From ab6fcd7d25fafbd8c2743f0dc46fb9907aa93fc9 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 11 Jan 2024 15:43:32 +0000 Subject: [PATCH] Publish Advisories GHSA-45x7-px36-x8w8 GHSA-2mqj-m65w-jghx GHSA-97x9-59rv-q5pm GHSA-c38c-c8mh-vq68 GHSA-cx99-25hr-5jxf GHSA-g273-wppx-82w4 --- .../GHSA-45x7-px36-x8w8/GHSA-45x7-px36-x8w8.json | 8 ++++++++ .../GHSA-2mqj-m65w-jghx/GHSA-2mqj-m65w-jghx.json | 8 ++++++-- .../GHSA-97x9-59rv-q5pm/GHSA-97x9-59rv-q5pm.json | 15 +++++++++++---- .../GHSA-c38c-c8mh-vq68/GHSA-c38c-c8mh-vq68.json | 10 +++++++--- .../GHSA-cx99-25hr-5jxf/GHSA-cx99-25hr-5jxf.json | 10 +++++++--- .../GHSA-g273-wppx-82w4/GHSA-g273-wppx-82w4.json | 10 +++++++--- 6 files changed, 46 insertions(+), 15 deletions(-) diff --git a/advisories/github-reviewed/2023/12/GHSA-45x7-px36-x8w8/GHSA-45x7-px36-x8w8.json b/advisories/github-reviewed/2023/12/GHSA-45x7-px36-x8w8/GHSA-45x7-px36-x8w8.json index a0bdd4c234a..c1cab55346c 100644 --- a/advisories/github-reviewed/2023/12/GHSA-45x7-px36-x8w8/GHSA-45x7-px36-x8w8.json +++ b/advisories/github-reviewed/2023/12/GHSA-45x7-px36-x8w8/GHSA-45x7-px36-x8w8.json @@ -298,6 +298,10 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2023/12/msg00017.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/33XHJUB6ROFUOH2OQNENFROTVH6MHSHA/" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3CAYYW35MUTNO65RVAELICTNZZFMT2XS/" @@ -310,6 +314,10 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/APYIXIQOVDCRWLHTGB4VYMAUIAQLKYJ3/" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BL5KTLOSLH2KHRN4HCXJPK3JUVLDGEL6/" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/C3AFMZ6MH2UHHOPIWT5YLSFV3D2VB3AC/" diff --git a/advisories/github-reviewed/2024/01/GHSA-2mqj-m65w-jghx/GHSA-2mqj-m65w-jghx.json b/advisories/github-reviewed/2024/01/GHSA-2mqj-m65w-jghx/GHSA-2mqj-m65w-jghx.json index 9881597a2f0..ebd68b2d09c 100644 --- a/advisories/github-reviewed/2024/01/GHSA-2mqj-m65w-jghx/GHSA-2mqj-m65w-jghx.json +++ b/advisories/github-reviewed/2024/01/GHSA-2mqj-m65w-jghx/GHSA-2mqj-m65w-jghx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2mqj-m65w-jghx", - "modified": "2024-01-10T16:00:18Z", + "modified": "2024-01-11T15:41:57Z", "published": "2024-01-10T15:46:00Z", "aliases": [ "CVE-2024-22190" @@ -40,6 +40,10 @@ "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-2mqj-m65w-jghx" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22190" + }, { "type": "WEB", "url": "https://github.com/gitpython-developers/GitPython/pull/1792" @@ -60,6 +64,6 @@ "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2024-01-10T15:46:00Z", - "nvd_published_at": null + "nvd_published_at": "2024-01-11T02:15:48Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2024/01/GHSA-97x9-59rv-q5pm/GHSA-97x9-59rv-q5pm.json b/advisories/github-reviewed/2024/01/GHSA-97x9-59rv-q5pm/GHSA-97x9-59rv-q5pm.json index 1d7afdc84de..88601123b3b 100644 --- a/advisories/github-reviewed/2024/01/GHSA-97x9-59rv-q5pm/GHSA-97x9-59rv-q5pm.json +++ b/advisories/github-reviewed/2024/01/GHSA-97x9-59rv-q5pm/GHSA-97x9-59rv-q5pm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-97x9-59rv-q5pm", - "modified": "2024-01-09T21:48:55Z", + "modified": "2024-01-11T15:42:21Z", "published": "2024-01-09T20:31:55Z", "aliases": [ "CVE-2024-21669" @@ -9,7 +9,10 @@ "summary": "Hyperledger Aries Cloud Agent Python result of presentation verification not checked for LDP-VC", "details": "### Impact\n\nWhen verifying W3C Format Verifiable Credentials using JSON-LD with Linked Data Proofs (LDP-VCs), the result of verifying the presentation `document.proof` was not factored into the final `verified` value (`true`/`false`) on the presentation record. Below is an example result from verifying a JSON-LD Presentation where there is an error noted in the processing (mismatched challenge), but the overall result is incorrectly `\"verified\": true`:\n\n```json\n{\n \"verified\": true,\n \"presentation_result\": {\n \"verified\": false,\n \"document\": {\n \"@context\": [\n \"https://www.w3.org/2018/credentials/v1\"\n ],\n \"type\": [\n \"VerifiablePresentation\"\n ],\n \"verifiableCredential\": [\n {\n \"@context\": [\n \"https://www.w3.org/2018/credentials/v1\",\n \"https://w3id.org/citizenship/v1\"\n ],\n \"type\": [\n \"VerifiableCredential\",\n \"PermanentResident\"\n ],\n \"issuer\": \"did:sov:EzcfrVw7Tveho5NjrmDWnd\",\n \"issuanceDate\": \"2023-11-18\",\n \"credentialSubject\": {\n \"type\": [\n \"PermanentResident\"\n ],\n \"id\": \"did:key:z6MkrpbudRMUpTWSdqFcG2ytbYu2QQfgGFUf8GJpShR8Gy7C\",\n \"givenName\": \"Bob\",\n \"familyName\": \"Builder\",\n \"gender\": \"Male\",\n \"birthCountry\": \"Bahamas\",\n \"birthDate\": \"1958-07-17\"\n },\n \"proof\": {\n \"type\": \"Ed25519Signature2018\",\n \"proofPurpose\": \"assertionMethod\",\n \"verificationMethod\": \"did:sov:EzcfrVw7Tveho5NjrmDWnd#key-1\",\n \"created\": \"2023-11-18T21:39:56.988853+00:00\",\n \"jws\": \"eyJhbGciOiAiRWREU0EiLCAiYjY0IjogZmFsc2UsICJjcml0IjogWyJiNjQiXX0..eKdLMhKJkiVNzTKOEv14KyAFJnk8QX5MqXPmRE5OjQvwRNkeXk1lQRovhDhXKw154OrSqLHgfSNwBd3xfwuDCA\"\n }\n }\n ],\n \"proof\": {\n \"type\": \"Ed25519Signature2018\",\n \"proofPurpose\": \"authentication\",\n \"verificationMethod\": \"did:key:z6MkrpbudRMUpTWSdqFcG2ytbYu2QQfgGFUf8GJpShR8Gy7C#z6MkrpbudRMUpTWSdqFcG2ytbYu2QQfgGFUf8GJpShR8Gy7C\",\n \"created\": \"2023-11-18T21:39:59.188276+00:00\",\n \"challenge\": \"ce0956d4-206d-4b69-a087-52bbb9ddaf1d\",\n \"jws\": \"eyJhbGciOiAiRWREU0EiLCAiYjY0IjogZmFsc2UsICJjcml0IjogWyJiNjQiXX0..4ciLzT3oF-Ch9nngGVgI_fBNIo_RPPXzRuFXjMx4AdwVNM4ioeB3TNDbHsF7fPXANznkZR0bHceyvMN3-CUSAw\"\n }\n },\n \"results\": [\n {\n \"verified\": false,\n \"proof\": {\n \"@context\": [\n \"https://www.w3.org/2018/credentials/v1\"\n ],\n \"type\": \"Ed25519Signature2018\",\n \"proofPurpose\": \"authentication\",\n \"verificationMethod\": \"did:key:z6MkrpbudRMUpTWSdqFcG2ytbYu2QQfgGFUf8GJpShR8Gy7C#z6MkrpbudRMUpTWSdqFcG2ytbYu2QQfgGFUf8GJpShR8Gy7C\",\n \"created\": \"2023-11-18T21:39:59.188276+00:00\",\n \"challenge\": \"ce0956d4-206d-4b69-a087-52bbb9ddaf1d\",\n \"jws\": \"eyJhbGciOiAiRWREU0EiLCAiYjY0IjogZmFsc2UsICJjcml0IjogWyJiNjQiXX0..4ciLzT3oF-Ch9nngGVgI_fBNIo_RPPXzRuFXjMx4AdwVNM4ioeB3TNDbHsF7fPXANznkZR0bHceyvMN3-CUSAw\"\n },\n \"error\": \"The challenge is not as expected; challenge=ce0956d4-206d-4b69-a087-52bbb9ddaf1d, expected=328daf6e-f1f5-475a-944e-6446e7b3a969\",\n \"purpose_result\": {\n \"valid\": false,\n \"error\": \"The challenge is not as expected; challenge=ce0956d4-206d-4b69-a087-52bbb9ddaf1d, expected=328daf6e-f1f5-475a-944e-6446e7b3a969\"\n }\n }\n ],\n \"errors\": [\n \"The challenge is not as expected; challenge=ce0956d4-206d-4b69-a087-52bbb9ddaf1d, expected=328daf6e-f1f5-475a-944e-6446e7b3a969\"\n ]\n },\n \"credential_results\": [\n {\n \"verified\": true,\n \"document\": {\n \"@context\": [\n \"https://www.w3.org/2018/credentials/v1\",\n \"https://w3id.org/citizenship/v1\"\n ],\n \"type\": [\n \"VerifiableCredential\",\n \"PermanentResident\"\n ],\n \"issuer\": \"did:sov:EzcfrVw7Tveho5NjrmDWnd\",\n \"issuanceDate\": \"2023-11-18\",\n \"credentialSubject\": {\n \"type\": [\n \"PermanentResident\"\n ],\n \"id\": \"did:key:z6MkrpbudRMUpTWSdqFcG2ytbYu2QQfgGFUf8GJpShR8Gy7C\",\n \"givenName\": \"Bob\",\n \"familyName\": \"Builder\",\n \"gender\": \"Male\",\n \"birthCountry\": \"Bahamas\",\n \"birthDate\": \"1958-07-17\"\n },\n \"proof\": {\n \"type\": \"Ed25519Signature2018\",\n \"proofPurpose\": \"assertionMethod\",\n \"verificationMethod\": \"did:sov:EzcfrVw7Tveho5NjrmDWnd#key-1\",\n \"created\": \"2023-11-18T21:39:56.988853+00:00\",\n \"jws\": \"eyJhbGciOiAiRWREU0EiLCAiYjY0IjogZmFsc2UsICJjcml0IjogWyJiNjQiXX0..eKdLMhKJkiVNzTKOEv14KyAFJnk8QX5MqXPmRE5OjQvwRNkeXk1lQRovhDhXKw154OrSqLHgfSNwBd3xfwuDCA\"\n }\n },\n \"results\": [\n {\n \"verified\": true,\n \"proof\": {\n \"@context\": [\n \"https://www.w3.org/2018/credentials/v1\",\n \"https://w3id.org/citizenship/v1\"\n ],\n \"type\": \"Ed25519Signature2018\",\n \"proofPurpose\": \"assertionMethod\",\n \"verificationMethod\": \"did:sov:EzcfrVw7Tveho5NjrmDWnd#key-1\",\n \"created\": \"2023-11-18T21:39:56.988853+00:00\",\n \"jws\": \"eyJhbGciOiAiRWREU0EiLCAiYjY0IjogZmFsc2UsICJjcml0IjogWyJiNjQiXX0..eKdLMhKJkiVNzTKOEv14KyAFJnk8QX5MqXPmRE5OjQvwRNkeXk1lQRovhDhXKw154OrSqLHgfSNwBd3xfwuDCA\"\n },\n \"purpose_result\": {\n \"valid\": true,\n \"controller\": {\n \"@context\": \"https://w3id.org/security/v2\",\n \"id\": \"did:sov:EzcfrVw7Tveho5NjrmDWnd\",\n \"assertionMethod\": [\n \"did:sov:EzcfrVw7Tveho5NjrmDWnd#key-1\"\n ],\n \"authentication\": [\n {\n \"id\": \"did:sov:EzcfrVw7Tveho5NjrmDWnd#key-1\",\n \"type\": \"Ed25519VerificationKey2018\",\n \"controller\": \"did:sov:EzcfrVw7Tveho5NjrmDWnd\",\n \"publicKeyBase58\": \"8dMkWKZxsK7vS8sR4XgS7gWvRawPp5TMYVFvnU2RyXqo\"\n }\n ],\n \"verificationMethod\": \"did:sov:EzcfrVw7Tveho5NjrmDWnd#key-1\",\n \"https://www.w3.org/ns/did#service\": {\n \"id\": \"did:sov:EzcfrVw7Tveho5NjrmDWnd#did-communication\",\n \"type\": \"did-communication\",\n \"https://www.w3.org/ns/did#serviceEndpoint\": {\n \"id\": \"http://alice:3000\"\n }\n }\n }\n }\n }\n ]\n }\n ],\n \"errors\": [\n \"The challenge is not as expected; challenge=ce0956d4-206d-4b69-a087-52bbb9ddaf1d, expected=328daf6e-f1f5-475a-944e-6446e7b3a969\"\n ]\n}\n```\n\nThe flaw enables holders of W3C Format Verifiable Credentials using JSON-LD with Linked Data Proofs (LDPs) to present incorrectly constructed proofs, and allows malicious verifiers to save and replay a presentation from such holders as their own.\n\nThis vulnerability has been present since the first implementation of support for JSON-LD W3C Verifiable Credential Data Model presentations, in Aries Cloud Agent Python release in 0.7.0.\n\nAll ACA-Py Users depending on W3C Format Verifiable Credentials using JSON-LD with Linked Data Proofs are impacted by this vulnerability.\n\n### Patches\n\nThis issue has been patched in version [0.10.5](https://github.com/hyperledger/aries-cloudagent-python/releases/tag/0.10.5) and fixed in [0.11.0](https://github.com/hyperledger/aries-cloudagent-python/releases/tag/0.11.0).\n\n### Workarounds\n\nThere is no workaround other upgrading to a patched/fixed version of ACA-Py.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L" + } ], "affected": [ { @@ -56,6 +59,10 @@ "type": "WEB", "url": "https://github.com/hyperledger/aries-cloudagent-python/security/advisories/GHSA-97x9-59rv-q5pm" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21669" + }, { "type": "WEB", "url": "https://github.com/hyperledger/aries-cloudagent-python/commit/0b01ffffc0789205ac990292f97238614c9fd293" @@ -79,11 +86,11 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-347" ], "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2024-01-09T20:31:55Z", - "nvd_published_at": null + "nvd_published_at": "2024-01-11T06:15:44Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2024/01/GHSA-c38c-c8mh-vq68/GHSA-c38c-c8mh-vq68.json b/advisories/github-reviewed/2024/01/GHSA-c38c-c8mh-vq68/GHSA-c38c-c8mh-vq68.json index 7fec687e1a1..86122c5cacd 100644 --- a/advisories/github-reviewed/2024/01/GHSA-c38c-c8mh-vq68/GHSA-c38c-c8mh-vq68.json +++ b/advisories/github-reviewed/2024/01/GHSA-c38c-c8mh-vq68/GHSA-c38c-c8mh-vq68.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c38c-c8mh-vq68", - "modified": "2024-01-10T15:22:48Z", + "modified": "2024-01-11T15:41:46Z", "published": "2024-01-10T15:22:48Z", "aliases": [ "CVE-2024-21666" @@ -40,6 +40,10 @@ "type": "WEB", "url": "https://github.com/pimcore/customer-data-framework/security/advisories/GHSA-c38c-c8mh-vq68" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21666" + }, { "type": "WEB", "url": "https://github.com/pimcore/customer-data-framework/commit/c33c0048390ef0cf98b801d46a81d0762243baa6" @@ -55,11 +59,11 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2024-01-10T15:22:48Z", - "nvd_published_at": null + "nvd_published_at": "2024-01-11T01:15:45Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2024/01/GHSA-cx99-25hr-5jxf/GHSA-cx99-25hr-5jxf.json b/advisories/github-reviewed/2024/01/GHSA-cx99-25hr-5jxf/GHSA-cx99-25hr-5jxf.json index 45006f17599..3bbcbcdae3d 100644 --- a/advisories/github-reviewed/2024/01/GHSA-cx99-25hr-5jxf/GHSA-cx99-25hr-5jxf.json +++ b/advisories/github-reviewed/2024/01/GHSA-cx99-25hr-5jxf/GHSA-cx99-25hr-5jxf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cx99-25hr-5jxf", - "modified": "2024-01-10T15:14:38Z", + "modified": "2024-01-11T15:41:40Z", "published": "2024-01-10T15:14:38Z", "aliases": [ "CVE-2024-21665" @@ -40,6 +40,10 @@ "type": "WEB", "url": "https://github.com/pimcore/ecommerce-framework-bundle/security/advisories/GHSA-cx99-25hr-5jxf" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21665" + }, { "type": "WEB", "url": "https://github.com/pimcore/ecommerce-framework-bundle/commit/05dec000ed009828084d05cf686f468afd1f464e" @@ -59,11 +63,11 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2024-01-10T15:14:38Z", - "nvd_published_at": null + "nvd_published_at": "2024-01-11T01:15:45Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2024/01/GHSA-g273-wppx-82w4/GHSA-g273-wppx-82w4.json b/advisories/github-reviewed/2024/01/GHSA-g273-wppx-82w4/GHSA-g273-wppx-82w4.json index 77eb4cb878a..1f0fb3e8c1e 100644 --- a/advisories/github-reviewed/2024/01/GHSA-g273-wppx-82w4/GHSA-g273-wppx-82w4.json +++ b/advisories/github-reviewed/2024/01/GHSA-g273-wppx-82w4/GHSA-g273-wppx-82w4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g273-wppx-82w4", - "modified": "2024-01-10T15:24:08Z", + "modified": "2024-01-11T15:41:51Z", "published": "2024-01-10T15:24:08Z", "aliases": [ "CVE-2024-21667" @@ -40,6 +40,10 @@ "type": "WEB", "url": "https://github.com/pimcore/customer-data-framework/security/advisories/GHSA-g273-wppx-82w4" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21667" + }, { "type": "WEB", "url": "https://github.com/pimcore/customer-data-framework/commit/6c34515be2ba39dceee7da07a1abf246309ccd77" @@ -55,11 +59,11 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-284" ], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2024-01-10T15:24:08Z", - "nvd_published_at": null + "nvd_published_at": "2024-01-11T01:15:45Z" } } \ No newline at end of file