Publish Advisories

GHSA-c476-j253-5rgq
GHSA-h5jh-rp76-q242
GHSA-qq5h-rjj9-q9qg
GHSA-v664-qgx9-wf79
GHSA-v664-qgx9-wf79
This commit is contained in:
advisory-database[bot]
2025-01-29 19:21:46 +00:00
parent a011dc728c
commit ee77ada6f0
5 changed files with 162 additions and 55 deletions
@@ -1,11 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c476-j253-5rgq",
"modified": "2025-01-29T15:31:34Z",
"modified": "2025-01-29T19:20:08Z",
"published": "2025-01-29T00:31:54Z",
"aliases": [
"CVE-2024-29869"
],
"summary": "Apache Hive Incorrectly Assigns Permissions for a Critical Resource",
"details": "Hive creates a credentials file to a temporary directory in the file system with permissions 644 by default when the file permissions are not set explicitly. Any unauthorized user having access to the directory can read the sensitive information written into this file. Users are recommended to upgrade to version 4.0.1, which fixes this issue.",
"severity": [
{
@@ -13,7 +14,27 @@
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [],
"affected": [
{
"package": {
"ecosystem": "Maven",
"name": "org.apache.hive:hive-exec"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "4.0.1"
}
]
}
]
}
],
"references": [
{
"type": "ADVISORY",
@@ -24,7 +45,7 @@
"url": "https://github.com/apache/hive/commit/20106e254527f7d71b2e34455c4322e14950c620"
},
{
"type": "WEB",
"type": "PACKAGE",
"url": "https://github.com/apache/hive"
},
{
@@ -45,8 +66,8 @@
"CWE-732"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"github_reviewed": true,
"github_reviewed_at": "2025-01-29T19:20:08Z",
"nvd_published_at": "2025-01-28T22:15:15Z"
}
}
@@ -1,21 +1,47 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h5jh-rp76-q242",
"modified": "2025-01-29T15:31:35Z",
"modified": "2025-01-29T19:20:33Z",
"published": "2025-01-29T15:31:35Z",
"aliases": [
"CVE-2024-57438"
],
"summary": "RuoYi has insecure permissions",
"details": "Insecure permissions in RuoYi v4.8.0 allows authenticated attackers to escalate privileges by assigning themselves higher level roles.",
"severity": [],
"affected": [],
"severity": [
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P"
}
],
"affected": [
{
"package": {
"ecosystem": "Maven",
"name": "com.ruoyi:ruoyi"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"last_affected": "4.8.0"
}
]
}
]
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57438"
},
{
"type": "WEB",
"type": "PACKAGE",
"url": "https://gitee.com/y_project/RuoYi"
},
{
@@ -32,10 +58,12 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"cwe_ids": [
"CWE-276"
],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2025-01-29T19:20:33Z",
"nvd_published_at": "2025-01-29T15:15:17Z"
}
}
@@ -1,11 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qq5h-rjj9-q9qg",
"modified": "2025-01-29T18:31:22Z",
"modified": "2025-01-29T19:20:35Z",
"published": "2025-01-29T15:31:35Z",
"aliases": [
"CVE-2024-57439"
],
"summary": "RuoYi vulnerable to Denial of Service by attackers with admin privileges",
"details": "An issue in the reset password interface of ruoyi v4.8.0 allows attackers with Admin privileges to cause a Denial of Service (DoS) by duplicating the login name of the account.",
"severity": [
{
@@ -13,14 +14,34 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [],
"affected": [
{
"package": {
"ecosystem": "Maven",
"name": "com.ruoyi:ruoyi"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"last_affected": "4.8.0"
}
]
}
]
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57439"
},
{
"type": "WEB",
"type": "PACKAGE",
"url": "https://gitee.com/y_project/RuoYi"
},
{
@@ -41,8 +62,8 @@
"CWE-281"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"github_reviewed": true,
"github_reviewed_at": "2025-01-29T19:20:35Z",
"nvd_published_at": "2025-01-29T15:15:17Z"
}
}
@@ -0,0 +1,74 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v664-qgx9-wf79",
"modified": "2025-01-29T19:20:31Z",
"published": "2025-01-29T15:31:35Z",
"aliases": [
"CVE-2024-57436"
],
"summary": "RuoYi allowed unauthorized attackers to view the session ID of the admin in the system monitoring",
"details": "RuoYi v4.8.0 was discovered to allow unauthorized attackers to view the session ID of the admin in the system monitoring. This issue can allow attackers to impersonate Admin users via using a crafted cookie.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:P"
}
],
"affected": [
{
"package": {
"ecosystem": "Maven",
"name": "com.ruoyi:ruoyi"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"last_affected": "4.8.0"
}
]
}
]
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57436"
},
{
"type": "PACKAGE",
"url": "https://gitee.com/y_project/RuoYi"
},
{
"type": "WEB",
"url": "https://github.com/peccc/restful_vul/blob/main/ruoyi_elevation_of_privileges/ruoyi_elevation_of_privileges.md"
},
{
"type": "WEB",
"url": "https://github.com/yangzongzhuan/RuoYi"
},
{
"type": "WEB",
"url": "https://ruoyi.vip"
}
],
"database_specific": {
"cwe_ids": [
"CWE-200",
"CWE-922"
],
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2025-01-29T19:20:31Z",
"nvd_published_at": "2025-01-29T15:15:17Z"
}
}
@@ -1,37 +0,0 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v664-qgx9-wf79",
"modified": "2025-01-29T15:31:35Z",
"published": "2025-01-29T15:31:35Z",
"aliases": [
"CVE-2024-57436"
],
"details": "RuoYi v4.8.0 was discovered to allow unauthorized attackers to view the session ID of the admin in the system monitoring. This issue can allow attackers to impersonate Admin users via using a crafted cookie.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57436"
},
{
"type": "WEB",
"url": "https://github.com/peccc/restful_vul/blob/main/ruoyi_elevation_of_privileges/ruoyi_elevation_of_privileges.md"
},
{
"type": "WEB",
"url": "https://github.com/yangzongzhuan/RuoYi"
},
{
"type": "WEB",
"url": "https://ruoyi.vip"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-29T15:15:17Z"
}
}