mirror of
https://github.com/netbirdio/advisory-database.git
synced 2026-05-22 18:04:22 -07:00
Publish Advisories
GHSA-5fqv-mpj8-h7gm GHSA-59c9-pxq8-9c73 GHSA-6mjg-37cp-42x5 GHSA-m8rw-rcpq-2vp2
This commit is contained in:
File diff suppressed because one or more lines are too long
@@ -1,10 +1,10 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-59c9-pxq8-9c73",
|
||||
"modified": "2023-12-13T13:33:57Z",
|
||||
"modified": "2024-09-30T19:44:16Z",
|
||||
"published": "2023-12-13T13:33:57Z",
|
||||
"aliases": [
|
||||
|
||||
"CVE-2023-50422"
|
||||
],
|
||||
"summary": "Improper JWT Signature Validation in SAP Security Services Library ",
|
||||
"details": "### Impact\nSAP BTP Security Services Integration Library ([Java] cloud-security-services-integration-library) allows under certain conditions an escalation of privileges. On successful exploitation, an unauthenticated attacker can obtain arbitrary permissions within the application.\n\n### Patches\nUpgrade to patched version >= 2.17.0 or >= 3.3.0 \nWe always recommend to upgrade to the latest released version.\n\n### Workarounds\nNo workarounds\n\n### References\nhttps://www.cve.org/CVERecord?id=CVE-2023-50422\n",
|
||||
@@ -12,6 +12,10 @@
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
|
||||
},
|
||||
{
|
||||
"type": "CVSS_V4",
|
||||
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
@@ -135,6 +139,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/SAP/cloud-security-services-integration-library/security/advisories/GHSA-59c9-pxq8-9c73"
|
||||
},
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50422"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/SAP/cloud-security-services-integration-library/commit/4b3e42ab23df6418243b29908b1a2582818d9360"
|
||||
@@ -143,6 +151,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/SAP/cloud-security-services-integration-library/commit/7ce9601979c30ae269a1cbaf7cf33486d10736f1"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://blogs.sap.com/2023/12/12/unveiling-critical-security-updates-sap-btp-security-note-3411067"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://en.wikipedia.org/wiki/JSON_Web_Token"
|
||||
@@ -150,6 +162,30 @@
|
||||
{
|
||||
"type": "PACKAGE",
|
||||
"url": "https://github.com/SAP/cloud-security-services-integration-library"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://me.sap.com/notes/3411067"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://me.sap.com/notes/3413475"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://mvnrepository.com/artifact/com.sap.cloud.security.xsuaa/spring-xsuaa"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://mvnrepository.com/artifact/com.sap.cloud.security/java-security"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://mvnrepository.com/artifact/com.sap.cloud.security/spring-security"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
|
||||
@@ -1,10 +1,10 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-6mjg-37cp-42x5",
|
||||
"modified": "2023-12-13T13:34:36Z",
|
||||
"modified": "2024-09-30T19:44:11Z",
|
||||
"published": "2023-12-13T13:34:36Z",
|
||||
"aliases": [
|
||||
|
||||
"CVE-2023-50423"
|
||||
],
|
||||
"summary": "Improper Privilege Management in sap-xssec",
|
||||
"details": "### Impact\n\nSAP BTP Security Services Integration Library ([Python] sap-xssec) allows under certain conditions an escalation of privileges. On successful exploitation, an unauthenticated attacker can obtain arbitrary permissions within the application.\n\n### Patches\nUpgrade to patched version >= 4.1.0\nWe always recommend to upgrade to the latest released version.\n\n### Workarounds\nNo workarounds\n\n### References\nhttps://www.cve.org/CVERecord?id=CVE-2023-50423\n",
|
||||
@@ -12,6 +12,10 @@
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
|
||||
},
|
||||
{
|
||||
"type": "CVSS_V4",
|
||||
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
@@ -40,13 +44,37 @@
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/SAP/cloud-pysec/security/advisories/GHSA-6mjg-37cp-42x5"
|
||||
},
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50423"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/SAP/cloud-pysec/commit/d90c9e0733fa9af68bd8ea0b1cf023cf482163ef"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://blogs.sap.com/2023/12/12/unveiling-critical-security-updates-sap-btp-security-note-3411067"
|
||||
},
|
||||
{
|
||||
"type": "PACKAGE",
|
||||
"url": "https://github.com/SAP/cloud-pysec"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/pypa/advisory-database/tree/main/vulns/sap-xssec/PYSEC-2023-261.yaml"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://me.sap.com/notes/3411067"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://pypi.org/project/sap-xssec"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
|
||||
@@ -1,10 +1,10 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-m8rw-rcpq-2vp2",
|
||||
"modified": "2024-05-20T22:00:28Z",
|
||||
"modified": "2024-09-30T19:44:18Z",
|
||||
"published": "2023-12-13T13:34:20Z",
|
||||
"aliases": [
|
||||
|
||||
"CVE-2023-50424"
|
||||
],
|
||||
"summary": "Improper Privilege Management in github.com/sap/cloud-security-client-go",
|
||||
"details": "### Impact\nSAP BTP Security Services Integration Library ([Golang] github.com/sap/cloud-security-client-go) allows under certain conditions an escalation of privileges. On successful exploitation, an unauthenticated attacker can obtain arbitrary permissions within the application.\n\n### Patches\nUpgrade to patched version >= 0.17.0\nWe always recommend to upgrade to the latest released version.\n\n### Workarounds\nNo workarounds\n\n### References\nhttps://www.cve.org/CVERecord?id=CVE-2023-50424",
|
||||
@@ -12,6 +12,10 @@
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
|
||||
},
|
||||
{
|
||||
"type": "CVSS_V4",
|
||||
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
|
||||
}
|
||||
],
|
||||
"affected": [
|
||||
@@ -44,6 +48,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/SAP/cloud-security-services-integration-library/security/advisories/GHSA-59c9-pxq8-9c73"
|
||||
},
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50424"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/SAP/cloud-security-client-go/commit/2e3bd63e152e09f267316a1071034eb5d4b7f498"
|
||||
@@ -60,6 +68,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://me.sap.com/notes/3411067"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://pkg.go.dev/github.com/sap/cloud-security-client-go@v0.17.0"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html"
|
||||
|
||||
Reference in New Issue
Block a user