Skip to content

Commit 37f79bb

Browse files
1 parent 2770397 commit 37f79bb

File tree

2 files changed

+83
-2
lines changed

2 files changed

+83
-2
lines changed

advisories/github-reviewed/2022/11/GHSA-25gv-mvm7-5h3h/GHSA-25gv-mvm7-5h3h.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-25gv-mvm7-5h3h",
4-
"modified": "2025-04-29T15:37:21Z",
4+
"modified": "2025-07-18T20:13:40Z",
55
"published": "2022-11-25T18:30:25Z",
66
"aliases": [
77
"CVE-2022-45208"
@@ -18,7 +18,7 @@
1818
{
1919
"package": {
2020
"ecosystem": "Maven",
21-
"name": "org.jeecgframework.boot:jeecg-boot-common"
21+
"name": "org.jeecgframework.boot:jeecg-module-system"
2222
},
2323
"ranges": [
2424
{
Lines changed: 81 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,81 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-5662-cv6m-63wh",
4+
"modified": "2025-07-18T20:13:21Z",
5+
"published": "2025-07-18T20:13:21Z",
6+
"aliases": [
7+
"CVE-2025-54059"
8+
],
9+
"summary": "melange's world-writable permissions expose SBOM files to potential image tampering",
10+
"details": "It was discovered that the SBOM files generated by melange in apks had file system permissions mode 666:\n```\n$ apkrane ls https://packages.wolfi.dev/os/x86_64/APKINDEX.tar.gz -P hello-wolfi --full --latest | xargs wget -q -O - | tar tzv 2>/dev/null var/lib/db/sbom\ndrwxr-xr-x root/root 0 2025-06-23 14:17 var/lib/db/sbom\n-rw-rw-rw- root/root 3383 2025-06-23 14:17 var/lib/db/sbom/hello-wolfi-2.12.2-r1.spdx.json\n```\n\nThis issue was introduced in commit 1b272db (\"Persist workspace filesystem throughout package builds (#1836)\") ([v0.23.0](https://github.com/chainguard-dev/melange/releases/tag/v0.23.0)).\n\n### Impact\nThis potentially allows an unprivileged user to tamper with apk SBOMs on a running image, potentially confusing security scanners. An attacker could also perform a DoS under special circumstances.\n\n### Patches\nThis issue was addressed in melange in e29494b (\"fix: tighten up permissions for written SBOM files and signature tarballs (#2086)\") ([v0.29.5](https://github.com/chainguard-dev/melange/releases/tag/v0.29.5)).\n\n## Acknowledgements\n\nThanks to Cody Harris [H2O.ai](https://h2o.ai/) and Markus Boehme for independently reporting this issue.",
11+
"severity": [
12+
{
13+
"type": "CVSS_V3",
14+
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
15+
}
16+
],
17+
"affected": [
18+
{
19+
"package": {
20+
"ecosystem": "Go",
21+
"name": "chainguard.dev/melange"
22+
},
23+
"ranges": [
24+
{
25+
"type": "ECOSYSTEM",
26+
"events": [
27+
{
28+
"introduced": "0.23.0"
29+
},
30+
{
31+
"fixed": "0.29.5"
32+
}
33+
]
34+
}
35+
]
36+
}
37+
],
38+
"references": [
39+
{
40+
"type": "WEB",
41+
"url": "https://github.com/chainguard-dev/melange/security/advisories/GHSA-5662-cv6m-63wh"
42+
},
43+
{
44+
"type": "ADVISORY",
45+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-54059"
46+
},
47+
{
48+
"type": "WEB",
49+
"url": "https://github.com/chainguard-dev/melange/pull/1836"
50+
},
51+
{
52+
"type": "WEB",
53+
"url": "https://github.com/chainguard-dev/melange/pull/2086"
54+
},
55+
{
56+
"type": "WEB",
57+
"url": "https://github.com/chainguard-dev/melange/commit/1b272db2a0bb3441553284cc56d87236b4b64c04"
58+
},
59+
{
60+
"type": "WEB",
61+
"url": "https://github.com/chainguard-dev/melange/commit/e29494b4a40a91619ec1c87a09003c6d5164cea1"
62+
},
63+
{
64+
"type": "PACKAGE",
65+
"url": "https://github.com/chainguard-dev/melange"
66+
},
67+
{
68+
"type": "WEB",
69+
"url": "https://github.com/chainguard-dev/melange/releases/tag/v0.29.5"
70+
}
71+
],
72+
"database_specific": {
73+
"cwe_ids": [
74+
"CWE-276"
75+
],
76+
"severity": "MODERATE",
77+
"github_reviewed": true,
78+
"github_reviewed_at": "2025-07-18T20:13:21Z",
79+
"nvd_published_at": "2025-07-18T16:15:30Z"
80+
}
81+
}

0 commit comments

Comments
 (0)
pFad - Phonifier reborn

Pfad - The Proxy pFad of © 2024 Garber Painting. All rights reserved.

Note: This service is not intended for secure transactions such as banking, social media, email, or purchasing. Use at your own risk. We assume no liability whatsoever for broken pages.


Alternative Proxies:

Alternative Proxy

pFad Proxy

pFad v3 Proxy

pFad v4 Proxy