From f1039eb72c003aa05128d928913aeb47d0beba2f Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 5 Jun 2024 17:13:28 +0000 Subject: [PATCH] Publish Advisories GHSA-hrmr-f5m6-m9pq GHSA-cr6f-gf5w-vhrc GHSA-m87m-mmvp-v9qm GHSA-qr5f-6fcv-w69q GHSA-m87m-mmvp-v9qm --- .../GHSA-hrmr-f5m6-m9pq.json | 108 +++++++++--------- .../GHSA-cr6f-gf5w-vhrc.json | 5 +- .../GHSA-m87m-mmvp-v9qm.json | 69 +++++++++++ .../GHSA-qr5f-6fcv-w69q.json | 77 +++++++++++++ .../GHSA-m87m-mmvp-v9qm.json | 38 ------ 5 files changed, 205 insertions(+), 92 deletions(-) create mode 100644 advisories/github-reviewed/2024/06/GHSA-m87m-mmvp-v9qm/GHSA-m87m-mmvp-v9qm.json create mode 100644 advisories/github-reviewed/2024/06/GHSA-qr5f-6fcv-w69q/GHSA-qr5f-6fcv-w69q.json delete mode 100644 advisories/unreviewed/2024/06/GHSA-m87m-mmvp-v9qm/GHSA-m87m-mmvp-v9qm.json diff --git a/advisories/github-reviewed/2018/10/GHSA-hrmr-f5m6-m9pq/GHSA-hrmr-f5m6-m9pq.json b/advisories/github-reviewed/2018/10/GHSA-hrmr-f5m6-m9pq/GHSA-hrmr-f5m6-m9pq.json index 368f39fd15a..6c5256745bd 100644 --- a/advisories/github-reviewed/2018/10/GHSA-hrmr-f5m6-m9pq/GHSA-hrmr-f5m6-m9pq.json +++ b/advisories/github-reviewed/2018/10/GHSA-hrmr-f5m6-m9pq/GHSA-hrmr-f5m6-m9pq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hrmr-f5m6-m9pq", - "modified": "2022-02-08T22:08:23Z", + "modified": "2024-06-05T17:11:42Z", "published": "2018-10-19T16:41:27Z", "aliases": [ "CVE-2018-11771" @@ -25,7 +25,7 @@ "type": "ECOSYSTEM", "events": [ { - "introduced": "0" + "introduced": "1.7" }, { "fixed": "1.18" @@ -42,55 +42,7 @@ }, { "type": "WEB", - "url": "https://lists.apache.org/thread.html/0adb631517766e793e18a59723e2df08ced41eb9a57478f14781c9f7@%3Cdev.tinkerpop.apache.org%3E" - }, - { - "type": "WEB", - "url": "https://lists.apache.org/thread.html/3565494c263dfeb4dcb2a71cb24d09a1ca285cd6ac74edc025a3af8a@%3Ccommits.tinkerpop.apache.org%3E" - }, - { - "type": "WEB", - "url": "https://lists.apache.org/thread.html/35f60d6d0407c13c39411038ba1aca71d92595ed7041beff4d07f2ee@%3Ccommits.tinkerpop.apache.org%3E" - }, - { - "type": "WEB", - "url": "https://lists.apache.org/thread.html/6c79965066c30d4e330e04d911d3761db41b82c89ae38d9a6b37a6f1@%3Cdev.tinkerpop.apache.org%3E" - }, - { - "type": "WEB", - "url": "https://lists.apache.org/thread.html/714c6ac1b1b50f8557e7342903ef45f1538a7bc60a0b47d6e48c273d@%3Ccommits.tinkerpop.apache.org%3E" - }, - { - "type": "WEB", - "url": "https://lists.apache.org/thread.html/b8da751fc0ca949534cdf2744111da6bb0349d2798fac94b0a50f330@%3Cannounce.apache.org%3E" - }, - { - "type": "WEB", - "url": "https://lists.apache.org/thread.html/b8ef29df0f1d55aa741170748352ae8e425c7b1d286b2f257711a2dd@%3Cdev.creadur.apache.org%3E" - }, - { - "type": "WEB", - "url": "https://lists.apache.org/thread.html/b907e70bc422905d7962fd18f863f746bf7b4e7ed9da25c148580c61@%3Cnotifications.commons.apache.org%3E" - }, - { - "type": "WEB", - "url": "https://lists.apache.org/thread.html/c7954dc1e8fafd7ca1449f078953b419ebf8936e087f235f3bd024be@%3Ccommits.tinkerpop.apache.org%3E" - }, - { - "type": "WEB", - "url": "https://lists.apache.org/thread.html/e3eae9e6fc021c4c22dda59a335d21c12eecab480b48115a2f098ef6@%3Ccommits.tinkerpop.apache.org%3E" - }, - { - "type": "WEB", - "url": "https://lists.apache.org/thread.html/eeecc1669242b28a3777ae13c68b376b0148d589d3d8170340d61120@%3Cdev.tinkerpop.apache.org%3E" - }, - { - "type": "WEB", - "url": "https://lists.apache.org/thread.html/f28052d04cb8dbaae39bfd3dc8438e58c2a8be306a3f381f4728d7c1@%3Ccommits.commons.apache.org%3E" - }, - { - "type": "WEB", - "url": "https://lists.apache.org/thread.html/f9cdd32af7d73e943452167d15801db39e8130409ebb9efb243b3f41@%3Ccommits.tinkerpop.apache.org%3E" + "url": "https://www.oracle.com/security-alerts/cpujan2022.html" }, { "type": "WEB", @@ -98,7 +50,59 @@ }, { "type": "WEB", - "url": "https://www.oracle.com/security-alerts/cpujan2022.html" + "url": "https://lists.apache.org/thread.html/f9cdd32af7d73e943452167d15801db39e8130409ebb9efb243b3f41@%3Ccommits.tinkerpop.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/f28052d04cb8dbaae39bfd3dc8438e58c2a8be306a3f381f4728d7c1@%3Ccommits.commons.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/eeecc1669242b28a3777ae13c68b376b0148d589d3d8170340d61120@%3Cdev.tinkerpop.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/e3eae9e6fc021c4c22dda59a335d21c12eecab480b48115a2f098ef6@%3Ccommits.tinkerpop.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/c7954dc1e8fafd7ca1449f078953b419ebf8936e087f235f3bd024be@%3Ccommits.tinkerpop.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/b907e70bc422905d7962fd18f863f746bf7b4e7ed9da25c148580c61@%3Cnotifications.commons.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/b8ef29df0f1d55aa741170748352ae8e425c7b1d286b2f257711a2dd@%3Cdev.creadur.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/b8da751fc0ca949534cdf2744111da6bb0349d2798fac94b0a50f330@%3Cannounce.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/714c6ac1b1b50f8557e7342903ef45f1538a7bc60a0b47d6e48c273d@%3Ccommits.tinkerpop.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/6c79965066c30d4e330e04d911d3761db41b82c89ae38d9a6b37a6f1@%3Cdev.tinkerpop.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/35f60d6d0407c13c39411038ba1aca71d92595ed7041beff4d07f2ee@%3Ccommits.tinkerpop.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/3565494c263dfeb4dcb2a71cb24d09a1ca285cd6ac74edc025a3af8a@%3Ccommits.tinkerpop.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/0adb631517766e793e18a59723e2df08ced41eb9a57478f14781c9f7@%3Cdev.tinkerpop.apache.org%3E" + }, + { + "type": "PACKAGE", + "url": "https://github.com/apache/commons-compress" }, { "type": "WEB", diff --git a/advisories/github-reviewed/2024/04/GHSA-cr6f-gf5w-vhrc/GHSA-cr6f-gf5w-vhrc.json b/advisories/github-reviewed/2024/04/GHSA-cr6f-gf5w-vhrc/GHSA-cr6f-gf5w-vhrc.json index f8500595494..e3bd29f2cc3 100644 --- a/advisories/github-reviewed/2024/04/GHSA-cr6f-gf5w-vhrc/GHSA-cr6f-gf5w-vhrc.json +++ b/advisories/github-reviewed/2024/04/GHSA-cr6f-gf5w-vhrc/GHSA-cr6f-gf5w-vhrc.json @@ -1,13 +1,14 @@ { "schema_version": "1.4.0", "id": "GHSA-cr6f-gf5w-vhrc", - "modified": "2024-06-05T16:54:51Z", + "modified": "2024-06-05T17:11:58Z", "published": "2024-04-06T06:31:08Z", + "withdrawn": "2024-06-05T17:11:58Z", "aliases": [ ], "summary": "PyMongo Out-of-bounds Read in the bson module ", - "details": "Versions of the package pymongo before 4.6.3 are vulnerable to Out-of-bounds Read in the bson module. Using the crafted payload the attacker could force the parser to deserialize unmanaged memory. The parser tries to interpret bytes next to buffer and throws an exception with string. If the following bytes are not printable UTF-8 the parser throws an exception with a single byte.\n\nThis advisory was initially published as CVE-2024-21506, which has since been rejected as a duplicate. The underlying vulnerability is valid and so this advisory has not been withdrawn.", + "details": "Versions of the package pymongo before 4.6.3 are vulnerable to Out-of-bounds Read in the bson module. Using the crafted payload the attacker could force the parser to deserialize unmanaged memory. The parser tries to interpret bytes next to buffer and throws an exception with string. If the following bytes are not printable UTF-8 the parser throws an exception with a single byte.\n\nThis advisory was initially published as CVE-2024-21506, which has since been rejected as a duplicate of CVE-2024-5629.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2024/06/GHSA-m87m-mmvp-v9qm/GHSA-m87m-mmvp-v9qm.json b/advisories/github-reviewed/2024/06/GHSA-m87m-mmvp-v9qm/GHSA-m87m-mmvp-v9qm.json new file mode 100644 index 00000000000..343d60c6bef --- /dev/null +++ b/advisories/github-reviewed/2024/06/GHSA-m87m-mmvp-v9qm/GHSA-m87m-mmvp-v9qm.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m87m-mmvp-v9qm", + "modified": "2024-06-05T17:10:59Z", + "published": "2024-06-05T15:30:39Z", + "aliases": [ + "CVE-2024-5629" + ], + "summary": "PyMongo Out-of-bounds Read in the bson module ", + "details": "Versions of the package pymongo before 4.6.3 are vulnerable to Out-of-bounds Read in the bson module. Using the crafted payload the attacker could force the parser to deserialize unmanaged memory. The parser tries to interpret bytes next to buffer and throws an exception with string. If the following bytes are not printable UTF-8 the parser throws an exception with a single byte.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:L" + } + ], + "affected": [ + { + "package": { + "ecosystem": "PyPI", + "name": "pymongo" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.6.3" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5629" + }, + { + "type": "WEB", + "url": "https://github.com/mongodb/mongo-python-driver/commit/56b6b6dbc267d365d97c037082369dabf37405d2" + }, + { + "type": "WEB", + "url": "https://gist.github.com/keltecc/62a7c2bf74a997d0a7b48a0ff3853a03" + }, + { + "type": "WEB", + "url": "https://jira.mongodb.org/browse/PYTHON-4305" + }, + { + "type": "WEB", + "url": "https://security.snyk.io/vuln/SNYK-PYTHON-PYMONGO-6370597" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-06-05T17:10:59Z", + "nvd_published_at": "2024-06-05T15:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/06/GHSA-qr5f-6fcv-w69q/GHSA-qr5f-6fcv-w69q.json b/advisories/github-reviewed/2024/06/GHSA-qr5f-6fcv-w69q/GHSA-qr5f-6fcv-w69q.json new file mode 100644 index 00000000000..ab563782768 --- /dev/null +++ b/advisories/github-reviewed/2024/06/GHSA-qr5f-6fcv-w69q/GHSA-qr5f-6fcv-w69q.json @@ -0,0 +1,77 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qr5f-6fcv-w69q", + "modified": "2024-06-05T17:12:58Z", + "published": "2024-06-05T17:12:58Z", + "aliases": [ + + ], + "summary": "Typo3 Security Misconfiguration in Frontend Session Handling", + "details": "It has been discovered session data of properly authenticated and logged in frontend users is kept and transformed into an anonymous user session during the logout process. This way the next user using the same client application gains access to previous session data.\n", + "severity": [ + + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "typo3/cms" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "8.0.0" + }, + { + "fixed": "8.7.27" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "typo3/cms" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "9.0.0" + }, + { + "fixed": "9.5.8" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms/2019-06-25-3.yaml" + }, + { + "type": "PACKAGE", + "url": "https://github.com/TYPO3/typo3" + }, + { + "type": "WEB", + "url": "https://typo3.org/security/advisory/typo3-core-sa-2019-018" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-06-05T17:12:58Z", + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-m87m-mmvp-v9qm/GHSA-m87m-mmvp-v9qm.json b/advisories/unreviewed/2024/06/GHSA-m87m-mmvp-v9qm/GHSA-m87m-mmvp-v9qm.json deleted file mode 100644 index d0142b560c5..00000000000 --- a/advisories/unreviewed/2024/06/GHSA-m87m-mmvp-v9qm/GHSA-m87m-mmvp-v9qm.json +++ /dev/null @@ -1,38 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-m87m-mmvp-v9qm", - "modified": "2024-06-05T15:30:39Z", - "published": "2024-06-05T15:30:39Z", - "aliases": [ - "CVE-2024-5629" - ], - "details": "An out-of-bounds read in the 'bson' module of PyMongo 4.6.2 or earlier allows deserialization of malformed BSON provided by a Server to raise an exception which may contain arbitrary application memory.", - "severity": [ - { - "type": "CVSS_V3", - "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:L" - } - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5629" - }, - { - "type": "WEB", - "url": "https://jira.mongodb.org/browse/PYTHON-4305" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-125" - ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2024-06-05T15:15:12Z" - } -} \ No newline at end of file