mirror of
https://github.com/netbirdio/advisory-database.git
synced 2026-05-22 18:04:22 -07:00
Publish Advisories
GHSA-22fx-6r9m-r8h9 GHSA-x3cq-8f32-5f63 GHSA-2mqw-rq5m-8hc8 GHSA-2vpq-fh52-j3wv GHSA-hcr5-wv4p-h2g2 GHSA-m4f6-vcj4-w5mx GHSA-r2x6-cjg7-8r43
This commit is contained in:
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-22fx-6r9m-r8h9",
|
||||
"modified": "2023-06-02T21:18:04Z",
|
||||
"modified": "2025-01-29T22:00:08Z",
|
||||
"published": "2023-05-05T18:30:17Z",
|
||||
"aliases": [
|
||||
"CVE-2023-29659"
|
||||
@@ -48,6 +48,14 @@
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/strukturag/libheif/commit/e05e15b57a38ec411cb9acb38512a1c36ff62991"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CKAE6NQBA3Q7GS6VTNDZRZZZVPPEFUEZ"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LGKHDCS4HRZE3UGXYYDYPTIPNIBRLQ5L"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CKAE6NQBA3Q7GS6VTNDZRZZZVPPEFUEZ"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-x3cq-8f32-5f63",
|
||||
"modified": "2025-01-23T22:26:19Z",
|
||||
"modified": "2025-01-29T22:00:17Z",
|
||||
"published": "2023-07-06T21:15:04Z",
|
||||
"aliases": [
|
||||
"CVE-2023-33246"
|
||||
@@ -105,10 +105,18 @@
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/apache/rocketmq/commit/c3ada731405c5990c36bf58d50b3e61965300703"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/Malayke/CVE-2023-33246_RocketMQ_RCE_EXPLOIT"
|
||||
},
|
||||
{
|
||||
"type": "PACKAGE",
|
||||
"url": "https://github.com/apache/rocketmq"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/jakabakos/CVE-2023-33246_Apache_RocketMQ_RCE"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://lists.apache.org/thread/1s8j2c8kogthtpv3060yddk03zq0pxyp"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-2mqw-rq5m-8hc8",
|
||||
"modified": "2025-01-29T20:50:56Z",
|
||||
"modified": "2025-01-29T22:00:22Z",
|
||||
"published": "2025-01-29T20:50:55Z",
|
||||
"aliases": [
|
||||
"CVE-2025-24788"
|
||||
@@ -43,6 +43,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/snowflakedb/snowflake-connector-net/security/advisories/GHSA-2mqw-rq5m-8hc8"
|
||||
},
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24788"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/snowflakedb/snowflake-connector-net/commit/89d91e8316ca213c5d184bcf469ed93977a5edf9"
|
||||
@@ -59,6 +63,6 @@
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": true,
|
||||
"github_reviewed_at": "2025-01-29T20:50:55Z",
|
||||
"nvd_published_at": null
|
||||
"nvd_published_at": "2025-01-29T21:15:21Z"
|
||||
}
|
||||
}
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-2vpq-fh52-j3wv",
|
||||
"modified": "2025-01-29T20:50:33Z",
|
||||
"modified": "2025-01-29T22:00:26Z",
|
||||
"published": "2025-01-29T20:50:33Z",
|
||||
"aliases": [
|
||||
"CVE-2025-24793"
|
||||
@@ -43,6 +43,14 @@
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/snowflakedb/snowflake-connector-python/security/advisories/GHSA-2vpq-fh52-j3wv"
|
||||
},
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24793"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/snowflakedb/snowflake-connector-python/commit/f3f9b666518d29c31a49384bbaa9a65889e72056"
|
||||
},
|
||||
{
|
||||
"type": "PACKAGE",
|
||||
"url": "https://github.com/snowflakedb/snowflake-connector-python"
|
||||
@@ -59,6 +67,6 @@
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": true,
|
||||
"github_reviewed_at": "2025-01-29T20:50:33Z",
|
||||
"nvd_published_at": null
|
||||
"nvd_published_at": "2025-01-29T21:15:21Z"
|
||||
}
|
||||
}
|
||||
@@ -1,14 +1,19 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-hcr5-wv4p-h2g2",
|
||||
"modified": "2025-01-29T20:47:51Z",
|
||||
"modified": "2025-01-29T22:00:39Z",
|
||||
"published": "2025-01-29T20:47:51Z",
|
||||
"aliases": [
|
||||
"CVE-2025-24884"
|
||||
],
|
||||
"summary": "kube-audit-rest's example logging configuration could disclose secret values in the audit log",
|
||||
"details": "### Impact\nIf the \"full-elastic-stack\" example vector configuration was used for a real cluster, the previous values of kubernetes secrets would have been disclosed in the audit messages.\n\n### Patches\nThe example has been updated to fix this in commit db1aa5b867256b0a7bf206544c6981ab068b73dc\n\n\n### Workarounds\nReplace \n```yaml\n\n if .request.requestKind.kind == \"Secret\" {\n del(.request.object.data)\n .request.object.data.redacted = \"REDACTED\"\n del(.request.oldObject.data)\n .request.oldObject.data.redacted = \"REDACTED\"\n }\n```\nIn the vector \"audit-files-json-parser-and-redaction\" step\nwith\n```yaml\n\n if .request.requestKind.kind == \"Secret\" {\n # Redact the secret data\n del(.request.object.data)\n .request.object.data.redacted = \"REDACTED\"\n del(.request.oldObject.data)\n .request.oldObject.data.redacted = \"REDACTED\"\n # Remove the previously set secret data - Not bothering to parse it as this annotation shouldn't ever be needed\n del(.request.object.metadata.annotations.[\"kubectl.kubernetes.io/last-applied-configuration\"])\n del(.request.oldObject.metadata.annotations.[\"kubectl.kubernetes.io/last-applied-configuration\"])\n }\n```",
|
||||
"severity": [],
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V4",
|
||||
"score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
{
|
||||
"package": {
|
||||
@@ -35,6 +40,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/RichardoC/kube-audit-rest/security/advisories/GHSA-hcr5-wv4p-h2g2"
|
||||
},
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24884"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/RichardoC/kube-audit-rest/commit/db1aa5b867256b0a7bf206544c6981ab068b73dc"
|
||||
@@ -46,11 +55,12 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-200",
|
||||
"CWE-532"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": true,
|
||||
"github_reviewed_at": "2025-01-29T20:47:51Z",
|
||||
"nvd_published_at": null
|
||||
"nvd_published_at": "2025-01-29T21:15:21Z"
|
||||
}
|
||||
}
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-m4f6-vcj4-w5mx",
|
||||
"modified": "2025-01-29T20:50:18Z",
|
||||
"modified": "2025-01-29T22:00:31Z",
|
||||
"published": "2025-01-29T20:50:18Z",
|
||||
"aliases": [
|
||||
"CVE-2025-24794"
|
||||
@@ -43,6 +43,14 @@
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/snowflakedb/snowflake-connector-python/security/advisories/GHSA-m4f6-vcj4-w5mx"
|
||||
},
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24794"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/snowflakedb/snowflake-connector-python/commit/3769b43822357c3874c40f5e74068458c2dc79af"
|
||||
},
|
||||
{
|
||||
"type": "PACKAGE",
|
||||
"url": "https://github.com/snowflakedb/snowflake-connector-python"
|
||||
@@ -59,6 +67,6 @@
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": true,
|
||||
"github_reviewed_at": "2025-01-29T20:50:18Z",
|
||||
"nvd_published_at": null
|
||||
"nvd_published_at": "2025-01-29T21:15:21Z"
|
||||
}
|
||||
}
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-r2x6-cjg7-8r43",
|
||||
"modified": "2025-01-29T20:49:59Z",
|
||||
"modified": "2025-01-29T22:00:35Z",
|
||||
"published": "2025-01-29T20:49:59Z",
|
||||
"aliases": [
|
||||
"CVE-2025-24795"
|
||||
@@ -43,6 +43,14 @@
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/snowflakedb/snowflake-connector-python/security/advisories/GHSA-r2x6-cjg7-8r43"
|
||||
},
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24795"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/snowflakedb/snowflake-connector-python/commit/3769b43822357c3874c40f5e74068458c2dc79af"
|
||||
},
|
||||
{
|
||||
"type": "PACKAGE",
|
||||
"url": "https://github.com/snowflakedb/snowflake-connector-python"
|
||||
@@ -59,6 +67,6 @@
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": true,
|
||||
"github_reviewed_at": "2025-01-29T20:49:59Z",
|
||||
"nvd_published_at": null
|
||||
"nvd_published_at": "2025-01-29T21:15:21Z"
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user