From b4e630076d1e091a52b107dea4b2cee7f644d24e Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 13 Feb 2025 19:06:21 +0000 Subject: [PATCH] Publish Advisories GHSA-8vvp-525h-cxf9 GHSA-9w38-p64v-xpmv GHSA-cff3-5qrp-hqx7 GHSA-f3jh-qvm4-mg39 GHSA-hgjh-9rj2-g67j GHSA-xjp4-hw94-mvp5 --- .../2024/03/GHSA-8vvp-525h-cxf9/GHSA-8vvp-525h-cxf9.json | 4 ++-- .../2024/03/GHSA-9w38-p64v-xpmv/GHSA-9w38-p64v-xpmv.json | 4 ++-- .../2024/03/GHSA-cff3-5qrp-hqx7/GHSA-cff3-5qrp-hqx7.json | 2 +- .../2024/03/GHSA-f3jh-qvm4-mg39/GHSA-f3jh-qvm4-mg39.json | 2 +- .../2024/03/GHSA-hgjh-9rj2-g67j/GHSA-hgjh-9rj2-g67j.json | 4 ++-- .../2024/03/GHSA-xjp4-hw94-mvp5/GHSA-xjp4-hw94-mvp5.json | 4 ++-- 6 files changed, 10 insertions(+), 10 deletions(-) diff --git a/advisories/github-reviewed/2024/03/GHSA-8vvp-525h-cxf9/GHSA-8vvp-525h-cxf9.json b/advisories/github-reviewed/2024/03/GHSA-8vvp-525h-cxf9/GHSA-8vvp-525h-cxf9.json index de9c8e76bca..b8362aa81d2 100644 --- a/advisories/github-reviewed/2024/03/GHSA-8vvp-525h-cxf9/GHSA-8vvp-525h-cxf9.json +++ b/advisories/github-reviewed/2024/03/GHSA-8vvp-525h-cxf9/GHSA-8vvp-525h-cxf9.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-8vvp-525h-cxf9", - "modified": "2024-12-06T22:00:54Z", + "modified": "2025-02-13T19:05:24Z", "published": "2024-03-19T12:30:40Z", "aliases": [ "CVE-2024-27439" ], "summary": "Cross-Site Request Forgery in Apache Wicket", - "details": "An error in the evaluation of the fetch metadata headers could allow a bypass of the CSRF protection in Apache Wicket.\nThis issue affects Apache Wicket: from 9.1.0 through 9.16.0, and the milestone releases for the 10.0 series.\nApache Wicket 8.x does not support CSRF protection via the fetch metadata headers and as such is not affected.\n\nUsers are recommended to upgrade to version 9.17.0 or 10.0.0, which fixes the issue.\n\n", + "details": "An error in the evaluation of the fetch metadata headers could allow a bypass of the CSRF protection in Apache Wicket.\nThis issue affects Apache Wicket: from 9.1.0 through 9.16.0, and the milestone releases for the 10.0 series.\nApache Wicket 8.x does not support CSRF protection via the fetch metadata headers and as such is not affected.\n\nUsers are recommended to upgrade to version 9.17.0 or 10.0.0, which fixes the issue.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2024/03/GHSA-9w38-p64v-xpmv/GHSA-9w38-p64v-xpmv.json b/advisories/github-reviewed/2024/03/GHSA-9w38-p64v-xpmv/GHSA-9w38-p64v-xpmv.json index d54733653da..13d69da672d 100644 --- a/advisories/github-reviewed/2024/03/GHSA-9w38-p64v-xpmv/GHSA-9w38-p64v-xpmv.json +++ b/advisories/github-reviewed/2024/03/GHSA-9w38-p64v-xpmv/GHSA-9w38-p64v-xpmv.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-9w38-p64v-xpmv", - "modified": "2024-11-04T21:24:14Z", + "modified": "2025-02-13T19:04:48Z", "published": "2024-03-21T09:31:14Z", "aliases": [ "CVE-2024-29133" ], "summary": "Apache Commons Configuration: StackOverflowError calling ListDelimiterHandler.flatten(Object, int) with a cyclical object tree", - "details": "This Out-of-bounds Write vulnerability in Apache Commons Configuration affects Apache Commons Configuration: from 2.0 before 2.10.1. User can see this as a 'StackOverflowError' calling 'ListDelimiterHandler.flatten(Object, int)' with a cyclical object tree.\nUsers are recommended to upgrade to version 2.10.1, which fixes the issue. \n\n", + "details": "This Out-of-bounds Write vulnerability in Apache Commons Configuration affects Apache Commons Configuration: from 2.0 before 2.10.1. User can see this as a 'StackOverflowError' calling 'ListDelimiterHandler.flatten(Object, int)' with a cyclical object tree.\nUsers are recommended to upgrade to version 2.10.1, which fixes the issue.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2024/03/GHSA-cff3-5qrp-hqx7/GHSA-cff3-5qrp-hqx7.json b/advisories/github-reviewed/2024/03/GHSA-cff3-5qrp-hqx7/GHSA-cff3-5qrp-hqx7.json index 4ae0ae5411c..25deba03d5c 100644 --- a/advisories/github-reviewed/2024/03/GHSA-cff3-5qrp-hqx7/GHSA-cff3-5qrp-hqx7.json +++ b/advisories/github-reviewed/2024/03/GHSA-cff3-5qrp-hqx7/GHSA-cff3-5qrp-hqx7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cff3-5qrp-hqx7", - "modified": "2024-05-02T19:01:34Z", + "modified": "2025-02-13T19:04:38Z", "published": "2024-03-26T18:32:06Z", "aliases": [ "CVE-2024-29735" diff --git a/advisories/github-reviewed/2024/03/GHSA-f3jh-qvm4-mg39/GHSA-f3jh-qvm4-mg39.json b/advisories/github-reviewed/2024/03/GHSA-f3jh-qvm4-mg39/GHSA-f3jh-qvm4-mg39.json index eafda842c7d..cdfc2e45adc 100644 --- a/advisories/github-reviewed/2024/03/GHSA-f3jh-qvm4-mg39/GHSA-f3jh-qvm4-mg39.json +++ b/advisories/github-reviewed/2024/03/GHSA-f3jh-qvm4-mg39/GHSA-f3jh-qvm4-mg39.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f3jh-qvm4-mg39", - "modified": "2024-11-12T21:41:14Z", + "modified": "2025-02-13T19:05:40Z", "published": "2024-03-18T15:30:51Z", "aliases": [ "CVE-2024-22257" diff --git a/advisories/github-reviewed/2024/03/GHSA-hgjh-9rj2-g67j/GHSA-hgjh-9rj2-g67j.json b/advisories/github-reviewed/2024/03/GHSA-hgjh-9rj2-g67j/GHSA-hgjh-9rj2-g67j.json index 4038850a3b8..abaa6501794 100644 --- a/advisories/github-reviewed/2024/03/GHSA-hgjh-9rj2-g67j/GHSA-hgjh-9rj2-g67j.json +++ b/advisories/github-reviewed/2024/03/GHSA-hgjh-9rj2-g67j/GHSA-hgjh-9rj2-g67j.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-hgjh-9rj2-g67j", - "modified": "2024-06-10T18:30:53Z", + "modified": "2025-02-13T19:05:43Z", "published": "2024-03-16T06:30:27Z", "aliases": [ "CVE-2024-22259" ], "summary": "Spring Framework URL Parsing with Host Validation Vulnerability", - "details": "Applications that use UriComponentsBuilder in Spring Framework to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/definitions/601.html  attack or to a SSRF attack if the URL is used after passing validation checks.\n\nThis is the same as CVE-2024-22243 https://spring.io/security/cve-2024-22243, but with different input.\n\n", + "details": "Applications that use UriComponentsBuilder in Spring Framework to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/definitions/601.html  attack or to a SSRF attack if the URL is used after passing validation checks.\n\nThis is the same as CVE-2024-22243 https://spring.io/security/cve-2024-22243, but with different input.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2024/03/GHSA-xjp4-hw94-mvp5/GHSA-xjp4-hw94-mvp5.json b/advisories/github-reviewed/2024/03/GHSA-xjp4-hw94-mvp5/GHSA-xjp4-hw94-mvp5.json index 9c3b6d4fd15..2fa33efc05a 100644 --- a/advisories/github-reviewed/2024/03/GHSA-xjp4-hw94-mvp5/GHSA-xjp4-hw94-mvp5.json +++ b/advisories/github-reviewed/2024/03/GHSA-xjp4-hw94-mvp5/GHSA-xjp4-hw94-mvp5.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-xjp4-hw94-mvp5", - "modified": "2024-12-13T15:30:38Z", + "modified": "2025-02-13T19:05:12Z", "published": "2024-03-21T09:31:14Z", "aliases": [ "CVE-2024-29131" ], "summary": "Apache Commons Configuration: StackOverflowError adding property in AbstractListDelimiterHandler.flattenIterator()", - "details": "This Out-of-bounds Write vulnerability in Apache Commons Configuration affects Apache Commons Configuration: from 2.0 before 2.10.1. User can see this as a 'StackOverflowError' when adding a property in 'AbstractListDelimiterHandler.flattenIterator()'.\nUsers are recommended to upgrade to version 2.10.1, which fixes the issue. \n\n", + "details": "This Out-of-bounds Write vulnerability in Apache Commons Configuration affects Apache Commons Configuration: from 2.0 before 2.10.1. User can see this as a 'StackOverflowError' when adding a property in 'AbstractListDelimiterHandler.flattenIterator()'.\nUsers are recommended to upgrade to version 2.10.1, which fixes the issue.", "severity": [ { "type": "CVSS_V3",