Commit Graph

2260 Commits

Author SHA1 Message Date
Sergey "Shnatsel" Davidoff
789aec01a3 Lexical is maintained again, unsoundness is fixed 2024-09-15 06:58:17 +01:00
John Vandenberg
7fbf1e630a Add more alternatives to proc-macro-error (#2076) 2024-09-09 06:08:37 -06:00
github-actions[bot]
ebef0eb749 Assigned RUSTSEC-2024-0373 to quinn-proto (#2074)
Co-authored-by: Shnatsel <291257+Shnatsel@users.noreply.github.com>
2024-09-08 02:47:13 +01:00
Dirkjan Ochtman
d1f40fb4f7 Add advisory for quinn-proto denial of service (#2059) 2024-09-08 02:44:40 +01:00
venkkatesh-sekar
7865e3577f fix (#2073) 2024-09-07 12:23:36 -06:00
github-actions[bot]
66cef906f6 Assigned RUSTSEC-2024-0371 to gix-path, RUSTSEC-2024-0372 to ic-cdk (#2072)
Co-authored-by: Shnatsel <291257+Shnatsel@users.noreply.github.com>
2024-09-07 02:48:33 +01:00
venkkatesh-sekar
1a553f13f0 Advisory for GHSA-rwq6-crjg-9cpw in ic-cdk (#2068)
* Add  CVE-2024-7884

* review

* Fix version specification

---------

Co-authored-by: Sergey "Shnatsel" Davidoff <shnatsel@gmail.com>
2024-09-07 02:48:14 +01:00
Eliah Kagan
987de17886 Advisory for CVE-2024-45405 (incomplete unescaping) in gix-path (#2071)
* Advisory for GHSA-m8rp-vv92-46c7 (incomplete unescaping) in gix-path

* Fix up body Markdown for RUSTSEC

- `<` `>` around a bare URL
- manual linking and rendering of referenced commit hash
- manual linking of a bare CVE number to associated global GHSA

* Add CVE number

* Add reference to GitHub Advisory Database entry

Now that it has been published there as well.
2024-09-07 02:44:44 +01:00
github-actions[bot]
9f0ebadc1c Assigned RUSTSEC-2024-0370 to proc-macro-error (#2070)
Co-authored-by: tarcieri <797+tarcieri@users.noreply.github.com>
2024-09-05 11:40:19 -06:00
Gnome!
088b041c02 Add unmaintained advisory for proc-macro-error (#2057) 2024-09-05 11:38:54 -06:00
github-actions[bot]
1f7b1c83df Assigned RUSTSEC-2024-0369 to phonenumber (#2069)
Co-authored-by: tarcieri <797+tarcieri@users.noreply.github.com>
2024-09-05 07:40:37 -06:00
Ruben De Smet
a9c7f518c7 rust-phonenumber: panic-on-parse (#2009) 2024-09-05 07:37:04 -06:00
Eliah Kagan
341f80ff92 Make small readability improvements in RUSTSEC-2023-0064 (#2064)
* Linkify bare URL in RUSTSEC-2023-0064

* Slightly improve wording in acknowledgement
2024-09-03 23:37:57 +01:00
Eliah Kagan
41db9ef9b8 Add global GHSA reference for RUSTSEC-2024-0367 (config scopes) (#2063)
* Add global GHSA reference for RUSTSEC-2024-0367 (config scopes)

This adds a link to the GitHub Advisory Database entry
https://github.com/advisories/GHSA-v26r-4c9c-h3j6 for
RUSTSEC-2024-0367 / CVE-2024-45305 / GHSA-v26r-4c9c-h3j6.

This entry was added to the GitHub Advisory Database since this
RUSTSEC entry was created in #2055 and updated in #2061.

(This also adds a reference to NVD entry, which has a useful
summary and appears as a reference in the global GHSA's reference
section.)

* Linkify bare URLs

The advisory, RUSTSEC-2024-0367, has two bare URLs in it, which
are displayed as links (and, in the repo-level GHSA, also showing
the linked-to lines of code). This surrounds them with `<` and `>`
so that they are rendered as hyperlinks, as they are in the global
GHSA.

(This does not correspond to a revision to the global GHSA because
they are already shown that way there. This change thus brings the
RUSTSEC advisory in line with the others.)
2024-09-03 23:23:51 +01:00
github-actions[bot]
a4b81423f7 Assigned RUSTSEC-2024-0368 to olm-sys (#2062)
Co-authored-by: Shnatsel <291257+Shnatsel@users.noreply.github.com>
2024-09-02 20:42:55 +01:00
Johannes Hayeß
0977c153d3 Add advisory for olm-sys (unmaintained, crypto failure) (#2060)
* Add advisory for olm-sys

* Upgrade to vulnerability

---------

Co-authored-by: Sergey "Shnatsel" Davidoff <shnatsel@gmail.com>
2024-09-02 20:42:34 +01:00
Eliah Kagan
ba8a561d8a Add CVE number for RUSTSEC-2024-0367 (config scopes) (#2061)
This adds CVE-2024-45305 to `aliases` for RUSTSEC-2024-0367.

No CVE had been issued for that vulnerability when it was added to
the RUSTSEC database in #2055, but it has been assigned since.
2024-09-02 20:40:46 +01:00
github-actions[bot]
f88a0b72a8 Assigned RUSTSEC-2024-0367 to gix-path (#2058)
Co-authored-by: Shnatsel <291257+Shnatsel@users.noreply.github.com>
2024-09-01 17:42:16 +01:00
Eliah Kagan
12bc01da3d Advisory for GHSA-v26r-4c9c-h3j6 (config scopes) in gix-path (#2055)
* Advisory for GHSA-v26r-4c9c-h3j6 (config scopes) in gix-path

* Fix a commit hash intended to be a link to commit info

This worked on GitHub but should not be expected to be a hyperlink
elsehwere. So this makes the rendered text and target explicit.

* Add CVSS metadata

It is present in GHSA-v26r-4c9c-h3j6, I just accidentally left it
out initially.

* Clarify some wording in the advisory

I have already made this change at GHSA-v26r-4c9c-h3j6.
2024-09-01 17:33:01 +01:00
github-actions[bot]
fe4d5979b3 Assigned RUSTSEC-2024-0366 to cosmwasm-vm (#2053)
Co-authored-by: Shnatsel <291257+Shnatsel@users.noreply.github.com>
2024-08-27 17:22:21 +01:00
Christoph Otter
956def623f Add cosmwasm-vm advisory CWA-2023-004 (#2052)
* Add CWA-2023-004

* Fix description
2024-08-27 17:21:54 +01:00
Austin Bonander
dd0703e582 update resolution for RUSTSEC-2024-0363 (sqlx) (#2050) 2024-08-24 15:46:16 +01:00
github-actions[bot]
1bc15cb78d Assigned RUSTSEC-2024-0365 to diesel (#2049)
Co-authored-by: Shnatsel <291257+Shnatsel@users.noreply.github.com>
2024-08-23 15:03:08 +01:00
Georg Semmler
db0c302d32 Fill an advisory for protocol level injections for diesel (#2048)
This is essentially the same as https://github.com/rustsec/advisory-db/pull/2039 but for diesel.
2024-08-23 14:59:22 +01:00
github-actions[bot]
d3238373a4 Assigned RUSTSEC-2024-0364 to gitoxide-core (#2047)
Co-authored-by: Shnatsel <291257+Shnatsel@users.noreply.github.com>
2024-08-23 00:15:02 +01:00
Eliah Kagan
749a2a3c65 Advisory for CVE-2024-43785 in gitoxide-core (#2046) 2024-08-23 00:12:22 +01:00
github-actions[bot]
201638b35a Assigned RUSTSEC-2024-0363 to sqlx (#2040)
Co-authored-by: Shnatsel <291257+Shnatsel@users.noreply.github.com>
2024-08-16 21:33:27 +01:00
Austin Bonander
aa6d10b9c3 Advisory for sqlx <= 0.8.0 (#2039)
https://github.com/launchbadge/sqlx/issues/3440
2024-08-16 21:32:57 +01:00
github-actions[bot]
3f19e3dd28 Assigned RUSTSEC-2024-0362 to alloy-json-abi (#2038)
Co-authored-by: tarcieri <797+tarcieri@users.noreply.github.com>
2024-08-15 07:40:17 -06:00
Luca
c33a710551 add alloy-json-abi stack-overflow (#2033) 2024-08-15 07:33:44 -06:00
Christoph Otter
1d209d3f18 Update versions for RUSTSEC-2024-0361 (#2036) 2024-08-08 18:11:37 +01:00
github-actions[bot]
fcaaabc8f1 Assigned RUSTSEC-2024-0361 to cosmwasm-vm (#2035)
Co-authored-by: Shnatsel <291257+Shnatsel@users.noreply.github.com>
2024-08-08 15:04:18 +01:00
Christoph Otter
c97d3fd8c8 Add cosmwasm-vm advisory CWA-2024-004 (#2034)
* Add CWA-2024-004

* Fix GHSA
2024-08-08 15:03:33 +01:00
github-actions[bot]
9d024c07ee Assigned RUSTSEC-2024-0360 to xmp_toolkit (#2030)
Co-authored-by: Shnatsel <291257+Shnatsel@users.noreply.github.com>
2024-07-26 19:09:25 +01:00
Eric Scouten
237684810f Unsoundness notice for xmp_toolkit < 1.9.0 (#2029)
* Unsoundness notice for xmp_toolkit < 1.9.0

* Add proper Markdown explanation of issue

* Move functions key into affected table

* Reword description slightly

* Reword to add mention of UB
2024-07-26 19:08:28 +01:00
github-actions[bot]
af0e1b678a Assigned RUSTSEC-2024-0359 to gix-attributes (#2028)
Co-authored-by: Shnatsel <291257+Shnatsel@users.noreply.github.com>
2024-07-25 00:36:13 +01:00
Eliah Kagan
884aaa1646 Unsoundness notice for gix-attributes (kstring integration) (#2027)
* Unsoundness notice for gix-attributes (kstring integration)

gix-attributes was found by @ssbr to be unsound, as reported in
https://github.com/Byron/gitoxide/issues/1460. This adds an
informational notice for that, as discussed in comments there.

It looks like the affected code, having been introduced in
https://github.com/Byron/gitoxide/pull/400, was present in all
versions of the crate prior to the fix in 0.22.3 (which was one of
the bugs fixed in https://github.com/Byron/gitoxide/pull/1462).

Co-authored-by: Devin Jeanpierre <jeanpierreda@google.com>

* Small adjustments for advisory

This makes some minor changes to the advisory description to adapt
the text from https://github.com/Byron/gitoxide/issues/1460 to be
an advisory. For the most part it has remained the same. Changes:

* Express the claim of unsoundness with more confidence, since it
  has been reviewed by the maintainer.

* Modify the link to the affected code to point to the latest tag
  for gix-attributes that has that code. The original link was to
  a branch, so it was broken when the fix was applied.

* Apply inline code formatting in a few more places, where doing
  so improves stylistic consistency.

---------

Co-authored-by: Devin Jeanpierre <jeanpierreda@google.com>
2024-07-25 00:34:53 +01:00
github-actions[bot]
0e7413f794 Assigned RUSTSEC-2024-0358 to object_store (#2026)
Co-authored-by: Shnatsel <291257+Shnatsel@users.noreply.github.com>
2024-07-23 19:54:53 +01:00
Jamie Strandboge
1ddd5bec7a Add advisory for object_store credentials leak via logs (#2025)
* Add advisory for object_store credentials leak via logs

* remove `informational = notice` which is not a vulnerability

---------

Co-authored-by: Sergey "Shnatsel" Davidoff <shnatsel@gmail.com>
2024-07-23 19:51:03 +01:00
github-actions[bot]
c0b44f487d Assigned RUSTSEC-2024-0357 to openssl (#2022)
Co-authored-by: Shnatsel <291257+Shnatsel@users.noreply.github.com>
2024-07-21 13:28:48 -04:00
Alex Gaynor
627aa62572 Added advisory for undefined behavior in openssl (#2021) 2024-07-21 18:26:54 +01:00
github-actions[bot]
eb081cbca8 Assigned RUSTSEC-2024-0356 to matrix-sdk-crypto (#2019)
Co-authored-by: Shnatsel <291257+Shnatsel@users.noreply.github.com>
2024-07-19 11:11:38 +01:00
Damir Jelić
2edb42e988 Add CVE-2024-40648 for matrix-sdk-crypto (#2018) 2024-07-19 11:10:26 +01:00
github-actions[bot]
72a75c7d51 Assigned RUSTSEC-2024-0355 to gix-path (#2016)
Co-authored-by: Shnatsel <291257+Shnatsel@users.noreply.github.com>
2024-07-18 17:46:06 +01:00
Eliah Kagan
75a41e6504 Advisory for CVE-2024-40644 (program files) in gix-path (#2015)
* Advisory for CVE-2024-40644 (program files) in gix-path

* Make the old hard-coded paths clear in the advisory

Since specific elements of it are referenced in the following text.
This way, even if this is read offline or otherwise without the
ability to load the linked code from GitHub, the advisory is clear.

* Add reference to entry in GitHub Advisory Database

* Fix version spec for affected public functions

Since it is only applicable to versions affected by the
vulnerability, which is already just that one version, I think
`*` is actually sufficient.
2024-07-18 17:45:36 +01:00
github-actions[bot]
f56c72df5f Assigned RUSTSEC-2024-0354 to vodozemac (#2014)
Co-authored-by: Shnatsel <291257+Shnatsel@users.noreply.github.com>
2024-07-18 12:24:58 +01:00
Damir Jelić
2bfbe39703 Add CVE-2024-40640 for vodozemac (#2013) 2024-07-18 12:23:57 +01:00
Carol (Nichols || Goulding)
97a2dc7583 Add some FAQ entries linking to security policies (#2010) 2024-07-09 18:54:53 -06:00
Manish Goregaokar
502a1ba737 Fix patched zerovec-derive version (#2007)
We accidentally proposed the wrong version here.

zerovec 0.10.4 and zerovec-derive 0.10.3 are patched.
2024-07-08 18:05:42 +01:00
github-actions[bot]
6a846dea66 Assigned RUSTSEC-2024-0351 to gix-ref, RUSTSEC-2024-0352 to gix-index, RUSTSEC-2024-0353 to gix-worktree (#2006)
Co-authored-by: tarcieri <797+tarcieri@users.noreply.github.com>
2024-07-08 09:14:36 -06:00