Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2024-01-05 15:31:03 +00:00
parent 6de762260f
commit c7d1823387
35 changed files with 283 additions and 102 deletions
@@ -1,10 +1,10 @@
{
"schema_version": "1.4.0",
"id": "GHSA-85rf-xh54-whp3",
"modified": "2021-08-25T21:02:38Z",
"modified": "2024-01-05T15:29:09Z",
"published": "2019-10-07T16:52:13Z",
"aliases": [
"CVE-2024-22050"
],
"summary": "Malicious URL drafting attack against iodines static file server may allow path traversal",
"details": "### Impact\n\nA path traversal vulnerability was detected in iodine's static file service. This vulnerability effects any application running iodine's static file server on an effected iodine version.\n\nMalicious URL drafting may cause the static file server to attempt a response containing data from files that shouldn't be normally accessible from the public folder.\n\n### Patches\n\nThe vulnerability was patched in version 0.7.34. Please upgrade to the latest version.\n\n### Workarounds\n\nA possible workaround would be to disable the static file service and it's `X-Sendfile` support, sending static files using nginx or a source code solution (sending the data dynamically).\n\nHowever, it would be better to upgrade iodine to the latest version, as it also contains non-security related fixes.\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Email [Boaz Segev](https://github.com/boazsegev)",
@@ -40,6 +40,10 @@
"type": "WEB",
"url": "https://github.com/boazsegev/iodine/security/advisories/GHSA-85rf-xh54-whp3"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22050"
},
{
"type": "WEB",
"url": "https://github.com/boazsegev/iodine/commit/5558233fb7defda706b4f9c87c17759705949889"
@@ -43,6 +43,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-36888"
},
{
"type": "WEB",
"url": "https://github.com/jenkinsci/hashicorp-vault-plugin/commit/3b38d767aba8bd98d6f4fb53c1f1678d95b5e752"
},
{
"type": "PACKAGE",
"url": "https://github.com/jenkinsci/hashicorp-vault-plugin"
@@ -43,6 +43,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-45385"
},
{
"type": "WEB",
"url": "https://github.com/jenkinsci/dockerhub-notification-plugin/commit/1163d4f297af23266c032fc66bd603b97f9ecd4b"
},
{
"type": "PACKAGE",
"url": "https://github.com/jenkinsci/dockerhub-notification-plugin"
@@ -0,0 +1,67 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qwf7-rv77-fcr3",
"modified": "2024-01-05T15:28:54Z",
"published": "2024-01-04T21:30:24Z",
"withdrawn": "2024-01-05T15:28:54Z",
"aliases": [
],
"summary": "Duplicate Advisory: Malicious URL drafting attack against iodines static file server may allow path traversal",
"details": "### Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-85rf-xh54-whp3. This link is maintained to preserve external references.\n\n### Original Description\nPath traversal in the static file service in Iodine less than 0.7.33 allows an unauthenticated, remote attacker to read files outside the public folder via malicious URLs.\n\n",
"severity": [
],
"affected": [
{
"package": {
"ecosystem": "RubyGems",
"name": "iodine"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
}
]
}
],
"database_specific": {
"last_known_affected_version_range": "< 0.7.33"
}
}
],
"references": [
{
"type": "WEB",
"url": "https://github.com/boazsegev/iodine/security/advisories/GHSA-85rf-xh54-whp3"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22050"
},
{
"type": "WEB",
"url": "https://github.com/boazsegev/iodine/commit/5558233fb7defda706b4f9c87c17759705949889"
},
{
"type": "ADVISORY",
"url": "https://github.com/advisories/GHSA-85rf-xh54-whp3"
},
{
"type": "WEB",
"url": "https://vulncheck.com/advisories/vc-advisory-GHSA-85rf-xh54-whp3"
}
],
"database_specific": {
"cwe_ids": [
"CWE-22"
],
"severity": "LOW",
"github_reviewed": true,
"github_reviewed_at": "2024-01-05T15:28:54Z",
"nvd_published_at": "2024-01-04T21:15:10Z"
}
}
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h54q-fpvg-vhq5",
"modified": "2021-11-25T00:00:45Z",
"modified": "2024-01-05T15:30:23Z",
"published": "2021-11-24T00:00:41Z",
"aliases": [
"CVE-2021-24830"
],
"details": "The Advanced Access Manager WordPress plugin before 6.8.0 does not escape some of its settings when outputting them, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6v5w-2xvc-ghhh",
"modified": "2022-05-24T17:37:50Z",
"modified": "2024-01-05T15:30:22Z",
"published": "2022-05-24T17:37:50Z",
"aliases": [
"CVE-2020-35935"
],
"details": "The Advanced Access Manager plugin before 6.6.2 for WordPress allows privilege escalation on profile updates via the aam_user_roles POST parameter if Multiple Role support is enabled. (The mechanism for deciding whether a user was entitled to add a role did not work in various custom-role scenarios.)",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7q52-2r47-35qw",
"modified": "2022-05-24T17:37:49Z",
"modified": "2024-01-05T15:30:22Z",
"published": "2022-05-24T17:37:49Z",
"aliases": [
"CVE-2020-35934"
],
"details": "The Advanced Access Manager plugin before 6.6.2 for WordPress displays the unfiltered user object (including all metadata) upon login via the REST API (aam/v1/authenticate or aam/v2/authenticate). This is a security problem if this object stores information that the user is not supposed to have (e.g., custom metadata added by a different plugin).",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [
@@ -25,6 +28,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-200",
"CWE-732"
],
"severity": "MODERATE",
@@ -1,14 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p367-375f-q2f8",
"modified": "2022-05-17T19:57:16Z",
"modified": "2024-01-05T15:30:21Z",
"published": "2022-05-17T19:57:16Z",
"aliases": [
"CVE-2014-6059"
],
"details": "WordPress Advanced Access Manager Plugin before 2.8.2 has an Arbitrary File Overwrite Vulnerability",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3x5r-c923-f923",
"modified": "2023-06-27T15:30:28Z",
"modified": "2024-01-05T15:30:23Z",
"published": "2023-06-23T18:30:24Z",
"aliases": [
"CVE-2023-32373"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32373"
},
{
"type": "WEB",
"url": "https://security.gentoo.org/glsa/202401-04"
},
{
"type": "WEB",
"url": "https://support.apple.com/en-us/HT213757"
@@ -50,7 +54,7 @@
"cwe_ids": [
"CWE-416"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-06-23T18:15:12Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m85j-wjrj-c4rg",
"modified": "2023-06-30T09:30:19Z",
"modified": "2024-01-05T15:30:23Z",
"published": "2023-06-23T18:30:23Z",
"aliases": [
"CVE-2023-28204"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28204"
},
{
"type": "WEB",
"url": "https://security.gentoo.org/glsa/202401-04"
},
{
"type": "WEB",
"url": "https://support.apple.com/en-us/HT213757"
@@ -50,7 +54,7 @@
"cwe_ids": [
"CWE-125"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-06-23T18:15:11Z"
@@ -29,6 +29,10 @@
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DF2RESDBALYFDF6OEJDUYFSN7XJADFRD/"
},
{
"type": "WEB",
"url": "https://security.gentoo.org/glsa/202401-04"
},
{
"type": "WEB",
"url": "https://support.apple.com/en-us/HT213811"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-57gp-c4c9-4j3c",
"modified": "2023-08-02T03:30:20Z",
"modified": "2024-01-05T15:30:23Z",
"published": "2023-07-27T00:30:57Z",
"aliases": [
"CVE-2023-38133"
@@ -29,6 +29,10 @@
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KQXJYKTGLKI6TJEFJCKPHCNY7PS72OER/"
},
{
"type": "WEB",
"url": "https://security.gentoo.org/glsa/202401-04"
},
{
"type": "WEB",
"url": "https://support.apple.com/en-us/HT213841"
@@ -66,7 +70,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-07-27T00:15:15Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-959x-mqwc-q2fp",
"modified": "2023-08-03T18:30:29Z",
"modified": "2024-01-05T15:30:23Z",
"published": "2023-07-28T06:30:39Z",
"aliases": [
"CVE-2023-38592"
@@ -29,6 +29,10 @@
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KQXJYKTGLKI6TJEFJCKPHCNY7PS72OER/"
},
{
"type": "WEB",
"url": "https://security.gentoo.org/glsa/202401-04"
},
{
"type": "WEB",
"url": "https://support.apple.com/en-us/HT213841"
@@ -58,7 +62,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-07-28T05:15:10Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9hxv-f7q5-4j7c",
"modified": "2023-08-01T21:30:42Z",
"modified": "2024-01-05T15:30:23Z",
"published": "2023-07-27T03:30:28Z",
"aliases": [
"CVE-2023-32393"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-32393"
},
{
"type": "WEB",
"url": "https://security.gentoo.org/glsa/202401-04"
},
{
"type": "WEB",
"url": "https://support.apple.com/en-us/HT213599"
@@ -42,7 +46,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-07-27T01:15:23Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c9g8-3cc3-422m",
"modified": "2023-08-03T18:30:29Z",
"modified": "2024-01-05T15:30:23Z",
"published": "2023-07-28T06:30:39Z",
"aliases": [
"CVE-2023-38599"
@@ -29,6 +29,10 @@
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KQXJYKTGLKI6TJEFJCKPHCNY7PS72OER/"
},
{
"type": "WEB",
"url": "https://security.gentoo.org/glsa/202401-04"
},
{
"type": "WEB",
"url": "https://support.apple.com/en-us/HT213841"
@@ -66,7 +70,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-07-28T05:15:10Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p785-479c-32q6",
"modified": "2023-08-03T00:30:15Z",
"modified": "2024-01-05T15:30:23Z",
"published": "2023-07-27T03:30:29Z",
"aliases": [
"CVE-2023-38600"
@@ -29,6 +29,10 @@
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KQXJYKTGLKI6TJEFJCKPHCNY7PS72OER/"
},
{
"type": "WEB",
"url": "https://security.gentoo.org/glsa/202401-04"
},
{
"type": "WEB",
"url": "https://support.apple.com/en-us/HT213841"
@@ -62,7 +66,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-07-27T01:15:38Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pxp9-4fx7-v479",
"modified": "2023-08-03T00:30:15Z",
"modified": "2024-01-05T15:30:23Z",
"published": "2023-07-27T03:30:29Z",
"aliases": [
"CVE-2023-38611"
@@ -29,6 +29,10 @@
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KQXJYKTGLKI6TJEFJCKPHCNY7PS72OER/"
},
{
"type": "WEB",
"url": "https://security.gentoo.org/glsa/202401-04"
},
{
"type": "WEB",
"url": "https://support.apple.com/en-us/HT213841"
@@ -62,7 +66,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-07-27T01:15:39Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qfg5-2446-wqxx",
"modified": "2023-08-03T21:30:44Z",
"modified": "2024-01-05T15:30:23Z",
"published": "2023-07-27T03:30:29Z",
"aliases": [
"CVE-2023-38572"
@@ -29,6 +29,10 @@
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KQXJYKTGLKI6TJEFJCKPHCNY7PS72OER/"
},
{
"type": "WEB",
"url": "https://security.gentoo.org/glsa/202401-04"
},
{
"type": "WEB",
"url": "https://support.apple.com/en-us/HT213841"
@@ -66,7 +70,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-07-27T01:15:36Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rv3f-cww5-rv8r",
"modified": "2023-08-01T21:30:42Z",
"modified": "2024-01-05T15:30:23Z",
"published": "2023-07-27T00:30:57Z",
"aliases": [
"CVE-2023-38594"
@@ -29,6 +29,10 @@
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KQXJYKTGLKI6TJEFJCKPHCNY7PS72OER/"
},
{
"type": "WEB",
"url": "https://security.gentoo.org/glsa/202401-04"
},
{
"type": "WEB",
"url": "https://support.apple.com/en-us/HT213841"
@@ -66,7 +70,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-07-27T00:15:15Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v874-wp44-mhr4",
"modified": "2023-08-02T03:30:20Z",
"modified": "2024-01-05T15:30:23Z",
"published": "2023-07-27T00:30:57Z",
"aliases": [
"CVE-2023-37450"
@@ -21,6 +21,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37450"
},
{
"type": "WEB",
"url": "https://security.gentoo.org/glsa/202401-04"
},
{
"type": "WEB",
"url": "https://support.apple.com/en-us/HT213826"
@@ -46,7 +50,7 @@
"cwe_ids": [
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-07-27T00:15:15Z"

Some files were not shown because too many files have changed in this diff Show More