diff --git a/advisories/unreviewed/2021/12/GHSA-r562-m862-63w3/GHSA-r562-m862-63w3.json b/advisories/github-reviewed/2021/12/GHSA-r562-m862-63w3/GHSA-r562-m862-63w3.json similarity index 60% rename from advisories/unreviewed/2021/12/GHSA-r562-m862-63w3/GHSA-r562-m862-63w3.json rename to advisories/github-reviewed/2021/12/GHSA-r562-m862-63w3/GHSA-r562-m862-63w3.json index 6d682aa9f8e..89220d14188 100644 --- a/advisories/unreviewed/2021/12/GHSA-r562-m862-63w3/GHSA-r562-m862-63w3.json +++ b/advisories/github-reviewed/2021/12/GHSA-r562-m862-63w3/GHSA-r562-m862-63w3.json @@ -1,17 +1,39 @@ { "schema_version": "1.4.0", "id": "GHSA-r562-m862-63w3", - "modified": "2021-12-15T00:01:44Z", + "modified": "2024-04-22T22:34:38Z", "published": "2021-12-09T00:00:28Z", "aliases": [ "CVE-2021-37941" ], + "summary": "APM Java Agent Local Privilege Escalation", "details": "A local privilege escalation issue was found with the APM Java agent, where a user on the system could attach a malicious file to an application running with the APM Java agent. Using this vector, a malicious or compromised user account could use the agent to run commands at a higher level of permissions than they possess. This vulnerability affects users that have set up the agent via the attacher cli 3, the attach API 2, as well as users that have enabled the profiling_inferred_spans_enabled option", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ - + { + "package": { + "ecosystem": "PyPI", + "name": "elastic-apm" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "1.10.0" + }, + { + "fixed": "1.27.0" + } + ] + } + ] + } ], "references": [ { @@ -21,6 +43,10 @@ { "type": "WEB", "url": "https://discuss.elastic.co/t/apm-java-agent-security-update/289627" + }, + { + "type": "PACKAGE", + "url": "https://github.com/elastic/apm-agent-python" } ], "database_specific": { @@ -28,8 +54,8 @@ "CWE-269" ], "severity": "HIGH", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-04-22T22:34:38Z", "nvd_published_at": "2021-12-08T22:15:00Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2022/05/GHSA-9q62-r72g-pvv7/GHSA-9q62-r72g-pvv7.json b/advisories/github-reviewed/2022/05/GHSA-9q62-r72g-pvv7/GHSA-9q62-r72g-pvv7.json new file mode 100644 index 00000000000..5d7605da3ae --- /dev/null +++ b/advisories/github-reviewed/2022/05/GHSA-9q62-r72g-pvv7/GHSA-9q62-r72g-pvv7.json @@ -0,0 +1,61 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9q62-r72g-pvv7", + "modified": "2024-04-22T22:36:13Z", + "published": "2022-05-24T16:55:55Z", + "aliases": [ + "CVE-2019-16224" + ], + "summary": "py-lmdb Invalid write operation", + "details": "An issue was discovered in py-lmdb 0.97. For certain values of `md_flags`, `mdb_node_add` does not properly set up a memcpy destination, leading to an invalid write operation. NOTE: this outcome occurs when accessing a `data.mdb` file supplied by an attacker.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + { + "package": { + "ecosystem": "PyPI", + "name": "lmdb" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "0.97" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-16224" + }, + { + "type": "WEB", + "url": "https://github.com/TeamSeri0us/pocs/tree/master/lmdb/lmdb%20initialization%20vuln" + }, + { + "type": "PACKAGE", + "url": "https://github.com/jnwatson/py-lmdb" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "CRITICAL", + "github_reviewed": true, + "github_reviewed_at": "2024-04-22T22:36:13Z", + "nvd_published_at": "2019-09-11T15:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2022/05/GHSA-c74c-p4p7-r8q5/GHSA-c74c-p4p7-r8q5.json b/advisories/github-reviewed/2022/05/GHSA-c74c-p4p7-r8q5/GHSA-c74c-p4p7-r8q5.json new file mode 100644 index 00000000000..7838aa35687 --- /dev/null +++ b/advisories/github-reviewed/2022/05/GHSA-c74c-p4p7-r8q5/GHSA-c74c-p4p7-r8q5.json @@ -0,0 +1,61 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c74c-p4p7-r8q5", + "modified": "2024-04-22T22:36:10Z", + "published": "2022-05-24T16:55:55Z", + "aliases": [ + "CVE-2019-16225" + ], + "summary": "py-lmdb Invalid write operation", + "details": "An issue was discovered in py-lmdb 0.97. For certain values of `mp_flags`, `mdb_page_touch `does not properly set up `mc->mc_pg[mc->top]`, leading to an invalid write operation. NOTE: this outcome occurs when accessing a `data.mdb` file supplied by an attacker.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + { + "package": { + "ecosystem": "PyPI", + "name": "lmdb" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "0.97" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-16225" + }, + { + "type": "WEB", + "url": "https://github.com/TeamSeri0us/pocs/tree/master/lmdb/lmdb%20write%20to%20illegal%20address" + }, + { + "type": "PACKAGE", + "url": "https://github.com/jnwatson/py-lmdb" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "CRITICAL", + "github_reviewed": true, + "github_reviewed_at": "2024-04-22T22:36:10Z", + "nvd_published_at": "2019-09-11T15:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2022/05/GHSA-ggwq-vrgp-6gv4/GHSA-ggwq-vrgp-6gv4.json b/advisories/github-reviewed/2022/05/GHSA-ggwq-vrgp-6gv4/GHSA-ggwq-vrgp-6gv4.json new file mode 100644 index 00000000000..1e2fb0ebda1 --- /dev/null +++ b/advisories/github-reviewed/2022/05/GHSA-ggwq-vrgp-6gv4/GHSA-ggwq-vrgp-6gv4.json @@ -0,0 +1,61 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ggwq-vrgp-6gv4", + "modified": "2024-04-22T22:36:08Z", + "published": "2022-05-24T16:55:56Z", + "aliases": [ + "CVE-2019-16228" + ], + "summary": "py-lmdb Divide by Zero interruptions", + "details": "An issue was discovered in py-lmdb 0.97. There is a divide-by-zero error in the function mdb_env_open2 if mdb_env_read_header obtains a zero value for a certain size field.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + { + "package": { + "ecosystem": "PyPI", + "name": "lmdb" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "0.97" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-16228" + }, + { + "type": "WEB", + "url": "https://github.com/TeamSeri0us/pocs/tree/master/lmdb/FPE" + }, + { + "type": "PACKAGE", + "url": "https://github.com/jnwatson/py-lmdb" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-369" + ], + "severity": "HIGH", + "github_reviewed": true, + "github_reviewed_at": "2024-04-22T22:36:08Z", + "nvd_published_at": "2019-09-11T15:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2022/05/GHSA-pf3p-v9xp-mrvf/GHSA-pf3p-v9xp-mrvf.json b/advisories/github-reviewed/2022/05/GHSA-pf3p-v9xp-mrvf/GHSA-pf3p-v9xp-mrvf.json new file mode 100644 index 00000000000..15db00d120b --- /dev/null +++ b/advisories/github-reviewed/2022/05/GHSA-pf3p-v9xp-mrvf/GHSA-pf3p-v9xp-mrvf.json @@ -0,0 +1,61 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pf3p-v9xp-mrvf", + "modified": "2024-04-22T22:36:09Z", + "published": "2022-05-24T22:00:30Z", + "aliases": [ + "CVE-2019-16227" + ], + "summary": "py_lmdb Invalid write operation", + "details": "An issue was discovered in py-lmdb 0.97. For certain values of `mn_flags`, `mdb_cursor_set` triggers a memcpy with an invalid write operation within `mdb_xcursor_init1`. NOTE: this outcome occurs when accessing a `data.mdb` file supplied by an attacker.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + { + "package": { + "ecosystem": "PyPI", + "name": "lmdb" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "0.97" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-16227" + }, + { + "type": "WEB", + "url": "https://github.com/TeamSeri0us/pocs/tree/master/lmdb/lmdb%20memcpy%20illegal%20dst" + }, + { + "type": "PACKAGE", + "url": "https://github.com/jnwatson/py-lmdb" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "CRITICAL", + "github_reviewed": true, + "github_reviewed_at": "2024-04-22T22:36:09Z", + "nvd_published_at": "2019-09-11T15:15:00Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-v9pc-9mvp-x87g/GHSA-v9pc-9mvp-x87g.json b/advisories/github-reviewed/2022/05/GHSA-v9pc-9mvp-x87g/GHSA-v9pc-9mvp-x87g.json similarity index 59% rename from advisories/unreviewed/2022/05/GHSA-v9pc-9mvp-x87g/GHSA-v9pc-9mvp-x87g.json rename to advisories/github-reviewed/2022/05/GHSA-v9pc-9mvp-x87g/GHSA-v9pc-9mvp-x87g.json index 989fbb677b7..29d8131dc9e 100644 --- a/advisories/unreviewed/2022/05/GHSA-v9pc-9mvp-x87g/GHSA-v9pc-9mvp-x87g.json +++ b/advisories/github-reviewed/2022/05/GHSA-v9pc-9mvp-x87g/GHSA-v9pc-9mvp-x87g.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-v9pc-9mvp-x87g", - "modified": "2022-05-17T02:47:20Z", + "modified": "2024-04-22T22:34:49Z", "published": "2022-05-17T02:47:20Z", "aliases": [ "CVE-2016-3076" ], + "summary": "Pillow Buffer overflow in Jpeg2KEncode.c", "details": "Heap-based buffer overflow in the j2k_encode_entry function in Pillow 2.5.0 through 3.1.1 allows remote attackers to cause a denial of service (memory corruption) via a crafted Jpeg2000 file.", "severity": [ { @@ -14,7 +15,25 @@ } ], "affected": [ - + { + "package": { + "ecosystem": "PyPI", + "name": "pillow" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.5.0" + }, + { + "fixed": "3.1.2" + } + ] + } + ] + } ], "references": [ { @@ -25,6 +44,14 @@ "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1321929" }, + { + "type": "PACKAGE", + "url": "https://github.com/python-pillow/Pillow" + }, + { + "type": "WEB", + "url": "https://github.com/python-pillow/Pillow/blob/4.1.x/docs/releasenotes/3.1.2.rst" + }, { "type": "WEB", "url": "http://pillow.readthedocs.io/en/4.1.x/releasenotes/3.1.2.html" @@ -39,8 +66,8 @@ "CWE-119" ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-04-22T22:34:49Z", "nvd_published_at": "2017-04-24T18:59:00Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/10/GHSA-5pj3-6fqm-8m7m/GHSA-5pj3-6fqm-8m7m.json b/advisories/github-reviewed/2022/10/GHSA-5pj3-6fqm-8m7m/GHSA-5pj3-6fqm-8m7m.json similarity index 64% rename from advisories/unreviewed/2022/10/GHSA-5pj3-6fqm-8m7m/GHSA-5pj3-6fqm-8m7m.json rename to advisories/github-reviewed/2022/10/GHSA-5pj3-6fqm-8m7m/GHSA-5pj3-6fqm-8m7m.json index 9159713efa0..285967a0bc4 100644 --- a/advisories/unreviewed/2022/10/GHSA-5pj3-6fqm-8m7m/GHSA-5pj3-6fqm-8m7m.json +++ b/advisories/github-reviewed/2022/10/GHSA-5pj3-6fqm-8m7m/GHSA-5pj3-6fqm-8m7m.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-5pj3-6fqm-8m7m", - "modified": "2022-11-01T19:00:28Z", + "modified": "2024-04-22T22:35:35Z", "published": "2022-10-30T12:00:28Z", "aliases": [ "CVE-2022-44020" ], + "summary": "OpenStack Sushy-Tools and VirtualBMC Improper Preservation of Permissions", "details": "An issue was discovered in OpenStack Sushy-Tools through 0.21.0 and VirtualBMC through 2.2.2. Changing the boot device configuration with these packages removes password protection from the managed libvirt XML domain. NOTE: this only affects an \"unsupported, production-like configuration.\"", "severity": [ { @@ -14,13 +15,54 @@ } ], "affected": [ - + { + "package": { + "ecosystem": "PyPI", + "name": "sushy-tools" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.21.1" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "PyPI", + "name": "virtualbmc" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.0.0" + } + ] + } + ] + } ], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-44020" }, + { + "type": "PACKAGE", + "url": "https://github.com/umago/virtualbmc" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GAD7QJIUWPCKJIGYP7PPHH5DILOEONFE" @@ -51,8 +93,8 @@ "CWE-281" ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-04-22T22:35:35Z", "nvd_published_at": "2022-10-30T00:15:00Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-9q62-r72g-pvv7/GHSA-9q62-r72g-pvv7.json b/advisories/unreviewed/2022/05/GHSA-9q62-r72g-pvv7/GHSA-9q62-r72g-pvv7.json deleted file mode 100644 index fb03cced127..00000000000 --- a/advisories/unreviewed/2022/05/GHSA-9q62-r72g-pvv7/GHSA-9q62-r72g-pvv7.json +++ /dev/null @@ -1,35 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-9q62-r72g-pvv7", - "modified": "2022-05-24T16:55:55Z", - "published": "2022-05-24T16:55:55Z", - "aliases": [ - "CVE-2019-16224" - ], - "details": "An issue was discovered in py-lmdb 0.97. For certain values of md_flags, mdb_node_add does not properly set up a memcpy destination, leading to an invalid write operation.", - "severity": [ - - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-16224" - }, - { - "type": "WEB", - "url": "https://github.com/TeamSeri0us/pocs/tree/master/lmdb/lmdb%20initialization%20vuln" - } - ], - "database_specific": { - "cwe_ids": [ - - ], - "severity": null, - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2019-09-11T15:15:00Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-c74c-p4p7-r8q5/GHSA-c74c-p4p7-r8q5.json b/advisories/unreviewed/2022/05/GHSA-c74c-p4p7-r8q5/GHSA-c74c-p4p7-r8q5.json deleted file mode 100644 index 218dc973a2a..00000000000 --- a/advisories/unreviewed/2022/05/GHSA-c74c-p4p7-r8q5/GHSA-c74c-p4p7-r8q5.json +++ /dev/null @@ -1,35 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-c74c-p4p7-r8q5", - "modified": "2022-05-24T16:55:55Z", - "published": "2022-05-24T16:55:55Z", - "aliases": [ - "CVE-2019-16225" - ], - "details": "An issue was discovered in py-lmdb 0.97. For certain values of mp_flags, mdb_page_touch does not properly set up mc->mc_pg[mc->top], leading to an invalid write operation.", - "severity": [ - - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-16225" - }, - { - "type": "WEB", - "url": "https://github.com/TeamSeri0us/pocs/tree/master/lmdb/lmdb%20write%20to%20illegal%20address" - } - ], - "database_specific": { - "cwe_ids": [ - - ], - "severity": null, - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2019-09-11T15:15:00Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-ggwq-vrgp-6gv4/GHSA-ggwq-vrgp-6gv4.json b/advisories/unreviewed/2022/05/GHSA-ggwq-vrgp-6gv4/GHSA-ggwq-vrgp-6gv4.json deleted file mode 100644 index 0ceca6eddc5..00000000000 --- a/advisories/unreviewed/2022/05/GHSA-ggwq-vrgp-6gv4/GHSA-ggwq-vrgp-6gv4.json +++ /dev/null @@ -1,35 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-ggwq-vrgp-6gv4", - "modified": "2022-05-24T16:55:56Z", - "published": "2022-05-24T16:55:56Z", - "aliases": [ - "CVE-2019-16228" - ], - "details": "An issue was discovered in py-lmdb 0.97. There is a divide-by-zero error in the function mdb_env_open2 if mdb_env_read_header obtains a zero value for a certain size field.", - "severity": [ - - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-16228" - }, - { - "type": "WEB", - "url": "https://github.com/TeamSeri0us/pocs/tree/master/lmdb/FPE" - } - ], - "database_specific": { - "cwe_ids": [ - - ], - "severity": null, - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2019-09-11T15:15:00Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-pf3p-v9xp-mrvf/GHSA-pf3p-v9xp-mrvf.json b/advisories/unreviewed/2022/05/GHSA-pf3p-v9xp-mrvf/GHSA-pf3p-v9xp-mrvf.json deleted file mode 100644 index 0681092f33f..00000000000 --- a/advisories/unreviewed/2022/05/GHSA-pf3p-v9xp-mrvf/GHSA-pf3p-v9xp-mrvf.json +++ /dev/null @@ -1,35 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-pf3p-v9xp-mrvf", - "modified": "2022-05-24T22:00:30Z", - "published": "2022-05-24T22:00:30Z", - "aliases": [ - "CVE-2019-16227" - ], - "details": "An issue was discovered in py_lmdb 0.97. For certain values of mn_flags, mdb_cursor_set triggers a memcpy with an invalid write operation within mdb_xcursor_init1.", - "severity": [ - - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-16227" - }, - { - "type": "WEB", - "url": "https://github.com/TeamSeri0us/pocs/tree/master/lmdb/lmdb%20memcpy%20illegal%20dst" - } - ], - "database_specific": { - "cwe_ids": [ - - ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2019-09-11T15:15:00Z" - } -} \ No newline at end of file