From c111e141ba830dc1ca91ddac9e96cf2a97ac1e8c Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 30 Jan 2024 23:19:52 +0000 Subject: [PATCH] Publish Advisories GHSA-3vcx-w94h-68vg GHSA-6q4p-jrjv-44gf GHSA-7p4p-v6hr-gp3m GHSA-p3g4-9xfv-wq9v GHSA-vf2c-w49g-3xf3 GHSA-xgmh-rvpw-6498 --- .../GHSA-3vcx-w94h-68vg.json | 30 ++++++++++++++++--- .../GHSA-6q4p-jrjv-44gf.json | 27 ++++++++++++++--- .../GHSA-7p4p-v6hr-gp3m.json | 27 ++++++++++++++--- .../GHSA-p3g4-9xfv-wq9v.json | 30 ++++++++++++++++--- .../GHSA-vf2c-w49g-3xf3.json | 27 ++++++++++++++--- .../GHSA-xgmh-rvpw-6498.json | 30 ++++++++++++++++--- 6 files changed, 147 insertions(+), 24 deletions(-) rename advisories/{unreviewed => github-reviewed}/2022/05/GHSA-3vcx-w94h-68vg/GHSA-3vcx-w94h-68vg.json (60%) rename advisories/{unreviewed => github-reviewed}/2022/05/GHSA-6q4p-jrjv-44gf/GHSA-6q4p-jrjv-44gf.json (66%) rename advisories/{unreviewed => github-reviewed}/2022/05/GHSA-7p4p-v6hr-gp3m/GHSA-7p4p-v6hr-gp3m.json (64%) rename advisories/{unreviewed => github-reviewed}/2022/05/GHSA-p3g4-9xfv-wq9v/GHSA-p3g4-9xfv-wq9v.json (64%) rename advisories/{unreviewed => github-reviewed}/2022/05/GHSA-vf2c-w49g-3xf3/GHSA-vf2c-w49g-3xf3.json (66%) rename advisories/{unreviewed => github-reviewed}/2022/05/GHSA-xgmh-rvpw-6498/GHSA-xgmh-rvpw-6498.json (58%) diff --git a/advisories/unreviewed/2022/05/GHSA-3vcx-w94h-68vg/GHSA-3vcx-w94h-68vg.json b/advisories/github-reviewed/2022/05/GHSA-3vcx-w94h-68vg/GHSA-3vcx-w94h-68vg.json similarity index 60% rename from advisories/unreviewed/2022/05/GHSA-3vcx-w94h-68vg/GHSA-3vcx-w94h-68vg.json rename to advisories/github-reviewed/2022/05/GHSA-3vcx-w94h-68vg/GHSA-3vcx-w94h-68vg.json index d98e6588b31..1fce5ffac1d 100644 --- a/advisories/unreviewed/2022/05/GHSA-3vcx-w94h-68vg/GHSA-3vcx-w94h-68vg.json +++ b/advisories/github-reviewed/2022/05/GHSA-3vcx-w94h-68vg/GHSA-3vcx-w94h-68vg.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-3vcx-w94h-68vg", - "modified": "2022-05-14T03:40:06Z", + "modified": "2024-01-30T23:17:57Z", "published": "2022-05-14T03:40:06Z", "aliases": [ "CVE-2018-1000055" ], + "summary": "XXE vulnerability in Jenkins Android Lint Plugin", "details": "Jenkins Android Lint Plugin 2.5 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with user permissions in Jenkins to extract secrets from the Jenkins master, perform server-side request forgery, or denial-of-service attacks.", "severity": [ { @@ -14,7 +15,28 @@ } ], "affected": [ - + { + "package": { + "ecosystem": "Maven", + "name": "org.jvnet.hudson.plugins:android-lint" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.6" + } + ] + } + ], + "database_specific": { + "last_known_affected_version_range": "<= 2.5" + } + } ], "references": [ { @@ -31,8 +53,8 @@ "CWE-611" ], "severity": "HIGH", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-01-30T23:17:57Z", "nvd_published_at": "2018-02-09T23:29:00Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-6q4p-jrjv-44gf/GHSA-6q4p-jrjv-44gf.json b/advisories/github-reviewed/2022/05/GHSA-6q4p-jrjv-44gf/GHSA-6q4p-jrjv-44gf.json similarity index 66% rename from advisories/unreviewed/2022/05/GHSA-6q4p-jrjv-44gf/GHSA-6q4p-jrjv-44gf.json rename to advisories/github-reviewed/2022/05/GHSA-6q4p-jrjv-44gf/GHSA-6q4p-jrjv-44gf.json index 2ef10b27304..d6a0d95360b 100644 --- a/advisories/unreviewed/2022/05/GHSA-6q4p-jrjv-44gf/GHSA-6q4p-jrjv-44gf.json +++ b/advisories/github-reviewed/2022/05/GHSA-6q4p-jrjv-44gf/GHSA-6q4p-jrjv-44gf.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-6q4p-jrjv-44gf", - "modified": "2023-02-02T21:34:15Z", + "modified": "2024-01-30T23:18:52Z", "published": "2022-05-24T16:52:46Z", "aliases": [ "CVE-2019-10386" ], + "summary": "Cross-site request forgery vulnerability in Jenkins XL TestView Plugin", "details": "A cross-site request forgery vulnerability in Jenkins XL TestView Plugin 1.2.0 and earlier in XLTestView.XLTestDescriptor#doTestConnection allows users with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.", "severity": [ { @@ -14,7 +15,25 @@ } ], "affected": [ - + { + "package": { + "ecosystem": "Maven", + "name": "com.xebialabs.xlt.ci:xltestview-plugin" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "1.2.0" + } + ] + } + ] + } ], "references": [ { @@ -35,8 +54,8 @@ "CWE-352" ], "severity": "HIGH", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-01-30T23:18:52Z", "nvd_published_at": "2019-08-07T15:15:00Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-7p4p-v6hr-gp3m/GHSA-7p4p-v6hr-gp3m.json b/advisories/github-reviewed/2022/05/GHSA-7p4p-v6hr-gp3m/GHSA-7p4p-v6hr-gp3m.json similarity index 64% rename from advisories/unreviewed/2022/05/GHSA-7p4p-v6hr-gp3m/GHSA-7p4p-v6hr-gp3m.json rename to advisories/github-reviewed/2022/05/GHSA-7p4p-v6hr-gp3m/GHSA-7p4p-v6hr-gp3m.json index d637b050978..b48a90b9ff4 100644 --- a/advisories/unreviewed/2022/05/GHSA-7p4p-v6hr-gp3m/GHSA-7p4p-v6hr-gp3m.json +++ b/advisories/github-reviewed/2022/05/GHSA-7p4p-v6hr-gp3m/GHSA-7p4p-v6hr-gp3m.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-7p4p-v6hr-gp3m", - "modified": "2022-05-14T03:13:12Z", + "modified": "2024-01-30T23:19:23Z", "published": "2022-05-14T03:13:12Z", "aliases": [ "CVE-2018-1000196" ], + "summary": "Jenkins Gitlab Hook Plugin stores and displays GitLab API token in plain text", "details": "A exposure of sensitive information vulnerability exists in Jenkins Gitlab Hook Plugin 1.4.2 and older in gitlab_notifier.rb, views/gitlab_notifier/global.erb that allows attackers with local Jenkins master file system access or control of a Jenkins administrator's web browser (e.g. malicious extension) to retrieve the configured Gitlab token.", "severity": [ { @@ -14,7 +15,25 @@ } ], "affected": [ - + { + "package": { + "ecosystem": "Maven", + "name": "org.jenkins-ci.ruby-plugins:gitlab-hook" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "1.4.2" + } + ] + } + ] + } ], "references": [ { @@ -31,8 +50,8 @@ "CWE-200" ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-01-30T23:19:23Z", "nvd_published_at": "2018-06-05T21:29:00Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-p3g4-9xfv-wq9v/GHSA-p3g4-9xfv-wq9v.json b/advisories/github-reviewed/2022/05/GHSA-p3g4-9xfv-wq9v/GHSA-p3g4-9xfv-wq9v.json similarity index 64% rename from advisories/unreviewed/2022/05/GHSA-p3g4-9xfv-wq9v/GHSA-p3g4-9xfv-wq9v.json rename to advisories/github-reviewed/2022/05/GHSA-p3g4-9xfv-wq9v/GHSA-p3g4-9xfv-wq9v.json index 3d71d515807..68e2f7608c6 100644 --- a/advisories/unreviewed/2022/05/GHSA-p3g4-9xfv-wq9v/GHSA-p3g4-9xfv-wq9v.json +++ b/advisories/github-reviewed/2022/05/GHSA-p3g4-9xfv-wq9v/GHSA-p3g4-9xfv-wq9v.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-p3g4-9xfv-wq9v", - "modified": "2022-05-14T03:40:05Z", + "modified": "2024-01-30T23:18:21Z", "published": "2022-05-14T03:40:05Z", "aliases": [ "CVE-2018-1000058" ], + "summary": "Arbitrary code execution due to incomplete sandbox protection in Pipeline: Supporting APIs Plugin", "details": "Jenkins Pipeline: Supporting APIs Plugin 2.17 and earlier have an arbitrary code execution due to incomplete sandbox protection: Methods related to Java deserialization like readResolve implemented in Pipeline scripts were not subject to sandbox protection, and could therefore execute arbitrary code. This could be exploited e.g. by regular Jenkins users with the permission to configure Pipelines in Jenkins, or by trusted committers to repositories containing Jenkinsfiles.", "severity": [ { @@ -14,7 +15,28 @@ } ], "affected": [ - + { + "package": { + "ecosystem": "Maven", + "name": "org.jenkins-ci.plugins.workflow:workflow-support" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.18" + } + ] + } + ], + "database_specific": { + "last_known_affected_version_range": "<= 2.17" + } + } ], "references": [ { @@ -35,8 +57,8 @@ "CWE-502" ], "severity": "HIGH", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-01-30T23:18:21Z", "nvd_published_at": "2018-02-09T23:29:00Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-vf2c-w49g-3xf3/GHSA-vf2c-w49g-3xf3.json b/advisories/github-reviewed/2022/05/GHSA-vf2c-w49g-3xf3/GHSA-vf2c-w49g-3xf3.json similarity index 66% rename from advisories/unreviewed/2022/05/GHSA-vf2c-w49g-3xf3/GHSA-vf2c-w49g-3xf3.json rename to advisories/github-reviewed/2022/05/GHSA-vf2c-w49g-3xf3/GHSA-vf2c-w49g-3xf3.json index c313827b96c..8343577d9bc 100644 --- a/advisories/unreviewed/2022/05/GHSA-vf2c-w49g-3xf3/GHSA-vf2c-w49g-3xf3.json +++ b/advisories/github-reviewed/2022/05/GHSA-vf2c-w49g-3xf3/GHSA-vf2c-w49g-3xf3.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-vf2c-w49g-3xf3", - "modified": "2023-10-25T18:31:25Z", + "modified": "2024-01-30T23:19:08Z", "published": "2022-05-24T16:52:46Z", "aliases": [ "CVE-2019-10387" ], + "summary": "Missing permission check in Jenkins XL TestView Plugin", "details": "A missing permission check in Jenkins XL TestView Plugin 1.2.0 and earlier in XLTestView.XLTestDescriptor#doTestConnection allows users with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.", "severity": [ { @@ -14,7 +15,25 @@ } ], "affected": [ - + { + "package": { + "ecosystem": "Maven", + "name": "com.xebialabs.xlt.ci:xltestview-plugin" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "1.2.0" + } + ] + } + ] + } ], "references": [ { @@ -35,8 +54,8 @@ "CWE-862" ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-01-30T23:19:08Z", "nvd_published_at": "2019-08-07T15:15:00Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-xgmh-rvpw-6498/GHSA-xgmh-rvpw-6498.json b/advisories/github-reviewed/2022/05/GHSA-xgmh-rvpw-6498/GHSA-xgmh-rvpw-6498.json similarity index 58% rename from advisories/unreviewed/2022/05/GHSA-xgmh-rvpw-6498/GHSA-xgmh-rvpw-6498.json rename to advisories/github-reviewed/2022/05/GHSA-xgmh-rvpw-6498/GHSA-xgmh-rvpw-6498.json index d96456a765a..0c5e1cccd28 100644 --- a/advisories/unreviewed/2022/05/GHSA-xgmh-rvpw-6498/GHSA-xgmh-rvpw-6498.json +++ b/advisories/github-reviewed/2022/05/GHSA-xgmh-rvpw-6498/GHSA-xgmh-rvpw-6498.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-xgmh-rvpw-6498", - "modified": "2022-05-14T03:33:40Z", + "modified": "2024-01-30T23:18:27Z", "published": "2022-05-14T03:33:40Z", "aliases": [ "CVE-2018-1000108" ], + "summary": "Reflected cross-site-scripting vulnerability in report URL of Jenkins CppNCSS Plugin", "details": "A cross-site scripting vulnerability exists in Jenkins CppNCSS Plugin 1.1 and earlier in AbstractProjectAction/index.jelly that allow an attacker to craft links to Jenkins URLs that run arbitrary JavaScript in the user's browser when accessed.", "severity": [ { @@ -14,7 +15,28 @@ } ], "affected": [ - + { + "package": { + "ecosystem": "Maven", + "name": "org.jenkins-ci.plugins:cppncss" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.2" + } + ] + } + ], + "database_specific": { + "last_known_affected_version_range": "<= 1.1" + } + } ], "references": [ { @@ -31,8 +53,8 @@ "CWE-79" ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-01-30T23:18:27Z", "nvd_published_at": "2018-03-13T13:29:00Z" } } \ No newline at end of file