From dd9bbb3e72efa642ab583cc5aa117789088dfb90 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 29 Jan 2025 22:01:13 +0000 Subject: [PATCH] Publish Advisories GHSA-22fx-6r9m-r8h9 GHSA-x3cq-8f32-5f63 GHSA-2mqw-rq5m-8hc8 GHSA-2vpq-fh52-j3wv GHSA-hcr5-wv4p-h2g2 GHSA-m4f6-vcj4-w5mx GHSA-r2x6-cjg7-8r43 --- .../GHSA-22fx-6r9m-r8h9/GHSA-22fx-6r9m-r8h9.json | 10 +++++++++- .../GHSA-x3cq-8f32-5f63/GHSA-x3cq-8f32-5f63.json | 10 +++++++++- .../GHSA-2mqw-rq5m-8hc8/GHSA-2mqw-rq5m-8hc8.json | 8 ++++++-- .../GHSA-2vpq-fh52-j3wv/GHSA-2vpq-fh52-j3wv.json | 12 ++++++++++-- .../GHSA-hcr5-wv4p-h2g2/GHSA-hcr5-wv4p-h2g2.json | 16 +++++++++++++--- .../GHSA-m4f6-vcj4-w5mx/GHSA-m4f6-vcj4-w5mx.json | 12 ++++++++++-- .../GHSA-r2x6-cjg7-8r43/GHSA-r2x6-cjg7-8r43.json | 12 ++++++++++-- 7 files changed, 67 insertions(+), 13 deletions(-) diff --git a/advisories/github-reviewed/2023/05/GHSA-22fx-6r9m-r8h9/GHSA-22fx-6r9m-r8h9.json b/advisories/github-reviewed/2023/05/GHSA-22fx-6r9m-r8h9/GHSA-22fx-6r9m-r8h9.json index dee9517ee4b..cebcb40725d 100644 --- a/advisories/github-reviewed/2023/05/GHSA-22fx-6r9m-r8h9/GHSA-22fx-6r9m-r8h9.json +++ b/advisories/github-reviewed/2023/05/GHSA-22fx-6r9m-r8h9/GHSA-22fx-6r9m-r8h9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-22fx-6r9m-r8h9", - "modified": "2023-06-02T21:18:04Z", + "modified": "2025-01-29T22:00:08Z", "published": "2023-05-05T18:30:17Z", "aliases": [ "CVE-2023-29659" @@ -48,6 +48,14 @@ "type": "WEB", "url": "https://github.com/strukturag/libheif/commit/e05e15b57a38ec411cb9acb38512a1c36ff62991" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CKAE6NQBA3Q7GS6VTNDZRZZZVPPEFUEZ" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LGKHDCS4HRZE3UGXYYDYPTIPNIBRLQ5L" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CKAE6NQBA3Q7GS6VTNDZRZZZVPPEFUEZ" diff --git a/advisories/github-reviewed/2023/07/GHSA-x3cq-8f32-5f63/GHSA-x3cq-8f32-5f63.json b/advisories/github-reviewed/2023/07/GHSA-x3cq-8f32-5f63/GHSA-x3cq-8f32-5f63.json index 14d691e95d2..49d6e6891db 100644 --- a/advisories/github-reviewed/2023/07/GHSA-x3cq-8f32-5f63/GHSA-x3cq-8f32-5f63.json +++ b/advisories/github-reviewed/2023/07/GHSA-x3cq-8f32-5f63/GHSA-x3cq-8f32-5f63.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x3cq-8f32-5f63", - "modified": "2025-01-23T22:26:19Z", + "modified": "2025-01-29T22:00:17Z", "published": "2023-07-06T21:15:04Z", "aliases": [ "CVE-2023-33246" @@ -105,10 +105,18 @@ "type": "WEB", "url": "https://github.com/apache/rocketmq/commit/c3ada731405c5990c36bf58d50b3e61965300703" }, + { + "type": "WEB", + "url": "https://github.com/Malayke/CVE-2023-33246_RocketMQ_RCE_EXPLOIT" + }, { "type": "PACKAGE", "url": "https://github.com/apache/rocketmq" }, + { + "type": "WEB", + "url": "https://github.com/jakabakos/CVE-2023-33246_Apache_RocketMQ_RCE" + }, { "type": "WEB", "url": "https://lists.apache.org/thread/1s8j2c8kogthtpv3060yddk03zq0pxyp" diff --git a/advisories/github-reviewed/2025/01/GHSA-2mqw-rq5m-8hc8/GHSA-2mqw-rq5m-8hc8.json b/advisories/github-reviewed/2025/01/GHSA-2mqw-rq5m-8hc8/GHSA-2mqw-rq5m-8hc8.json index 5275b2a9bda..c156ddbf10d 100644 --- a/advisories/github-reviewed/2025/01/GHSA-2mqw-rq5m-8hc8/GHSA-2mqw-rq5m-8hc8.json +++ b/advisories/github-reviewed/2025/01/GHSA-2mqw-rq5m-8hc8/GHSA-2mqw-rq5m-8hc8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2mqw-rq5m-8hc8", - "modified": "2025-01-29T20:50:56Z", + "modified": "2025-01-29T22:00:22Z", "published": "2025-01-29T20:50:55Z", "aliases": [ "CVE-2025-24788" @@ -43,6 +43,10 @@ "type": "WEB", "url": "https://github.com/snowflakedb/snowflake-connector-net/security/advisories/GHSA-2mqw-rq5m-8hc8" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24788" + }, { "type": "WEB", "url": "https://github.com/snowflakedb/snowflake-connector-net/commit/89d91e8316ca213c5d184bcf469ed93977a5edf9" @@ -59,6 +63,6 @@ "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2025-01-29T20:50:55Z", - "nvd_published_at": null + "nvd_published_at": "2025-01-29T21:15:21Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2025/01/GHSA-2vpq-fh52-j3wv/GHSA-2vpq-fh52-j3wv.json b/advisories/github-reviewed/2025/01/GHSA-2vpq-fh52-j3wv/GHSA-2vpq-fh52-j3wv.json index 7cbadee2ea5..73c8eb0e078 100644 --- a/advisories/github-reviewed/2025/01/GHSA-2vpq-fh52-j3wv/GHSA-2vpq-fh52-j3wv.json +++ b/advisories/github-reviewed/2025/01/GHSA-2vpq-fh52-j3wv/GHSA-2vpq-fh52-j3wv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2vpq-fh52-j3wv", - "modified": "2025-01-29T20:50:33Z", + "modified": "2025-01-29T22:00:26Z", "published": "2025-01-29T20:50:33Z", "aliases": [ "CVE-2025-24793" @@ -43,6 +43,14 @@ "type": "WEB", "url": "https://github.com/snowflakedb/snowflake-connector-python/security/advisories/GHSA-2vpq-fh52-j3wv" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24793" + }, + { + "type": "WEB", + "url": "https://github.com/snowflakedb/snowflake-connector-python/commit/f3f9b666518d29c31a49384bbaa9a65889e72056" + }, { "type": "PACKAGE", "url": "https://github.com/snowflakedb/snowflake-connector-python" @@ -59,6 +67,6 @@ "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2025-01-29T20:50:33Z", - "nvd_published_at": null + "nvd_published_at": "2025-01-29T21:15:21Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2025/01/GHSA-hcr5-wv4p-h2g2/GHSA-hcr5-wv4p-h2g2.json b/advisories/github-reviewed/2025/01/GHSA-hcr5-wv4p-h2g2/GHSA-hcr5-wv4p-h2g2.json index cadcdcb3de2..e1111b1821f 100644 --- a/advisories/github-reviewed/2025/01/GHSA-hcr5-wv4p-h2g2/GHSA-hcr5-wv4p-h2g2.json +++ b/advisories/github-reviewed/2025/01/GHSA-hcr5-wv4p-h2g2/GHSA-hcr5-wv4p-h2g2.json @@ -1,14 +1,19 @@ { "schema_version": "1.4.0", "id": "GHSA-hcr5-wv4p-h2g2", - "modified": "2025-01-29T20:47:51Z", + "modified": "2025-01-29T22:00:39Z", "published": "2025-01-29T20:47:51Z", "aliases": [ "CVE-2025-24884" ], "summary": "kube-audit-rest's example logging configuration could disclose secret values in the audit log", "details": "### Impact\nIf the \"full-elastic-stack\" example vector configuration was used for a real cluster, the previous values of kubernetes secrets would have been disclosed in the audit messages.\n\n### Patches\nThe example has been updated to fix this in commit db1aa5b867256b0a7bf206544c6981ab068b73dc\n\n\n### Workarounds\nReplace \n```yaml\n\n if .request.requestKind.kind == \"Secret\" {\n del(.request.object.data)\n .request.object.data.redacted = \"REDACTED\"\n del(.request.oldObject.data)\n .request.oldObject.data.redacted = \"REDACTED\"\n }\n```\nIn the vector \"audit-files-json-parser-and-redaction\" step\nwith\n```yaml\n\n if .request.requestKind.kind == \"Secret\" {\n # Redact the secret data\n del(.request.object.data)\n .request.object.data.redacted = \"REDACTED\"\n del(.request.oldObject.data)\n .request.oldObject.data.redacted = \"REDACTED\"\n # Remove the previously set secret data - Not bothering to parse it as this annotation shouldn't ever be needed\n del(.request.object.metadata.annotations.[\"kubectl.kubernetes.io/last-applied-configuration\"])\n del(.request.oldObject.metadata.annotations.[\"kubectl.kubernetes.io/last-applied-configuration\"])\n }\n```", - "severity": [], + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], "affected": [ { "package": { @@ -35,6 +40,10 @@ "type": "WEB", "url": "https://github.com/RichardoC/kube-audit-rest/security/advisories/GHSA-hcr5-wv4p-h2g2" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24884" + }, { "type": "WEB", "url": "https://github.com/RichardoC/kube-audit-rest/commit/db1aa5b867256b0a7bf206544c6981ab068b73dc" @@ -46,11 +55,12 @@ ], "database_specific": { "cwe_ids": [ + "CWE-200", "CWE-532" ], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2025-01-29T20:47:51Z", - "nvd_published_at": null + "nvd_published_at": "2025-01-29T21:15:21Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2025/01/GHSA-m4f6-vcj4-w5mx/GHSA-m4f6-vcj4-w5mx.json b/advisories/github-reviewed/2025/01/GHSA-m4f6-vcj4-w5mx/GHSA-m4f6-vcj4-w5mx.json index d2f036bd5c0..ddb67c5bdb4 100644 --- a/advisories/github-reviewed/2025/01/GHSA-m4f6-vcj4-w5mx/GHSA-m4f6-vcj4-w5mx.json +++ b/advisories/github-reviewed/2025/01/GHSA-m4f6-vcj4-w5mx/GHSA-m4f6-vcj4-w5mx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m4f6-vcj4-w5mx", - "modified": "2025-01-29T20:50:18Z", + "modified": "2025-01-29T22:00:31Z", "published": "2025-01-29T20:50:18Z", "aliases": [ "CVE-2025-24794" @@ -43,6 +43,14 @@ "type": "WEB", "url": "https://github.com/snowflakedb/snowflake-connector-python/security/advisories/GHSA-m4f6-vcj4-w5mx" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24794" + }, + { + "type": "WEB", + "url": "https://github.com/snowflakedb/snowflake-connector-python/commit/3769b43822357c3874c40f5e74068458c2dc79af" + }, { "type": "PACKAGE", "url": "https://github.com/snowflakedb/snowflake-connector-python" @@ -59,6 +67,6 @@ "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2025-01-29T20:50:18Z", - "nvd_published_at": null + "nvd_published_at": "2025-01-29T21:15:21Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2025/01/GHSA-r2x6-cjg7-8r43/GHSA-r2x6-cjg7-8r43.json b/advisories/github-reviewed/2025/01/GHSA-r2x6-cjg7-8r43/GHSA-r2x6-cjg7-8r43.json index 1c6b4ede2c6..d93452bc77d 100644 --- a/advisories/github-reviewed/2025/01/GHSA-r2x6-cjg7-8r43/GHSA-r2x6-cjg7-8r43.json +++ b/advisories/github-reviewed/2025/01/GHSA-r2x6-cjg7-8r43/GHSA-r2x6-cjg7-8r43.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r2x6-cjg7-8r43", - "modified": "2025-01-29T20:49:59Z", + "modified": "2025-01-29T22:00:35Z", "published": "2025-01-29T20:49:59Z", "aliases": [ "CVE-2025-24795" @@ -43,6 +43,14 @@ "type": "WEB", "url": "https://github.com/snowflakedb/snowflake-connector-python/security/advisories/GHSA-r2x6-cjg7-8r43" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24795" + }, + { + "type": "WEB", + "url": "https://github.com/snowflakedb/snowflake-connector-python/commit/3769b43822357c3874c40f5e74068458c2dc79af" + }, { "type": "PACKAGE", "url": "https://github.com/snowflakedb/snowflake-connector-python" @@ -59,6 +67,6 @@ "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2025-01-29T20:49:59Z", - "nvd_published_at": null + "nvd_published_at": "2025-01-29T21:15:21Z" } } \ No newline at end of file