From 1c629fe2f3f67ee167cbe09ee60db6644394670e Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 27 Jul 2022 21:14:34 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-5q8m-mqmx-pxp9.json | 4 ++ .../GHSA-96jq-75wh-2658.json | 4 ++ .../GHSA-m929-7fr6-cvjg.json | 4 ++ .../GHSA-x84v-xcm2-53pg.json | 4 ++ .../GHSA-7x9j-7223-rg5m.json | 4 ++ .../GHSA-h9gj-rqrw-x4fq.json | 4 ++ .../GHSA-7pm4-g2qj-j85x.json | 4 ++ .../GHSA-8wx2-9q48-vm9r.json | 4 ++ .../GHSA-7553-jr98-vx47.json | 4 ++ .../GHSA-jxfh-8wgv-vfr2.json | 4 ++ .../GHSA-gxr4-xjj5-5px2.json | 4 ++ .../GHSA-jpcq-cgw6-v4j6.json | 4 ++ .../GHSA-344f-f5vg-2jfj.json | 4 ++ .../GHSA-q4m3-2j7h-f7xw.json | 4 ++ .../GHSA-6phf-73q6-gh87.json | 4 ++ .../GHSA-hwj3-m3p6-hj38.json | 4 ++ .../GHSA-c6pw-q7f2-97hv.json | 4 ++ .../GHSA-rcjj-h6gh-jf3r.json | 4 ++ .../GHSA-rhm9-p9w5-fwm7.json | 4 ++ .../GHSA-8q59-q68h-6hv4.json | 4 ++ .../GHSA-gwrp-pvrq-jmwv.json | 4 ++ .../GHSA-3c6g-pvg8-gqw2.json | 4 ++ .../GHSA-7chv-rrw6-w6fc.json | 4 ++ .../GHSA-7grw-6pjh-jpc9.json | 4 ++ .../GHSA-fg3j-q579-v8x4.json | 4 ++ .../GHSA-mw3r-pfmg-xp92.json | 4 ++ .../GHSA-wqvq-5m8c-6g24.json | 4 ++ .../GHSA-2363-cqg2-863c.json | 4 ++ .../GHSA-w9jg-gvgr-354m.json | 4 ++ .../GHSA-2q8x-2p7f-574v.json | 4 ++ .../GHSA-64xx-cq4q-mf44.json | 4 ++ .../GHSA-6w62-hx7r-mw68.json | 4 ++ .../GHSA-6wf9-jmg9-vxcc.json | 4 ++ .../GHSA-83mx-573x-5rw9.json | 4 ++ .../GHSA-8hfj-xrj2-pm22.json | 4 ++ .../GHSA-9279-7hph-r3xw.json | 4 ++ .../GHSA-hph2-m3g5-xxv4.json | 4 ++ .../GHSA-p8pq-r894-fm8f.json | 4 ++ .../GHSA-xw4p-crpj-vjx2.json | 4 ++ .../GHSA-f6jp-j6w3-w9hm.json | 4 ++ .../GHSA-9gj3-hwp5-pmwc.json | 4 ++ .../GHSA-gpqq-952q-5327.json | 4 ++ .../GHSA-j7qv-pgf6-hvh4.json | 4 ++ .../GHSA-wph7-x527-w3h5.json | 4 ++ .../GHSA-7h26-63m7-qhf2.json | 4 ++ .../GHSA-pvmx-g8h5-cprj.json | 4 ++ .../GHSA-v585-23hc-c647.json | 4 ++ .../GHSA-55x5-fj6c-h6m8.json | 4 ++ .../GHSA-9m6f-7xcq-8vf8.json | 4 ++ .../GHSA-cvm9-fjm9-3572.json | 4 ++ .../GHSA-f9xh-2qgp-cq57.json | 4 ++ .../GHSA-fp5r-v3w9-4333.json | 4 ++ .../GHSA-jfh8-c2jp-5v3q.json | 8 +++ .../GHSA-r695-7vr9-jgc2.json | 4 ++ .../GHSA-vfqx-33qm-g869.json | 4 ++ .../GHSA-wh8g-3j2c-rqj5.json | 4 ++ .../GHSA-wx5j-54mm-rqqq.json | 4 ++ .../GHSA-xr38-w74q-r8jv.json | 3 +- .../GHSA-2h63-qp69-fwvw.json | 4 ++ .../GHSA-65fg-84f6-3jq3.json | 4 ++ .../GHSA-h65f-jvqw-m9fj.json | 4 ++ .../GHSA-m8gw-hjpr-rjv7.json | 4 ++ .../GHSA-w9p3-5cr8-m3jj.json | 4 ++ .../GHSA-2qp4-g3q3-f92w.json | 8 +++ .../GHSA-5545-2q6w-2gh6.json | 4 ++ .../GHSA-9f3j-pm6f-9fm5.json | 4 ++ .../GHSA-hrhx-6h34-j5hc.json | 4 ++ .../GHSA-rmr5-cpv2-vgjf.json | 4 ++ .../GHSA-36p3-wjmg-h94x.json | 4 ++ .../GHSA-4fc4-4p5g-6w89.json | 4 ++ .../GHSA-jvfv-hrrc-6q72.json | 4 ++ .../GHSA-8m5h-hrqm-pxm2.json | 4 ++ .../GHSA-c2jg-hw38-jrqq.json | 4 ++ .../GHSA-g5mm-vmx4-3rg7.json | 4 ++ .../GHSA-q77q-vx4q-xx6q.json | 4 ++ .../GHSA-v8j6-6c2r-r27c.json | 6 +- .../GHSA-vp37-2f9p-3vr3.json | 4 ++ .../GHSA-269q-hmxg-m83q.json | 4 ++ .../GHSA-gfwj-fwqj-fp3v.json | 4 ++ .../GHSA-h3ch-5pp2-vh6w.json | 4 ++ .../GHSA-h66p-m766-33fv.json | 59 ++++++++++++++++ .../GHSA-hh26-6xwr-ggv7.json | 4 ++ .../GHSA-hh32-7344-cg2f.json | 4 ++ .../GHSA-rqph-vqwm-22vc.json | 4 ++ .../GHSA-rv87-vcv4-fjvr.json | 70 +++++++++++++++++++ .../GHSA-wx54-3278-m5g4.json | 4 ++ .../GHSA-x3pr-fcgm-wjgc.json | 63 +++++++++++++++++ .../GHSA-jjc5-fp7p-6f8w.json | 4 +- .../GHSA-h66p-m766-33fv.json | 36 ---------- .../GHSA-rv87-vcv4-fjvr.json | 36 ---------- .../GHSA-x3pr-fcgm-wjgc.json | 37 ---------- 91 files changed, 537 insertions(+), 113 deletions(-) create mode 100644 advisories/github-reviewed/2022/05/GHSA-h66p-m766-33fv/GHSA-h66p-m766-33fv.json create mode 100644 advisories/github-reviewed/2022/05/GHSA-rv87-vcv4-fjvr/GHSA-rv87-vcv4-fjvr.json create mode 100644 advisories/github-reviewed/2022/05/GHSA-x3pr-fcgm-wjgc/GHSA-x3pr-fcgm-wjgc.json delete mode 100644 advisories/unreviewed/2022/05/GHSA-h66p-m766-33fv/GHSA-h66p-m766-33fv.json delete mode 100644 advisories/unreviewed/2022/05/GHSA-rv87-vcv4-fjvr/GHSA-rv87-vcv4-fjvr.json delete mode 100644 advisories/unreviewed/2022/05/GHSA-x3pr-fcgm-wjgc/GHSA-x3pr-fcgm-wjgc.json diff --git a/advisories/github-reviewed/2018/10/GHSA-5q8m-mqmx-pxp9/GHSA-5q8m-mqmx-pxp9.json b/advisories/github-reviewed/2018/10/GHSA-5q8m-mqmx-pxp9/GHSA-5q8m-mqmx-pxp9.json index c4aa048f65e..408962e1bc4 100644 --- a/advisories/github-reviewed/2018/10/GHSA-5q8m-mqmx-pxp9/GHSA-5q8m-mqmx-pxp9.json +++ b/advisories/github-reviewed/2018/10/GHSA-5q8m-mqmx-pxp9/GHSA-5q8m-mqmx-pxp9.json @@ -67,6 +67,10 @@ "type": "WEB", "url": "https://pivotal.io/security/cve-2018-1274" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "WEB", "url": "http://www.securityfocus.com/bid/103769" diff --git a/advisories/github-reviewed/2018/10/GHSA-96jq-75wh-2658/GHSA-96jq-75wh-2658.json b/advisories/github-reviewed/2018/10/GHSA-96jq-75wh-2658/GHSA-96jq-75wh-2658.json index 0ec9c3cc91e..7377b610702 100644 --- a/advisories/github-reviewed/2018/10/GHSA-96jq-75wh-2658/GHSA-96jq-75wh-2658.json +++ b/advisories/github-reviewed/2018/10/GHSA-96jq-75wh-2658/GHSA-96jq-75wh-2658.json @@ -103,6 +103,10 @@ "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpujul2020.html" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuoct2021.html" diff --git a/advisories/github-reviewed/2018/10/GHSA-m929-7fr6-cvjg/GHSA-m929-7fr6-cvjg.json b/advisories/github-reviewed/2018/10/GHSA-m929-7fr6-cvjg/GHSA-m929-7fr6-cvjg.json index 1d81c84ac47..ff08846bd4a 100644 --- a/advisories/github-reviewed/2018/10/GHSA-m929-7fr6-cvjg/GHSA-m929-7fr6-cvjg.json +++ b/advisories/github-reviewed/2018/10/GHSA-m929-7fr6-cvjg/GHSA-m929-7fr6-cvjg.json @@ -74,6 +74,10 @@ { "type": "WEB", "url": "https://pivotal.io/security/cve-2018-1259" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" } ], "database_specific": { diff --git a/advisories/github-reviewed/2018/10/GHSA-x84v-xcm2-53pg/GHSA-x84v-xcm2-53pg.json b/advisories/github-reviewed/2018/10/GHSA-x84v-xcm2-53pg/GHSA-x84v-xcm2-53pg.json index 61ae4405002..2506e4dfff4 100644 --- a/advisories/github-reviewed/2018/10/GHSA-x84v-xcm2-53pg/GHSA-x84v-xcm2-53pg.json +++ b/advisories/github-reviewed/2018/10/GHSA-x84v-xcm2-53pg/GHSA-x84v-xcm2-53pg.json @@ -75,6 +75,10 @@ "type": "WEB", "url": "https://usn.ubuntu.com/3790-2/" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "WEB", "url": "http://docs.python-requests.org/en/master/community/updates/#release-and-version-history" diff --git a/advisories/github-reviewed/2018/12/GHSA-7x9j-7223-rg5m/GHSA-7x9j-7223-rg5m.json b/advisories/github-reviewed/2018/12/GHSA-7x9j-7223-rg5m/GHSA-7x9j-7223-rg5m.json index 04871b317d5..aafad02331e 100644 --- a/advisories/github-reviewed/2018/12/GHSA-7x9j-7223-rg5m/GHSA-7x9j-7223-rg5m.json +++ b/advisories/github-reviewed/2018/12/GHSA-7x9j-7223-rg5m/GHSA-7x9j-7223-rg5m.json @@ -80,6 +80,10 @@ "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpujul2020.html" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuoct2020.html" diff --git a/advisories/github-reviewed/2019/05/GHSA-h9gj-rqrw-x4fq/GHSA-h9gj-rqrw-x4fq.json b/advisories/github-reviewed/2019/05/GHSA-h9gj-rqrw-x4fq/GHSA-h9gj-rqrw-x4fq.json index 768c522e320..5b0740893c4 100644 --- a/advisories/github-reviewed/2019/05/GHSA-h9gj-rqrw-x4fq/GHSA-h9gj-rqrw-x4fq.json +++ b/advisories/github-reviewed/2019/05/GHSA-h9gj-rqrw-x4fq/GHSA-h9gj-rqrw-x4fq.json @@ -76,6 +76,10 @@ "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpujul2020.html" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuoct2021.html" diff --git a/advisories/github-reviewed/2020/01/GHSA-7pm4-g2qj-j85x/GHSA-7pm4-g2qj-j85x.json b/advisories/github-reviewed/2020/01/GHSA-7pm4-g2qj-j85x/GHSA-7pm4-g2qj-j85x.json index fce113a5b21..e4f79a2121c 100644 --- a/advisories/github-reviewed/2020/01/GHSA-7pm4-g2qj-j85x/GHSA-7pm4-g2qj-j85x.json +++ b/advisories/github-reviewed/2020/01/GHSA-7pm4-g2qj-j85x/GHSA-7pm4-g2qj-j85x.json @@ -79,6 +79,10 @@ "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpujul2020.html" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuoct2020.html" diff --git a/advisories/github-reviewed/2020/01/GHSA-8wx2-9q48-vm9r/GHSA-8wx2-9q48-vm9r.json b/advisories/github-reviewed/2020/01/GHSA-8wx2-9q48-vm9r/GHSA-8wx2-9q48-vm9r.json index d71137e0137..0ade8a25f55 100644 --- a/advisories/github-reviewed/2020/01/GHSA-8wx2-9q48-vm9r/GHSA-8wx2-9q48-vm9r.json +++ b/advisories/github-reviewed/2020/01/GHSA-8wx2-9q48-vm9r/GHSA-8wx2-9q48-vm9r.json @@ -299,6 +299,10 @@ "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpujul2020.html" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuoct2020.html" diff --git a/advisories/github-reviewed/2020/02/GHSA-7553-jr98-vx47/GHSA-7553-jr98-vx47.json b/advisories/github-reviewed/2020/02/GHSA-7553-jr98-vx47/GHSA-7553-jr98-vx47.json index 2b75510d7c5..6fd82788ed4 100644 --- a/advisories/github-reviewed/2020/02/GHSA-7553-jr98-vx47/GHSA-7553-jr98-vx47.json +++ b/advisories/github-reviewed/2020/02/GHSA-7553-jr98-vx47/GHSA-7553-jr98-vx47.json @@ -92,6 +92,10 @@ "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpujul2020.html" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuoct2021.html" diff --git a/advisories/github-reviewed/2020/03/GHSA-jxfh-8wgv-vfr2/GHSA-jxfh-8wgv-vfr2.json b/advisories/github-reviewed/2020/03/GHSA-jxfh-8wgv-vfr2/GHSA-jxfh-8wgv-vfr2.json index 2c3d6899f81..5d9318d0da6 100644 --- a/advisories/github-reviewed/2020/03/GHSA-jxfh-8wgv-vfr2/GHSA-jxfh-8wgv-vfr2.json +++ b/advisories/github-reviewed/2020/03/GHSA-jxfh-8wgv-vfr2/GHSA-jxfh-8wgv-vfr2.json @@ -171,6 +171,10 @@ "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpujul2020.html" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuoct2021.html" diff --git a/advisories/github-reviewed/2020/04/GHSA-gxr4-xjj5-5px2/GHSA-gxr4-xjj5-5px2.json b/advisories/github-reviewed/2020/04/GHSA-gxr4-xjj5-5px2/GHSA-gxr4-xjj5-5px2.json index 1eb67d9eb43..17c1353fcd2 100644 --- a/advisories/github-reviewed/2020/04/GHSA-gxr4-xjj5-5px2/GHSA-gxr4-xjj5-5px2.json +++ b/advisories/github-reviewed/2020/04/GHSA-gxr4-xjj5-5px2/GHSA-gxr4-xjj5-5px2.json @@ -176,6 +176,10 @@ "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpujul2020.html" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuoct2020.html" diff --git a/advisories/github-reviewed/2020/04/GHSA-jpcq-cgw6-v4j6/GHSA-jpcq-cgw6-v4j6.json b/advisories/github-reviewed/2020/04/GHSA-jpcq-cgw6-v4j6/GHSA-jpcq-cgw6-v4j6.json index 373e2755887..03db6093406 100644 --- a/advisories/github-reviewed/2020/04/GHSA-jpcq-cgw6-v4j6/GHSA-jpcq-cgw6-v4j6.json +++ b/advisories/github-reviewed/2020/04/GHSA-jpcq-cgw6-v4j6/GHSA-jpcq-cgw6-v4j6.json @@ -264,6 +264,10 @@ "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpujul2020.html" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuoct2020.html" diff --git a/advisories/github-reviewed/2020/05/GHSA-344f-f5vg-2jfj/GHSA-344f-f5vg-2jfj.json b/advisories/github-reviewed/2020/05/GHSA-344f-f5vg-2jfj/GHSA-344f-f5vg-2jfj.json index c04c2961e13..bbd03234138 100644 --- a/advisories/github-reviewed/2020/05/GHSA-344f-f5vg-2jfj/GHSA-344f-f5vg-2jfj.json +++ b/advisories/github-reviewed/2020/05/GHSA-344f-f5vg-2jfj/GHSA-344f-f5vg-2jfj.json @@ -240,6 +240,10 @@ "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpujul2020.html" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuoct2020.html" diff --git a/advisories/github-reviewed/2020/05/GHSA-q4m3-2j7h-f7xw/GHSA-q4m3-2j7h-f7xw.json b/advisories/github-reviewed/2020/05/GHSA-q4m3-2j7h-f7xw/GHSA-q4m3-2j7h-f7xw.json index b4b54b87ff9..b8aaaab1f4b 100644 --- a/advisories/github-reviewed/2020/05/GHSA-q4m3-2j7h-f7xw/GHSA-q4m3-2j7h-f7xw.json +++ b/advisories/github-reviewed/2020/05/GHSA-q4m3-2j7h-f7xw/GHSA-q4m3-2j7h-f7xw.json @@ -56,6 +56,10 @@ "type": "WEB", "url": "https://www.npmjs.com/advisories/1524" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "PACKAGE", "url": "https://github.com/jquery/jquery" diff --git a/advisories/github-reviewed/2020/06/GHSA-6phf-73q6-gh87/GHSA-6phf-73q6-gh87.json b/advisories/github-reviewed/2020/06/GHSA-6phf-73q6-gh87/GHSA-6phf-73q6-gh87.json index ce6041439c5..20d1b5893bd 100644 --- a/advisories/github-reviewed/2020/06/GHSA-6phf-73q6-gh87/GHSA-6phf-73q6-gh87.json +++ b/advisories/github-reviewed/2020/06/GHSA-6phf-73q6-gh87/GHSA-6phf-73q6-gh87.json @@ -244,6 +244,10 @@ "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpujul2020.html" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuoct2021.html" diff --git a/advisories/github-reviewed/2020/06/GHSA-hwj3-m3p6-hj38/GHSA-hwj3-m3p6-hj38.json b/advisories/github-reviewed/2020/06/GHSA-hwj3-m3p6-hj38/GHSA-hwj3-m3p6-hj38.json index 482c6c7fd42..4566520531a 100644 --- a/advisories/github-reviewed/2020/06/GHSA-hwj3-m3p6-hj38/GHSA-hwj3-m3p6-hj38.json +++ b/advisories/github-reviewed/2020/06/GHSA-hwj3-m3p6-hj38/GHSA-hwj3-m3p6-hj38.json @@ -146,6 +146,10 @@ "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpujul2020.html" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuoct2020.html" diff --git a/advisories/github-reviewed/2020/09/GHSA-c6pw-q7f2-97hv/GHSA-c6pw-q7f2-97hv.json b/advisories/github-reviewed/2020/09/GHSA-c6pw-q7f2-97hv/GHSA-c6pw-q7f2-97hv.json index b33b62ff2c2..78d3f3c2c89 100644 --- a/advisories/github-reviewed/2020/09/GHSA-c6pw-q7f2-97hv/GHSA-c6pw-q7f2-97hv.json +++ b/advisories/github-reviewed/2020/09/GHSA-c6pw-q7f2-97hv/GHSA-c6pw-q7f2-97hv.json @@ -60,6 +60,10 @@ "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuApr2021.html" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2019/11/28/1" diff --git a/advisories/github-reviewed/2020/12/GHSA-rcjj-h6gh-jf3r/GHSA-rcjj-h6gh-jf3r.json b/advisories/github-reviewed/2020/12/GHSA-rcjj-h6gh-jf3r/GHSA-rcjj-h6gh-jf3r.json index f8492bae24e..19930967536 100644 --- a/advisories/github-reviewed/2020/12/GHSA-rcjj-h6gh-jf3r/GHSA-rcjj-h6gh-jf3r.json +++ b/advisories/github-reviewed/2020/12/GHSA-rcjj-h6gh-jf3r/GHSA-rcjj-h6gh-jf3r.json @@ -126,6 +126,10 @@ "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpujan2022.html" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuoct2021.html" diff --git a/advisories/github-reviewed/2021/02/GHSA-rhm9-p9w5-fwm7/GHSA-rhm9-p9w5-fwm7.json b/advisories/github-reviewed/2021/02/GHSA-rhm9-p9w5-fwm7/GHSA-rhm9-p9w5-fwm7.json index 77a7612a598..37913e2d04e 100644 --- a/advisories/github-reviewed/2021/02/GHSA-rhm9-p9w5-fwm7/GHSA-rhm9-p9w5-fwm7.json +++ b/advisories/github-reviewed/2021/02/GHSA-rhm9-p9w5-fwm7/GHSA-rhm9-p9w5-fwm7.json @@ -73,6 +73,10 @@ "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuapr2022.html" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "PACKAGE", "url": "https://github.com/pyca/cryptography" diff --git a/advisories/github-reviewed/2021/03/GHSA-8q59-q68h-6hv4/GHSA-8q59-q68h-6hv4.json b/advisories/github-reviewed/2021/03/GHSA-8q59-q68h-6hv4/GHSA-8q59-q68h-6hv4.json index 7759c4c4d5d..0a6d010e9c1 100644 --- a/advisories/github-reviewed/2021/03/GHSA-8q59-q68h-6hv4/GHSA-8q59-q68h-6hv4.json +++ b/advisories/github-reviewed/2021/03/GHSA-8q59-q68h-6hv4/GHSA-8q59-q68h-6hv4.json @@ -66,6 +66,10 @@ "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuapr2022.html" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "PACKAGE", "url": "https://github.com/yaml/pyyaml" diff --git a/advisories/github-reviewed/2021/04/GHSA-gwrp-pvrq-jmwv/GHSA-gwrp-pvrq-jmwv.json b/advisories/github-reviewed/2021/04/GHSA-gwrp-pvrq-jmwv/GHSA-gwrp-pvrq-jmwv.json index 4e2c803fdaf..f7d8c2299d7 100644 --- a/advisories/github-reviewed/2021/04/GHSA-gwrp-pvrq-jmwv/GHSA-gwrp-pvrq-jmwv.json +++ b/advisories/github-reviewed/2021/04/GHSA-gwrp-pvrq-jmwv/GHSA-gwrp-pvrq-jmwv.json @@ -220,6 +220,10 @@ "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpujan2022.html" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuoct2021.html" diff --git a/advisories/github-reviewed/2021/05/GHSA-3c6g-pvg8-gqw2/GHSA-3c6g-pvg8-gqw2.json b/advisories/github-reviewed/2021/05/GHSA-3c6g-pvg8-gqw2/GHSA-3c6g-pvg8-gqw2.json index a8f16c88e9f..e00bcf425b0 100644 --- a/advisories/github-reviewed/2021/05/GHSA-3c6g-pvg8-gqw2/GHSA-3c6g-pvg8-gqw2.json +++ b/advisories/github-reviewed/2021/05/GHSA-3c6g-pvg8-gqw2/GHSA-3c6g-pvg8-gqw2.json @@ -128,6 +128,10 @@ "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpujan2022.html" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "PACKAGE", "url": "https://github.com/trentm/json" diff --git a/advisories/github-reviewed/2021/05/GHSA-7chv-rrw6-w6fc/GHSA-7chv-rrw6-w6fc.json b/advisories/github-reviewed/2021/05/GHSA-7chv-rrw6-w6fc/GHSA-7chv-rrw6-w6fc.json index 1b7c02001eb..054cf4b4fbc 100644 --- a/advisories/github-reviewed/2021/05/GHSA-7chv-rrw6-w6fc/GHSA-7chv-rrw6-w6fc.json +++ b/advisories/github-reviewed/2021/05/GHSA-7chv-rrw6-w6fc/GHSA-7chv-rrw6-w6fc.json @@ -84,6 +84,10 @@ "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpujan2022.html" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuoct2021.html" diff --git a/advisories/github-reviewed/2021/06/GHSA-7grw-6pjh-jpc9/GHSA-7grw-6pjh-jpc9.json b/advisories/github-reviewed/2021/06/GHSA-7grw-6pjh-jpc9/GHSA-7grw-6pjh-jpc9.json index ce4ae75c551..d15113d3445 100644 --- a/advisories/github-reviewed/2021/06/GHSA-7grw-6pjh-jpc9/GHSA-7grw-6pjh-jpc9.json +++ b/advisories/github-reviewed/2021/06/GHSA-7grw-6pjh-jpc9/GHSA-7grw-6pjh-jpc9.json @@ -115,6 +115,10 @@ "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpujan2022.html" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuoct2021.html" diff --git a/advisories/github-reviewed/2021/06/GHSA-fg3j-q579-v8x4/GHSA-fg3j-q579-v8x4.json b/advisories/github-reviewed/2021/06/GHSA-fg3j-q579-v8x4/GHSA-fg3j-q579-v8x4.json index 35eb8bcb6d4..6b1da2709f1 100644 --- a/advisories/github-reviewed/2021/06/GHSA-fg3j-q579-v8x4/GHSA-fg3j-q579-v8x4.json +++ b/advisories/github-reviewed/2021/06/GHSA-fg3j-q579-v8x4/GHSA-fg3j-q579-v8x4.json @@ -119,6 +119,10 @@ "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpujan2022.html" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuoct2021.html" diff --git a/advisories/github-reviewed/2021/06/GHSA-mw3r-pfmg-xp92/GHSA-mw3r-pfmg-xp92.json b/advisories/github-reviewed/2021/06/GHSA-mw3r-pfmg-xp92/GHSA-mw3r-pfmg-xp92.json index c97f9520a12..8a65177e705 100644 --- a/advisories/github-reviewed/2021/06/GHSA-mw3r-pfmg-xp92/GHSA-mw3r-pfmg-xp92.json +++ b/advisories/github-reviewed/2021/06/GHSA-mw3r-pfmg-xp92/GHSA-mw3r-pfmg-xp92.json @@ -64,6 +64,10 @@ "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20210513-0004/" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuoct2021.html" diff --git a/advisories/github-reviewed/2021/06/GHSA-wqvq-5m8c-6g24/GHSA-wqvq-5m8c-6g24.json b/advisories/github-reviewed/2021/06/GHSA-wqvq-5m8c-6g24/GHSA-wqvq-5m8c-6g24.json index 59aa10458bd..3dc90a0a23a 100644 --- a/advisories/github-reviewed/2021/06/GHSA-wqvq-5m8c-6g24/GHSA-wqvq-5m8c-6g24.json +++ b/advisories/github-reviewed/2021/06/GHSA-wqvq-5m8c-6g24/GHSA-wqvq-5m8c-6g24.json @@ -60,6 +60,10 @@ "type": "WEB", "url": "https://usn.ubuntu.com/4570-1/" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuoct2021.html" diff --git a/advisories/github-reviewed/2021/07/GHSA-2363-cqg2-863c/GHSA-2363-cqg2-863c.json b/advisories/github-reviewed/2021/07/GHSA-2363-cqg2-863c/GHSA-2363-cqg2-863c.json index eadd790eca2..4776babcb01 100644 --- a/advisories/github-reviewed/2021/07/GHSA-2363-cqg2-863c/GHSA-2363-cqg2-863c.json +++ b/advisories/github-reviewed/2021/07/GHSA-2363-cqg2-863c/GHSA-2363-cqg2-863c.json @@ -108,6 +108,10 @@ "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuapr2022.html" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "PACKAGE", "url": "https://github.com/hunterhacker/jdom" diff --git a/advisories/github-reviewed/2021/07/GHSA-w9jg-gvgr-354m/GHSA-w9jg-gvgr-354m.json b/advisories/github-reviewed/2021/07/GHSA-w9jg-gvgr-354m/GHSA-w9jg-gvgr-354m.json index bca6f4450cc..67458e3b0d8 100644 --- a/advisories/github-reviewed/2021/07/GHSA-w9jg-gvgr-354m/GHSA-w9jg-gvgr-354m.json +++ b/advisories/github-reviewed/2021/07/GHSA-w9jg-gvgr-354m/GHSA-w9jg-gvgr-354m.json @@ -221,6 +221,10 @@ "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpujan2022.html" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "PACKAGE", "url": "https://github.com/spring-projects/spring-security" diff --git a/advisories/github-reviewed/2021/08/GHSA-2q8x-2p7f-574v/GHSA-2q8x-2p7f-574v.json b/advisories/github-reviewed/2021/08/GHSA-2q8x-2p7f-574v/GHSA-2q8x-2p7f-574v.json index 969d4aa9a93..33a677aebf1 100644 --- a/advisories/github-reviewed/2021/08/GHSA-2q8x-2p7f-574v/GHSA-2q8x-2p7f-574v.json +++ b/advisories/github-reviewed/2021/08/GHSA-2q8x-2p7f-574v/GHSA-2q8x-2p7f-574v.json @@ -76,6 +76,10 @@ "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpujan2022.html" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "WEB", "url": "https://x-stream.github.io/CVE-2021-39153.html" diff --git a/advisories/github-reviewed/2021/08/GHSA-64xx-cq4q-mf44/GHSA-64xx-cq4q-mf44.json b/advisories/github-reviewed/2021/08/GHSA-64xx-cq4q-mf44/GHSA-64xx-cq4q-mf44.json index 056a063457f..c69fa824694 100644 --- a/advisories/github-reviewed/2021/08/GHSA-64xx-cq4q-mf44/GHSA-64xx-cq4q-mf44.json +++ b/advisories/github-reviewed/2021/08/GHSA-64xx-cq4q-mf44/GHSA-64xx-cq4q-mf44.json @@ -76,6 +76,10 @@ "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpujan2022.html" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "WEB", "url": "https://x-stream.github.io/CVE-2021-39139.html" diff --git a/advisories/github-reviewed/2021/08/GHSA-6w62-hx7r-mw68/GHSA-6w62-hx7r-mw68.json b/advisories/github-reviewed/2021/08/GHSA-6w62-hx7r-mw68/GHSA-6w62-hx7r-mw68.json index 63d5cd2ee4e..e5bcfe5bf1e 100644 --- a/advisories/github-reviewed/2021/08/GHSA-6w62-hx7r-mw68/GHSA-6w62-hx7r-mw68.json +++ b/advisories/github-reviewed/2021/08/GHSA-6w62-hx7r-mw68/GHSA-6w62-hx7r-mw68.json @@ -76,6 +76,10 @@ "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpujan2022.html" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "WEB", "url": "https://x-stream.github.io/CVE-2021-39154.html" diff --git a/advisories/github-reviewed/2021/08/GHSA-6wf9-jmg9-vxcc/GHSA-6wf9-jmg9-vxcc.json b/advisories/github-reviewed/2021/08/GHSA-6wf9-jmg9-vxcc/GHSA-6wf9-jmg9-vxcc.json index 97dbd3d7c55..bc3ac80867d 100644 --- a/advisories/github-reviewed/2021/08/GHSA-6wf9-jmg9-vxcc/GHSA-6wf9-jmg9-vxcc.json +++ b/advisories/github-reviewed/2021/08/GHSA-6wf9-jmg9-vxcc/GHSA-6wf9-jmg9-vxcc.json @@ -76,6 +76,10 @@ "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpujan2022.html" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "WEB", "url": "https://x-stream.github.io/CVE-2021-39140.html" diff --git a/advisories/github-reviewed/2021/08/GHSA-83mx-573x-5rw9/GHSA-83mx-573x-5rw9.json b/advisories/github-reviewed/2021/08/GHSA-83mx-573x-5rw9/GHSA-83mx-573x-5rw9.json index a6fe44befb1..57f6b7c8b16 100644 --- a/advisories/github-reviewed/2021/08/GHSA-83mx-573x-5rw9/GHSA-83mx-573x-5rw9.json +++ b/advisories/github-reviewed/2021/08/GHSA-83mx-573x-5rw9/GHSA-83mx-573x-5rw9.json @@ -120,6 +120,10 @@ "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuapr2022.html" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuoct2021.html" diff --git a/advisories/github-reviewed/2021/08/GHSA-8hfj-xrj2-pm22/GHSA-8hfj-xrj2-pm22.json b/advisories/github-reviewed/2021/08/GHSA-8hfj-xrj2-pm22/GHSA-8hfj-xrj2-pm22.json index 1c20c2b5b59..b7b6676b5ab 100644 --- a/advisories/github-reviewed/2021/08/GHSA-8hfj-xrj2-pm22/GHSA-8hfj-xrj2-pm22.json +++ b/advisories/github-reviewed/2021/08/GHSA-8hfj-xrj2-pm22/GHSA-8hfj-xrj2-pm22.json @@ -104,6 +104,10 @@ "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuapr2022.html" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuoct2021.html" diff --git a/advisories/github-reviewed/2021/08/GHSA-9279-7hph-r3xw/GHSA-9279-7hph-r3xw.json b/advisories/github-reviewed/2021/08/GHSA-9279-7hph-r3xw/GHSA-9279-7hph-r3xw.json index e14691acb72..a8a52584551 100644 --- a/advisories/github-reviewed/2021/08/GHSA-9279-7hph-r3xw/GHSA-9279-7hph-r3xw.json +++ b/advisories/github-reviewed/2021/08/GHSA-9279-7hph-r3xw/GHSA-9279-7hph-r3xw.json @@ -79,6 +79,10 @@ "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuapr2022.html" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2021/07/12/1" diff --git a/advisories/github-reviewed/2021/08/GHSA-hph2-m3g5-xxv4/GHSA-hph2-m3g5-xxv4.json b/advisories/github-reviewed/2021/08/GHSA-hph2-m3g5-xxv4/GHSA-hph2-m3g5-xxv4.json index e5b511b07df..02d08274ea1 100644 --- a/advisories/github-reviewed/2021/08/GHSA-hph2-m3g5-xxv4/GHSA-hph2-m3g5-xxv4.json +++ b/advisories/github-reviewed/2021/08/GHSA-hph2-m3g5-xxv4/GHSA-hph2-m3g5-xxv4.json @@ -76,6 +76,10 @@ "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpujan2022.html" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "WEB", "url": "https://x-stream.github.io/CVE-2021-39151.html" diff --git a/advisories/github-reviewed/2021/08/GHSA-p8pq-r894-fm8f/GHSA-p8pq-r894-fm8f.json b/advisories/github-reviewed/2021/08/GHSA-p8pq-r894-fm8f/GHSA-p8pq-r894-fm8f.json index 56272b1b24f..76baec74c4b 100644 --- a/advisories/github-reviewed/2021/08/GHSA-p8pq-r894-fm8f/GHSA-p8pq-r894-fm8f.json +++ b/advisories/github-reviewed/2021/08/GHSA-p8pq-r894-fm8f/GHSA-p8pq-r894-fm8f.json @@ -76,6 +76,10 @@ "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpujan2022.html" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "WEB", "url": "https://x-stream.github.io/CVE-2021-39146.html" diff --git a/advisories/github-reviewed/2021/08/GHSA-xw4p-crpj-vjx2/GHSA-xw4p-crpj-vjx2.json b/advisories/github-reviewed/2021/08/GHSA-xw4p-crpj-vjx2/GHSA-xw4p-crpj-vjx2.json index 64153b34b91..e2e446b844c 100644 --- a/advisories/github-reviewed/2021/08/GHSA-xw4p-crpj-vjx2/GHSA-xw4p-crpj-vjx2.json +++ b/advisories/github-reviewed/2021/08/GHSA-xw4p-crpj-vjx2/GHSA-xw4p-crpj-vjx2.json @@ -76,6 +76,10 @@ "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpujan2022.html" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "WEB", "url": "https://x-stream.github.io/CVE-2021-39152.html" diff --git a/advisories/github-reviewed/2021/09/GHSA-f6jp-j6w3-w9hm/GHSA-f6jp-j6w3-w9hm.json b/advisories/github-reviewed/2021/09/GHSA-f6jp-j6w3-w9hm/GHSA-f6jp-j6w3-w9hm.json index af104ad6308..acae390ab83 100644 --- a/advisories/github-reviewed/2021/09/GHSA-f6jp-j6w3-w9hm/GHSA-f6jp-j6w3-w9hm.json +++ b/advisories/github-reviewed/2021/09/GHSA-f6jp-j6w3-w9hm/GHSA-f6jp-j6w3-w9hm.json @@ -51,6 +51,10 @@ { "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20220609-0001/" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" } ], "database_specific": { diff --git a/advisories/github-reviewed/2021/10/GHSA-9gj3-hwp5-pmwc/GHSA-9gj3-hwp5-pmwc.json b/advisories/github-reviewed/2021/10/GHSA-9gj3-hwp5-pmwc/GHSA-9gj3-hwp5-pmwc.json index f67d8b29f62..c7dbf0e0efa 100644 --- a/advisories/github-reviewed/2021/10/GHSA-9gj3-hwp5-pmwc/GHSA-9gj3-hwp5-pmwc.json +++ b/advisories/github-reviewed/2021/10/GHSA-9gj3-hwp5-pmwc/GHSA-9gj3-hwp5-pmwc.json @@ -84,6 +84,10 @@ "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuapr2022.html" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "WEB", "url": "https://www.tenable.com/security/tns-2022-09" diff --git a/advisories/github-reviewed/2021/10/GHSA-gpqq-952q-5327/GHSA-gpqq-952q-5327.json b/advisories/github-reviewed/2021/10/GHSA-gpqq-952q-5327/GHSA-gpqq-952q-5327.json index 77289f581b5..b51e284d303 100644 --- a/advisories/github-reviewed/2021/10/GHSA-gpqq-952q-5327/GHSA-gpqq-952q-5327.json +++ b/advisories/github-reviewed/2021/10/GHSA-gpqq-952q-5327/GHSA-gpqq-952q-5327.json @@ -76,6 +76,10 @@ "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuapr2022.html" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "WEB", "url": "https://www.tenable.com/security/tns-2022-09" diff --git a/advisories/github-reviewed/2021/10/GHSA-j7qv-pgf6-hvh4/GHSA-j7qv-pgf6-hvh4.json b/advisories/github-reviewed/2021/10/GHSA-j7qv-pgf6-hvh4/GHSA-j7qv-pgf6-hvh4.json index f45a4aa684b..efa8a2760dc 100644 --- a/advisories/github-reviewed/2021/10/GHSA-j7qv-pgf6-hvh4/GHSA-j7qv-pgf6-hvh4.json +++ b/advisories/github-reviewed/2021/10/GHSA-j7qv-pgf6-hvh4/GHSA-j7qv-pgf6-hvh4.json @@ -92,6 +92,10 @@ "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuapr2022.html" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "WEB", "url": "https://www.tenable.com/security/tns-2022-09" diff --git a/advisories/github-reviewed/2021/10/GHSA-wph7-x527-w3h5/GHSA-wph7-x527-w3h5.json b/advisories/github-reviewed/2021/10/GHSA-wph7-x527-w3h5/GHSA-wph7-x527-w3h5.json index 484ec6a544a..4d84a483228 100644 --- a/advisories/github-reviewed/2021/10/GHSA-wph7-x527-w3h5/GHSA-wph7-x527-w3h5.json +++ b/advisories/github-reviewed/2021/10/GHSA-wph7-x527-w3h5/GHSA-wph7-x527-w3h5.json @@ -128,6 +128,10 @@ "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpujan2022.html" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "PACKAGE", "url": "https://github.com/apache/tomcat" diff --git a/advisories/github-reviewed/2021/11/GHSA-7h26-63m7-qhf2/GHSA-7h26-63m7-qhf2.json b/advisories/github-reviewed/2021/11/GHSA-7h26-63m7-qhf2/GHSA-7h26-63m7-qhf2.json index 4612d09991a..4cd0151ac02 100644 --- a/advisories/github-reviewed/2021/11/GHSA-7h26-63m7-qhf2/GHSA-7h26-63m7-qhf2.json +++ b/advisories/github-reviewed/2021/11/GHSA-7h26-63m7-qhf2/GHSA-7h26-63m7-qhf2.json @@ -60,6 +60,10 @@ "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpujan2022.html" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "PACKAGE", "url": "https://github.com/ckeditor/ckeditor4" diff --git a/advisories/github-reviewed/2021/11/GHSA-pvmx-g8h5-cprj/GHSA-pvmx-g8h5-cprj.json b/advisories/github-reviewed/2021/11/GHSA-pvmx-g8h5-cprj/GHSA-pvmx-g8h5-cprj.json index 3a3e915e9b7..ce49c6d02f0 100644 --- a/advisories/github-reviewed/2021/11/GHSA-pvmx-g8h5-cprj/GHSA-pvmx-g8h5-cprj.json +++ b/advisories/github-reviewed/2021/11/GHSA-pvmx-g8h5-cprj/GHSA-pvmx-g8h5-cprj.json @@ -60,6 +60,10 @@ "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpujan2022.html" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "PACKAGE", "url": "https://github.com/ckeditor/ckeditor4" diff --git a/advisories/github-reviewed/2021/11/GHSA-v585-23hc-c647/GHSA-v585-23hc-c647.json b/advisories/github-reviewed/2021/11/GHSA-v585-23hc-c647/GHSA-v585-23hc-c647.json index a97b494aec7..ebe8930b8bf 100644 --- a/advisories/github-reviewed/2021/11/GHSA-v585-23hc-c647/GHSA-v585-23hc-c647.json +++ b/advisories/github-reviewed/2021/11/GHSA-v585-23hc-c647/GHSA-v585-23hc-c647.json @@ -75,6 +75,10 @@ "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpujan2022.html" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuoct2021.html" diff --git a/advisories/github-reviewed/2021/12/GHSA-55x5-fj6c-h6m8/GHSA-55x5-fj6c-h6m8.json b/advisories/github-reviewed/2021/12/GHSA-55x5-fj6c-h6m8/GHSA-55x5-fj6c-h6m8.json index 0ed6b385c7f..3a1ecb09168 100644 --- a/advisories/github-reviewed/2021/12/GHSA-55x5-fj6c-h6m8/GHSA-55x5-fj6c-h6m8.json +++ b/advisories/github-reviewed/2021/12/GHSA-55x5-fj6c-h6m8/GHSA-55x5-fj6c-h6m8.json @@ -88,6 +88,10 @@ "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuapr2022.html" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "PACKAGE", "url": "https://github.com/lxml/lxml" diff --git a/advisories/github-reviewed/2021/12/GHSA-9m6f-7xcq-8vf8/GHSA-9m6f-7xcq-8vf8.json b/advisories/github-reviewed/2021/12/GHSA-9m6f-7xcq-8vf8/GHSA-9m6f-7xcq-8vf8.json index e94521237c4..72f330bea3a 100644 --- a/advisories/github-reviewed/2021/12/GHSA-9m6f-7xcq-8vf8/GHSA-9m6f-7xcq-8vf8.json +++ b/advisories/github-reviewed/2021/12/GHSA-9m6f-7xcq-8vf8/GHSA-9m6f-7xcq-8vf8.json @@ -75,6 +75,10 @@ "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpujan2022.html" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuoct2021.html" diff --git a/advisories/github-reviewed/2021/12/GHSA-cvm9-fjm9-3572/GHSA-cvm9-fjm9-3572.json b/advisories/github-reviewed/2021/12/GHSA-cvm9-fjm9-3572/GHSA-cvm9-fjm9-3572.json index 47bc81c194b..4611633c5f6 100644 --- a/advisories/github-reviewed/2021/12/GHSA-cvm9-fjm9-3572/GHSA-cvm9-fjm9-3572.json +++ b/advisories/github-reviewed/2021/12/GHSA-cvm9-fjm9-3572/GHSA-cvm9-fjm9-3572.json @@ -75,6 +75,10 @@ "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpujan2022.html" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuoct2021.html" diff --git a/advisories/github-reviewed/2021/12/GHSA-f9xh-2qgp-cq57/GHSA-f9xh-2qgp-cq57.json b/advisories/github-reviewed/2021/12/GHSA-f9xh-2qgp-cq57/GHSA-f9xh-2qgp-cq57.json index 89e0266f0f5..8fb240dfdb2 100644 --- a/advisories/github-reviewed/2021/12/GHSA-f9xh-2qgp-cq57/GHSA-f9xh-2qgp-cq57.json +++ b/advisories/github-reviewed/2021/12/GHSA-f9xh-2qgp-cq57/GHSA-f9xh-2qgp-cq57.json @@ -75,6 +75,10 @@ "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpujan2022.html" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuoct2021.html" diff --git a/advisories/github-reviewed/2021/12/GHSA-fp5r-v3w9-4333/GHSA-fp5r-v3w9-4333.json b/advisories/github-reviewed/2021/12/GHSA-fp5r-v3w9-4333/GHSA-fp5r-v3w9-4333.json index 83e5e8a9f63..4a39a32010c 100644 --- a/advisories/github-reviewed/2021/12/GHSA-fp5r-v3w9-4333/GHSA-fp5r-v3w9-4333.json +++ b/advisories/github-reviewed/2021/12/GHSA-fp5r-v3w9-4333/GHSA-fp5r-v3w9-4333.json @@ -72,6 +72,10 @@ "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpujan2022.html" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2022/01/18/3" diff --git a/advisories/github-reviewed/2021/12/GHSA-jfh8-c2jp-5v3q/GHSA-jfh8-c2jp-5v3q.json b/advisories/github-reviewed/2021/12/GHSA-jfh8-c2jp-5v3q/GHSA-jfh8-c2jp-5v3q.json index c50bb3a10c1..a61ff58ae33 100644 --- a/advisories/github-reviewed/2021/12/GHSA-jfh8-c2jp-5v3q/GHSA-jfh8-c2jp-5v3q.json +++ b/advisories/github-reviewed/2021/12/GHSA-jfh8-c2jp-5v3q/GHSA-jfh8-c2jp-5v3q.json @@ -270,6 +270,14 @@ "type": "WEB", "url": "http://packetstormsecurity.com/files/165673/UniFi-Network-Application-Unauthenticated-Log4Shell-Remote-Code-Execution.html" }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/167794/Open-Xchange-App-Suite-7.10.x-Cross-Site-Scripting-Command-Injection.html" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2022/Jul/11" + }, { "type": "WEB", "url": "http://seclists.org/fulldisclosure/2022/Mar/23" diff --git a/advisories/github-reviewed/2021/12/GHSA-r695-7vr9-jgc2/GHSA-r695-7vr9-jgc2.json b/advisories/github-reviewed/2021/12/GHSA-r695-7vr9-jgc2/GHSA-r695-7vr9-jgc2.json index 4ce185d8edf..40c619e4ebf 100644 --- a/advisories/github-reviewed/2021/12/GHSA-r695-7vr9-jgc2/GHSA-r695-7vr9-jgc2.json +++ b/advisories/github-reviewed/2021/12/GHSA-r695-7vr9-jgc2/GHSA-r695-7vr9-jgc2.json @@ -75,6 +75,10 @@ "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpujan2022.html" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuoct2021.html" diff --git a/advisories/github-reviewed/2021/12/GHSA-vfqx-33qm-g869/GHSA-vfqx-33qm-g869.json b/advisories/github-reviewed/2021/12/GHSA-vfqx-33qm-g869/GHSA-vfqx-33qm-g869.json index f5c43c223df..24268ef34a5 100644 --- a/advisories/github-reviewed/2021/12/GHSA-vfqx-33qm-g869/GHSA-vfqx-33qm-g869.json +++ b/advisories/github-reviewed/2021/12/GHSA-vfqx-33qm-g869/GHSA-vfqx-33qm-g869.json @@ -75,6 +75,10 @@ "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpujan2022.html" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuoct2021.html" diff --git a/advisories/github-reviewed/2021/12/GHSA-wh8g-3j2c-rqj5/GHSA-wh8g-3j2c-rqj5.json b/advisories/github-reviewed/2021/12/GHSA-wh8g-3j2c-rqj5/GHSA-wh8g-3j2c-rqj5.json index 122b0b323d3..25854666641 100644 --- a/advisories/github-reviewed/2021/12/GHSA-wh8g-3j2c-rqj5/GHSA-wh8g-3j2c-rqj5.json +++ b/advisories/github-reviewed/2021/12/GHSA-wh8g-3j2c-rqj5/GHSA-wh8g-3j2c-rqj5.json @@ -75,6 +75,10 @@ "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpujan2022.html" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuoct2021.html" diff --git a/advisories/github-reviewed/2021/12/GHSA-wx5j-54mm-rqqq/GHSA-wx5j-54mm-rqqq.json b/advisories/github-reviewed/2021/12/GHSA-wx5j-54mm-rqqq/GHSA-wx5j-54mm-rqqq.json index 40cb8c4c045..1140f9645d2 100644 --- a/advisories/github-reviewed/2021/12/GHSA-wx5j-54mm-rqqq/GHSA-wx5j-54mm-rqqq.json +++ b/advisories/github-reviewed/2021/12/GHSA-wx5j-54mm-rqqq/GHSA-wx5j-54mm-rqqq.json @@ -63,6 +63,10 @@ "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuapr2022.html" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "PACKAGE", "url": "https://github.com/netty/netty/" diff --git a/advisories/github-reviewed/2021/12/GHSA-xr38-w74q-r8jv/GHSA-xr38-w74q-r8jv.json b/advisories/github-reviewed/2021/12/GHSA-xr38-w74q-r8jv/GHSA-xr38-w74q-r8jv.json index 072d458925d..803e9066e80 100644 --- a/advisories/github-reviewed/2021/12/GHSA-xr38-w74q-r8jv/GHSA-xr38-w74q-r8jv.json +++ b/advisories/github-reviewed/2021/12/GHSA-xr38-w74q-r8jv/GHSA-xr38-w74q-r8jv.json @@ -127,7 +127,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-862" + "CWE-862", + "CWE-863" ], "severity": "MODERATE", "github_reviewed": true diff --git a/advisories/github-reviewed/2022/01/GHSA-2h63-qp69-fwvw/GHSA-2h63-qp69-fwvw.json b/advisories/github-reviewed/2022/01/GHSA-2h63-qp69-fwvw/GHSA-2h63-qp69-fwvw.json index b8c8a228f57..b13e880f578 100644 --- a/advisories/github-reviewed/2022/01/GHSA-2h63-qp69-fwvw/GHSA-2h63-qp69-fwvw.json +++ b/advisories/github-reviewed/2022/01/GHSA-2h63-qp69-fwvw/GHSA-2h63-qp69-fwvw.json @@ -110,6 +110,10 @@ "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpujan2022.html" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuoct2021.html" diff --git a/advisories/github-reviewed/2022/01/GHSA-65fg-84f6-3jq3/GHSA-65fg-84f6-3jq3.json b/advisories/github-reviewed/2022/01/GHSA-65fg-84f6-3jq3/GHSA-65fg-84f6-3jq3.json index 2e9ccfa3748..04b682e6f68 100644 --- a/advisories/github-reviewed/2022/01/GHSA-65fg-84f6-3jq3/GHSA-65fg-84f6-3jq3.json +++ b/advisories/github-reviewed/2022/01/GHSA-65fg-84f6-3jq3/GHSA-65fg-84f6-3jq3.json @@ -56,6 +56,10 @@ "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuapr2022.html" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2022/01/18/4" diff --git a/advisories/github-reviewed/2022/01/GHSA-h65f-jvqw-m9fj/GHSA-h65f-jvqw-m9fj.json b/advisories/github-reviewed/2022/01/GHSA-h65f-jvqw-m9fj/GHSA-h65f-jvqw-m9fj.json index 208bbc965ff..0c8eef71070 100644 --- a/advisories/github-reviewed/2022/01/GHSA-h65f-jvqw-m9fj/GHSA-h65f-jvqw-m9fj.json +++ b/advisories/github-reviewed/2022/01/GHSA-h65f-jvqw-m9fj/GHSA-h65f-jvqw-m9fj.json @@ -48,6 +48,10 @@ "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuapr2022.html" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2022/01/24/3" diff --git a/advisories/github-reviewed/2022/01/GHSA-m8gw-hjpr-rjv7/GHSA-m8gw-hjpr-rjv7.json b/advisories/github-reviewed/2022/01/GHSA-m8gw-hjpr-rjv7/GHSA-m8gw-hjpr-rjv7.json index f8c6dbbcaf0..b3c2c03775a 100644 --- a/advisories/github-reviewed/2022/01/GHSA-m8gw-hjpr-rjv7/GHSA-m8gw-hjpr-rjv7.json +++ b/advisories/github-reviewed/2022/01/GHSA-m8gw-hjpr-rjv7/GHSA-m8gw-hjpr-rjv7.json @@ -68,6 +68,10 @@ "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuapr2022.html" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "PACKAGE", "url": "https://github.com/dojo/dojo" diff --git a/advisories/github-reviewed/2022/01/GHSA-w9p3-5cr8-m3jj/GHSA-w9p3-5cr8-m3jj.json b/advisories/github-reviewed/2022/01/GHSA-w9p3-5cr8-m3jj/GHSA-w9p3-5cr8-m3jj.json index 5e6fa4b999d..1a6c983dfc9 100644 --- a/advisories/github-reviewed/2022/01/GHSA-w9p3-5cr8-m3jj/GHSA-w9p3-5cr8-m3jj.json +++ b/advisories/github-reviewed/2022/01/GHSA-w9p3-5cr8-m3jj/GHSA-w9p3-5cr8-m3jj.json @@ -56,6 +56,10 @@ "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuapr2022.html" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2022/01/18/3" diff --git a/advisories/github-reviewed/2022/02/GHSA-2qp4-g3q3-f92w/GHSA-2qp4-g3q3-f92w.json b/advisories/github-reviewed/2022/02/GHSA-2qp4-g3q3-f92w/GHSA-2qp4-g3q3-f92w.json index 73c468b0337..cc170da50d5 100644 --- a/advisories/github-reviewed/2022/02/GHSA-2qp4-g3q3-f92w/GHSA-2qp4-g3q3-f92w.json +++ b/advisories/github-reviewed/2022/02/GHSA-2qp4-g3q3-f92w/GHSA-2qp4-g3q3-f92w.json @@ -43,6 +43,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-24329" }, + { + "type": "WEB", + "url": "https://blog.jetbrains.com" + }, { "type": "WEB", "url": "https://blog.jetbrains.com/blog/2022/02/08/jetbrains-security-bulletin-q4-2021/" @@ -51,6 +55,10 @@ "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuapr2022.html" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "PACKAGE", "url": "https://github.com/JetBrains/kotlin" diff --git a/advisories/github-reviewed/2022/02/GHSA-5545-2q6w-2gh6/GHSA-5545-2q6w-2gh6.json b/advisories/github-reviewed/2022/02/GHSA-5545-2q6w-2gh6/GHSA-5545-2q6w-2gh6.json index 66930d181d1..c5ccd3afac6 100644 --- a/advisories/github-reviewed/2022/02/GHSA-5545-2q6w-2gh6/GHSA-5545-2q6w-2gh6.json +++ b/advisories/github-reviewed/2022/02/GHSA-5545-2q6w-2gh6/GHSA-5545-2q6w-2gh6.json @@ -47,6 +47,10 @@ "type": "WEB", "url": "https://github.com/numpy/numpy/issues/19038" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "PACKAGE", "url": "https://github.com/numpy/numpy" diff --git a/advisories/github-reviewed/2022/02/GHSA-9f3j-pm6f-9fm5/GHSA-9f3j-pm6f-9fm5.json b/advisories/github-reviewed/2022/02/GHSA-9f3j-pm6f-9fm5/GHSA-9f3j-pm6f-9fm5.json index 9deb101aa06..55364e46355 100644 --- a/advisories/github-reviewed/2022/02/GHSA-9f3j-pm6f-9fm5/GHSA-9f3j-pm6f-9fm5.json +++ b/advisories/github-reviewed/2022/02/GHSA-9f3j-pm6f-9fm5/GHSA-9f3j-pm6f-9fm5.json @@ -90,6 +90,10 @@ "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuapr2022.html" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "PACKAGE", "url": "https://github.com/apache/tomcat" diff --git a/advisories/github-reviewed/2022/02/GHSA-hrhx-6h34-j5hc/GHSA-hrhx-6h34-j5hc.json b/advisories/github-reviewed/2022/02/GHSA-hrhx-6h34-j5hc/GHSA-hrhx-6h34-j5hc.json index 2ef9edc93db..09218f91491 100644 --- a/advisories/github-reviewed/2022/02/GHSA-hrhx-6h34-j5hc/GHSA-hrhx-6h34-j5hc.json +++ b/advisories/github-reviewed/2022/02/GHSA-hrhx-6h34-j5hc/GHSA-hrhx-6h34-j5hc.json @@ -52,6 +52,10 @@ "type": "WEB", "url": "https://github.com/traefik/traefik/releases/tag/v2.6.1" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "PACKAGE", "url": "https://github.com/traefik/traefik" diff --git a/advisories/github-reviewed/2022/02/GHSA-rmr5-cpv2-vgjf/GHSA-rmr5-cpv2-vgjf.json b/advisories/github-reviewed/2022/02/GHSA-rmr5-cpv2-vgjf/GHSA-rmr5-cpv2-vgjf.json index 2bd098c9a61..240f4d52748 100644 --- a/advisories/github-reviewed/2022/02/GHSA-rmr5-cpv2-vgjf/GHSA-rmr5-cpv2-vgjf.json +++ b/advisories/github-reviewed/2022/02/GHSA-rmr5-cpv2-vgjf/GHSA-rmr5-cpv2-vgjf.json @@ -64,6 +64,10 @@ "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuapr2022.html" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "WEB", "url": "https://x-stream.github.io/CVE-2021-43859.html" diff --git a/advisories/github-reviewed/2022/03/GHSA-36p3-wjmg-h94x/GHSA-36p3-wjmg-h94x.json b/advisories/github-reviewed/2022/03/GHSA-36p3-wjmg-h94x/GHSA-36p3-wjmg-h94x.json index 398dfbc944e..73dc22a45d9 100644 --- a/advisories/github-reviewed/2022/03/GHSA-36p3-wjmg-h94x/GHSA-36p3-wjmg-h94x.json +++ b/advisories/github-reviewed/2022/03/GHSA-36p3-wjmg-h94x/GHSA-36p3-wjmg-h94x.json @@ -255,6 +255,10 @@ "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuapr2022.html" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "WEB", "url": "http://packetstormsecurity.com/files/166713/Spring4Shell-Code-Execution.html" diff --git a/advisories/github-reviewed/2022/03/GHSA-4fc4-4p5g-6w89/GHSA-4fc4-4p5g-6w89.json b/advisories/github-reviewed/2022/03/GHSA-4fc4-4p5g-6w89/GHSA-4fc4-4p5g-6w89.json index 3aa8636b975..39f547782b0 100644 --- a/advisories/github-reviewed/2022/03/GHSA-4fc4-4p5g-6w89/GHSA-4fc4-4p5g-6w89.json +++ b/advisories/github-reviewed/2022/03/GHSA-4fc4-4p5g-6w89/GHSA-4fc4-4p5g-6w89.json @@ -60,6 +60,10 @@ "type": "WEB", "url": "https://www.drupal.org/sa-core-2022-005" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "PACKAGE", "url": "https://github.com/ckeditor/ckeditor4" diff --git a/advisories/github-reviewed/2022/03/GHSA-jvfv-hrrc-6q72/GHSA-jvfv-hrrc-6q72.json b/advisories/github-reviewed/2022/03/GHSA-jvfv-hrrc-6q72/GHSA-jvfv-hrrc-6q72.json index e9648145eee..9ed798218ab 100644 --- a/advisories/github-reviewed/2022/03/GHSA-jvfv-hrrc-6q72/GHSA-jvfv-hrrc-6q72.json +++ b/advisories/github-reviewed/2022/03/GHSA-jvfv-hrrc-6q72/GHSA-jvfv-hrrc-6q72.json @@ -48,6 +48,10 @@ "type": "WEB", "url": "https://huntr.dev/bounties/f1ae5779-b406-4594-a8a3-d089c68d6e70" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "PACKAGE", "url": "https://github.com/liquibase/liquibase" diff --git a/advisories/github-reviewed/2022/04/GHSA-8m5h-hrqm-pxm2/GHSA-8m5h-hrqm-pxm2.json b/advisories/github-reviewed/2022/04/GHSA-8m5h-hrqm-pxm2/GHSA-8m5h-hrqm-pxm2.json index c721ebc8c81..d2495e1b49c 100644 --- a/advisories/github-reviewed/2022/04/GHSA-8m5h-hrqm-pxm2/GHSA-8m5h-hrqm-pxm2.json +++ b/advisories/github-reviewed/2022/04/GHSA-8m5h-hrqm-pxm2/GHSA-8m5h-hrqm-pxm2.json @@ -63,6 +63,10 @@ "type": "ADVISORY", "url": "https://securitylab.github.com/advisories/GHSL-2022-008_The_OWASP_Enterprise_Security_API/" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "PACKAGE", "url": "https://github.com/ESAPI/esapi-java-legacy" diff --git a/advisories/github-reviewed/2022/04/GHSA-c2jg-hw38-jrqq/GHSA-c2jg-hw38-jrqq.json b/advisories/github-reviewed/2022/04/GHSA-c2jg-hw38-jrqq/GHSA-c2jg-hw38-jrqq.json index 55789ca1e25..54f9884acae 100644 --- a/advisories/github-reviewed/2022/04/GHSA-c2jg-hw38-jrqq/GHSA-c2jg-hw38-jrqq.json +++ b/advisories/github-reviewed/2022/04/GHSA-c2jg-hw38-jrqq/GHSA-c2jg-hw38-jrqq.json @@ -68,6 +68,10 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GLKHA6WREIVAMBQD7KKWYHPHGGNKMAG6/" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "PACKAGE", "url": "https://github.com/twisted/twisted" diff --git a/advisories/github-reviewed/2022/04/GHSA-g5mm-vmx4-3rg7/GHSA-g5mm-vmx4-3rg7.json b/advisories/github-reviewed/2022/04/GHSA-g5mm-vmx4-3rg7/GHSA-g5mm-vmx4-3rg7.json index 4a4def76382..f73802a9c1b 100644 --- a/advisories/github-reviewed/2022/04/GHSA-g5mm-vmx4-3rg7/GHSA-g5mm-vmx4-3rg7.json +++ b/advisories/github-reviewed/2022/04/GHSA-g5mm-vmx4-3rg7/GHSA-g5mm-vmx4-3rg7.json @@ -67,6 +67,10 @@ "type": "WEB", "url": "https://tanzu.vmware.com/security/cve-2022-22968" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "PACKAGE", "url": "https://github.com/spring-projects/spring-framework" diff --git a/advisories/github-reviewed/2022/04/GHSA-q77q-vx4q-xx6q/GHSA-q77q-vx4q-xx6q.json b/advisories/github-reviewed/2022/04/GHSA-q77q-vx4q-xx6q/GHSA-q77q-vx4q-xx6q.json index 60d2233124b..3ef1c658655 100644 --- a/advisories/github-reviewed/2022/04/GHSA-q77q-vx4q-xx6q/GHSA-q77q-vx4q-xx6q.json +++ b/advisories/github-reviewed/2022/04/GHSA-q77q-vx4q-xx6q/GHSA-q77q-vx4q-xx6q.json @@ -55,6 +55,10 @@ "type": "WEB", "url": "https://github.com/ESAPI/esapi-java-legacy/blob/develop/documentation/esapi4java-core-2.3.0.0-release-notes.txt" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "PACKAGE", "url": "https://github.com/ESAPI/esapi-java-legacy" diff --git a/advisories/github-reviewed/2022/04/GHSA-v8j6-6c2r-r27c/GHSA-v8j6-6c2r-r27c.json b/advisories/github-reviewed/2022/04/GHSA-v8j6-6c2r-r27c/GHSA-v8j6-6c2r-r27c.json index 0949018d067..03bbf933906 100644 --- a/advisories/github-reviewed/2022/04/GHSA-v8j6-6c2r-r27c/GHSA-v8j6-6c2r-r27c.json +++ b/advisories/github-reviewed/2022/04/GHSA-v8j6-6c2r-r27c/GHSA-v8j6-6c2r-r27c.json @@ -1,7 +1,7 @@ { "schema_version": "1.2.0", "id": "GHSA-v8j6-6c2r-r27c", - "modified": "2022-04-22T20:30:35Z", + "modified": "2022-07-27T04:19:48Z", "published": "2022-04-13T00:00:30Z", "aliases": [ "CVE-2021-31805" @@ -48,6 +48,10 @@ "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20220420-0001/" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2022/04/12/6" diff --git a/advisories/github-reviewed/2022/04/GHSA-vp37-2f9p-3vr3/GHSA-vp37-2f9p-3vr3.json b/advisories/github-reviewed/2022/04/GHSA-vp37-2f9p-3vr3/GHSA-vp37-2f9p-3vr3.json index c28a0bb0e90..357cef93a92 100644 --- a/advisories/github-reviewed/2022/04/GHSA-vp37-2f9p-3vr3/GHSA-vp37-2f9p-3vr3.json +++ b/advisories/github-reviewed/2022/04/GHSA-vp37-2f9p-3vr3/GHSA-vp37-2f9p-3vr3.json @@ -48,6 +48,10 @@ "type": "WEB", "url": "https://github.com/nahsra/antisamy/releases/tag/v1.6.7" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "PACKAGE", "url": "https://github.com/nahsra/antisamy" diff --git a/advisories/github-reviewed/2022/05/GHSA-269q-hmxg-m83q/GHSA-269q-hmxg-m83q.json b/advisories/github-reviewed/2022/05/GHSA-269q-hmxg-m83q/GHSA-269q-hmxg-m83q.json index ca748ab29c9..737cd0426e2 100644 --- a/advisories/github-reviewed/2022/05/GHSA-269q-hmxg-m83q/GHSA-269q-hmxg-m83q.json +++ b/advisories/github-reviewed/2022/05/GHSA-269q-hmxg-m83q/GHSA-269q-hmxg-m83q.json @@ -59,6 +59,10 @@ "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20220616-0004/" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "PACKAGE", "url": "https://github.com/netty/netty" diff --git a/advisories/github-reviewed/2022/05/GHSA-gfwj-fwqj-fp3v/GHSA-gfwj-fwqj-fp3v.json b/advisories/github-reviewed/2022/05/GHSA-gfwj-fwqj-fp3v/GHSA-gfwj-fwqj-fp3v.json index eaaabaebd26..43bd0ccc5fa 100644 --- a/advisories/github-reviewed/2022/05/GHSA-gfwj-fwqj-fp3v/GHSA-gfwj-fwqj-fp3v.json +++ b/advisories/github-reviewed/2022/05/GHSA-gfwj-fwqj-fp3v/GHSA-gfwj-fwqj-fp3v.json @@ -85,6 +85,10 @@ "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpujan2022.html" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpuoct2021.html" diff --git a/advisories/github-reviewed/2022/05/GHSA-h3ch-5pp2-vh6w/GHSA-h3ch-5pp2-vh6w.json b/advisories/github-reviewed/2022/05/GHSA-h3ch-5pp2-vh6w/GHSA-h3ch-5pp2-vh6w.json index 8d14c103b70..42e32c62511 100644 --- a/advisories/github-reviewed/2022/05/GHSA-h3ch-5pp2-vh6w/GHSA-h3ch-5pp2-vh6w.json +++ b/advisories/github-reviewed/2022/05/GHSA-h3ch-5pp2-vh6w/GHSA-h3ch-5pp2-vh6w.json @@ -67,6 +67,10 @@ "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20220629-0003/" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "PACKAGE", "url": "https://github.com/apache/tomcat" diff --git a/advisories/github-reviewed/2022/05/GHSA-h66p-m766-33fv/GHSA-h66p-m766-33fv.json b/advisories/github-reviewed/2022/05/GHSA-h66p-m766-33fv/GHSA-h66p-m766-33fv.json new file mode 100644 index 00000000000..29a6511f5f6 --- /dev/null +++ b/advisories/github-reviewed/2022/05/GHSA-h66p-m766-33fv/GHSA-h66p-m766-33fv.json @@ -0,0 +1,59 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-h66p-m766-33fv", + "modified": "2022-07-27T20:57:55Z", + "published": "2022-05-13T01:48:37Z", + "aliases": [ + "CVE-2018-1000403" + ], + "summary": "AWS CodeDeploy Plugin stored AWS Secret Key in plain text", + "details": "Jenkins project Jenkins AWS CodeDeploy Plugin version 1.19 and earlier contains a Insufficiently Protected Credentials vulnerability in AWSCodeDeployPublisher.java that can result in Credentials Disclosure. This attack appears to be exploitable via local file access. \n\nAWS CodeDeploy Plugin 1.20 and newer stores the AWS Secret Key encrypted in the configuration files on disk and no longer transfers it to users viewing the configuration form in plain text. Existing jobs need to have their configuration saved for existing plain text secret keys to be overwritten.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Maven", + "name": "com.amazonaws:codedeploy" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.20" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-1000403" + }, + { + "type": "WEB", + "url": "https://jenkins.io/security/advisory/2018-06-25/#SECURITY-833" + }, + { + "type": "PACKAGE", + "url": "https://github.com/jenkinsci/aws-codedeploy-plugin" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-522" + ], + "severity": "HIGH", + "github_reviewed": true + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2022/05/GHSA-hh26-6xwr-ggv7/GHSA-hh26-6xwr-ggv7.json b/advisories/github-reviewed/2022/05/GHSA-hh26-6xwr-ggv7/GHSA-hh26-6xwr-ggv7.json index 9d71366ac35..4039c2eca98 100644 --- a/advisories/github-reviewed/2022/05/GHSA-hh26-6xwr-ggv7/GHSA-hh26-6xwr-ggv7.json +++ b/advisories/github-reviewed/2022/05/GHSA-hh26-6xwr-ggv7/GHSA-hh26-6xwr-ggv7.json @@ -70,6 +70,10 @@ "type": "WEB", "url": "https://tanzu.vmware.com/security/cve-2022-22970" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "PACKAGE", "url": "https://github.com/spring-projects/spring-framework" diff --git a/advisories/github-reviewed/2022/05/GHSA-hh32-7344-cg2f/GHSA-hh32-7344-cg2f.json b/advisories/github-reviewed/2022/05/GHSA-hh32-7344-cg2f/GHSA-hh32-7344-cg2f.json index 303a2aeaa1a..afcc8d2226c 100644 --- a/advisories/github-reviewed/2022/05/GHSA-hh32-7344-cg2f/GHSA-hh32-7344-cg2f.json +++ b/advisories/github-reviewed/2022/05/GHSA-hh32-7344-cg2f/GHSA-hh32-7344-cg2f.json @@ -67,6 +67,10 @@ "type": "WEB", "url": "https://tanzu.vmware.com/security/cve-2022-22978" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "PACKAGE", "url": "https://github.com/spring-projects/spring-security" diff --git a/advisories/github-reviewed/2022/05/GHSA-rqph-vqwm-22vc/GHSA-rqph-vqwm-22vc.json b/advisories/github-reviewed/2022/05/GHSA-rqph-vqwm-22vc/GHSA-rqph-vqwm-22vc.json index 3c13b0b8396..54f49a29b33 100644 --- a/advisories/github-reviewed/2022/05/GHSA-rqph-vqwm-22vc/GHSA-rqph-vqwm-22vc.json +++ b/advisories/github-reviewed/2022/05/GHSA-rqph-vqwm-22vc/GHSA-rqph-vqwm-22vc.json @@ -69,6 +69,10 @@ { "type": "WEB", "url": "https://tanzu.vmware.com/security/cve-2022-22971" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" } ], "database_specific": { diff --git a/advisories/github-reviewed/2022/05/GHSA-rv87-vcv4-fjvr/GHSA-rv87-vcv4-fjvr.json b/advisories/github-reviewed/2022/05/GHSA-rv87-vcv4-fjvr/GHSA-rv87-vcv4-fjvr.json new file mode 100644 index 00000000000..c5e3df578f7 --- /dev/null +++ b/advisories/github-reviewed/2022/05/GHSA-rv87-vcv4-fjvr/GHSA-rv87-vcv4-fjvr.json @@ -0,0 +1,70 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-rv87-vcv4-fjvr", + "modified": "2022-07-27T21:12:17Z", + "published": "2022-05-14T03:05:26Z", + "aliases": [ + "CVE-2018-1000606" + ], + "summary": "URLTrigger Plugin server-side request forgery vulnerability", + "details": "A server-side request forgery vulnerability exists in Jenkins URLTrigger Plugin 0.41 and earlier in URLTrigger.java that allows attackers with Overall/Read access to cause Jenkins to send a GET request to a specified URL. As of version 0.43, this form validation method no longer connects to a user provided URL.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Maven", + "name": "org.jenkins-ci.plugins:urltrigger" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.43" + } + ] + } + ], + "database_specific": { + "last_known_affected_version_range": "<= 0.41" + } + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-1000606" + }, + { + "type": "WEB", + "url": "https://github.com/jenkinsci/urltrigger-plugin/commit/46220e69c220bacf8eb23911c8feba9dd68d1a26" + }, + { + "type": "WEB", + "url": "https://github.com/jenkinsci/urltrigger-plugin/commit/aec43e370550b26636aa9cab0f23a5cbcffdc44f" + }, + { + "type": "WEB", + "url": "https://jenkins.io/security/advisory/2018-06-25/#SECURITY-819" + }, + { + "type": "PACKAGE", + "url": "https://github.com/jenkinsci/urltrigger-plugin" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": true + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2022/05/GHSA-wx54-3278-m5g4/GHSA-wx54-3278-m5g4.json b/advisories/github-reviewed/2022/05/GHSA-wx54-3278-m5g4/GHSA-wx54-3278-m5g4.json index e846e450c02..58c4ff7db41 100644 --- a/advisories/github-reviewed/2022/05/GHSA-wx54-3278-m5g4/GHSA-wx54-3278-m5g4.json +++ b/advisories/github-reviewed/2022/05/GHSA-wx54-3278-m5g4/GHSA-wx54-3278-m5g4.json @@ -67,6 +67,10 @@ "type": "WEB", "url": "https://tanzu.vmware.com/security/cve-2022-22976" }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujul2022.html" + }, { "type": "PACKAGE", "url": "https://github.com/spring-projects/spring-security" diff --git a/advisories/github-reviewed/2022/05/GHSA-x3pr-fcgm-wjgc/GHSA-x3pr-fcgm-wjgc.json b/advisories/github-reviewed/2022/05/GHSA-x3pr-fcgm-wjgc/GHSA-x3pr-fcgm-wjgc.json new file mode 100644 index 00000000000..9371f616e80 --- /dev/null +++ b/advisories/github-reviewed/2022/05/GHSA-x3pr-fcgm-wjgc/GHSA-x3pr-fcgm-wjgc.json @@ -0,0 +1,63 @@ +{ + "schema_version": "1.2.0", + "id": "GHSA-x3pr-fcgm-wjgc", + "modified": "2022-07-27T20:55:20Z", + "published": "2022-05-24T17:08:46Z", + "aliases": [ + "CVE-2020-2111" + ], + "summary": "Subversion Plugin stored XSS vulnerability before v2.13.1", + "details": "Jenkins Subversion Plugin 2.13.0 and earlier does not escape the error message for the Project Repository Base URL field form validation, resulting in a stored cross-site scripting vulnerability. Subversion Plugin 2.13.1 escapes the affected part of the error message.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Maven", + "name": "org.jenkins-ci.plugins:subversion" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.13.1" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-2111" + }, + { + "type": "WEB", + "url": "https://jenkins.io/security/advisory/2020-02-12/#SECURITY-1725" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2020/02/12/3" + }, + { + "type": "PACKAGE", + "url": "https://github.com/jenkinsci/subversion-plugin" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": true + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2022/07/GHSA-jjc5-fp7p-6f8w/GHSA-jjc5-fp7p-6f8w.json b/advisories/github-reviewed/2022/07/GHSA-jjc5-fp7p-6f8w/GHSA-jjc5-fp7p-6f8w.json index c929d73b156..710683ccc12 100644 --- a/advisories/github-reviewed/2022/07/GHSA-jjc5-fp7p-6f8w/GHSA-jjc5-fp7p-6f8w.json +++ b/advisories/github-reviewed/2022/07/GHSA-jjc5-fp7p-6f8w/GHSA-jjc5-fp7p-6f8w.json @@ -1,10 +1,10 @@ { "schema_version": "1.2.0", "id": "GHSA-jjc5-fp7p-6f8w", - "modified": "2022-07-15T21:39:14Z", + "modified": "2022-07-27T04:30:50Z", "published": "2022-07-15T21:39:14Z", "aliases": [ - + "CVE-2022-31179" ], "summary": "Shescape prior to 1.5.8 vulnerable to insufficient escaping of line feeds for CMD", "details": "### Impact\n\nThis impacts users that use Shescape (any API function) to escape arguments for **cmd.exe** on **Windows**. An attacker can omit all arguments following their input by including a line feed character (`'\\n'`) in the payload. Example:\n\n```javascript\nimport cp from \"node:child_process\";\nimport * as shescape from \"shescape\";\n\n// 1. Prerequisites\nconst options = {\n shell: \"cmd.exe\",\n};\n\n// 2. Attack\nconst payload = \"attacker\\n\";\n\n// 3. Usage\nlet escapedPayload;\nescapedPayload = shescape.escape(payload, options);\n// Or\nescapedPayload = shescape.escapeAll([payload], options)[0];\n// Or\nescapedPayload = shescape.quote(payload, options);\n// Or\nescapedPayload = shescape.quoteAll([payload], options)[0];\n\ncp.execSync(`echo Hello ${escapedPayload}! How are you doing?`, options);\n// Outputs: \"Hello attacker\"\n```\n\n> **Note**: `execSync` is just illustrative here, all of `exec`, `execFile`, `execFileSync`, `fork`, `spawn`, and `spawnSync` can be attacked using a line feed character if CMD is the shell being used.\n\n### Patches\n\nThis bug has been patched in [v1.5.8] which you can upgrade to now. No further changes are required.\n\n### Workarounds\n\nAlternatively, line feed characters (`'\\n'`) can be stripped out manually or the user input can be made the last argument (this only limits the impact).\n\n### References\n\n- https://github.com/ericcornelissen/shescape/pull/332\n- https://github.com/ericcornelissen/shescape/releases/tag/v1.5.8\n\n### For more information\n\nIf you have any questions or comments about this advisory:\n\n- Comment on https://github.com/ericcornelissen/shescape/pull/332\n- Open an issue at https://github.com/ericcornelissen/shescape/issues (_New issue_ > _Question_ > _Get started_)\n\n[v1.5.8]: https://github.com/ericcornelissen/shescape/releases/tag/v1.5.8\n", diff --git a/advisories/unreviewed/2022/05/GHSA-h66p-m766-33fv/GHSA-h66p-m766-33fv.json b/advisories/unreviewed/2022/05/GHSA-h66p-m766-33fv/GHSA-h66p-m766-33fv.json deleted file mode 100644 index cc82c25a111..00000000000 --- a/advisories/unreviewed/2022/05/GHSA-h66p-m766-33fv/GHSA-h66p-m766-33fv.json +++ /dev/null @@ -1,36 +0,0 @@ -{ - "schema_version": "1.2.0", - "id": "GHSA-h66p-m766-33fv", - "modified": "2022-05-13T01:48:37Z", - "published": "2022-05-13T01:48:37Z", - "aliases": [ - "CVE-2018-1000403" - ], - "details": "Jenkins project Jenkins AWS CodeDeploy Plugin version 1.19 and earlier contains a Insufficiently Protected Credentials vulnerability in AWSCodeDeployPublisher.java that can result in Credentials Disclosure. This attack appear to be exploitable via local file access. This vulnerability appears to have been fixed in 1.20 and later.", - "severity": [ - { - "type": "CVSS_V3", - "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" - } - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-1000403" - }, - { - "type": "WEB", - "url": "https://jenkins.io/security/advisory/2018-06-25/#SECURITY-833" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-522" - ], - "severity": "HIGH", - "github_reviewed": false - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-rv87-vcv4-fjvr/GHSA-rv87-vcv4-fjvr.json b/advisories/unreviewed/2022/05/GHSA-rv87-vcv4-fjvr/GHSA-rv87-vcv4-fjvr.json deleted file mode 100644 index 176657e636a..00000000000 --- a/advisories/unreviewed/2022/05/GHSA-rv87-vcv4-fjvr/GHSA-rv87-vcv4-fjvr.json +++ /dev/null @@ -1,36 +0,0 @@ -{ - "schema_version": "1.2.0", - "id": "GHSA-rv87-vcv4-fjvr", - "modified": "2022-05-14T03:05:26Z", - "published": "2022-05-14T03:05:26Z", - "aliases": [ - "CVE-2018-1000606" - ], - "details": "A server-side request forgery vulnerability exists in Jenkins URLTrigger Plugin 0.41 and earlier in URLTrigger.java that allows attackers with Overall/Read access to cause Jenkins to send a GET request to a specified URL.", - "severity": [ - { - "type": "CVSS_V3", - "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" - } - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-1000606" - }, - { - "type": "WEB", - "url": "https://jenkins.io/security/advisory/2018-06-25/#SECURITY-819" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-918" - ], - "severity": "MODERATE", - "github_reviewed": false - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-x3pr-fcgm-wjgc/GHSA-x3pr-fcgm-wjgc.json b/advisories/unreviewed/2022/05/GHSA-x3pr-fcgm-wjgc/GHSA-x3pr-fcgm-wjgc.json deleted file mode 100644 index 2d1c32d0006..00000000000 --- a/advisories/unreviewed/2022/05/GHSA-x3pr-fcgm-wjgc/GHSA-x3pr-fcgm-wjgc.json +++ /dev/null @@ -1,37 +0,0 @@ -{ - "schema_version": "1.2.0", - "id": "GHSA-x3pr-fcgm-wjgc", - "modified": "2022-05-24T17:08:46Z", - "published": "2022-05-24T17:08:46Z", - "aliases": [ - "CVE-2020-2111" - ], - "details": "Jenkins Subversion Plugin 2.13.0 and earlier does not escape the error message for the Project Repository Base URL field form validation, resulting in a stored cross-site scripting vulnerability.", - "severity": [ - - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-2111" - }, - { - "type": "WEB", - "url": "https://jenkins.io/security/advisory/2020-02-12/#SECURITY-1725" - }, - { - "type": "WEB", - "url": "http://www.openwall.com/lists/oss-security/2020/02/12/3" - } - ], - "database_specific": { - "cwe_ids": [ - - ], - "severity": "LOW", - "github_reviewed": false - } -} \ No newline at end of file