csaf2cusa/csaf/advisories/2024/csaf-openEuler-SA-2024-1822.json
Jia Chao 6669e5b3b8 修改,适用 csaf
Signed-off-by: Jia Chao <jiac13@chinaunicom.cn>
2024-07-24 15:38:55 +08:00

314 lines
11 KiB
JSON

{
"document":{
"aggregate_severity":{
"namespace":"https://nvd.nist.gov/vuln-metrics/cvss",
"text":"High"
},
"category":"csaf_vex",
"csaf_version":"2.0",
"distribution":{
"tlp":{
"label":"WHITE",
"url":"https:/www.first.org/tlp/"
}
},
"lang":"en",
"notes":[
{
"text":"rubygem-rack security update",
"category":"general",
"title":"Synopsis"
},
{
"text":"An update for rubygem-rack is now available for openEuler-22.03-LTS-SP1",
"category":"general",
"title":"Summary"
},
{
"text":"Rack provides a minimal, modular, and adaptable interface for developing web applications in Ruby. By wrapping HTTP requests and responses in the simplest way possible, it unifies and distills the API for web servers, web frameworks, and software in between (the so-called middleware) into a single method call.\n\nSecurity Fix(es):\n\nA denial of service vulnerability in the multipart parsing component of Rack fixed in 2.0.9.2, 2.1.4.2, 2.2.4.1 and 3.0.0.1 could allow an attacker tocraft input that can cause RFC2183 multipart boundary parsing in Rack to take an unexpected amount of time, possibly resulting in a denial of service attack vector. Any applications that parse multipart posts using Rack (virtually all Rails applications) are impacted.(CVE-2022-44572)\n\nRack is a modular Ruby web server interface. Carefully crafted Range headers can cause a server to respond with an unexpectedly large response. Responding with such large responses could lead to a denial of service issue. Vulnerable applications will use the `Rack::File` middleware or the `Rack::Utils.byte_ranges` methods (this includes Rails applications). The vulnerability is fixed in 3.0.9.1 and 2.2.8.1.(CVE-2024-26141)",
"category":"general",
"title":"Description"
},
{
"text":"An update for rubygem-rack is now available for openEuler-22.03-LTS-SP1.\n\nopenEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.",
"category":"general",
"title":"Topic"
},
{
"text":"High",
"category":"general",
"title":"Severity"
},
{
"text":"rubygem-rack",
"category":"general",
"title":"Affected Component"
}
],
"publisher":{
"issuing_authority":"openEuler security committee",
"name":"openEuler",
"namespace":"https://www.openeuler.org",
"contact_details":"openeuler-security@openeuler.org",
"category":"vendor"
},
"references":[
{
"summary":"openEuler-SA-2024-1822",
"category":"self",
"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2024-1822"
},
{
"summary":"CVE-2022-44572",
"category":"self",
"url":"https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2022-44572&packageName=rubygem-rack"
},
{
"summary":"CVE-2024-26141",
"category":"self",
"url":"https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2024-26141&packageName=rubygem-rack"
},
{
"summary":"nvd cve",
"category":"external",
"url":"https://nvd.nist.gov/vuln/detail/CVE-2022-44572"
},
{
"summary":"nvd cve",
"category":"external",
"url":"https://nvd.nist.gov/vuln/detail/CVE-2024-26141"
},
{
"summary":"openEuler-SA-2024-1822 vex file",
"category":"self",
"url":"https://repo.openeuler.org/security/data/csaf/advisories/2024/csaf-openEuler-SA-2024-1822.json"
}
],
"title":"An update for rubygem-rack is now available for openEuler-22.03-LTS-SP1",
"tracking":{
"initial_release_date":"2024-07-12T22:51:59+08:00",
"revision_history":[
{
"date":"2024-07-12T22:51:59+08:00",
"summary":"Initial",
"number":"1.0.0"
}
],
"generator":{
"date":"2024-07-12T22:51:59+08:00",
"engine":{
"name":"openEuler CSAF Tool V1.0"
}
},
"current_release_date":"2024-07-12T22:51:59+08:00",
"id":"openEuler-SA-2024-1822",
"version":"1.0.0",
"status":"final"
}
},
"product_tree":{
"branches":[
{
"name":"openEuler",
"category":"vendor",
"branches":[
{
"name":"openEuler",
"branches":[
{
"product":{
"product_identification_helper":{
"cpe":"cpe:/a:openEuler:openEuler:22.03-LTS-SP1"
},
"product_id":"openEuler-22.03-LTS-SP1",
"name":"openEuler-22.03-LTS-SP1"
},
"name":"openEuler-22.03-LTS-SP1",
"category":"product_version"
}
],
"category":"product_name"
},
{
"name":"noarch",
"branches":[
{
"product":{
"product_identification_helper":{
"cpe":"cpe:/a:openEuler:openEuler:22.03-LTS-SP1"
},
"product_id":"rubygem-rack-2.2.3.1-4.oe2203sp1.noarch.rpm",
"name":"rubygem-rack-2.2.3.1-4.oe2203sp1.noarch.rpm"
},
"name":"rubygem-rack-2.2.3.1-4.oe2203sp1.noarch.rpm",
"category":"product_version"
},
{
"product":{
"product_identification_helper":{
"cpe":"cpe:/a:openEuler:openEuler:22.03-LTS-SP1"
},
"product_id":"rubygem-rack-help-2.2.3.1-4.oe2203sp1.noarch.rpm",
"name":"rubygem-rack-help-2.2.3.1-4.oe2203sp1.noarch.rpm"
},
"name":"rubygem-rack-help-2.2.3.1-4.oe2203sp1.noarch.rpm",
"category":"product_version"
}
],
"category":"product_name"
},
{
"name":"src",
"branches":[
{
"product":{
"product_identification_helper":{
"cpe":"cpe:/a:openEuler:openEuler:22.03-LTS-SP1"
},
"product_id":"rubygem-rack-2.2.3.1-4.oe2203sp1.src.rpm",
"name":"rubygem-rack-2.2.3.1-4.oe2203sp1.src.rpm"
},
"name":"rubygem-rack-2.2.3.1-4.oe2203sp1.src.rpm",
"category":"product_version"
}
],
"category":"product_name"
}
]
}
],
"relationships":[
{
"relates_to_product_reference":"openEuler-22.03-LTS-SP1",
"product_reference":"rubygem-rack-2.2.3.1-4.oe2203sp1.noarch.rpm",
"full_product_name":{
"product_id":"openEuler-22.03-LTS-SP1:rubygem-rack-2.2.3.1-4.oe2203sp1.noarch",
"name":"rubygem-rack-2.2.3.1-4.oe2203sp1.noarch as a component of openEuler-22.03-LTS-SP1"
},
"category":"default_component_of"
},
{
"relates_to_product_reference":"openEuler-22.03-LTS-SP1",
"product_reference":"rubygem-rack-help-2.2.3.1-4.oe2203sp1.noarch.rpm",
"full_product_name":{
"product_id":"openEuler-22.03-LTS-SP1:rubygem-rack-help-2.2.3.1-4.oe2203sp1.noarch",
"name":"rubygem-rack-help-2.2.3.1-4.oe2203sp1.noarch as a component of openEuler-22.03-LTS-SP1"
},
"category":"default_component_of"
},
{
"relates_to_product_reference":"openEuler-22.03-LTS-SP1",
"product_reference":"rubygem-rack-2.2.3.1-4.oe2203sp1.src.rpm",
"full_product_name":{
"product_id":"openEuler-22.03-LTS-SP1:rubygem-rack-2.2.3.1-4.oe2203sp1.src",
"name":"rubygem-rack-2.2.3.1-4.oe2203sp1.src as a component of openEuler-22.03-LTS-SP1"
},
"category":"default_component_of"
}
]
},
"vulnerabilities":[
{
"cve":"CVE-2022-44572",
"notes":[
{
"text":"A denial of service vulnerability in the multipart parsing component of Rack fixed in 2.0.9.2, 2.1.4.2, 2.2.4.1 and 3.0.0.1 could allow an attacker tocraft input that can cause RFC2183 multipart boundary parsing in Rack to take an unexpected amount of time, possibly resulting in a denial of service attack vector. Any applications that parse multipart posts using Rack (virtually all Rails applications) are impacted.",
"category":"description",
"title":"Vulnerability Description"
}
],
"product_status":{
"fixed":[
"openEuler-22.03-LTS-SP1:rubygem-rack-2.2.3.1-4.oe2203sp1.noarch",
"openEuler-22.03-LTS-SP1:rubygem-rack-help-2.2.3.1-4.oe2203sp1.noarch",
"openEuler-22.03-LTS-SP1:rubygem-rack-2.2.3.1-4.oe2203sp1.src"
]
},
"remediations":[
{
"product_ids":[
"openEuler-22.03-LTS-SP1:rubygem-rack-2.2.3.1-4.oe2203sp1.noarch",
"openEuler-22.03-LTS-SP1:rubygem-rack-help-2.2.3.1-4.oe2203sp1.noarch",
"openEuler-22.03-LTS-SP1:rubygem-rack-2.2.3.1-4.oe2203sp1.src"
],
"details":"rubygem-rack security update",
"category":"vendor_fix",
"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2024-1822"
}
],
"scores":[
{
"cvss_v3":{
"baseSeverity":"HIGH",
"baseScore":7.5,
"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version":"3.1"
},
"products":[
"openEuler-22.03-LTS-SP1:rubygem-rack-2.2.3.1-4.oe2203sp1.noarch",
"openEuler-22.03-LTS-SP1:rubygem-rack-help-2.2.3.1-4.oe2203sp1.noarch",
"openEuler-22.03-LTS-SP1:rubygem-rack-2.2.3.1-4.oe2203sp1.src"
]
}
],
"threats":[
{
"details":"High",
"category":"impact"
}
],
"title":"CVE-2022-44572"
},
{
"cve":"CVE-2024-26141",
"notes":[
{
"text":"Rack is a modular Ruby web server interface. Carefully crafted Range headers can cause a server to respond with an unexpectedly large response. Responding with such large responses could lead to a denial of service issue. Vulnerable applications will use the `Rack::File` middleware or the `Rack::Utils.byte_ranges` methods (this includes Rails applications). The vulnerability is fixed in 3.0.9.1 and 2.2.8.1.",
"category":"description",
"title":"Vulnerability Description"
}
],
"product_status":{
"fixed":[
"openEuler-22.03-LTS-SP1:rubygem-rack-2.2.3.1-4.oe2203sp1.noarch",
"openEuler-22.03-LTS-SP1:rubygem-rack-help-2.2.3.1-4.oe2203sp1.noarch",
"openEuler-22.03-LTS-SP1:rubygem-rack-2.2.3.1-4.oe2203sp1.src"
]
},
"remediations":[
{
"product_ids":[
"openEuler-22.03-LTS-SP1:rubygem-rack-2.2.3.1-4.oe2203sp1.noarch",
"openEuler-22.03-LTS-SP1:rubygem-rack-help-2.2.3.1-4.oe2203sp1.noarch",
"openEuler-22.03-LTS-SP1:rubygem-rack-2.2.3.1-4.oe2203sp1.src"
],
"details":"rubygem-rack security update",
"category":"vendor_fix",
"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2024-1822"
}
],
"scores":[
{
"cvss_v3":{
"baseSeverity":"MEDIUM",
"baseScore":5.8,
"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L",
"version":"3.1"
},
"products":[
"openEuler-22.03-LTS-SP1:rubygem-rack-2.2.3.1-4.oe2203sp1.noarch",
"openEuler-22.03-LTS-SP1:rubygem-rack-help-2.2.3.1-4.oe2203sp1.noarch",
"openEuler-22.03-LTS-SP1:rubygem-rack-2.2.3.1-4.oe2203sp1.src"
]
}
],
"threats":[
{
"details":"Medium",
"category":"impact"
}
],
"title":"CVE-2024-26141"
}
]
}