Publish Advisories

GHSA-qq5v-f4c3-395c
GHSA-63qx-x74g-jcr7
GHSA-h6h5-6fmq-rh28
GHSA-9m5j-4xx9-44j9
This commit is contained in:
advisory-database[bot]
2024-08-07 19:48:03 +00:00
parent 515ded3fb1
commit ccd22b43f8
4 changed files with 46 additions and 6 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qq5v-f4c3-395c",
"modified": "2021-05-21T14:15:41Z",
"modified": "2024-08-07T19:45:51Z",
"published": "2021-05-21T14:31:41Z",
"aliases": [
"CVE-2021-23347"
@@ -58,6 +58,18 @@
{
"type": "WEB",
"url": "https://github.com/argoproj/argo-cd/security/advisories/GHSA-qq5v-f4c3-395c"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-23347"
},
{
"type": "WEB",
"url": "https://github.com/argoproj/argo-cd/pull/5563"
},
{
"type": "WEB",
"url": "https://snyk.io/vuln/SNYK-GOLANG-GITHUBCOMARGOPROJARGOCDCMD-1078291"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-63qx-x74g-jcr7",
"modified": "2022-02-07T19:06:18Z",
"modified": "2024-08-07T19:46:23Z",
"published": "2022-02-07T19:06:18Z",
"aliases": [
"CVE-2022-24348"
@@ -89,6 +89,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-209",
"CWE-22",
"CWE-284"
],
@@ -1,20 +1,43 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9m5j-4xx9-44j9",
"modified": "2024-08-07T18:30:44Z",
"modified": "2024-08-07T19:45:30Z",
"published": "2024-08-07T18:30:44Z",
"aliases": [
"CVE-2024-7143"
],
"summary": "Pulp incorrectly assigns RBAC permissions in tasks that create objects",
"details": "A flaw was found in the Pulp package. When a role-based access control (RBAC) object in Pulp is set to assign permissions on its creation, it uses the `AutoAddObjPermsMixin` (typically the add_roles_for_object_creator method). This method finds the object creator by checking the current authenticated user. For objects that are created within a task, this current user is set by the first user with any permissions on the task object. This means the oldest user with model/domain-level task permissions will always be set as the current user of a task, even if they didn't dispatch the task. Therefore, all objects created in tasks will have their permissions assigned to this oldest user, and the creating user will receive nothing.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N"
}
],
"affected": [
{
"package": {
"ecosystem": "PyPI",
"name": "pulpcore"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"last_affected": "3.56.0"
}
]
}
]
}
],
"references": [
{
@@ -29,6 +52,10 @@
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2300125"
},
{
"type": "PACKAGE",
"url": "https://github.com/pulp/pulpcore"
},
{
"type": "WEB",
"url": "https://github.com/pulp/pulpcore/blob/93f241f34c503da0fbac94bdba739feda2636e12/pulpcore/tasking/_util.py#L108"
@@ -39,8 +66,8 @@
"CWE-277"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"github_reviewed": true,
"github_reviewed_at": "2024-08-07T19:45:30Z",
"nvd_published_at": "2024-08-07T17:15:52Z"
}
}