github / advisory-database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Creative Commons Attribution 4.0 International
1.68k stars 312 forks source link

[GHSA-64x4-9hc6-r2h6] Microsoft: CBC Padding Oracle in Azure Blob Storage Encryption Library #4457

Closed andrewpollock closed 2 months ago

andrewpollock commented 2 months ago

Updates

Comments Adding missing Python and Java packages, reported to us via https://github.com/google/osv.dev/issues/2024

darakian commented 2 months ago

@andrewpollock many thanks for the update. I swapped azure-storage-blobs over to azure-storage-blob assuming the former was a typo. https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2022-30187 Shows blob as a singular 👍

advisory-database[bot] commented 2 months ago

Hi @andrewpollock! Thank you so much for contributing to the GitHub Advisory Database. This database is free, open, and accessible to all, and it's people like you who make it great. Thanks for choosing to help others. We hope you send in more contributions in the future!