From 028dc05b92767b38d0a0304814a63096e50ddeaf Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 24 Jul 2023 15:31:35 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-f5xq-h855-6hmf.json | 10 ++-- .../GHSA-gj58-7wr2-fh9g.json | 3 +- .../GHSA-mjgc-6w7g-2jm9.json | 8 +++- .../GHSA-q493-fq52-3qhm.json | 8 +++- .../GHSA-qjg9-wm29-5rcr.json | 10 ++-- .../GHSA-v36c-pq4h-93xc.json | 1 + .../GHSA-45m8-h637-23mm.json | 8 +++- .../GHSA-97p6-2wmw-hgqw.json | 8 +++- .../GHSA-fh7g-p43j-mxhc.json | 3 +- .../GHSA-vqjc-h5m3-4q6j.json | 9 +++- .../GHSA-rqg9-g4fr-3cfj.json | 3 +- .../GHSA-vmqf-73mx-mcw4.json | 1 + .../GHSA-wg4r-r6qv-94rv.json | 1 + .../GHSA-3h6x-gjf3-36gg.json | 3 +- .../GHSA-3mvx-8xgc-hh5r.json | 1 + .../GHSA-5f4g-m368-xv75.json | 1 + .../GHSA-5j9q-qmpc-xr4h.json | 3 +- .../GHSA-62wm-7vp9-fwxg.json | 3 +- .../GHSA-8fpw-v4hg-9mh6.json | 2 +- .../GHSA-8h88-6gx7-v9hf.json | 3 +- .../GHSA-9fp2-68jw-464m.json | 3 +- .../GHSA-c2qf-9gp9-pqg9.json | 3 +- .../GHSA-fqx8-cxfv-jq6h.json | 4 +- .../GHSA-j5q8-gr47-f6vp.json | 3 +- .../GHSA-p496-gr7f-4c2g.json | 2 +- .../GHSA-pcvw-8qvg-9cqf.json | 1 + .../GHSA-pr98-wpx5-8xmp.json | 3 +- .../GHSA-q427-r549-25f6.json | 3 +- .../GHSA-v364-rr92-9x6x.json | 2 + .../GHSA-wxv8-vqc5-v4j2.json | 1 + .../GHSA-2r69-696x-qxj9.json | 3 +- .../GHSA-3c8q-f97c-vpw3.json | 3 +- .../GHSA-6m4r-6x5q-4gv6.json | 3 +- .../GHSA-g4hg-xr8w-wm8x.json | 3 +- .../GHSA-h6h4-hwj4-6rv9.json | 3 +- .../GHSA-w4mh-9fw9-766v.json | 1 + .../GHSA-7639-pv9r-w8cv.json | 2 +- .../GHSA-7j2h-f54c-qv9j.json | 3 +- .../GHSA-99mv-pfx6-v678.json | 1 + .../GHSA-9p6h-67hg-3ph5.json | 1 + .../GHSA-c8xc-gc49-4vf2.json | 2 + .../GHSA-cr6m-g8w4-422x.json | 4 +- .../GHSA-f7h3-whmx-5pqj.json | 3 +- .../GHSA-ffqc-r4j7-pvvm.json | 4 +- .../GHSA-g5w2-92px-9hwf.json | 3 +- .../GHSA-gc9p-mgj9-4r5j.json | 3 +- .../GHSA-h7cv-65j5-5g78.json | 1 + .../GHSA-m3m5-474m-99qj.json | 1 + .../GHSA-mgwv-57p9-8v74.json | 3 +- .../GHSA-qg67-mxc2-7gc6.json | 3 +- .../GHSA-qrr2-wwrr-wp96.json | 1 + .../GHSA-xfxv-hqvj-fpfc.json | 4 +- .../GHSA-59rr-qhh3-g554.json | 3 +- .../GHSA-fxfc-w6xq-5pp8.json | 3 +- .../GHSA-j8g4-6p94-j4fp.json | 3 +- .../GHSA-qwqq-2qch-x65x.json | 3 +- .../GHSA-vjcc-9q9g-593v.json | 1 + .../GHSA-x6gc-63rj-4gw6.json | 5 +- .../GHSA-8482-w39m-g3c5.json | 1 + .../GHSA-px5r-qw43-pqcc.json | 3 +- .../GHSA-r8cv-8cqg-5fqv.json | 3 +- .../GHSA-75hr-42cm-p5wq.json | 1 + .../GHSA-3qhf-px5p-g68q.json | 39 ++++++++++++++++ .../GHSA-h49p-m77c-w5m9.json | 39 ++++++++++++++++ .../GHSA-p4m9-r3rr-cx92.json | 46 +++++++++++++++++++ .../GHSA-r6xc-9724-9r8g.json | 39 ++++++++++++++++ .../GHSA-wrgm-rq8f-75r7.json | 39 ++++++++++++++++ .../GHSA-xrrm-rgr6-3gfq.json | 39 ++++++++++++++++ 68 files changed, 382 insertions(+), 54 deletions(-) create mode 100644 advisories/unreviewed/2023/07/GHSA-3qhf-px5p-g68q/GHSA-3qhf-px5p-g68q.json create mode 100644 advisories/unreviewed/2023/07/GHSA-h49p-m77c-w5m9/GHSA-h49p-m77c-w5m9.json create mode 100644 advisories/unreviewed/2023/07/GHSA-p4m9-r3rr-cx92/GHSA-p4m9-r3rr-cx92.json create mode 100644 advisories/unreviewed/2023/07/GHSA-r6xc-9724-9r8g/GHSA-r6xc-9724-9r8g.json create mode 100644 advisories/unreviewed/2023/07/GHSA-wrgm-rq8f-75r7/GHSA-wrgm-rq8f-75r7.json create mode 100644 advisories/unreviewed/2023/07/GHSA-xrrm-rgr6-3gfq/GHSA-xrrm-rgr6-3gfq.json diff --git a/advisories/unreviewed/2022/01/GHSA-f5xq-h855-6hmf/GHSA-f5xq-h855-6hmf.json b/advisories/unreviewed/2022/01/GHSA-f5xq-h855-6hmf/GHSA-f5xq-h855-6hmf.json index 26594edf521..6e353e38a67 100644 --- a/advisories/unreviewed/2022/01/GHSA-f5xq-h855-6hmf/GHSA-f5xq-h855-6hmf.json +++ b/advisories/unreviewed/2022/01/GHSA-f5xq-h855-6hmf/GHSA-f5xq-h855-6hmf.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-f5xq-h855-6hmf", - "modified": "2022-01-27T00:03:54Z", + "modified": "2023-07-24T15:30:18Z", "published": "2022-01-20T00:02:04Z", "aliases": [ "CVE-2022-22155" ], "details": "An Uncontrolled Resource Consumption vulnerability in the handling of IPv6 neighbor state change events in Juniper Networks Junos OS allows an adjacent attacker to cause a memory leak in the Flexible PIC Concentrator (FPC) of an ACX5448 router. The continuous flapping of an IPv6 neighbor with specific timing will cause the FPC to run out of resources, leading to a Denial of Service (DoS) condition. Once the condition occurs, further packet processing will be impacted, creating a sustained Denial of Service (DoS) condition, requiring a manual PFE restart to restore service. The following error messages will be seen after the FPC resources have been exhausted: fpc0 DNX_NH::dnx_nh_tag_ipv4_hw_install(),3135: dnx_nh_tag_ipv4_hw_install: BCM L3 Egress create object failed for NH 602 (-14:No resources for operation), BCM NH Params: unit:0 Port:41, L3_INTF:0 Flags: 0x40 fpc0 DNX_NH::dnx_nh_tag_ipv4_hw_install(),3135: dnx_nh_tag_ipv4_hw_install: BCM L3 Egress create object failed for NH 602 (-14:No resources for operation), BCM NH Params: unit:0 Port:41, L3_INTF:0 Flags: 0x40 fpc0 DNX_NH::dnx_nh_tag_ipv4_hw_install(),3135: dnx_nh_tag_ipv4_hw_install: BCM L3 Egress create object failed for NH 602 (-14:No resources for operation), BCM NH Params: unit:0 Port:41, L3_INTF:0 Flags: 0x40 fpc0 DNX_NH::dnx_nh_tag_ipv4_hw_install(),3135: dnx_nh_tag_ipv4_hw_install: BCM L3 Egress create object failed for NH 602 (-14:No resources for operation), BCM NH Params: unit:0 Port:41, L3_INTF:0 Flags: 0x40 This issue only affects the ACX5448 router. No other products or platforms are affected by this vulnerability. This issue affects Juniper Networks Junos OS on ACX5448: 18.4 versions prior to 18.4R3-S10; 19.1 versions prior to 19.1R3-S5; 19.2 versions prior to 19.2R1-S8, 19.2R3-S2; 19.3 versions prior to 19.3R2-S6, 19.3R3-S2; 19.4 versions prior to 19.4R1-S3, 19.4R2-S2, 19.4R3; 20.1 versions prior to 20.1R2; 20.2 versions prior to 20.2R1-S1, 20.2R2.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-400" + "CWE-400", + "CWE-401" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/01/GHSA-gj58-7wr2-fh9g/GHSA-gj58-7wr2-fh9g.json b/advisories/unreviewed/2022/01/GHSA-gj58-7wr2-fh9g/GHSA-gj58-7wr2-fh9g.json index a633c6a82b2..ebe20776436 100644 --- a/advisories/unreviewed/2022/01/GHSA-gj58-7wr2-fh9g/GHSA-gj58-7wr2-fh9g.json +++ b/advisories/unreviewed/2022/01/GHSA-gj58-7wr2-fh9g/GHSA-gj58-7wr2-fh9g.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/01/GHSA-mjgc-6w7g-2jm9/GHSA-mjgc-6w7g-2jm9.json b/advisories/unreviewed/2022/01/GHSA-mjgc-6w7g-2jm9/GHSA-mjgc-6w7g-2jm9.json index 95a25d8a3e6..f125a525ea0 100644 --- a/advisories/unreviewed/2022/01/GHSA-mjgc-6w7g-2jm9/GHSA-mjgc-6w7g-2jm9.json +++ b/advisories/unreviewed/2022/01/GHSA-mjgc-6w7g-2jm9/GHSA-mjgc-6w7g-2jm9.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-mjgc-6w7g-2jm9", - "modified": "2022-01-16T00:01:05Z", + "modified": "2023-07-24T15:30:17Z", "published": "2022-01-11T00:00:55Z", "aliases": [ "CVE-2022-22271" ], "details": "A missing input validation before memory copy in TIMA trustlet prior to SMR Jan-2022 Release 1 allows attackers to copy data from arbitrary memory.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-20" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/01/GHSA-q493-fq52-3qhm/GHSA-q493-fq52-3qhm.json b/advisories/unreviewed/2022/01/GHSA-q493-fq52-3qhm/GHSA-q493-fq52-3qhm.json index f98ede88c7a..d0aa174dbe0 100644 --- a/advisories/unreviewed/2022/01/GHSA-q493-fq52-3qhm/GHSA-q493-fq52-3qhm.json +++ b/advisories/unreviewed/2022/01/GHSA-q493-fq52-3qhm/GHSA-q493-fq52-3qhm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-q493-fq52-3qhm", - "modified": "2022-01-22T00:02:15Z", + "modified": "2023-07-24T15:30:18Z", "published": "2022-01-15T00:01:53Z", "aliases": [ "CVE-2022-20698" ], "details": "A vulnerability in the OOXML parsing module in Clam AntiVirus (ClamAV) Software version 0.104.1 and LTS version 0.103.4 and prior versions could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to improper checks that may result in an invalid pointer read. An attacker could exploit this vulnerability by sending a crafted OOXML file to an affected device. An exploit could allow the attacker to cause the ClamAV scanning process to crash, resulting in a denial of service condition.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ @@ -25,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-20" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/01/GHSA-qjg9-wm29-5rcr/GHSA-qjg9-wm29-5rcr.json b/advisories/unreviewed/2022/01/GHSA-qjg9-wm29-5rcr/GHSA-qjg9-wm29-5rcr.json index 7ebc55a8f38..f5ac77344b4 100644 --- a/advisories/unreviewed/2022/01/GHSA-qjg9-wm29-5rcr/GHSA-qjg9-wm29-5rcr.json +++ b/advisories/unreviewed/2022/01/GHSA-qjg9-wm29-5rcr/GHSA-qjg9-wm29-5rcr.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-qjg9-wm29-5rcr", - "modified": "2022-01-28T00:03:46Z", + "modified": "2023-07-24T15:30:18Z", "published": "2022-01-22T00:00:47Z", "aliases": [ "CVE-2022-21933" ], "details": "ASUS VivoMini/Mini PC device has an improper input validation vulnerability. A local attacker with system privilege can use system management interrupt (SMI) to modify memory, resulting in arbitrary code execution for controlling the system or disrupting service.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/01/GHSA-v36c-pq4h-93xc/GHSA-v36c-pq4h-93xc.json b/advisories/unreviewed/2022/01/GHSA-v36c-pq4h-93xc/GHSA-v36c-pq4h-93xc.json index a8331b3ab32..f9a231984d5 100644 --- a/advisories/unreviewed/2022/01/GHSA-v36c-pq4h-93xc/GHSA-v36c-pq4h-93xc.json +++ b/advisories/unreviewed/2022/01/GHSA-v36c-pq4h-93xc/GHSA-v36c-pq4h-93xc.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-457", "CWE-787", "CWE-908" ], diff --git a/advisories/unreviewed/2022/02/GHSA-45m8-h637-23mm/GHSA-45m8-h637-23mm.json b/advisories/unreviewed/2022/02/GHSA-45m8-h637-23mm/GHSA-45m8-h637-23mm.json index 0a2f3e85b5f..e8575fc7276 100644 --- a/advisories/unreviewed/2022/02/GHSA-45m8-h637-23mm/GHSA-45m8-h637-23mm.json +++ b/advisories/unreviewed/2022/02/GHSA-45m8-h637-23mm/GHSA-45m8-h637-23mm.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-45m8-h637-23mm", - "modified": "2022-02-27T00:00:25Z", + "modified": "2023-07-24T15:30:19Z", "published": "2022-02-19T00:01:26Z", "aliases": [ "CVE-2022-21800" ], "details": "MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 uses the MD5 algorithm to hash the passwords before storing them but does not salt the hash. As a result, attackers may be able to crack the hashed passwords.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-326", "CWE-327" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/02/GHSA-97p6-2wmw-hgqw/GHSA-97p6-2wmw-hgqw.json b/advisories/unreviewed/2022/02/GHSA-97p6-2wmw-hgqw/GHSA-97p6-2wmw-hgqw.json index 6f7d68733bc..fe146d120ff 100644 --- a/advisories/unreviewed/2022/02/GHSA-97p6-2wmw-hgqw/GHSA-97p6-2wmw-hgqw.json +++ b/advisories/unreviewed/2022/02/GHSA-97p6-2wmw-hgqw/GHSA-97p6-2wmw-hgqw.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-97p6-2wmw-hgqw", - "modified": "2022-02-18T00:00:55Z", + "modified": "2023-07-24T15:30:19Z", "published": "2022-02-11T00:00:45Z", "aliases": [ "CVE-2022-20680" ], "details": "A vulnerability in the web-based management interface of Cisco Prime Service Catalog could allow an authenticated, remote attacker to access sensitive information on an affected device. This vulnerability is due to improper enforcement of Administrator privilege levels for low-value sensitive data. An attacker with read-only Administrator access to the web-based management interface could exploit this vulnerability by sending a malicious HTTP request to the page that contains the sensitive data. A successful exploit could allow the attacker to collect sensitive information about users of the system and orders that have been placed using the application.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ @@ -25,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-200", "CWE-269" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/02/GHSA-fh7g-p43j-mxhc/GHSA-fh7g-p43j-mxhc.json b/advisories/unreviewed/2022/02/GHSA-fh7g-p43j-mxhc/GHSA-fh7g-p43j-mxhc.json index af0124f0172..bc1de849f04 100644 --- a/advisories/unreviewed/2022/02/GHSA-fh7g-p43j-mxhc/GHSA-fh7g-p43j-mxhc.json +++ b/advisories/unreviewed/2022/02/GHSA-fh7g-p43j-mxhc/GHSA-fh7g-p43j-mxhc.json @@ -36,7 +36,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-427" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/02/GHSA-vqjc-h5m3-4q6j/GHSA-vqjc-h5m3-4q6j.json b/advisories/unreviewed/2022/02/GHSA-vqjc-h5m3-4q6j/GHSA-vqjc-h5m3-4q6j.json index 586f7f5bd8b..8a5a6db1665 100644 --- a/advisories/unreviewed/2022/02/GHSA-vqjc-h5m3-4q6j/GHSA-vqjc-h5m3-4q6j.json +++ b/advisories/unreviewed/2022/02/GHSA-vqjc-h5m3-4q6j/GHSA-vqjc-h5m3-4q6j.json @@ -1,14 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vqjc-h5m3-4q6j", - "modified": "2022-02-27T00:00:25Z", + "modified": "2023-07-24T15:30:19Z", "published": "2022-02-19T00:01:27Z", "aliases": [ "CVE-2022-21196" ], "details": "MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does not perform proper authorization and authentication checks on multiple API routes. An attacker may gain access to these API routes and achieve remote code execution, create a denial-of-service condition, and obtain sensitive information.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ @@ -25,6 +28,8 @@ ], "database_specific": { "cwe_ids": [ + "CWE-285", + "CWE-287", "CWE-863" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2022/03/GHSA-rqg9-g4fr-3cfj/GHSA-rqg9-g4fr-3cfj.json b/advisories/unreviewed/2022/03/GHSA-rqg9-g4fr-3cfj/GHSA-rqg9-g4fr-3cfj.json index 3c0666b7d8c..28deb476e4e 100644 --- a/advisories/unreviewed/2022/03/GHSA-rqg9-g4fr-3cfj/GHSA-rqg9-g4fr-3cfj.json +++ b/advisories/unreviewed/2022/03/GHSA-rqg9-g4fr-3cfj/GHSA-rqg9-g4fr-3cfj.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-755" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/03/GHSA-vmqf-73mx-mcw4/GHSA-vmqf-73mx-mcw4.json b/advisories/unreviewed/2022/03/GHSA-vmqf-73mx-mcw4/GHSA-vmqf-73mx-mcw4.json index 34b7bd05604..a8b8ad3cd8a 100644 --- a/advisories/unreviewed/2022/03/GHSA-vmqf-73mx-mcw4/GHSA-vmqf-73mx-mcw4.json +++ b/advisories/unreviewed/2022/03/GHSA-vmqf-73mx-mcw4/GHSA-vmqf-73mx-mcw4.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-287", "CWE-522" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/03/GHSA-wg4r-r6qv-94rv/GHSA-wg4r-r6qv-94rv.json b/advisories/unreviewed/2022/03/GHSA-wg4r-r6qv-94rv/GHSA-wg4r-r6qv-94rv.json index 43cdfa02435..44b973c19f7 100644 --- a/advisories/unreviewed/2022/03/GHSA-wg4r-r6qv-94rv/GHSA-wg4r-r6qv-94rv.json +++ b/advisories/unreviewed/2022/03/GHSA-wg4r-r6qv-94rv/GHSA-wg4r-r6qv-94rv.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-285", "CWE-863" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/04/GHSA-3h6x-gjf3-36gg/GHSA-3h6x-gjf3-36gg.json b/advisories/unreviewed/2022/04/GHSA-3h6x-gjf3-36gg/GHSA-3h6x-gjf3-36gg.json index 205714c4d42..32de87ad31a 100644 --- a/advisories/unreviewed/2022/04/GHSA-3h6x-gjf3-36gg/GHSA-3h6x-gjf3-36gg.json +++ b/advisories/unreviewed/2022/04/GHSA-3h6x-gjf3-36gg/GHSA-3h6x-gjf3-36gg.json @@ -44,7 +44,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-400" + "CWE-400", + "CWE-404" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/04/GHSA-3mvx-8xgc-hh5r/GHSA-3mvx-8xgc-hh5r.json b/advisories/unreviewed/2022/04/GHSA-3mvx-8xgc-hh5r/GHSA-3mvx-8xgc-hh5r.json index d65ec7656cc..01f6a2ef593 100644 --- a/advisories/unreviewed/2022/04/GHSA-3mvx-8xgc-hh5r/GHSA-3mvx-8xgc-hh5r.json +++ b/advisories/unreviewed/2022/04/GHSA-3mvx-8xgc-hh5r/GHSA-3mvx-8xgc-hh5r.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-203", "CWE-326" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/04/GHSA-5f4g-m368-xv75/GHSA-5f4g-m368-xv75.json b/advisories/unreviewed/2022/04/GHSA-5f4g-m368-xv75/GHSA-5f4g-m368-xv75.json index 67984084c35..84e18015086 100644 --- a/advisories/unreviewed/2022/04/GHSA-5f4g-m368-xv75/GHSA-5f4g-m368-xv75.json +++ b/advisories/unreviewed/2022/04/GHSA-5f4g-m368-xv75/GHSA-5f4g-m368-xv75.json @@ -33,6 +33,7 @@ "database_specific": { "cwe_ids": [ "CWE-326", + "CWE-327", "CWE-359" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/04/GHSA-5j9q-qmpc-xr4h/GHSA-5j9q-qmpc-xr4h.json b/advisories/unreviewed/2022/04/GHSA-5j9q-qmpc-xr4h/GHSA-5j9q-qmpc-xr4h.json index c6c2721a4e7..d174c049af9 100644 --- a/advisories/unreviewed/2022/04/GHSA-5j9q-qmpc-xr4h/GHSA-5j9q-qmpc-xr4h.json +++ b/advisories/unreviewed/2022/04/GHSA-5j9q-qmpc-xr4h/GHSA-5j9q-qmpc-xr4h.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-327", + "CWE-693" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/04/GHSA-62wm-7vp9-fwxg/GHSA-62wm-7vp9-fwxg.json b/advisories/unreviewed/2022/04/GHSA-62wm-7vp9-fwxg/GHSA-62wm-7vp9-fwxg.json index 7a885de90b9..8afdfadf828 100644 --- a/advisories/unreviewed/2022/04/GHSA-62wm-7vp9-fwxg/GHSA-62wm-7vp9-fwxg.json +++ b/advisories/unreviewed/2022/04/GHSA-62wm-7vp9-fwxg/GHSA-62wm-7vp9-fwxg.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-863" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/04/GHSA-8fpw-v4hg-9mh6/GHSA-8fpw-v4hg-9mh6.json b/advisories/unreviewed/2022/04/GHSA-8fpw-v4hg-9mh6/GHSA-8fpw-v4hg-9mh6.json index 3e8d93dd685..5b81dfed99f 100644 --- a/advisories/unreviewed/2022/04/GHSA-8fpw-v4hg-9mh6/GHSA-8fpw-v4hg-9mh6.json +++ b/advisories/unreviewed/2022/04/GHSA-8fpw-v4hg-9mh6/GHSA-8fpw-v4hg-9mh6.json @@ -32,7 +32,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/04/GHSA-8h88-6gx7-v9hf/GHSA-8h88-6gx7-v9hf.json b/advisories/unreviewed/2022/04/GHSA-8h88-6gx7-v9hf/GHSA-8h88-6gx7-v9hf.json index cf4a9934224..5c0ba30fcf4 100644 --- a/advisories/unreviewed/2022/04/GHSA-8h88-6gx7-v9hf/GHSA-8h88-6gx7-v9hf.json +++ b/advisories/unreviewed/2022/04/GHSA-8h88-6gx7-v9hf/GHSA-8h88-6gx7-v9hf.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-22", + "CWE-755" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/04/GHSA-9fp2-68jw-464m/GHSA-9fp2-68jw-464m.json b/advisories/unreviewed/2022/04/GHSA-9fp2-68jw-464m/GHSA-9fp2-68jw-464m.json index be1f47d163c..6657decd037 100644 --- a/advisories/unreviewed/2022/04/GHSA-9fp2-68jw-464m/GHSA-9fp2-68jw-464m.json +++ b/advisories/unreviewed/2022/04/GHSA-9fp2-68jw-464m/GHSA-9fp2-68jw-464m.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-326" + "CWE-326", + "CWE-338" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/04/GHSA-c2qf-9gp9-pqg9/GHSA-c2qf-9gp9-pqg9.json b/advisories/unreviewed/2022/04/GHSA-c2qf-9gp9-pqg9/GHSA-c2qf-9gp9-pqg9.json index c6c566938e2..794b11555c2 100644 --- a/advisories/unreviewed/2022/04/GHSA-c2qf-9gp9-pqg9/GHSA-c2qf-9gp9-pqg9.json +++ b/advisories/unreviewed/2022/04/GHSA-c2qf-9gp9-pqg9/GHSA-c2qf-9gp9-pqg9.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-22" + "CWE-22", + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/04/GHSA-fqx8-cxfv-jq6h/GHSA-fqx8-cxfv-jq6h.json b/advisories/unreviewed/2022/04/GHSA-fqx8-cxfv-jq6h/GHSA-fqx8-cxfv-jq6h.json index 64a2a4673e3..b2bce20d552 100644 --- a/advisories/unreviewed/2022/04/GHSA-fqx8-cxfv-jq6h/GHSA-fqx8-cxfv-jq6h.json +++ b/advisories/unreviewed/2022/04/GHSA-fqx8-cxfv-jq6h/GHSA-fqx8-cxfv-jq6h.json @@ -32,7 +32,9 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-22", + "CWE-74", + "CWE-78" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/04/GHSA-j5q8-gr47-f6vp/GHSA-j5q8-gr47-f6vp.json b/advisories/unreviewed/2022/04/GHSA-j5q8-gr47-f6vp/GHSA-j5q8-gr47-f6vp.json index 7400f608de8..b63e2bd8fcb 100644 --- a/advisories/unreviewed/2022/04/GHSA-j5q8-gr47-f6vp/GHSA-j5q8-gr47-f6vp.json +++ b/advisories/unreviewed/2022/04/GHSA-j5q8-gr47-f6vp/GHSA-j5q8-gr47-f6vp.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-287" + "CWE-287", + "CWE-306" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/04/GHSA-p496-gr7f-4c2g/GHSA-p496-gr7f-4c2g.json b/advisories/unreviewed/2022/04/GHSA-p496-gr7f-4c2g/GHSA-p496-gr7f-4c2g.json index 9658e50ac4b..531c635a70f 100644 --- a/advisories/unreviewed/2022/04/GHSA-p496-gr7f-4c2g/GHSA-p496-gr7f-4c2g.json +++ b/advisories/unreviewed/2022/04/GHSA-p496-gr7f-4c2g/GHSA-p496-gr7f-4c2g.json @@ -28,7 +28,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-325" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/04/GHSA-pcvw-8qvg-9cqf/GHSA-pcvw-8qvg-9cqf.json b/advisories/unreviewed/2022/04/GHSA-pcvw-8qvg-9cqf/GHSA-pcvw-8qvg-9cqf.json index 1d243cd3ab2..9ae7c527427 100644 --- a/advisories/unreviewed/2022/04/GHSA-pcvw-8qvg-9cqf/GHSA-pcvw-8qvg-9cqf.json +++ b/advisories/unreviewed/2022/04/GHSA-pcvw-8qvg-9cqf/GHSA-pcvw-8qvg-9cqf.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-74" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/04/GHSA-pr98-wpx5-8xmp/GHSA-pr98-wpx5-8xmp.json b/advisories/unreviewed/2022/04/GHSA-pr98-wpx5-8xmp/GHSA-pr98-wpx5-8xmp.json index af946490666..80518794cff 100644 --- a/advisories/unreviewed/2022/04/GHSA-pr98-wpx5-8xmp/GHSA-pr98-wpx5-8xmp.json +++ b/advisories/unreviewed/2022/04/GHSA-pr98-wpx5-8xmp/GHSA-pr98-wpx5-8xmp.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-78" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/04/GHSA-q427-r549-25f6/GHSA-q427-r549-25f6.json b/advisories/unreviewed/2022/04/GHSA-q427-r549-25f6/GHSA-q427-r549-25f6.json index 75163638c92..494c71c29ed 100644 --- a/advisories/unreviewed/2022/04/GHSA-q427-r549-25f6/GHSA-q427-r549-25f6.json +++ b/advisories/unreviewed/2022/04/GHSA-q427-r549-25f6/GHSA-q427-r549-25f6.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-22" + "CWE-22", + "CWE-59" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/04/GHSA-v364-rr92-9x6x/GHSA-v364-rr92-9x6x.json b/advisories/unreviewed/2022/04/GHSA-v364-rr92-9x6x/GHSA-v364-rr92-9x6x.json index c51e78c08a9..18abc1da9e3 100644 --- a/advisories/unreviewed/2022/04/GHSA-v364-rr92-9x6x/GHSA-v364-rr92-9x6x.json +++ b/advisories/unreviewed/2022/04/GHSA-v364-rr92-9x6x/GHSA-v364-rr92-9x6x.json @@ -28,6 +28,8 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", + "CWE-23", "CWE-287" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/04/GHSA-wxv8-vqc5-v4j2/GHSA-wxv8-vqc5-v4j2.json b/advisories/unreviewed/2022/04/GHSA-wxv8-vqc5-v4j2/GHSA-wxv8-vqc5-v4j2.json index 8fe736c0dd8..fb451fdf60b 100644 --- a/advisories/unreviewed/2022/04/GHSA-wxv8-vqc5-v4j2/GHSA-wxv8-vqc5-v4j2.json +++ b/advisories/unreviewed/2022/04/GHSA-wxv8-vqc5-v4j2/GHSA-wxv8-vqc5-v4j2.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-284", "CWE-863" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/05/GHSA-2r69-696x-qxj9/GHSA-2r69-696x-qxj9.json b/advisories/unreviewed/2022/05/GHSA-2r69-696x-qxj9/GHSA-2r69-696x-qxj9.json index 1e96783edce..a8a5fb64feb 100644 --- a/advisories/unreviewed/2022/05/GHSA-2r69-696x-qxj9/GHSA-2r69-696x-qxj9.json +++ b/advisories/unreviewed/2022/05/GHSA-2r69-696x-qxj9/GHSA-2r69-696x-qxj9.json @@ -44,7 +44,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-287" + "CWE-287", + "CWE-306" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-3c8q-f97c-vpw3/GHSA-3c8q-f97c-vpw3.json b/advisories/unreviewed/2022/05/GHSA-3c8q-f97c-vpw3/GHSA-3c8q-f97c-vpw3.json index b4063b848ac..988282ac0bd 100644 --- a/advisories/unreviewed/2022/05/GHSA-3c8q-f97c-vpw3/GHSA-3c8q-f97c-vpw3.json +++ b/advisories/unreviewed/2022/05/GHSA-3c8q-f97c-vpw3/GHSA-3c8q-f97c-vpw3.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-6m4r-6x5q-4gv6/GHSA-6m4r-6x5q-4gv6.json b/advisories/unreviewed/2022/05/GHSA-6m4r-6x5q-4gv6/GHSA-6m4r-6x5q-4gv6.json index 19e92772e63..32b7ff7890a 100644 --- a/advisories/unreviewed/2022/05/GHSA-6m4r-6x5q-4gv6/GHSA-6m4r-6x5q-4gv6.json +++ b/advisories/unreviewed/2022/05/GHSA-6m4r-6x5q-4gv6/GHSA-6m4r-6x5q-4gv6.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-g4hg-xr8w-wm8x/GHSA-g4hg-xr8w-wm8x.json b/advisories/unreviewed/2022/05/GHSA-g4hg-xr8w-wm8x/GHSA-g4hg-xr8w-wm8x.json index f017ea39d22..77a9f6559f4 100644 --- a/advisories/unreviewed/2022/05/GHSA-g4hg-xr8w-wm8x/GHSA-g4hg-xr8w-wm8x.json +++ b/advisories/unreviewed/2022/05/GHSA-g4hg-xr8w-wm8x/GHSA-g4hg-xr8w-wm8x.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-807" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-h6h4-hwj4-6rv9/GHSA-h6h4-hwj4-6rv9.json b/advisories/unreviewed/2022/05/GHSA-h6h4-hwj4-6rv9/GHSA-h6h4-hwj4-6rv9.json index 07db2acd0de..8931c25842f 100644 --- a/advisories/unreviewed/2022/05/GHSA-h6h4-hwj4-6rv9/GHSA-h6h4-hwj4-6rv9.json +++ b/advisories/unreviewed/2022/05/GHSA-h6h4-hwj4-6rv9/GHSA-h6h4-hwj4-6rv9.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-269" + "CWE-269", + "CWE-284" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-w4mh-9fw9-766v/GHSA-w4mh-9fw9-766v.json b/advisories/unreviewed/2022/05/GHSA-w4mh-9fw9-766v/GHSA-w4mh-9fw9-766v.json index b19041aeff0..1a0a2386ca4 100644 --- a/advisories/unreviewed/2022/05/GHSA-w4mh-9fw9-766v/GHSA-w4mh-9fw9-766v.json +++ b/advisories/unreviewed/2022/05/GHSA-w4mh-9fw9-766v/GHSA-w4mh-9fw9-766v.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-284", "CWE-863" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2022/06/GHSA-7639-pv9r-w8cv/GHSA-7639-pv9r-w8cv.json b/advisories/unreviewed/2022/06/GHSA-7639-pv9r-w8cv/GHSA-7639-pv9r-w8cv.json index 66b87fd5c5d..b3c8a92cfc1 100644 --- a/advisories/unreviewed/2022/06/GHSA-7639-pv9r-w8cv/GHSA-7639-pv9r-w8cv.json +++ b/advisories/unreviewed/2022/06/GHSA-7639-pv9r-w8cv/GHSA-7639-pv9r-w8cv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7639-pv9r-w8cv", - "modified": "2022-07-07T00:00:29Z", + "modified": "2023-07-24T15:30:25Z", "published": "2022-06-25T00:00:53Z", "aliases": [ "CVE-2022-1740" diff --git a/advisories/unreviewed/2022/06/GHSA-7j2h-f54c-qv9j/GHSA-7j2h-f54c-qv9j.json b/advisories/unreviewed/2022/06/GHSA-7j2h-f54c-qv9j/GHSA-7j2h-f54c-qv9j.json index 6ceaadd0779..e3de1e19d1d 100644 --- a/advisories/unreviewed/2022/06/GHSA-7j2h-f54c-qv9j/GHSA-7j2h-f54c-qv9j.json +++ b/advisories/unreviewed/2022/06/GHSA-7j2h-f54c-qv9j/GHSA-7j2h-f54c-qv9j.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-269" + "CWE-269", + "CWE-59" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/06/GHSA-99mv-pfx6-v678/GHSA-99mv-pfx6-v678.json b/advisories/unreviewed/2022/06/GHSA-99mv-pfx6-v678/GHSA-99mv-pfx6-v678.json index 2bf75596311..cf357f3870f 100644 --- a/advisories/unreviewed/2022/06/GHSA-99mv-pfx6-v678/GHSA-99mv-pfx6-v678.json +++ b/advisories/unreviewed/2022/06/GHSA-99mv-pfx6-v678/GHSA-99mv-pfx6-v678.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-306", "CWE-400" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/06/GHSA-9p6h-67hg-3ph5/GHSA-9p6h-67hg-3ph5.json b/advisories/unreviewed/2022/06/GHSA-9p6h-67hg-3ph5/GHSA-9p6h-67hg-3ph5.json index bb1c2bea3c7..fcb9f6e9643 100644 --- a/advisories/unreviewed/2022/06/GHSA-9p6h-67hg-3ph5/GHSA-9p6h-67hg-3ph5.json +++ b/advisories/unreviewed/2022/06/GHSA-9p6h-67hg-3ph5/GHSA-9p6h-67hg-3ph5.json @@ -48,6 +48,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-126" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/06/GHSA-c8xc-gc49-4vf2/GHSA-c8xc-gc49-4vf2.json b/advisories/unreviewed/2022/06/GHSA-c8xc-gc49-4vf2/GHSA-c8xc-gc49-4vf2.json index 7e6a0f83534..5c2b4a84412 100644 --- a/advisories/unreviewed/2022/06/GHSA-c8xc-gc49-4vf2/GHSA-c8xc-gc49-4vf2.json +++ b/advisories/unreviewed/2022/06/GHSA-c8xc-gc49-4vf2/GHSA-c8xc-gc49-4vf2.json @@ -28,6 +28,8 @@ ], "database_specific": { "cwe_ids": [ + "CWE-287", + "CWE-804", "CWE-863" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/06/GHSA-cr6m-g8w4-422x/GHSA-cr6m-g8w4-422x.json b/advisories/unreviewed/2022/06/GHSA-cr6m-g8w4-422x/GHSA-cr6m-g8w4-422x.json index 10cc2a86ebc..c470abe84dc 100644 --- a/advisories/unreviewed/2022/06/GHSA-cr6m-g8w4-422x/GHSA-cr6m-g8w4-422x.json +++ b/advisories/unreviewed/2022/06/GHSA-cr6m-g8w4-422x/GHSA-cr6m-g8w4-422x.json @@ -28,7 +28,9 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-121", + "CWE-20", + "CWE-787" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/06/GHSA-f7h3-whmx-5pqj/GHSA-f7h3-whmx-5pqj.json b/advisories/unreviewed/2022/06/GHSA-f7h3-whmx-5pqj/GHSA-f7h3-whmx-5pqj.json index 0b3335604d5..cdb80564fe4 100644 --- a/advisories/unreviewed/2022/06/GHSA-f7h3-whmx-5pqj/GHSA-f7h3-whmx-5pqj.json +++ b/advisories/unreviewed/2022/06/GHSA-f7h3-whmx-5pqj/GHSA-f7h3-whmx-5pqj.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-269" + "CWE-269", + "CWE-59" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/06/GHSA-ffqc-r4j7-pvvm/GHSA-ffqc-r4j7-pvvm.json b/advisories/unreviewed/2022/06/GHSA-ffqc-r4j7-pvvm/GHSA-ffqc-r4j7-pvvm.json index c2c678ef660..87323c9b0a1 100644 --- a/advisories/unreviewed/2022/06/GHSA-ffqc-r4j7-pvvm/GHSA-ffqc-r4j7-pvvm.json +++ b/advisories/unreviewed/2022/06/GHSA-ffqc-r4j7-pvvm/GHSA-ffqc-r4j7-pvvm.json @@ -28,7 +28,9 @@ ], "database_specific": { "cwe_ids": [ - "CWE-269" + "CWE-266", + "CWE-269", + "CWE-863" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/06/GHSA-g5w2-92px-9hwf/GHSA-g5w2-92px-9hwf.json b/advisories/unreviewed/2022/06/GHSA-g5w2-92px-9hwf/GHSA-g5w2-92px-9hwf.json index 86ebc2176a3..f4177d59a67 100644 --- a/advisories/unreviewed/2022/06/GHSA-g5w2-92px-9hwf/GHSA-g5w2-92px-9hwf.json +++ b/advisories/unreviewed/2022/06/GHSA-g5w2-92px-9hwf/GHSA-g5w2-92px-9hwf.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-269" + "CWE-269", + "CWE-59" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/06/GHSA-gc9p-mgj9-4r5j/GHSA-gc9p-mgj9-4r5j.json b/advisories/unreviewed/2022/06/GHSA-gc9p-mgj9-4r5j/GHSA-gc9p-mgj9-4r5j.json index 6381b58a991..3c0d2025bc5 100644 --- a/advisories/unreviewed/2022/06/GHSA-gc9p-mgj9-4r5j/GHSA-gc9p-mgj9-4r5j.json +++ b/advisories/unreviewed/2022/06/GHSA-gc9p-mgj9-4r5j/GHSA-gc9p-mgj9-4r5j.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-732" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/06/GHSA-h7cv-65j5-5g78/GHSA-h7cv-65j5-5g78.json b/advisories/unreviewed/2022/06/GHSA-h7cv-65j5-5g78/GHSA-h7cv-65j5-5g78.json index 40d50c8478e..c77e4ddaad7 100644 --- a/advisories/unreviewed/2022/06/GHSA-h7cv-65j5-5g78/GHSA-h7cv-65j5-5g78.json +++ b/advisories/unreviewed/2022/06/GHSA-h7cv-65j5-5g78/GHSA-h7cv-65j5-5g78.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1244", "CWE-863" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/06/GHSA-m3m5-474m-99qj/GHSA-m3m5-474m-99qj.json b/advisories/unreviewed/2022/06/GHSA-m3m5-474m-99qj/GHSA-m3m5-474m-99qj.json index 8ee8f1fb88a..7c7f39267fe 100644 --- a/advisories/unreviewed/2022/06/GHSA-m3m5-474m-99qj/GHSA-m3m5-474m-99qj.json +++ b/advisories/unreviewed/2022/06/GHSA-m3m5-474m-99qj/GHSA-m3m5-474m-99qj.json @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-862", "CWE-863" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/06/GHSA-mgwv-57p9-8v74/GHSA-mgwv-57p9-8v74.json b/advisories/unreviewed/2022/06/GHSA-mgwv-57p9-8v74/GHSA-mgwv-57p9-8v74.json index dabe71b0b16..8a7984c05b3 100644 --- a/advisories/unreviewed/2022/06/GHSA-mgwv-57p9-8v74/GHSA-mgwv-57p9-8v74.json +++ b/advisories/unreviewed/2022/06/GHSA-mgwv-57p9-8v74/GHSA-mgwv-57p9-8v74.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-269" + "CWE-269", + "CWE-59" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/06/GHSA-qg67-mxc2-7gc6/GHSA-qg67-mxc2-7gc6.json b/advisories/unreviewed/2022/06/GHSA-qg67-mxc2-7gc6/GHSA-qg67-mxc2-7gc6.json index 4ac1bf7e2e7..d52fe8ea995 100644 --- a/advisories/unreviewed/2022/06/GHSA-qg67-mxc2-7gc6/GHSA-qg67-mxc2-7gc6.json +++ b/advisories/unreviewed/2022/06/GHSA-qg67-mxc2-7gc6/GHSA-qg67-mxc2-7gc6.json @@ -32,7 +32,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-212" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/06/GHSA-qrr2-wwrr-wp96/GHSA-qrr2-wwrr-wp96.json b/advisories/unreviewed/2022/06/GHSA-qrr2-wwrr-wp96/GHSA-qrr2-wwrr-wp96.json index 9e6add245a2..81a720028f6 100644 --- a/advisories/unreviewed/2022/06/GHSA-qrr2-wwrr-wp96/GHSA-qrr2-wwrr-wp96.json +++ b/advisories/unreviewed/2022/06/GHSA-qrr2-wwrr-wp96/GHSA-qrr2-wwrr-wp96.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-284", "CWE-863" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/06/GHSA-xfxv-hqvj-fpfc/GHSA-xfxv-hqvj-fpfc.json b/advisories/unreviewed/2022/06/GHSA-xfxv-hqvj-fpfc/GHSA-xfxv-hqvj-fpfc.json index 23a3f0538de..499848c6ac3 100644 --- a/advisories/unreviewed/2022/06/GHSA-xfxv-hqvj-fpfc/GHSA-xfxv-hqvj-fpfc.json +++ b/advisories/unreviewed/2022/06/GHSA-xfxv-hqvj-fpfc/GHSA-xfxv-hqvj-fpfc.json @@ -28,7 +28,9 @@ ], "database_specific": { "cwe_ids": [ - "CWE-287" + "CWE-256", + "CWE-287", + "CWE-522" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/07/GHSA-59rr-qhh3-g554/GHSA-59rr-qhh3-g554.json b/advisories/unreviewed/2022/07/GHSA-59rr-qhh3-g554/GHSA-59rr-qhh3-g554.json index b8c2bf169ab..31a4da5e8b7 100644 --- a/advisories/unreviewed/2022/07/GHSA-59rr-qhh3-g554/GHSA-59rr-qhh3-g554.json +++ b/advisories/unreviewed/2022/07/GHSA-59rr-qhh3-g554/GHSA-59rr-qhh3-g554.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-287" + "CWE-287", + "CWE-306" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/07/GHSA-fxfc-w6xq-5pp8/GHSA-fxfc-w6xq-5pp8.json b/advisories/unreviewed/2022/07/GHSA-fxfc-w6xq-5pp8/GHSA-fxfc-w6xq-5pp8.json index ff32c894332..2c172236001 100644 --- a/advisories/unreviewed/2022/07/GHSA-fxfc-w6xq-5pp8/GHSA-fxfc-w6xq-5pp8.json +++ b/advisories/unreviewed/2022/07/GHSA-fxfc-w6xq-5pp8/GHSA-fxfc-w6xq-5pp8.json @@ -40,7 +40,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-326" + "CWE-326", + "CWE-427" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/07/GHSA-j8g4-6p94-j4fp/GHSA-j8g4-6p94-j4fp.json b/advisories/unreviewed/2022/07/GHSA-j8g4-6p94-j4fp/GHSA-j8g4-6p94-j4fp.json index 13955d39aad..1925e30716b 100644 --- a/advisories/unreviewed/2022/07/GHSA-j8g4-6p94-j4fp/GHSA-j8g4-6p94-j4fp.json +++ b/advisories/unreviewed/2022/07/GHSA-j8g4-6p94-j4fp/GHSA-j8g4-6p94-j4fp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j8g4-6p94-j4fp", - "modified": "2022-07-26T00:01:04Z", + "modified": "2023-07-24T15:30:25Z", "published": "2022-07-19T00:00:25Z", "aliases": [ "CVE-2022-2108" @@ -32,6 +32,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-862", "CWE-863" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/07/GHSA-qwqq-2qch-x65x/GHSA-qwqq-2qch-x65x.json b/advisories/unreviewed/2022/07/GHSA-qwqq-2qch-x65x/GHSA-qwqq-2qch-x65x.json index fa430f6c411..4b67b1777b0 100644 --- a/advisories/unreviewed/2022/07/GHSA-qwqq-2qch-x65x/GHSA-qwqq-2qch-x65x.json +++ b/advisories/unreviewed/2022/07/GHSA-qwqq-2qch-x65x/GHSA-qwqq-2qch-x65x.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-425" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/07/GHSA-vjcc-9q9g-593v/GHSA-vjcc-9q9g-593v.json b/advisories/unreviewed/2022/07/GHSA-vjcc-9q9g-593v/GHSA-vjcc-9q9g-593v.json index 963f87a843b..f17301c7e48 100644 --- a/advisories/unreviewed/2022/07/GHSA-vjcc-9q9g-593v/GHSA-vjcc-9q9g-593v.json +++ b/advisories/unreviewed/2022/07/GHSA-vjcc-9q9g-593v/GHSA-vjcc-9q9g-593v.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-284", "CWE-863" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/07/GHSA-x6gc-63rj-4gw6/GHSA-x6gc-63rj-4gw6.json b/advisories/unreviewed/2022/07/GHSA-x6gc-63rj-4gw6/GHSA-x6gc-63rj-4gw6.json index 5bd7552e5ba..c42c580092b 100644 --- a/advisories/unreviewed/2022/07/GHSA-x6gc-63rj-4gw6/GHSA-x6gc-63rj-4gw6.json +++ b/advisories/unreviewed/2022/07/GHSA-x6gc-63rj-4gw6/GHSA-x6gc-63rj-4gw6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x6gc-63rj-4gw6", - "modified": "2022-07-20T00:00:18Z", + "modified": "2023-07-24T15:30:25Z", "published": "2022-07-13T00:01:56Z", "aliases": [ "CVE-2022-31257" @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-269" + "CWE-269", + "CWE-284" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/08/GHSA-8482-w39m-g3c5/GHSA-8482-w39m-g3c5.json b/advisories/unreviewed/2022/08/GHSA-8482-w39m-g3c5/GHSA-8482-w39m-g3c5.json index c0b4e21392e..80b1eecc7cc 100644 --- a/advisories/unreviewed/2022/08/GHSA-8482-w39m-g3c5/GHSA-8482-w39m-g3c5.json +++ b/advisories/unreviewed/2022/08/GHSA-8482-w39m-g3c5/GHSA-8482-w39m-g3c5.json @@ -28,6 +28,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-285", "CWE-863" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/08/GHSA-px5r-qw43-pqcc/GHSA-px5r-qw43-pqcc.json b/advisories/unreviewed/2022/08/GHSA-px5r-qw43-pqcc/GHSA-px5r-qw43-pqcc.json index 11d7458f2f8..2765facc4db 100644 --- a/advisories/unreviewed/2022/08/GHSA-px5r-qw43-pqcc/GHSA-px5r-qw43-pqcc.json +++ b/advisories/unreviewed/2022/08/GHSA-px5r-qw43-pqcc/GHSA-px5r-qw43-pqcc.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/08/GHSA-r8cv-8cqg-5fqv/GHSA-r8cv-8cqg-5fqv.json b/advisories/unreviewed/2022/08/GHSA-r8cv-8cqg-5fqv/GHSA-r8cv-8cqg-5fqv.json index a0c1a8a21d2..6b8c769f48c 100644 --- a/advisories/unreviewed/2022/08/GHSA-r8cv-8cqg-5fqv/GHSA-r8cv-8cqg-5fqv.json +++ b/advisories/unreviewed/2022/08/GHSA-r8cv-8cqg-5fqv/GHSA-r8cv-8cqg-5fqv.json @@ -28,7 +28,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-444" + "CWE-444", + "CWE-79" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/09/GHSA-75hr-42cm-p5wq/GHSA-75hr-42cm-p5wq.json b/advisories/unreviewed/2022/09/GHSA-75hr-42cm-p5wq/GHSA-75hr-42cm-p5wq.json index 4dacabf21cf..4692a0738af 100644 --- a/advisories/unreviewed/2022/09/GHSA-75hr-42cm-p5wq/GHSA-75hr-42cm-p5wq.json +++ b/advisories/unreviewed/2022/09/GHSA-75hr-42cm-p5wq/GHSA-75hr-42cm-p5wq.json @@ -33,6 +33,7 @@ "database_specific": { "cwe_ids": [ "CWE-287", + "CWE-319", "CWE-326" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/07/GHSA-3qhf-px5p-g68q/GHSA-3qhf-px5p-g68q.json b/advisories/unreviewed/2023/07/GHSA-3qhf-px5p-g68q/GHSA-3qhf-px5p-g68q.json new file mode 100644 index 00000000000..35482a0b68e --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-3qhf-px5p-g68q/GHSA-3qhf-px5p-g68q.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3qhf-px5p-g68q", + "modified": "2023-07-24T15:30:27Z", + "published": "2023-07-24T15:30:27Z", + "aliases": [ + "CVE-2022-30280" + ], + "details": "/SecurityManagement/html/createuser.jsf in Nokia NetAct 22 allows CSRF. A remote attacker is able to create users with arbitrary privileges, even administrative privileges. The application (even if it implements a CSRF token for the random GET request) does not ever verify a CSRF token. With a little help of social engineering/phishing (such as sending a link via email or chat), an attacker may trick the users of a web application into executing actions of the attacker's choosing. If the victim is a normal user, a successful CSRF attack can force the user to perform state changing requests like transferring funds, changing their email address, and so forth. If the victim is an administrative account, CSRF can compromise the entire web application.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-30280" + }, + { + "type": "WEB", + "url": "https://www.gruppotim.it/it/footer/red-team.html" + }, + { + "type": "WEB", + "url": "https://www.telecomitalia.com/tit/it/innovazione/cybersecurity/red-team.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-h49p-m77c-w5m9/GHSA-h49p-m77c-w5m9.json b/advisories/unreviewed/2023/07/GHSA-h49p-m77c-w5m9/GHSA-h49p-m77c-w5m9.json new file mode 100644 index 00000000000..2de906443f6 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-h49p-m77c-w5m9/GHSA-h49p-m77c-w5m9.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h49p-m77c-w5m9", + "modified": "2023-07-24T15:30:27Z", + "published": "2023-07-24T15:30:27Z", + "aliases": [ + "CVE-2022-28867" + ], + "details": "An issue was discovered in Nokia NetAct 22 through the Administration of Measurements website section. A malicious user can edit or add the templateName parameter in order to include JavaScript code, which is then stored and executed by a victim's web browser. The most common mechanism for delivering malicious content is to include it as a parameter in a URL that is posted publicly or e-mailed directly to victims. Here, the /aom/html/EditTemplate.jsf and /aom/html/ViewAllTemplatesPage.jsf templateName parameter is used.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-28867" + }, + { + "type": "WEB", + "url": "https://www.gruppotim.it/it/footer/red-team.html" + }, + { + "type": "WEB", + "url": "https://www.telecomitalia.com/tit/it/innovazione/cybersecurity/red-team.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-p4m9-r3rr-cx92/GHSA-p4m9-r3rr-cx92.json b/advisories/unreviewed/2023/07/GHSA-p4m9-r3rr-cx92/GHSA-p4m9-r3rr-cx92.json new file mode 100644 index 00000000000..ec96aec701d --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-p4m9-r3rr-cx92/GHSA-p4m9-r3rr-cx92.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p4m9-r3rr-cx92", + "modified": "2023-07-24T15:30:27Z", + "published": "2023-07-24T15:30:27Z", + "aliases": [ + "CVE-2023-3863" + ], + "details": "A use-after-free flaw was found in nfc_llcp_find_local in net/nfc/llcp_core.c in NFC in the Linux kernel. This flaw allows a local user with special privileges to impact a kernel information leak issue.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-3863" + }, + { + "type": "WEB", + "url": "https://github.com/torvalds/linux/commit/6709d4b7bc2e079241fdef15d1160581c5261c10" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2023-3863" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2225126" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-r6xc-9724-9r8g/GHSA-r6xc-9724-9r8g.json b/advisories/unreviewed/2023/07/GHSA-r6xc-9724-9r8g/GHSA-r6xc-9724-9r8g.json new file mode 100644 index 00000000000..bee6ac74d9d --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-r6xc-9724-9r8g/GHSA-r6xc-9724-9r8g.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r6xc-9724-9r8g", + "modified": "2023-07-24T15:30:27Z", + "published": "2023-07-24T15:30:27Z", + "aliases": [ + "CVE-2022-28864" + ], + "details": "An issue was discovered in Nokia NetAct 22 through the Administration of Measurements website section. A malicious user can edit or add the templateName parameter in order to include malicious code, which is then downloaded as a .csv or .xlsx file and executed on a victim machine. Here, the /aom/html/EditTemplate.jsf and /aom/html/ViewAllTemplatesPage.jsf templateName parameter is used.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-28864" + }, + { + "type": "WEB", + "url": "https://www.gruppotim.it/it/footer/red-team.html" + }, + { + "type": "WEB", + "url": "https://www.telecomitalia.com/tit/it/innovazione/cybersecurity/red-team.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-wrgm-rq8f-75r7/GHSA-wrgm-rq8f-75r7.json b/advisories/unreviewed/2023/07/GHSA-wrgm-rq8f-75r7/GHSA-wrgm-rq8f-75r7.json new file mode 100644 index 00000000000..02b1abf193b --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-wrgm-rq8f-75r7/GHSA-wrgm-rq8f-75r7.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wrgm-rq8f-75r7", + "modified": "2023-07-24T15:30:27Z", + "published": "2023-07-24T15:30:27Z", + "aliases": [ + "CVE-2022-28863" + ], + "details": "An issue was discovered in Nokia NetAct 22. A remote user, authenticated to the website, can visit the Site Configuration Tool section and arbitrarily upload potentially dangerous files without restrictions via the /netact/sct dir parameter in conjunction with the operation=upload value.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-28863" + }, + { + "type": "WEB", + "url": "https://www.gruppotim.it/it/footer/red-team.html" + }, + { + "type": "WEB", + "url": "https://www.telecomitalia.com/tit/it/innovazione/cybersecurity/red-team.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-xrrm-rgr6-3gfq/GHSA-xrrm-rgr6-3gfq.json b/advisories/unreviewed/2023/07/GHSA-xrrm-rgr6-3gfq/GHSA-xrrm-rgr6-3gfq.json new file mode 100644 index 00000000000..e6c11f300ed --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-xrrm-rgr6-3gfq/GHSA-xrrm-rgr6-3gfq.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xrrm-rgr6-3gfq", + "modified": "2023-07-24T15:30:27Z", + "published": "2023-07-24T15:30:27Z", + "aliases": [ + "CVE-2022-28865" + ], + "details": "An issue was discovered in Nokia NetAct 22 through the Site Configuration Tool website section. A malicious user can change a filename of an uploaded file to include JavaScript code, which is then stored and executed by a victim's web browser. The most common mechanism for delivering malicious content is to include it as a parameter in a URL that is posted publicly or e-mailed directly to victims. Here, the /netact/sct filename parameter is used.", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-28865" + }, + { + "type": "WEB", + "url": "https://www.gruppotim.it/it/footer/red-team.html" + }, + { + "type": "WEB", + "url": "https://www.telecomitalia.com/tit/it/innovazione/cybersecurity/red-team.html" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file