Publish Advisories

GHSA-r969-783f-6jqr
GHSA-vfph-hjfv-cpv2
GHSA-vp66-gf7w-9m4x
This commit is contained in:
advisory-database[bot]
2024-02-20 23:49:50 +00:00
parent 01aaf1b6fe
commit bee259b794
3 changed files with 81 additions and 12 deletions
@@ -1,11 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r969-783f-6jqr",
"modified": "2024-02-17T06:30:35Z",
"modified": "2024-02-20T23:48:04Z",
"published": "2024-02-17T06:30:35Z",
"aliases": [
"CVE-2024-21499"
],
"summary": "Improper Neutralization of HTTP Headers in github.com/greenpau/caddy-security",
"details": "All versions of the package github.com/greenpau/caddy-security are vulnerable to HTTP Header Injection via the X-Forwarded-Proto header due to redirecting to the injected protocol.Exploiting this vulnerability could lead to bypass of security mechanisms or confusion in handling TLS.",
"severity": [
{
@@ -14,7 +15,25 @@
}
],
"affected": [
{
"package": {
"ecosystem": "Go",
"name": "github.com/greenpau/caddy-security"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.1.23"
}
]
}
]
}
],
"references": [
{
@@ -32,6 +51,10 @@
{
"type": "WEB",
"url": "https://security.snyk.io/vuln/SNYK-GOLANG-GITHUBCOMGREENPAUCADDYSECURITY-6249863"
},
{
"type": "PACKAGE",
"url": "github.com/greenpau/caddy-security"
}
],
"database_specific": {
@@ -39,8 +62,8 @@
"CWE-644"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"github_reviewed": true,
"github_reviewed_at": "2024-02-20T23:48:04Z",
"nvd_published_at": "2024-02-17T05:15:10Z"
}
}
@@ -1,11 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vfph-hjfv-cpv2",
"modified": "2024-02-17T06:30:35Z",
"modified": "2024-02-20T23:48:22Z",
"published": "2024-02-17T06:30:35Z",
"aliases": [
"CVE-2024-21500"
],
"summary": "Improper Restriction of Excessive Authentication Attempts in github.com/greenpau/caddy-security",
"details": "All versions of the package github.com/greenpau/caddy-security are vulnerable to Improper Restriction of Excessive Authentication Attempts via the two-factor authentication (2FA). Although the application blocks the user after several failed attempts to provide 2FA codes, attackers can bypass this blocking mechanism by automating the applications full multistep 2FA process.",
"severity": [
{
@@ -14,7 +15,25 @@
}
],
"affected": [
{
"package": {
"ecosystem": "Go",
"name": "github.com/greenpau/caddy-security"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.1.23"
}
]
}
]
}
],
"references": [
{
@@ -32,6 +51,10 @@
{
"type": "WEB",
"url": "https://security.snyk.io/vuln/SNYK-GOLANG-GITHUBCOMGREENPAUCADDYSECURITY-6249864"
},
{
"type": "PACKAGE",
"url": "github.com/greenpau/caddy-security"
}
],
"database_specific": {
@@ -39,8 +62,8 @@
"CWE-307"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"github_reviewed": true,
"github_reviewed_at": "2024-02-20T23:48:22Z",
"nvd_published_at": "2024-02-17T05:15:10Z"
}
}
@@ -1,11 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vp66-gf7w-9m4x",
"modified": "2024-02-17T06:30:34Z",
"modified": "2024-02-20T23:47:50Z",
"published": "2024-02-17T06:30:34Z",
"aliases": [
"CVE-2024-21492"
],
"summary": "Insufficient Session Expiration in github.com/greenpau/caddy-security",
"details": "All versions of the package github.com/greenpau/caddy-security are vulnerable to Insufficient Session Expiration due to improper user session invalidation upon clicking the \"Sign Out\" button. User sessions remain valid even after requests are sent to /logout and /oauth2/google/logout. Attackers who gain access to an active but supposedly logged-out session can perform unauthorized actions on behalf of the user.",
"severity": [
{
@@ -14,7 +15,25 @@
}
],
"affected": [
{
"package": {
"ecosystem": "Go",
"name": "github.com/greenpau/caddy-security"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.1.23"
}
]
}
]
}
],
"references": [
{
@@ -32,6 +51,10 @@
{
"type": "WEB",
"url": "https://security.snyk.io/vuln/SNYK-GOLANG-GITHUBCOMGREENPAUCADDYSECURITY-5920787"
},
{
"type": "PACKAGE",
"url": "github.com/greenpau/caddy-security"
}
],
"database_specific": {
@@ -39,8 +62,8 @@
"CWE-613"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"github_reviewed": true,
"github_reviewed_at": "2024-02-20T23:47:50Z",
"nvd_published_at": "2024-02-17T05:15:08Z"
}
}