From 06d7eb4dadca05d997adcf15b87bd7bc5b98ebc5 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 27 Oct 2023 21:03:32 +0000 Subject: [PATCH] Publish Advisories GHSA-cfh5-3ghh-wfjx GHSA-wqq4-5wpv-mx2g --- .../GHSA-cfh5-3ghh-wfjx.json | 38 ++----------------- .../GHSA-wqq4-5wpv-mx2g.json | 16 +++++++- 2 files changed, 17 insertions(+), 37 deletions(-) rename advisories/{unreviewed => github-reviewed}/2018/10/GHSA-cfh5-3ghh-wfjx/GHSA-cfh5-3ghh-wfjx.json (86%) rename advisories/{unreviewed => github-reviewed}/2023/10/GHSA-wqq4-5wpv-mx2g/GHSA-wqq4-5wpv-mx2g.json (81%) diff --git a/advisories/unreviewed/2018/10/GHSA-cfh5-3ghh-wfjx/GHSA-cfh5-3ghh-wfjx.json b/advisories/github-reviewed/2018/10/GHSA-cfh5-3ghh-wfjx/GHSA-cfh5-3ghh-wfjx.json similarity index 86% rename from advisories/unreviewed/2018/10/GHSA-cfh5-3ghh-wfjx/GHSA-cfh5-3ghh-wfjx.json rename to advisories/github-reviewed/2018/10/GHSA-cfh5-3ghh-wfjx/GHSA-cfh5-3ghh-wfjx.json index 493cd20afdf..00f6e84aac6 100644 --- a/advisories/unreviewed/2018/10/GHSA-cfh5-3ghh-wfjx/GHSA-cfh5-3ghh-wfjx.json +++ b/advisories/github-reviewed/2018/10/GHSA-cfh5-3ghh-wfjx/GHSA-cfh5-3ghh-wfjx.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-cfh5-3ghh-wfjx", - "modified": "2023-10-27T15:30:16Z", + "modified": "2023-10-27T21:02:46Z", "published": "2018-10-17T00:05:06Z", "aliases": [ "CVE-2014-3577" ], - "summary": "Moderate severity vulnerability that affects org.apache.httpcomponents:httpclient", + "summary": "Improper Verification of Cryptographic Signature in org.apache.httpcomponents:httpclient", "details": "org.apache.http.conn.ssl.AbstractVerifier in Apache HttpComponents HttpClient before 4.3.5 and HttpAsyncClient before 4.0.2 does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a \"CN=\" string in a field in the distinguished name (DN) of a certificate, as demonstrated by the \"foo,CN=www.apache.org\" string in the O field.", "severity": [ @@ -49,14 +49,6 @@ "type": "ADVISORY", "url": "https://github.com/advisories/GHSA-cfh5-3ghh-wfjx" }, - { - "type": "WEB", - "url": "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05103564" - }, - { - "type": "WEB", - "url": "https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05363782" - }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E" @@ -193,18 +185,6 @@ "type": "WEB", "url": "http://seclists.org/fulldisclosure/2014/Aug/48" }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/60466" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/60589" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/60713" - }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2021/10/06/1" @@ -213,18 +193,6 @@ "type": "WEB", "url": "http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html" }, - { - "type": "WEB", - "url": "http://www.osvdb.org/110143" - }, - { - "type": "WEB", - "url": "http://www.securityfocus.com/bid/69258" - }, - { - "type": "WEB", - "url": "http://www.securitytracker.com/id/1030812" - }, { "type": "WEB", "url": "http://www.ubuntu.com/usn/USN-2769-1" @@ -235,7 +203,7 @@ "CWE-347" ], "severity": "MODERATE", - "github_reviewed": false, + "github_reviewed": true, "github_reviewed_at": "2020-06-16T21:31:17Z", "nvd_published_at": "2014-08-21T14:55:00Z" } diff --git a/advisories/unreviewed/2023/10/GHSA-wqq4-5wpv-mx2g/GHSA-wqq4-5wpv-mx2g.json b/advisories/github-reviewed/2023/10/GHSA-wqq4-5wpv-mx2g/GHSA-wqq4-5wpv-mx2g.json similarity index 81% rename from advisories/unreviewed/2023/10/GHSA-wqq4-5wpv-mx2g/GHSA-wqq4-5wpv-mx2g.json rename to advisories/github-reviewed/2023/10/GHSA-wqq4-5wpv-mx2g/GHSA-wqq4-5wpv-mx2g.json index 02abd6b55a9..a000a3e5ec8 100644 --- a/advisories/unreviewed/2023/10/GHSA-wqq4-5wpv-mx2g/GHSA-wqq4-5wpv-mx2g.json +++ b/advisories/github-reviewed/2023/10/GHSA-wqq4-5wpv-mx2g/GHSA-wqq4-5wpv-mx2g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wqq4-5wpv-mx2g", - "modified": "2023-10-25T18:32:19Z", + "modified": "2023-10-27T21:01:50Z", "published": "2023-10-16T14:05:37Z", "aliases": [ "CVE-2023-45143" @@ -67,6 +67,18 @@ { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/E72T67UPDRXHIDLO3OROR25YAMN4GGW5/" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FNA62Q767CFAFHBCDKYNPBMZWB7TWYVU/" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LKYHSZQFDNR7RSA7LHVLLIAQMVYCUGBG/" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X6QXN4ORIVF6XBW4WWFE7VNPVC74S45Y/" } ], "database_specific": { @@ -74,7 +86,7 @@ "CWE-200" ], "severity": "LOW", - "github_reviewed": false, + "github_reviewed": true, "github_reviewed_at": "2023-10-16T14:05:37Z", "nvd_published_at": null }