diff --git a/advisories/github-reviewed/2023/12/GHSA-hwcc-4cv8-cf3h/GHSA-hwcc-4cv8-cf3h.json b/advisories/github-reviewed/2023/12/GHSA-hwcc-4cv8-cf3h/GHSA-hwcc-4cv8-cf3h.json new file mode 100644 index 00000000000..d77f9e0a9b4 --- /dev/null +++ b/advisories/github-reviewed/2023/12/GHSA-hwcc-4cv8-cf3h/GHSA-hwcc-4cv8-cf3h.json @@ -0,0 +1,72 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hwcc-4cv8-cf3h", + "modified": "2023-12-22T19:51:09Z", + "published": "2023-12-22T19:51:09Z", + "aliases": [ + "CVE-2023-51662" + ], + "summary": "Snowflake Connector .NET does not properly check the Certificate Revocation List (CRL)", + "details": "### Issue\nSnowflake recently received a report about a vulnerability in the Snowflake Connector .NET where the checks against the Certificate Revocation List (CRL) were not performed where the insecureMode flag was set to false, which is the default setting. The vulnerability affects versions between 2.0.25 and 2.1.4 (inclusive). Snowflake fixed the issue in [version 2.1.5](https://docs.snowflake.com/release-notes/clients-drivers/dotnet-2023#version-2-1-5-december-18-2023).\n\n### Attack Scenario\nSnowflake uses CRL to check if a TLS certificate has been revoked before its expiration date. The lack of correct validation of revoked certificates could, in theory, allow an attacker who has both access to the private key of a correctly issued Snowflake certificate and the ability to intercept network traffic to perform a Man-in-the-Middle (MitM) attack in order to compromise Snowflake credentials used by the driver.\n\nThe vulnerability is difficult to exploit given both conditions required and, at the time of this advisory's publication, Snowflake is not aware of any compromise of its certificates, nor unauthorized issuance of such by any publicly trusted Certificate Authority (CA). However, an upgrade to the newest version is recommended to ensure the highest level of security and protection against future unforeseen threats.\n\n### Solution\nOn December 18, 2023, Snowflake released [version 2.1.5](https://docs.snowflake.com/release-notes/clients-drivers/dotnet-2023#version-2-1-5-december-18-2023) of the Snowflake Connector .NET, which fixes the issue, and we recommend users upgrade to [version 2.1.5](https://docs.snowflake.com/release-notes/clients-drivers/dotnet-2023#version-2-1-5-december-18-2023). Customers continuing to use the impacted versions of the connector should update their insecureMode flag to true. \n\n### Acknowledgement\nSnowflake would like to thank [Timo Vink](https://github.com/TimoVink) for reporting this vulnerability.\n\n### Additional Information\nIf you discover a security vulnerability in one of our products or websites, please report the issue to HackerOne. For more information, please see our [Vulnerability Disclosure Policy](https://hackerone.com/snowflake?type=team).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:L" + } + ], + "affected": [ + { + "package": { + "ecosystem": "NuGet", + "name": "Snowflake.Data" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.0.25" + }, + { + "fixed": "2.1.5" + } + ] + } + ], + "database_specific": { + "last_known_affected_version_range": "<= 2.1.4" + } + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/snowflakedb/snowflake-connector-net/security/advisories/GHSA-hwcc-4cv8-cf3h" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51662" + }, + { + "type": "WEB", + "url": "https://github.com/snowflakedb/snowflake-connector-net/commit/49cb77ddd6e18c110eca35aa580e89d73c46cc33" + }, + { + "type": "WEB", + "url": "https://docs.snowflake.com/release-notes/clients-drivers/dotnet-2023#version-2-1-5-december-18-2023" + }, + { + "type": "PACKAGE", + "url": "https://github.com/snowflakedb/snowflake-connector-net" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-295" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2023-12-22T19:51:09Z", + "nvd_published_at": "2023-12-22T17:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2023/12/GHSA-jcrr-rr6w-8c83/GHSA-jcrr-rr6w-8c83.json b/advisories/github-reviewed/2023/12/GHSA-jcrr-rr6w-8c83/GHSA-jcrr-rr6w-8c83.json new file mode 100644 index 00000000000..2ebc754e94d --- /dev/null +++ b/advisories/github-reviewed/2023/12/GHSA-jcrr-rr6w-8c83/GHSA-jcrr-rr6w-8c83.json @@ -0,0 +1,65 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jcrr-rr6w-8c83", + "modified": "2023-12-22T19:51:38Z", + "published": "2023-12-22T12:31:52Z", + "aliases": [ + "CVE-2023-49391" + ], + "summary": "free5GC AMF denial of service vulnerability", + "details": "An issue was discovered in free5GC version 3.3.0, allows remote attackers to execute arbitrary code and cause a denial of service (DoS) on AMF component via crafted NGAP message.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Go", + "name": "github.com/free5gc/amf" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "1.2.0" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49391" + }, + { + "type": "WEB", + "url": "https://github.com/free5gc/free5gc/issues/497" + }, + { + "type": "WEB", + "url": "https://github.com/free5gc/amf/commit/6fc612c35997cf4e8be1e5c86ae2242f04b576a9" + }, + { + "type": "PACKAGE", + "url": "https://github.com/free5gc/amf" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "HIGH", + "github_reviewed": true, + "github_reviewed_at": "2023-12-22T19:51:38Z", + "nvd_published_at": "2023-12-22T11:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2023/12/GHSA-vf5m-xrhm-v999/GHSA-vf5m-xrhm-v999.json b/advisories/github-reviewed/2023/12/GHSA-vf5m-xrhm-v999/GHSA-vf5m-xrhm-v999.json new file mode 100644 index 00000000000..d824e030f5b --- /dev/null +++ b/advisories/github-reviewed/2023/12/GHSA-vf5m-xrhm-v999/GHSA-vf5m-xrhm-v999.json @@ -0,0 +1,100 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vf5m-xrhm-v999", + "modified": "2023-12-22T19:51:53Z", + "published": "2023-12-22T19:51:53Z", + "aliases": [ + "CVE-2023-51649" + ], + "summary": "Nautobot missing object-level permissions enforcement when running Job Buttons", + "details": "### Impact\n\nWhen submitting a Job to run via a Job Button, only the model-level `extras.run_job` permission is checked (i.e., does the user have permission to run Jobs in general?). Object-level permissions (i.e., does the user have permission to run this *specific* Job?) are not enforced by the URL/view used in this case (`/extras/job-button//run/`) The effect is that a user with permissions to run even a single Job can actually run all configured JobButton Jobs.\n\n> Not all Jobs can be configured as JobButtons; only those implemented as subclasses of `JobButtonReceiver` can be used in this way, so this vulnerability only applies specifically to `JobButtonReceiver` subclasses.\n\nAdditionally, although the documentation states that both `extras.run_job` permission and `extras.run_jobbutton` permission must be granted to a user in order to run Jobs via JobButton, the `extras.run_jobbutton` permission is not actually enforced by the view code, only by the UI by disabling the button from being clicked normally. Furthermore, the `extras.run_jobbutton` permission never prevented invoking Jobs (including `JobButtonReceiver` subclasses) via the normal \"Job Run\" UI, so after some discussion, we've decided that the `extras.run_jobbutton` permission is redundant, and as it never achieved its stated/documented purpose, the fixes below will remove the UI check for `extras.run_jobbutton` and all other references to the `extras.run_jobbutton` permission, rather than adding enforcement of this previously unenforced permission.\n\n### Patches\n_Has the problem been patched? What versions should users upgrade to?_\n\nFix will be available in Nautobot 1.6.8 (https://github.com/nautobot/nautobot/pull/4995) and 2.1.0 (https://github.com/nautobot/nautobot/pull/4993)\n\n### Workarounds\n_Is there a way for users to fix or remediate the vulnerability without upgrading?_\n\nPartial mitigation can be achieved by auditing `JobButtonReceiver` subclasses defined in the system and restricting which users are permitted to create or edit JobButton records. \n\n### References\n\n- https://github.com/nautobot/nautobot/issues/4988\n- https://github.com/nautobot/nautobot/pull/4993\n- https://github.com/nautobot/nautobot/pull/4995\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:L" + } + ], + "affected": [ + { + "package": { + "ecosystem": "PyPI", + "name": "nautobot" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "1.5.14" + }, + { + "fixed": "1.6.8" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "PyPI", + "name": "nautobot" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.0.0" + }, + { + "fixed": "2.1.0" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/nautobot/nautobot/security/advisories/GHSA-vf5m-xrhm-v999" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51649" + }, + { + "type": "WEB", + "url": "https://github.com/nautobot/nautobot/issues/4988" + }, + { + "type": "WEB", + "url": "https://github.com/nautobot/nautobot/pull/4993" + }, + { + "type": "WEB", + "url": "https://github.com/nautobot/nautobot/pull/4995" + }, + { + "type": "WEB", + "url": "https://github.com/nautobot/nautobot/commit/3d964f996f4926126c1d7853ca87b2ff475997a2" + }, + { + "type": "WEB", + "url": "https://github.com/nautobot/nautobot/commit/d33d0c15a36948c45244e5b5e10bc79b8e62de7f" + }, + { + "type": "PACKAGE", + "url": "https://github.com/nautobot/nautobot" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "LOW", + "github_reviewed": true, + "github_reviewed_at": "2023-12-22T19:51:53Z", + "nvd_published_at": "2023-12-22T17:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/12/GHSA-jcrr-rr6w-8c83/GHSA-jcrr-rr6w-8c83.json b/advisories/unreviewed/2023/12/GHSA-jcrr-rr6w-8c83/GHSA-jcrr-rr6w-8c83.json deleted file mode 100644 index 472a9ee7ab1..00000000000 --- a/advisories/unreviewed/2023/12/GHSA-jcrr-rr6w-8c83/GHSA-jcrr-rr6w-8c83.json +++ /dev/null @@ -1,35 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-jcrr-rr6w-8c83", - "modified": "2023-12-22T12:31:52Z", - "published": "2023-12-22T12:31:52Z", - "aliases": [ - "CVE-2023-49391" - ], - "details": "An issue was discovered in free5GC version 3.3.0, allows remote attackers to execute arbitrary code and cause a denial of service (DoS) on AMF component via crafted NGAP message.", - "severity": [ - - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49391" - }, - { - "type": "WEB", - "url": "https://github.com/free5gc/free5gc/issues/497" - } - ], - "database_specific": { - "cwe_ids": [ - - ], - "severity": null, - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2023-12-22T11:15:07Z" - } -} \ No newline at end of file