Skip to content

Commit 06cdadd

Browse files
committed
data/reports: add 16 unreviewed reports
- data/reports/GO-2024-2902.yaml - data/reports/GO-2024-2915.yaml - data/reports/GO-2024-2901.yaml - data/reports/GO-2024-2913.yaml - data/reports/GO-2024-2911.yaml - data/reports/GO-2024-2914.yaml - data/reports/GO-2024-2916.yaml - data/reports/GO-2024-2891.yaml - data/reports/GO-2024-2907.yaml - data/reports/GO-2024-2919.yaml - data/reports/GO-2024-2899.yaml - data/reports/GO-2024-2904.yaml - data/reports/GO-2024-2906.yaml - data/reports/GO-2024-2917.yaml - data/reports/GO-2024-2903.yaml - data/reports/GO-2024-2900.yaml Fixes #2902 Fixes #2915 Fixes #2901 Fixes #2913 Fixes #2911 Fixes #2914 Fixes #2916 Fixes #2891 Fixes #2907 Fixes #2919 Fixes #2899 Fixes #2904 Fixes #2906 Fixes #2917 Fixes #2903 Fixes #2900 Change-Id: I9f2058ccf726462824192c0a7da1c227a8224661 Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/592457 Reviewed-by: Damien Neil <dneil@google.com> LUCI-TryBot-Result: Go LUCI <golang-scoped@luci-project-accounts.iam.gserviceaccount.com>
1 parent 12d366a commit 06cdadd

32 files changed

+2050
-0
lines changed

data/osv/GO-2024-2891.json

+236
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,236 @@
1+
{
2+
"schema_version": "1.3.1",
3+
"id": "GO-2024-2891",
4+
"modified": "0001-01-01T00:00:00Z",
5+
"published": "0001-01-01T00:00:00Z",
6+
"aliases": [
7+
"CVE-2024-32873",
8+
"GHSA-pxv8-qhrh-jc7v"
9+
],
10+
"summary": "evmos allows transferring unvested tokens after delegations in github.com/evmos/evmos/v10",
11+
"details": "evmos allows transferring unvested tokens after delegations in github.com/evmos/evmos/v10",
12+
"affected": [
13+
{
14+
"package": {
15+
"name": "github.com/evmos/evmos/v10",
16+
"ecosystem": "Go"
17+
},
18+
"ranges": [
19+
{
20+
"type": "SEMVER",
21+
"events": [
22+
{
23+
"introduced": "0"
24+
}
25+
]
26+
}
27+
],
28+
"ecosystem_specific": {}
29+
},
30+
{
31+
"package": {
32+
"name": "github.com/evmos/evmos/v11",
33+
"ecosystem": "Go"
34+
},
35+
"ranges": [
36+
{
37+
"type": "SEMVER",
38+
"events": [
39+
{
40+
"introduced": "0"
41+
}
42+
]
43+
}
44+
],
45+
"ecosystem_specific": {}
46+
},
47+
{
48+
"package": {
49+
"name": "github.com/evmos/evmos/v12",
50+
"ecosystem": "Go"
51+
},
52+
"ranges": [
53+
{
54+
"type": "SEMVER",
55+
"events": [
56+
{
57+
"introduced": "0"
58+
}
59+
]
60+
}
61+
],
62+
"ecosystem_specific": {}
63+
},
64+
{
65+
"package": {
66+
"name": "github.com/evmos/evmos/v13",
67+
"ecosystem": "Go"
68+
},
69+
"ranges": [
70+
{
71+
"type": "SEMVER",
72+
"events": [
73+
{
74+
"introduced": "0"
75+
}
76+
]
77+
}
78+
],
79+
"ecosystem_specific": {}
80+
},
81+
{
82+
"package": {
83+
"name": "github.com/evmos/evmos/v14",
84+
"ecosystem": "Go"
85+
},
86+
"ranges": [
87+
{
88+
"type": "SEMVER",
89+
"events": [
90+
{
91+
"introduced": "0"
92+
}
93+
]
94+
}
95+
],
96+
"ecosystem_specific": {}
97+
},
98+
{
99+
"package": {
100+
"name": "github.com/evmos/evmos/v15",
101+
"ecosystem": "Go"
102+
},
103+
"ranges": [
104+
{
105+
"type": "SEMVER",
106+
"events": [
107+
{
108+
"introduced": "0"
109+
}
110+
]
111+
}
112+
],
113+
"ecosystem_specific": {}
114+
},
115+
{
116+
"package": {
117+
"name": "github.com/evmos/evmos/v16",
118+
"ecosystem": "Go"
119+
},
120+
"ranges": [
121+
{
122+
"type": "SEMVER",
123+
"events": [
124+
{
125+
"introduced": "0"
126+
}
127+
]
128+
}
129+
],
130+
"ecosystem_specific": {}
131+
},
132+
{
133+
"package": {
134+
"name": "github.com/evmos/evmos/v17",
135+
"ecosystem": "Go"
136+
},
137+
"ranges": [
138+
{
139+
"type": "SEMVER",
140+
"events": [
141+
{
142+
"introduced": "0"
143+
}
144+
]
145+
}
146+
],
147+
"ecosystem_specific": {}
148+
},
149+
{
150+
"package": {
151+
"name": "github.com/evmos/evmos/v6",
152+
"ecosystem": "Go"
153+
},
154+
"ranges": [
155+
{
156+
"type": "SEMVER",
157+
"events": [
158+
{
159+
"introduced": "0"
160+
}
161+
]
162+
}
163+
],
164+
"ecosystem_specific": {}
165+
},
166+
{
167+
"package": {
168+
"name": "github.com/evmos/evmos/v7",
169+
"ecosystem": "Go"
170+
},
171+
"ranges": [
172+
{
173+
"type": "SEMVER",
174+
"events": [
175+
{
176+
"introduced": "0"
177+
}
178+
]
179+
}
180+
],
181+
"ecosystem_specific": {}
182+
},
183+
{
184+
"package": {
185+
"name": "github.com/evmos/evmos/v8",
186+
"ecosystem": "Go"
187+
},
188+
"ranges": [
189+
{
190+
"type": "SEMVER",
191+
"events": [
192+
{
193+
"introduced": "0"
194+
}
195+
]
196+
}
197+
],
198+
"ecosystem_specific": {}
199+
},
200+
{
201+
"package": {
202+
"name": "github.com/evmos/evmos/v9",
203+
"ecosystem": "Go"
204+
},
205+
"ranges": [
206+
{
207+
"type": "SEMVER",
208+
"events": [
209+
{
210+
"introduced": "0"
211+
}
212+
]
213+
}
214+
],
215+
"ecosystem_specific": {}
216+
}
217+
],
218+
"references": [
219+
{
220+
"type": "ADVISORY",
221+
"url": "https://github.com/evmos/evmos/security/advisories/GHSA-pxv8-qhrh-jc7v"
222+
},
223+
{
224+
"type": "ADVISORY",
225+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32873"
226+
},
227+
{
228+
"type": "WEB",
229+
"url": "https://github.com/evmos/evmos/commit/b2a09ca66613d8b04decd3f2dcba8e1e77709dcb"
230+
}
231+
],
232+
"database_specific": {
233+
"url": "https://pkg.go.dev/vuln/GO-2024-2891",
234+
"review_status": "UNREVIEWED"
235+
}
236+
}

data/osv/GO-2024-2899.json

+52
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,52 @@
1+
{
2+
"schema_version": "1.3.1",
3+
"id": "GO-2024-2899",
4+
"modified": "0001-01-01T00:00:00Z",
5+
"published": "0001-01-01T00:00:00Z",
6+
"aliases": [
7+
"CVE-2024-36127",
8+
"GHSA-v6mg-7f7p-qmqp"
9+
],
10+
"summary": "apko Exposure of HTTP basic auth credentials in log output in chainguard.dev/apko",
11+
"details": "apko Exposure of HTTP basic auth credentials in log output in chainguard.dev/apko",
12+
"affected": [
13+
{
14+
"package": {
15+
"name": "chainguard.dev/apko",
16+
"ecosystem": "Go"
17+
},
18+
"ranges": [
19+
{
20+
"type": "SEMVER",
21+
"events": [
22+
{
23+
"introduced": "0"
24+
},
25+
{
26+
"fixed": "0.14.5"
27+
}
28+
]
29+
}
30+
],
31+
"ecosystem_specific": {}
32+
}
33+
],
34+
"references": [
35+
{
36+
"type": "ADVISORY",
37+
"url": "https://github.com/chainguard-dev/apko/security/advisories/GHSA-v6mg-7f7p-qmqp"
38+
},
39+
{
40+
"type": "ADVISORY",
41+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36127"
42+
},
43+
{
44+
"type": "WEB",
45+
"url": "https://github.com/chainguard-dev/apko/commit/2c0533e4d52e83031a04f6a83ec63fc2a11eff01"
46+
}
47+
],
48+
"database_specific": {
49+
"url": "https://pkg.go.dev/vuln/GO-2024-2899",
50+
"review_status": "UNREVIEWED"
51+
}
52+
}

data/osv/GO-2024-2900.json

+80
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,80 @@
1+
{
2+
"schema_version": "1.3.1",
3+
"id": "GO-2024-2900",
4+
"modified": "0001-01-01T00:00:00Z",
5+
"published": "0001-01-01T00:00:00Z",
6+
"aliases": [
7+
"CVE-2024-36129",
8+
"GHSA-c74f-6mfw-mm4v"
9+
],
10+
"summary": "Denial of Service via Zip/Decompression Bomb sent over HTTP or gRPC in go.opentelemetry.io/collector/config/configgrpc",
11+
"details": "Denial of Service via Zip/Decompression Bomb sent over HTTP or gRPC in go.opentelemetry.io/collector/config/configgrpc",
12+
"affected": [
13+
{
14+
"package": {
15+
"name": "go.opentelemetry.io/collector/config/configgrpc",
16+
"ecosystem": "Go"
17+
},
18+
"ranges": [
19+
{
20+
"type": "SEMVER",
21+
"events": [
22+
{
23+
"introduced": "0"
24+
},
25+
{
26+
"fixed": "0.102.1"
27+
}
28+
]
29+
}
30+
],
31+
"ecosystem_specific": {}
32+
},
33+
{
34+
"package": {
35+
"name": "go.opentelemetry.io/collector/config/confighttp",
36+
"ecosystem": "Go"
37+
},
38+
"ranges": [
39+
{
40+
"type": "SEMVER",
41+
"events": [
42+
{
43+
"introduced": "0"
44+
},
45+
{
46+
"fixed": "0.102.0"
47+
}
48+
]
49+
}
50+
],
51+
"ecosystem_specific": {}
52+
}
53+
],
54+
"references": [
55+
{
56+
"type": "ADVISORY",
57+
"url": "https://github.com/open-telemetry/opentelemetry-collector/security/advisories/GHSA-c74f-6mfw-mm4v"
58+
},
59+
{
60+
"type": "ADVISORY",
61+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36129"
62+
},
63+
{
64+
"type": "WEB",
65+
"url": "https://github.com/open-telemetry/opentelemetry-collector/pull/10289"
66+
},
67+
{
68+
"type": "WEB",
69+
"url": "https://github.com/open-telemetry/opentelemetry-collector/pull/10323"
70+
},
71+
{
72+
"type": "WEB",
73+
"url": "https://opentelemetry.io/blog/2024/cve-2024-36129"
74+
}
75+
],
76+
"database_specific": {
77+
"url": "https://pkg.go.dev/vuln/GO-2024-2900",
78+
"review_status": "UNREVIEWED"
79+
}
80+
}

0 commit comments

Comments
 (0)