mirror of
https://github.com/CVEProject/cvelist.git
synced 2025-06-19 17:32:41 +00:00
"-Synchronized-Data."
This commit is contained in:
parent
91fd8daea4
commit
870d7019c0
@ -86,7 +86,9 @@
|
|||||||
"references": {
|
"references": {
|
||||||
"reference_data": [
|
"reference_data": [
|
||||||
{
|
{
|
||||||
"url": "http://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-3gvq-h42f-v3c7"
|
"url": "http://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-3gvq-h42f-v3c7",
|
||||||
|
"refsource": "MISC",
|
||||||
|
"name": "http://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-3gvq-h42f-v3c7"
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
|
@ -78,7 +78,9 @@
|
|||||||
"references": {
|
"references": {
|
||||||
"reference_data": [
|
"reference_data": [
|
||||||
{
|
{
|
||||||
"url": "http://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-hg2w-62p6-g67c"
|
"url": "http://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-hg2w-62p6-g67c",
|
||||||
|
"refsource": "MISC",
|
||||||
|
"name": "http://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-hg2w-62p6-g67c"
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
|
@ -78,7 +78,9 @@
|
|||||||
"references": {
|
"references": {
|
||||||
"reference_data": [
|
"reference_data": [
|
||||||
{
|
{
|
||||||
"url": "http://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-gc66-xfrc-24qr"
|
"url": "http://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-gc66-xfrc-24qr",
|
||||||
|
"refsource": "MISC",
|
||||||
|
"name": "http://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-gc66-xfrc-24qr"
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
|
@ -78,7 +78,9 @@
|
|||||||
"references": {
|
"references": {
|
||||||
"reference_data": [
|
"reference_data": [
|
||||||
{
|
{
|
||||||
"url": "http://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-f6vh-7v4x-8fjp"
|
"url": "http://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-f6vh-7v4x-8fjp",
|
||||||
|
"refsource": "MISC",
|
||||||
|
"name": "http://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-f6vh-7v4x-8fjp"
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
|
@ -41,7 +41,7 @@
|
|||||||
"description_data": [
|
"description_data": [
|
||||||
{
|
{
|
||||||
"lang": "eng",
|
"lang": "eng",
|
||||||
"value": "Improper Handling of Insufficient Permissions or Privileges in zephyr. Zephyr versions >= v1.14.2, >= v2.2.0 contain Improper Handling of Insufficient Permissions or Privileges (CWE-280). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-vf79-hqwm-w4xc"
|
"value": "Improper Handling of Insufficient Permissions or Privileges in zephyr. Zephyr versions >= v1.14.2, >= v2.2.0 contain Improper Handling of Insufficient Permissions or Privileges (CWE-280). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-vf79-hqwm-w4xc"
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
@ -78,7 +78,9 @@
|
|||||||
"references": {
|
"references": {
|
||||||
"reference_data": [
|
"reference_data": [
|
||||||
{
|
{
|
||||||
"url": "http://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-vf79-hqwm-w4xc"
|
"url": "http://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-vf79-hqwm-w4xc",
|
||||||
|
"refsource": "MISC",
|
||||||
|
"name": "http://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-vf79-hqwm-w4xc"
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
|
@ -78,7 +78,9 @@
|
|||||||
"references": {
|
"references": {
|
||||||
"reference_data": [
|
"reference_data": [
|
||||||
{
|
{
|
||||||
"url": "http://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-7fhv-rgxr-x56h"
|
"url": "http://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-7fhv-rgxr-x56h",
|
||||||
|
"refsource": "MISC",
|
||||||
|
"name": "http://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-7fhv-rgxr-x56h"
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
|
@ -78,7 +78,9 @@
|
|||||||
"references": {
|
"references": {
|
||||||
"reference_data": [
|
"reference_data": [
|
||||||
{
|
{
|
||||||
"url": "http://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-5qhg-j6wc-4f6q"
|
"url": "http://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-5qhg-j6wc-4f6q",
|
||||||
|
"refsource": "MISC",
|
||||||
|
"name": "http://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-5qhg-j6wc-4f6q"
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
|
@ -78,7 +78,9 @@
|
|||||||
"references": {
|
"references": {
|
||||||
"reference_data": [
|
"reference_data": [
|
||||||
{
|
{
|
||||||
"url": "http://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-hx4p-j86p-2mhr"
|
"url": "http://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-hx4p-j86p-2mhr",
|
||||||
|
"refsource": "MISC",
|
||||||
|
"name": "http://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-hx4p-j86p-2mhr"
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
|
@ -78,7 +78,9 @@
|
|||||||
"references": {
|
"references": {
|
||||||
"reference_data": [
|
"reference_data": [
|
||||||
{
|
{
|
||||||
"url": "http://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-mm57-9hqw-qh44"
|
"url": "http://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-mm57-9hqw-qh44",
|
||||||
|
"refsource": "MISC",
|
||||||
|
"name": "http://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-mm57-9hqw-qh44"
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
|
@ -86,7 +86,9 @@
|
|||||||
"references": {
|
"references": {
|
||||||
"reference_data": [
|
"reference_data": [
|
||||||
{
|
{
|
||||||
"url": "http://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-g9mg-fj58-6fqh"
|
"url": "http://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-g9mg-fj58-6fqh",
|
||||||
|
"refsource": "MISC",
|
||||||
|
"name": "http://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-g9mg-fj58-6fqh"
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
|
@ -78,7 +78,9 @@
|
|||||||
"references": {
|
"references": {
|
||||||
"reference_data": [
|
"reference_data": [
|
||||||
{
|
{
|
||||||
"url": "http://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-94vp-8gc2-rm45"
|
"url": "http://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-94vp-8gc2-rm45",
|
||||||
|
"refsource": "MISC",
|
||||||
|
"name": "http://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-94vp-8gc2-rm45"
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
|
@ -1,110 +1,110 @@
|
|||||||
{
|
{
|
||||||
"references" : {
|
"references": {
|
||||||
"reference_data" : [
|
"reference_data": [
|
||||||
{
|
|
||||||
"name" : "https://www.ibm.com/support/pages/node/6454303",
|
|
||||||
"title" : "IBM Security Bulletin 6454303 (8335-GCA)",
|
|
||||||
"url" : "https://www.ibm.com/support/pages/node/6454303",
|
|
||||||
"refsource" : "CONFIRM"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"name" : "ibm-bmc-cve20204839-bo (190037)",
|
|
||||||
"title" : "X-Force Vulnerability Report",
|
|
||||||
"url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/190037",
|
|
||||||
"refsource" : "XF"
|
|
||||||
}
|
|
||||||
]
|
|
||||||
},
|
|
||||||
"impact" : {
|
|
||||||
"cvssv3" : {
|
|
||||||
"TM" : {
|
|
||||||
"RC" : "C",
|
|
||||||
"RL" : "O",
|
|
||||||
"E" : "U"
|
|
||||||
},
|
|
||||||
"BM" : {
|
|
||||||
"SCORE" : "4.900",
|
|
||||||
"PR" : "H",
|
|
||||||
"UI" : "N",
|
|
||||||
"AC" : "L",
|
|
||||||
"S" : "U",
|
|
||||||
"A" : "H",
|
|
||||||
"AV" : "N",
|
|
||||||
"I" : "N",
|
|
||||||
"C" : "N"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"problemtype" : {
|
|
||||||
"problemtype_data" : [
|
|
||||||
{
|
|
||||||
"description" : [
|
|
||||||
{
|
|
||||||
"lang" : "eng",
|
|
||||||
"value" : "Denial of Service"
|
|
||||||
}
|
|
||||||
]
|
|
||||||
}
|
|
||||||
]
|
|
||||||
},
|
|
||||||
"data_version" : "4.0",
|
|
||||||
"CVE_data_meta" : {
|
|
||||||
"DATE_PUBLIC" : "2021-05-24T00:00:00",
|
|
||||||
"ASSIGNER" : "psirt@us.ibm.com",
|
|
||||||
"STATE" : "PUBLIC",
|
|
||||||
"ID" : "CVE-2020-4839"
|
|
||||||
},
|
|
||||||
"data_format" : "MITRE",
|
|
||||||
"affects" : {
|
|
||||||
"vendor" : {
|
|
||||||
"vendor_data" : [
|
|
||||||
{
|
{
|
||||||
"product" : {
|
"name": "https://www.ibm.com/support/pages/node/6454303",
|
||||||
"product_data" : [
|
"title": "IBM Security Bulletin 6454303 (8335-GCA)",
|
||||||
{
|
"url": "https://www.ibm.com/support/pages/node/6454303",
|
||||||
"product_name" : "8335-GTB",
|
"refsource": "CONFIRM"
|
||||||
"version" : {
|
},
|
||||||
"version_data" : [
|
{
|
||||||
{
|
"name": "ibm-bmc-cve20204839-bo (190037)",
|
||||||
"version_value" : "OP820"
|
"title": "X-Force Vulnerability Report",
|
||||||
}
|
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/190037",
|
||||||
]
|
"refsource": "XF"
|
||||||
}
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"product_name" : "8335-GTA",
|
|
||||||
"version" : {
|
|
||||||
"version_data" : [
|
|
||||||
{
|
|
||||||
"version_value" : "OP820"
|
|
||||||
}
|
|
||||||
]
|
|
||||||
}
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"version" : {
|
|
||||||
"version_data" : [
|
|
||||||
{
|
|
||||||
"version_value" : "OP820"
|
|
||||||
}
|
|
||||||
]
|
|
||||||
},
|
|
||||||
"product_name" : "8335-GCA"
|
|
||||||
}
|
|
||||||
]
|
|
||||||
},
|
|
||||||
"vendor_name" : "IBM"
|
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
}
|
},
|
||||||
},
|
"impact": {
|
||||||
"data_type" : "CVE",
|
"cvssv3": {
|
||||||
"description" : {
|
"TM": {
|
||||||
"description_data" : [
|
"RC": "C",
|
||||||
{
|
"RL": "O",
|
||||||
"lang" : "eng",
|
"E": "U"
|
||||||
"value" : "IBM Host firmware for LC-class Systems is vulnerable to a stack based buffer overflow, caused by improper bounds checking. A remote privileged attacker could exploit this vulnerability and cause a denial of service. IBM X-Force ID: 190037."
|
},
|
||||||
}
|
"BM": {
|
||||||
]
|
"SCORE": "4.900",
|
||||||
}
|
"PR": "H",
|
||||||
}
|
"UI": "N",
|
||||||
|
"AC": "L",
|
||||||
|
"S": "U",
|
||||||
|
"A": "H",
|
||||||
|
"AV": "N",
|
||||||
|
"I": "N",
|
||||||
|
"C": "N"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"problemtype": {
|
||||||
|
"problemtype_data": [
|
||||||
|
{
|
||||||
|
"description": [
|
||||||
|
{
|
||||||
|
"lang": "eng",
|
||||||
|
"value": "Denial of Service"
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"data_version": "4.0",
|
||||||
|
"CVE_data_meta": {
|
||||||
|
"DATE_PUBLIC": "2021-05-24T00:00:00",
|
||||||
|
"ASSIGNER": "psirt@us.ibm.com",
|
||||||
|
"STATE": "PUBLIC",
|
||||||
|
"ID": "CVE-2020-4839"
|
||||||
|
},
|
||||||
|
"data_format": "MITRE",
|
||||||
|
"affects": {
|
||||||
|
"vendor": {
|
||||||
|
"vendor_data": [
|
||||||
|
{
|
||||||
|
"product": {
|
||||||
|
"product_data": [
|
||||||
|
{
|
||||||
|
"product_name": "8335-GTB",
|
||||||
|
"version": {
|
||||||
|
"version_data": [
|
||||||
|
{
|
||||||
|
"version_value": "OP820"
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"product_name": "8335-GTA",
|
||||||
|
"version": {
|
||||||
|
"version_data": [
|
||||||
|
{
|
||||||
|
"version_value": "OP820"
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"version": {
|
||||||
|
"version_data": [
|
||||||
|
{
|
||||||
|
"version_value": "OP820"
|
||||||
|
}
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"product_name": "8335-GCA"
|
||||||
|
}
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"vendor_name": "IBM"
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"data_type": "CVE",
|
||||||
|
"description": {
|
||||||
|
"description_data": [
|
||||||
|
{
|
||||||
|
"lang": "eng",
|
||||||
|
"value": "IBM Host firmware for LC-class Systems is vulnerable to a stack based buffer overflow, caused by improper bounds checking. A remote privileged attacker could exploit this vulnerability and cause a denial of service. IBM X-Force ID: 190037."
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
|
}
|
@ -1,7 +1,8 @@
|
|||||||
{
|
{
|
||||||
"CVE_data_meta": {
|
"CVE_data_meta": {
|
||||||
"ID": "CVE-2021-21657",
|
"ID": "CVE-2021-21657",
|
||||||
"ASSIGNER": "jenkinsci-cert@googlegroups.com"
|
"ASSIGNER": "jenkinsci-cert@googlegroups.com",
|
||||||
|
"STATE": "PUBLIC"
|
||||||
},
|
},
|
||||||
"affects": {
|
"affects": {
|
||||||
"vendor": {
|
"vendor": {
|
||||||
|
@ -1,7 +1,8 @@
|
|||||||
{
|
{
|
||||||
"CVE_data_meta": {
|
"CVE_data_meta": {
|
||||||
"ID": "CVE-2021-21658",
|
"ID": "CVE-2021-21658",
|
||||||
"ASSIGNER": "jenkinsci-cert@googlegroups.com"
|
"ASSIGNER": "jenkinsci-cert@googlegroups.com",
|
||||||
|
"STATE": "PUBLIC"
|
||||||
},
|
},
|
||||||
"affects": {
|
"affects": {
|
||||||
"vendor": {
|
"vendor": {
|
||||||
|
@ -1,7 +1,8 @@
|
|||||||
{
|
{
|
||||||
"CVE_data_meta": {
|
"CVE_data_meta": {
|
||||||
"ID": "CVE-2021-21659",
|
"ID": "CVE-2021-21659",
|
||||||
"ASSIGNER": "jenkinsci-cert@googlegroups.com"
|
"ASSIGNER": "jenkinsci-cert@googlegroups.com",
|
||||||
|
"STATE": "PUBLIC"
|
||||||
},
|
},
|
||||||
"affects": {
|
"affects": {
|
||||||
"vendor": {
|
"vendor": {
|
||||||
|
@ -1,7 +1,8 @@
|
|||||||
{
|
{
|
||||||
"CVE_data_meta": {
|
"CVE_data_meta": {
|
||||||
"ID": "CVE-2021-21660",
|
"ID": "CVE-2021-21660",
|
||||||
"ASSIGNER": "jenkinsci-cert@googlegroups.com"
|
"ASSIGNER": "jenkinsci-cert@googlegroups.com",
|
||||||
|
"STATE": "PUBLIC"
|
||||||
},
|
},
|
||||||
"affects": {
|
"affects": {
|
||||||
"vendor": {
|
"vendor": {
|
||||||
@ -59,7 +60,8 @@
|
|||||||
},
|
},
|
||||||
{
|
{
|
||||||
"name": "https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-21660",
|
"name": "https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-21660",
|
||||||
"url": "https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-21660"
|
"url": "https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-21660",
|
||||||
|
"refsource": "MISC"
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
|
@ -58,7 +58,7 @@
|
|||||||
"description_data": [
|
"description_data": [
|
||||||
{
|
{
|
||||||
"lang": "eng",
|
"lang": "eng",
|
||||||
"value": "A DNS proxy and possible amplification attack vulnerability in WebClientInfo of Apache Wicket allows an attacker to trigger arbitrary DNS lookups from the server when the X-Forwarded-For header is not properly sanitized. This DNS lookup can be engineered to overload an internal DNS server or to slow down request processing of the Apache Wicket application causing a possible denial of service on either the internal infrastructure or the web application itself.\n\nThis issue affects Apache Wicket Apache Wicket 9.x version 9.2.0 and prior versions; Apache Wicket 8.x version 8.11.0 and prior versions; Apache Wicket 7.x version 7.17.0 and prior versions and Apache Wicket 6.x version 6.2.0 and later versions."
|
"value": "A DNS proxy and possible amplification attack vulnerability in WebClientInfo of Apache Wicket allows an attacker to trigger arbitrary DNS lookups from the server when the X-Forwarded-For header is not properly sanitized. This DNS lookup can be engineered to overload an internal DNS server or to slow down request processing of the Apache Wicket application causing a possible denial of service on either the internal infrastructure or the web application itself. This issue affects Apache Wicket Apache Wicket 9.x version 9.2.0 and prior versions; Apache Wicket 8.x version 8.11.0 and prior versions; Apache Wicket 7.x version 7.17.0 and prior versions and Apache Wicket 6.x version 6.2.0 and later versions."
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
@ -80,8 +80,29 @@
|
|||||||
"references": {
|
"references": {
|
||||||
"reference_data": [
|
"reference_data": [
|
||||||
{
|
{
|
||||||
"refsource": "CONFIRM",
|
"refsource": "MISC",
|
||||||
"url": "https://lists.apache.org/thread.html/rc2ef22f90793e158cef65a7e370cdbca023c499d1403d65feeca870d%40%3Cusers.wicket.apache.org%3E"
|
"url": "https://lists.apache.org/thread.html/rc2ef22f90793e158cef65a7e370cdbca023c499d1403d65feeca870d%40%3Cusers.wicket.apache.org%3E",
|
||||||
|
"name": "https://lists.apache.org/thread.html/rc2ef22f90793e158cef65a7e370cdbca023c499d1403d65feeca870d%40%3Cusers.wicket.apache.org%3E"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"refsource": "MLIST",
|
||||||
|
"name": "[wicket-users] 20210525 CVE-2021-23937: Apache Wicket: DNS proxy and possible amplification attack",
|
||||||
|
"url": "https://lists.apache.org/thread.html/rc2ef22f90793e158cef65a7e370cdbca023c499d1403d65feeca870d@%3Cusers.wicket.apache.org%3E"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"refsource": "MLIST",
|
||||||
|
"name": "[wicket-dev] 20210525 CVE-2021-23937: Apache Wicket: DNS proxy and possible amplification attack",
|
||||||
|
"url": "https://lists.apache.org/thread.html/rce158bb896c9ef812393a11646fdef7b9023833e54854c4302ff7b70@%3Cdev.wicket.apache.org%3E"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"refsource": "MLIST",
|
||||||
|
"name": "[wicket-announce] 20210525 CVE-2021-23937: Apache Wicket: DNS proxy and possible amplification attack",
|
||||||
|
"url": "https://lists.apache.org/thread.html/rce23bba1e11368f9f4cccce0e9b02b88dcdac4e4b2304e66bd098cf5@%3Cannounce.wicket.apache.org%3E"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"refsource": "MLIST",
|
||||||
|
"name": "[oss-security] 20210525 CVE-2021-23937: Apache Wicket: DNS proxy and possible amplification attack",
|
||||||
|
"url": "http://www.openwall.com/lists/oss-security/2021/05/25/2"
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
@ -94,4 +115,4 @@
|
|||||||
"value": "Sanitize the X-Forwarded-For header by running an Apache Wicket application behind a reverse HTTP proxy. This proxy should put the client IP address in the X-Forwarded-For header and not pass through the contents of the header as received by the client."
|
"value": "Sanitize the X-Forwarded-For header by running an Apache Wicket application behind a reverse HTTP proxy. This proxy should put the client IP address in the X-Forwarded-For header and not pass through the contents of the header as received by the client."
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
}
|
}
|
@ -1,110 +1,110 @@
|
|||||||
{
|
{
|
||||||
"problemtype" : {
|
"problemtype": {
|
||||||
"problemtype_data" : [
|
"problemtype_data": [
|
||||||
{
|
|
||||||
"description" : [
|
|
||||||
{
|
|
||||||
"lang" : "eng",
|
|
||||||
"value" : "File Manipulation"
|
|
||||||
}
|
|
||||||
]
|
|
||||||
}
|
|
||||||
]
|
|
||||||
},
|
|
||||||
"references" : {
|
|
||||||
"reference_data" : [
|
|
||||||
{
|
|
||||||
"refsource" : "CONFIRM",
|
|
||||||
"name" : "https://www.ibm.com/support/pages/node/6454303",
|
|
||||||
"title" : "IBM Security Bulletin 6454303 (8335-GCA)",
|
|
||||||
"url" : "https://www.ibm.com/support/pages/node/6454303"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"name" : "ibm-bmc-cve202129695-dir-traversal (200558)",
|
|
||||||
"title" : "X-Force Vulnerability Report",
|
|
||||||
"url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/200558",
|
|
||||||
"refsource" : "XF"
|
|
||||||
}
|
|
||||||
]
|
|
||||||
},
|
|
||||||
"impact" : {
|
|
||||||
"cvssv3" : {
|
|
||||||
"BM" : {
|
|
||||||
"PR" : "H",
|
|
||||||
"SCORE" : "4.900",
|
|
||||||
"S" : "U",
|
|
||||||
"UI" : "N",
|
|
||||||
"AC" : "L",
|
|
||||||
"C" : "N",
|
|
||||||
"I" : "H",
|
|
||||||
"AV" : "N",
|
|
||||||
"A" : "N"
|
|
||||||
},
|
|
||||||
"TM" : {
|
|
||||||
"E" : "U",
|
|
||||||
"RC" : "C",
|
|
||||||
"RL" : "O"
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"affects" : {
|
|
||||||
"vendor" : {
|
|
||||||
"vendor_data" : [
|
|
||||||
{
|
{
|
||||||
"vendor_name" : "IBM",
|
"description": [
|
||||||
"product" : {
|
{
|
||||||
"product_data" : [
|
"lang": "eng",
|
||||||
{
|
"value": "File Manipulation"
|
||||||
"product_name" : "8335-GTB",
|
}
|
||||||
"version" : {
|
]
|
||||||
"version_data" : [
|
|
||||||
{
|
|
||||||
"version_value" : "OP820"
|
|
||||||
}
|
|
||||||
]
|
|
||||||
}
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"version" : {
|
|
||||||
"version_data" : [
|
|
||||||
{
|
|
||||||
"version_value" : "OP820"
|
|
||||||
}
|
|
||||||
]
|
|
||||||
},
|
|
||||||
"product_name" : "8335-GTA"
|
|
||||||
},
|
|
||||||
{
|
|
||||||
"product_name" : "8335-GCA",
|
|
||||||
"version" : {
|
|
||||||
"version_data" : [
|
|
||||||
{
|
|
||||||
"version_value" : "OP820"
|
|
||||||
}
|
|
||||||
]
|
|
||||||
}
|
|
||||||
}
|
|
||||||
]
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
}
|
},
|
||||||
},
|
"references": {
|
||||||
"data_type" : "CVE",
|
"reference_data": [
|
||||||
"description" : {
|
{
|
||||||
"description_data" : [
|
"refsource": "CONFIRM",
|
||||||
{
|
"name": "https://www.ibm.com/support/pages/node/6454303",
|
||||||
"lang" : "eng",
|
"title": "IBM Security Bulletin 6454303 (8335-GCA)",
|
||||||
"value" : "IBM Host firmware for LC-class Systems could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request that would allow them to delete arbitrary files on the system. IBM X-Force ID: 200558."
|
"url": "https://www.ibm.com/support/pages/node/6454303"
|
||||||
}
|
},
|
||||||
]
|
{
|
||||||
},
|
"name": "ibm-bmc-cve202129695-dir-traversal (200558)",
|
||||||
"data_version" : "4.0",
|
"title": "X-Force Vulnerability Report",
|
||||||
"CVE_data_meta" : {
|
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/200558",
|
||||||
"STATE" : "PUBLIC",
|
"refsource": "XF"
|
||||||
"ID" : "CVE-2021-29695",
|
}
|
||||||
"ASSIGNER" : "psirt@us.ibm.com",
|
]
|
||||||
"DATE_PUBLIC" : "2021-05-24T00:00:00"
|
},
|
||||||
},
|
"impact": {
|
||||||
"data_format" : "MITRE"
|
"cvssv3": {
|
||||||
}
|
"BM": {
|
||||||
|
"PR": "H",
|
||||||
|
"SCORE": "4.900",
|
||||||
|
"S": "U",
|
||||||
|
"UI": "N",
|
||||||
|
"AC": "L",
|
||||||
|
"C": "N",
|
||||||
|
"I": "H",
|
||||||
|
"AV": "N",
|
||||||
|
"A": "N"
|
||||||
|
},
|
||||||
|
"TM": {
|
||||||
|
"E": "U",
|
||||||
|
"RC": "C",
|
||||||
|
"RL": "O"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"affects": {
|
||||||
|
"vendor": {
|
||||||
|
"vendor_data": [
|
||||||
|
{
|
||||||
|
"vendor_name": "IBM",
|
||||||
|
"product": {
|
||||||
|
"product_data": [
|
||||||
|
{
|
||||||
|
"product_name": "8335-GTB",
|
||||||
|
"version": {
|
||||||
|
"version_data": [
|
||||||
|
{
|
||||||
|
"version_value": "OP820"
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"version": {
|
||||||
|
"version_data": [
|
||||||
|
{
|
||||||
|
"version_value": "OP820"
|
||||||
|
}
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"product_name": "8335-GTA"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"product_name": "8335-GCA",
|
||||||
|
"version": {
|
||||||
|
"version_data": [
|
||||||
|
{
|
||||||
|
"version_value": "OP820"
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"data_type": "CVE",
|
||||||
|
"description": {
|
||||||
|
"description_data": [
|
||||||
|
{
|
||||||
|
"lang": "eng",
|
||||||
|
"value": "IBM Host firmware for LC-class Systems could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request that would allow them to delete arbitrary files on the system. IBM X-Force ID: 200558."
|
||||||
|
}
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"data_version": "4.0",
|
||||||
|
"CVE_data_meta": {
|
||||||
|
"STATE": "PUBLIC",
|
||||||
|
"ID": "CVE-2021-29695",
|
||||||
|
"ASSIGNER": "psirt@us.ibm.com",
|
||||||
|
"DATE_PUBLIC": "2021-05-24T00:00:00"
|
||||||
|
},
|
||||||
|
"data_format": "MITRE"
|
||||||
|
}
|
@ -1,90 +1,90 @@
|
|||||||
{
|
{
|
||||||
"description" : {
|
"description": {
|
||||||
"description_data" : [
|
"description_data": [
|
||||||
{
|
|
||||||
"value" : "IBM Spectrum Scale 5.1.0.1 could allow a local with access to the GUI pod container to obtain sensitive cryptographic keys that could allow them to elevate their privileges. IBM X-Force ID: 200883.",
|
|
||||||
"lang" : "eng"
|
|
||||||
}
|
|
||||||
]
|
|
||||||
},
|
|
||||||
"data_type" : "CVE",
|
|
||||||
"affects" : {
|
|
||||||
"vendor" : {
|
|
||||||
"vendor_data" : [
|
|
||||||
{
|
{
|
||||||
"product" : {
|
"value": "IBM Spectrum Scale 5.1.0.1 could allow a local with access to the GUI pod container to obtain sensitive cryptographic keys that could allow them to elevate their privileges. IBM X-Force ID: 200883.",
|
||||||
"product_data" : [
|
"lang": "eng"
|
||||||
{
|
|
||||||
"version" : {
|
|
||||||
"version_data" : [
|
|
||||||
{
|
|
||||||
"version_value" : "5.1.0.1"
|
|
||||||
}
|
|
||||||
]
|
|
||||||
},
|
|
||||||
"product_name" : "Spectrum Scale"
|
|
||||||
}
|
|
||||||
]
|
|
||||||
},
|
|
||||||
"vendor_name" : "IBM"
|
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
}
|
},
|
||||||
},
|
"data_type": "CVE",
|
||||||
"data_format" : "MITRE",
|
"affects": {
|
||||||
"CVE_data_meta" : {
|
"vendor": {
|
||||||
"STATE" : "PUBLIC",
|
"vendor_data": [
|
||||||
"ID" : "CVE-2021-29708",
|
{
|
||||||
"DATE_PUBLIC" : "2021-05-24T00:00:00",
|
"product": {
|
||||||
"ASSIGNER" : "psirt@us.ibm.com"
|
"product_data": [
|
||||||
},
|
{
|
||||||
"data_version" : "4.0",
|
"version": {
|
||||||
"problemtype" : {
|
"version_data": [
|
||||||
"problemtype_data" : [
|
{
|
||||||
{
|
"version_value": "5.1.0.1"
|
||||||
"description" : [
|
}
|
||||||
{
|
]
|
||||||
"lang" : "eng",
|
},
|
||||||
"value" : "Obtain Information"
|
"product_name": "Spectrum Scale"
|
||||||
}
|
}
|
||||||
|
]
|
||||||
|
},
|
||||||
|
"vendor_name": "IBM"
|
||||||
|
}
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
]
|
},
|
||||||
},
|
"data_format": "MITRE",
|
||||||
"impact" : {
|
"CVE_data_meta": {
|
||||||
"cvssv3" : {
|
"STATE": "PUBLIC",
|
||||||
"BM" : {
|
"ID": "CVE-2021-29708",
|
||||||
"AC" : "L",
|
"DATE_PUBLIC": "2021-05-24T00:00:00",
|
||||||
"UI" : "N",
|
"ASSIGNER": "psirt@us.ibm.com"
|
||||||
"S" : "U",
|
},
|
||||||
"AV" : "L",
|
"data_version": "4.0",
|
||||||
"A" : "H",
|
"problemtype": {
|
||||||
"C" : "H",
|
"problemtype_data": [
|
||||||
"I" : "H",
|
{
|
||||||
"PR" : "H",
|
"description": [
|
||||||
"SCORE" : "6.700"
|
{
|
||||||
},
|
"lang": "eng",
|
||||||
"TM" : {
|
"value": "Obtain Information"
|
||||||
"RL" : "O",
|
}
|
||||||
"RC" : "C",
|
]
|
||||||
"E" : "U"
|
}
|
||||||
}
|
]
|
||||||
}
|
},
|
||||||
},
|
"impact": {
|
||||||
"references" : {
|
"cvssv3": {
|
||||||
"reference_data" : [
|
"BM": {
|
||||||
{
|
"AC": "L",
|
||||||
"name" : "https://www.ibm.com/support/pages/node/6455629",
|
"UI": "N",
|
||||||
"title" : "IBM Security Bulletin 6455629 (Spectrum Scale)",
|
"S": "U",
|
||||||
"url" : "https://www.ibm.com/support/pages/node/6455629",
|
"AV": "L",
|
||||||
"refsource" : "CONFIRM"
|
"A": "H",
|
||||||
},
|
"C": "H",
|
||||||
{
|
"I": "H",
|
||||||
"title" : "X-Force Vulnerability Report",
|
"PR": "H",
|
||||||
"name" : "ibm-spectrum-cve202129708-info-disc (200883)",
|
"SCORE": "6.700"
|
||||||
"url" : "https://exchange.xforce.ibmcloud.com/vulnerabilities/200883",
|
},
|
||||||
"refsource" : "XF"
|
"TM": {
|
||||||
}
|
"RL": "O",
|
||||||
]
|
"RC": "C",
|
||||||
}
|
"E": "U"
|
||||||
}
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
"references": {
|
||||||
|
"reference_data": [
|
||||||
|
{
|
||||||
|
"name": "https://www.ibm.com/support/pages/node/6455629",
|
||||||
|
"title": "IBM Security Bulletin 6455629 (Spectrum Scale)",
|
||||||
|
"url": "https://www.ibm.com/support/pages/node/6455629",
|
||||||
|
"refsource": "CONFIRM"
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"title": "X-Force Vulnerability Report",
|
||||||
|
"name": "ibm-spectrum-cve202129708-info-disc (200883)",
|
||||||
|
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/200883",
|
||||||
|
"refsource": "XF"
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
|
}
|
@ -74,7 +74,9 @@
|
|||||||
"references": {
|
"references": {
|
||||||
"reference_data": [
|
"reference_data": [
|
||||||
{
|
{
|
||||||
"url": "http://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-27r3-rxch-2hm7"
|
"url": "http://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-27r3-rxch-2hm7",
|
||||||
|
"refsource": "MISC",
|
||||||
|
"name": "http://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-27r3-rxch-2hm7"
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
|
Loading…
x
Reference in New Issue
Block a user