mirror of
https://github.com/netbirdio/advisory-database.git
synced 2026-05-22 18:04:22 -07:00
Publish Advisories
GHSA-4g42-gqrg-4633 GHSA-7g45-4rm6-3mm3 GHSA-8f6x-v685-g2xc GHSA-xm2m-2q6h-22jw GHSA-9hxf-ppjv-w6rq GHSA-47f6-5gq3-vx9c
This commit is contained in:
@@ -1,13 +1,13 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-4g42-gqrg-4633",
|
||||
"modified": "2023-06-21T21:47:38Z",
|
||||
"modified": "2025-02-13T18:58:22Z",
|
||||
"published": "2023-06-14T09:30:42Z",
|
||||
"aliases": [
|
||||
"CVE-2023-34396"
|
||||
],
|
||||
"summary": "Apache Struts vulnerable to memory exhaustion",
|
||||
"details": "Denial of service via out of memory (OOM) owing to no sanity limit on normal form fields in multipart forms. When a Multipart request has non-file normal form fields, Struts used to bring them into memory as Strings without checking their sizes. This could lead to an OOM if developer has set struts.multipart.maxSize to a value equal or greater than the available memory.\n\nUpgrade to Struts 2.5.31 or 6.1.2.1 or greater\n\n\n",
|
||||
"details": "Denial of service via out of memory (OOM) owing to no sanity limit on normal form fields in multipart forms. When a Multipart request has non-file normal form fields, Struts used to bring them into memory as Strings without checking their sizes. This could lead to an OOM if developer has set struts.multipart.maxSize to a value equal or greater than the available memory.\n\nUpgrade to Struts 2.5.31 or 6.1.2.1 or greater",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
|
||||
@@ -1,13 +1,13 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-7g45-4rm6-3mm3",
|
||||
"modified": "2024-02-13T21:48:06Z",
|
||||
"modified": "2025-02-13T18:58:56Z",
|
||||
"published": "2023-06-14T18:30:38Z",
|
||||
"aliases": [
|
||||
"CVE-2023-2976"
|
||||
],
|
||||
"summary": "Guava vulnerable to insecure use of temporary directory",
|
||||
"details": "Use of Java's default temporary directory for file creation in `FileBackedOutputStream` in Google Guava versions 1.0 to 31.1 on Unix systems and Android Ice Cream Sandwich allows other users and apps on the machine with access to the default Java temporary directory to be able to access the files created by the class.\n\nEven though the security vulnerability is fixed in version 32.0.0, maintainers recommend using version 32.0.1 as version 32.0.0 breaks some functionality under Windows.\n\n",
|
||||
"details": "Use of Java's default temporary directory for file creation in `FileBackedOutputStream` in Google Guava versions 1.0 to 31.1 on Unix systems and Android Ice Cream Sandwich allows other users and apps on the machine with access to the default Java temporary directory to be able to access the files created by the class.\n\nEven though the security vulnerability is fixed in version 32.0.0, maintainers recommend using version 32.0.1 as version 32.0.0 breaks some functionality under Windows.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
|
||||
@@ -1,13 +1,13 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-8f6x-v685-g2xc",
|
||||
"modified": "2023-06-21T21:47:08Z",
|
||||
"modified": "2025-02-13T18:58:19Z",
|
||||
"published": "2023-06-14T09:30:42Z",
|
||||
"aliases": [
|
||||
"CVE-2023-34149"
|
||||
],
|
||||
"summary": "Apache Struts vulnerable to memory exhaustion",
|
||||
"details": "Denial of service via out of memory (OOM) owing to not properly checking of list bounds. When a Multipart request has non-file normal form fields, Struts used to bring them into memory as Strings without checking their sizes. This could lead to OOM if developer has set struts.multipart.maxSize to a value equal or greater than the available memory.\n\nUpgrade to Struts 2.5.31 or 6.1.2.1 or greater.\n\n\n",
|
||||
"details": "Denial of service via out of memory (OOM) owing to not properly checking of list bounds. When a Multipart request has non-file normal form fields, Struts used to bring them into memory as Strings without checking their sizes. This could lead to OOM if developer has set struts.multipart.maxSize to a value equal or greater than the available memory.\n\nUpgrade to Struts 2.5.31 or 6.1.2.1 or greater.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
|
||||
@@ -1,13 +1,13 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-xm2m-2q6h-22jw",
|
||||
"modified": "2024-04-12T16:39:23Z",
|
||||
"modified": "2025-02-13T18:58:07Z",
|
||||
"published": "2023-06-12T18:30:18Z",
|
||||
"aliases": [
|
||||
"CVE-2023-34468"
|
||||
],
|
||||
"summary": "Apache NiFi vulnerable to Code Injection",
|
||||
"details": "The DBCPConnectionPool and HikariCPConnectionPool Controller Services in Apache NiFi 0.0.2 through 1.21.0 allow an authenticated and authorized user to configure a Database URL with the H2 driver that enables custom code execution.\n\nThe resolution validates the Database URL and rejects H2 JDBC locations.\n\nYou are recommended to upgrade to version 1.22.0 or later which fixes this issue.\n\n\n",
|
||||
"details": "The DBCPConnectionPool and HikariCPConnectionPool Controller Services in Apache NiFi 0.0.2 through 1.21.0 allow an authenticated and authorized user to configure a Database URL with the H2 driver that enables custom code execution.\n\nThe resolution validates the Database URL and rejects H2 JDBC locations.\n\nYou are recommended to upgrade to version 1.22.0 or later which fixes this issue.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
|
||||
@@ -1,13 +1,13 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-9hxf-ppjv-w6rq",
|
||||
"modified": "2023-07-24T16:55:40Z",
|
||||
"modified": "2025-02-13T18:58:13Z",
|
||||
"published": "2023-07-06T21:15:08Z",
|
||||
"aliases": [
|
||||
"CVE-2023-32732"
|
||||
],
|
||||
"summary": "gRPC connection termination issue",
|
||||
"details": "gRPC contains a vulnerability whereby a client can cause a termination of connection between a HTTP2 proxy and a gRPC server: a base64 encoding error for `-bin` suffixed headers will result in a disconnection by the gRPC server, but is typically allowed by HTTP2 proxies. We recommend upgrading beyond the commit in https://github.com/grpc/grpc/pull/32309.\n",
|
||||
"details": "gRPC contains a vulnerability whereby a client can cause a termination of connection between a HTTP2 proxy and a gRPC server: a base64 encoding error for `-bin` suffixed headers will result in a disconnection by the gRPC server, but is typically allowed by HTTP2 proxies. We recommend upgrading beyond the commit in https://github.com/grpc/grpc/pull/32309.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
|
||||
@@ -1,13 +1,13 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-47f6-5gq3-vx9c",
|
||||
"modified": "2024-06-20T09:30:58Z",
|
||||
"modified": "2025-02-13T18:58:20Z",
|
||||
"published": "2024-06-10T21:36:32Z",
|
||||
"aliases": [
|
||||
"CVE-2024-35241"
|
||||
],
|
||||
"summary": "Composer has a command injection via malicious git branch name",
|
||||
"details": "### Impact\n\nThe `status`, `reinstall` and `remove` commands with packages installed from source via git containing specially crafted branch names in the repository can be used to execute code.\n\n### Patches\n\n2.2.24 for 2.2 LTS or 2.7.7 for mainline\n\n### Workarounds\n\nAvoid installing dependencies via git by using `--prefer-dist` or the `preferred-install: dist` config setting.\n",
|
||||
"details": "### Impact\n\nThe `status`, `reinstall` and `remove` commands with packages installed from source via git containing specially crafted branch names in the repository can be used to execute code.\n\n### Patches\n\n2.2.24 for 2.2 LTS or 2.7.7 for mainline\n\n### Workarounds\n\nAvoid installing dependencies via git by using `--prefer-dist` or the `preferred-install: dist` config setting.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
|
||||
Reference in New Issue
Block a user