Publish Advisories

GHSA-22fx-6r9m-r8h9
GHSA-x3cq-8f32-5f63
GHSA-2mqw-rq5m-8hc8
GHSA-2vpq-fh52-j3wv
GHSA-hcr5-wv4p-h2g2
GHSA-m4f6-vcj4-w5mx
GHSA-r2x6-cjg7-8r43
This commit is contained in:
advisory-database[bot]
2025-01-29 22:01:13 +00:00
parent 8e077ab32b
commit dd9bbb3e72
7 changed files with 67 additions and 13 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-22fx-6r9m-r8h9",
"modified": "2023-06-02T21:18:04Z",
"modified": "2025-01-29T22:00:08Z",
"published": "2023-05-05T18:30:17Z",
"aliases": [
"CVE-2023-29659"
@@ -48,6 +48,14 @@
"type": "WEB",
"url": "https://github.com/strukturag/libheif/commit/e05e15b57a38ec411cb9acb38512a1c36ff62991"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CKAE6NQBA3Q7GS6VTNDZRZZZVPPEFUEZ"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LGKHDCS4HRZE3UGXYYDYPTIPNIBRLQ5L"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CKAE6NQBA3Q7GS6VTNDZRZZZVPPEFUEZ"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x3cq-8f32-5f63",
"modified": "2025-01-23T22:26:19Z",
"modified": "2025-01-29T22:00:17Z",
"published": "2023-07-06T21:15:04Z",
"aliases": [
"CVE-2023-33246"
@@ -105,10 +105,18 @@
"type": "WEB",
"url": "https://github.com/apache/rocketmq/commit/c3ada731405c5990c36bf58d50b3e61965300703"
},
{
"type": "WEB",
"url": "https://github.com/Malayke/CVE-2023-33246_RocketMQ_RCE_EXPLOIT"
},
{
"type": "PACKAGE",
"url": "https://github.com/apache/rocketmq"
},
{
"type": "WEB",
"url": "https://github.com/jakabakos/CVE-2023-33246_Apache_RocketMQ_RCE"
},
{
"type": "WEB",
"url": "https://lists.apache.org/thread/1s8j2c8kogthtpv3060yddk03zq0pxyp"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2mqw-rq5m-8hc8",
"modified": "2025-01-29T20:50:56Z",
"modified": "2025-01-29T22:00:22Z",
"published": "2025-01-29T20:50:55Z",
"aliases": [
"CVE-2025-24788"
@@ -43,6 +43,10 @@
"type": "WEB",
"url": "https://github.com/snowflakedb/snowflake-connector-net/security/advisories/GHSA-2mqw-rq5m-8hc8"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24788"
},
{
"type": "WEB",
"url": "https://github.com/snowflakedb/snowflake-connector-net/commit/89d91e8316ca213c5d184bcf469ed93977a5edf9"
@@ -59,6 +63,6 @@
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2025-01-29T20:50:55Z",
"nvd_published_at": null
"nvd_published_at": "2025-01-29T21:15:21Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2vpq-fh52-j3wv",
"modified": "2025-01-29T20:50:33Z",
"modified": "2025-01-29T22:00:26Z",
"published": "2025-01-29T20:50:33Z",
"aliases": [
"CVE-2025-24793"
@@ -43,6 +43,14 @@
"type": "WEB",
"url": "https://github.com/snowflakedb/snowflake-connector-python/security/advisories/GHSA-2vpq-fh52-j3wv"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24793"
},
{
"type": "WEB",
"url": "https://github.com/snowflakedb/snowflake-connector-python/commit/f3f9b666518d29c31a49384bbaa9a65889e72056"
},
{
"type": "PACKAGE",
"url": "https://github.com/snowflakedb/snowflake-connector-python"
@@ -59,6 +67,6 @@
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2025-01-29T20:50:33Z",
"nvd_published_at": null
"nvd_published_at": "2025-01-29T21:15:21Z"
}
}
@@ -1,14 +1,19 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hcr5-wv4p-h2g2",
"modified": "2025-01-29T20:47:51Z",
"modified": "2025-01-29T22:00:39Z",
"published": "2025-01-29T20:47:51Z",
"aliases": [
"CVE-2025-24884"
],
"summary": "kube-audit-rest's example logging configuration could disclose secret values in the audit log",
"details": "### Impact\nIf the \"full-elastic-stack\" example vector configuration was used for a real cluster, the previous values of kubernetes secrets would have been disclosed in the audit messages.\n\n### Patches\nThe example has been updated to fix this in commit db1aa5b867256b0a7bf206544c6981ab068b73dc\n\n\n### Workarounds\nReplace \n```yaml\n\n if .request.requestKind.kind == \"Secret\" {\n del(.request.object.data)\n .request.object.data.redacted = \"REDACTED\"\n del(.request.oldObject.data)\n .request.oldObject.data.redacted = \"REDACTED\"\n }\n```\nIn the vector \"audit-files-json-parser-and-redaction\" step\nwith\n```yaml\n\n if .request.requestKind.kind == \"Secret\" {\n # Redact the secret data\n del(.request.object.data)\n .request.object.data.redacted = \"REDACTED\"\n del(.request.oldObject.data)\n .request.oldObject.data.redacted = \"REDACTED\"\n # Remove the previously set secret data - Not bothering to parse it as this annotation shouldn't ever be needed\n del(.request.object.metadata.annotations.[\"kubectl.kubernetes.io/last-applied-configuration\"])\n del(.request.oldObject.metadata.annotations.[\"kubectl.kubernetes.io/last-applied-configuration\"])\n }\n```",
"severity": [],
"severity": [
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [
{
"package": {
@@ -35,6 +40,10 @@
"type": "WEB",
"url": "https://github.com/RichardoC/kube-audit-rest/security/advisories/GHSA-hcr5-wv4p-h2g2"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24884"
},
{
"type": "WEB",
"url": "https://github.com/RichardoC/kube-audit-rest/commit/db1aa5b867256b0a7bf206544c6981ab068b73dc"
@@ -46,11 +55,12 @@
],
"database_specific": {
"cwe_ids": [
"CWE-200",
"CWE-532"
],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2025-01-29T20:47:51Z",
"nvd_published_at": null
"nvd_published_at": "2025-01-29T21:15:21Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m4f6-vcj4-w5mx",
"modified": "2025-01-29T20:50:18Z",
"modified": "2025-01-29T22:00:31Z",
"published": "2025-01-29T20:50:18Z",
"aliases": [
"CVE-2025-24794"
@@ -43,6 +43,14 @@
"type": "WEB",
"url": "https://github.com/snowflakedb/snowflake-connector-python/security/advisories/GHSA-m4f6-vcj4-w5mx"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24794"
},
{
"type": "WEB",
"url": "https://github.com/snowflakedb/snowflake-connector-python/commit/3769b43822357c3874c40f5e74068458c2dc79af"
},
{
"type": "PACKAGE",
"url": "https://github.com/snowflakedb/snowflake-connector-python"
@@ -59,6 +67,6 @@
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2025-01-29T20:50:18Z",
"nvd_published_at": null
"nvd_published_at": "2025-01-29T21:15:21Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r2x6-cjg7-8r43",
"modified": "2025-01-29T20:49:59Z",
"modified": "2025-01-29T22:00:35Z",
"published": "2025-01-29T20:49:59Z",
"aliases": [
"CVE-2025-24795"
@@ -43,6 +43,14 @@
"type": "WEB",
"url": "https://github.com/snowflakedb/snowflake-connector-python/security/advisories/GHSA-r2x6-cjg7-8r43"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24795"
},
{
"type": "WEB",
"url": "https://github.com/snowflakedb/snowflake-connector-python/commit/3769b43822357c3874c40f5e74068458c2dc79af"
},
{
"type": "PACKAGE",
"url": "https://github.com/snowflakedb/snowflake-connector-python"
@@ -59,6 +67,6 @@
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2025-01-29T20:49:59Z",
"nvd_published_at": null
"nvd_published_at": "2025-01-29T21:15:21Z"
}
}