Publish Advisories

GHSA-354q-38f3-jh4j
GHSA-f886-x4w4-9rwj
GHSA-7jf7-rx7v-xwqq
GHSA-295v-9m5g-79q9
GHSA-7jpg-h873-5g68
GHSA-fhf9-47gc-m9wc
GHSA-h6hv-h4xf-gmgh
GHSA-r2p2-3cx2-xc3r
GHSA-vj8j-762w-6jmv
GHSA-3jvv-m32r-4hpf
GHSA-73h3-w2hp-q47q
This commit is contained in:
advisory-database[bot]
2023-07-06 06:31:34 +00:00
parent e4b2594814
commit f36aa16f7c
11 changed files with 122 additions and 2 deletions
@@ -36,6 +36,10 @@
{
"type": "WEB",
"url": "https://lore.kernel.org/lkml/ZD1xyZxb3rHot8PV@redhat.com/t/"
},
{
"type": "WEB",
"url": "https://www.debian.org/security/2023/dsa-5448"
}
],
"database_specific": {
@@ -32,6 +32,10 @@
{
"type": "WEB",
"url": "https://lore.kernel.org/all/CA+UBctCu7fXn4q41O_3=id1+OdyQ85tZY1x+TkT-6OVBL6KAUw@mail.gmail.com/"
},
{
"type": "WEB",
"url": "https://www.debian.org/security/2023/dsa-5448"
}
],
"database_specific": {
@@ -29,6 +29,10 @@
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20230622-0001/"
},
{
"type": "WEB",
"url": "https://www.debian.org/security/2023/dsa-5448"
},
{
"type": "WEB",
"url": "https://www.zerodayinitiative.com/advisories/ZDI-23-547/"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-295v-9m5g-79q9",
"modified": "2023-06-28T21:30:29Z",
"modified": "2023-07-06T06:30:17Z",
"published": "2023-06-28T21:30:29Z",
"aliases": [
"CVE-2023-3090"
@@ -28,6 +28,10 @@
{
"type": "WEB",
"url": "https://kernel.dance/90cbed5247439a966b645b34eb0a2e037836ea8e"
},
{
"type": "WEB",
"url": "https://www.debian.org/security/2023/dsa-5448"
}
],
"database_specific": {
@@ -29,6 +29,10 @@
"type": "WEB",
"url": "https://git.kernel.org/linus/4d56304e5827c8cc8cc18c75343d283af7c4825c"
},
{
"type": "WEB",
"url": "https://www.debian.org/security/2023/dsa-5448"
},
{
"type": "WEB",
"url": "https://www.openwall.com/lists/oss-security/2023/06/07/1"
@@ -28,6 +28,10 @@
{
"type": "WEB",
"url": "https://www.papercut.com/"
},
{
"type": "WEB",
"url": "https://www.papercut.com/kb/Main/SecurityBulletinJune2023"
}
],
"database_specific": {
@@ -28,6 +28,10 @@
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2214348"
},
{
"type": "WEB",
"url": "https://www.debian.org/security/2023/dsa-5448"
}
],
"database_specific": {
@@ -24,6 +24,10 @@
{
"type": "WEB",
"url": "https://lore.kernel.org/lkml/1682238502-1892-1-git-send-email-yangpc@wangsu.com/T/"
},
{
"type": "WEB",
"url": "https://www.debian.org/security/2023/dsa-5448"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vj8j-762w-6jmv",
"modified": "2023-06-28T21:30:30Z",
"modified": "2023-07-06T06:30:17Z",
"published": "2023-06-28T21:30:30Z",
"aliases": [
"CVE-2023-3390"
@@ -28,6 +28,10 @@
{
"type": "WEB",
"url": "https://kernel.dance/1240eb93f0616b21c675416516ff3d74798fdc97"
},
{
"type": "WEB",
"url": "https://www.debian.org/security/2023/dsa-5448"
}
],
"database_specific": {
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3jvv-m32r-4hpf",
"modified": "2023-07-06T06:30:17Z",
"published": "2023-07-06T06:30:17Z",
"aliases": [
"CVE-2023-26138"
],
"details": "All versions of the package drogonframework/drogon are vulnerable to CRLF Injection when untrusted user input is used to set request headers in the addHeader function. An attacker can add the \\r\\n (carriage return line feeds) characters and inject additional headers in the request sent.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26138"
},
{
"type": "WEB",
"url": "https://gist.github.com/dellalibera/d2abd809f32ec6c61be1f41d80edf61b"
},
{
"type": "WEB",
"url": "https://security.snyk.io/vuln/SNYK-UNMANAGED-DROGONFRAMEWORKDROGON-5665555"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}
@@ -0,0 +1,42 @@
{
"schema_version": "1.4.0",
"id": "GHSA-73h3-w2hp-q47q",
"modified": "2023-07-06T06:30:17Z",
"published": "2023-07-06T06:30:17Z",
"aliases": [
"CVE-2023-26137"
],
"details": "All versions of the package drogonframework/drogon are vulnerable to HTTP Response Splitting when untrusted user input is used to build header values in the addHeader and addCookie functions. An attacker can add the \\r\\n (carriage return line feeds) characters to end the HTTP response headers and inject malicious content.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26137"
},
{
"type": "WEB",
"url": "https://gist.github.com/dellalibera/666d67165830ded052a1ede2d2c0b02a"
},
{
"type": "WEB",
"url": "https://security.snyk.io/vuln/SNYK-UNMANAGED-DROGONFRAMEWORKDROGON-5665554"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": null
}
}