Publish Advisories

GHSA-jhm9-h84h-rw83
GHSA-3wx7-46ch-7rq2
GHSA-8gq9-2x98-w8hf
GHSA-vvpx-j8f3-3w6h
GHSA-mwq8-fjpf-c2gr
GHSA-2ccf-ffrj-m4qw
GHSA-4m3m-ppvx-xgw9
GHSA-833c-xh79-p429
GHSA-f4v8-58f6-mwj4
GHSA-mj9r-fpv3-rgfx
GHSA-wxmh-65f7-jcvw
This commit is contained in:
advisory-database[bot]
2023-04-24 15:57:35 +00:00
parent e4d111beed
commit dda722f192
11 changed files with 65 additions and 8 deletions
@@ -67,6 +67,10 @@
"type": "WEB",
"url": "https://github.com/phpbb/phpbb-app/commit/efc0a146bf12125eeb71d00470af774326a7bf0a"
},
{
"type": "WEB",
"url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/phpbb/phpbb/CVE-2020-8226.yaml"
},
{
"type": "PACKAGE",
"url": "https://github.com/phpbb/phpbb-app"
@@ -103,6 +103,10 @@
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20220715-0011/"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20230420-0008/"
},
{
"type": "WEB",
"url": "https://www.debian.org/security/2023/dsa-5343"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8gq9-2x98-w8hf",
"modified": "2022-12-19T14:43:11Z",
"modified": "2023-04-24T15:56:18Z",
"published": "2022-09-23T20:31:15Z",
"aliases": [
"CVE-2022-1941"
@@ -109,6 +109,10 @@
"type": "PACKAGE",
"url": "https://github.com/protocolbuffers/protobuf"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2023/04/msg00019.html"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CBAUKJQL6O4TIWYBENORSY5P43TVB4M3/"
@@ -68,6 +68,10 @@
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RLBQ3A7ROLEQXQLXFDLNJ7MYPKG5GULE/"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XX3IMUTZKRQ73PBZM4E2JP4BKYH4C6XE/"
},
{
"type": "WEB",
"url": "https://pkg.go.dev/vuln/GO-2023-1571"
@@ -52,9 +52,17 @@
"type": "PACKAGE",
"url": "https://github.com/matrix-org/matrix-js-sdk"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2023/04/msg00027.html"
},
{
"type": "WEB",
"url": "https://matrix.org/blog/2023/03/28/security-releases-matrix-js-sdk-24-0-0-and-matrix-react-sdk-3-69-0"
},
{
"type": "WEB",
"url": "https://www.debian.org/security/2023/dsa-5392"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2ccf-ffrj-m4qw",
"modified": "2023-04-21T22:32:47Z",
"modified": "2023-04-24T15:56:27Z",
"published": "2023-04-21T22:32:47Z",
"aliases": [
"CVE-2023-29020"
@@ -59,14 +59,30 @@
"type": "WEB",
"url": "https://github.com/fastify/fastify-passport/security/advisories/GHSA-2ccf-ffrj-m4qw"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29020"
},
{
"type": "WEB",
"url": "https://github.com/fastify/fastify-passport/commit/07c90feab9cba0dd4779e47cfb0717a7e2f01d3d"
},
{
"type": "WEB",
"url": "https://cheatsheetseries.owasp.org/cheatsheets/Cross-Site_Request_Forgery_Prevention_Cheat_Sheet.html#synchronizer-token-pattern"
},
{
"type": "PACKAGE",
"url": "https://github.com/fastify/fastify-passport"
},
{
"type": "WEB",
"url": "https://owasp.org/www-community/attacks/csrf"
}
],
"database_specific": {
"cwe_ids": [
"CWE-352"
],
"severity": "MODERATE",
"github_reviewed": true,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4m3m-ppvx-xgw9",
"modified": "2023-04-21T22:33:30Z",
"modified": "2023-04-24T15:56:25Z",
"published": "2023-04-21T22:33:30Z",
"aliases": [
"CVE-2023-29019"
@@ -59,14 +59,26 @@
"type": "WEB",
"url": "https://github.com/fastify/fastify-passport/security/advisories/GHSA-4m3m-ppvx-xgw9"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29019"
},
{
"type": "WEB",
"url": "https://github.com/fastify/fastify-passport/commit/43c82c321db58ea3e375dd475de60befbfcf2a11"
},
{
"type": "PACKAGE",
"url": "https://github.com/fastify/fastify-passport"
},
{
"type": "WEB",
"url": "https://owasp.org/www-community/attacks/Session_fixation"
}
],
"database_specific": {
"cwe_ids": [
"CWE-384"
],
"severity": "HIGH",
"github_reviewed": true,
@@ -1,10 +1,10 @@
{
"schema_version": "1.4.0",
"id": "GHSA-833c-xh79-p429",
"modified": "2023-04-21T19:42:10Z",
"modified": "2023-04-24T15:57:13Z",
"published": "2023-04-21T19:42:10Z",
"aliases": [
"CVE-2023-30622"
],
"summary": "A potential risk in clusternet which can be leveraged to make a cluster-level privilege escalation",
"details": "## Summary:\nA potential risk in clusternet which can be leveraged to make a cluster-level privilege escalation.\n## Detailed analysis:\nThe clusternet has a deployment called cluster-hub inside the clusternet-system Kubernetes namespace, which runs on worker nodes\nrandomly. The deployment has a service account called clusternet-hub, which has a cluster role called clusternet:hub via cluster role binding. The clusternet:hub cluster role has \"*\" verbs of \"*.*\" resources. Thus, if a malicious user can access the worker node which runs the clusternet, he/she can leverage the service account to do malicious actions to critical system resources. For example, he/she can leverage the service account to get ALL secrets in the entire cluster, resulting in cluster-level privilege escalation.",
@@ -97,6 +97,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-94",
"CWE-95"
],
"severity": "CRITICAL",
@@ -48,7 +48,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": true,
@@ -67,6 +67,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29197"
},
{
"type": "WEB",
"url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/guzzlehttp/psr7/CVE-2023-29197.yaml"
},
{
"type": "PACKAGE",
"url": "https://github.com/guzzle/psr7"