vuln-list-alt/oval/p11/ALT-PU-2021-2719/definitions.json
2024-12-12 21:07:30 +00:00

107 lines
3.8 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20212719",
"Version": "oval:org.altlinux.errata:def:20212719",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2021-2719: package `gem-rack-cors` update to version 1.1.1-alt1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch p11"
],
"Products": [
"ALT Container"
]
}
],
"References": [
{
"RefID": "ALT-PU-2021-2719",
"RefURL": "https://errata.altlinux.org/ALT-PU-2021-2719",
"Source": "ALTPU"
},
{
"RefID": "BDU:2021-04587",
"RefURL": "https://bdu.fstec.ru/vul/2021-04587",
"Source": "BDU"
},
{
"RefID": "CVE-2019-18978",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2019-18978",
"Source": "CVE"
}
],
"Description": "This update upgrades gem-rack-cors to version 1.1.1-alt1. \nSecurity Fix(es):\n\n * BDU:2021-04587: Уязвимость программного обеспечения организации совместимости приложений Rack с CORS Rack-cors, связанная с некорректным ограничением имени пути к каталогу, позволяющая нарушителю получить доступ к конфиденциальным данным\n\n * CVE-2019-18978: An issue was discovered in the rack-cors (aka Rack CORS Middleware) gem before 1.0.4 for Ruby. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonical format.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "Low",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2021-09-04"
},
"Updated": {
"Date": "2021-09-04"
},
"BDUs": [
{
"ID": "BDU:2021-04587",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"CVSS3": "AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"CWE": "CWE-22",
"Href": "https://bdu.fstec.ru/vul/2021-04587",
"Impact": "Low",
"Public": "20191114"
}
],
"CVEs": [
{
"ID": "CVE-2019-18978",
"CVSS": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"CVSS3": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"CWE": "CWE-22",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2019-18978",
"Impact": "Low",
"Public": "20191114"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:container:11"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:3001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20212719001",
"Comment": "gem-rack-cors is earlier than 0:1.1.1-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20212719002",
"Comment": "gem-rack-cors-devel is earlier than 0:1.1.1-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20212719003",
"Comment": "gem-rack-cors-doc is earlier than 0:1.1.1-alt1"
}
]
}
]
}
}
]
}