From bb9d2b0934636380a90f8f0765121c393c91e700 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 18 Oct 2024 21:50:40 +0000 Subject: [PATCH] Publish Advisories GHSA-4mg4-wvmx-5332 GHSA-gc9g-67cq-p7v4 GHSA-hm2p-fhwx-9285 GHSA-rr8j-7w34-xp5j --- .../GHSA-4mg4-wvmx-5332.json | 18 +++++++++++++++++- .../GHSA-gc9g-67cq-p7v4.json | 18 +++++++++++++++++- .../GHSA-hm2p-fhwx-9285.json | 18 +++++++++++++++++- .../GHSA-rr8j-7w34-xp5j.json | 4 ++-- 4 files changed, 53 insertions(+), 5 deletions(-) diff --git a/advisories/github-reviewed/2021/06/GHSA-4mg4-wvmx-5332/GHSA-4mg4-wvmx-5332.json b/advisories/github-reviewed/2021/06/GHSA-4mg4-wvmx-5332/GHSA-4mg4-wvmx-5332.json index 3e20cdc12d8..c1390266d6a 100644 --- a/advisories/github-reviewed/2021/06/GHSA-4mg4-wvmx-5332/GHSA-4mg4-wvmx-5332.json +++ b/advisories/github-reviewed/2021/06/GHSA-4mg4-wvmx-5332/GHSA-4mg4-wvmx-5332.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4mg4-wvmx-5332", - "modified": "2021-05-27T21:39:48Z", + "modified": "2024-10-18T21:49:19Z", "published": "2021-06-15T16:11:47Z", "aliases": [ "CVE-2021-33510" @@ -12,6 +12,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N" } ], "affected": [ @@ -40,6 +44,18 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-33510" }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-4mg4-wvmx-5332" + }, + { + "type": "PACKAGE", + "url": "https://github.com/plone/Plone" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/plone/PYSEC-2021-82.yaml" + }, { "type": "WEB", "url": "https://plone.org/security/hotfix/20210518/server-side-request-forgery-via-event-ical-url" diff --git a/advisories/github-reviewed/2021/06/GHSA-gc9g-67cq-p7v4/GHSA-gc9g-67cq-p7v4.json b/advisories/github-reviewed/2021/06/GHSA-gc9g-67cq-p7v4/GHSA-gc9g-67cq-p7v4.json index d72ec5b7ef5..65a26631f4d 100644 --- a/advisories/github-reviewed/2021/06/GHSA-gc9g-67cq-p7v4/GHSA-gc9g-67cq-p7v4.json +++ b/advisories/github-reviewed/2021/06/GHSA-gc9g-67cq-p7v4/GHSA-gc9g-67cq-p7v4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gc9g-67cq-p7v4", - "modified": "2021-05-27T21:47:01Z", + "modified": "2024-10-18T21:48:44Z", "published": "2021-06-15T16:12:04Z", "aliases": [ "CVE-2021-33511" @@ -12,6 +12,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N" } ], "affected": [ @@ -40,6 +44,18 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-33511" }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-gc9g-67cq-p7v4" + }, + { + "type": "PACKAGE", + "url": "https://github.com/plone/Plone" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/plone/PYSEC-2021-83.yaml" + }, { "type": "WEB", "url": "https://plone.org/security/hotfix/20210518/server-side-request-forgery-via-lxml-parser" diff --git a/advisories/github-reviewed/2021/06/GHSA-hm2p-fhwx-9285/GHSA-hm2p-fhwx-9285.json b/advisories/github-reviewed/2021/06/GHSA-hm2p-fhwx-9285/GHSA-hm2p-fhwx-9285.json index e5172685a7c..7062d760c06 100644 --- a/advisories/github-reviewed/2021/06/GHSA-hm2p-fhwx-9285/GHSA-hm2p-fhwx-9285.json +++ b/advisories/github-reviewed/2021/06/GHSA-hm2p-fhwx-9285/GHSA-hm2p-fhwx-9285.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hm2p-fhwx-9285", - "modified": "2021-05-27T21:32:19Z", + "modified": "2024-10-18T21:49:59Z", "published": "2021-06-15T16:11:38Z", "aliases": [ "CVE-2021-33509" @@ -12,6 +12,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H" } ], "affected": [ @@ -40,6 +44,18 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-33509" }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-hm2p-fhwx-9285" + }, + { + "type": "PACKAGE", + "url": "https://github.com/plone/Plone" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/plone/PYSEC-2021-81.yaml" + }, { "type": "WEB", "url": "https://plone.org/security/hotfix/20210518/writing-arbitrary-files-via-docutils-and-python-script" diff --git a/advisories/github-reviewed/2024/10/GHSA-rr8j-7w34-xp5j/GHSA-rr8j-7w34-xp5j.json b/advisories/github-reviewed/2024/10/GHSA-rr8j-7w34-xp5j/GHSA-rr8j-7w34-xp5j.json index b496084d591..e8981f0ea0c 100644 --- a/advisories/github-reviewed/2024/10/GHSA-rr8j-7w34-xp5j/GHSA-rr8j-7w34-xp5j.json +++ b/advisories/github-reviewed/2024/10/GHSA-rr8j-7w34-xp5j/GHSA-rr8j-7w34-xp5j.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-rr8j-7w34-xp5j", - "modified": "2024-10-11T16:52:47Z", + "modified": "2024-10-18T21:48:29Z", "published": "2024-10-10T21:30:43Z", "aliases": [ "CVE-2024-9180" ], "summary": "Vault Community Edition privilege escalation vulnerability", - "details": "A privileged Vault operator with write permissions to the root namespace’s identity endpoint could escalate their privileges to Vault’s root policy. Fixed in Vault Community Edition 1.18.0 and Vault Enterprise 1.18.0, 1.17.7, 1.16.11, and 1.15.16.", + "details": "A privileged Vault operator with write permissions to the root namespace’s identity endpoint could escalate their privileges to Vault’s root policy. Fixed in Vault Community Edition 1.18.0 and Vault Enterprise 1.18.0, 1.17.7, 1.16.11, and 1.15.16", "severity": [ { "type": "CVSS_V3",