GHSA-v444-jggx-6v7f

Suggest an improvement
Source
https://github.com/advisories/GHSA-v444-jggx-6v7f
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/01/GHSA-v444-jggx-6v7f/GHSA-v444-jggx-6v7f.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-v444-jggx-6v7f
Withdrawn
2024-01-05T15:27:09Z
Published
2024-01-04T21:30:24Z
Modified
2024-12-07T05:44:50Z
Severity
  • 3.1 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N CVSS Calculator
Summary
Duplicate Advisory: Race Condition leading to logging errors
Details

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-hjp3-5g2q-7jww. This link is maintained to preserve external references.

Original Description

A race condition exists in Audited 4.0.0 to 5.3.3 that can result in an authenticated user to cause audit log entries to be attributed to another user.

Database specific
{
    "cwe_ids":  [
        "CWE-362"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2024-01-05T15:27:09Z",
    "nvd_published_at":  "2024-01-04T21:15:09Z",
    "severity":  "LOW"
}
References

Affected packages

RubyGems / audited

Package

Name
audited
Purl
pkg:gem/audited

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.0.0

Affected versions

4.*
4.0.0
4.2.0
4.2.1
4.2.2
4.3.0
4.4.0
4.4.1
4.5.0
4.6.0
4.7.0
4.7.1
4.8.0
4.9.0
4.10.0
5.*
5.0.0
5.0.1
5.0.2
5.1.0
5.2.0
5.3.0
5.3.1
5.3.2
5.3.3
5.4.0
5.4.1
5.4.2
5.4.3
5.5.0
5.5.1.pre
5.6.0
5.7.0
5.8.0

Database specific

last_known_affected_version_range
"< 5.3.3"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/01/GHSA-v444-jggx-6v7f/GHSA-v444-jggx-6v7f.json"