From 14255708c64a452a3089b0a62707b826afb1a4e7 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 9 Sep 2024 21:20:03 +0000 Subject: [PATCH] Publish GHSA-gfr2-qpxh-qj9m --- .../GHSA-gfr2-qpxh-qj9m.json | 98 ++++++++++++++++--- 1 file changed, 86 insertions(+), 12 deletions(-) diff --git a/advisories/github-reviewed/2021/04/GHSA-gfr2-qpxh-qj9m/GHSA-gfr2-qpxh-qj9m.json b/advisories/github-reviewed/2021/04/GHSA-gfr2-qpxh-qj9m/GHSA-gfr2-qpxh-qj9m.json index 284ac4a99d9..e5a79cd8910 100644 --- a/advisories/github-reviewed/2021/04/GHSA-gfr2-qpxh-qj9m/GHSA-gfr2-qpxh-qj9m.json +++ b/advisories/github-reviewed/2021/04/GHSA-gfr2-qpxh-qj9m/GHSA-gfr2-qpxh-qj9m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gfr2-qpxh-qj9m", - "modified": "2022-05-05T21:55:25Z", + "modified": "2024-09-09T21:18:37Z", "published": "2021-04-07T20:35:24Z", "aliases": [ "CVE-2020-1735" @@ -12,6 +12,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N" } ], "affected": [ @@ -25,10 +29,48 @@ "type": "ECOSYSTEM", "events": [ { - "introduced": "2.7.0" + "introduced": "2.7.0a1" }, { - "fixed": "2.9.7" + "fixed": "2.7.18" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "PyPI", + "name": "ansible" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.8.0a1" + }, + { + "fixed": "2.8.12" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "PyPI", + "name": "ansible" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.9.0a1" + }, + { + "fixed": "2.9.8" } ] } @@ -46,23 +88,31 @@ }, { "type": "WEB", - "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1735" - }, - { - "type": "PACKAGE", - "url": "https://github.com/ansible/ansible" + "url": "https://github.com/ansible/ansible/pull/69023" }, { "type": "WEB", - "url": "https://github.com/ansible/ansible/blob/stable-2.9/changelogs/CHANGELOG-v2.9.rst#security-fixes-7" + "url": "https://github.com/ansible/ansible/pull/69024" }, { "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DKPA4KC3OJSUFASUYMG66HKJE7ADNGFW" + "url": "https://github.com/ansible/ansible/pull/69025" }, { "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MRRYUU5ZBLPBXCYG6CFP35D64NP2UB2S" + "url": "https://github.com/ansible/ansible/commit/18f91bbb88a84b1d3614ef41c3550da735592ac1" + }, + { + "type": "WEB", + "url": "https://github.com/ansible/ansible/commit/40969ff43812fabf5397f818d9e521f9b39c9c9a" + }, + { + "type": "WEB", + "url": "https://github.com/ansible/ansible/commit/de9a4f5474c5f5db442ae7493d6b5da7177e335d" + }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202006-11" }, { "type": "WEB", @@ -70,7 +120,31 @@ }, { "type": "WEB", - "url": "https://security.gentoo.org/glsa/202006-11" + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MRRYUU5ZBLPBXCYG6CFP35D64NP2UB2S" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DKPA4KC3OJSUFASUYMG66HKJE7ADNGFW" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/ansible/PYSEC-2020-7.yaml" + }, + { + "type": "WEB", + "url": "https://github.com/ansible/ansible/blob/stable-2.9/changelogs/CHANGELOG-v2.9.rst#security-fixes-7" + }, + { + "type": "PACKAGE", + "url": "https://github.com/ansible/ansible" + }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-gfr2-qpxh-qj9m" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1735" } ], "database_specific": {