diff --git a/advisories/github-reviewed/2023/04/GHSA-2hw6-4rv9-82fp/GHSA-2hw6-4rv9-82fp.json b/advisories/github-reviewed/2023/04/GHSA-2hw6-4rv9-82fp/GHSA-2hw6-4rv9-82fp.json index b6eb5b9379a..cfded2f957a 100644 --- a/advisories/github-reviewed/2023/04/GHSA-2hw6-4rv9-82fp/GHSA-2hw6-4rv9-82fp.json +++ b/advisories/github-reviewed/2023/04/GHSA-2hw6-4rv9-82fp/GHSA-2hw6-4rv9-82fp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2hw6-4rv9-82fp", - "modified": "2023-04-11T21:58:45Z", + "modified": "2025-02-13T18:50:46Z", "published": "2023-04-05T00:30:39Z", "aliases": [ "CVE-2023-0265" diff --git a/advisories/github-reviewed/2023/04/GHSA-fwhv-9phj-wrj5/GHSA-fwhv-9phj-wrj5.json b/advisories/github-reviewed/2023/04/GHSA-fwhv-9phj-wrj5/GHSA-fwhv-9phj-wrj5.json index f43cc7873f5..a4adf021ea4 100644 --- a/advisories/github-reviewed/2023/04/GHSA-fwhv-9phj-wrj5/GHSA-fwhv-9phj-wrj5.json +++ b/advisories/github-reviewed/2023/04/GHSA-fwhv-9phj-wrj5/GHSA-fwhv-9phj-wrj5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fwhv-9phj-wrj5", - "modified": "2023-04-11T21:58:17Z", + "modified": "2025-02-13T18:50:43Z", "published": "2023-04-05T00:30:39Z", "aliases": [ "CVE-2023-0325" diff --git a/advisories/github-reviewed/2024/06/GHSA-hcr7-cqwc-q5gq/GHSA-hcr7-cqwc-q5gq.json b/advisories/github-reviewed/2024/06/GHSA-hcr7-cqwc-q5gq/GHSA-hcr7-cqwc-q5gq.json index 03dc8cfb1bb..4e821c12b20 100644 --- a/advisories/github-reviewed/2024/06/GHSA-hcr7-cqwc-q5gq/GHSA-hcr7-cqwc-q5gq.json +++ b/advisories/github-reviewed/2024/06/GHSA-hcr7-cqwc-q5gq/GHSA-hcr7-cqwc-q5gq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hcr7-cqwc-q5gq", - "modified": "2025-02-11T19:01:37Z", + "modified": "2025-02-13T18:50:04Z", "published": "2024-06-20T09:30:59Z", "aliases": [ "CVE-2024-34693" diff --git a/advisories/github-reviewed/2024/06/GHSA-v74c-qc46-9gg9/GHSA-v74c-qc46-9gg9.json b/advisories/github-reviewed/2024/06/GHSA-v74c-qc46-9gg9/GHSA-v74c-qc46-9gg9.json index 7b87814541c..846af51780d 100644 --- a/advisories/github-reviewed/2024/06/GHSA-v74c-qc46-9gg9/GHSA-v74c-qc46-9gg9.json +++ b/advisories/github-reviewed/2024/06/GHSA-v74c-qc46-9gg9/GHSA-v74c-qc46-9gg9.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-v74c-qc46-9gg9", - "modified": "2024-06-12T19:44:49Z", + "modified": "2025-02-13T18:50:15Z", "published": "2024-06-12T15:31:45Z", "aliases": [ "CVE-2024-36263" ], "summary": "Apache Submarine Server Core has a SQL Injection Vulnerability", - "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Submarine Server Core.\n\nThis issue affects Apache Submarine Server Core: all versions.\n\nAs this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users.\n\nNOTE: This vulnerability only affects products that are no longer supported by the maintainer.\n\n", + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Submarine Server Core.\n\nThis issue affects Apache Submarine Server Core: all versions.\n\nAs this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users.\n\nNOTE: This vulnerability only affects products that are no longer supported by the maintainer.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2024/06/GHSA-v9qv-c7wm-wgmf/GHSA-v9qv-c7wm-wgmf.json b/advisories/github-reviewed/2024/06/GHSA-v9qv-c7wm-wgmf/GHSA-v9qv-c7wm-wgmf.json index f99265ef0ce..729684062e0 100644 --- a/advisories/github-reviewed/2024/06/GHSA-v9qv-c7wm-wgmf/GHSA-v9qv-c7wm-wgmf.json +++ b/advisories/github-reviewed/2024/06/GHSA-v9qv-c7wm-wgmf/GHSA-v9qv-c7wm-wgmf.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-v9qv-c7wm-wgmf", - "modified": "2024-06-20T09:30:58Z", + "modified": "2025-02-13T18:50:48Z", "published": "2024-06-10T21:36:25Z", "aliases": [ "CVE-2024-35242" ], "summary": "Composer has multiple command injections via malicious git/hg branch names", - "details": "### Impact\n\nThe `composer install` command running inside a git/hg repository which has specially crafted branch names can lead to command injection. So this requires cloning untrusted repositories.\n\n### Patches\n\n2.2.24 for 2.2 LTS or 2.7.7 for mainline\n\n### Workarounds\n\nAvoid cloning potentially compromised repositories.\n", + "details": "### Impact\n\nThe `composer install` command running inside a git/hg repository which has specially crafted branch names can lead to command injection. So this requires cloning untrusted repositories.\n\n### Patches\n\n2.2.24 for 2.2 LTS or 2.7.7 for mainline\n\n### Workarounds\n\nAvoid cloning potentially compromised repositories.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2024/07/GHSA-hcf8-5j78-887v/GHSA-hcf8-5j78-887v.json b/advisories/github-reviewed/2024/07/GHSA-hcf8-5j78-887v/GHSA-hcf8-5j78-887v.json index a713e3f8bbd..29d0044db24 100644 --- a/advisories/github-reviewed/2024/07/GHSA-hcf8-5j78-887v/GHSA-hcf8-5j78-887v.json +++ b/advisories/github-reviewed/2024/07/GHSA-hcf8-5j78-887v/GHSA-hcf8-5j78-887v.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-hcf8-5j78-887v", - "modified": "2024-11-14T22:46:02Z", + "modified": "2025-02-13T18:49:53Z", "published": "2024-07-17T15:30:52Z", "aliases": [ "CVE-2024-29120" ], "summary": "Apache StreamPark: Information leakage vulnerability", - "details": "In Streampark (version < 2.1.4), when a user logged in successfully, the Backend service would return \"Authorization\" as the front-end authentication credential. User can use this credential to request other users' information, including the administrator's username, password, salt value, etc. \n\nMitigation:\n\nall users should upgrade to 2.1.4\n\n", + "details": "In Streampark (version < 2.1.4), when a user logged in successfully, the Backend service would return \"Authorization\" as the front-end authentication credential. User can use this credential to request other users' information, including the administrator's username, password, salt value, etc. \n\nMitigation:\n\nall users should upgrade to 2.1.4", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2024/07/GHSA-xhqw-4hcq-fcvr/GHSA-xhqw-4hcq-fcvr.json b/advisories/github-reviewed/2024/07/GHSA-xhqw-4hcq-fcvr/GHSA-xhqw-4hcq-fcvr.json index d8831d85edb..27da4b0c281 100644 --- a/advisories/github-reviewed/2024/07/GHSA-xhqw-4hcq-fcvr/GHSA-xhqw-4hcq-fcvr.json +++ b/advisories/github-reviewed/2024/07/GHSA-xhqw-4hcq-fcvr/GHSA-xhqw-4hcq-fcvr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xhqw-4hcq-fcvr", - "modified": "2024-08-19T21:49:26Z", + "modified": "2025-02-13T18:49:45Z", "published": "2024-07-31T09:30:49Z", "aliases": [ "CVE-2024-7300"