mirror of
https://github.com/netbirdio/advisory-database.git
synced 2026-05-22 18:04:22 -07:00
Publish Advisories
GHSA-qq5v-f4c3-395c GHSA-63qx-x74g-jcr7 GHSA-h6h5-6fmq-rh28 GHSA-9m5j-4xx9-44j9
This commit is contained in:
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-qq5v-f4c3-395c",
|
||||
"modified": "2021-05-21T14:15:41Z",
|
||||
"modified": "2024-08-07T19:45:51Z",
|
||||
"published": "2021-05-21T14:31:41Z",
|
||||
"aliases": [
|
||||
"CVE-2021-23347"
|
||||
@@ -58,6 +58,18 @@
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/argoproj/argo-cd/security/advisories/GHSA-qq5v-f4c3-395c"
|
||||
},
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-23347"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/argoproj/argo-cd/pull/5563"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://snyk.io/vuln/SNYK-GOLANG-GITHUBCOMARGOPROJARGOCDCMD-1078291"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-63qx-x74g-jcr7",
|
||||
"modified": "2022-02-07T19:06:18Z",
|
||||
"modified": "2024-08-07T19:46:23Z",
|
||||
"published": "2022-02-07T19:06:18Z",
|
||||
"aliases": [
|
||||
"CVE-2022-24348"
|
||||
|
||||
@@ -89,6 +89,7 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-209",
|
||||
"CWE-22",
|
||||
"CWE-284"
|
||||
],
|
||||
|
||||
+31
-4
@@ -1,20 +1,43 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-9m5j-4xx9-44j9",
|
||||
"modified": "2024-08-07T18:30:44Z",
|
||||
"modified": "2024-08-07T19:45:30Z",
|
||||
"published": "2024-08-07T18:30:44Z",
|
||||
"aliases": [
|
||||
"CVE-2024-7143"
|
||||
],
|
||||
"summary": "Pulp incorrectly assigns RBAC permissions in tasks that create objects",
|
||||
"details": "A flaw was found in the Pulp package. When a role-based access control (RBAC) object in Pulp is set to assign permissions on its creation, it uses the `AutoAddObjPermsMixin` (typically the add_roles_for_object_creator method). This method finds the object creator by checking the current authenticated user. For objects that are created within a task, this current user is set by the first user with any permissions on the task object. This means the oldest user with model/domain-level task permissions will always be set as the current user of a task, even if they didn't dispatch the task. Therefore, all objects created in tasks will have their permissions assigned to this oldest user, and the creating user will receive nothing.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L"
|
||||
},
|
||||
{
|
||||
"type": "CVSS_V4",
|
||||
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
|
||||
{
|
||||
"package": {
|
||||
"ecosystem": "PyPI",
|
||||
"name": "pulpcore"
|
||||
},
|
||||
"ranges": [
|
||||
{
|
||||
"type": "ECOSYSTEM",
|
||||
"events": [
|
||||
{
|
||||
"introduced": "0"
|
||||
},
|
||||
{
|
||||
"last_affected": "3.56.0"
|
||||
}
|
||||
]
|
||||
}
|
||||
]
|
||||
}
|
||||
],
|
||||
"references": [
|
||||
{
|
||||
@@ -29,6 +52,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2300125"
|
||||
},
|
||||
{
|
||||
"type": "PACKAGE",
|
||||
"url": "https://github.com/pulp/pulpcore"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/pulp/pulpcore/blob/93f241f34c503da0fbac94bdba739feda2636e12/pulpcore/tasking/_util.py#L108"
|
||||
@@ -39,8 +66,8 @@
|
||||
"CWE-277"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"github_reviewed": true,
|
||||
"github_reviewed_at": "2024-08-07T19:45:30Z",
|
||||
"nvd_published_at": "2024-08-07T17:15:52Z"
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user