Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2024-12-02 05:12:45 +00:00
parent d1b640d076
commit f5d4b02cfa
882 changed files with 1879 additions and 5637 deletions
@@ -3,9 +3,7 @@
"id": "GHSA-j59f-6m4q-62h6",
"modified": "2023-12-07T22:05:54Z",
"published": "2019-05-30T17:28:48Z",
"aliases": [
],
"aliases": [],
"summary": "Improper Key Verification in ipns",
"details": "Versions 0.1.1 or 0.1.2 of `ipns` are vulnerable to improper key validation. This is due to the public key verification was not being performed properly, resulting in any key being valid.\n\n\n## Recommendation\n\nUpdate to version 0.1.3 or later.",
"severity": [
@@ -3,14 +3,10 @@
"id": "GHSA-22h7-7wwg-qmgg",
"modified": "2020-08-31T19:00:24Z",
"published": "2020-09-04T17:56:39Z",
"aliases": [
],
"aliases": [],
"summary": "Prototype Pollution in @hapi/hoek",
"details": "Versions of `@hapi/hoek` prior to 8.5.1 and 9.0.3 are vulnerable to Prototype Pollution. The `clone` function fails to prevent the modification of the Object prototype when passed specially-crafted input. Attackers may use this to change existing properties that exist in all objects, which may lead to Denial of Service or Remote Code Execution in specific circumstances. \nThis issue __does not__ affect hapi applications since the framework protects against such malicious inputs. Applications that use `@hapi/hoek` outside of the hapi ecosystem may be vulnerable.\n\n\n## Recommendation\n\nUpdate to version 8.5.1, 9.0.3 or later.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -3,14 +3,10 @@
"id": "GHSA-23vw-mhv5-grv5",
"modified": "2020-08-31T19:00:56Z",
"published": "2020-09-03T15:48:43Z",
"aliases": [
],
"aliases": [],
"summary": "Denial of Service in @hapi/hapi",
"details": "Versions of `@hapi/hapi` prior to 18.4.1 or 19.1.1 are vulnerable to Denial of Service. The CORS request handler has a vulnerability which will cause the function to throw a system error if the header contains some invalid values. If no unhandled exception handler is available, the application will exist, allowing an attacker to shut down services.\n\n\n## Recommendation\n\nUpgrade to versions 18.4.1, 19.1.1 or later.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -58,9 +54,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2020-08-31T19:00:56Z",
@@ -3,14 +3,10 @@
"id": "GHSA-25v4-mcx4-hh35",
"modified": "2020-08-31T18:59:41Z",
"published": "2020-09-04T17:28:28Z",
"aliases": [
],
"aliases": [],
"summary": "Cross-Site Scripting in atlasboard-atlassian-package",
"details": "All versions of `atlasboard-atlassian-package` prior to 0.4.2 are vulnerable to Cross-Site Scripting (XSS). The package fails to properly sanitize user input that is rendered as HTML, which may allow attackers to execute arbitrary JavaScript in a victim's browser. This requires attackers being able to change issue summaries in Jira tickets.\n\n\n## Recommendation\n\nNo fix is currently available. Consider using an alternative package until a fix is made available.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -3,9 +3,7 @@
"id": "GHSA-2p62-c4rm-mr72",
"modified": "2023-12-07T22:04:42Z",
"published": "2020-09-01T19:44:57Z",
"aliases": [
],
"aliases": [],
"summary": "Malicious Package in another-date-picker",
"details": "Version 2.0.43 of `another-date-picker` contained malicious code. The code when executed in the browser would enumerate password, cvc, cardnumber fields from forms and send the extracted values to `https://js-metrics.com/minjs.php?pl=`\n\n\n\n## Recommendation\n\nIf version 2.0.43 of this module is found installed you will want to replace it with a version before or after 2.0.43. In addition to replacing the installed module, you will also want to evaluate your application to determine whether or not user data was compromised.",
"severity": [
@@ -3,14 +3,10 @@
"id": "GHSA-36c4-4r89-6whg",
"modified": "2021-10-04T21:05:01Z",
"published": "2020-09-03T15:49:02Z",
"aliases": [
],
"aliases": [],
"summary": "Prototype Pollution in @commercial/subtext",
"details": "Versions of `@commercial/subtext` prior to 5.1.2 are vulnerable to Prototype Pollution. A multipart payload can be constructed in a way that one of the parts content can be set as the entire payload objects prototype. If this prototype contains data, it may bypass other validation rules which enforce access and privacy. If this prototype evaluates to null, it can cause unhandled exceptions when the request payload is accessed.\n\n\n## Recommendation\n\nUpgrade to version 5.1.2 or later.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -3,14 +3,10 @@
"id": "GHSA-3wqh-h42r-x8fq",
"modified": "2020-08-31T19:00:42Z",
"published": "2020-09-03T15:46:22Z",
"aliases": [
],
"aliases": [],
"summary": "Denial of Service in @hapi/subtext",
"details": "Versions of `@hapi/subtext` prior to 6.1.3 or 7.0.3 are vulnerable to Denial of Service. The Content-Encoding HTTP header parser has a vulnerability which will cause the function to throw a system error if the header contains some invalid values. Because hapi rethrows system errors (as opposed to catching expected application errors), the error is thrown all the way up the stack. If no unhandled exception handler is available, the application will exist, allowing an attacker to shut down services.\n\n\n## Recommendation\n\nUpgrade to version 6.1.3 or 7.0.3",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -58,9 +54,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2020-08-31T19:00:42Z",
@@ -3,14 +3,10 @@
"id": "GHSA-49mg-94fc-2fx6",
"modified": "2020-08-31T19:00:00Z",
"published": "2020-09-04T17:32:49Z",
"aliases": [
],
"aliases": [],
"summary": "Command Injection in npm-git-publish",
"details": "All versions of `npm-git-publish` are vulnerable to Command Injection. The package fails to sanitize input and passes it directly to an `execSync` call, which may allow attackers to execute arbitrary code in the system. The `publish` function is vulnerable through the `gitRemoteUrl` variable.\n\n\n## Recommendation\n\nNo fix is currently available. Consider using an alternative package until a fix is made available.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -3,14 +3,10 @@
"id": "GHSA-4qqc-mp5f-ccv4",
"modified": "2020-09-02T15:04:08Z",
"published": "2020-09-02T15:05:51Z",
"aliases": [
],
"aliases": [],
"summary": "Command Injection in bestzip",
"details": "Versions of `bestzip` prior to 2.1.7 are vulnerable to Command Injection. The package fails to sanitize input rules and passes it directly to an `exec` call on the `zip` function . This may allow attackers to execute arbitrary code in the system as long as the values of `destination` is user-controlled. This only affects users with a native `zip` command available. The following examples demonstrate the issue from the CLI and also programatically:\n- `bestzip test.zip 'sourcefile; mkdir folder'`\n- `zip({ source: 'sourcefile', destination: './test.zip; mkdir folder' })`",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -3,14 +3,10 @@
"id": "GHSA-4r97-78gf-q24v",
"modified": "2020-08-31T19:00:12Z",
"published": "2020-09-04T17:53:27Z",
"aliases": [
],
"aliases": [],
"summary": "Prototype Pollution in klona",
"details": "Versions of `klona` prior to 1.1.1 are vulnerable to prototype pollution. The package does not restrict the modification of an Object's prototype when cloning objects, which may allow an attacker to add or modify an existing property that will exist on all objects.\n\n\n\n\n## Recommendation\n\nUpgrade to version 1.1.1 or later.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -3,14 +3,10 @@
"id": "GHSA-5854-jvxx-2cg9",
"modified": "2020-08-31T19:00:47Z",
"published": "2020-09-03T15:46:57Z",
"aliases": [
],
"aliases": [],
"summary": "Denial of Service in subtext",
"details": "Versions of `subtext` >=4.1.0 are vulnerable to Denial of Service. The Content-Encoding HTTP header parser has a vulnerability which will cause the function to throw a system error if the header contains some invalid values. Because hapi rethrows system errors (as opposed to catching expected application errors), the error is thrown all the way up the stack. If no unhandled exception handler is available, the application will exist, allowing an attacker to shut down services.\n\n\n## Recommendation\n\nThis package is deprecated and is now maintained as `@hapi/subtext`. Please update your dependencies to use `@hapi/subtext`. ",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -36,9 +32,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2020-08-31T19:00:47Z",
@@ -3,14 +3,10 @@
"id": "GHSA-5ff8-jcf9-fw62",
"modified": "2021-10-04T20:53:26Z",
"published": "2020-09-04T17:55:35Z",
"aliases": [
],
"aliases": [],
"summary": "Cross-Site Scripting in markdown-it-katex",
"details": "All versions of `markdown-it-katex` are vulnerable to Cross-Site Scripting (XSS). The package fails to properly escape error messages, which may allow attackers to execute arbitrary JavaScript in a victim's browser by triggering an error.\n\n\n## Recommendation\n\nNo fix is currently available. Consider using an alternative package until a fix is made available.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -3,14 +3,10 @@
"id": "GHSA-5vj8-3v2h-h38v",
"modified": "2022-04-28T19:57:43Z",
"published": "2020-09-04T18:04:08Z",
"aliases": [
],
"aliases": [],
"summary": "Remote Code Execution in next",
"details": "Versions of `next` prior to 5.1.0 are vulnerable to Remote Code Execution. The `/path:` route fails to properly sanitize input and passes it to a `require()` call. This allows attackers to execute JavaScript code on the server. Note that prior version 0.9.9 package `next` npm package hosted a different utility (0.4.1 being the latest version of that codebase), and this advisory does not apply to those versions.\n\n## Recommendation\n\nUpgrade to version 5.1.0.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -3,14 +3,10 @@
"id": "GHSA-65m9-m259-7jqw",
"modified": "2021-10-04T21:06:12Z",
"published": "2020-09-03T15:49:29Z",
"aliases": [
],
"aliases": [],
"summary": "Improper Authorization in react-oauth-flow",
"details": "All versions of `react-oauth-flow` fail to properly implement the OAuth protocol. The package stores secrets in the front-end code. Instead of using a public OAuth client, it uses a confidential client on the browser. This may allow attackers to compromise server credentials.\n\n\n## Recommendation\n\nNo fix is currently available. Consider using an alternative module until a fix is made available.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -3,14 +3,10 @@
"id": "GHSA-66mv-xh68-h6v2",
"modified": "2020-08-31T19:00:58Z",
"published": "2020-09-03T15:48:53Z",
"aliases": [
],
"aliases": [],
"summary": "Denial of Service in @commercial/hapi",
"details": "Affected versions of `@commercial/hapi` are vulnerable to Denial of Service. The CORS request handler has a vulnerability which will cause the function to throw a system error if the header contains some invalid values. If no unhandled exception handler is available, the application will exist, allowing an attacker to shut down services.\n\n\n## Recommendation\n\nUpgrade to versions 16.8.2, 17.9.2, 18.4.1, 19.1.1 or later.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -96,9 +92,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2020-08-31T19:00:58Z",
@@ -3,9 +3,7 @@
"id": "GHSA-6fcr-9h9g-23fq",
"modified": "2023-12-07T22:08:14Z",
"published": "2020-09-02T21:50:51Z",
"aliases": [
],
"aliases": [],
"summary": "Denial of Service in ipfs-bitswap",
"details": "Versions of `ipfs-bitswap` prior to 0.24.1 are vulnerable to Denial of Service (DoS). The package put unwanted blocks in the blockstore, which could be used to exhaust system resources in specific conditions.\n\n\n## Recommendation\n\nUpgrade to version 0.24.1 or later.",
"severity": [
@@ -8,9 +8,7 @@
],
"summary": "Prototype Pollution",
"details": "All versions of `utils-extend` are vulnerable to prototype pollution. The `extend` function does not restrict the modification of an Object's prototype, which may allow an attacker to add or modify an existing property that will exist on all objects.\n\n## Recommendation\n\nNo fix is currently available. Consider using an alternative package until a fix is made available.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -8,9 +8,7 @@
],
"summary": "XXE in Apache Standard Taglibs",
"details": "Apache Standard Taglibs before 1.2.3 allows remote attackers to execute arbitrary code or conduct external XML entity (XXE) attacks via a crafted XSLT extension in a (1) <x:parse> or (2) <x:transform> JSTL XML tag.",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -3,9 +3,7 @@
"id": "GHSA-7cvf-p83w-48q6",
"modified": "2023-12-07T22:07:51Z",
"published": "2020-09-03T21:37:29Z",
"aliases": [
],
"aliases": [],
"summary": "Malicious Package in beffer-xor",
"details": "Version 2.0.2 contained malicious code. The package targeted the Ethereum cryptocurrency and performed transactions to wallets not controlled by the user.\n\n\n## Recommendation\n\nRemove the package from your environment. Ensure no Ethereum funds were compromised.",
"severity": [
@@ -3,14 +3,10 @@
"id": "GHSA-7hx8-2rxv-66xv",
"modified": "2020-08-31T19:00:54Z",
"published": "2020-09-03T15:48:00Z",
"aliases": [
],
"aliases": [],
"summary": "Denial of Service in hapi",
"details": "All Versions of `hapi` are vulnerable to Denial of Service. The CORS request handler has a vulnerability which will cause the function to throw a system error if the header contains some invalid values. If no unhandled exception handler is available, the application will exist, allowing an attacker to shut down services.\n\n\n## Recommendation\n\nThis package is deprecated and is now maintained as `@hapi/hapi`. Please update your dependencies to use `@hapi/hapi`. ",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -36,9 +32,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2020-08-31T19:00:54Z",

Some files were not shown because too many files have changed in this diff Show More