Publish Advisories

GHSA-x3mh-jvjw-3xwx
GHSA-3wx7-46ch-7rq2
GHSA-8cf7-32gw-wr33
GHSA-hjrf-2m68-5959
GHSA-r9hx-vwmv-q579
GHSA-r7jw-wp68-3xch
GHSA-6mjq-h674-j845
GHSA-cggh-pq45-6h9x
This commit is contained in:
advisory-database[bot]
2024-06-24 21:25:26 +00:00
parent 00d19b7f7b
commit e04cbcbd2f
8 changed files with 197 additions and 108 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x3mh-jvjw-3xwx",
"modified": "2022-08-11T21:38:00Z",
"modified": "2024-06-24T21:24:17Z",
"published": "2022-03-16T00:00:45Z",
"aliases": [
"CVE-2022-0778"
@@ -61,55 +61,7 @@
},
{
"type": "WEB",
"url": "https://www.tenable.com/security/tns-2022-09"
},
{
"type": "WEB",
"url": "https://www.tenable.com/security/tns-2022-08"
},
{
"type": "WEB",
"url": "https://www.tenable.com/security/tns-2022-07"
},
{
"type": "WEB",
"url": "https://www.tenable.com/security/tns-2022-06"
},
{
"type": "WEB",
"url": "https://www.oracle.com/security-alerts/cpujul2022.html"
},
{
"type": "WEB",
"url": "https://www.oracle.com/security-alerts/cpuapr2022.html"
},
{
"type": "WEB",
"url": "https://www.openssl.org/news/secadv/20220315.txt"
},
{
"type": "WEB",
"url": "https://www.debian.org/security/2022/dsa-5103"
},
{
"type": "WEB",
"url": "https://support.apple.com/kb/HT213257"
},
{
"type": "WEB",
"url": "https://support.apple.com/kb/HT213256"
},
{
"type": "WEB",
"url": "https://support.apple.com/kb/HT213255"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20220429-0005"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20220321-0002"
"url": "https://rustsec.org/advisories/RUSTSEC-2022-0014.html"
},
{
"type": "WEB",
@@ -117,7 +69,59 @@
},
{
"type": "WEB",
"url": "https://rustsec.org/advisories/RUSTSEC-2022-0014.html"
"url": "https://security.netapp.com/advisory/ntap-20220321-0002"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20220429-0005"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20240621-0006"
},
{
"type": "WEB",
"url": "https://support.apple.com/kb/HT213255"
},
{
"type": "WEB",
"url": "https://support.apple.com/kb/HT213256"
},
{
"type": "WEB",
"url": "https://support.apple.com/kb/HT213257"
},
{
"type": "WEB",
"url": "https://www.debian.org/security/2022/dsa-5103"
},
{
"type": "WEB",
"url": "https://www.openssl.org/news/secadv/20220315.txt"
},
{
"type": "WEB",
"url": "https://www.oracle.com/security-alerts/cpuapr2022.html"
},
{
"type": "WEB",
"url": "https://www.oracle.com/security-alerts/cpujul2022.html"
},
{
"type": "WEB",
"url": "https://www.tenable.com/security/tns-2022-06"
},
{
"type": "WEB",
"url": "https://www.tenable.com/security/tns-2022-07"
},
{
"type": "WEB",
"url": "https://www.tenable.com/security/tns-2022-08"
},
{
"type": "WEB",
"url": "https://www.tenable.com/security/tns-2022-09"
},
{
"type": "WEB",
@@ -135,6 +139,18 @@
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/323SNN6ZX7PRJJWP2BUAFLPUAE42XWLZ"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W6K3PR542DXWLEFFMFIDMME4CWMHJRMG"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GDB3GQVJPXJE7X5C5JN6JAA4XUDWD6E6"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/323SNN6ZX7PRJJWP2BUAFLPUAE42XWLZ"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2022/03/msg00024.html"
@@ -155,6 +171,18 @@
"type": "WEB",
"url": "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=3118eb64934499d93db3230748a452351d1d9a65"
},
{
"type": "WEB",
"url": "https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=a466912611aa6cbdf550cd10601390e587451246"
},
{
"type": "WEB",
"url": "https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=380085481c64de749a6dd25cdf0bcf4360b30f83"
},
{
"type": "WEB",
"url": "https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=3118eb64934499d93db3230748a452351d1d9a65"
},
{
"type": "WEB",
"url": "https://cert-portal.siemens.com/productcert/pdf/ssa-712929.pdf"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3wx7-46ch-7rq2",
"modified": "2022-09-08T14:25:14Z",
"modified": "2024-06-24T21:24:18Z",
"published": "2022-07-06T19:57:19Z",
"aliases": [
"CVE-2022-2097"
@@ -61,51 +61,7 @@
},
{
"type": "WEB",
"url": "https://cert-portal.siemens.com/productcert/pdf/ssa-332410.pdf"
},
{
"type": "WEB",
"url": "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=919925673d6c9cfed3c1085497f5dfbbed5fc431"
},
{
"type": "WEB",
"url": "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=a98f339ddd7e8f487d6e0088d4a9a42324885a93"
},
{
"type": "PACKAGE",
"url": "https://github.com/alexcrichton/openssl-src-rs"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2023/02/msg00019.html"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/R6CK57NBQFTPUMXAPJURCGXUYT76NQAK"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/V6567JERRHHJW2GNGJGKDRNHR7SNPZK7"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VCMNWKERPBKOEBNL7CLTTX3ZZCZLH7XA"
},
{
"type": "WEB",
"url": "https://rustsec.org/advisories/RUSTSEC-2022-0032.html"
},
{
"type": "WEB",
"url": "https://security.gentoo.org/glsa/202210-02"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20220715-0011"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20230420-0008"
"url": "https://www.openssl.org/news/secadv/20220705.txt"
},
{
"type": "WEB",
@@ -113,13 +69,82 @@
},
{
"type": "WEB",
"url": "https://www.openssl.org/news/secadv/20220705.txt"
"url": "https://security.netapp.com/advisory/ntap-20240621-0006"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20230420-0008"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20220715-0011"
},
{
"type": "WEB",
"url": "https://security.gentoo.org/glsa/202210-02"
},
{
"type": "WEB",
"url": "https://rustsec.org/advisories/RUSTSEC-2022-0032.html"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VCMNWKERPBKOEBNL7CLTTX3ZZCZLH7XA"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/V6567JERRHHJW2GNGJGKDRNHR7SNPZK7"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/R6CK57NBQFTPUMXAPJURCGXUYT76NQAK"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VCMNWKERPBKOEBNL7CLTTX3ZZCZLH7XA"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V6567JERRHHJW2GNGJGKDRNHR7SNPZK7"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R6CK57NBQFTPUMXAPJURCGXUYT76NQAK"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2023/02/msg00019.html"
},
{
"type": "PACKAGE",
"url": "https://github.com/alexcrichton/openssl-src-rs"
},
{
"type": "WEB",
"url": "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=a98f339ddd7e8f487d6e0088d4a9a42324885a93"
},
{
"type": "WEB",
"url": "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=919925673d6c9cfed3c1085497f5dfbbed5fc431"
},
{
"type": "WEB",
"url": "https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=a98f339ddd7e8f487d6e0088d4a9a42324885a93"
},
{
"type": "WEB",
"url": "https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=919925673d6c9cfed3c1085497f5dfbbed5fc431"
},
{
"type": "WEB",
"url": "https://cert-portal.siemens.com/productcert/pdf/ssa-332410.pdf"
}
],
"database_specific": {
"cwe_ids": [
"CWE-311",
"CWE-326"
"CWE-326",
"CWE-327"
],
"severity": "HIGH",
"github_reviewed": true,
@@ -1,15 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8cf7-32gw-wr33",
"modified": "2022-12-23T00:39:12Z",
"modified": "2024-06-24T21:23:38Z",
"published": "2022-12-22T03:32:22Z",
"aliases": [
"CVE-2022-23539"
],
"summary": "jsonwebtoken unrestricted key type could lead to legacy keys usage ",
"details": "# Overview\n\nVersions `<=8.5.1` of `jsonwebtoken` library could be misconfigured so that legacy, insecure key types are used for signature verification. For example, DSA keys could be used with the RS256 algorithm. \n\n# Am I affected?\n\nYou are affected if you are using an algorithm and a key type other than the combinations mentioned below\n\n| Key type | algorithm |\n|----------|------------------------------------------|\n| ec | ES256, ES384, ES512 |\n| rsa | RS256, RS384, RS512, PS256, PS384, PS512 |\n| rsa-pss | PS256, PS384, PS512 |\n\nAnd for Elliptic Curve algorithms:\n\n| `alg` | Curve |\n|-------|------------|\n| ES256 | prime256v1 |\n| ES384 | secp384r1 |\n| ES512 | secp521r1 |\n\n# How do I fix it?\n\nUpdate to version 9.0.0. This version validates for asymmetric key type and algorithm combinations. Please refer to the above mentioned algorithm / key type combinations for the valid secure configuration. After updating to version 9.0.0, If you still intend to continue with signing or verifying tokens using invalid key type/algorithm value combinations, youll need to set the `allowInvalidAsymmetricKeyTypes` option to `true` in the `sign()` and/or `verify()` functions.\n\n# Will the fix impact my users?\n\nThere will be no impact, if you update to version 9.0.0 and you already use a valid secure combination of key type and algorithm. Otherwise, use the `allowInvalidAsymmetricKeyTypes` option to `true` in the `sign()` and `verify()` functions to continue usage of invalid key type/algorithm combination in 9.0.0 for legacy compatibility. \n\n",
"details": "# Overview\n\nVersions `<=8.5.1` of `jsonwebtoken` library could be misconfigured so that legacy, insecure key types are used for signature verification. For example, DSA keys could be used with the RS256 algorithm. \n\n# Am I affected?\n\nYou are affected if you are using an algorithm and a key type other than the combinations mentioned below\n\n| Key type | algorithm |\n|----------|------------------------------------------|\n| ec | ES256, ES384, ES512 |\n| rsa | RS256, RS384, RS512, PS256, PS384, PS512 |\n| rsa-pss | PS256, PS384, PS512 |\n\nAnd for Elliptic Curve algorithms:\n\n| `alg` | Curve |\n|-------|------------|\n| ES256 | prime256v1 |\n| ES384 | secp384r1 |\n| ES512 | secp521r1 |\n\n# How do I fix it?\n\nUpdate to version 9.0.0. This version validates for asymmetric key type and algorithm combinations. Please refer to the above mentioned algorithm / key type combinations for the valid secure configuration. After updating to version 9.0.0, If you still intend to continue with signing or verifying tokens using invalid key type/algorithm value combinations, youll need to set the `allowInvalidAsymmetricKeyTypes` option to `true` in the `sign()` and/or `verify()` functions.\n\n# Will the fix impact my users?\n\nThere will be no impact, if you update to version 9.0.0 and you already use a valid secure combination of key type and algorithm. Otherwise, use the `allowInvalidAsymmetricKeyTypes` option to `true` in the `sign()` and `verify()` functions to continue usage of invalid key type/algorithm combination in 9.0.0 for legacy compatibility. \n\n",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"
}
],
"affected": [
{
@@ -51,13 +54,17 @@
{
"type": "PACKAGE",
"url": "https://github.com/auth0/node-jsonwebtoken"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20240621-0007"
}
],
"database_specific": {
"cwe_ids": [
"CWE-327"
],
"severity": "MODERATE",
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2022-12-22T03:32:22Z",
"nvd_published_at": "2022-12-23T00:15:00Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hjrf-2m68-5959",
"modified": "2022-12-30T00:47:06Z",
"modified": "2024-06-24T21:24:06Z",
"published": "2022-12-22T03:33:19Z",
"aliases": [
"CVE-2022-23541"
@@ -58,10 +58,15 @@
{
"type": "WEB",
"url": "https://github.com/auth0/node-jsonwebtoken/releases/tag/v9.0.0"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20240621-0007"
}
],
"database_specific": {
"cwe_ids": [
"CWE-1259",
"CWE-287"
],
"severity": "MODERATE",
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r9hx-vwmv-q579",
"modified": "2022-12-27T14:51:05Z",
"modified": "2024-06-24T21:24:10Z",
"published": "2022-12-23T00:30:23Z",
"aliases": [
"CVE-2022-40897"
@@ -60,6 +60,14 @@
"type": "WEB",
"url": "https://github.com/pypa/setuptools/compare/v65.5.0...v65.5.1"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ADES3NLOE5QJKBLGNZNI2RGVOSQXA37R"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YNA2BAH2ACBZ4TVJZKFLCR7L23BG5C3H"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ADES3NLOE5QJKBLGNZNI2RGVOSQXA37R"
@@ -80,6 +88,10 @@
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20230214-0001"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20240621-0006"
},
{
"type": "WEB",
"url": "https://setuptools.pypa.io/en/latest"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r7jw-wp68-3xch",
"modified": "2023-02-21T20:00:42Z",
"modified": "2024-06-24T21:24:19Z",
"published": "2023-02-08T22:28:34Z",
"aliases": [
"CVE-2023-0215"
@@ -87,6 +87,10 @@
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20230427-0009"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20240621-0006"
},
{
"type": "WEB",
"url": "https://www.openssl.org/news/secadv/20230207.txt"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6mjq-h674-j845",
"modified": "2023-06-23T13:56:06Z",
"modified": "2024-06-24T21:24:21Z",
"published": "2023-06-20T16:33:22Z",
"aliases": [
"CVE-2023-34462"
@@ -56,6 +56,10 @@
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20230803-0001"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20240621-0007"
},
{
"type": "WEB",
"url": "https://www.debian.org/security/2023/dsa-5558"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cggh-pq45-6h9x",
"modified": "2023-07-11T22:45:02Z",
"modified": "2024-06-24T21:25:02Z",
"published": "2023-07-01T00:30:46Z",
"aliases": [
"CVE-2023-30589"
@@ -79,6 +79,10 @@
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20230803-0009"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20240621-0006"
}
],
"database_specific": {