diff --git a/advisories/github-reviewed/2024/03/GHSA-2g4c-8fpm-c46v/GHSA-2g4c-8fpm-c46v.json b/advisories/github-reviewed/2024/03/GHSA-2g4c-8fpm-c46v/GHSA-2g4c-8fpm-c46v.json new file mode 100644 index 00000000000..3c8fb0f4654 --- /dev/null +++ b/advisories/github-reviewed/2024/03/GHSA-2g4c-8fpm-c46v/GHSA-2g4c-8fpm-c46v.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2g4c-8fpm-c46v", + "modified": "2024-03-27T21:57:42Z", + "published": "2024-03-27T21:57:42Z", + "aliases": [ + "CVE-2024-21505" + ], + "summary": "web3-utils Prototype Pollution vulnerability", + "details": "### Impact: \nThe mergeDeep() function in the web3-utils package has been identified for Prototype Pollution vulnerability. An attacker has the ability to modify an object's prototype, which could result in changing the behavior of all objects that inherit from the impacted prototype by providing carefully crafted input to function.\n\n### Patches: \nIt has been fixed in web3-utils version 4.2.1 so all packages and apps depending on web3-utils >=4.0.1 and <=4.2.0 should upgrade to web3-utils 4.2.1.\n\n### Workarounds: \nNone\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + { + "package": { + "ecosystem": "npm", + "name": "web3-utils" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "4.0.1" + }, + { + "fixed": "4.2.1" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/web3/web3.js/security/advisories/GHSA-2g4c-8fpm-c46v" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21505" + }, + { + "type": "WEB", + "url": "https://github.com/web3/web3.js/commit/8ed041c6635d807b3da8960ad49e125e3d1b0e80" + }, + { + "type": "PACKAGE", + "url": "https://github.com/web3/web3.js" + }, + { + "type": "WEB", + "url": "https://security.snyk.io/vuln/SNYK-JS-WEB3UTILS-6229337" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1321" + ], + "severity": "HIGH", + "github_reviewed": true, + "github_reviewed_at": "2024-03-27T21:57:42Z", + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/03/GHSA-5667-3wch-7q7w/GHSA-5667-3wch-7q7w.json b/advisories/github-reviewed/2024/03/GHSA-5667-3wch-7q7w/GHSA-5667-3wch-7q7w.json similarity index 61% rename from advisories/unreviewed/2024/03/GHSA-5667-3wch-7q7w/GHSA-5667-3wch-7q7w.json rename to advisories/github-reviewed/2024/03/GHSA-5667-3wch-7q7w/GHSA-5667-3wch-7q7w.json index 84cc1ff789d..5019c08f12f 100644 --- a/advisories/unreviewed/2024/03/GHSA-5667-3wch-7q7w/GHSA-5667-3wch-7q7w.json +++ b/advisories/github-reviewed/2024/03/GHSA-5667-3wch-7q7w/GHSA-5667-3wch-7q7w.json @@ -1,17 +1,36 @@ { "schema_version": "1.4.0", "id": "GHSA-5667-3wch-7q7w", - "modified": "2024-03-27T09:30:40Z", + "modified": "2024-03-27T21:58:42Z", "published": "2024-03-27T09:30:40Z", "aliases": [ "CVE-2024-1023" ], + "summary": "Eclipse Vert.x memory leak", "details": "A vulnerability in the Eclipse Vert.x toolkit results in a memory leak due to using Netty FastThreadLocal data structures. Specifically, when the Vert.x HTTP client establishes connections to different hosts, triggering the memory leak. The leak can be accelerated with intimate runtime knowledge, allowing an attacker to exploit this vulnerability. For instance, a server accepting arbitrary internet addresses could serve as an attack vector by connecting to these addresses, thereby accelerating the memory leak.", "severity": [ ], "affected": [ - + { + "package": { + "ecosystem": "Maven", + "name": "io.vertx:vertx-core" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "4.4.5" + }, + { + "fixed": "4.5.2" + } + ] + } + ] + } ], "references": [ { @@ -30,6 +49,14 @@ "type": "WEB", "url": "https://github.com/eclipse-vertx/vert.x/pull/5082" }, + { + "type": "WEB", + "url": "https://github.com/eclipse-vertx/vert.x/commit/665ceba38444e3929bb7b9a2a0bae2cb603fe81b" + }, + { + "type": "WEB", + "url": "https://github.com/eclipse-vertx/vert.x/commit/dd6f64302b56cd4d3dcf61efaaf174b5f6ce676d" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-1023" @@ -37,15 +64,19 @@ { "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2260840" + }, + { + "type": "PACKAGE", + "url": "https://github.com/eclipse-vertx/vert.x" } ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], - "severity": null, - "github_reviewed": false, - "github_reviewed_at": null, + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-03-27T21:58:41Z", "nvd_published_at": "2024-03-27T08:15:38Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2024/03/GHSA-87qp-7cw8-8q9c/GHSA-87qp-7cw8-8q9c.json b/advisories/github-reviewed/2024/03/GHSA-87qp-7cw8-8q9c/GHSA-87qp-7cw8-8q9c.json index a3017df393f..9fac622640d 100644 --- a/advisories/github-reviewed/2024/03/GHSA-87qp-7cw8-8q9c/GHSA-87qp-7cw8-8q9c.json +++ b/advisories/github-reviewed/2024/03/GHSA-87qp-7cw8-8q9c/GHSA-87qp-7cw8-8q9c.json @@ -1,13 +1,14 @@ { "schema_version": "1.4.0", "id": "GHSA-87qp-7cw8-8q9c", - "modified": "2024-03-25T19:36:43Z", + "modified": "2024-03-27T21:57:36Z", "published": "2024-03-25T06:30:24Z", + "withdrawn": "2024-03-27T21:57:36Z", "aliases": [ - "CVE-2024-21505" + ], - "summary": "web3-utils Prototype Pollution vulnerability", - "details": "Versions of the package web3-utils before 4.2.1 are vulnerable to Prototype Pollution via the utility functions format and mergeDeep, due to insecure recursive merge.\nAn attacker can manipulate an object's prototype, potentially leading to the alteration of the behavior of all objects inheriting from the affected prototype by passing specially crafted input to these functions.", + "summary": "Duplicate Advisory: web3-utils Prototype Pollution vulnerability", + "details": "## Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-2g4c-8fpm-c46v. This link is maintained to preserve external references.\n\n## Original Description\nVersions of the package web3-utils before 4.2.1 are vulnerable to Prototype Pollution via the utility functions format and mergeDeep, due to insecure recursive merge.\nAn attacker can manipulate an object's prototype, potentially leading to the alteration of the behavior of all objects inheriting from the affected prototype by passing specially crafted input to these functions.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/03/GHSA-r364-m2j9-mf4h/GHSA-r364-m2j9-mf4h.json b/advisories/github-reviewed/2024/03/GHSA-r364-m2j9-mf4h/GHSA-r364-m2j9-mf4h.json similarity index 60% rename from advisories/unreviewed/2024/03/GHSA-r364-m2j9-mf4h/GHSA-r364-m2j9-mf4h.json rename to advisories/github-reviewed/2024/03/GHSA-r364-m2j9-mf4h/GHSA-r364-m2j9-mf4h.json index 730100bd9b4..969e2f88802 100644 --- a/advisories/unreviewed/2024/03/GHSA-r364-m2j9-mf4h/GHSA-r364-m2j9-mf4h.json +++ b/advisories/github-reviewed/2024/03/GHSA-r364-m2j9-mf4h/GHSA-r364-m2j9-mf4h.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-r364-m2j9-mf4h", - "modified": "2024-03-27T03:31:16Z", + "modified": "2024-03-27T21:58:06Z", "published": "2024-03-27T03:31:16Z", "aliases": [ "CVE-2024-2206" ], + "summary": "gradio Server-Side Request Forgery vulnerability", "details": "The /proxy route allows a user to proxy arbitrary urls including potential internal endpoints.", "severity": [ { @@ -14,7 +15,25 @@ } ], "affected": [ - + { + "package": { + "ecosystem": "PyPI", + "name": "gradio" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.18.0" + } + ] + } + ] + } ], "references": [ { @@ -25,6 +44,10 @@ "type": "WEB", "url": "https://github.com/gradio-app/gradio/commit/49d9c48537aa706bf72628e3640389470138bdc6" }, + { + "type": "PACKAGE", + "url": "https://github.com/gradio-app/gradio" + }, { "type": "WEB", "url": "https://huntr.com/bounties/2286c1ed-b889-45d6-adda-7014ea06d98e" @@ -35,8 +58,8 @@ "CWE-918" ], "severity": "HIGH", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-03-27T21:58:06Z", "nvd_published_at": "2024-03-27T01:15:46Z" } } \ No newline at end of file