-
Notifications
You must be signed in to change notification settings - Fork 61
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
data/reports: add 19 unreviewed reports
- data/reports/GO-2024-3020.yaml - data/reports/GO-2024-3022.yaml - data/reports/GO-2024-3024.yaml - data/reports/GO-2024-3025.yaml - data/reports/GO-2024-3030.yaml - data/reports/GO-2024-3031.yaml - data/reports/GO-2024-3044.yaml - data/reports/GO-2024-3045.yaml - data/reports/GO-2024-3046.yaml - data/reports/GO-2024-3047.yaml - data/reports/GO-2024-3048.yaml - data/reports/GO-2024-3049.yaml - data/reports/GO-2024-3050.yaml - data/reports/GO-2024-3051.yaml - data/reports/GO-2024-3052.yaml - data/reports/GO-2024-3053.yaml - data/reports/GO-2024-3054.yaml - data/reports/GO-2024-3055.yaml - data/reports/GO-2024-3056.yaml Fixes #3020 Fixes #3022 Fixes #3024 Fixes #3025 Fixes #3030 Fixes #3031 Fixes #3044 Fixes #3045 Fixes #3046 Fixes #3047 Fixes #3048 Fixes #3049 Fixes #3050 Fixes #3051 Fixes #3052 Fixes #3053 Fixes #3054 Fixes #3055 Fixes #3056 Change-Id: I4acf1bbe85a209dd79a8549d6176fb33175d4356 Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/603716 LUCI-TryBot-Result: Go LUCI <golang-scoped@luci-project-accounts.iam.gserviceaccount.com> Auto-Submit: Tatiana Bradley <tatianabradley@google.com> Reviewed-by: Zvonimir Pavlinovic <zpavlinovic@google.com>
- Loading branch information
Showing
38 changed files
with
1,996 additions
and
0 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,121 @@ | ||
{ | ||
"schema_version": "1.3.1", | ||
"id": "GO-2024-3020", | ||
"modified": "0001-01-01T00:00:00Z", | ||
"published": "0001-01-01T00:00:00Z", | ||
"aliases": [ | ||
"CVE-2024-39832", | ||
"GHSA-762m-4cx6-6mf4" | ||
], | ||
"summary": "Mattermost allows a remote actor to permanently delete local data by abusing dangerous error handling in github.com/mattermost/mattermost-server", | ||
"details": "Mattermost allows a remote actor to permanently delete local data by abusing dangerous error handling in github.com/mattermost/mattermost-server", | ||
"affected": [ | ||
{ | ||
"package": { | ||
"name": "github.com/mattermost/mattermost-server", | ||
"ecosystem": "Go" | ||
}, | ||
"ranges": [ | ||
{ | ||
"type": "SEMVER", | ||
"events": [ | ||
{ | ||
"introduced": "9.5.0+incompatible" | ||
}, | ||
{ | ||
"fixed": "9.5.7+incompatible" | ||
}, | ||
{ | ||
"introduced": "9.7.0+incompatible" | ||
}, | ||
{ | ||
"fixed": "9.7.6+incompatible" | ||
}, | ||
{ | ||
"introduced": "9.8.0+incompatible" | ||
}, | ||
{ | ||
"fixed": "9.8.2+incompatible" | ||
}, | ||
{ | ||
"introduced": "9.9.0+incompatible" | ||
}, | ||
{ | ||
"fixed": "9.9.1+incompatible" | ||
} | ||
] | ||
} | ||
], | ||
"ecosystem_specific": {} | ||
}, | ||
{ | ||
"package": { | ||
"name": "github.com/mattermost/mattermost-server/v5", | ||
"ecosystem": "Go" | ||
}, | ||
"ranges": [ | ||
{ | ||
"type": "SEMVER", | ||
"events": [ | ||
{ | ||
"introduced": "0" | ||
} | ||
] | ||
} | ||
], | ||
"ecosystem_specific": {} | ||
}, | ||
{ | ||
"package": { | ||
"name": "github.com/mattermost/mattermost-server/v6", | ||
"ecosystem": "Go" | ||
}, | ||
"ranges": [ | ||
{ | ||
"type": "SEMVER", | ||
"events": [ | ||
{ | ||
"introduced": "0" | ||
} | ||
] | ||
} | ||
], | ||
"ecosystem_specific": {} | ||
}, | ||
{ | ||
"package": { | ||
"name": "github.com/mattermost/mattermost/server/v8", | ||
"ecosystem": "Go" | ||
}, | ||
"ranges": [ | ||
{ | ||
"type": "SEMVER", | ||
"events": [ | ||
{ | ||
"introduced": "0" | ||
} | ||
] | ||
} | ||
], | ||
"ecosystem_specific": {} | ||
} | ||
], | ||
"references": [ | ||
{ | ||
"type": "ADVISORY", | ||
"url": "https://github.com/advisories/GHSA-762m-4cx6-6mf4" | ||
}, | ||
{ | ||
"type": "ADVISORY", | ||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39832" | ||
}, | ||
{ | ||
"type": "WEB", | ||
"url": "https://mattermost.com/security-updates" | ||
} | ||
], | ||
"database_specific": { | ||
"url": "https://pkg.go.dev/vuln/GO-2024-3020", | ||
"review_status": "UNREVIEWED" | ||
} | ||
} |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,109 @@ | ||
{ | ||
"schema_version": "1.3.1", | ||
"id": "GO-2024-3022", | ||
"modified": "0001-01-01T00:00:00Z", | ||
"published": "0001-01-01T00:00:00Z", | ||
"aliases": [ | ||
"CVE-2024-41926", | ||
"GHSA-9fpw-c9x7-cv3j" | ||
], | ||
"summary": "Mattermost allows remote actor to set arbitrary RemoteId values for synced users in github.com/mattermost/mattermost-server", | ||
"details": "Mattermost allows remote actor to set arbitrary RemoteId values for synced users in github.com/mattermost/mattermost-server", | ||
"affected": [ | ||
{ | ||
"package": { | ||
"name": "github.com/mattermost/mattermost-server", | ||
"ecosystem": "Go" | ||
}, | ||
"ranges": [ | ||
{ | ||
"type": "SEMVER", | ||
"events": [ | ||
{ | ||
"introduced": "9.5.0+incompatible" | ||
}, | ||
{ | ||
"fixed": "9.5.7+incompatible" | ||
}, | ||
{ | ||
"introduced": "9.9.0+incompatible" | ||
}, | ||
{ | ||
"fixed": "9.9.1+incompatible" | ||
} | ||
] | ||
} | ||
], | ||
"ecosystem_specific": {} | ||
}, | ||
{ | ||
"package": { | ||
"name": "github.com/mattermost/mattermost-server/v5", | ||
"ecosystem": "Go" | ||
}, | ||
"ranges": [ | ||
{ | ||
"type": "SEMVER", | ||
"events": [ | ||
{ | ||
"introduced": "0" | ||
} | ||
] | ||
} | ||
], | ||
"ecosystem_specific": {} | ||
}, | ||
{ | ||
"package": { | ||
"name": "github.com/mattermost/mattermost-server/v6", | ||
"ecosystem": "Go" | ||
}, | ||
"ranges": [ | ||
{ | ||
"type": "SEMVER", | ||
"events": [ | ||
{ | ||
"introduced": "0" | ||
} | ||
] | ||
} | ||
], | ||
"ecosystem_specific": {} | ||
}, | ||
{ | ||
"package": { | ||
"name": "github.com/mattermost/mattermost/server/v8", | ||
"ecosystem": "Go" | ||
}, | ||
"ranges": [ | ||
{ | ||
"type": "SEMVER", | ||
"events": [ | ||
{ | ||
"introduced": "0" | ||
} | ||
] | ||
} | ||
], | ||
"ecosystem_specific": {} | ||
} | ||
], | ||
"references": [ | ||
{ | ||
"type": "ADVISORY", | ||
"url": "https://github.com/advisories/GHSA-9fpw-c9x7-cv3j" | ||
}, | ||
{ | ||
"type": "ADVISORY", | ||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41926" | ||
}, | ||
{ | ||
"type": "WEB", | ||
"url": "https://mattermost.com/security-updates" | ||
} | ||
], | ||
"database_specific": { | ||
"url": "https://pkg.go.dev/vuln/GO-2024-3022", | ||
"review_status": "UNREVIEWED" | ||
} | ||
} |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,121 @@ | ||
{ | ||
"schema_version": "1.3.1", | ||
"id": "GO-2024-3024", | ||
"modified": "0001-01-01T00:00:00Z", | ||
"published": "0001-01-01T00:00:00Z", | ||
"aliases": [ | ||
"CVE-2024-39839", | ||
"GHSA-vg6q-84p8-qvqh" | ||
], | ||
"summary": "Mattermost allows a user on a remote to set their remote username prop to an arbitrary string in github.com/mattermost/mattermost-server", | ||
"details": "Mattermost allows a user on a remote to set their remote username prop to an arbitrary string in github.com/mattermost/mattermost-server", | ||
"affected": [ | ||
{ | ||
"package": { | ||
"name": "github.com/mattermost/mattermost-server", | ||
"ecosystem": "Go" | ||
}, | ||
"ranges": [ | ||
{ | ||
"type": "SEMVER", | ||
"events": [ | ||
{ | ||
"introduced": "9.5.0+incompatible" | ||
}, | ||
{ | ||
"fixed": "9.5.7+incompatible" | ||
}, | ||
{ | ||
"introduced": "9.7.0+incompatible" | ||
}, | ||
{ | ||
"fixed": "9.7.6+incompatible" | ||
}, | ||
{ | ||
"introduced": "9.8.0+incompatible" | ||
}, | ||
{ | ||
"fixed": "9.8.2+incompatible" | ||
}, | ||
{ | ||
"introduced": "9.9.0+incompatible" | ||
}, | ||
{ | ||
"fixed": "9.9.1+incompatible" | ||
} | ||
] | ||
} | ||
], | ||
"ecosystem_specific": {} | ||
}, | ||
{ | ||
"package": { | ||
"name": "github.com/mattermost/mattermost-server/v5", | ||
"ecosystem": "Go" | ||
}, | ||
"ranges": [ | ||
{ | ||
"type": "SEMVER", | ||
"events": [ | ||
{ | ||
"introduced": "0" | ||
} | ||
] | ||
} | ||
], | ||
"ecosystem_specific": {} | ||
}, | ||
{ | ||
"package": { | ||
"name": "github.com/mattermost/mattermost-server/v6", | ||
"ecosystem": "Go" | ||
}, | ||
"ranges": [ | ||
{ | ||
"type": "SEMVER", | ||
"events": [ | ||
{ | ||
"introduced": "0" | ||
} | ||
] | ||
} | ||
], | ||
"ecosystem_specific": {} | ||
}, | ||
{ | ||
"package": { | ||
"name": "github.com/mattermost/mattermost/server/v8", | ||
"ecosystem": "Go" | ||
}, | ||
"ranges": [ | ||
{ | ||
"type": "SEMVER", | ||
"events": [ | ||
{ | ||
"introduced": "0" | ||
} | ||
] | ||
} | ||
], | ||
"ecosystem_specific": {} | ||
} | ||
], | ||
"references": [ | ||
{ | ||
"type": "ADVISORY", | ||
"url": "https://github.com/advisories/GHSA-vg6q-84p8-qvqh" | ||
}, | ||
{ | ||
"type": "ADVISORY", | ||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39839" | ||
}, | ||
{ | ||
"type": "WEB", | ||
"url": "https://mattermost.com/security-updates" | ||
} | ||
], | ||
"database_specific": { | ||
"url": "https://pkg.go.dev/vuln/GO-2024-3024", | ||
"review_status": "UNREVIEWED" | ||
} | ||
} |
Oops, something went wrong.