Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2024-12-05 05:09:16 +00:00
parent 694e8cf999
commit f6b0e16688
918 changed files with 1094 additions and 3282 deletions
@@ -8,9 +8,7 @@
],
"summary": "react-dev-utils on Windows vulnerable to Remote Code Execution",
"details": "`react-dev-utils` on Windows is vulnerable to remote code execution.\n\n\n## Recommendation\n\nUpdate to one of the following versions, depending on the release line that you are using.\n- 1.0.4\n- 2.0.2\n- 3.1.2\n- 4.2.2\n- 5.0.2\n- 6.0.0-next.a671462c",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -3,9 +3,7 @@
"id": "GHSA-c35v-qwqg-87jc",
"modified": "2022-08-03T16:27:53Z",
"published": "2019-06-06T15:32:32Z",
"aliases": [
],
"aliases": [],
"summary": "express-basic-auth Timing Attack due to native string comparison instead of constant time string comparison",
"details": "Versions of `express-basic-auth` prior to 1.1.7 are vulnerable to Timing Attacks. The package uses native string comparison instead of a constant time string comparison, which may lead to Timing Attacks. Timing Attacks can be used to increase the efficiency of brute-force attacks by removing the exponential increase in entropy gained from longer secrets.\n\n\n## Recommendation\n\nUpgrade to version 1.1.7 or later.",
"severity": [
@@ -3,9 +3,7 @@
"id": "GHSA-f7r3-p866-q9qr",
"modified": "2022-08-03T16:34:42Z",
"published": "2019-06-03T17:27:49Z",
"aliases": [
],
"aliases": [],
"summary": "ircdkit vulnerable to Denial of Service due to unhandled connection end event",
"details": "Versions of `ircdkit` 1.0.3 and prior are vulnerable to a remote denial of service.\n\n\n## Recommendation\n\nUpgrade to version 1.0.4.",
"severity": [
@@ -3,9 +3,7 @@
"id": "GHSA-xf5p-87ch-gxw2",
"modified": "2022-08-02T17:43:57Z",
"published": "2019-06-05T14:10:03Z",
"aliases": [
],
"aliases": [],
"summary": "Marked ReDoS due to email addresses being evaluated in quadratic time",
"details": "Versions of `marked` from 0.3.14 until 0.6.2 are vulnerable to Regular Expression Denial of Service. Email addresses may be evaluated in quadratic time, allowing attackers to potentially crash the node process due to resource exhaustion.\n\n\n## Recommendation\n\nUpgrade to version 0.6.2 or later.",
"severity": [
File diff suppressed because one or more lines are too long
@@ -4,9 +4,7 @@
"modified": "2023-02-24T18:48:34Z",
"published": "2023-02-16T15:30:28Z",
"withdrawn": "2023-02-24T18:48:34Z",
"aliases": [
],
"aliases": [],
"summary": "Duplicate advisory: Sequelize vulnerable to Improper Filtering of Special Elements",
"details": "## Duplicate advisory\nThis advisory has been withdrawn because it is a duplicate of [GHSA-f598-mfpv-gmfx](https://github.com/advisories/GHSA-f598-mfpv-gmfx). This link is maintained to preserve external references.\n\n## Original Description\nDue to improper attribute filtering in the sequelize js library, an attacker can peform SQL injections. This issue can be mitigated by not accepting untrusted input.",
"severity": [
@@ -4,9 +4,7 @@
"modified": "2023-04-28T22:06:24Z",
"published": "2023-02-16T15:30:28Z",
"withdrawn": "2023-02-23T16:57:49Z",
"aliases": [
],
"aliases": [],
"summary": "Duplicate advisory: Sequelize - Unsafe fall-through in getWhereConditions",
"details": "## Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of [GHSA-vqfx-gj96-3w95](https://github.com/advisories/GHSA-vqfx-gj96-3w95). This link is maintained to preserve external references.\n\n## Original Description\nDue to improper parameter filtering in the sequalize js library, can a attacker peform injection.",
"severity": [
@@ -245,9 +245,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2023-08-09T12:56:43Z",
@@ -3,14 +3,10 @@
"id": "GHSA-w6rp-vxj2-fjhr",
"modified": "2023-10-26T23:10:19Z",
"published": "2023-10-26T23:10:19Z",
"aliases": [
],
"aliases": [],
"summary": "Cosmos packet-forward-middleware vulnerable to chain-halt",
"details": "The Cosmos SDK is used for Inter-Blockchain Communication Protocol (IBC) applications and middleware. The [packet-forward-middleware](https://github.com/cosmos/ibc-apps/tree/main/middleware/packet-forward-middleware) module is an IBC middleware module built for Cosmos blockchains utilizing the IBC protocol allowing routing of incoming IBC packets from a source chain to a destination chain. The `packet-forward-middleware` module is vulnerable to potential chain-halt due to error non-determinism.\n\n### Patches\nPlease patch at your earliest convenience by applying one of the following patch versions, respective to the chain's ibc-go major version:\nv4.1.1\nv5.2.1\nv6.1.1",
"severity": [
],
"severity": [],
"affected": [
{
"package": {
@@ -81,9 +77,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2023-10-26T23:10:19Z",
@@ -3,9 +3,7 @@
"id": "GHSA-259p-rvjx-ffwg",
"modified": "2024-02-08T18:24:21Z",
"published": "2024-02-08T18:24:21Z",
"aliases": [
],
"aliases": [],
"summary": "Panel::Software Customized WiX .be TEMP folder is vulnerable to DLL redirection attacks that allow the attacker to escalate privileges",
"details": "# Summary\n\n.be TEMP folder is vulnerable to DLL redirection attacks that allow the attacker to escalate privileges.\n\n# Details\n\nIf the bundle is not run as admin, the user's TEMP folder is used and not the system TEMP folder. A utility is able to monitor the user's TEMP folder for changes and drop its own DLL into the .be/.Local folder immediately when the .be folder is created. When the burn engine elevates, the malicious DLL receives elevated privileges.\n\n# PoC\n\nAs a standard, non-admin user:\n\n1. Monitor the user's TEMP folder for changes using ReadDirectoryChangesW\n1. On FILE_ACTION_ADDED, check if the folder name is .be\n1. Create a folder in .be named after the bundle + .Local (e.g. MyInstaller.exe.Local)\n1. Put the malicious COMCTL32.DLL in the .Local folder following the naming used for the real DLL (e.g. MyInstaller.exe.Local/x86_microsoft.windows.common-controls_.../COMCTL32.dll)\n1. Do hacker things when the engine escalates and the malicious DLL is loaded\n\nProper naming for the path can be obtained by using GetModuleHandle(\"comctl32.dll\") and GetModuleFileName.\n\n# Impact\n\nDLL redirection utilizing .exe.Local Windows capability. This impacts any installer built with the WiX installer framework.\n",
"severity": [
@@ -3,9 +3,7 @@
"id": "GHSA-8v28-3g86-chj5",
"modified": "2024-02-08T18:24:35Z",
"published": "2024-02-08T18:24:35Z",
"aliases": [
],
"aliases": [],
"summary": "PanelSwWix4.Sdk .be TEMP folder is vulnerable to DLL redirection attacks that allow the attacker to escalate privileges",
"details": "# Summary\n\n.be TEMP folder is vulnerable to DLL redirection attacks that allow the attacker to escalate privileges.\n\n# Details\n\nIf the bundle is not run as admin, the user's TEMP folder is used and not the system TEMP folder. A utility is able to monitor the user's TEMP folder for changes and drop its own DLL into the .be/.Local folder immediately when the .be folder is created. When the burn engine elevates, the malicious DLL receives elevated privileges.\n\n# PoC\n\nAs a standard, non-admin user:\n\n1. Monitor the user's TEMP folder for changes using ReadDirectoryChangesW\n1. On FILE_ACTION_ADDED, check if the folder name is .be\n1. Create a folder in .be named after the bundle + .Local (e.g. MyInstaller.exe.Local)\n1. Put the malicious COMCTL32.DLL in the .Local folder following the naming used for the real DLL (e.g. MyInstaller.exe.Local/x86_microsoft.windows.common-controls_.../COMCTL32.dll)\n1. Do hacker things when the engine escalates and the malicious DLL is loaded\n\nProper naming for the path can be obtained by using GetModuleHandle(\"comctl32.dll\") and GetModuleFileName.\n\n# Impact\n\nDLL redirection utilizing .exe.Local Windows capability. This impacts any installer built with the WiX installer framework.\n",
"severity": [
@@ -3,9 +3,7 @@
"id": "GHSA-hq76-662x-7mw4",
"modified": "2024-09-03T19:45:27Z",
"published": "2024-09-03T19:45:26Z",
"aliases": [
],
"aliases": [],
"summary": "Pimcore includes vulnerable PHPOffice/PhpSpreadsheet",
"details": "### Summary\nPimcore 10.6.x and Enterprise 10.6.x versions currently depend on PHPOffice/PhpSpreadsheet version 1.x, which has recently been identified with a security vulnerability (CVE-2024-45048). To mitigate this issue, it is recommended to update to the latest version 2.2.2. For more details, please refer to the official advisory: [GHSA-ghg6-32f9-2jp7](https://github.com/advisories/GHSA-ghg6-32f9-2jp7).\n\n",
"severity": [
@@ -168,9 +166,7 @@
}
],
"database_specific": {
"cwe_ids": [
],
"cwe_ids": [],
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2024-09-03T19:45:26Z",
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
}
],
"affected": [
],
"affected": [],
"references": [
{
"type": "ADVISORY",
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
}
],
"affected": [
],
"affected": [],
"references": [
{
"type": "ADVISORY",
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"affected": [],
"references": [
{
"type": "ADVISORY",
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"affected": [],
"references": [
{
"type": "ADVISORY",
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"affected": [],
"references": [
{
"type": "ADVISORY",
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"affected": [],
"references": [
{
"type": "ADVISORY",
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"affected": [],
"references": [
{
"type": "ADVISORY",
@@ -13,9 +13,7 @@
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
],
"affected": [],
"references": [
{
"type": "ADVISORY",

Some files were not shown because too many files have changed in this diff Show More