Publish Advisories

GHSA-8vvp-525h-cxf9
GHSA-9w38-p64v-xpmv
GHSA-cff3-5qrp-hqx7
GHSA-f3jh-qvm4-mg39
GHSA-hgjh-9rj2-g67j
GHSA-xjp4-hw94-mvp5
This commit is contained in:
advisory-database[bot]
2025-02-13 19:06:21 +00:00
parent cdbbdb8256
commit b4e630076d
6 changed files with 10 additions and 10 deletions
@@ -1,13 +1,13 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8vvp-525h-cxf9",
"modified": "2024-12-06T22:00:54Z",
"modified": "2025-02-13T19:05:24Z",
"published": "2024-03-19T12:30:40Z",
"aliases": [
"CVE-2024-27439"
],
"summary": "Cross-Site Request Forgery in Apache Wicket",
"details": "An error in the evaluation of the fetch metadata headers could allow a bypass of the CSRF protection in Apache Wicket.\nThis issue affects Apache Wicket: from 9.1.0 through 9.16.0, and the milestone releases for the 10.0 series.\nApache Wicket 8.x does not support CSRF protection via the fetch metadata headers and as such is not affected.\n\nUsers are recommended to upgrade to version 9.17.0 or 10.0.0, which fixes the issue.\n\n",
"details": "An error in the evaluation of the fetch metadata headers could allow a bypass of the CSRF protection in Apache Wicket.\nThis issue affects Apache Wicket: from 9.1.0 through 9.16.0, and the milestone releases for the 10.0 series.\nApache Wicket 8.x does not support CSRF protection via the fetch metadata headers and as such is not affected.\n\nUsers are recommended to upgrade to version 9.17.0 or 10.0.0, which fixes the issue.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,13 +1,13 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9w38-p64v-xpmv",
"modified": "2024-11-04T21:24:14Z",
"modified": "2025-02-13T19:04:48Z",
"published": "2024-03-21T09:31:14Z",
"aliases": [
"CVE-2024-29133"
],
"summary": "Apache Commons Configuration: StackOverflowError calling ListDelimiterHandler.flatten(Object, int) with a cyclical object tree",
"details": "This Out-of-bounds Write vulnerability in Apache Commons Configuration affects Apache Commons Configuration: from 2.0 before 2.10.1. User can see this as a 'StackOverflowError' calling 'ListDelimiterHandler.flatten(Object, int)' with a cyclical object tree.\nUsers are recommended to upgrade to version 2.10.1, which fixes the issue. \n\n",
"details": "This Out-of-bounds Write vulnerability in Apache Commons Configuration affects Apache Commons Configuration: from 2.0 before 2.10.1. User can see this as a 'StackOverflowError' calling 'ListDelimiterHandler.flatten(Object, int)' with a cyclical object tree.\nUsers are recommended to upgrade to version 2.10.1, which fixes the issue.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cff3-5qrp-hqx7",
"modified": "2024-05-02T19:01:34Z",
"modified": "2025-02-13T19:04:38Z",
"published": "2024-03-26T18:32:06Z",
"aliases": [
"CVE-2024-29735"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f3jh-qvm4-mg39",
"modified": "2024-11-12T21:41:14Z",
"modified": "2025-02-13T19:05:40Z",
"published": "2024-03-18T15:30:51Z",
"aliases": [
"CVE-2024-22257"
@@ -1,13 +1,13 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hgjh-9rj2-g67j",
"modified": "2024-06-10T18:30:53Z",
"modified": "2025-02-13T19:05:43Z",
"published": "2024-03-16T06:30:27Z",
"aliases": [
"CVE-2024-22259"
],
"summary": "Spring Framework URL Parsing with Host Validation Vulnerability",
"details": "Applications that use UriComponentsBuilder in Spring Framework to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/definitions/601.html  attack or to a SSRF attack if the URL is used after passing validation checks.\n\nThis is the same as CVE-2024-22243 https://spring.io/security/cve-2024-22243, but with different input.\n\n",
"details": "Applications that use UriComponentsBuilder in Spring Framework to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/definitions/601.html  attack or to a SSRF attack if the URL is used after passing validation checks.\n\nThis is the same as CVE-2024-22243 https://spring.io/security/cve-2024-22243, but with different input.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,13 +1,13 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xjp4-hw94-mvp5",
"modified": "2024-12-13T15:30:38Z",
"modified": "2025-02-13T19:05:12Z",
"published": "2024-03-21T09:31:14Z",
"aliases": [
"CVE-2024-29131"
],
"summary": "Apache Commons Configuration: StackOverflowError adding property in AbstractListDelimiterHandler.flattenIterator()",
"details": "This Out-of-bounds Write vulnerability in Apache Commons Configuration affects Apache Commons Configuration: from 2.0 before 2.10.1. User can see this as a 'StackOverflowError' when adding a property in 'AbstractListDelimiterHandler.flattenIterator()'.\nUsers are recommended to upgrade to version 2.10.1, which fixes the issue. \n\n",
"details": "This Out-of-bounds Write vulnerability in Apache Commons Configuration affects Apache Commons Configuration: from 2.0 before 2.10.1. User can see this as a 'StackOverflowError' when adding a property in 'AbstractListDelimiterHandler.flattenIterator()'.\nUsers are recommended to upgrade to version 2.10.1, which fixes the issue.",
"severity": [
{
"type": "CVSS_V3",