diff --git a/advisories/github-reviewed/2023/12/GHSA-hh8p-p8mp-gqhm/GHSA-hh8p-p8mp-gqhm.json b/advisories/github-reviewed/2023/12/GHSA-hh8p-p8mp-gqhm/GHSA-hh8p-p8mp-gqhm.json index a80f8357c1c..6fc05e2cd80 100644 --- a/advisories/github-reviewed/2023/12/GHSA-hh8p-p8mp-gqhm/GHSA-hh8p-p8mp-gqhm.json +++ b/advisories/github-reviewed/2023/12/GHSA-hh8p-p8mp-gqhm/GHSA-hh8p-p8mp-gqhm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hh8p-p8mp-gqhm", - "modified": "2023-12-20T20:32:39Z", + "modified": "2024-01-02T15:14:39Z", "published": "2023-12-20T06:30:25Z", "aliases": [ "CVE-2023-6975" @@ -11,7 +11,7 @@ "severity": [ { "type": "CVSS_V3", - "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" } ], "affected": [ diff --git a/advisories/github-reviewed/2023/12/GHSA-jj93-39pf-7mcf/GHSA-jj93-39pf-7mcf.json b/advisories/github-reviewed/2023/12/GHSA-jj93-39pf-7mcf/GHSA-jj93-39pf-7mcf.json index cb42b02a145..72fd784c6d7 100644 --- a/advisories/github-reviewed/2023/12/GHSA-jj93-39pf-7mcf/GHSA-jj93-39pf-7mcf.json +++ b/advisories/github-reviewed/2023/12/GHSA-jj93-39pf-7mcf/GHSA-jj93-39pf-7mcf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jj93-39pf-7mcf", - "modified": "2023-12-21T18:13:09Z", + "modified": "2024-01-02T15:15:18Z", "published": "2023-12-21T12:30:28Z", "aliases": [ "CVE-2023-50475" @@ -9,7 +9,10 @@ "summary": "bsock uses weak hashing algorithms", "details": "An issue was discovered in the bsock component of bcoin-org bcoin that allows remote attackers to obtain sensitive information via weak hashing algorithms in the component `\\vendor\\faye-websocket.js`.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } ], "affected": [ { @@ -60,9 +63,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-327" ], - "severity": "MODERATE", + "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2023-12-21T18:13:09Z", "nvd_published_at": "2023-12-21T11:15:08Z"