diff --git a/gems/css_parser/GHSA-84w7-hpvm-rxx2.yml b/gems/css_parser/GHSA-84w7-hpvm-rxx2.yml new file mode 100644 index 0000000000..dbbf7f8c1a --- /dev/null +++ b/gems/css_parser/GHSA-84w7-hpvm-rxx2.yml @@ -0,0 +1,38 @@ +--- +gem: css_parser +ghsa: 84w7-hpvm-rxx2 +url: https://github.com/premailer/css_parser/security/advisories/GHSA-84w7-hpvm-rxx2 +title: ReDoS - expand_shorthand! regex (RE_FUNCTIONS) backtracks + exponentially on an unclosed CSS function value +date: 2021-09-20 +description: | + ## SUMMARY + + expand_shorthand! (and the expand_dimensions_shorthand! it calls) + runs the RE_FUNCTIONS regex over declaration values. That regex + has a nested quantifier inside a group that can recurse, so on a + value that opens a CSS function and never closes it, the match + degrades into exponential backtracking. A CSS string of a few dozen + bytes pins one CPU core for minutes to hours. + + ## IMPACT + + Any code that parses untrusted CSS and then expands shorthands is + affected. That includes premailer, whose adapters call expand_shorthand! + while inlining styles, so an application that runs premailer over + attacker-supplied email or user CSS can be stalled by a tiny payload. + The property has to be one of the dimension shorthands (margin, + padding, border-*), all of which an attacker can name freely. +unaffected_versions: + - "< 1.10.0" +patched_versions: + - ">= 3.2.0" +related: + url: + - https://rubygems.org/gems/css_parser/versions/3.2.0 + - https://github.com/premailer/css_parser/blob/master/CHANGELOG.md#version-320 + - https://github.com/premailer/css_parser/compare/v3.1.0...v3.2.0 + - https://github.com/premailer/css_parser/security/advisories/GHSA-84w7-hpvm-rxx2 +notes: | + - No CVE in GHSA URL, but has "Moderate" (no value) severity. + - date from rubygems.org URL. diff --git a/gems/css_parser/GHSA-w3mx-4vv9-hjpg.yml b/gems/css_parser/GHSA-w3mx-4vv9-hjpg.yml new file mode 100644 index 0000000000..a58ded39e6 --- /dev/null +++ b/gems/css_parser/GHSA-w3mx-4vv9-hjpg.yml @@ -0,0 +1,66 @@ +--- +gem: css_parser +ghsa: w3mx-4vv9-hjpg +url: https://github.com/premailer/css_parser/security/advisories/GHSA-w3mx-4vv9-hjpg +title: Arbitrary local-file read via attacker-controlled `@import` + into `load_file!` (the `base_dir` branch of `add_block!`) - + incomplete fix of GHSA-9pmc-p236-855h +date: 2026-10-07 +description: | + ## Summary + + When css_parser parses CSS that contains an @import rule and the caller + has supplied a :base_dir option (but not a :base_uri), the + attacker-controlled import path is passed directly into load_file!, + which does File.expand_path(file_name, base_dir) followed by File.read + with no path containment, no traversal guard, and no allow_file_uris + gate. An attacker who controls CSS content can therefore cause the + library to read an arbitrary local file — either by absolute path + (@import "/etc/…") or by ../ traversal escaping base_dir — and the + file's content is merged into the parser's ruleset. To the extent + the loose CSS grammar turns that content into selectors/declarations, + it is surfaced to the consumer. + + This is the base_dir sibling of the SSRF/file:// issue fixed as + GHSA-9pmc-p236-855h / CVE-2026-53727. That advisory and its fix only + closed the file://-via-base_uri arm of the same @import handler; + the base_dir arm and load_file! itself were left untouched, and the + fix's own docstring incorrectly assumes load_file! only ever receives + caller-supplied paths. + + The primary downstream consumer, Premailer, reaches this arm + automatically for local-file / HTML-file input (it sets @base_dir + from the file's directory while leaving @base_url nil), so an + attacker-supplied local email/HTML file causes Premailer to read + a file outside the email directory and inline its content into + the returned HTML. + + ## IMPACT + + An attacker who controls CSS content (a submitted stylesheet, an + email/HTML template processed server-side by Premailer from a + local file, etc.) can: + + * Read arbitrary local files by absolute path or ../ traversal, + bounded by process file permissions. + + * Use the always-executed File.read (visible via loaded_uris / + circular_reference_check) as a file-existence / read oracle + even when content is not fully surfaced. + + * Exfiltrate file content through the CSS-parse channel: files + that the loose CSS grammar turns into selectors/declarations (CSS, + many config/.env-style/JSON-ish files) leak strongly; arbitrary + binary content leaks only partially. +cvss_v3: 5.3 +patched_versions: + - ">= 3.3.0" +related: + url: + - https://rubygems.org/gems/css_parser/versions/3.3.0 + - https://github.com/premailer/css_parser/blob/master/CHANGELOG.md#version-330 + - https://github.com/premailer/css_parser/compare/v3.2.0...v3.3.0 + - https://github.com/premailer/css_parser/security/advisories/GHSA-w3mx-4vv9-hjpg +notes: | + - No CVE value in GHSA URL. + - cvss_v3 from GHSA URL. diff --git a/gems/katello/CVE-2026-79654.yml b/gems/katello/CVE-2026-79654.yml new file mode 100644 index 0000000000..5c444ba45b --- /dev/null +++ b/gems/katello/CVE-2026-79654.yml @@ -0,0 +1,42 @@ +--- +gem: katello +cve: 2026-79654 +ghsa: xqhp-pxqr-f7m6 +url: https://nvd.nist.gov/vuln/detail/CVE-2026-79654 +title: Katello - Unauthorized disclosure of Content View lifecycle information +date: 2026-10-05 +description: | + A flaw was found in Katello where the Content View History API does + not properly enforce authorization when accessing a Content View + specified by the user. An authenticated user with permission to + view Content Views in one organization may be able to access the + lifecycle history of a Content View belonging to another organization + by supplying its identifier to the affected API endpoint. This can + result in unauthorized disclosure of Content View lifecycle + information, including publication and promotion events, associated + users, and timestamps. +cvss_v3: 4.3 +patched_versions: + - "~> 4.21.2" + - ">= 5.0.1" +related: + url: + - https://nvd.nist.gov/vuln/detail/CVE-2026-79654 + - https://rubygems.org/gems/katello/versions/5.0.1 + - https://github.com/Katello/katello/compare/5.0.0...5.0.1 + - https://rubygems.org/gems/katello/versions/4.21.2 + - https://github.com/Katello/katello/compare/4.21.1.1...4.21.2 + - https://github.com/Katello/katello/pull/11847 + - https://github.com/Katello/katello/commit/2a80275ce766a7b370d09123e3e9e063b33d8df3 + - https://access.redhat.com/security/cve/CVE-2026-79654 + - https://bugzilla.redhat.com/show_bug.cgi?id=2523348 + - https://projects.theforeman.org/issues/39701 + - https://access.redhat.com/errata/RHSA-2026:74503 + - https://access.redhat.com/errata/RHSA-2026:74504 + - https://access.redhat.com/errata/RHSA-2026:74506 + - https://access.redhat.com/errata/RHSA-2026:74505 + - https://github.com/advisories/GHSA-xqhp-pxqr-f7m6 +notes: | + - GHSA Unreviewed RedHat advisory + - cvss_v3 from nvd.nist.gov URL + - Both /compare/ URLs mentioned CVE number.