diff --git a/advisories/github-reviewed/2024/03/GHSA-9w38-p64v-xpmv/GHSA-9w38-p64v-xpmv.json b/advisories/github-reviewed/2024/03/GHSA-9w38-p64v-xpmv/GHSA-9w38-p64v-xpmv.json index 29095da1c50..d54733653da 100644 --- a/advisories/github-reviewed/2024/03/GHSA-9w38-p64v-xpmv/GHSA-9w38-p64v-xpmv.json +++ b/advisories/github-reviewed/2024/03/GHSA-9w38-p64v-xpmv/GHSA-9w38-p64v-xpmv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9w38-p64v-xpmv", - "modified": "2024-05-02T18:47:31Z", + "modified": "2024-11-04T21:24:14Z", "published": "2024-03-21T09:31:14Z", "aliases": [ "CVE-2024-29133" @@ -12,6 +12,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N" } ], "affected": [ diff --git a/advisories/github-reviewed/2024/04/GHSA-3494-cfwf-56hw/GHSA-3494-cfwf-56hw.json b/advisories/github-reviewed/2024/04/GHSA-3494-cfwf-56hw/GHSA-3494-cfwf-56hw.json index 211918d734a..52b1033ff52 100644 --- a/advisories/github-reviewed/2024/04/GHSA-3494-cfwf-56hw/GHSA-3494-cfwf-56hw.json +++ b/advisories/github-reviewed/2024/04/GHSA-3494-cfwf-56hw/GHSA-3494-cfwf-56hw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3494-cfwf-56hw", - "modified": "2024-05-10T21:49:12Z", + "modified": "2024-11-04T21:24:44Z", "published": "2024-04-28T00:30:22Z", "aliases": [ "CVE-2024-33851" @@ -9,7 +9,14 @@ "summary": "mdanter/ecc affected by timing vulnerability in cryptographic side-channels", "details": "phpecc, as used in **all versions** of mdanter/ecc, as well as paragonie/ecc before 2.0.1, has a branch-based timing leak in Point addition. (This Composer package is also known as phpecc/phpecc on GitHub, previously known as the Matyas Danter ECC library.)\n\nParagon Initiative Enterprises [hard-forked phpecc/phpecc](https://github.com/phpecc/phpecc/issues/289) and discovered the issue in the original code, then released v2.0.1 which fixes the vulnerability. [The upstream code](https://github.com/phpecc/phpecc) is no longer maintained and remains vulnerable for all versions.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N" + } ], "affected": [ { diff --git a/advisories/github-reviewed/2024/10/GHSA-66c4-2g2v-54qw/GHSA-66c4-2g2v-54qw.json b/advisories/github-reviewed/2024/10/GHSA-66c4-2g2v-54qw/GHSA-66c4-2g2v-54qw.json index aace2d02fea..a8c23e3c682 100644 --- a/advisories/github-reviewed/2024/10/GHSA-66c4-2g2v-54qw/GHSA-66c4-2g2v-54qw.json +++ b/advisories/github-reviewed/2024/10/GHSA-66c4-2g2v-54qw/GHSA-66c4-2g2v-54qw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-66c4-2g2v-54qw", - "modified": "2024-10-29T20:29:13Z", + "modified": "2024-11-04T21:25:35Z", "published": "2024-10-29T18:30:36Z", "aliases": [ "CVE-2024-10452" @@ -44,6 +44,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10452" }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-66c4-2g2v-54qw" + }, { "type": "PACKAGE", "url": "https://github.com/grafana/grafana" diff --git a/advisories/github-reviewed/2024/10/GHSA-762v-rq7q-ff97/GHSA-762v-rq7q-ff97.json b/advisories/github-reviewed/2024/10/GHSA-762v-rq7q-ff97/GHSA-762v-rq7q-ff97.json index 4c5dde647c1..0e3c9b4d7c2 100644 --- a/advisories/github-reviewed/2024/10/GHSA-762v-rq7q-ff97/GHSA-762v-rq7q-ff97.json +++ b/advisories/github-reviewed/2024/10/GHSA-762v-rq7q-ff97/GHSA-762v-rq7q-ff97.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-762v-rq7q-ff97", - "modified": "2024-10-29T16:13:16Z", + "modified": "2024-11-04T21:25:24Z", "published": "2024-10-29T09:30:51Z", "aliases": [ "CVE-2024-47401" @@ -44,6 +44,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47401" }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-762v-rq7q-ff97" + }, { "type": "PACKAGE", "url": "https://github.com/mattermost/mattermost" diff --git a/advisories/github-reviewed/2024/10/GHSA-g376-m3h3-mj4r/GHSA-g376-m3h3-mj4r.json b/advisories/github-reviewed/2024/10/GHSA-g376-m3h3-mj4r/GHSA-g376-m3h3-mj4r.json index 59cd7d54e87..eb00d5a63c5 100644 --- a/advisories/github-reviewed/2024/10/GHSA-g376-m3h3-mj4r/GHSA-g376-m3h3-mj4r.json +++ b/advisories/github-reviewed/2024/10/GHSA-g376-m3h3-mj4r/GHSA-g376-m3h3-mj4r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g376-m3h3-mj4r", - "modified": "2024-10-29T16:13:12Z", + "modified": "2024-11-04T21:25:15Z", "published": "2024-10-29T09:30:51Z", "aliases": [ "CVE-2024-50052"