From efedee73b8c402e32f632ce4f3ace8252ff0aa33 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 16 Sep 2024 14:30:36 +0000 Subject: [PATCH] Publish Advisories GHSA-8p5c-f328-9fvv GHSA-pg2f-r7pc-6fxx GHSA-j8fq-86c5-5v2r GHSA-5v8v-66v8-mwm7 GHSA-hwqr-f3v9-hwxr GHSA-5c8p-qhch-qhx6 GHSA-547x-748v-vp6p --- .../GHSA-8p5c-f328-9fvv.json | 18 ++++++++- .../GHSA-pg2f-r7pc-6fxx.json | 18 ++++++++- .../GHSA-j8fq-86c5-5v2r.json | 26 +++++++++---- .../GHSA-5v8v-66v8-mwm7.json | 37 ++++++++++++++++++- .../GHSA-hwqr-f3v9-hwxr.json | 29 +++++++++++++-- .../GHSA-5c8p-qhch-qhx6.json | 6 ++- .../GHSA-547x-748v-vp6p.json | 6 ++- 7 files changed, 123 insertions(+), 17 deletions(-) diff --git a/advisories/github-reviewed/2018/07/GHSA-8p5c-f328-9fvv/GHSA-8p5c-f328-9fvv.json b/advisories/github-reviewed/2018/07/GHSA-8p5c-f328-9fvv/GHSA-8p5c-f328-9fvv.json index fc9c78a47f6..bbdf19c67d6 100644 --- a/advisories/github-reviewed/2018/07/GHSA-8p5c-f328-9fvv/GHSA-8p5c-f328-9fvv.json +++ b/advisories/github-reviewed/2018/07/GHSA-8p5c-f328-9fvv/GHSA-8p5c-f328-9fvv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8p5c-f328-9fvv", - "modified": "2022-04-26T18:15:07Z", + "modified": "2024-09-16T13:49:58Z", "published": "2018-07-13T16:01:21Z", "aliases": [ "CVE-2017-0359" @@ -12,6 +12,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" } ], "affected": [ @@ -55,14 +59,26 @@ "type": "WEB", "url": "https://github.com/anthraxx/diffoscope/commit/f379d1f611dbd5d361e12b732e07c8aee45ff226" }, + { + "type": "WEB", + "url": "https://bugs.debian.org/854723" + }, { "type": "WEB", "url": "https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=854723" }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-8p5c-f328-9fvv" + }, { "type": "PACKAGE", "url": "https://github.com/anthraxx/diffoscope" }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/diffoscope/PYSEC-2018-83.yaml" + }, { "type": "WEB", "url": "https://security-tracker.debian.org/tracker/CVE-2017-0359" diff --git a/advisories/github-reviewed/2019/09/GHSA-pg2f-r7pc-6fxx/GHSA-pg2f-r7pc-6fxx.json b/advisories/github-reviewed/2019/09/GHSA-pg2f-r7pc-6fxx/GHSA-pg2f-r7pc-6fxx.json index a53eacf8472..42bc7c23414 100644 --- a/advisories/github-reviewed/2019/09/GHSA-pg2f-r7pc-6fxx/GHSA-pg2f-r7pc-6fxx.json +++ b/advisories/github-reviewed/2019/09/GHSA-pg2f-r7pc-6fxx/GHSA-pg2f-r7pc-6fxx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pg2f-r7pc-6fxx", - "modified": "2021-08-17T22:19:46Z", + "modified": "2024-09-16T13:44:56Z", "published": "2019-09-11T22:57:57Z", "aliases": [ "CVE-2019-11457" @@ -12,6 +12,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" } ], "affected": [ @@ -40,6 +44,18 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-11457" }, + { + "type": "PACKAGE", + "url": "https://github.com/MicroPyramid/Django-CRM" + }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-pg2f-r7pc-6fxx" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/django-crm/PYSEC-2019-174.yaml" + }, { "type": "WEB", "url": "https://www.netsparker.com/blog/web-security" diff --git a/advisories/github-reviewed/2021/10/GHSA-j8fq-86c5-5v2r/GHSA-j8fq-86c5-5v2r.json b/advisories/github-reviewed/2021/10/GHSA-j8fq-86c5-5v2r/GHSA-j8fq-86c5-5v2r.json index ae759eb0ee4..b4302a8b569 100644 --- a/advisories/github-reviewed/2021/10/GHSA-j8fq-86c5-5v2r/GHSA-j8fq-86c5-5v2r.json +++ b/advisories/github-reviewed/2021/10/GHSA-j8fq-86c5-5v2r/GHSA-j8fq-86c5-5v2r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j8fq-86c5-5v2r", - "modified": "2022-03-21T19:58:43Z", + "modified": "2024-09-16T13:56:48Z", "published": "2021-10-27T18:53:48Z", "aliases": [ "CVE-2021-42343" @@ -12,19 +12,17 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" } ], "affected": [ { "package": { "ecosystem": "PyPI", - "name": "distributed" - }, - "ecosystem_specific": { - "affected_functions": [ - "dask.distributed.LocalCluster", - "dask.distributed.Client" - ] + "name": "dask" }, "ranges": [ { @@ -62,9 +60,21 @@ "type": "WEB", "url": "https://docs.dask.org/en/latest/changelog.html" }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-j8fq-86c5-5v2r" + }, + { + "type": "WEB", + "url": "https://github.com/dask/dask/tags" + }, { "type": "PACKAGE", "url": "https://github.com/dask/distributed" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/dask/PYSEC-2021-387.yaml" } ], "database_specific": { diff --git a/advisories/github-reviewed/2022/05/GHSA-5v8v-66v8-mwm7/GHSA-5v8v-66v8-mwm7.json b/advisories/github-reviewed/2022/05/GHSA-5v8v-66v8-mwm7/GHSA-5v8v-66v8-mwm7.json index 33067b6ffa1..5a190a23f39 100644 --- a/advisories/github-reviewed/2022/05/GHSA-5v8v-66v8-mwm7/GHSA-5v8v-66v8-mwm7.json +++ b/advisories/github-reviewed/2022/05/GHSA-5v8v-66v8-mwm7/GHSA-5v8v-66v8-mwm7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5v8v-66v8-mwm7", - "modified": "2022-06-16T23:47:42Z", + "modified": "2024-09-16T13:48:46Z", "published": "2022-05-24T17:28:21Z", "aliases": [ "CVE-2020-8927" @@ -12,6 +12,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N" } ], "affected": [ @@ -2826,6 +2830,25 @@ ] } ] + }, + { + "package": { + "ecosystem": "PyPI", + "name": "brotli" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.0.8" + } + ] + } + ] } ], "references": [ @@ -2841,6 +2864,10 @@ "type": "WEB", "url": "https://github.com/github/advisory-database/issues/785" }, + { + "type": "WEB", + "url": "https://github.com/google/brotli/commit/223d80cfbec8fd346e32906c732c8ede21f0cea6" + }, { "type": "WEB", "url": "https://www.debian.org/security/2020/dsa-4801" @@ -2897,10 +2924,18 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2020/12/msg00003.html" }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/brotli/PYSEC-2020-29.yaml" + }, { "type": "WEB", "url": "https://github.com/google/brotli/releases/tag/v1.0.9" }, + { + "type": "WEB", + "url": "https://github.com/google/brotli/releases/tag/v1.0.8" + }, { "type": "PACKAGE", "url": "https://github.com/bitemyapp/brotli2-rs" diff --git a/advisories/github-reviewed/2022/07/GHSA-hwqr-f3v9-hwxr/GHSA-hwqr-f3v9-hwxr.json b/advisories/github-reviewed/2022/07/GHSA-hwqr-f3v9-hwxr/GHSA-hwqr-f3v9-hwxr.json index 032af7d4484..929b4ba2ee5 100644 --- a/advisories/github-reviewed/2022/07/GHSA-hwqr-f3v9-hwxr/GHSA-hwqr-f3v9-hwxr.json +++ b/advisories/github-reviewed/2022/07/GHSA-hwqr-f3v9-hwxr/GHSA-hwqr-f3v9-hwxr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hwqr-f3v9-hwxr", - "modified": "2022-07-15T21:56:08Z", + "modified": "2024-09-16T13:56:39Z", "published": "2022-07-15T21:56:08Z", "aliases": [ @@ -9,7 +9,14 @@ "summary": "Workers for local Dask clusters mistakenly listened on public interfaces", "details": "Versions of `distributed` earlier than `2021.10.0` had a potential security vulnerability relating to single-machine Dask clusters.\n\nClusters started with `dask.distributed.LocalCluster` or `dask.distributed.Client()` (which defaults to using `LocalCluster`) would mistakenly configure their respective Dask workers to listen on external interfaces (typically with a randomly selected high port) rather than only on `localhost`. A Dask cluster created using this method AND running on a machine that has these ports exposed could be used by a sophisticated attacker to enable remote code execution. Users running on machines with standard firewalls in place, or using clusters created via cluster objects other than `LocalCluster` (e.g. `dask_kubernetes.KubeCluster`) should not be affected. This vulnerability is documented in CVE-2021-42343, and was fixed in version `2021.10.0` (PR #5427).", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" + } ], "affected": [ { @@ -17,6 +24,12 @@ "ecosystem": "PyPI", "name": "distributed" }, + "ecosystem_specific": { + "affected_functions": [ + "dask.distributed.LocalCluster", + "dask.distributed.Client" + ] + }, "ranges": [ { "type": "ECOSYSTEM", @@ -37,6 +50,14 @@ "type": "WEB", "url": "https://github.com/dask/distributed/security/advisories/GHSA-hwqr-f3v9-hwxr" }, + { + "type": "WEB", + "url": "https://github.com/dask/distributed/pull/5427" + }, + { + "type": "WEB", + "url": "https://github.com/dask/distributed/commit/afce4be8e05fb180e50a9d9e38465f1a82295e1b" + }, { "type": "WEB", "url": "https://docs.dask.org/en/latest/changelog.html" @@ -64,9 +85,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-668" ], - "severity": "MODERATE", + "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2022-07-15T21:56:08Z", "nvd_published_at": null diff --git a/advisories/github-reviewed/2022/08/GHSA-5c8p-qhch-qhx6/GHSA-5c8p-qhch-qhx6.json b/advisories/github-reviewed/2022/08/GHSA-5c8p-qhch-qhx6/GHSA-5c8p-qhch-qhx6.json index 6cad70f7525..9a4281d5684 100644 --- a/advisories/github-reviewed/2022/08/GHSA-5c8p-qhch-qhx6/GHSA-5c8p-qhch-qhx6.json +++ b/advisories/github-reviewed/2022/08/GHSA-5c8p-qhch-qhx6/GHSA-5c8p-qhch-qhx6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5c8p-qhch-qhx6", - "modified": "2022-09-01T22:19:29Z", + "modified": "2024-09-16T13:50:34Z", "published": "2022-08-27T00:00:44Z", "aliases": [ "CVE-2021-3427" @@ -12,6 +12,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N" } ], "affected": [ diff --git a/advisories/github-reviewed/2024/02/GHSA-547x-748v-vp6p/GHSA-547x-748v-vp6p.json b/advisories/github-reviewed/2024/02/GHSA-547x-748v-vp6p/GHSA-547x-748v-vp6p.json index 8f7a6b81641..1d0607b9c34 100644 --- a/advisories/github-reviewed/2024/02/GHSA-547x-748v-vp6p/GHSA-547x-748v-vp6p.json +++ b/advisories/github-reviewed/2024/02/GHSA-547x-748v-vp6p/GHSA-547x-748v-vp6p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-547x-748v-vp6p", - "modified": "2024-03-06T16:21:30Z", + "modified": "2024-09-16T13:44:03Z", "published": "2024-02-02T06:30:31Z", "aliases": [ "CVE-2024-21485" @@ -12,6 +12,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N" } ], "affected": [