mirror of
https://github.com/netbirdio/advisory-database.git
synced 2026-05-22 18:04:22 -07:00
Publish Advisories
GHSA-jhm9-h84h-rw83 GHSA-3wx7-46ch-7rq2 GHSA-8gq9-2x98-w8hf GHSA-vvpx-j8f3-3w6h GHSA-mwq8-fjpf-c2gr GHSA-2ccf-ffrj-m4qw GHSA-4m3m-ppvx-xgw9 GHSA-833c-xh79-p429 GHSA-f4v8-58f6-mwj4 GHSA-mj9r-fpv3-rgfx GHSA-wxmh-65f7-jcvw
This commit is contained in:
@@ -67,6 +67,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/phpbb/phpbb-app/commit/efc0a146bf12125eeb71d00470af774326a7bf0a"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/phpbb/phpbb/CVE-2020-8226.yaml"
|
||||
},
|
||||
{
|
||||
"type": "PACKAGE",
|
||||
"url": "https://github.com/phpbb/phpbb-app"
|
||||
|
||||
@@ -103,6 +103,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://security.netapp.com/advisory/ntap-20220715-0011/"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.netapp.com/advisory/ntap-20230420-0008/"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.debian.org/security/2023/dsa-5343"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-8gq9-2x98-w8hf",
|
||||
"modified": "2022-12-19T14:43:11Z",
|
||||
"modified": "2023-04-24T15:56:18Z",
|
||||
"published": "2022-09-23T20:31:15Z",
|
||||
"aliases": [
|
||||
"CVE-2022-1941"
|
||||
@@ -109,6 +109,10 @@
|
||||
"type": "PACKAGE",
|
||||
"url": "https://github.com/protocolbuffers/protobuf"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://lists.debian.org/debian-lts-announce/2023/04/msg00019.html"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CBAUKJQL6O4TIWYBENORSY5P43TVB4M3/"
|
||||
|
||||
@@ -68,6 +68,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RLBQ3A7ROLEQXQLXFDLNJ7MYPKG5GULE/"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XX3IMUTZKRQ73PBZM4E2JP4BKYH4C6XE/"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://pkg.go.dev/vuln/GO-2023-1571"
|
||||
|
||||
@@ -52,9 +52,17 @@
|
||||
"type": "PACKAGE",
|
||||
"url": "https://github.com/matrix-org/matrix-js-sdk"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://lists.debian.org/debian-lts-announce/2023/04/msg00027.html"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://matrix.org/blog/2023/03/28/security-releases-matrix-js-sdk-24-0-0-and-matrix-react-sdk-3-69-0"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.debian.org/security/2023/dsa-5392"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-2ccf-ffrj-m4qw",
|
||||
"modified": "2023-04-21T22:32:47Z",
|
||||
"modified": "2023-04-24T15:56:27Z",
|
||||
"published": "2023-04-21T22:32:47Z",
|
||||
"aliases": [
|
||||
"CVE-2023-29020"
|
||||
@@ -59,14 +59,30 @@
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/fastify/fastify-passport/security/advisories/GHSA-2ccf-ffrj-m4qw"
|
||||
},
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29020"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/fastify/fastify-passport/commit/07c90feab9cba0dd4779e47cfb0717a7e2f01d3d"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://cheatsheetseries.owasp.org/cheatsheets/Cross-Site_Request_Forgery_Prevention_Cheat_Sheet.html#synchronizer-token-pattern"
|
||||
},
|
||||
{
|
||||
"type": "PACKAGE",
|
||||
"url": "https://github.com/fastify/fastify-passport"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://owasp.org/www-community/attacks/csrf"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
"CWE-352"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": true,
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-4m3m-ppvx-xgw9",
|
||||
"modified": "2023-04-21T22:33:30Z",
|
||||
"modified": "2023-04-24T15:56:25Z",
|
||||
"published": "2023-04-21T22:33:30Z",
|
||||
"aliases": [
|
||||
"CVE-2023-29019"
|
||||
@@ -59,14 +59,26 @@
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/fastify/fastify-passport/security/advisories/GHSA-4m3m-ppvx-xgw9"
|
||||
},
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29019"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/fastify/fastify-passport/commit/43c82c321db58ea3e375dd475de60befbfcf2a11"
|
||||
},
|
||||
{
|
||||
"type": "PACKAGE",
|
||||
"url": "https://github.com/fastify/fastify-passport"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://owasp.org/www-community/attacks/Session_fixation"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
"CWE-384"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": true,
|
||||
|
||||
@@ -1,10 +1,10 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-833c-xh79-p429",
|
||||
"modified": "2023-04-21T19:42:10Z",
|
||||
"modified": "2023-04-24T15:57:13Z",
|
||||
"published": "2023-04-21T19:42:10Z",
|
||||
"aliases": [
|
||||
|
||||
"CVE-2023-30622"
|
||||
],
|
||||
"summary": "A potential risk in clusternet which can be leveraged to make a cluster-level privilege escalation",
|
||||
"details": "## Summary:\nA potential risk in clusternet which can be leveraged to make a cluster-level privilege escalation.\n## Detailed analysis:\nThe clusternet has a deployment called cluster-hub inside the clusternet-system Kubernetes namespace, which runs on worker nodes\nrandomly. The deployment has a service account called clusternet-hub, which has a cluster role called clusternet:hub via cluster role binding. The clusternet:hub cluster role has \"*\" verbs of \"*.*\" resources. Thus, if a malicious user can access the worker node which runs the clusternet, he/she can leverage the service account to do malicious actions to critical system resources. For example, he/she can leverage the service account to get ALL secrets in the entire cluster, resulting in cluster-level privilege escalation.",
|
||||
|
||||
@@ -97,6 +97,7 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-94",
|
||||
"CWE-95"
|
||||
],
|
||||
"severity": "CRITICAL",
|
||||
|
||||
@@ -48,7 +48,7 @@
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
|
||||
"CWE-79"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": true,
|
||||
|
||||
@@ -67,6 +67,10 @@
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29197"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/guzzlehttp/psr7/CVE-2023-29197.yaml"
|
||||
},
|
||||
{
|
||||
"type": "PACKAGE",
|
||||
"url": "https://github.com/guzzle/psr7"
|
||||
|
||||
Reference in New Issue
Block a user