File tree Expand file tree Collapse file tree 8 files changed +287
-0
lines changed
Expand file tree Collapse file tree 8 files changed +287
-0
lines changed Original file line number Diff line number Diff line change 1+ {
2+ "schema_version" : " 1.3.1" ,
3+ "id" : " GO-2024-3122" ,
4+ "modified" : " 0001-01-01T00:00:00Z" ,
5+ "published" : " 0001-01-01T00:00:00Z" ,
6+ "aliases" : [
7+ " CVE-2024-45039" ,
8+ " GHSA-q3hw-3gm4-w5cr"
9+ ],
10+ "summary" : " gnark's Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark" ,
11+ "details" : " gnark's Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark" ,
12+ "affected" : [
13+ {
14+ "package" : {
15+ "name" : " github.com/consensys/gnark" ,
16+ "ecosystem" : " Go"
17+ },
18+ "ranges" : [
19+ {
20+ "type" : " SEMVER" ,
21+ "events" : [
22+ {
23+ "introduced" : " 0"
24+ },
25+ {
26+ "fixed" : " 0.11.0"
27+ }
28+ ]
29+ }
30+ ],
31+ "ecosystem_specific" : {}
32+ }
33+ ],
34+ "references" : [
35+ {
36+ "type" : " ADVISORY" ,
37+ "url" : " https://github.com/Consensys/gnark/security/advisories/GHSA-q3hw-3gm4-w5cr"
38+ },
39+ {
40+ "type" : " ADVISORY" ,
41+ "url" : " https://nvd.nist.gov/vuln/detail/CVE-2024-45039"
42+ }
43+ ],
44+ "database_specific" : {
45+ "url" : " https://pkg.go.dev/vuln/GO-2024-3122" ,
46+ "review_status" : " UNREVIEWED"
47+ }
48+ }
Original file line number Diff line number Diff line change 1+ {
2+ "schema_version" : " 1.3.1" ,
3+ "id" : " GO-2024-3140" ,
4+ "modified" : " 0001-01-01T00:00:00Z" ,
5+ "published" : " 0001-01-01T00:00:00Z" ,
6+ "aliases" : [
7+ " CVE-2024-8986" ,
8+ " GHSA-xxxw-3j6h-q7h6"
9+ ],
10+ "summary" : " Grafana plugin SDK Information Leakage in github.com/grafana/grafana-plugin-sdk-go" ,
11+ "details" : " Grafana plugin SDK Information Leakage in github.com/grafana/grafana-plugin-sdk-go" ,
12+ "affected" : [
13+ {
14+ "package" : {
15+ "name" : " github.com/grafana/grafana-plugin-sdk-go" ,
16+ "ecosystem" : " Go"
17+ },
18+ "ranges" : [
19+ {
20+ "type" : " SEMVER" ,
21+ "events" : [
22+ {
23+ "introduced" : " 0"
24+ },
25+ {
26+ "fixed" : " 0.250.0"
27+ }
28+ ]
29+ }
30+ ],
31+ "ecosystem_specific" : {}
32+ }
33+ ],
34+ "references" : [
35+ {
36+ "type" : " ADVISORY" ,
37+ "url" : " https://github.com/advisories/GHSA-xxxw-3j6h-q7h6"
38+ },
39+ {
40+ "type" : " ADVISORY" ,
41+ "url" : " https://nvd.nist.gov/vuln/detail/CVE-2024-8986"
42+ },
43+ {
44+ "type" : " FIX" ,
45+ "url" : " https://github.com/grafana/grafana-plugin-sdk-go/commit/aaa26d1bebaaf6160c37d3f1226a750eab70ca41"
46+ },
47+ {
48+ "type" : " WEB" ,
49+ "url" : " https://grafana.com/security/security-advisories/cve-2024-8986"
50+ }
51+ ],
52+ "database_specific" : {
53+ "url" : " https://pkg.go.dev/vuln/GO-2024-3140" ,
54+ "review_status" : " UNREVIEWED"
55+ }
56+ }
Original file line number Diff line number Diff line change 1+ {
2+ "schema_version" : " 1.3.1" ,
3+ "id" : " GO-2024-3259" ,
4+ "modified" : " 0001-01-01T00:00:00Z" ,
5+ "published" : " 0001-01-01T00:00:00Z" ,
6+ "aliases" : [
7+ " GHSA-p7mv-53f2-4cwj"
8+ ],
9+ "summary" : " CometBFT Vote Extensions: Panic when receiving a Pre-commit with an invalid data in github.com/cometbft/cometbft" ,
10+ "details" : " CometBFT Vote Extensions: Panic when receiving a Pre-commit with an invalid data in github.com/cometbft/cometbft" ,
11+ "affected" : [
12+ {
13+ "package" : {
14+ "name" : " github.com/cometbft/cometbft" ,
15+ "ecosystem" : " Go"
16+ },
17+ "ranges" : [
18+ {
19+ "type" : " SEMVER" ,
20+ "events" : [
21+ {
22+ "introduced" : " 0.38.0"
23+ },
24+ {
25+ "fixed" : " 0.38.15"
26+ }
27+ ]
28+ }
29+ ],
30+ "ecosystem_specific" : {}
31+ }
32+ ],
33+ "references" : [
34+ {
35+ "type" : " ADVISORY" ,
36+ "url" : " https://github.com/cometbft/cometbft/security/advisories/GHSA-p7mv-53f2-4cwj"
37+ },
38+ {
39+ "type" : " WEB" ,
40+ "url" : " https://docs.cometbft.com/v0.38/spec/abci/abci++_basic_concepts"
41+ },
42+ {
43+ "type" : " WEB" ,
44+ "url" : " https://github.com/cometbft/cometbft/releases/tag/v0.38.15"
45+ }
46+ ],
47+ "database_specific" : {
48+ "url" : " https://pkg.go.dev/vuln/GO-2024-3259" ,
49+ "review_status" : " UNREVIEWED"
50+ }
51+ }
Original file line number Diff line number Diff line change 1+ {
2+ "schema_version" : " 1.3.1" ,
3+ "id" : " GO-2024-3265" ,
4+ "modified" : " 0001-01-01T00:00:00Z" ,
5+ "published" : " 0001-01-01T00:00:00Z" ,
6+ "aliases" : [
7+ " CVE-2024-52009" ,
8+ " GHSA-gppm-hq3p-h4rp"
9+ ],
10+ "summary" : " Git credentials are exposed in Atlantis logs in github.com/runatlantis/atlantis" ,
11+ "details" : " Git credentials are exposed in Atlantis logs in github.com/runatlantis/atlantis" ,
12+ "affected" : [
13+ {
14+ "package" : {
15+ "name" : " github.com/runatlantis/atlantis" ,
16+ "ecosystem" : " Go"
17+ },
18+ "ranges" : [
19+ {
20+ "type" : " SEMVER" ,
21+ "events" : [
22+ {
23+ "introduced" : " 0"
24+ },
25+ {
26+ "fixed" : " 0.30.0"
27+ }
28+ ]
29+ }
30+ ],
31+ "ecosystem_specific" : {}
32+ }
33+ ],
34+ "references" : [
35+ {
36+ "type" : " ADVISORY" ,
37+ "url" : " https://github.com/runatlantis/atlantis/security/advisories/GHSA-gppm-hq3p-h4rp"
38+ },
39+ {
40+ "type" : " FIX" ,
41+ "url" : " https://github.com/runatlantis/atlantis/pull/4667"
42+ },
43+ {
44+ "type" : " REPORT" ,
45+ "url" : " https://github.com/runatlantis/atlantis/issues/4060"
46+ },
47+ {
48+ "type" : " WEB" ,
49+ "url" : " https://github.com/runatlantis/atlantis/releases/tag/v0.30.0"
50+ }
51+ ],
52+ "database_specific" : {
53+ "url" : " https://pkg.go.dev/vuln/GO-2024-3265" ,
54+ "review_status" : " UNREVIEWED"
55+ }
56+ }
Original file line number Diff line number Diff line change 1+ id : GO-2024-3122
2+ modules :
3+ - module : github.com/consensys/gnark
4+ versions :
5+ - fixed : 0.11.0
6+ vulnerable_at : 0.10.0
7+ summary : gnark's Groth16 commitment extension unsound for more than one commitment in github.com/consensys/gnark
8+ cves :
9+ - CVE-2024-45039
10+ ghsas :
11+ - GHSA-q3hw-3gm4-w5cr
12+ references :
13+ - advisory : https://github.com/Consensys/gnark/security/advisories/GHSA-q3hw-3gm4-w5cr
14+ - advisory : https://nvd.nist.gov/vuln/detail/CVE-2024-45039
15+ source :
16+ id : GHSA-q3hw-3gm4-w5cr
17+ created : 2024-11-12T11:30:11.924411-05:00
18+ review_status : NEEDS_REVIEW
Original file line number Diff line number Diff line change 1+ id : GO-2024-3140
2+ modules :
3+ - module : github.com/grafana/grafana-plugin-sdk-go
4+ versions :
5+ - fixed : 0.250.0
6+ vulnerable_at : 0.249.0
7+ summary : Grafana plugin SDK Information Leakage in github.com/grafana/grafana-plugin-sdk-go
8+ cves :
9+ - CVE-2024-8986
10+ ghsas :
11+ - GHSA-xxxw-3j6h-q7h6
12+ references :
13+ - advisory : https://github.com/advisories/GHSA-xxxw-3j6h-q7h6
14+ - advisory : https://nvd.nist.gov/vuln/detail/CVE-2024-8986
15+ - fix : https://github.com/grafana/grafana-plugin-sdk-go/commit/aaa26d1bebaaf6160c37d3f1226a750eab70ca41
16+ - web : https://grafana.com/security/security-advisories/cve-2024-8986
17+ source :
18+ id : GHSA-xxxw-3j6h-q7h6
19+ created : 2024-11-12T11:30:05.469931-05:00
20+ review_status : NEEDS_REVIEW
Original file line number Diff line number Diff line change 1+ id : GO-2024-3259
2+ modules :
3+ - module : github.com/cometbft/cometbft
4+ versions :
5+ - introduced : 0.38.0
6+ - fixed : 0.38.15
7+ vulnerable_at : 0.38.14
8+ summary : ' CometBFT Vote Extensions: Panic when receiving a Pre-commit with an invalid data in github.com/cometbft/cometbft'
9+ ghsas :
10+ - GHSA-p7mv-53f2-4cwj
11+ references :
12+ - advisory : https://github.com/cometbft/cometbft/security/advisories/GHSA-p7mv-53f2-4cwj
13+ - web : https://docs.cometbft.com/v0.38/spec/abci/abci++_basic_concepts
14+ - web : https://github.com/cometbft/cometbft/releases/tag/v0.38.15
15+ source :
16+ id : GHSA-p7mv-53f2-4cwj
17+ created : 2024-11-12T11:29:13.234193-05:00
18+ review_status : NEEDS_REVIEW
Original file line number Diff line number Diff line change 1+ id : GO-2024-3265
2+ modules :
3+ - module : github.com/runatlantis/atlantis
4+ versions :
5+ - fixed : 0.30.0
6+ vulnerable_at : 0.29.0
7+ summary : Git credentials are exposed in Atlantis logs in github.com/runatlantis/atlantis
8+ cves :
9+ - CVE-2024-52009
10+ ghsas :
11+ - GHSA-gppm-hq3p-h4rp
12+ references :
13+ - advisory : https://github.com/runatlantis/atlantis/security/advisories/GHSA-gppm-hq3p-h4rp
14+ - fix : https://github.com/runatlantis/atlantis/pull/4667
15+ - report : https://github.com/runatlantis/atlantis/issues/4060
16+ - web : https://github.com/runatlantis/atlantis/releases/tag/v0.30.0
17+ source :
18+ id : GHSA-gppm-hq3p-h4rp
19+ created : 2024-11-12T11:29:08.000581-05:00
20+ review_status : NEEDS_REVIEW
You can’t perform that action at this time.
0 commit comments