diff --git a/advisories/github-reviewed/2021/05/GHSA-qq5v-f4c3-395c/GHSA-qq5v-f4c3-395c.json b/advisories/github-reviewed/2021/05/GHSA-qq5v-f4c3-395c/GHSA-qq5v-f4c3-395c.json index 8cbdcdc523c..74e8b1480be 100644 --- a/advisories/github-reviewed/2021/05/GHSA-qq5v-f4c3-395c/GHSA-qq5v-f4c3-395c.json +++ b/advisories/github-reviewed/2021/05/GHSA-qq5v-f4c3-395c/GHSA-qq5v-f4c3-395c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qq5v-f4c3-395c", - "modified": "2021-05-21T14:15:41Z", + "modified": "2024-08-07T19:45:51Z", "published": "2021-05-21T14:31:41Z", "aliases": [ "CVE-2021-23347" @@ -58,6 +58,18 @@ { "type": "WEB", "url": "https://github.com/argoproj/argo-cd/security/advisories/GHSA-qq5v-f4c3-395c" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-23347" + }, + { + "type": "WEB", + "url": "https://github.com/argoproj/argo-cd/pull/5563" + }, + { + "type": "WEB", + "url": "https://snyk.io/vuln/SNYK-GOLANG-GITHUBCOMARGOPROJARGOCDCMD-1078291" } ], "database_specific": { diff --git a/advisories/github-reviewed/2022/02/GHSA-63qx-x74g-jcr7/GHSA-63qx-x74g-jcr7.json b/advisories/github-reviewed/2022/02/GHSA-63qx-x74g-jcr7/GHSA-63qx-x74g-jcr7.json index d7d877b5d72..e2ffad211b0 100644 --- a/advisories/github-reviewed/2022/02/GHSA-63qx-x74g-jcr7/GHSA-63qx-x74g-jcr7.json +++ b/advisories/github-reviewed/2022/02/GHSA-63qx-x74g-jcr7/GHSA-63qx-x74g-jcr7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-63qx-x74g-jcr7", - "modified": "2022-02-07T19:06:18Z", + "modified": "2024-08-07T19:46:23Z", "published": "2022-02-07T19:06:18Z", "aliases": [ "CVE-2022-24348" diff --git a/advisories/github-reviewed/2022/03/GHSA-h6h5-6fmq-rh28/GHSA-h6h5-6fmq-rh28.json b/advisories/github-reviewed/2022/03/GHSA-h6h5-6fmq-rh28/GHSA-h6h5-6fmq-rh28.json index abdf0c74112..131abc25c49 100644 --- a/advisories/github-reviewed/2022/03/GHSA-h6h5-6fmq-rh28/GHSA-h6h5-6fmq-rh28.json +++ b/advisories/github-reviewed/2022/03/GHSA-h6h5-6fmq-rh28/GHSA-h6h5-6fmq-rh28.json @@ -89,6 +89,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-209", "CWE-22", "CWE-284" ], diff --git a/advisories/unreviewed/2024/08/GHSA-9m5j-4xx9-44j9/GHSA-9m5j-4xx9-44j9.json b/advisories/github-reviewed/2024/08/GHSA-9m5j-4xx9-44j9/GHSA-9m5j-4xx9-44j9.json similarity index 69% rename from advisories/unreviewed/2024/08/GHSA-9m5j-4xx9-44j9/GHSA-9m5j-4xx9-44j9.json rename to advisories/github-reviewed/2024/08/GHSA-9m5j-4xx9-44j9/GHSA-9m5j-4xx9-44j9.json index ec6aca2afc4..9cef313dacd 100644 --- a/advisories/unreviewed/2024/08/GHSA-9m5j-4xx9-44j9/GHSA-9m5j-4xx9-44j9.json +++ b/advisories/github-reviewed/2024/08/GHSA-9m5j-4xx9-44j9/GHSA-9m5j-4xx9-44j9.json @@ -1,20 +1,43 @@ { "schema_version": "1.4.0", "id": "GHSA-9m5j-4xx9-44j9", - "modified": "2024-08-07T18:30:44Z", + "modified": "2024-08-07T19:45:30Z", "published": "2024-08-07T18:30:44Z", "aliases": [ "CVE-2024-7143" ], + "summary": "Pulp incorrectly assigns RBAC permissions in tasks that create objects", "details": "A flaw was found in the Pulp package. When a role-based access control (RBAC) object in Pulp is set to assign permissions on its creation, it uses the `AutoAddObjPermsMixin` (typically the add_roles_for_object_creator method). This method finds the object creator by checking the current authenticated user. For objects that are created within a task, this current user is set by the first user with any permissions on the task object. This means the oldest user with model/domain-level task permissions will always be set as the current user of a task, even if they didn't dispatch the task. Therefore, all objects created in tasks will have their permissions assigned to this oldest user, and the creating user will receive nothing.", "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N" } ], "affected": [ - + { + "package": { + "ecosystem": "PyPI", + "name": "pulpcore" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "3.56.0" + } + ] + } + ] + } ], "references": [ { @@ -29,6 +52,10 @@ "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2300125" }, + { + "type": "PACKAGE", + "url": "https://github.com/pulp/pulpcore" + }, { "type": "WEB", "url": "https://github.com/pulp/pulpcore/blob/93f241f34c503da0fbac94bdba739feda2636e12/pulpcore/tasking/_util.py#L108" @@ -39,8 +66,8 @@ "CWE-277" ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-08-07T19:45:30Z", "nvd_published_at": "2024-08-07T17:15:52Z" } } \ No newline at end of file