From 1a3a7d8d748114d3c7483973f4616e4ac4131463 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 21 May 2024 18:19:59 +0000 Subject: [PATCH] Publish Advisories GHSA-7g3v-4ggr-xvjf GHSA-hp56-xvf4-g6wr --- .../GHSA-7g3v-4ggr-xvjf/GHSA-7g3v-4ggr-xvjf.json | 14 +++++++++++--- .../GHSA-hp56-xvf4-g6wr/GHSA-hp56-xvf4-g6wr.json | 14 +++++++++++--- 2 files changed, 22 insertions(+), 6 deletions(-) diff --git a/advisories/github-reviewed/2023/09/GHSA-7g3v-4ggr-xvjf/GHSA-7g3v-4ggr-xvjf.json b/advisories/github-reviewed/2023/09/GHSA-7g3v-4ggr-xvjf/GHSA-7g3v-4ggr-xvjf.json index 14145420d46..1a9f0c39f7a 100644 --- a/advisories/github-reviewed/2023/09/GHSA-7g3v-4ggr-xvjf/GHSA-7g3v-4ggr-xvjf.json +++ b/advisories/github-reviewed/2023/09/GHSA-7g3v-4ggr-xvjf/GHSA-7g3v-4ggr-xvjf.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-7g3v-4ggr-xvjf", - "modified": "2023-09-22T19:42:20Z", + "modified": "2024-05-21T18:18:33Z", "published": "2023-09-20T06:30:50Z", "aliases": [ "CVE-2023-43621" ], "summary": "Croc may expose secret to local users", - "details": "An issue was discovered in Croc through 9.6.5. The shared secret, located on a command line, can be read by local users who list all processes and their arguments.", + "details": "An issue was discovered in Croc before 9.6.16. The shared secret, located on a command line, can be read by local users who list all processes and their arguments.", "severity": [ { "type": "CVSS_V3", @@ -28,7 +28,7 @@ "introduced": "0" }, { - "last_affected": "9.6.5" + "fixed": "9.6.16" } ] } @@ -44,6 +44,14 @@ "type": "WEB", "url": "https://github.com/schollz/croc/issues/598" }, + { + "type": "WEB", + "url": "https://github.com/schollz/croc/pull/701" + }, + { + "type": "WEB", + "url": "https://github.com/schollz/croc/commit/863dabb93a271f41b3431c4384357e1856a69533" + }, { "type": "PACKAGE", "url": "https://github.com/schollz/croc" diff --git a/advisories/github-reviewed/2023/09/GHSA-hp56-xvf4-g6wr/GHSA-hp56-xvf4-g6wr.json b/advisories/github-reviewed/2023/09/GHSA-hp56-xvf4-g6wr/GHSA-hp56-xvf4-g6wr.json index 7dd956ef2cc..b1032651c7e 100644 --- a/advisories/github-reviewed/2023/09/GHSA-hp56-xvf4-g6wr/GHSA-hp56-xvf4-g6wr.json +++ b/advisories/github-reviewed/2023/09/GHSA-hp56-xvf4-g6wr/GHSA-hp56-xvf4-g6wr.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-hp56-xvf4-g6wr", - "modified": "2023-09-22T19:25:11Z", + "modified": "2024-05-21T18:19:30Z", "published": "2023-09-20T06:30:50Z", "aliases": [ "CVE-2023-43617" ], "summary": "Cros secrets may be disclosed to untrusted relay", - "details": "An issue was discovered in Croc through 9.6.5. When a custom shared secret is used, the sender and receiver may divulge parts of this secret to an untrusted Relay, as part of composing a room name.", + "details": "An issue was discovered in Croc before 9.6.16. When a custom shared secret is used, the sender and receiver may divulge parts of this secret to an untrusted Relay, as part of composing a room name.", "severity": [ { "type": "CVSS_V3", @@ -28,7 +28,7 @@ "introduced": "0" }, { - "last_affected": "9.6.5" + "fixed": "9.6.16" } ] } @@ -44,6 +44,14 @@ "type": "WEB", "url": "https://github.com/schollz/croc/issues/596" }, + { + "type": "WEB", + "url": "https://github.com/schollz/croc/pull/699" + }, + { + "type": "WEB", + "url": "https://github.com/schollz/croc/commit/0f1ca436cd8e608738da0b23bf594537cfbe6213" + }, { "type": "PACKAGE", "url": "https://github.com/schollz/croc"