Skip to content

File tree

7 files changed

+220
-12
lines changed

7 files changed

+220
-12
lines changed

advisories/github-reviewed/2024/09/GHSA-39v3-f278-vj3g/GHSA-39v3-f278-vj3g.json

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-39v3-f278-vj3g",
4-
"modified": "2024-09-17T21:30:20Z",
4+
"modified": "2024-09-17T22:29:19Z",
55
"published": "2024-09-17T21:30:20Z",
66
"aliases": [
77
"CVE-2024-45816"
@@ -44,6 +44,10 @@
4444
"type": "WEB",
4545
"url": "https://github.com/backstage/backstage/security/advisories/GHSA-39v3-f278-vj3g"
4646
},
47+
{
48+
"type": "ADVISORY",
49+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45816"
50+
},
4751
{
4852
"type": "PACKAGE",
4953
"url": "https://github.com/backstage/backstage"
@@ -56,6 +60,6 @@
5660
"severity": "MODERATE",
5761
"github_reviewed": true,
5862
"github_reviewed_at": "2024-09-17T21:30:20Z",
59-
"nvd_published_at": null
63+
"nvd_published_at": "2024-09-17T21:15:12Z"
6064
}
6165
}

advisories/github-reviewed/2024/09/GHSA-3x3f-jcp3-g22j/GHSA-3x3f-jcp3-g22j.json

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-3x3f-jcp3-g22j",
4-
"modified": "2024-09-17T21:29:49Z",
4+
"modified": "2024-09-17T22:29:09Z",
55
"published": "2024-09-17T21:29:49Z",
66
"aliases": [
77
"CVE-2024-45815"
@@ -44,6 +44,10 @@
4444
"type": "WEB",
4545
"url": "https://github.com/backstage/backstage/security/advisories/GHSA-3x3f-jcp3-g22j"
4646
},
47+
{
48+
"type": "ADVISORY",
49+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45815"
50+
},
4751
{
4852
"type": "PACKAGE",
4953
"url": "https://github.com/backstage/backstage"
@@ -56,6 +60,6 @@
5660
"severity": "MODERATE",
5761
"github_reviewed": true,
5862
"github_reviewed_at": "2024-09-17T21:29:49Z",
59-
"nvd_published_at": null
63+
"nvd_published_at": "2024-09-17T21:15:12Z"
6064
}
6165
}

advisories/github-reviewed/2024/09/GHSA-4p75-5p53-65m9/GHSA-4p75-5p53-65m9.json

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-4p75-5p53-65m9",
4-
"modified": "2024-09-17T14:58:45Z",
4+
"modified": "2024-09-17T22:27:56Z",
55
"published": "2024-09-17T14:58:45Z",
66
"aliases": [
77
"CVE-2024-45604"
@@ -44,6 +44,10 @@
4444
"type": "WEB",
4545
"url": "https://github.com/contao/contao/security/advisories/GHSA-4p75-5p53-65m9"
4646
},
47+
{
48+
"type": "ADVISORY",
49+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45604"
50+
},
4751
{
4852
"type": "WEB",
4953
"url": "https://github.com/contao/contao/commit/63409c6bdfd95197d9906e229d765b630d45742e"
@@ -64,6 +68,6 @@
6468
"severity": "MODERATE",
6569
"github_reviewed": true,
6670
"github_reviewed_at": "2024-09-17T14:58:45Z",
67-
"nvd_published_at": null
71+
"nvd_published_at": "2024-09-17T20:15:04Z"
6872
}
6973
}

advisories/github-reviewed/2024/09/GHSA-64vr-g452-qvp3/GHSA-64vr-g452-qvp3.json

Lines changed: 22 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-64vr-g452-qvp3",
4-
"modified": "2024-09-17T19:28:01Z",
4+
"modified": "2024-09-17T22:28:57Z",
55
"published": "2024-09-17T19:28:01Z",
66
"aliases": [
77
"CVE-2024-45812"
@@ -129,6 +129,14 @@
129129
"type": "WEB",
130130
"url": "https://github.com/vitejs/vite/security/advisories/GHSA-64vr-g452-qvp3"
131131
},
132+
{
133+
"type": "WEB",
134+
"url": "https://github.com/webpack/webpack/security/advisories/GHSA-4vvj-4cpr-p986"
135+
},
136+
{
137+
"type": "ADVISORY",
138+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45812"
139+
},
132140
{
133141
"type": "WEB",
134142
"url": "https://github.com/vitejs/vite/commit/179b17773cf35c73ddb041f9e6c703fd9f3126af"
@@ -141,6 +149,10 @@
141149
"type": "WEB",
142150
"url": "https://github.com/vitejs/vite/commit/2ddd8541ec3b2d2e5b698749e0f2362ef28056bd"
143151
},
152+
{
153+
"type": "WEB",
154+
"url": "https://github.com/vitejs/vite/commit/ade1d89660e17eedfd35652165b0c26905259fad"
155+
},
144156
{
145157
"type": "WEB",
146158
"url": "https://github.com/vitejs/vite/commit/e8127166979e7ace6eeaa2c3b733c8994caa31f3"
@@ -152,6 +164,14 @@
152164
{
153165
"type": "PACKAGE",
154166
"url": "https://github.com/vitejs/vite"
167+
},
168+
{
169+
"type": "WEB",
170+
"url": "https://research.securitum.com/xss-in-amp4email-dom-clobbering"
171+
},
172+
{
173+
"type": "WEB",
174+
"url": "https://scnps.co/papers/sp23_domclob.pdf"
155175
}
156176
],
157177
"database_specific": {
@@ -161,6 +181,6 @@
161181
"severity": "MODERATE",
162182
"github_reviewed": true,
163183
"github_reviewed_at": "2024-09-17T19:28:01Z",
164-
"nvd_published_at": null
184+
"nvd_published_at": "2024-09-17T20:15:06Z"
165185
}
166186
}

advisories/github-reviewed/2024/09/GHSA-9cwx-2883-4wfx/GHSA-9cwx-2883-4wfx.json

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-9cwx-2883-4wfx",
4-
"modified": "2024-09-17T18:44:13Z",
4+
"modified": "2024-09-17T22:28:27Z",
55
"published": "2024-09-17T18:44:12Z",
66
"aliases": [
77
"CVE-2024-45811"
@@ -132,6 +132,10 @@
132132
"type": "WEB",
133133
"url": "https://github.com/vitejs/vite/security/advisories/GHSA-9cwx-2883-4wfx"
134134
},
135+
{
136+
"type": "ADVISORY",
137+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45811"
138+
},
135139
{
136140
"type": "WEB",
137141
"url": "https://github.com/vitejs/vite/commit/4573a6fd6f1b097fb7296a3e135e0646b996b249"
@@ -165,6 +169,6 @@
165169
"severity": "MODERATE",
166170
"github_reviewed": true,
167171
"github_reviewed_at": "2024-09-17T18:44:12Z",
168-
"nvd_published_at": null
172+
"nvd_published_at": "2024-09-17T20:15:05Z"
169173
}
170174
}
Lines changed: 164 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,164 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-gc7q-jgjv-vjr2",
4+
"modified": "2024-09-17T22:29:01Z",
5+
"published": "2024-09-17T22:29:01Z",
6+
"aliases": [
7+
"CVE-2024-4629"
8+
],
9+
"summary": "Keycloak Services has a potential bypass of brute force protection",
10+
"details": "If an attacker launches many login attempts in parallel then the attacker can have more guesses at a password than the brute force protection configuration permits. This is due to the brute force check occurring before the brute force protector has locked the user.\n\n**Acknowledgements:**\nSpecial thanks to Maurizio Agazzini for reporting this issue and helping us improve our project.",
11+
"severity": [
12+
{
13+
"type": "CVSS_V3",
14+
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
15+
},
16+
{
17+
"type": "CVSS_V4",
18+
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"
19+
}
20+
],
21+
"affected": [
22+
{
23+
"package": {
24+
"ecosystem": "Maven",
25+
"name": "org.keycloak:keycloak-services"
26+
},
27+
"ranges": [
28+
{
29+
"type": "ECOSYSTEM",
30+
"events": [
31+
{
32+
"introduced": "0"
33+
},
34+
{
35+
"fixed": "22.0.12"
36+
}
37+
]
38+
}
39+
]
40+
},
41+
{
42+
"package": {
43+
"ecosystem": "Maven",
44+
"name": "org.keycloak:keycloak-services"
45+
},
46+
"ranges": [
47+
{
48+
"type": "ECOSYSTEM",
49+
"events": [
50+
{
51+
"introduced": "23.0.0"
52+
},
53+
{
54+
"fixed": "24.0.7"
55+
}
56+
]
57+
}
58+
]
59+
},
60+
{
61+
"package": {
62+
"ecosystem": "Maven",
63+
"name": "org.keycloak:keycloak-services"
64+
},
65+
"ranges": [
66+
{
67+
"type": "ECOSYSTEM",
68+
"events": [
69+
{
70+
"introduced": "25.0.0"
71+
},
72+
{
73+
"fixed": "25.0.4"
74+
}
75+
]
76+
}
77+
]
78+
}
79+
],
80+
"references": [
81+
{
82+
"type": "WEB",
83+
"url": "https://github.com/keycloak/keycloak/security/advisories/GHSA-gc7q-jgjv-vjr2"
84+
},
85+
{
86+
"type": "ADVISORY",
87+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4629"
88+
},
89+
{
90+
"type": "WEB",
91+
"url": "https://github.com/keycloak/keycloak/commit/d78b3072ffffbff3954bf9f3181e3daf8e93c1ab"
92+
},
93+
{
94+
"type": "WEB",
95+
"url": "https://github.com/keycloak/keycloak/commit/c8053dd812d9b9f05b293f901b9dc39e061ebb88"
96+
},
97+
{
98+
"type": "WEB",
99+
"url": "https://github.com/keycloak/keycloak/commit/b25c28458a562abda2f84fc684e59cce8577e562"
100+
},
101+
{
102+
"type": "WEB",
103+
"url": "https://github.com/keycloak/keycloak/commit/99f92ad5fff5555d53930c2d32f8be3e08c514c1"
104+
},
105+
{
106+
"type": "WEB",
107+
"url": "https://github.com/keycloak/keycloak/commit/461fa631dc55b9739c9ed8c49de9f5b213955200"
108+
},
109+
{
110+
"type": "WEB",
111+
"url": "https://github.com/keycloak/keycloak/commit/2fb358e1a21c5387cdc11100ce3562b4dcfe5416"
112+
},
113+
{
114+
"type": "PACKAGE",
115+
"url": "https://github.com/keycloak/keycloak"
116+
},
117+
{
118+
"type": "WEB",
119+
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2276761"
120+
},
121+
{
122+
"type": "WEB",
123+
"url": "https://access.redhat.com/security/cve/CVE-2024-4629"
124+
},
125+
{
126+
"type": "WEB",
127+
"url": "https://access.redhat.com/errata/RHSA-2024:6501"
128+
},
129+
{
130+
"type": "WEB",
131+
"url": "https://access.redhat.com/errata/RHSA-2024:6500"
132+
},
133+
{
134+
"type": "WEB",
135+
"url": "https://access.redhat.com/errata/RHSA-2024:6499"
136+
},
137+
{
138+
"type": "WEB",
139+
"url": "https://access.redhat.com/errata/RHSA-2024:6497"
140+
},
141+
{
142+
"type": "WEB",
143+
"url": "https://access.redhat.com/errata/RHSA-2024:6495"
144+
},
145+
{
146+
"type": "WEB",
147+
"url": "https://access.redhat.com/errata/RHSA-2024:6494"
148+
},
149+
{
150+
"type": "WEB",
151+
"url": "https://access.redhat.com/errata/RHSA-2024:6493"
152+
}
153+
],
154+
"database_specific": {
155+
"cwe_ids": [
156+
"CWE-307",
157+
"CWE-837"
158+
],
159+
"severity": "MODERATE",
160+
"github_reviewed": true,
161+
"github_reviewed_at": "2024-09-17T22:29:01Z",
162+
"nvd_published_at": null
163+
}
164+
}

advisories/github-reviewed/2024/09/GHSA-v345-w9f2-mpm5/GHSA-v345-w9f2-mpm5.json

Lines changed: 10 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-v345-w9f2-mpm5",
4-
"modified": "2024-09-17T17:55:38Z",
4+
"modified": "2024-09-17T22:28:09Z",
55
"published": "2024-09-17T17:55:38Z",
66
"aliases": [
77
"CVE-2024-45606"
@@ -44,6 +44,10 @@
4444
"type": "WEB",
4545
"url": "https://github.com/getsentry/sentry/security/advisories/GHSA-v345-w9f2-mpm5"
4646
},
47+
{
48+
"type": "ADVISORY",
49+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45606"
50+
},
4751
{
4852
"type": "WEB",
4953
"url": "https://github.com/getsentry/sentry/pull/77016"
@@ -52,6 +56,10 @@
5256
"type": "WEB",
5357
"url": "https://github.com/getsentry/sentry/commit/e8e71708758e1f9f56ce815ace73fe60d9e608dc"
5458
},
59+
{
60+
"type": "WEB",
61+
"url": "https://github.com/getsentry/self-hosted"
62+
},
5563
{
5664
"type": "PACKAGE",
5765
"url": "https://github.com/getsentry/sentry"
@@ -64,6 +72,6 @@
6472
"severity": "HIGH",
6573
"github_reviewed": true,
6674
"github_reviewed_at": "2024-09-17T17:55:38Z",
67-
"nvd_published_at": null
75+
"nvd_published_at": "2024-09-17T20:15:05Z"
6876
}
6977
}

0 commit comments

Comments
 (0)