diff --git a/advisories/github-reviewed/2022/05/GHSA-7hwc-2cq4-6x2w/GHSA-7hwc-2cq4-6x2w.json b/advisories/github-reviewed/2022/05/GHSA-7hwc-2cq4-6x2w/GHSA-7hwc-2cq4-6x2w.json index da43ec9d321..c8602e8615d 100644 --- a/advisories/github-reviewed/2022/05/GHSA-7hwc-2cq4-6x2w/GHSA-7hwc-2cq4-6x2w.json +++ b/advisories/github-reviewed/2022/05/GHSA-7hwc-2cq4-6x2w/GHSA-7hwc-2cq4-6x2w.json @@ -109,6 +109,101 @@ ] } ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "symfony/security-bundle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.7.0" + }, + { + "fixed": "2.7.48" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "symfony/security-bundle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.8.0" + }, + { + "fixed": "2.8.41" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "symfony/security-bundle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.3.0" + }, + { + "fixed": "3.3.17" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "symfony/security-bundle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.4.0" + }, + { + "fixed": "3.4.11" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "symfony/security-bundle" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "4.0.0" + }, + { + "fixed": "4.0.11" + } + ] + } + ] } ], "references": [ @@ -120,6 +215,14 @@ "type": "WEB", "url": "https://github.com/symfony/symfony/commit/b20e83562e32c56f8d9b8296ab07b0e4c0a54db8" }, + { + "type": "WEB", + "url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/security-bundle/CVE-2018-11408.yaml" + }, + { + "type": "WEB", + "url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/symfony/CVE-2018-11408.yaml" + }, { "type": "PACKAGE", "url": "https://github.com/symfony/symfony" @@ -143,6 +246,10 @@ { "type": "WEB", "url": "https://symfony.com/blog/cve-2018-11408-open-redirect-vulnerability-on-security-handlers" + }, + { + "type": "WEB", + "url": "https://symfony.com/cve-2018-11408" } ], "database_specific": { diff --git a/advisories/github-reviewed/2022/05/GHSA-c49r-8gj6-768r/GHSA-c49r-8gj6-768r.json b/advisories/github-reviewed/2022/05/GHSA-c49r-8gj6-768r/GHSA-c49r-8gj6-768r.json index 38692d62418..db993605bcc 100644 --- a/advisories/github-reviewed/2022/05/GHSA-c49r-8gj6-768r/GHSA-c49r-8gj6-768r.json +++ b/advisories/github-reviewed/2022/05/GHSA-c49r-8gj6-768r/GHSA-c49r-8gj6-768r.json @@ -15,6 +15,82 @@ } ], "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "symfony/intl" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.7.0" + }, + { + "fixed": "2.7.38" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "symfony/intl" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.8.0" + }, + { + "fixed": "2.8.31" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "symfony/intl" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.0.0" + }, + { + "fixed": "3.2.14" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "symfony/intl" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.3.0" + }, + { + "fixed": "3.3.13" + } + ] + } + ] + }, { "package": { "ecosystem": "Packagist", @@ -32,10 +108,7 @@ } ] } - ], - "database_specific": { - "last_known_affected_version_range": "<= 2.7.37" - } + ] }, { "package": { @@ -54,10 +127,7 @@ } ] } - ], - "database_specific": { - "last_known_affected_version_range": "<= 2.8.30" - } + ] }, { "package": { @@ -69,17 +139,14 @@ "type": "ECOSYSTEM", "events": [ { - "introduced": "3.2.0" + "introduced": "3.0.0" }, { "fixed": "3.2.14" } ] } - ], - "database_specific": { - "last_known_affected_version_range": "<= 3.2.13" - } + ] }, { "package": { @@ -98,10 +165,7 @@ } ] } - ], - "database_specific": { - "last_known_affected_version_range": "<= 3.3.12" - } + ] } ], "references": [ @@ -113,6 +177,14 @@ "type": "WEB", "url": "https://github.com/symfony/symfony/pull/24994" }, + { + "type": "WEB", + "url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/intl/CVE-2017-16654.yaml" + }, + { + "type": "WEB", + "url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/symfony/CVE-2017-16654.yaml" + }, { "type": "PACKAGE", "url": "https://github.com/symfony/symfony" @@ -125,6 +197,10 @@ "type": "WEB", "url": "https://symfony.com/blog/cve-2017-16654-intl-bundle-readers-breaking-out-of-paths" }, + { + "type": "WEB", + "url": "https://symfony.com/cve-2017-16654" + }, { "type": "WEB", "url": "https://www.debian.org/security/2018/dsa-4262"