From c4b7629e1f1214feb0836847a82f061601f5d869 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 13 Feb 2025 18:59:16 +0000 Subject: [PATCH] Publish Advisories GHSA-4g42-gqrg-4633 GHSA-7g45-4rm6-3mm3 GHSA-8f6x-v685-g2xc GHSA-xm2m-2q6h-22jw GHSA-9hxf-ppjv-w6rq GHSA-47f6-5gq3-vx9c --- .../2023/06/GHSA-4g42-gqrg-4633/GHSA-4g42-gqrg-4633.json | 4 ++-- .../2023/06/GHSA-7g45-4rm6-3mm3/GHSA-7g45-4rm6-3mm3.json | 4 ++-- .../2023/06/GHSA-8f6x-v685-g2xc/GHSA-8f6x-v685-g2xc.json | 4 ++-- .../2023/06/GHSA-xm2m-2q6h-22jw/GHSA-xm2m-2q6h-22jw.json | 4 ++-- .../2023/07/GHSA-9hxf-ppjv-w6rq/GHSA-9hxf-ppjv-w6rq.json | 4 ++-- .../2024/06/GHSA-47f6-5gq3-vx9c/GHSA-47f6-5gq3-vx9c.json | 4 ++-- 6 files changed, 12 insertions(+), 12 deletions(-) diff --git a/advisories/github-reviewed/2023/06/GHSA-4g42-gqrg-4633/GHSA-4g42-gqrg-4633.json b/advisories/github-reviewed/2023/06/GHSA-4g42-gqrg-4633/GHSA-4g42-gqrg-4633.json index ddecb7dcfd2..7a0d2a1bd1a 100644 --- a/advisories/github-reviewed/2023/06/GHSA-4g42-gqrg-4633/GHSA-4g42-gqrg-4633.json +++ b/advisories/github-reviewed/2023/06/GHSA-4g42-gqrg-4633/GHSA-4g42-gqrg-4633.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-4g42-gqrg-4633", - "modified": "2023-06-21T21:47:38Z", + "modified": "2025-02-13T18:58:22Z", "published": "2023-06-14T09:30:42Z", "aliases": [ "CVE-2023-34396" ], "summary": "Apache Struts vulnerable to memory exhaustion", - "details": "Denial of service via out of memory (OOM) owing to no sanity limit on normal form fields in multipart forms. When a Multipart request has non-file normal form fields, Struts used to bring them into memory as Strings without checking their sizes. This could lead to an OOM if developer has set struts.multipart.maxSize to a value equal or greater than the available memory.\n\nUpgrade to Struts 2.5.31 or 6.1.2.1 or greater\n\n\n", + "details": "Denial of service via out of memory (OOM) owing to no sanity limit on normal form fields in multipart forms. When a Multipart request has non-file normal form fields, Struts used to bring them into memory as Strings without checking their sizes. This could lead to an OOM if developer has set struts.multipart.maxSize to a value equal or greater than the available memory.\n\nUpgrade to Struts 2.5.31 or 6.1.2.1 or greater", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2023/06/GHSA-7g45-4rm6-3mm3/GHSA-7g45-4rm6-3mm3.json b/advisories/github-reviewed/2023/06/GHSA-7g45-4rm6-3mm3/GHSA-7g45-4rm6-3mm3.json index 379a7f5a755..ba916d7cc28 100644 --- a/advisories/github-reviewed/2023/06/GHSA-7g45-4rm6-3mm3/GHSA-7g45-4rm6-3mm3.json +++ b/advisories/github-reviewed/2023/06/GHSA-7g45-4rm6-3mm3/GHSA-7g45-4rm6-3mm3.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-7g45-4rm6-3mm3", - "modified": "2024-02-13T21:48:06Z", + "modified": "2025-02-13T18:58:56Z", "published": "2023-06-14T18:30:38Z", "aliases": [ "CVE-2023-2976" ], "summary": "Guava vulnerable to insecure use of temporary directory", - "details": "Use of Java's default temporary directory for file creation in `FileBackedOutputStream` in Google Guava versions 1.0 to 31.1 on Unix systems and Android Ice Cream Sandwich allows other users and apps on the machine with access to the default Java temporary directory to be able to access the files created by the class.\n\nEven though the security vulnerability is fixed in version 32.0.0, maintainers recommend using version 32.0.1 as version 32.0.0 breaks some functionality under Windows.\n\n", + "details": "Use of Java's default temporary directory for file creation in `FileBackedOutputStream` in Google Guava versions 1.0 to 31.1 on Unix systems and Android Ice Cream Sandwich allows other users and apps on the machine with access to the default Java temporary directory to be able to access the files created by the class.\n\nEven though the security vulnerability is fixed in version 32.0.0, maintainers recommend using version 32.0.1 as version 32.0.0 breaks some functionality under Windows.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2023/06/GHSA-8f6x-v685-g2xc/GHSA-8f6x-v685-g2xc.json b/advisories/github-reviewed/2023/06/GHSA-8f6x-v685-g2xc/GHSA-8f6x-v685-g2xc.json index 282aa0677d8..f736da4160a 100644 --- a/advisories/github-reviewed/2023/06/GHSA-8f6x-v685-g2xc/GHSA-8f6x-v685-g2xc.json +++ b/advisories/github-reviewed/2023/06/GHSA-8f6x-v685-g2xc/GHSA-8f6x-v685-g2xc.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-8f6x-v685-g2xc", - "modified": "2023-06-21T21:47:08Z", + "modified": "2025-02-13T18:58:19Z", "published": "2023-06-14T09:30:42Z", "aliases": [ "CVE-2023-34149" ], "summary": "Apache Struts vulnerable to memory exhaustion", - "details": "Denial of service via out of memory (OOM) owing to not properly checking of list bounds. When a Multipart request has non-file normal form fields, Struts used to bring them into memory as Strings without checking their sizes. This could lead to OOM if developer has set struts.multipart.maxSize to a value equal or greater than the available memory.\n\nUpgrade to Struts 2.5.31 or 6.1.2.1 or greater.\n\n\n", + "details": "Denial of service via out of memory (OOM) owing to not properly checking of list bounds. When a Multipart request has non-file normal form fields, Struts used to bring them into memory as Strings without checking their sizes. This could lead to OOM if developer has set struts.multipart.maxSize to a value equal or greater than the available memory.\n\nUpgrade to Struts 2.5.31 or 6.1.2.1 or greater.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2023/06/GHSA-xm2m-2q6h-22jw/GHSA-xm2m-2q6h-22jw.json b/advisories/github-reviewed/2023/06/GHSA-xm2m-2q6h-22jw/GHSA-xm2m-2q6h-22jw.json index 04230031f77..6cd4644d16f 100644 --- a/advisories/github-reviewed/2023/06/GHSA-xm2m-2q6h-22jw/GHSA-xm2m-2q6h-22jw.json +++ b/advisories/github-reviewed/2023/06/GHSA-xm2m-2q6h-22jw/GHSA-xm2m-2q6h-22jw.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-xm2m-2q6h-22jw", - "modified": "2024-04-12T16:39:23Z", + "modified": "2025-02-13T18:58:07Z", "published": "2023-06-12T18:30:18Z", "aliases": [ "CVE-2023-34468" ], "summary": "Apache NiFi vulnerable to Code Injection", - "details": "The DBCPConnectionPool and HikariCPConnectionPool Controller Services in Apache NiFi 0.0.2 through 1.21.0 allow an authenticated and authorized user to configure a Database URL with the H2 driver that enables custom code execution.\n\nThe resolution validates the Database URL and rejects H2 JDBC locations.\n\nYou are recommended to upgrade to version 1.22.0 or later which fixes this issue.\n\n\n", + "details": "The DBCPConnectionPool and HikariCPConnectionPool Controller Services in Apache NiFi 0.0.2 through 1.21.0 allow an authenticated and authorized user to configure a Database URL with the H2 driver that enables custom code execution.\n\nThe resolution validates the Database URL and rejects H2 JDBC locations.\n\nYou are recommended to upgrade to version 1.22.0 or later which fixes this issue.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2023/07/GHSA-9hxf-ppjv-w6rq/GHSA-9hxf-ppjv-w6rq.json b/advisories/github-reviewed/2023/07/GHSA-9hxf-ppjv-w6rq/GHSA-9hxf-ppjv-w6rq.json index de90c5930aa..fc1783de81b 100644 --- a/advisories/github-reviewed/2023/07/GHSA-9hxf-ppjv-w6rq/GHSA-9hxf-ppjv-w6rq.json +++ b/advisories/github-reviewed/2023/07/GHSA-9hxf-ppjv-w6rq/GHSA-9hxf-ppjv-w6rq.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-9hxf-ppjv-w6rq", - "modified": "2023-07-24T16:55:40Z", + "modified": "2025-02-13T18:58:13Z", "published": "2023-07-06T21:15:08Z", "aliases": [ "CVE-2023-32732" ], "summary": "gRPC connection termination issue", - "details": "gRPC contains a vulnerability whereby a client can cause a termination of connection between a HTTP2 proxy and a gRPC server: a base64 encoding error for `-bin` suffixed headers will result in a disconnection by the gRPC server, but is typically allowed by HTTP2 proxies. We recommend upgrading beyond the commit in https://github.com/grpc/grpc/pull/32309.\n", + "details": "gRPC contains a vulnerability whereby a client can cause a termination of connection between a HTTP2 proxy and a gRPC server: a base64 encoding error for `-bin` suffixed headers will result in a disconnection by the gRPC server, but is typically allowed by HTTP2 proxies. We recommend upgrading beyond the commit in https://github.com/grpc/grpc/pull/32309.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2024/06/GHSA-47f6-5gq3-vx9c/GHSA-47f6-5gq3-vx9c.json b/advisories/github-reviewed/2024/06/GHSA-47f6-5gq3-vx9c/GHSA-47f6-5gq3-vx9c.json index b96be1f34e1..08e12777e66 100644 --- a/advisories/github-reviewed/2024/06/GHSA-47f6-5gq3-vx9c/GHSA-47f6-5gq3-vx9c.json +++ b/advisories/github-reviewed/2024/06/GHSA-47f6-5gq3-vx9c/GHSA-47f6-5gq3-vx9c.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-47f6-5gq3-vx9c", - "modified": "2024-06-20T09:30:58Z", + "modified": "2025-02-13T18:58:20Z", "published": "2024-06-10T21:36:32Z", "aliases": [ "CVE-2024-35241" ], "summary": "Composer has a command injection via malicious git branch name", - "details": "### Impact\n\nThe `status`, `reinstall` and `remove` commands with packages installed from source via git containing specially crafted branch names in the repository can be used to execute code.\n\n### Patches\n\n2.2.24 for 2.2 LTS or 2.7.7 for mainline\n\n### Workarounds\n\nAvoid installing dependencies via git by using `--prefer-dist` or the `preferred-install: dist` config setting.\n", + "details": "### Impact\n\nThe `status`, `reinstall` and `remove` commands with packages installed from source via git containing specially crafted branch names in the repository can be used to execute code.\n\n### Patches\n\n2.2.24 for 2.2 LTS or 2.7.7 for mainline\n\n### Workarounds\n\nAvoid installing dependencies via git by using `--prefer-dist` or the `preferred-install: dist` config setting.", "severity": [ { "type": "CVSS_V3",