From f5b94e7c21495b03fa730aac201c7473b1bc1c37 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 30 Jan 2024 18:43:50 +0000 Subject: [PATCH] Publish Advisories GHSA-6p78-f7h9-6838 GHSA-7mgx-gvjw-m3w3 GHSA-v89q-c273-3p42 GHSA-vvh2-82c7-ppfg GHSA-x2c2-q32w-4w6m GHSA-6p78-f7h9-6838 GHSA-7mgx-gvjw-m3w3 --- .../GHSA-6p78-f7h9-6838.json | 66 +++++++++ .../GHSA-7mgx-gvjw-m3w3.json | 135 ++++++++++++++++++ .../GHSA-v89q-c273-3p42.json | 37 ++++- .../GHSA-vvh2-82c7-ppfg.json | 33 ++++- .../GHSA-x2c2-q32w-4w6m.json | 58 ++++++++ .../GHSA-6p78-f7h9-6838.json | 39 ----- .../GHSA-7mgx-gvjw-m3w3.json | 35 ----- 7 files changed, 319 insertions(+), 84 deletions(-) create mode 100644 advisories/github-reviewed/2024/01/GHSA-6p78-f7h9-6838/GHSA-6p78-f7h9-6838.json create mode 100644 advisories/github-reviewed/2024/01/GHSA-7mgx-gvjw-m3w3/GHSA-7mgx-gvjw-m3w3.json rename advisories/{unreviewed => github-reviewed}/2024/01/GHSA-v89q-c273-3p42/GHSA-v89q-c273-3p42.json (51%) rename advisories/{unreviewed => github-reviewed}/2024/01/GHSA-vvh2-82c7-ppfg/GHSA-vvh2-82c7-ppfg.json (56%) create mode 100644 advisories/github-reviewed/2024/01/GHSA-x2c2-q32w-4w6m/GHSA-x2c2-q32w-4w6m.json delete mode 100644 advisories/unreviewed/2024/01/GHSA-6p78-f7h9-6838/GHSA-6p78-f7h9-6838.json delete mode 100644 advisories/unreviewed/2024/01/GHSA-7mgx-gvjw-m3w3/GHSA-7mgx-gvjw-m3w3.json diff --git a/advisories/github-reviewed/2024/01/GHSA-6p78-f7h9-6838/GHSA-6p78-f7h9-6838.json b/advisories/github-reviewed/2024/01/GHSA-6p78-f7h9-6838/GHSA-6p78-f7h9-6838.json new file mode 100644 index 00000000000..9802d912477 --- /dev/null +++ b/advisories/github-reviewed/2024/01/GHSA-6p78-f7h9-6838/GHSA-6p78-f7h9-6838.json @@ -0,0 +1,66 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6p78-f7h9-6838", + "modified": "2024-01-30T18:42:48Z", + "published": "2024-01-30T09:30:34Z", + "aliases": [ + "CVE-2023-36260" + ], + "summary": "Craft CMS Feed-Me", + "details": "An issue discovered in Craft CMS version 4.6.1.1 allows remote attackers to cause a denial of service (DoS) via crafted string to Feed-Me Name and Feed-Me URL fields due to saving a feed using an Asset element type with no volume selected.", + "severity": [ + + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "craftcms/cms" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.6.2" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36260" + }, + { + "type": "WEB", + "url": "https://github.com/craftcms/feed-me/commit/b5d6ede51848349bd91bc95fec288b6793f15e28" + }, + { + "type": "PACKAGE", + "url": "https://github.com/craftcms/feed-me" + }, + { + "type": "WEB", + "url": "https://github.com/craftcms/feed-me/releases/tag/4.6.2" + }, + { + "type": "WEB", + "url": "https://www.linkedin.com/pulse/threat-briefing-craftcms-amrcybersecurity-emi0e/?trackingId=E75GttWvQp6gfvPiJDDUBA%3D%3D" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-01-30T18:42:48Z", + "nvd_published_at": "2024-01-30T09:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/01/GHSA-7mgx-gvjw-m3w3/GHSA-7mgx-gvjw-m3w3.json b/advisories/github-reviewed/2024/01/GHSA-7mgx-gvjw-m3w3/GHSA-7mgx-gvjw-m3w3.json new file mode 100644 index 00000000000..57bda4c338d --- /dev/null +++ b/advisories/github-reviewed/2024/01/GHSA-7mgx-gvjw-m3w3/GHSA-7mgx-gvjw-m3w3.json @@ -0,0 +1,135 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7mgx-gvjw-m3w3", + "modified": "2024-01-30T18:43:26Z", + "published": "2024-01-30T03:30:30Z", + "aliases": [ + "CVE-2023-51982" + ], + "summary": "CrateDB authentication bypass vulnerability", + "details": "CrateDB 5.5.1 is contains an authentication bypass vulnerability in the Admin UI component. After configuring password authentication and_ Local_ In the case of an address, identity authentication can be bypassed by setting the X-Real IP request header to a specific value and accessing the Admin UI directly using the default user identity.", + "severity": [ + + ], + "affected": [ + { + "package": { + "ecosystem": "Maven", + "name": "io.crate:crate" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "5.2.11" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "io.crate:crate" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "5.3.0" + }, + { + "fixed": "5.3.8" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "io.crate:crate" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "5.4.0" + }, + { + "fixed": "5.4.7" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "io.crate:crate" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "5.5.0" + }, + { + "fixed": "5.5.2" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51982" + }, + { + "type": "WEB", + "url": "https://github.com/crate/crate/issues/15231" + }, + { + "type": "WEB", + "url": "https://github.com/crate/crate/pull/15234" + }, + { + "type": "WEB", + "url": "https://github.com/crate/crate/commit/0c166ef083bec4d64dd55c1d8cb9b3dec350d241" + }, + { + "type": "WEB", + "url": "https://github.com/crate/crate/commit/5be7b3864137c23305ece10df3f7c311ee50ae4d" + }, + { + "type": "WEB", + "url": "https://github.com/crate/crate/commit/b8b4cec49a1c7eb2b5af568400bd571d194dc03e" + }, + { + "type": "WEB", + "url": "https://github.com/crate/crate/commit/da59311ca920743ebc58ee64c29cfe5723487f56" + }, + { + "type": "PACKAGE", + "url": "https://github.com/crate/crate" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-01-30T18:43:26Z", + "nvd_published_at": "2024-01-30T01:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-v89q-c273-3p42/GHSA-v89q-c273-3p42.json b/advisories/github-reviewed/2024/01/GHSA-v89q-c273-3p42/GHSA-v89q-c273-3p42.json similarity index 51% rename from advisories/unreviewed/2024/01/GHSA-v89q-c273-3p42/GHSA-v89q-c273-3p42.json rename to advisories/github-reviewed/2024/01/GHSA-v89q-c273-3p42/GHSA-v89q-c273-3p42.json index bc77d45b452..d8660812c5a 100644 --- a/advisories/unreviewed/2024/01/GHSA-v89q-c273-3p42/GHSA-v89q-c273-3p42.json +++ b/advisories/github-reviewed/2024/01/GHSA-v89q-c273-3p42/GHSA-v89q-c273-3p42.json @@ -1,17 +1,36 @@ { "schema_version": "1.4.0", "id": "GHSA-v89q-c273-3p42", - "modified": "2024-01-30T09:30:34Z", + "modified": "2024-01-30T18:42:40Z", "published": "2024-01-30T09:30:34Z", "aliases": [ "CVE-2023-36259" ], + "summary": "Craft CMS Audit Plugin Cross Site Scripting vulnerability", "details": "Cross Site Scripting (XSS) vulnerability in Craft CMS Audit Plugin before version 3.0.2 allows attackers to execute arbitrary code during user creation.", "severity": [ ], "affected": [ - + { + "package": { + "ecosystem": "Packagist", + "name": "superbig/craft-audit" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.0.2" + } + ] + } + ] + } ], "references": [ { @@ -22,6 +41,14 @@ "type": "WEB", "url": "https://github.com/sjelfull/craft-audit/pull/73" }, + { + "type": "WEB", + "url": "https://github.com/sjelfull/craft-audit/commit/c2888aa48457f24696ac0a2ba4f54f39e5c672ed" + }, + { + "type": "PACKAGE", + "url": "https://github.com/sjelfull/craft-audit" + }, { "type": "WEB", "url": "https://www.linkedin.com/pulse/threat-briefing-craftcms-amrcybersecurity-emi0e/?trackingId=E75GttWvQp6gfvPiJDDUBA%3D%3D" @@ -31,9 +58,9 @@ "cwe_ids": [ ], - "severity": null, - "github_reviewed": false, - "github_reviewed_at": null, + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-01-30T18:42:40Z", "nvd_published_at": "2024-01-30T09:15:47Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-vvh2-82c7-ppfg/GHSA-vvh2-82c7-ppfg.json b/advisories/github-reviewed/2024/01/GHSA-vvh2-82c7-ppfg/GHSA-vvh2-82c7-ppfg.json similarity index 56% rename from advisories/unreviewed/2024/01/GHSA-vvh2-82c7-ppfg/GHSA-vvh2-82c7-ppfg.json rename to advisories/github-reviewed/2024/01/GHSA-vvh2-82c7-ppfg/GHSA-vvh2-82c7-ppfg.json index 5592cf4cbbb..01ddc6c0178 100644 --- a/advisories/unreviewed/2024/01/GHSA-vvh2-82c7-ppfg/GHSA-vvh2-82c7-ppfg.json +++ b/advisories/github-reviewed/2024/01/GHSA-vvh2-82c7-ppfg/GHSA-vvh2-82c7-ppfg.json @@ -1,12 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-vvh2-82c7-ppfg", - "modified": "2024-01-30T06:30:23Z", + "modified": "2024-01-30T18:43:05Z", "published": "2024-01-30T06:30:23Z", "aliases": [ "CVE-2024-21488" ], - "details": "Versions of the package network before 0.7.0 are vulnerable to Arbitrary Command Injection due to use of the child_process exec function without input sanitization. If (attacker-controlled) user input is given to the mac_address_for function of the package, it is possible for an attacker to execute arbitrary commands on the operating system that this package is being run on.", + "summary": "network Arbitrary Command Injection vulnerability", + "details": "Versions of the package network before 0.7.0 are vulnerable to Arbitrary Command Injection due to use of the `child_process` exec function without input sanitization. If (attacker-controlled) user input is given to the `mac_address_for` function of the package, it is possible for an attacker to execute arbitrary commands on the operating system that this package is being run on.", "severity": [ { "type": "CVSS_V3", @@ -14,7 +15,25 @@ } ], "affected": [ - + { + "package": { + "ecosystem": "npm", + "name": "network" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.7.0" + } + ] + } + ] + } ], "references": [ { @@ -37,6 +56,10 @@ "type": "WEB", "url": "https://gist.github.com/icemonster/282ab98fb68fc22aac7c576538f6369c" }, + { + "type": "PACKAGE", + "url": "https://github.com/tomas/network" + }, { "type": "WEB", "url": "https://security.snyk.io/vuln/SNYK-JS-NETWORK-6184371" @@ -47,8 +70,8 @@ "CWE-77" ], "severity": "HIGH", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-01-30T18:43:05Z", "nvd_published_at": "2024-01-30T05:15:09Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2024/01/GHSA-x2c2-q32w-4w6m/GHSA-x2c2-q32w-4w6m.json b/advisories/github-reviewed/2024/01/GHSA-x2c2-q32w-4w6m/GHSA-x2c2-q32w-4w6m.json new file mode 100644 index 00000000000..182cb02c432 --- /dev/null +++ b/advisories/github-reviewed/2024/01/GHSA-x2c2-q32w-4w6m/GHSA-x2c2-q32w-4w6m.json @@ -0,0 +1,58 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x2c2-q32w-4w6m", + "modified": "2024-01-30T18:42:28Z", + "published": "2024-01-30T18:42:28Z", + "aliases": [ + "CVE-2024-24567" + ], + "summary": "Vyper's raw_call `value=` kwargs not disabled for static and delegate calls", + "details": "### Summary\nVyper compiler allows passing a value in builtin `raw_call` even if the call is a `delegatecall` or a `staticcall`. But in the context of `delegatecall` and `staticcall` the handling of value is not possible due to the semantics of the respective opcodes, and vyper will silently ignore the `value=` argument.\n\nA contract search was performed and no vulnerable contracts were found in production.\n\n### Details\nThe IR for `raw_call` is built in the `RawCall` class:\nhttps://github.com/vyperlang/vyper/blob/9136169468f317a53b4e7448389aa315f90b95ba/vyper/builtins/functions.py#L1100\n\nHowever, the compiler doesn't validate that if either `delegatecall` or `staticall` are provided as kwargs, that `value` wasn't set. For example, the following compiles without errors:\n```python\nraw_call(self, call_data2, max_outsize=255, is_delegate_call=True, value=msg.value/2)\n```\n\n### Impact\nIf the semantics of the EVM are unknown to the developer, he could suspect that by specifying the `value` kwarg, exactly the given amount will be sent along to the target. However in fact, no `value` will be sent.\n\nHere is an example of an potentially problematic implementation of multicall utilizing the `raw_call` built-in:\n```python\nvalue_accumulator: uint256 = empty(uint256)\n results: DynArray[Result, max_value(uint8)] = []\n return_data: Bytes[max_value(uint8)] = b\"\"\n success: bool = empty(bool)\n for batch in data:\n msg_value: uint256 = batch.value\n value_accumulator = unsafe_add(value_accumulator, msg_value)\n if (batch.allow_failure == False):\n return_data = raw_call(self, batch.call_data, max_outsize=255, value=msg_value, is_delegate_call=True)\n success = True\n results.append(Result({success: success, return_data: return_data}))\n else:\n success, return_data = \\\n raw_call(self, batch.call_data, max_outsize=255, value=msg_value, is_delegate_call=True, revert_on_failure=False)\n results.append(Result({success: success, return_data: return_data}))\n assert msg.value == value_accumulator, \"Multicall: value mismatch\"\n return results\n```\n\n### Patches\n_Has the problem been patched? What versions should users upgrade to?_\n\n### Workarounds\n_Is there a way for users to fix or remediate the vulnerability without upgrading?_\n\n### References\n_Are there any links users can visit to find out more?_\n", + "severity": [ + + ], + "affected": [ + { + "package": { + "ecosystem": "PyPI", + "name": "vyper" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "0.3.10" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/vyperlang/vyper/security/advisories/GHSA-x2c2-q32w-4w6m" + }, + { + "type": "PACKAGE", + "url": "https://github.com/vyperlang/vyper" + }, + { + "type": "WEB", + "url": "https://github.com/vyperlang/vyper/blob/9136169468f317a53b4e7448389aa315f90b95ba/vyper/builtins/functions.py#L1100" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-01-30T18:42:28Z", + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-6p78-f7h9-6838/GHSA-6p78-f7h9-6838.json b/advisories/unreviewed/2024/01/GHSA-6p78-f7h9-6838/GHSA-6p78-f7h9-6838.json deleted file mode 100644 index 939afca9ffb..00000000000 --- a/advisories/unreviewed/2024/01/GHSA-6p78-f7h9-6838/GHSA-6p78-f7h9-6838.json +++ /dev/null @@ -1,39 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-6p78-f7h9-6838", - "modified": "2024-01-30T09:30:34Z", - "published": "2024-01-30T09:30:34Z", - "aliases": [ - "CVE-2023-36260" - ], - "details": "An issue discovered in Craft CMS version 4.6.1. allows remote attackers to cause a denial of service (DoS) via crafted string to Feed-Me Name and Feed-Me URL fields due to saving a feed using an Asset element type with no volume selected.", - "severity": [ - - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-36260" - }, - { - "type": "WEB", - "url": "https://github.com/craftcms/feed-me/commit/b5d6ede51848349bd91bc95fec288b6793f15e28%29" - }, - { - "type": "WEB", - "url": "https://www.linkedin.com/pulse/threat-briefing-craftcms-amrcybersecurity-emi0e/?trackingId=E75GttWvQp6gfvPiJDDUBA%3D%3D" - } - ], - "database_specific": { - "cwe_ids": [ - - ], - "severity": null, - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2024-01-30T09:15:47Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-7mgx-gvjw-m3w3/GHSA-7mgx-gvjw-m3w3.json b/advisories/unreviewed/2024/01/GHSA-7mgx-gvjw-m3w3/GHSA-7mgx-gvjw-m3w3.json deleted file mode 100644 index 0752fd6cbd8..00000000000 --- a/advisories/unreviewed/2024/01/GHSA-7mgx-gvjw-m3w3/GHSA-7mgx-gvjw-m3w3.json +++ /dev/null @@ -1,35 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-7mgx-gvjw-m3w3", - "modified": "2024-01-30T03:30:30Z", - "published": "2024-01-30T03:30:30Z", - "aliases": [ - "CVE-2023-51982" - ], - "details": "CrateDB 5.5.1 is contains an authentication bypass vulnerability in the Admin UI component. After configuring password authentication and_ Local_ In the case of an address, identity authentication can be bypassed by setting the X-Real IP request header to a specific value and accessing the Admin UI directly using the default user identity.(https://github.com/crate/crate/issues/15231)", - "severity": [ - - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51982" - }, - { - "type": "WEB", - "url": "https://github.com/crate/crate/issues/15231" - } - ], - "database_specific": { - "cwe_ids": [ - - ], - "severity": null, - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2024-01-30T01:15:59Z" - } -} \ No newline at end of file