Publish Advisories

GHSA-6p78-f7h9-6838
GHSA-7mgx-gvjw-m3w3
GHSA-v89q-c273-3p42
GHSA-vvh2-82c7-ppfg
GHSA-x2c2-q32w-4w6m
GHSA-6p78-f7h9-6838
GHSA-7mgx-gvjw-m3w3
This commit is contained in:
advisory-database[bot]
2024-01-30 18:43:50 +00:00
parent bab026ad09
commit f5b94e7c21
7 changed files with 319 additions and 84 deletions
@@ -0,0 +1,66 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6p78-f7h9-6838",
"modified": "2024-01-30T18:42:48Z",
"published": "2024-01-30T09:30:34Z",
"aliases": [
"CVE-2023-36260"
],
"summary": "Craft CMS Feed-Me",
"details": "An issue discovered in Craft CMS version 4.6.1.1 allows remote attackers to cause a denial of service (DoS) via crafted string to Feed-Me Name and Feed-Me URL fields due to saving a feed using an Asset element type with no volume selected.",
"severity": [
],
"affected": [
{
"package": {
"ecosystem": "Packagist",
"name": "craftcms/cms"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "4.6.2"
}
]
}
]
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36260"
},
{
"type": "WEB",
"url": "https://github.com/craftcms/feed-me/commit/b5d6ede51848349bd91bc95fec288b6793f15e28"
},
{
"type": "PACKAGE",
"url": "https://github.com/craftcms/feed-me"
},
{
"type": "WEB",
"url": "https://github.com/craftcms/feed-me/releases/tag/4.6.2"
},
{
"type": "WEB",
"url": "https://www.linkedin.com/pulse/threat-briefing-craftcms-amrcybersecurity-emi0e/?trackingId=E75GttWvQp6gfvPiJDDUBA%3D%3D"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-01-30T18:42:48Z",
"nvd_published_at": "2024-01-30T09:15:47Z"
}
}
@@ -0,0 +1,135 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7mgx-gvjw-m3w3",
"modified": "2024-01-30T18:43:26Z",
"published": "2024-01-30T03:30:30Z",
"aliases": [
"CVE-2023-51982"
],
"summary": "CrateDB authentication bypass vulnerability",
"details": "CrateDB 5.5.1 is contains an authentication bypass vulnerability in the Admin UI component. After configuring password authentication and_ Local_ In the case of an address, identity authentication can be bypassed by setting the X-Real IP request header to a specific value and accessing the Admin UI directly using the default user identity.",
"severity": [
],
"affected": [
{
"package": {
"ecosystem": "Maven",
"name": "io.crate:crate"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "5.2.11"
}
]
}
]
},
{
"package": {
"ecosystem": "Maven",
"name": "io.crate:crate"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "5.3.0"
},
{
"fixed": "5.3.8"
}
]
}
]
},
{
"package": {
"ecosystem": "Maven",
"name": "io.crate:crate"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "5.4.0"
},
{
"fixed": "5.4.7"
}
]
}
]
},
{
"package": {
"ecosystem": "Maven",
"name": "io.crate:crate"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "5.5.0"
},
{
"fixed": "5.5.2"
}
]
}
]
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51982"
},
{
"type": "WEB",
"url": "https://github.com/crate/crate/issues/15231"
},
{
"type": "WEB",
"url": "https://github.com/crate/crate/pull/15234"
},
{
"type": "WEB",
"url": "https://github.com/crate/crate/commit/0c166ef083bec4d64dd55c1d8cb9b3dec350d241"
},
{
"type": "WEB",
"url": "https://github.com/crate/crate/commit/5be7b3864137c23305ece10df3f7c311ee50ae4d"
},
{
"type": "WEB",
"url": "https://github.com/crate/crate/commit/b8b4cec49a1c7eb2b5af568400bd571d194dc03e"
},
{
"type": "WEB",
"url": "https://github.com/crate/crate/commit/da59311ca920743ebc58ee64c29cfe5723487f56"
},
{
"type": "PACKAGE",
"url": "https://github.com/crate/crate"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-01-30T18:43:26Z",
"nvd_published_at": "2024-01-30T01:15:59Z"
}
}
@@ -1,17 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v89q-c273-3p42",
"modified": "2024-01-30T09:30:34Z",
"modified": "2024-01-30T18:42:40Z",
"published": "2024-01-30T09:30:34Z",
"aliases": [
"CVE-2023-36259"
],
"summary": "Craft CMS Audit Plugin Cross Site Scripting vulnerability",
"details": "Cross Site Scripting (XSS) vulnerability in Craft CMS Audit Plugin before version 3.0.2 allows attackers to execute arbitrary code during user creation.",
"severity": [
],
"affected": [
{
"package": {
"ecosystem": "Packagist",
"name": "superbig/craft-audit"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "3.0.2"
}
]
}
]
}
],
"references": [
{
@@ -22,6 +41,14 @@
"type": "WEB",
"url": "https://github.com/sjelfull/craft-audit/pull/73"
},
{
"type": "WEB",
"url": "https://github.com/sjelfull/craft-audit/commit/c2888aa48457f24696ac0a2ba4f54f39e5c672ed"
},
{
"type": "PACKAGE",
"url": "https://github.com/sjelfull/craft-audit"
},
{
"type": "WEB",
"url": "https://www.linkedin.com/pulse/threat-briefing-craftcms-amrcybersecurity-emi0e/?trackingId=E75GttWvQp6gfvPiJDDUBA%3D%3D"
@@ -31,9 +58,9 @@
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-01-30T18:42:40Z",
"nvd_published_at": "2024-01-30T09:15:47Z"
}
}
@@ -1,12 +1,13 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vvh2-82c7-ppfg",
"modified": "2024-01-30T06:30:23Z",
"modified": "2024-01-30T18:43:05Z",
"published": "2024-01-30T06:30:23Z",
"aliases": [
"CVE-2024-21488"
],
"details": "Versions of the package network before 0.7.0 are vulnerable to Arbitrary Command Injection due to use of the child_process exec function without input sanitization. If (attacker-controlled) user input is given to the mac_address_for function of the package, it is possible for an attacker to execute arbitrary commands on the operating system that this package is being run on.",
"summary": "network Arbitrary Command Injection vulnerability",
"details": "Versions of the package network before 0.7.0 are vulnerable to Arbitrary Command Injection due to use of the `child_process` exec function without input sanitization. If (attacker-controlled) user input is given to the `mac_address_for` function of the package, it is possible for an attacker to execute arbitrary commands on the operating system that this package is being run on.",
"severity": [
{
"type": "CVSS_V3",
@@ -14,7 +15,25 @@
}
],
"affected": [
{
"package": {
"ecosystem": "npm",
"name": "network"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "0.7.0"
}
]
}
]
}
],
"references": [
{
@@ -37,6 +56,10 @@
"type": "WEB",
"url": "https://gist.github.com/icemonster/282ab98fb68fc22aac7c576538f6369c"
},
{
"type": "PACKAGE",
"url": "https://github.com/tomas/network"
},
{
"type": "WEB",
"url": "https://security.snyk.io/vuln/SNYK-JS-NETWORK-6184371"
@@ -47,8 +70,8 @@
"CWE-77"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"github_reviewed": true,
"github_reviewed_at": "2024-01-30T18:43:05Z",
"nvd_published_at": "2024-01-30T05:15:09Z"
}
}
File diff suppressed because one or more lines are too long
@@ -1,39 +0,0 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6p78-f7h9-6838",
"modified": "2024-01-30T09:30:34Z",
"published": "2024-01-30T09:30:34Z",
"aliases": [
"CVE-2023-36260"
],
"details": "An issue discovered in Craft CMS version 4.6.1. allows remote attackers to cause a denial of service (DoS) via crafted string to Feed-Me Name and Feed-Me URL fields due to saving a feed using an Asset element type with no volume selected.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36260"
},
{
"type": "WEB",
"url": "https://github.com/craftcms/feed-me/commit/b5d6ede51848349bd91bc95fec288b6793f15e28%29"
},
{
"type": "WEB",
"url": "https://www.linkedin.com/pulse/threat-briefing-craftcms-amrcybersecurity-emi0e/?trackingId=E75GttWvQp6gfvPiJDDUBA%3D%3D"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-30T09:15:47Z"
}
}
@@ -1,35 +0,0 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7mgx-gvjw-m3w3",
"modified": "2024-01-30T03:30:30Z",
"published": "2024-01-30T03:30:30Z",
"aliases": [
"CVE-2023-51982"
],
"details": "CrateDB 5.5.1 is contains an authentication bypass vulnerability in the Admin UI component. After configuring password authentication and_ Local_ In the case of an address, identity authentication can be bypassed by setting the X-Real IP request header to a specific value and accessing the Admin UI directly using the default user identity.(https://github.com/crate/crate/issues/15231)",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51982"
},
{
"type": "WEB",
"url": "https://github.com/crate/crate/issues/15231"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-01-30T01:15:59Z"
}
}