diff --git a/advisories/github-reviewed/2024/08/GHSA-795c-9xpc-xw6g/GHSA-795c-9xpc-xw6g.json b/advisories/github-reviewed/2024/08/GHSA-795c-9xpc-xw6g/GHSA-795c-9xpc-xw6g.json new file mode 100644 index 00000000000..786c005634a --- /dev/null +++ b/advisories/github-reviewed/2024/08/GHSA-795c-9xpc-xw6g/GHSA-795c-9xpc-xw6g.json @@ -0,0 +1,100 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-795c-9xpc-xw6g", + "modified": "2024-08-07T19:02:12Z", + "published": "2024-08-07T15:30:42Z", + "aliases": [ + "CVE-2024-41990" + ], + "summary": "Django vulnerable to a denial-of-service attack", + "details": "An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The urlize() and urlizetrunc() template filters are subject to a potential denial-of-service attack via very large inputs with a specific sequence of characters.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "PyPI", + "name": "Django" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "5.0" + }, + { + "fixed": "5.0.8" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "PyPI", + "name": "Django" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "4.2" + }, + { + "fixed": "4.2.15" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41990" + }, + { + "type": "WEB", + "url": "https://github.com/django/django/commit/7b7b909579c8311c140c89b8a9431bf537febf93" + }, + { + "type": "WEB", + "url": "https://github.com/django/django/commit/d0a82e26a74940bf0c78204933c3bdd6a283eb88" + }, + { + "type": "WEB", + "url": "https://docs.djangoproject.com/en/dev/releases/security" + }, + { + "type": "PACKAGE", + "url": "https://github.com/django/django" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/django/PYSEC-2024-68.yaml" + }, + { + "type": "WEB", + "url": "https://www.djangoproject.com/weblog/2024/aug/06/security-releases" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-130" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-08-07T19:02:12Z", + "nvd_published_at": "2024-08-07T15:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/08/GHSA-jh75-99hh-qvx9/GHSA-jh75-99hh-qvx9.json b/advisories/github-reviewed/2024/08/GHSA-jh75-99hh-qvx9/GHSA-jh75-99hh-qvx9.json new file mode 100644 index 00000000000..fba79c925c8 --- /dev/null +++ b/advisories/github-reviewed/2024/08/GHSA-jh75-99hh-qvx9/GHSA-jh75-99hh-qvx9.json @@ -0,0 +1,100 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jh75-99hh-qvx9", + "modified": "2024-08-07T19:01:44Z", + "published": "2024-08-07T15:30:42Z", + "aliases": [ + "CVE-2024-41989" + ], + "summary": "Django memory consumption vulnerability", + "details": "An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The floatformat template filter is subject to significant memory consumption when given a string representation of a number in scientific notation with a large exponent.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "PyPI", + "name": "Django" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "5.0" + }, + { + "fixed": "5.0.8" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "PyPI", + "name": "Django" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "4.2" + }, + { + "fixed": "4.2.15" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41989" + }, + { + "type": "WEB", + "url": "https://github.com/django/django/commit/27900fe56f3d3cabb4aeb6ccb82f92bab29073a8" + }, + { + "type": "WEB", + "url": "https://github.com/django/django/commit/fc76660f589ac07e45e9cd34ccb8087aeb11904b" + }, + { + "type": "WEB", + "url": "https://docs.djangoproject.com/en/dev/releases/security" + }, + { + "type": "PACKAGE", + "url": "https://github.com/django/django" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/django/PYSEC-2024-67.yaml" + }, + { + "type": "WEB", + "url": "https://www.djangoproject.com/weblog/2024/aug/06/security-releases" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-08-07T19:01:44Z", + "nvd_published_at": "2024-08-07T15:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/08/GHSA-pv4p-cwwg-4rph/GHSA-pv4p-cwwg-4rph.json b/advisories/github-reviewed/2024/08/GHSA-pv4p-cwwg-4rph/GHSA-pv4p-cwwg-4rph.json new file mode 100644 index 00000000000..4c9a25fe13b --- /dev/null +++ b/advisories/github-reviewed/2024/08/GHSA-pv4p-cwwg-4rph/GHSA-pv4p-cwwg-4rph.json @@ -0,0 +1,100 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pv4p-cwwg-4rph", + "modified": "2024-08-07T19:02:40Z", + "published": "2024-08-07T15:30:42Z", + "aliases": [ + "CVE-2024-42005" + ], + "summary": "Django SQL injection vulnerability", + "details": "An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. QuerySet.values() and values_list() methods on models with a JSONField are subject to SQL injection in column aliases via a crafted JSON object key as a passed *arg.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "PyPI", + "name": "Django" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "5.0" + }, + { + "fixed": "5.0.8" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "PyPI", + "name": "Django" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "4.2" + }, + { + "fixed": "4.2.15" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42005" + }, + { + "type": "WEB", + "url": "https://github.com/django/django/commit/32ebcbf2e1fe3e5ba79a6554a167efce81f7422d" + }, + { + "type": "WEB", + "url": "https://github.com/django/django/commit/f4af67b9b41e0f4c117a8741da3abbd1c869ab28" + }, + { + "type": "WEB", + "url": "https://docs.djangoproject.com/en/dev/releases/security" + }, + { + "type": "PACKAGE", + "url": "https://github.com/django/django" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/django/PYSEC-2024-70.yaml" + }, + { + "type": "WEB", + "url": "https://www.djangoproject.com/weblog/2024/aug/06/security-releases" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": true, + "github_reviewed_at": "2024-08-07T19:02:40Z", + "nvd_published_at": "2024-08-07T15:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/08/GHSA-r836-hh6v-rg5g/GHSA-r836-hh6v-rg5g.json b/advisories/github-reviewed/2024/08/GHSA-r836-hh6v-rg5g/GHSA-r836-hh6v-rg5g.json new file mode 100644 index 00000000000..f4aa5bf8fe4 --- /dev/null +++ b/advisories/github-reviewed/2024/08/GHSA-r836-hh6v-rg5g/GHSA-r836-hh6v-rg5g.json @@ -0,0 +1,104 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r836-hh6v-rg5g", + "modified": "2024-08-07T19:03:05Z", + "published": "2024-08-07T15:30:42Z", + "aliases": [ + "CVE-2024-41991" + ], + "summary": "Django vulnerable to denial-of-service attack", + "details": "An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The urlize and urlizetrunc template filters, and the AdminURLFieldWidget widget, are subject to a potential denial-of-service attack via certain inputs with a very large number of Unicode characters.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "PyPI", + "name": "Django" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "5.0" + }, + { + "fixed": "5.0.8" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "PyPI", + "name": "Django" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "4.2" + }, + { + "fixed": "4.2.15" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41991" + }, + { + "type": "WEB", + "url": "https://github.com/django/django/commit/523da8771bce321023f490f70d71a9e973ddc927" + }, + { + "type": "WEB", + "url": "https://github.com/django/django/commit/efea1ef7e2190e3f77ca0651b5458297bc0f6a9f" + }, + { + "type": "WEB", + "url": "https://docs.djangoproject.com/en/dev/releases/security" + }, + { + "type": "PACKAGE", + "url": "https://github.com/django/django" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/django/PYSEC-2024-69.yaml" + }, + { + "type": "WEB", + "url": "https://groups.google.com/forum/#%21forum/django-announce" + }, + { + "type": "WEB", + "url": "https://www.djangoproject.com/weblog/2024/aug/06/security-releases" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1333" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-08-07T19:03:05Z", + "nvd_published_at": "2024-08-07T15:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-795c-9xpc-xw6g/GHSA-795c-9xpc-xw6g.json b/advisories/unreviewed/2024/08/GHSA-795c-9xpc-xw6g/GHSA-795c-9xpc-xw6g.json deleted file mode 100644 index 216499540f1..00000000000 --- a/advisories/unreviewed/2024/08/GHSA-795c-9xpc-xw6g/GHSA-795c-9xpc-xw6g.json +++ /dev/null @@ -1,43 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-795c-9xpc-xw6g", - "modified": "2024-08-07T15:30:42Z", - "published": "2024-08-07T15:30:42Z", - "aliases": [ - "CVE-2024-41990" - ], - "details": "An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The urlize() and urlizetrunc() template filters are subject to a potential denial-of-service attack via very large inputs with a specific sequence of characters.", - "severity": [ - - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41990" - }, - { - "type": "WEB", - "url": "https://docs.djangoproject.com/en/dev/releases/security" - }, - { - "type": "WEB", - "url": "https://groups.google.com/forum/#%21forum/django-announce" - }, - { - "type": "WEB", - "url": "https://www.djangoproject.com/weblog/2024/aug/06/security-releases" - } - ], - "database_specific": { - "cwe_ids": [ - - ], - "severity": null, - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2024-08-07T15:15:56Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-jh75-99hh-qvx9/GHSA-jh75-99hh-qvx9.json b/advisories/unreviewed/2024/08/GHSA-jh75-99hh-qvx9/GHSA-jh75-99hh-qvx9.json deleted file mode 100644 index 080fd1b0eb0..00000000000 --- a/advisories/unreviewed/2024/08/GHSA-jh75-99hh-qvx9/GHSA-jh75-99hh-qvx9.json +++ /dev/null @@ -1,43 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-jh75-99hh-qvx9", - "modified": "2024-08-07T15:30:42Z", - "published": "2024-08-07T15:30:42Z", - "aliases": [ - "CVE-2024-41989" - ], - "details": "An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The floatformat template filter is subject to significant memory consumption when given a string representation of a number in scientific notation with a large exponent.", - "severity": [ - - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41989" - }, - { - "type": "WEB", - "url": "https://docs.djangoproject.com/en/dev/releases/security" - }, - { - "type": "WEB", - "url": "https://groups.google.com/forum/#%21forum/django-announce" - }, - { - "type": "WEB", - "url": "https://www.djangoproject.com/weblog/2024/aug/06/security-releases" - } - ], - "database_specific": { - "cwe_ids": [ - - ], - "severity": null, - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2024-08-07T15:15:56Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-pv4p-cwwg-4rph/GHSA-pv4p-cwwg-4rph.json b/advisories/unreviewed/2024/08/GHSA-pv4p-cwwg-4rph/GHSA-pv4p-cwwg-4rph.json deleted file mode 100644 index 03695760be2..00000000000 --- a/advisories/unreviewed/2024/08/GHSA-pv4p-cwwg-4rph/GHSA-pv4p-cwwg-4rph.json +++ /dev/null @@ -1,43 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-pv4p-cwwg-4rph", - "modified": "2024-08-07T15:30:42Z", - "published": "2024-08-07T15:30:42Z", - "aliases": [ - "CVE-2024-42005" - ], - "details": "An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. QuerySet.values() and values_list() methods on models with a JSONField are subject to SQL injection in column aliases via a crafted JSON object key as a passed *arg.", - "severity": [ - - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42005" - }, - { - "type": "WEB", - "url": "https://docs.djangoproject.com/en/dev/releases/security" - }, - { - "type": "WEB", - "url": "https://groups.google.com/forum/#%21forum/django-announce" - }, - { - "type": "WEB", - "url": "https://www.djangoproject.com/weblog/2024/aug/06/security-releases" - } - ], - "database_specific": { - "cwe_ids": [ - - ], - "severity": null, - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2024-08-07T15:15:56Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2024/08/GHSA-r836-hh6v-rg5g/GHSA-r836-hh6v-rg5g.json b/advisories/unreviewed/2024/08/GHSA-r836-hh6v-rg5g/GHSA-r836-hh6v-rg5g.json deleted file mode 100644 index 092bd5faa97..00000000000 --- a/advisories/unreviewed/2024/08/GHSA-r836-hh6v-rg5g/GHSA-r836-hh6v-rg5g.json +++ /dev/null @@ -1,43 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-r836-hh6v-rg5g", - "modified": "2024-08-07T15:30:42Z", - "published": "2024-08-07T15:30:42Z", - "aliases": [ - "CVE-2024-41991" - ], - "details": "An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The urlize and urlizetrunc template filters, and the AdminURLFieldWidget widget, are subject to a potential denial-of-service attack via certain inputs with a very large number of Unicode characters.", - "severity": [ - - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41991" - }, - { - "type": "WEB", - "url": "https://docs.djangoproject.com/en/dev/releases/security" - }, - { - "type": "WEB", - "url": "https://groups.google.com/forum/#%21forum/django-announce" - }, - { - "type": "WEB", - "url": "https://www.djangoproject.com/weblog/2024/aug/06/security-releases" - } - ], - "database_specific": { - "cwe_ids": [ - - ], - "severity": null, - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2024-08-07T15:15:56Z" - } -} \ No newline at end of file