnerability by disabling authentication on their healthcheck probes using the setting `.solrOptions.security.probesRequireAuth=false`.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,13 +1,13 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m4v8-wqvr-p9f7",
"modified": "2024-04-20T00:31:52Z",
"modified": "2025-02-13T19:02:14Z",
"published": "2024-04-04T14:20:39Z",
"aliases": [
"CVE-2024-30260"
],
"summary": "Undici's Proxy-Authorization header not cleared on cross-origin redirect for dispatch, request, stream, pipeline",
"details": "### Impact\n\nUndici cleared Authorization and Proxy-Authorization headers for `fetch()`, but did not clear them for `undici.request()`.\n\n### Patches\n\nThis has been patched in https://github.com/nodejs/undici/commit/6805746680d27a5369d7fb67bc05f95a28247d75.\nFixes has been released in v5.28.4 and v6.11.1.\n\n### Workarounds\n\nuse `fetch()` or disable `maxRedirections`.\n\n### References\n\nLinzi Shang reported this.\n\n* https://hackerone.com/reports/2408074\n* https://github.com/nodejs/undici/security/advisories/GHSA-3787-6prv-h9w3\n",
"details": "### Impact\n\nUndici cleared Authorization and Proxy-Authorization headers for `fetch()`, but did not clear them for `undici.request()`.\n\n### Patches\n\nThis has been patched in https://github.com/nodejs/undici/commit/6805746680d27a5369d7fb67bc05f95a28247d75.\nFixes has been released in v5.28.4 and v6.11.1.\n\n### Workarounds\n\nuse `fetch()` or disable `maxRedirections`.\n\n### References\n\nLinzi Shang reported this.\n\n* https://hackerone.com/reports/2408074\n* https://github.com/nodejs/undici/security/advisories/GHSA-3787-6prv-h9w3",
"severity": [
{
"type": "CVSS_V3",

Some files were not shown because too many files have changed in this diff Show More