diff --git a/advisories/github-reviewed/2022/03/GHSA-x3mh-jvjw-3xwx/GHSA-x3mh-jvjw-3xwx.json b/advisories/github-reviewed/2022/03/GHSA-x3mh-jvjw-3xwx/GHSA-x3mh-jvjw-3xwx.json index cd3a855becb..c242f3ba72e 100644 --- a/advisories/github-reviewed/2022/03/GHSA-x3mh-jvjw-3xwx/GHSA-x3mh-jvjw-3xwx.json +++ b/advisories/github-reviewed/2022/03/GHSA-x3mh-jvjw-3xwx/GHSA-x3mh-jvjw-3xwx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x3mh-jvjw-3xwx", - "modified": "2022-08-11T21:38:00Z", + "modified": "2024-06-24T21:24:17Z", "published": "2022-03-16T00:00:45Z", "aliases": [ "CVE-2022-0778" @@ -61,55 +61,7 @@ }, { "type": "WEB", - "url": "https://www.tenable.com/security/tns-2022-09" - }, - { - "type": "WEB", - "url": "https://www.tenable.com/security/tns-2022-08" - }, - { - "type": "WEB", - "url": "https://www.tenable.com/security/tns-2022-07" - }, - { - "type": "WEB", - "url": "https://www.tenable.com/security/tns-2022-06" - }, - { - "type": "WEB", - "url": "https://www.oracle.com/security-alerts/cpujul2022.html" - }, - { - "type": "WEB", - "url": "https://www.oracle.com/security-alerts/cpuapr2022.html" - }, - { - "type": "WEB", - "url": "https://www.openssl.org/news/secadv/20220315.txt" - }, - { - "type": "WEB", - "url": "https://www.debian.org/security/2022/dsa-5103" - }, - { - "type": "WEB", - "url": "https://support.apple.com/kb/HT213257" - }, - { - "type": "WEB", - "url": "https://support.apple.com/kb/HT213256" - }, - { - "type": "WEB", - "url": "https://support.apple.com/kb/HT213255" - }, - { - "type": "WEB", - "url": "https://security.netapp.com/advisory/ntap-20220429-0005" - }, - { - "type": "WEB", - "url": "https://security.netapp.com/advisory/ntap-20220321-0002" + "url": "https://rustsec.org/advisories/RUSTSEC-2022-0014.html" }, { "type": "WEB", @@ -117,7 +69,59 @@ }, { "type": "WEB", - "url": "https://rustsec.org/advisories/RUSTSEC-2022-0014.html" + "url": "https://security.netapp.com/advisory/ntap-20220321-0002" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20220429-0005" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240621-0006" + }, + { + "type": "WEB", + "url": "https://support.apple.com/kb/HT213255" + }, + { + "type": "WEB", + "url": "https://support.apple.com/kb/HT213256" + }, + { + "type": "WEB", + "url": "https://support.apple.com/kb/HT213257" + }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2022/dsa-5103" + }, + { + "type": "WEB", + "url": "https://www.openssl.org/news/secadv/20220315.txt" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuapr2022.html" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, + { + "type": "WEB", + "url": "https://www.tenable.com/security/tns-2022-06" + }, + { + "type": "WEB", + "url": "https://www.tenable.com/security/tns-2022-07" + }, + { + "type": "WEB", + "url": "https://www.tenable.com/security/tns-2022-08" + }, + { + "type": "WEB", + "url": "https://www.tenable.com/security/tns-2022-09" }, { "type": "WEB", @@ -135,6 +139,18 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/323SNN6ZX7PRJJWP2BUAFLPUAE42XWLZ" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W6K3PR542DXWLEFFMFIDMME4CWMHJRMG" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GDB3GQVJPXJE7X5C5JN6JAA4XUDWD6E6" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/323SNN6ZX7PRJJWP2BUAFLPUAE42XWLZ" + }, { "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2022/03/msg00024.html" @@ -155,6 +171,18 @@ "type": "WEB", "url": "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=3118eb64934499d93db3230748a452351d1d9a65" }, + { + "type": "WEB", + "url": "https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=a466912611aa6cbdf550cd10601390e587451246" + }, + { + "type": "WEB", + "url": "https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=380085481c64de749a6dd25cdf0bcf4360b30f83" + }, + { + "type": "WEB", + "url": "https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=3118eb64934499d93db3230748a452351d1d9a65" + }, { "type": "WEB", "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-712929.pdf" diff --git a/advisories/github-reviewed/2022/07/GHSA-3wx7-46ch-7rq2/GHSA-3wx7-46ch-7rq2.json b/advisories/github-reviewed/2022/07/GHSA-3wx7-46ch-7rq2/GHSA-3wx7-46ch-7rq2.json index c62b2f2f77c..c40bdee9b72 100644 --- a/advisories/github-reviewed/2022/07/GHSA-3wx7-46ch-7rq2/GHSA-3wx7-46ch-7rq2.json +++ b/advisories/github-reviewed/2022/07/GHSA-3wx7-46ch-7rq2/GHSA-3wx7-46ch-7rq2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3wx7-46ch-7rq2", - "modified": "2022-09-08T14:25:14Z", + "modified": "2024-06-24T21:24:18Z", "published": "2022-07-06T19:57:19Z", "aliases": [ "CVE-2022-2097" @@ -61,51 +61,7 @@ }, { "type": "WEB", - "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-332410.pdf" - }, - { - "type": "WEB", - "url": "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=919925673d6c9cfed3c1085497f5dfbbed5fc431" - }, - { - "type": "WEB", - "url": "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=a98f339ddd7e8f487d6e0088d4a9a42324885a93" - }, - { - "type": "PACKAGE", - "url": "https://github.com/alexcrichton/openssl-src-rs" - }, - { - "type": "WEB", - "url": "https://lists.debian.org/debian-lts-announce/2023/02/msg00019.html" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/R6CK57NBQFTPUMXAPJURCGXUYT76NQAK" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/V6567JERRHHJW2GNGJGKDRNHR7SNPZK7" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VCMNWKERPBKOEBNL7CLTTX3ZZCZLH7XA" - }, - { - "type": "WEB", - "url": "https://rustsec.org/advisories/RUSTSEC-2022-0032.html" - }, - { - "type": "WEB", - "url": "https://security.gentoo.org/glsa/202210-02" - }, - { - "type": "WEB", - "url": "https://security.netapp.com/advisory/ntap-20220715-0011" - }, - { - "type": "WEB", - "url": "https://security.netapp.com/advisory/ntap-20230420-0008" + "url": "https://www.openssl.org/news/secadv/20220705.txt" }, { "type": "WEB", @@ -113,13 +69,82 @@ }, { "type": "WEB", - "url": "https://www.openssl.org/news/secadv/20220705.txt" + "url": "https://security.netapp.com/advisory/ntap-20240621-0006" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20230420-0008" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20220715-0011" + }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202210-02" + }, + { + "type": "WEB", + "url": "https://rustsec.org/advisories/RUSTSEC-2022-0032.html" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VCMNWKERPBKOEBNL7CLTTX3ZZCZLH7XA" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/V6567JERRHHJW2GNGJGKDRNHR7SNPZK7" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/R6CK57NBQFTPUMXAPJURCGXUYT76NQAK" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VCMNWKERPBKOEBNL7CLTTX3ZZCZLH7XA" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V6567JERRHHJW2GNGJGKDRNHR7SNPZK7" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R6CK57NBQFTPUMXAPJURCGXUYT76NQAK" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2023/02/msg00019.html" + }, + { + "type": "PACKAGE", + "url": "https://github.com/alexcrichton/openssl-src-rs" + }, + { + "type": "WEB", + "url": "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=a98f339ddd7e8f487d6e0088d4a9a42324885a93" + }, + { + "type": "WEB", + "url": "https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=919925673d6c9cfed3c1085497f5dfbbed5fc431" + }, + { + "type": "WEB", + "url": "https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=a98f339ddd7e8f487d6e0088d4a9a42324885a93" + }, + { + "type": "WEB", + "url": "https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=919925673d6c9cfed3c1085497f5dfbbed5fc431" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-332410.pdf" } ], "database_specific": { "cwe_ids": [ "CWE-311", - "CWE-326" + "CWE-326", + "CWE-327" ], "severity": "HIGH", "github_reviewed": true, diff --git a/advisories/github-reviewed/2022/12/GHSA-8cf7-32gw-wr33/GHSA-8cf7-32gw-wr33.json b/advisories/github-reviewed/2022/12/GHSA-8cf7-32gw-wr33/GHSA-8cf7-32gw-wr33.json index 9cf58b06db7..0d23ac32272 100644 --- a/advisories/github-reviewed/2022/12/GHSA-8cf7-32gw-wr33/GHSA-8cf7-32gw-wr33.json +++ b/advisories/github-reviewed/2022/12/GHSA-8cf7-32gw-wr33/GHSA-8cf7-32gw-wr33.json @@ -1,15 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8cf7-32gw-wr33", - "modified": "2022-12-23T00:39:12Z", + "modified": "2024-06-24T21:23:38Z", "published": "2022-12-22T03:32:22Z", "aliases": [ "CVE-2022-23539" ], "summary": "jsonwebtoken unrestricted key type could lead to legacy keys usage ", - "details": "# Overview\n\nVersions `<=8.5.1` of `jsonwebtoken` library could be misconfigured so that legacy, insecure key types are used for signature verification. For example, DSA keys could be used with the RS256 algorithm. \n\n# Am I affected?\n\nYou are affected if you are using an algorithm and a key type other than the combinations mentioned below\n\n| Key type | algorithm |\n|----------|------------------------------------------|\n| ec | ES256, ES384, ES512 |\n| rsa | RS256, RS384, RS512, PS256, PS384, PS512 |\n| rsa-pss | PS256, PS384, PS512 |\n\nAnd for Elliptic Curve algorithms:\n\n| `alg` | Curve |\n|-------|------------|\n| ES256 | prime256v1 |\n| ES384 | secp384r1 |\n| ES512 | secp521r1 |\n\n# How do I fix it?\n\nUpdate to version 9.0.0. This version validates for asymmetric key type and algorithm combinations. Please refer to the above mentioned algorithm / key type combinations for the valid secure configuration. After updating to version 9.0.0, If you still intend to continue with signing or verifying tokens using invalid key type/algorithm value combinations, you’ll need to set the `allowInvalidAsymmetricKeyTypes` option to `true` in the `sign()` and/or `verify()` functions.\n\n# Will the fix impact my users?\n\nThere will be no impact, if you update to version 9.0.0 and you already use a valid secure combination of key type and algorithm. Otherwise, use the `allowInvalidAsymmetricKeyTypes` option to `true` in the `sign()` and `verify()` functions to continue usage of invalid key type/algorithm combination in 9.0.0 for legacy compatibility. \n\n", + "details": "# Overview\n\nVersions `<=8.5.1` of `jsonwebtoken` library could be misconfigured so that legacy, insecure key types are used for signature verification. For example, DSA keys could be used with the RS256 algorithm. \n\n# Am I affected?\n\nYou are affected if you are using an algorithm and a key type other than the combinations mentioned below\n\n| Key type | algorithm |\n|----------|------------------------------------------|\n| ec | ES256, ES384, ES512 |\n| rsa | RS256, RS384, RS512, PS256, PS384, PS512 |\n| rsa-pss | PS256, PS384, PS512 |\n\nAnd for Elliptic Curve algorithms:\n\n| `alg` | Curve |\n|-------|------------|\n| ES256 | prime256v1 |\n| ES384 | secp384r1 |\n| ES512 | secp521r1 |\n\n# How do I fix it?\n\nUpdate to version 9.0.0. This version validates for asymmetric key type and algorithm combinations. Please refer to the above mentioned algorithm / key type combinations for the valid secure configuration. After updating to version 9.0.0, If you still intend to continue with signing or verifying tokens using invalid key type/algorithm value combinations, you’ll need to set the `allowInvalidAsymmetricKeyTypes` option to `true` in the `sign()` and/or `verify()` functions.\n\n# Will the fix impact my users?\n\nThere will be no impact, if you update to version 9.0.0 and you already use a valid secure combination of key type and algorithm. Otherwise, use the `allowInvalidAsymmetricKeyTypes` option to `true` in the `sign()` and `verify()` functions to continue usage of invalid key type/algorithm combination in 9.0.0 for legacy compatibility. \n\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ { @@ -51,13 +54,17 @@ { "type": "PACKAGE", "url": "https://github.com/auth0/node-jsonwebtoken" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240621-0007" } ], "database_specific": { "cwe_ids": [ "CWE-327" ], - "severity": "MODERATE", + "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2022-12-22T03:32:22Z", "nvd_published_at": "2022-12-23T00:15:00Z" diff --git a/advisories/github-reviewed/2022/12/GHSA-hjrf-2m68-5959/GHSA-hjrf-2m68-5959.json b/advisories/github-reviewed/2022/12/GHSA-hjrf-2m68-5959/GHSA-hjrf-2m68-5959.json index 93edc3718f7..3d9f4dc3410 100644 --- a/advisories/github-reviewed/2022/12/GHSA-hjrf-2m68-5959/GHSA-hjrf-2m68-5959.json +++ b/advisories/github-reviewed/2022/12/GHSA-hjrf-2m68-5959/GHSA-hjrf-2m68-5959.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hjrf-2m68-5959", - "modified": "2022-12-30T00:47:06Z", + "modified": "2024-06-24T21:24:06Z", "published": "2022-12-22T03:33:19Z", "aliases": [ "CVE-2022-23541" @@ -58,10 +58,15 @@ { "type": "WEB", "url": "https://github.com/auth0/node-jsonwebtoken/releases/tag/v9.0.0" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240621-0007" } ], "database_specific": { "cwe_ids": [ + "CWE-1259", "CWE-287" ], "severity": "MODERATE", diff --git a/advisories/github-reviewed/2022/12/GHSA-r9hx-vwmv-q579/GHSA-r9hx-vwmv-q579.json b/advisories/github-reviewed/2022/12/GHSA-r9hx-vwmv-q579/GHSA-r9hx-vwmv-q579.json index fe986538ec3..f74f6b08097 100644 --- a/advisories/github-reviewed/2022/12/GHSA-r9hx-vwmv-q579/GHSA-r9hx-vwmv-q579.json +++ b/advisories/github-reviewed/2022/12/GHSA-r9hx-vwmv-q579/GHSA-r9hx-vwmv-q579.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r9hx-vwmv-q579", - "modified": "2022-12-27T14:51:05Z", + "modified": "2024-06-24T21:24:10Z", "published": "2022-12-23T00:30:23Z", "aliases": [ "CVE-2022-40897" @@ -60,6 +60,14 @@ "type": "WEB", "url": "https://github.com/pypa/setuptools/compare/v65.5.0...v65.5.1" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ADES3NLOE5QJKBLGNZNI2RGVOSQXA37R" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YNA2BAH2ACBZ4TVJZKFLCR7L23BG5C3H" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ADES3NLOE5QJKBLGNZNI2RGVOSQXA37R" @@ -80,6 +88,10 @@ "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20230214-0001" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240621-0006" + }, { "type": "WEB", "url": "https://setuptools.pypa.io/en/latest" diff --git a/advisories/github-reviewed/2023/02/GHSA-r7jw-wp68-3xch/GHSA-r7jw-wp68-3xch.json b/advisories/github-reviewed/2023/02/GHSA-r7jw-wp68-3xch/GHSA-r7jw-wp68-3xch.json index 05f74df9eca..332df7c756a 100644 --- a/advisories/github-reviewed/2023/02/GHSA-r7jw-wp68-3xch/GHSA-r7jw-wp68-3xch.json +++ b/advisories/github-reviewed/2023/02/GHSA-r7jw-wp68-3xch/GHSA-r7jw-wp68-3xch.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r7jw-wp68-3xch", - "modified": "2023-02-21T20:00:42Z", + "modified": "2024-06-24T21:24:19Z", "published": "2023-02-08T22:28:34Z", "aliases": [ "CVE-2023-0215" @@ -87,6 +87,10 @@ "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20230427-0009" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240621-0006" + }, { "type": "WEB", "url": "https://www.openssl.org/news/secadv/20230207.txt" diff --git a/advisories/github-reviewed/2023/06/GHSA-6mjq-h674-j845/GHSA-6mjq-h674-j845.json b/advisories/github-reviewed/2023/06/GHSA-6mjq-h674-j845/GHSA-6mjq-h674-j845.json index 13389ecc523..78b6092728b 100644 --- a/advisories/github-reviewed/2023/06/GHSA-6mjq-h674-j845/GHSA-6mjq-h674-j845.json +++ b/advisories/github-reviewed/2023/06/GHSA-6mjq-h674-j845/GHSA-6mjq-h674-j845.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6mjq-h674-j845", - "modified": "2023-06-23T13:56:06Z", + "modified": "2024-06-24T21:24:21Z", "published": "2023-06-20T16:33:22Z", "aliases": [ "CVE-2023-34462" @@ -56,6 +56,10 @@ "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20230803-0001" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240621-0007" + }, { "type": "WEB", "url": "https://www.debian.org/security/2023/dsa-5558" diff --git a/advisories/github-reviewed/2023/07/GHSA-cggh-pq45-6h9x/GHSA-cggh-pq45-6h9x.json b/advisories/github-reviewed/2023/07/GHSA-cggh-pq45-6h9x/GHSA-cggh-pq45-6h9x.json index c323858b47e..f808bef0af1 100644 --- a/advisories/github-reviewed/2023/07/GHSA-cggh-pq45-6h9x/GHSA-cggh-pq45-6h9x.json +++ b/advisories/github-reviewed/2023/07/GHSA-cggh-pq45-6h9x/GHSA-cggh-pq45-6h9x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cggh-pq45-6h9x", - "modified": "2023-07-11T22:45:02Z", + "modified": "2024-06-24T21:25:02Z", "published": "2023-07-01T00:30:46Z", "aliases": [ "CVE-2023-30589" @@ -79,6 +79,10 @@ { "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20230803-0009" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240621-0006" } ], "database_specific": {