mirror of
https://github.com/netbirdio/advisory-database.git
synced 2026-05-22 18:04:22 -07:00
Publish Advisories
GHSA-8vvp-525h-cxf9 GHSA-9w38-p64v-xpmv GHSA-cff3-5qrp-hqx7 GHSA-f3jh-qvm4-mg39 GHSA-hgjh-9rj2-g67j GHSA-xjp4-hw94-mvp5
This commit is contained in:
@@ -1,13 +1,13 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-8vvp-525h-cxf9",
|
||||
"modified": "2024-12-06T22:00:54Z",
|
||||
"modified": "2025-02-13T19:05:24Z",
|
||||
"published": "2024-03-19T12:30:40Z",
|
||||
"aliases": [
|
||||
"CVE-2024-27439"
|
||||
],
|
||||
"summary": "Cross-Site Request Forgery in Apache Wicket",
|
||||
"details": "An error in the evaluation of the fetch metadata headers could allow a bypass of the CSRF protection in Apache Wicket.\nThis issue affects Apache Wicket: from 9.1.0 through 9.16.0, and the milestone releases for the 10.0 series.\nApache Wicket 8.x does not support CSRF protection via the fetch metadata headers and as such is not affected.\n\nUsers are recommended to upgrade to version 9.17.0 or 10.0.0, which fixes the issue.\n\n",
|
||||
"details": "An error in the evaluation of the fetch metadata headers could allow a bypass of the CSRF protection in Apache Wicket.\nThis issue affects Apache Wicket: from 9.1.0 through 9.16.0, and the milestone releases for the 10.0 series.\nApache Wicket 8.x does not support CSRF protection via the fetch metadata headers and as such is not affected.\n\nUsers are recommended to upgrade to version 9.17.0 or 10.0.0, which fixes the issue.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
|
||||
@@ -1,13 +1,13 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-9w38-p64v-xpmv",
|
||||
"modified": "2024-11-04T21:24:14Z",
|
||||
"modified": "2025-02-13T19:04:48Z",
|
||||
"published": "2024-03-21T09:31:14Z",
|
||||
"aliases": [
|
||||
"CVE-2024-29133"
|
||||
],
|
||||
"summary": "Apache Commons Configuration: StackOverflowError calling ListDelimiterHandler.flatten(Object, int) with a cyclical object tree",
|
||||
"details": "This Out-of-bounds Write vulnerability in Apache Commons Configuration affects Apache Commons Configuration: from 2.0 before 2.10.1. User can see this as a 'StackOverflowError' calling 'ListDelimiterHandler.flatten(Object, int)' with a cyclical object tree.\nUsers are recommended to upgrade to version 2.10.1, which fixes the issue. \n\n",
|
||||
"details": "This Out-of-bounds Write vulnerability in Apache Commons Configuration affects Apache Commons Configuration: from 2.0 before 2.10.1. User can see this as a 'StackOverflowError' calling 'ListDelimiterHandler.flatten(Object, int)' with a cyclical object tree.\nUsers are recommended to upgrade to version 2.10.1, which fixes the issue.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-cff3-5qrp-hqx7",
|
||||
"modified": "2024-05-02T19:01:34Z",
|
||||
"modified": "2025-02-13T19:04:38Z",
|
||||
"published": "2024-03-26T18:32:06Z",
|
||||
"aliases": [
|
||||
"CVE-2024-29735"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-f3jh-qvm4-mg39",
|
||||
"modified": "2024-11-12T21:41:14Z",
|
||||
"modified": "2025-02-13T19:05:40Z",
|
||||
"published": "2024-03-18T15:30:51Z",
|
||||
"aliases": [
|
||||
"CVE-2024-22257"
|
||||
|
||||
@@ -1,13 +1,13 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-hgjh-9rj2-g67j",
|
||||
"modified": "2024-06-10T18:30:53Z",
|
||||
"modified": "2025-02-13T19:05:43Z",
|
||||
"published": "2024-03-16T06:30:27Z",
|
||||
"aliases": [
|
||||
"CVE-2024-22259"
|
||||
],
|
||||
"summary": "Spring Framework URL Parsing with Host Validation Vulnerability",
|
||||
"details": "Applications that use UriComponentsBuilder in Spring Framework to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/definitions/601.html attack or to a SSRF attack if the URL is used after passing validation checks.\n\nThis is the same as CVE-2024-22243 https://spring.io/security/cve-2024-22243, but with different input.\n\n",
|
||||
"details": "Applications that use UriComponentsBuilder in Spring Framework to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/definitions/601.html attack or to a SSRF attack if the URL is used after passing validation checks.\n\nThis is the same as CVE-2024-22243 https://spring.io/security/cve-2024-22243, but with different input.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
|
||||
@@ -1,13 +1,13 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-xjp4-hw94-mvp5",
|
||||
"modified": "2024-12-13T15:30:38Z",
|
||||
"modified": "2025-02-13T19:05:12Z",
|
||||
"published": "2024-03-21T09:31:14Z",
|
||||
"aliases": [
|
||||
"CVE-2024-29131"
|
||||
],
|
||||
"summary": "Apache Commons Configuration: StackOverflowError adding property in AbstractListDelimiterHandler.flattenIterator()",
|
||||
"details": "This Out-of-bounds Write vulnerability in Apache Commons Configuration affects Apache Commons Configuration: from 2.0 before 2.10.1. User can see this as a 'StackOverflowError' when adding a property in 'AbstractListDelimiterHandler.flattenIterator()'.\nUsers are recommended to upgrade to version 2.10.1, which fixes the issue. \n\n",
|
||||
"details": "This Out-of-bounds Write vulnerability in Apache Commons Configuration affects Apache Commons Configuration: from 2.0 before 2.10.1. User can see this as a 'StackOverflowError' when adding a property in 'AbstractListDelimiterHandler.flattenIterator()'.\nUsers are recommended to upgrade to version 2.10.1, which fixes the issue.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
|
||||
Reference in New Issue
Block a user