Publish Advisories

GHSA-8qhm-ch8h-xgjr
GHSA-2h5h-59f5-c5x9
GHSA-jmp2-wc4p-wfh2
GHSA-mgv8-gggw-mrg6
This commit is contained in:
advisory-database[bot]
2023-05-09 16:41:27 +00:00
parent fc60182f9d
commit cfe3e80cb8
4 changed files with 45 additions and 12 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8qhm-ch8h-xgjr",
"modified": "2023-04-27T23:51:52Z",
"modified": "2023-05-09T16:41:02Z",
"published": "2023-04-27T15:30:44Z",
"aliases": [
"CVE-2023-30349"
@@ -9,7 +9,10 @@
"summary": "Remote code execution in JFinal CMS",
"details": "JFinal CMS v5.1.0 was discovered to contain a remote code execution (RCE) vulnerability via the ActionEnter function.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
{
@@ -50,7 +53,7 @@
"cwe_ids": [
],
"severity": "HIGH",
"severity": "CRITICAL",
"github_reviewed": true,
"github_reviewed_at": "2023-04-27T23:51:52Z",
"nvd_published_at": null
File diff suppressed because one or more lines are too long
@@ -78,14 +78,26 @@
"type": "WEB",
"url": "https://github.com/mutagen-io/mutagen/security/advisories/GHSA-jmp2-wc4p-wfh2"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30844"
},
{
"type": "PACKAGE",
"url": "https://github.com/mutagen-io/mutagen"
},
{
"type": "WEB",
"url": "https://github.com/mutagen-io/mutagen/releases/tag/v0.16.6"
},
{
"type": "WEB",
"url": "https://github.com/mutagen-io/mutagen/releases/tag/v0.17.1"
}
],
"database_specific": {
"cwe_ids": [
"CWE-150"
],
"severity": "LOW",
"github_reviewed": true,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mgv8-gggw-mrg6",
"modified": "2023-05-05T22:22:23Z",
"modified": "2023-05-09T16:39:40Z",
"published": "2023-05-05T22:22:23Z",
"aliases": [
"CVE-2023-30837"
@@ -9,7 +9,10 @@
"summary": "vyper vulnerable to storage allocator overflow",
"details": "### Impact\nThe storage allocator does not guard against allocation overflows. This can result in vulnerabilities like the following:\n```vyper\nowner: public(address)\ntake_up_some_space: public(uint256[10])\nbuffer: public(uint256[max_value(uint256)])\n\n@external\ndef initialize():\n self.owner = msg.sender\n\n@external\ndef foo(idx: uint256, data: uint256):\n self.buffer[idx] = data\n```\nPer @toonvanhove, \"An attacker can overwrite the owner variable by calling this contract with calldata: `0x04bc52f8 fffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff5 ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff` (spaces inserted for readability)\n`0x04bc52f8` is the selector for `foo(uint256, uint256)`, and the last argument `fff...fff` is the new value for the owner variable.\"",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
}
],
"affected": [
{
@@ -37,6 +40,14 @@
"type": "WEB",
"url": "https://github.com/vyperlang/vyper/security/advisories/GHSA-mgv8-gggw-mrg6"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-30837"
},
{
"type": "WEB",
"url": "https://github.com/vyperlang/vyper/commit/0bb7203b584e771b23536ba065a6efda457161bb"
},
{
"type": "PACKAGE",
"url": "https://github.com/vyperlang/vyper"
@@ -44,9 +55,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-789"
],
"severity": "MODERATE",
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2023-05-05T22:22:23Z",
"nvd_published_at": null