Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update 20250215070407 #780

Closed
wants to merge 1 commit into from
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 5 additions & 1 deletion data/cassandra/BIT-cassandra-2025-23015.json
Original file line number Diff line number Diff line change
Expand Up @@ -75,8 +75,12 @@
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2025/02/11/1"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20250214-0006/"
}
],
"published": "2025-02-06T07:09:06.498Z",
"modified": "2025-02-12T07:43:48.785Z"
"modified": "2025-02-15T07:41:15.776Z"
}
6 changes: 5 additions & 1 deletion data/cassandra/BIT-cassandra-2025-24860.json
Original file line number Diff line number Diff line change
Expand Up @@ -59,8 +59,12 @@
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2025/02/03/3"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20250214-0005/"
}
],
"published": "2025-02-06T07:08:57.983Z",
"modified": "2025-02-07T07:41:28.471Z"
"modified": "2025-02-15T07:41:15.776Z"
}
67 changes: 67 additions & 0 deletions data/gitlab/BIT-gitlab-2024-12379.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,67 @@
{
"schema_version": "1.5.0",
"id": "BIT-gitlab-2024-12379",
"details": "A denial of service vulnerability in GitLab CE/EE affecting all versions from 14.1 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 allows an attacker to impact the availability of GitLab via unbounded symbol creation via the scopes parameter in a Personal Access Token.",
"aliases": [
"CVE-2024-12379"
],
"affected": [
{
"package": {
"ecosystem": "Bitnami",
"name": "gitlab",
"purl": "pkg:bitnami/gitlab"
},
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
}
],
"ranges": [
{
"type": "SEMVER",
"events": [
{
"introduced": "14.1.0"
},
{
"fixed": "17.6.5"
},
{
"introduced": "17.7.0"
},
{
"fixed": "17.7.4"
},
{
"introduced": "17.8.0"
},
{
"fixed": "17.8.2"
}
]
}
]
}
],
"database_specific": {
"severity": "Medium",
"cpes": [
"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*",
"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*"
]
},
"references": [
{
"type": "WEB",
"url": "https://gitlab.com/gitlab-org/gitlab/-/issues/508559"
},
{
"type": "WEB",
"url": "https://hackerone.com/reports/2871791"
}
],
"published": "2025-02-15T07:26:42.712Z",
"modified": "2025-02-15T07:41:15.776Z"
}
66 changes: 66 additions & 0 deletions data/gitlab/BIT-gitlab-2024-3303.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,66 @@
{
"schema_version": "1.5.0",
"id": "BIT-gitlab-2024-3303",
"details": "An issue was discovered in GitLab EE affecting all versions starting from 16.0 prior to 17.6.5, starting from 17.7 prior to 17.7.4, and starting from 17.8 prior to 17.8.2, which allows an attacker to exfiltrate contents of a private issue using prompt injection.",
"aliases": [
"CVE-2024-3303"
],
"affected": [
{
"package": {
"ecosystem": "Bitnami",
"name": "gitlab",
"purl": "pkg:bitnami/gitlab"
},
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N"
}
],
"ranges": [
{
"type": "SEMVER",
"events": [
{
"introduced": "16.0.0"
},
{
"fixed": "17.6.5"
},
{
"introduced": "17.7.0"
},
{
"fixed": "17.7.4"
},
{
"introduced": "17.8.0"
},
{
"fixed": "17.8.2"
}
]
}
]
}
],
"database_specific": {
"severity": "Medium",
"cpes": [
"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*"
]
},
"references": [
{
"type": "WEB",
"url": "https://gitlab.com/gitlab-org/gitlab/-/issues/454460"
},
{
"type": "WEB",
"url": "https://hackerone.com/reports/2418620"
}
],
"published": "2025-02-15T07:22:59.303Z",
"modified": "2025-02-15T07:41:15.776Z"
}
55 changes: 55 additions & 0 deletions data/gitlab/BIT-gitlab-2024-7102.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,55 @@
{
"schema_version": "1.5.0",
"id": "BIT-gitlab-2024-7102",
"details": "An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.5.0 which allows an attacker to trigger a pipeline as another user under certain circumstances.",
"aliases": [
"CVE-2024-7102"
],
"affected": [
{
"package": {
"ecosystem": "Bitnami",
"name": "gitlab",
"purl": "pkg:bitnami/gitlab"
},
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"
}
],
"ranges": [
{
"type": "SEMVER",
"events": [
{
"introduced": "16.4.0"
},
{
"fixed": "17.5.0"
}
]
}
]
}
],
"database_specific": {
"severity": "Critical",
"cpes": [
"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*",
"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*"
]
},
"references": [
{
"type": "WEB",
"url": "https://gitlab.com/gitlab-org/gitlab/-/issues/474414"
},
{
"type": "WEB",
"url": "https://hackerone.com/reports/2623063"
}
],
"published": "2025-02-15T07:16:10.108Z",
"modified": "2025-02-15T07:41:15.776Z"
}
55 changes: 55 additions & 0 deletions data/gitlab/BIT-gitlab-2024-8266.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,55 @@
{
"schema_version": "1.5.0",
"id": "BIT-gitlab-2024-8266",
"details": "An issue was discovered in GitLab CE/EE affecting all versions starting from 17.1 prior to 17.6.0, which allows an attacker with maintainer role to trigger a pipeline as project owner under certain circumstances.",
"aliases": [
"CVE-2024-8266"
],
"affected": [
{
"package": {
"ecosystem": "Bitnami",
"name": "gitlab",
"purl": "pkg:bitnami/gitlab"
},
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N"
}
],
"ranges": [
{
"type": "SEMVER",
"events": [
{
"introduced": "17.1.0"
},
{
"fixed": "17.6.0"
}
]
}
]
}
],
"database_specific": {
"severity": "Medium",
"cpes": [
"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*",
"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*"
]
},
"references": [
{
"type": "WEB",
"url": "https://gitlab.com/gitlab-org/gitlab/-/issues/481531"
},
{
"type": "WEB",
"url": "https://hackerone.com/reports/2649798"
}
],
"published": "2025-02-15T07:14:17.896Z",
"modified": "2025-02-15T07:41:15.776Z"
}
66 changes: 66 additions & 0 deletions data/gitlab/BIT-gitlab-2024-9870.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,66 @@
{
"schema_version": "1.5.0",
"id": "BIT-gitlab-2024-9870",
"details": "An external service interaction vulnerability in GitLab EE affecting all versions from 15.11 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 allows an attacker to send requests from the GitLab server to unintended services.",
"aliases": [
"CVE-2024-9870"
],
"affected": [
{
"package": {
"ecosystem": "Bitnami",
"name": "gitlab",
"purl": "pkg:bitnami/gitlab"
},
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
}
],
"ranges": [
{
"type": "SEMVER",
"events": [
{
"introduced": "15.11.0"
},
{
"fixed": "17.6.5"
},
{
"introduced": "17.7.0"
},
{
"fixed": "17.7.4"
},
{
"introduced": "17.8.0"
},
{
"fixed": "17.8.2"
}
]
}
]
}
],
"database_specific": {
"severity": "Medium",
"cpes": [
"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*"
]
},
"references": [
{
"type": "WEB",
"url": "https://gitlab.com/gitlab-org/gitlab/-/issues/498911"
},
{
"type": "WEB",
"url": "https://hackerone.com/reports/2734142"
}
],
"published": "2025-02-15T07:11:29.204Z",
"modified": "2025-02-15T07:41:15.776Z"
}
Loading
Loading