diff --git a/advisories/github-reviewed/2023/06/GHSA-j8xg-fqg3-53r7/GHSA-j8xg-fqg3-53r7.json b/advisories/github-reviewed/2023/06/GHSA-j8xg-fqg3-53r7/GHSA-j8xg-fqg3-53r7.json index 64e5e634d57..88c441c704a 100644 --- a/advisories/github-reviewed/2023/06/GHSA-j8xg-fqg3-53r7/GHSA-j8xg-fqg3-53r7.json +++ b/advisories/github-reviewed/2023/06/GHSA-j8xg-fqg3-53r7/GHSA-j8xg-fqg3-53r7.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-j8xg-fqg3-53r7", - "modified": "2024-06-21T21:33:53Z", + "modified": "2025-02-13T19:00:43Z", "published": "2023-06-22T06:30:18Z", "aliases": [ "CVE-2023-26115" ], "summary": "word-wrap vulnerable to Regular Expression Denial of Service", - "details": "All versions of the package word-wrap are vulnerable to Regular Expression Denial of Service (ReDoS) due to the usage of an insecure regular expression within the result variable.\n", + "details": "All versions of the package word-wrap are vulnerable to Regular Expression Denial of Service (ReDoS) due to the usage of an insecure regular expression within the result variable.", "severity": [ { "type": "CVSS_V3", @@ -20,11 +20,6 @@ "ecosystem": "npm", "name": "word-wrap" }, - "ecosystem_specific": { - "affected_functions": [ - "(word-wrap)" - ] - }, "ranges": [ { "type": "ECOSYSTEM", diff --git a/advisories/github-reviewed/2023/06/GHSA-mpv3-g8m3-3fjc/GHSA-mpv3-g8m3-3fjc.json b/advisories/github-reviewed/2023/06/GHSA-mpv3-g8m3-3fjc/GHSA-mpv3-g8m3-3fjc.json index 0b3b2fb4faf..5f66f38135f 100644 --- a/advisories/github-reviewed/2023/06/GHSA-mpv3-g8m3-3fjc/GHSA-mpv3-g8m3-3fjc.json +++ b/advisories/github-reviewed/2023/06/GHSA-mpv3-g8m3-3fjc/GHSA-mpv3-g8m3-3fjc.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-mpv3-g8m3-3fjc", - "modified": "2023-06-23T21:38:39Z", + "modified": "2025-02-13T19:00:46Z", "published": "2023-06-22T21:30:49Z", "aliases": [ "CVE-2023-3128" ], "summary": "Grafana vulnerable to Authentication Bypass by Spoofing", - "details": "Grafana is validating Azure AD accounts based on the email claim. \n\nOn Azure AD, the profile email field is not unique and can be easily modified. \n\nThis leads to account takeover and authentication bypass when Azure AD OAuth is configured with a multi-tenant app. \n\n", + "details": "Grafana is validating Azure AD accounts based on the email claim. \n\nOn Azure AD, the profile email field is not unique and can be easily modified. \n\nThis leads to account takeover and authentication bypass when Azure AD OAuth is configured with a multi-tenant app.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2023/07/GHSA-4pvw-g9fx-594r/GHSA-4pvw-g9fx-594r.json b/advisories/github-reviewed/2023/07/GHSA-4pvw-g9fx-594r/GHSA-4pvw-g9fx-594r.json index 9090078f243..dbc5a4b006b 100644 --- a/advisories/github-reviewed/2023/07/GHSA-4pvw-g9fx-594r/GHSA-4pvw-g9fx-594r.json +++ b/advisories/github-reviewed/2023/07/GHSA-4pvw-g9fx-594r/GHSA-4pvw-g9fx-594r.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-4pvw-g9fx-594r", - "modified": "2023-08-03T17:39:56Z", + "modified": "2025-02-13T19:02:06Z", "published": "2023-07-25T18:30:32Z", "aliases": [ "CVE-2023-38435" ], "summary": "Cross-site Scripting in healthcheck webconsole plugin", - "details": "\nAn improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Apache Felix Healthcheck Webconsole Plugin version 2.0.2 and prior may allow an attacker to perform a reflected cross-site scripting (XSS) attack.\n\nUpgrade to Apache Felix Healthcheck Webconsole Plugin 2.1.0 or higher.", + "details": "An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Apache Felix Healthcheck Webconsole Plugin version 2.0.2 and prior may allow an attacker to perform a reflected cross-site scripting (XSS) attack.\n\nUpgrade to Apache Felix Healthcheck Webconsole Plugin 2.1.0 or higher.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2023/07/GHSA-4q2q-q5pw-2342/GHSA-4q2q-q5pw-2342.json b/advisories/github-reviewed/2023/07/GHSA-4q2q-q5pw-2342/GHSA-4q2q-q5pw-2342.json index 09be7be3a8f..77f65dbd85d 100644 --- a/advisories/github-reviewed/2023/07/GHSA-4q2q-q5pw-2342/GHSA-4q2q-q5pw-2342.json +++ b/advisories/github-reviewed/2023/07/GHSA-4q2q-q5pw-2342/GHSA-4q2q-q5pw-2342.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-4q2q-q5pw-2342", - "modified": "2023-07-25T16:38:48Z", + "modified": "2025-02-13T19:00:55Z", "published": "2023-07-13T09:30:28Z", "aliases": [ "CVE-2023-37415" ], "summary": "Apache Airflow Apache Hive Provider Improper Input Validation vulnerability", - "details": "Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Apache Hive Provider.\n\nPatching on top of CVE-2023-35797\nBefore 6.1.2 the proxy_user option can also inject semicolon.\n\nThis issue affects Apache Airflow Apache Hive Provider: before 6.1.2.\n\nIt is recommended updating provider version to 6.1.2 in order to avoid this vulnerability.\n\n", + "details": "Improper Input Validation vulnerability in Apache Software Foundation Apache Airflow Apache Hive Provider.\n\nPatching on top of CVE-2023-35797\nBefore 6.1.2 the proxy_user option can also inject semicolon.\n\nThis issue affects Apache Airflow Apache Hive Provider: before 6.1.2.\n\nIt is recommended updating provider version to 6.1.2 in order to avoid this vulnerability.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2023/07/GHSA-86pw-4rqp-6x7v/GHSA-86pw-4rqp-6x7v.json b/advisories/github-reviewed/2023/07/GHSA-86pw-4rqp-6x7v/GHSA-86pw-4rqp-6x7v.json index 5fbd6ffe658..653813e7385 100644 --- a/advisories/github-reviewed/2023/07/GHSA-86pw-4rqp-6x7v/GHSA-86pw-4rqp-6x7v.json +++ b/advisories/github-reviewed/2023/07/GHSA-86pw-4rqp-6x7v/GHSA-86pw-4rqp-6x7v.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-86pw-4rqp-6x7v", - "modified": "2023-08-03T17:55:50Z", + "modified": "2025-02-13T19:01:45Z", "published": "2023-07-25T09:30:17Z", "aliases": [ "CVE-2023-34189" ], "summary": "Apache InLong: General user can delete and update process", - "details": "Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0. The attacker could use general users to delete and update the process, which only the admin can operate occurrences. \n\nUsers are advised to upgrade to Apache InLong's 1.8.0 or cherry-pick https://github.com/apache/inlong/pull/8109  to solve it.\n\n", + "details": "Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0. The attacker could use general users to delete and update the process, which only the admin can operate occurrences. \n\nUsers are advised to upgrade to Apache InLong's 1.8.0 or cherry-pick https://github.com/apache/inlong/pull/8109  to solve it.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2023/07/GHSA-cgcv-5272-97pr/GHSA-cgcv-5272-97pr.json b/advisories/github-reviewed/2023/07/GHSA-cgcv-5272-97pr/GHSA-cgcv-5272-97pr.json index 99f20cca8f3..f35b26c93f6 100644 --- a/advisories/github-reviewed/2023/07/GHSA-cgcv-5272-97pr/GHSA-cgcv-5272-97pr.json +++ b/advisories/github-reviewed/2023/07/GHSA-cgcv-5272-97pr/GHSA-cgcv-5272-97pr.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-cgcv-5272-97pr", - "modified": "2023-07-07T16:29:50Z", + "modified": "2025-02-13T19:01:03Z", "published": "2023-07-03T21:30:57Z", "aliases": [ "CVE-2023-2728" ], "summary": "Kubernetes mountable secrets policy bypass", - "details": "Users may be able to launch containers that bypass the mountable secrets policy enforced by the ServiceAccount admission plugin when using ephemeral containers. The policy ensures pods running with a service account may only reference secrets specified in the service account’s secrets field. Kubernetes clusters are only affected if the ServiceAccount admission plugin and the `kubernetes.io/enforce-mountable-secrets` annotation are used together with ephemeral containers.\n\n", + "details": "Users may be able to launch containers that bypass the mountable secrets policy enforced by the ServiceAccount admission plugin when using ephemeral containers. The policy ensures pods running with a service account may only reference secrets specified in the service account’s secrets field. Kubernetes clusters are only affected if the ServiceAccount admission plugin and the `kubernetes.io/enforce-mountable-secrets` annotation are used together with ephemeral containers.", "severity": [ { "type": "CVSS_V3", @@ -129,6 +129,10 @@ "type": "WEB", "url": "https://groups.google.com/g/kubernetes-security-announce/c/vPWYJ_L84m8" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20230803-0004" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2023/07/06/3" diff --git a/advisories/github-reviewed/2023/07/GHSA-cggh-pq45-6h9x/GHSA-cggh-pq45-6h9x.json b/advisories/github-reviewed/2023/07/GHSA-cggh-pq45-6h9x/GHSA-cggh-pq45-6h9x.json index cc3e6d28bf0..6daf28b588d 100644 --- a/advisories/github-reviewed/2023/07/GHSA-cggh-pq45-6h9x/GHSA-cggh-pq45-6h9x.json +++ b/advisories/github-reviewed/2023/07/GHSA-cggh-pq45-6h9x/GHSA-cggh-pq45-6h9x.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-cggh-pq45-6h9x", - "modified": "2024-06-24T21:25:02Z", + "modified": "2025-02-13T19:00:49Z", "published": "2023-07-01T00:30:46Z", "aliases": [ "CVE-2023-30589" ], "summary": "llhttp vulnerable to HTTP request smuggling", - "details": "The llhttp parser in the http module in Node v20.2.0 does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Smuggling (HRS).\n\nThe CR character (without LF) is sufficient to delimit HTTP header fields in the llhttp parser. According to RFC7230 section 3, only the CRLF sequence should delimit each header-field. This impacts all Node.js active versions: v16, v18, and, v20\n", + "details": "The llhttp parser in the http module in Node v20.2.0 does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Smuggling (HRS).\n\nThe CR character (without LF) is sufficient to delimit HTTP header fields in the llhttp parser. According to RFC7230 section 3, only the CRLF sequence should delimit each header-field. This impacts all Node.js active versions: v16, v18, and, v20", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2023/07/GHSA-gpq8-963w-8qc9/GHSA-gpq8-963w-8qc9.json b/advisories/github-reviewed/2023/07/GHSA-gpq8-963w-8qc9/GHSA-gpq8-963w-8qc9.json index 3cd78b2a994..b21900a285b 100644 --- a/advisories/github-reviewed/2023/07/GHSA-gpq8-963w-8qc9/GHSA-gpq8-963w-8qc9.json +++ b/advisories/github-reviewed/2023/07/GHSA-gpq8-963w-8qc9/GHSA-gpq8-963w-8qc9.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-gpq8-963w-8qc9", - "modified": "2023-07-20T14:54:54Z", + "modified": "2025-02-13T19:00:52Z", "published": "2023-07-12T12:31:36Z", "aliases": [ "CVE-2023-37582" ], "summary": "RocketMQ NameServer component Code Injection vulnerability", - "details": "The RocketMQ NameServer component still has a remote command execution vulnerability as the CVE-2023-33246 issue was not completely fixed in version 5.1.1. \n\nWhen NameServer address are leaked on the extranet and lack permission verification, an attacker can exploit this vulnerability by using the update configuration function on the NameServer component to execute commands as the system users that RocketMQ is running as. \n\nIt is recommended for users to upgrade their NameServer version to 5.1.2 or above for RocketMQ 5.x or 4.9.7 or above for RocketMQ 4.x to prevent these attacks.\n", + "details": "The RocketMQ NameServer component still has a remote command execution vulnerability as the CVE-2023-33246 issue was not completely fixed in version 5.1.1. \n\nWhen NameServer address are leaked on the extranet and lack permission verification, an attacker can exploit this vulnerability by using the update configuration function on the NameServer component to execute commands as the system users that RocketMQ is running as. \n\nIt is recommended for users to upgrade their NameServer version to 5.1.2 or above for RocketMQ 5.x or 4.9.7 or above for RocketMQ 4.x to prevent these attacks.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2023/07/GHSA-pmhc-2g4f-85cg/GHSA-pmhc-2g4f-85cg.json b/advisories/github-reviewed/2023/07/GHSA-pmhc-2g4f-85cg/GHSA-pmhc-2g4f-85cg.json index 2ed976ef328..bc6069bbf25 100644 --- a/advisories/github-reviewed/2023/07/GHSA-pmhc-2g4f-85cg/GHSA-pmhc-2g4f-85cg.json +++ b/advisories/github-reviewed/2023/07/GHSA-pmhc-2g4f-85cg/GHSA-pmhc-2g4f-85cg.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-pmhc-2g4f-85cg", - "modified": "2024-10-02T21:39:09Z", + "modified": "2025-02-13T19:01:43Z", "published": "2023-07-24T21:30:39Z", "aliases": [ "CVE-2023-34478" ], "summary": "Path Traversal in Apache Shiro", - "details": "Apache Shiro, before 1.12.0 or 2.0.0-alpha-3, may be susceptible to a path traversal attack that results in an authentication bypass when used together with APIs or other web frameworks that route requests based on non-normalized requests.\n\nMitigation: Update to Apache Shiro 1.12.0+ or 2.0.0-alpha-3+\n", + "details": "Apache Shiro, before 1.12.0 or 2.0.0-alpha-3, may be susceptible to a path traversal attack that results in an authentication bypass when used together with APIs or other web frameworks that route requests based on non-normalized requests.\n\nMitigation: Update to Apache Shiro 1.12.0+ or 2.0.0-alpha-3+", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2023/07/GHSA-pq67-9jf9-hc3c/GHSA-pq67-9jf9-hc3c.json b/advisories/github-reviewed/2023/07/GHSA-pq67-9jf9-hc3c/GHSA-pq67-9jf9-hc3c.json index b12164fa522..61865c12f2e 100644 --- a/advisories/github-reviewed/2023/07/GHSA-pq67-9jf9-hc3c/GHSA-pq67-9jf9-hc3c.json +++ b/advisories/github-reviewed/2023/07/GHSA-pq67-9jf9-hc3c/GHSA-pq67-9jf9-hc3c.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-pq67-9jf9-hc3c", - "modified": "2024-10-02T21:39:49Z", + "modified": "2025-02-13T19:01:49Z", "published": "2023-07-25T09:30:18Z", "aliases": [ "CVE-2023-34434" ], "summary": "JDBC URL bypassing by allowLoadLocalInfileInPath param", - "details": "Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0. \n\nThe attacker could bypass the current logic and achieve arbitrary file reading. To solve it, users are advised to upgrade to Apache InLong's 1.8.0 or cherry-pick https://github.com/apache/inlong/pull/8130 .\n\n", + "details": "Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0. \n\nThe attacker could bypass the current logic and achieve arbitrary file reading. To solve it, users are advised to upgrade to Apache InLong's 1.8.0 or cherry-pick https://github.com/apache/inlong/pull/8130 .", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2023/07/GHSA-q8cm-3v62-jj79/GHSA-q8cm-3v62-jj79.json b/advisories/github-reviewed/2023/07/GHSA-q8cm-3v62-jj79/GHSA-q8cm-3v62-jj79.json index 9b603f746eb..e5a8197a3cf 100644 --- a/advisories/github-reviewed/2023/07/GHSA-q8cm-3v62-jj79/GHSA-q8cm-3v62-jj79.json +++ b/advisories/github-reviewed/2023/07/GHSA-q8cm-3v62-jj79/GHSA-q8cm-3v62-jj79.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-q8cm-3v62-jj79", - "modified": "2023-08-03T17:59:54Z", + "modified": "2025-02-13T19:01:59Z", "published": "2023-07-25T15:30:26Z", "aliases": [ "CVE-2023-37895" ], "summary": "Remote code execution in Apache Jackrabbit", - "details": "Java object deserialization issue in Jackrabbit webapp/standalone on all platforms allows attacker to remotely execute code via RMIVersions up to (including) 2.20.10 (stable branch) and 2.21.17 (unstable branch) use the component \"commons-beanutils\", which contains a class that can be used for remote code execution over RMI.\n\nUsers are advised to immediately update to versions 2.20.11 or 2.21.18. Note that earlier stable branches (1.0.x .. 2.18.x) have been EOLd already and do not receive updates anymore.\n\nIn general, RMI support can expose vulnerabilities by the mere presence of an exploitable class on the classpath. Even if Jackrabbit itself does not contain any code known to be exploitable anymore, adding other components to your server can expose the same type of problem. We therefore recommend to disable RMI access altogether (see further below), and will discuss deprecating RMI support in future Jackrabbit releases.\n\nHow to check whether RMI support is enabledRMI support can be over an RMI-specific TCP port, and over an HTTP binding. Both are by default enabled in Jackrabbit webapp/standalone.\n\nThe native RMI protocol by default uses port 1099. To check whether it is enabled, tools like \"netstat\" can be used to check.\n\nRMI-over-HTTP in Jackrabbit by default uses the path \"/rmi\". So when running standalone on port 8080, check whether an HTTP GET request on localhost:8080/rmi returns 404 (not enabled) or 200 (enabled). Note that the HTTP path may be different when the webapp is deployed in a container as non-root context, in which case the prefix is under the user's control.\n\nTurning off RMIFind web.xml (either in JAR/WAR file or in unpacked web application folder), and remove the declaration and the mapping definition for the RemoteBindingServlet:\n\n        \n            RMI\n            org.apache.jackrabbit.servlet.remote.RemoteBindingServlet\n        \n\n        \n            RMI\n            /rmi\n        \n\nFind the bootstrap.properties file (in $REPOSITORY_HOME), and set\n\n        rmi.enabled=false\n\n    and also remove\n\n        rmi.host\n        rmi.port\n        rmi.url-pattern\n\n If there is no file named bootstrap.properties in $REPOSITORY_HOME, it is located somewhere in the classpath. In this case, place a copy in $REPOSITORY_HOME and modify it as explained.\n\n \n\n", + "details": "Java object deserialization issue in Jackrabbit webapp/standalone on all platforms allows attacker to remotely execute code via RMIVersions up to (including) 2.20.10 (stable branch) and 2.21.17 (unstable branch) use the component \"commons-beanutils\", which contains a class that can be used for remote code execution over RMI.\n\nUsers are advised to immediately update to versions 2.20.11 or 2.21.18. Note that earlier stable branches (1.0.x .. 2.18.x) have been EOLd already and do not receive updates anymore.\n\nIn general, RMI support can expose vulnerabilities by the mere presence of an exploitable class on the classpath. Even if Jackrabbit itself does not contain any code known to be exploitable anymore, adding other components to your server can expose the same type of problem. We therefore recommend to disable RMI access altogether (see further below), and will discuss deprecating RMI support in future Jackrabbit releases.\n\nHow to check whether RMI support is enabledRMI support can be over an RMI-specific TCP port, and over an HTTP binding. Both are by default enabled in Jackrabbit webapp/standalone.\n\nThe native RMI protocol by default uses port 1099. To check whether it is enabled, tools like \"netstat\" can be used to check.\n\nRMI-over-HTTP in Jackrabbit by default uses the path \"/rmi\". So when running standalone on port 8080, check whether an HTTP GET request on localhost:8080/rmi returns 404 (not enabled) or 200 (enabled). Note that the HTTP path may be different when the webapp is deployed in a container as non-root context, in which case the prefix is under the user's control.\n\nTurning off RMIFind web.xml (either in JAR/WAR file or in unpacked web application folder), and remove the declaration and the mapping definition for the RemoteBindingServlet:\n\n        \n            RMI\n            org.apache.jackrabbit.servlet.remote.RemoteBindingServlet\n        \n\n        \n            RMI\n            /rmi\n        \n\nFind the bootstrap.properties file (in $REPOSITORY_HOME), and set\n\n        rmi.enabled=false\n\n    and also remove\n\n        rmi.host\n        rmi.port\n        rmi.url-pattern\n\n If there is no file named bootstrap.properties in $REPOSITORY_HOME, it is located somewhere in the classpath. In this case, place a copy in $REPOSITORY_HOME and modify it as explained.\n\n ", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2023/07/GHSA-qc2g-gmh6-95p4/GHSA-qc2g-gmh6-95p4.json b/advisories/github-reviewed/2023/07/GHSA-qc2g-gmh6-95p4/GHSA-qc2g-gmh6-95p4.json index f4e7150476a..d1e86f22d2b 100644 --- a/advisories/github-reviewed/2023/07/GHSA-qc2g-gmh6-95p4/GHSA-qc2g-gmh6-95p4.json +++ b/advisories/github-reviewed/2023/07/GHSA-qc2g-gmh6-95p4/GHSA-qc2g-gmh6-95p4.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-qc2g-gmh6-95p4", - "modified": "2023-07-05T22:46:57Z", + "modified": "2025-02-13T19:00:59Z", "published": "2023-07-03T21:30:57Z", "aliases": [ "CVE-2023-2727" ], "summary": "kube-apiserver vulnerable to policy bypass", - "details": "Users may be able to launch containers using images that are restricted by ImagePolicyWebhook when using ephemeral containers. Kubernetes clusters are only affected if the ImagePolicyWebhook admission plugin is used together with ephemeral containers.\n\n", + "details": "Users may be able to launch containers using images that are restricted by ImagePolicyWebhook when using ephemeral containers. Kubernetes clusters are only affected if the ImagePolicyWebhook admission plugin is used together with ephemeral containers.", "severity": [ { "type": "CVSS_V3", @@ -129,6 +129,10 @@ "type": "WEB", "url": "https://groups.google.com/g/kubernetes-security-announce/c/vPWYJ_L84m8" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20230803-0004" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2023/07/06/2" diff --git a/advisories/github-reviewed/2023/07/GHSA-r5pv-7g89-cxmc/GHSA-r5pv-7g89-cxmc.json b/advisories/github-reviewed/2023/07/GHSA-r5pv-7g89-cxmc/GHSA-r5pv-7g89-cxmc.json index 4e8be852eba..02c8244fb82 100644 --- a/advisories/github-reviewed/2023/07/GHSA-r5pv-7g89-cxmc/GHSA-r5pv-7g89-cxmc.json +++ b/advisories/github-reviewed/2023/07/GHSA-r5pv-7g89-cxmc/GHSA-r5pv-7g89-cxmc.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-r5pv-7g89-cxmc", - "modified": "2024-10-02T21:40:22Z", + "modified": "2025-02-13T19:01:55Z", "published": "2023-07-25T09:30:18Z", "aliases": [ "CVE-2023-35088" ], "summary": "SQL injection in audit endpoint", - "details": "Improper Neutralization of Special Elements Used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0. \nIn the toAuditCkSql method, the groupId, streamId, auditId, and dt are directly concatenated into the SQL query statement, which may lead to SQL injection attacks.\nUsers are advised to upgrade to Apache InLong's 1.8.0 or cherry-pick [1] to solve it.\n\n[1] https://github.com/apache/inlong/pull/8198 \n\n", + "details": "Improper Neutralization of Special Elements Used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0. \nIn the toAuditCkSql method, the groupId, streamId, auditId, and dt are directly concatenated into the SQL query statement, which may lead to SQL injection attacks.\nUsers are advised to upgrade to Apache InLong's 1.8.0 or cherry-pick [1] to solve it.\n\n[1] https://github.com/apache/inlong/pull/8198", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2024/04/GHSA-2wrp-6fg6-hmc5/GHSA-2wrp-6fg6-hmc5.json b/advisories/github-reviewed/2024/04/GHSA-2wrp-6fg6-hmc5/GHSA-2wrp-6fg6-hmc5.json index dab23a13e64..27255a8dd05 100644 --- a/advisories/github-reviewed/2024/04/GHSA-2wrp-6fg6-hmc5/GHSA-2wrp-6fg6-hmc5.json +++ b/advisories/github-reviewed/2024/04/GHSA-2wrp-6fg6-hmc5/GHSA-2wrp-6fg6-hmc5.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-2wrp-6fg6-hmc5", - "modified": "2024-08-27T18:36:46Z", + "modified": "2025-02-13T19:00:56Z", "published": "2024-04-16T06:30:28Z", "aliases": [ "CVE-2024-22262" ], "summary": "Spring Framework URL Parsing with Host Validation", - "details": "Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/definitions/601.html  attack or to a SSRF attack if the URL is used after passing validation checks.\n\nThis is the same as CVE-2024-22259 https://spring.io/security/cve-2024-22259  and CVE-2024-22243 https://spring.io/security/cve-2024-22243 , but with different input.\n\n", + "details": "Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/definitions/601.html  attack or to a SSRF attack if the URL is used after passing validation checks.\n\nThis is the same as CVE-2024-22259 https://spring.io/security/cve-2024-22259  and CVE-2024-22243 https://spring.io/security/cve-2024-22243 , but with different input.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2024/04/GHSA-6623-c6mr-6737/GHSA-6623-c6mr-6737.json b/advisories/github-reviewed/2024/04/GHSA-6623-c6mr-6737/GHSA-6623-c6mr-6737.json index 73c22f341ad..d7e5908e237 100644 --- a/advisories/github-reviewed/2024/04/GHSA-6623-c6mr-6737/GHSA-6623-c6mr-6737.json +++ b/advisories/github-reviewed/2024/04/GHSA-6623-c6mr-6737/GHSA-6623-c6mr-6737.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-6623-c6mr-6737", - "modified": "2024-05-02T19:03:17Z", + "modified": "2025-02-13T19:01:48Z", "published": "2024-04-09T12:30:47Z", "aliases": [ "CVE-2024-31862" ], "summary": "Apache Zeppelin: Denial of service with invalid notebook name", - "details": "Improper Input Validation vulnerability in Apache Zeppelin when creating a new note from Zeppelin's UI. This issue affects Apache Zeppelin from 0.10.1 before 0.11.0.\n\nUsers are recommended to upgrade to version 0.11.0, which fixes the issue.\n\n", + "details": "Improper Input Validation vulnerability in Apache Zeppelin when creating a new note from Zeppelin's UI. This issue affects Apache Zeppelin from 0.10.1 before 0.11.0.\n\nUsers are recommended to upgrade to version 0.11.0, which fixes the issue.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2024/04/GHSA-79vv-vp32-gpp7/GHSA-79vv-vp32-gpp7.json b/advisories/github-reviewed/2024/04/GHSA-79vv-vp32-gpp7/GHSA-79vv-vp32-gpp7.json index c912c8da897..96e21836c27 100644 --- a/advisories/github-reviewed/2024/04/GHSA-79vv-vp32-gpp7/GHSA-79vv-vp32-gpp7.json +++ b/advisories/github-reviewed/2024/04/GHSA-79vv-vp32-gpp7/GHSA-79vv-vp32-gpp7.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-79vv-vp32-gpp7", - "modified": "2024-11-18T16:26:39Z", + "modified": "2025-02-13T19:01:30Z", "published": "2024-04-12T09:33:40Z", "aliases": [ "CVE-2024-27309" ], "summary": "Apache Kafka: Potential incorrect access control during migration from ZK mode to KRaft mode", - "details": "While an Apache Kafka cluster is being migrated from ZooKeeper mode to KRaft mode, in some cases ACLs will not be correctly enforced.\n\nTwo preconditions are needed to trigger the bug:\n1. The administrator decides to remove an ACL\n2. The resource associated with the removed ACL continues to have two or more other ACLs associated with it after the removal.\n\nWhen those two preconditions are met, Kafka will treat the resource as if it had only one ACL associated with it after the removal, rather than the two or more that would be correct.\n\nThe incorrect condition is cleared by removing all brokers in ZK mode, or by adding a new ACL to the affected resource. Once the migration is completed, there is no metadata loss (the ACLs all remain).\n\nThe full impact depends on the ACLs in use. If only ALLOW ACLs were configured during the migration, the impact would be limited to availability impact. if DENY ACLs were configured, the impact could include confidentiality and integrity impact depending on the ACLs configured, as the DENY ACLs might be ignored due to this vulnerability during the migration period.\n\n", + "details": "While an Apache Kafka cluster is being migrated from ZooKeeper mode to KRaft mode, in some cases ACLs will not be correctly enforced.\n\nTwo preconditions are needed to trigger the bug:\n1. The administrator decides to remove an ACL\n2. The resource associated with the removed ACL continues to have two or more other ACLs associated with it after the removal.\n\nWhen those two preconditions are met, Kafka will treat the resource as if it had only one ACL associated with it after the removal, rather than the two or more that would be correct.\n\nThe incorrect condition is cleared by removing all brokers in ZK mode, or by adding a new ACL to the affected resource. Once the migration is completed, there is no metadata loss (the ACLs all remain).\n\nThe full impact depends on the ACLs in use. If only ALLOW ACLs were configured during the migration, the impact would be limited to availability impact. if DENY ACLs were configured, the impact could include confidentiality and integrity impact depending on the ACLs configured, as the DENY ACLs might be ignored due to this vulnerability during the migration period.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2024/04/GHSA-cvqr-mwh6-2vc6/GHSA-cvqr-mwh6-2vc6.json b/advisories/github-reviewed/2024/04/GHSA-cvqr-mwh6-2vc6/GHSA-cvqr-mwh6-2vc6.json index c8e9c023949..058933dfe9c 100644 --- a/advisories/github-reviewed/2024/04/GHSA-cvqr-mwh6-2vc6/GHSA-cvqr-mwh6-2vc6.json +++ b/advisories/github-reviewed/2024/04/GHSA-cvqr-mwh6-2vc6/GHSA-cvqr-mwh6-2vc6.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-cvqr-mwh6-2vc6", - "modified": "2024-05-02T14:53:08Z", + "modified": "2025-02-13T19:00:40Z", "published": "2024-04-21T18:30:36Z", "aliases": [ "CVE-2024-29217" ], "summary": "Apache Answer: XSS vulnerability when changing personal website", - "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'/`XSS`) vulnerability in Apache Answer.This issue affects Apache Answer: before 1.3.0.\n\nXSS attack when user changes personal website. A logged-in user, when modifying their personal website, can input malicious code in the website to create such an attack.\nUsers are recommended to upgrade to version [1.3.0], which fixes the issue.\n\n", + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'/`XSS`) vulnerability in Apache Answer.This issue affects Apache Answer: before 1.3.0.\n\nXSS attack when user changes personal website. A logged-in user, when modifying their personal website, can input malicious code in the website to create such an attack.\nUsers are recommended to upgrade to version [1.3.0], which fixes the issue.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2024/04/GHSA-g64r-xf39-q4p5/GHSA-g64r-xf39-q4p5.json b/advisories/github-reviewed/2024/04/GHSA-g64r-xf39-q4p5/GHSA-g64r-xf39-q4p5.json index 639d632dd04..fc34d3bbaba 100644 --- a/advisories/github-reviewed/2024/04/GHSA-g64r-xf39-q4p5/GHSA-g64r-xf39-q4p5.json +++ b/advisories/github-reviewed/2024/04/GHSA-g64r-xf39-q4p5/GHSA-g64r-xf39-q4p5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g64r-xf39-q4p5", - "modified": "2024-05-02T19:00:12Z", + "modified": "2025-02-13T19:01:59Z", "published": "2024-04-09T09:31:12Z", "aliases": [ "CVE-2024-31860" diff --git a/advisories/github-reviewed/2024/04/GHSA-g9qx-25vj-rf53/GHSA-g9qx-25vj-rf53.json b/advisories/github-reviewed/2024/04/GHSA-g9qx-25vj-rf53/GHSA-g9qx-25vj-rf53.json index d6ed5d1aeba..47b3c8c4c76 100644 --- a/advisories/github-reviewed/2024/04/GHSA-g9qx-25vj-rf53/GHSA-g9qx-25vj-rf53.json +++ b/advisories/github-reviewed/2024/04/GHSA-g9qx-25vj-rf53/GHSA-g9qx-25vj-rf53.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-g9qx-25vj-rf53", - "modified": "2024-11-01T18:36:45Z", + "modified": "2025-02-13T19:01:24Z", "published": "2024-04-12T15:37:22Z", "aliases": [ "CVE-2024-31391" ], "summary": "Apache Solr Operator liveness and readiness probes may leak basic auth credentials", - "details": "Insertion of Sensitive Information into Log File vulnerability in the Apache Solr Operator.\n\nThis issue affects all versions of the Apache Solr Operator from 0.3.0 through 0.8.0.\n\nWhen asked to bootstrap Solr security, the operator will enable basic authentication and create several accounts for accessing Solr: including the \"solr\" and \"admin\" accounts for use by end-users, and a \"k8s-oper\" account which the operator uses for its own requests to Solr.\nOne common source of these operator requests is healthchecks: liveness, readiness, and startup probes are all used to determine Solr's health and ability to receive traffic.\nBy default, the operator configures the Solr APIs used for these probes to be exempt from authentication, but users may specifically request that authentication be required on probe endpoints as well.\nWhenever one of these probes would fail, if authentication was in use, the Solr Operator would create a Kubernetes \"event\" containing the username and password of the \"k8s-oper\" account.\n\nWithin the affected version range, this vulnerability affects any solrcloud resource which (1) bootstrapped security through use of the `.solrOptions.security.authenticationType=basic` option, and (2) required authentication be used on probes by setting `.solrOptions.security.probesRequireAuth=true`.\n\nUsers are recommended to upgrade to Solr Operator version 0.8.1, which fixes this issue by ensuring that probes no longer print the credentials used for Solr requests.  Users may also mitigate the vulnerability by disabling authentication on their healthcheck probes using the setting `.solrOptions.security.probesRequireAuth=false`.\n", + "details": "Insertion of Sensitive Information into Log File vulnerability in the Apache Solr Operator.\n\nThis issue affects all versions of the Apache Solr Operator from 0.3.0 through 0.8.0.\n\nWhen asked to bootstrap Solr security, the operator will enable basic authentication and create several accounts for accessing Solr: including the \"solr\" and \"admin\" accounts for use by end-users, and a \"k8s-oper\" account which the operator uses for its own requests to Solr.\nOne common source of these operator requests is healthchecks: liveness, readiness, and startup probes are all used to determine Solr's health and ability to receive traffic.\nBy default, the operator configures the Solr APIs used for these probes to be exempt from authentication, but users may specifically request that authentication be required on probe endpoints as well.\nWhenever one of these probes would fail, if authentication was in use, the Solr Operator would create a Kubernetes \"event\" containing the username and password of the \"k8s-oper\" account.\n\nWithin the affected version range, this vulnerability affects any solrcloud resource which (1) bootstrapped security through use of the `.solrOptions.security.authenticationType=basic` option, and (2) required authentication be used on probes by setting `.solrOptions.security.probesRequireAuth=true`.\n\nUsers are recommended to upgrade to Solr Operator version 0.8.1, which fixes this issue by ensuring that probes no longer print the credentials used for Solr requests.  Users may also mitigate the vulnerability by disabling authentication on their healthcheck probes using the setting `.solrOptions.security.probesRequireAuth=false`.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2024/04/GHSA-m4v8-wqvr-p9f7/GHSA-m4v8-wqvr-p9f7.json b/advisories/github-reviewed/2024/04/GHSA-m4v8-wqvr-p9f7/GHSA-m4v8-wqvr-p9f7.json index d4305cb7f01..32dc46bfe82 100644 --- a/advisories/github-reviewed/2024/04/GHSA-m4v8-wqvr-p9f7/GHSA-m4v8-wqvr-p9f7.json +++ b/advisories/github-reviewed/2024/04/GHSA-m4v8-wqvr-p9f7/GHSA-m4v8-wqvr-p9f7.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-m4v8-wqvr-p9f7", - "modified": "2024-04-20T00:31:52Z", + "modified": "2025-02-13T19:02:14Z", "published": "2024-04-04T14:20:39Z", "aliases": [ "CVE-2024-30260" ], "summary": "Undici's Proxy-Authorization header not cleared on cross-origin redirect for dispatch, request, stream, pipeline", - "details": "### Impact\n\nUndici cleared Authorization and Proxy-Authorization headers for `fetch()`, but did not clear them for `undici.request()`.\n\n### Patches\n\nThis has been patched in https://github.com/nodejs/undici/commit/6805746680d27a5369d7fb67bc05f95a28247d75.\nFixes has been released in v5.28.4 and v6.11.1.\n\n### Workarounds\n\nuse `fetch()` or disable `maxRedirections`.\n\n### References\n\nLinzi Shang reported this.\n\n* https://hackerone.com/reports/2408074\n* https://github.com/nodejs/undici/security/advisories/GHSA-3787-6prv-h9w3\n", + "details": "### Impact\n\nUndici cleared Authorization and Proxy-Authorization headers for `fetch()`, but did not clear them for `undici.request()`.\n\n### Patches\n\nThis has been patched in https://github.com/nodejs/undici/commit/6805746680d27a5369d7fb67bc05f95a28247d75.\nFixes has been released in v5.28.4 and v6.11.1.\n\n### Workarounds\n\nuse `fetch()` or disable `maxRedirections`.\n\n### References\n\nLinzi Shang reported this.\n\n* https://hackerone.com/reports/2408074\n* https://github.com/nodejs/undici/security/advisories/GHSA-3787-6prv-h9w3", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2024/04/GHSA-mr82-8j83-vxmv/GHSA-mr82-8j83-vxmv.json b/advisories/github-reviewed/2024/04/GHSA-mr82-8j83-vxmv/GHSA-mr82-8j83-vxmv.json index d0d2ee291d0..921ac320214 100644 --- a/advisories/github-reviewed/2024/04/GHSA-mr82-8j83-vxmv/GHSA-mr82-8j83-vxmv.json +++ b/advisories/github-reviewed/2024/04/GHSA-mr82-8j83-vxmv/GHSA-mr82-8j83-vxmv.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-mr82-8j83-vxmv", - "modified": "2024-04-26T03:30:28Z", + "modified": "2025-02-13T19:01:02Z", "published": "2024-04-15T03:31:00Z", "aliases": [ "CVE-2024-3772" ], "summary": "Pydantic regular expression denial of service", - "details": "Regular expression denial of service in Pydantic < 2.4.0, < 1.10.13 allows remote attackers to cause denial of service via a crafted email string.\n", + "details": "Regular expression denial of service in Pydantic < 2.4.0, < 1.10.13 allows remote attackers to cause denial of service via a crafted email string.", "severity": [ { "type": "CVSS_V3",