Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2024-11-28 05:06:42 +00:00
parent 0b181b9109
commit e6472b93b4
938 changed files with 1562 additions and 4666 deletions
@@ -8,9 +8,7 @@
],
"summary": "Apache Tomcat Default Installation Reveals Sensitive Information",
"details": "The default installation of Apache Tomcat 4.0 through 4.1 and 3.0 through 3.3.1 allows remote attackers to obtain the installation path and other sensitive system information via the (1) SnoopServlet or (2) TroubleShooter example servlets.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -90,9 +88,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "LOW",
"github_reviewed": true,
"github_reviewed_at": "2024-02-12T20:18:08Z",
@@ -8,9 +8,7 @@
],
"summary": "Apache Tomcat Source Code Disclosure",
"details": "Apache Tomcat 4.0.5 and earlier, when using both the invoker servlet and the default servlet, allows remote attackers to read source code for server files or bypass certain protections, a variant of CAN-2002-1148.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -8,9 +8,7 @@
],
"summary": "Apache Tomcat Source Code Disclosure",
"details": "The default servlet (`org.apache.catalina.servlets.DefaultServlet`) in Tomcat 4.0.4 and 4.1.10 and earlier allows remote attackers to read source code for server files via a direct request to the servlet.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -8,9 +8,7 @@
],
"summary": "Apache Tomcat may be started without proper security settings",
"details": "Apache Tomcat may be started without proper security settings if errors are encountered while reading the `web.xml` file, which could allow attackers to bypass intended restrictions.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -8,9 +8,7 @@
],
"summary": "OpenStack Nova Router metadata queries are not restricted by tenant",
"details": "Interaction error in OpenStack Nova and Neutron before Havana 2013.2.1 and icehouse-1 does not validate the instance ID of the tenant making a request, which allows remote tenants to obtain sensitive metadata by spoofing the device ID that is bound to a port, which is not properly handled by (1) api/metadata/handler.py in Nova and (2) the neutron-metadata-agent (`agent/metadata/agent.py`) in Neutron.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -8,9 +8,7 @@
],
"summary": "OpenStack Compute Nova Improper Access Control",
"details": "The XenAPI backend in OpenStack Compute (Nova) Folsom, Grizzly, and Havana before 2013.2 does not properly apply security groups (1) when resizing an image or (2) during live migration, which allows remote attackers to bypass intended restrictions.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -75,9 +73,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-05-14T21:27:12Z",
@@ -8,9 +8,7 @@
],
"summary": "OpenStack Compute (Nova) Denial of service due to improper validation of virtual size of QCOW2 image",
"details": "OpenStack Compute (Nova) Folsom, Grizzly, and Havana, when use_cow_images is set to False, does not verify the virtual size of a QCOW2 image, which allows local users to cause a denial of service (host file system disk consumption) by transferring an image with a large virtual size that does not contain a large amount of data from Glance. NOTE: this issue is due to an incomplete fix for CVE-2013-2096.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -67,9 +65,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "LOW",
"github_reviewed": true,
"github_reviewed_at": "2024-05-14T21:14:01Z",
@@ -8,9 +8,7 @@
],
"summary": "OpenStack Compute (Nova) Resource limit circumvention in Nova private flavors",
"details": "The \"create an instance\" API in OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not properly enforce the os-flavor-access:is_public property, which allows remote authenticated users to boot arbitrary flavors by guessing the flavor id. NOTE: this issue is due to an incomplete fix for CVE-2013-2256.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -67,9 +65,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "LOW",
"github_reviewed": true,
"github_reviewed_at": "2024-05-14T21:27:13Z",
@@ -8,9 +8,7 @@
],
"summary": "OpenStack Glance improper validation of the image_size_cap configuration option",
"details": "OpenStack Image Registry and Delivery Service (Glance) before 2013.2.4, 2014.x before 2014.1.3, and Juno before Juno-3, when using the V2 API, does not properly enforce the image_size_cap configuration option, which allows remote authenticated users to cause a denial of service (disk consumption) by uploading a large image.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -83,9 +81,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-05-14T21:32:14Z",
@@ -8,9 +8,7 @@
],
"summary": "OpenStack Nova denial of service through compressed disk images",
"details": "OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not properly verify the virtual size of a QCOW2 image, which allows local users to cause a denial of service (host file system disk consumption) via a compressed QCOW2 image. NOTE: this issue is due to an incomplete fix for CVE-2013-2096.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -67,9 +65,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "LOW",
"github_reviewed": true,
"github_reviewed_at": "2024-05-14T21:13:58Z",
@@ -8,9 +8,7 @@
],
"summary": "OpenStack Cinder file disclosure in image convert",
"details": "OpenStack Cinder before 2014.1.5 (icehouse), 2014.2.x before 2014.2.4 (juno), and 2015.1.x before 2015.1.1 (kilo) allows remote authenticated users to read arbitrary files via a crafted qcow2 signature in an image to the upload-to-image command.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -120,9 +120,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2024-05-14T21:08:44Z",
@@ -8,9 +8,7 @@
],
"summary": "OpenStack Swift Unchecked user input in XML responses",
"details": "XML injection vulnerability in account/utils.py in OpenStack Swift Folsom, Grizzly, and Havana allows attackers to trigger invalid or spoofed Swift responses via an account name.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -8,9 +8,7 @@
],
"summary": "OpenStack Glance is vulnerable to Exposure of Sensitive Information",
"details": "The v1 API in OpenStack Glance Essex (2012.1), Folsom (2012.2), and Grizzly, when using the single-tenant Swift or S3 store, reports the location field, which allows remote authenticated users to obtain the operator's backend credentials via a request for a cached image.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -8,9 +8,7 @@
],
"summary": "MoinMoin Improper ACL handling for calendars and includes",
"details": "MoinMoin before 20070507 does not properly enforce ACLs for calendars and includes, which allows remote attackers to read certain pages via unspecified vectors.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -67,9 +65,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-05-14T20:41:20Z",
@@ -8,9 +8,7 @@
],
"summary": "OpenStack Nova VMware instance leak potentially leading to compute DoS",
"details": "The VMware driver in OpenStack Compute (Nova) before 2014.1.4 allows remote authenticated users to cause a denial of service (disk consumption) by deleting an instance in the resize state.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -71,9 +69,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-05-14T21:14:03Z",
@@ -8,9 +8,7 @@
],
"summary": "OpenStack Swift metadata constraints are not correctly enforced",
"details": "OpenStack Object Storage (Swift) before 2.2.0 allows remote authenticated users to bypass the max_meta_count and other metadata constraints via multiple crafted requests which exceed the limit when combined.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -99,9 +97,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-05-14T21:30:43Z",
@@ -8,9 +8,7 @@
],
"summary": "OpenStack Neutron Race condition vulnerability",
"details": "Race condition in OpenStack Neutron before 2014.2.4 and 2015.1 before 2015.1.2, when using the ML2 plugin or the security groups AMQP API, allows remote authenticated users to bypass IP anti-spoofing controls by changing the device owner of a port to start with network: before the security group rules are applied.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -8,9 +8,7 @@
],
"summary": "MoinMoin Improper Access Control ",
"details": "`_macro_Getval` in `wikimacro.py` in MoinMoin 1.5.8 and earlier does not properly enforce ACLs, which allows remote attackers to read protected pages. The issue has been fixed on [4a7de0173734](http://hg.moinmo.in/moin/1.5/rev/4a7de0173734).",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -91,9 +89,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-05-14T20:41:37Z",
@@ -8,9 +8,7 @@
],
"summary": "OpenStack Nova Long server names grow nova-api log files significantly",
"details": "OpenStack Compute (Nova) Essex before 2011.3 allows remote authenticated users to cause a denial of service (Nova-API log file and disk consumption) via a long server name.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -71,9 +69,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-05-14T21:27:08Z",

Some files were not shown because too many files have changed in this diff Show More