From 2396fd1ee67294ff6782cde208e663bc0bc8456f Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 8 Feb 2023 18:06:24 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-8xqr-4cpm-wx7g.json | 4 -- .../GHSA-j4mr-9xw3-c9jx.json | 4 -- .../GHSA-vmhw-fhj6-m3g5.json | 4 -- .../GHSA-xm28-fw2x-fqv2.json | 4 -- .../GHSA-xrmp-99wj-p6jc.json | 4 -- .../GHSA-28xh-wpgr-7fm8.json | 4 -- .../GHSA-4vmm-mhcq-4x9j.json | 4 -- .../GHSA-57cf-349j-352g.json | 4 -- .../GHSA-5v72-xg48-5rpm.json | 4 -- .../GHSA-73cw-jxmm-qpgh.json | 4 -- .../GHSA-8f93-rv4p-x4jw.json | 4 -- .../GHSA-8w57-jfpm-945m.json | 4 -- .../GHSA-g74r-ffvr-5q9f.json | 4 -- .../GHSA-gc94-6w89-hpqr.json | 8 ++- .../GHSA-h9x2-5rm7-x4gm.json | 4 -- .../GHSA-mxjr-xmcg-fg7w.json | 4 -- .../GHSA-g8m7-qhv7-9h5x.json | 4 -- .../GHSA-65p8-3hm4-h9h8.json | 4 -- .../GHSA-rch7-f4h5-x9rj.json | 4 -- .../GHSA-3fw8-66wf-pr7m.json | 8 ++- .../GHSA-4x7c-cx64-49w8.json | 4 -- .../GHSA-9xgp-hfw7-73rq.json | 4 -- .../GHSA-c6h2-mpc6-232h.json | 4 -- .../GHSA-chgg-rrmv-5q7x.json | 4 -- .../GHSA-mpcx-8qqw-rmcq.json | 4 -- .../GHSA-q9r2-f3vc-rjg8.json | 4 -- .../GHSA-qrg3-f6h6-vq8q.json | 4 -- .../GHSA-wx84-69jh-jjp2.json | 4 -- .../GHSA-72p9-6gc7-q93r.json | 33 ++++++++++-- .../GHSA-78cj-2m29-q5r9.json | 50 ++++++++++++++++--- .../GHSA-cmg8-5c63-pg95.json | 39 ++++++++++++--- .../GHSA-p258-xmh3-72pv.json | 31 ++++++++++-- .../GHSA-rqhg-cxfr-8xqw.json | 46 +++++++++++++++-- 33 files changed, 178 insertions(+), 141 deletions(-) rename advisories/{unreviewed => github-reviewed}/2022/05/GHSA-72p9-6gc7-q93r/GHSA-72p9-6gc7-q93r.json (68%) rename advisories/{unreviewed => github-reviewed}/2022/05/GHSA-78cj-2m29-q5r9/GHSA-78cj-2m29-q5r9.json (59%) rename advisories/{unreviewed => github-reviewed}/2022/05/GHSA-cmg8-5c63-pg95/GHSA-cmg8-5c63-pg95.json (65%) rename advisories/{unreviewed => github-reviewed}/2022/05/GHSA-p258-xmh3-72pv/GHSA-p258-xmh3-72pv.json (68%) rename advisories/{unreviewed => github-reviewed}/2022/05/GHSA-rqhg-cxfr-8xqw/GHSA-rqhg-cxfr-8xqw.json (61%) diff --git a/advisories/github-reviewed/2019/05/GHSA-8xqr-4cpm-wx7g/GHSA-8xqr-4cpm-wx7g.json b/advisories/github-reviewed/2019/05/GHSA-8xqr-4cpm-wx7g/GHSA-8xqr-4cpm-wx7g.json index e0edaaba484..e42b56e62aa 100644 --- a/advisories/github-reviewed/2019/05/GHSA-8xqr-4cpm-wx7g/GHSA-8xqr-4cpm-wx7g.json +++ b/advisories/github-reviewed/2019/05/GHSA-8xqr-4cpm-wx7g/GHSA-8xqr-4cpm-wx7g.json @@ -41,10 +41,6 @@ "type": "WEB", "url": "https://github.com/tanem/react-svg/pull/57/commits/ec7de5d678f53a085cee1348cb1aa069c9fc42fb" }, - { - "type": "WEB", - "url": "https://nodesecurity.io/advisories/648" - }, { "type": "WEB", "url": "https://www.npmjs.com/advisories/648" diff --git a/advisories/github-reviewed/2019/05/GHSA-j4mr-9xw3-c9jx/GHSA-j4mr-9xw3-c9jx.json b/advisories/github-reviewed/2019/05/GHSA-j4mr-9xw3-c9jx/GHSA-j4mr-9xw3-c9jx.json index c63b94e0f8c..4e6caf7eade 100644 --- a/advisories/github-reviewed/2019/05/GHSA-j4mr-9xw3-c9jx/GHSA-j4mr-9xw3-c9jx.json +++ b/advisories/github-reviewed/2019/05/GHSA-j4mr-9xw3-c9jx/GHSA-j4mr-9xw3-c9jx.json @@ -37,10 +37,6 @@ "type": "WEB", "url": "https://hackerone.com/reports/321692" }, - { - "type": "WEB", - "url": "https://nodesecurity.io/advisories/660" - }, { "type": "WEB", "url": "https://www.npmjs.com/advisories/660" diff --git a/advisories/github-reviewed/2019/05/GHSA-vmhw-fhj6-m3g5/GHSA-vmhw-fhj6-m3g5.json b/advisories/github-reviewed/2019/05/GHSA-vmhw-fhj6-m3g5/GHSA-vmhw-fhj6-m3g5.json index 19ff203da00..f4d58476341 100644 --- a/advisories/github-reviewed/2019/05/GHSA-vmhw-fhj6-m3g5/GHSA-vmhw-fhj6-m3g5.json +++ b/advisories/github-reviewed/2019/05/GHSA-vmhw-fhj6-m3g5/GHSA-vmhw-fhj6-m3g5.json @@ -41,10 +41,6 @@ "type": "WEB", "url": "https://hackerone.com/reports/330349" }, - { - "type": "WEB", - "url": "https://nodesecurity.io/advisories/656" - }, { "type": "WEB", "url": "https://www.npmjs.com/advisories/656" diff --git a/advisories/github-reviewed/2019/05/GHSA-xm28-fw2x-fqv2/GHSA-xm28-fw2x-fqv2.json b/advisories/github-reviewed/2019/05/GHSA-xm28-fw2x-fqv2/GHSA-xm28-fw2x-fqv2.json index 5b7e18bbd6d..cda68758abb 100644 --- a/advisories/github-reviewed/2019/05/GHSA-xm28-fw2x-fqv2/GHSA-xm28-fw2x-fqv2.json +++ b/advisories/github-reviewed/2019/05/GHSA-xm28-fw2x-fqv2/GHSA-xm28-fw2x-fqv2.json @@ -44,10 +44,6 @@ "type": "WEB", "url": "https://github.com/strongloop/node-foreman/blob/v2.0.0/forward.js#L30" }, - { - "type": "WEB", - "url": "https://nodesecurity.io/advisories/645" - }, { "type": "WEB", "url": "https://snyk.io/vuln/npm:foreman:20180429" diff --git a/advisories/github-reviewed/2019/05/GHSA-xrmp-99wj-p6jc/GHSA-xrmp-99wj-p6jc.json b/advisories/github-reviewed/2019/05/GHSA-xrmp-99wj-p6jc/GHSA-xrmp-99wj-p6jc.json index 564e2fc1855..5a3a81bdf7d 100644 --- a/advisories/github-reviewed/2019/05/GHSA-xrmp-99wj-p6jc/GHSA-xrmp-99wj-p6jc.json +++ b/advisories/github-reviewed/2019/05/GHSA-xrmp-99wj-p6jc/GHSA-xrmp-99wj-p6jc.json @@ -40,10 +40,6 @@ "type": "WEB", "url": "https://hackerone.com/reports/310446" }, - { - "type": "WEB", - "url": "https://nodesecurity.io/advisories/611" - }, { "type": "WEB", "url": "https://snyk.io/vuln/npm:deap:20180415" diff --git a/advisories/github-reviewed/2019/06/GHSA-28xh-wpgr-7fm8/GHSA-28xh-wpgr-7fm8.json b/advisories/github-reviewed/2019/06/GHSA-28xh-wpgr-7fm8/GHSA-28xh-wpgr-7fm8.json index 13b2b44d6ce..5fdd95779da 100644 --- a/advisories/github-reviewed/2019/06/GHSA-28xh-wpgr-7fm8/GHSA-28xh-wpgr-7fm8.json +++ b/advisories/github-reviewed/2019/06/GHSA-28xh-wpgr-7fm8/GHSA-28xh-wpgr-7fm8.json @@ -45,10 +45,6 @@ "type": "WEB", "url": "https://hackerone.com/reports/319473" }, - { - "type": "WEB", - "url": "https://nodesecurity.io/advisories/663" - }, { "type": "WEB", "url": "https://www.npmjs.com/advisories/663" diff --git a/advisories/github-reviewed/2019/06/GHSA-4vmm-mhcq-4x9j/GHSA-4vmm-mhcq-4x9j.json b/advisories/github-reviewed/2019/06/GHSA-4vmm-mhcq-4x9j/GHSA-4vmm-mhcq-4x9j.json index e7f77b292e9..acb9f7c3ff2 100644 --- a/advisories/github-reviewed/2019/06/GHSA-4vmm-mhcq-4x9j/GHSA-4vmm-mhcq-4x9j.json +++ b/advisories/github-reviewed/2019/06/GHSA-4vmm-mhcq-4x9j/GHSA-4vmm-mhcq-4x9j.json @@ -44,10 +44,6 @@ "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1577703" }, - { - "type": "WEB", - "url": "https://nodesecurity.io/advisories/568" - }, { "type": "WEB", "url": "https://snyk.io/vuln/npm:constantinople:20180421" diff --git a/advisories/github-reviewed/2019/06/GHSA-57cf-349j-352g/GHSA-57cf-349j-352g.json b/advisories/github-reviewed/2019/06/GHSA-57cf-349j-352g/GHSA-57cf-349j-352g.json index ed57247a69f..f1311e95977 100644 --- a/advisories/github-reviewed/2019/06/GHSA-57cf-349j-352g/GHSA-57cf-349j-352g.json +++ b/advisories/github-reviewed/2019/06/GHSA-57cf-349j-352g/GHSA-57cf-349j-352g.json @@ -37,10 +37,6 @@ "type": "WEB", "url": "https://hackerone.com/reports/320269" }, - { - "type": "WEB", - "url": "https://nodesecurity.io/advisories/653" - }, { "type": "WEB", "url": "https://www.npmjs.com/advisories/653" diff --git a/advisories/github-reviewed/2019/06/GHSA-5v72-xg48-5rpm/GHSA-5v72-xg48-5rpm.json b/advisories/github-reviewed/2019/06/GHSA-5v72-xg48-5rpm/GHSA-5v72-xg48-5rpm.json index 64eb43a48b1..6b87002bd69 100644 --- a/advisories/github-reviewed/2019/06/GHSA-5v72-xg48-5rpm/GHSA-5v72-xg48-5rpm.json +++ b/advisories/github-reviewed/2019/06/GHSA-5v72-xg48-5rpm/GHSA-5v72-xg48-5rpm.json @@ -59,10 +59,6 @@ "type": "WEB", "url": "https://github.com/websockets/ws/commit/c4fe46608acd61fbf7397eadc47378903f95b78a" }, - { - "type": "WEB", - "url": "https://nodesecurity.io/advisories/550" - }, { "type": "WEB", "url": "https://snyk.io/vuln/npm:ws:20171108" diff --git a/advisories/github-reviewed/2019/06/GHSA-73cw-jxmm-qpgh/GHSA-73cw-jxmm-qpgh.json b/advisories/github-reviewed/2019/06/GHSA-73cw-jxmm-qpgh/GHSA-73cw-jxmm-qpgh.json index 81724356da5..d1afd7fd0d8 100644 --- a/advisories/github-reviewed/2019/06/GHSA-73cw-jxmm-qpgh/GHSA-73cw-jxmm-qpgh.json +++ b/advisories/github-reviewed/2019/06/GHSA-73cw-jxmm-qpgh/GHSA-73cw-jxmm-qpgh.json @@ -41,10 +41,6 @@ "type": "WEB", "url": "https://github.com/DCKT/localhost-now/blob/master/lib/app.js#L17" }, - { - "type": "WEB", - "url": "https://nodesecurity.io/advisories/655" - }, { "type": "WEB", "url": "https://www.npmjs.com/advisories/655" diff --git a/advisories/github-reviewed/2019/06/GHSA-8f93-rv4p-x4jw/GHSA-8f93-rv4p-x4jw.json b/advisories/github-reviewed/2019/06/GHSA-8f93-rv4p-x4jw/GHSA-8f93-rv4p-x4jw.json index 77525eaf4ef..6c7aa77e249 100644 --- a/advisories/github-reviewed/2019/06/GHSA-8f93-rv4p-x4jw/GHSA-8f93-rv4p-x4jw.json +++ b/advisories/github-reviewed/2019/06/GHSA-8f93-rv4p-x4jw/GHSA-8f93-rv4p-x4jw.json @@ -37,10 +37,6 @@ "type": "WEB", "url": "https://hackerone.com/reports/319465" }, - { - "type": "WEB", - "url": "https://nodesecurity.io/advisories/662" - }, { "type": "WEB", "url": "https://www.npmjs.com/advisories/662" diff --git a/advisories/github-reviewed/2019/06/GHSA-8w57-jfpm-945m/GHSA-8w57-jfpm-945m.json b/advisories/github-reviewed/2019/06/GHSA-8w57-jfpm-945m/GHSA-8w57-jfpm-945m.json index bba3f0f81f2..7907e4b190e 100644 --- a/advisories/github-reviewed/2019/06/GHSA-8w57-jfpm-945m/GHSA-8w57-jfpm-945m.json +++ b/advisories/github-reviewed/2019/06/GHSA-8w57-jfpm-945m/GHSA-8w57-jfpm-945m.json @@ -41,10 +41,6 @@ "type": "WEB", "url": "https://github.com/TooTallNate/node-http-proxy-agent/blob/2.0.0/index.js#L80" }, - { - "type": "WEB", - "url": "https://nodesecurity.io/advisories/607" - }, { "type": "WEB", "url": "https://www.npmjs.com/advisories/607" diff --git a/advisories/github-reviewed/2019/06/GHSA-g74r-ffvr-5q9f/GHSA-g74r-ffvr-5q9f.json b/advisories/github-reviewed/2019/06/GHSA-g74r-ffvr-5q9f/GHSA-g74r-ffvr-5q9f.json index 7f69a267c05..b6f70f7c09f 100644 --- a/advisories/github-reviewed/2019/06/GHSA-g74r-ffvr-5q9f/GHSA-g74r-ffvr-5q9f.json +++ b/advisories/github-reviewed/2019/06/GHSA-g74r-ffvr-5q9f/GHSA-g74r-ffvr-5q9f.json @@ -83,10 +83,6 @@ "type": "WEB", "url": "https://gist.github.com/ChALkeR/c2d2fd3f1d72d51ad883df195be03a85" }, - { - "type": "WEB", - "url": "https://nodesecurity.io/advisories/597" - }, { "type": "WEB", "url": "https://www.npmjs.com/advisories/597" diff --git a/advisories/github-reviewed/2019/06/GHSA-gc94-6w89-hpqr/GHSA-gc94-6w89-hpqr.json b/advisories/github-reviewed/2019/06/GHSA-gc94-6w89-hpqr/GHSA-gc94-6w89-hpqr.json index 8e71e76f54e..fccd157a4a7 100644 --- a/advisories/github-reviewed/2019/06/GHSA-gc94-6w89-hpqr/GHSA-gc94-6w89-hpqr.json +++ b/advisories/github-reviewed/2019/06/GHSA-gc94-6w89-hpqr/GHSA-gc94-6w89-hpqr.json @@ -45,10 +45,6 @@ "type": "PACKAGE", "url": "https://github.com/pillys/fs-path" }, - { - "type": "WEB", - "url": "https://nodesecurity.io/advisories/661" - }, { "type": "WEB", "url": "https://www.npmjs.com/advisories/661" @@ -60,6 +56,8 @@ "CWE-77" ], "severity": "HIGH", - "github_reviewed": true + "github_reviewed": true, + "github_reviewed_at": "2019-06-12T16:34:26Z", + "nvd_published_at": null } } \ No newline at end of file diff --git a/advisories/github-reviewed/2019/06/GHSA-h9x2-5rm7-x4gm/GHSA-h9x2-5rm7-x4gm.json b/advisories/github-reviewed/2019/06/GHSA-h9x2-5rm7-x4gm/GHSA-h9x2-5rm7-x4gm.json index 842c1202636..81d50813e6b 100644 --- a/advisories/github-reviewed/2019/06/GHSA-h9x2-5rm7-x4gm/GHSA-h9x2-5rm7-x4gm.json +++ b/advisories/github-reviewed/2019/06/GHSA-h9x2-5rm7-x4gm/GHSA-h9x2-5rm7-x4gm.json @@ -41,10 +41,6 @@ "type": "WEB", "url": "https://github.com/vdemedes/secure-compare/pull/1" }, - { - "type": "WEB", - "url": "https://nodesecurity.io/advisories/50" - }, { "type": "WEB", "url": "https://www.npmjs.com/advisories/50" diff --git a/advisories/github-reviewed/2019/06/GHSA-mxjr-xmcg-fg7w/GHSA-mxjr-xmcg-fg7w.json b/advisories/github-reviewed/2019/06/GHSA-mxjr-xmcg-fg7w/GHSA-mxjr-xmcg-fg7w.json index c8d8a9f482f..eb90ed06b33 100644 --- a/advisories/github-reviewed/2019/06/GHSA-mxjr-xmcg-fg7w/GHSA-mxjr-xmcg-fg7w.json +++ b/advisories/github-reviewed/2019/06/GHSA-mxjr-xmcg-fg7w/GHSA-mxjr-xmcg-fg7w.json @@ -44,10 +44,6 @@ "type": "WEB", "url": "https://github.com/muzzley/mobile-icon-resizer/commit/a6c50f884bd282d74ab77e1fce6317d5d0dd2f0f" }, - { - "type": "WEB", - "url": "https://nodesecurity.io/advisories/317" - }, { "type": "WEB", "url": "https://snyk.io/vuln/npm:mobile-icon-resizer:20160408" diff --git a/advisories/github-reviewed/2019/07/GHSA-g8m7-qhv7-9h5x/GHSA-g8m7-qhv7-9h5x.json b/advisories/github-reviewed/2019/07/GHSA-g8m7-qhv7-9h5x/GHSA-g8m7-qhv7-9h5x.json index 99f8eeda9b7..e21fc3c8f98 100644 --- a/advisories/github-reviewed/2019/07/GHSA-g8m7-qhv7-9h5x/GHSA-g8m7-qhv7-9h5x.json +++ b/advisories/github-reviewed/2019/07/GHSA-g8m7-qhv7-9h5x/GHSA-g8m7-qhv7-9h5x.json @@ -49,10 +49,6 @@ "type": "WEB", "url": "https://hackerone.com/reports/569966" }, - { - "type": "WEB", - "url": "https://nodesecurity.io/advisories/554" - }, { "type": "WEB", "url": "https://www.npmjs.com/advisories/554" diff --git a/advisories/github-reviewed/2019/08/GHSA-65p8-3hm4-h9h8/GHSA-65p8-3hm4-h9h8.json b/advisories/github-reviewed/2019/08/GHSA-65p8-3hm4-h9h8/GHSA-65p8-3hm4-h9h8.json index 8ddaeb192cf..7d36d331f6f 100644 --- a/advisories/github-reviewed/2019/08/GHSA-65p8-3hm4-h9h8/GHSA-65p8-3hm4-h9h8.json +++ b/advisories/github-reviewed/2019/08/GHSA-65p8-3hm4-h9h8/GHSA-65p8-3hm4-h9h8.json @@ -44,10 +44,6 @@ "type": "WEB", "url": "https://github.com/christian-bromann/rgb2hex/blob/v0.1.0/index.js#L25" }, - { - "type": "WEB", - "url": "https://nodesecurity.io/advisories/647" - }, { "type": "WEB", "url": "https://snyk.io/vuln/npm:rgb2hex:20180429" diff --git a/advisories/github-reviewed/2019/08/GHSA-rch7-f4h5-x9rj/GHSA-rch7-f4h5-x9rj.json b/advisories/github-reviewed/2019/08/GHSA-rch7-f4h5-x9rj/GHSA-rch7-f4h5-x9rj.json index c017cf2c263..355a39e70c3 100644 --- a/advisories/github-reviewed/2019/08/GHSA-rch7-f4h5-x9rj/GHSA-rch7-f4h5-x9rj.json +++ b/advisories/github-reviewed/2019/08/GHSA-rch7-f4h5-x9rj/GHSA-rch7-f4h5-x9rj.json @@ -40,10 +40,6 @@ "type": "WEB", "url": "https://github.com/libp2p/js-libp2p-secio/pull/95" }, - { - "type": "WEB", - "url": "https://nodesecurity.io/advisories/558" - }, { "type": "WEB", "url": "https://snyk.io/vuln/npm:libp2p-secio:20180115" diff --git a/advisories/github-reviewed/2020/08/GHSA-3fw8-66wf-pr7m/GHSA-3fw8-66wf-pr7m.json b/advisories/github-reviewed/2020/08/GHSA-3fw8-66wf-pr7m/GHSA-3fw8-66wf-pr7m.json index 25a4d35499f..a7b7746828f 100644 --- a/advisories/github-reviewed/2020/08/GHSA-3fw8-66wf-pr7m/GHSA-3fw8-66wf-pr7m.json +++ b/advisories/github-reviewed/2020/08/GHSA-3fw8-66wf-pr7m/GHSA-3fw8-66wf-pr7m.json @@ -64,10 +64,6 @@ "type": "WEB", "url": "https://bugzilla.suse.com/show_bug.cgi?id=CVE-2013-7370" }, - { - "type": "WEB", - "url": "https://nodesecurity.io/advisories/methodOverride_Middleware_Reflected_Cross-Site_Scripting" - }, { "type": "WEB", "url": "https://security-tracker.debian.org/tracker/CVE-2013-7370" @@ -90,6 +86,8 @@ "CWE-79" ], "severity": "LOW", - "github_reviewed": true + "github_reviewed": true, + "github_reviewed_at": "2020-08-31T18:07:25Z", + "nvd_published_at": null } } \ No newline at end of file diff --git a/advisories/github-reviewed/2020/08/GHSA-4x7c-cx64-49w8/GHSA-4x7c-cx64-49w8.json b/advisories/github-reviewed/2020/08/GHSA-4x7c-cx64-49w8/GHSA-4x7c-cx64-49w8.json index 45daeeb6414..e6325b6c21b 100644 --- a/advisories/github-reviewed/2020/08/GHSA-4x7c-cx64-49w8/GHSA-4x7c-cx64-49w8.json +++ b/advisories/github-reviewed/2020/08/GHSA-4x7c-cx64-49w8/GHSA-4x7c-cx64-49w8.json @@ -60,10 +60,6 @@ { "type": "WEB", "url": "https://github.com/mafintosh/is-my-json-valid/commit/b3051b277f7caa08cd2edc6f74f50aeda65d2976" - }, - { - "type": "WEB", - "url": "https://nodesecurity.io/advisories/572" } ], "database_specific": { diff --git a/advisories/github-reviewed/2020/08/GHSA-9xgp-hfw7-73rq/GHSA-9xgp-hfw7-73rq.json b/advisories/github-reviewed/2020/08/GHSA-9xgp-hfw7-73rq/GHSA-9xgp-hfw7-73rq.json index 214b6b2e701..8c8aa9a9ecb 100644 --- a/advisories/github-reviewed/2020/08/GHSA-9xgp-hfw7-73rq/GHSA-9xgp-hfw7-73rq.json +++ b/advisories/github-reviewed/2020/08/GHSA-9xgp-hfw7-73rq/GHSA-9xgp-hfw7-73rq.json @@ -37,10 +37,6 @@ { "type": "WEB", "url": "https://github.com/keystonejs/keystone/issues/1085" - }, - { - "type": "WEB", - "url": "https://nodesecurity.io/advisories/60" } ], "database_specific": { diff --git a/advisories/github-reviewed/2020/08/GHSA-c6h2-mpc6-232h/GHSA-c6h2-mpc6-232h.json b/advisories/github-reviewed/2020/08/GHSA-c6h2-mpc6-232h/GHSA-c6h2-mpc6-232h.json index ad352912da1..df5b2faa8f9 100644 --- a/advisories/github-reviewed/2020/08/GHSA-c6h2-mpc6-232h/GHSA-c6h2-mpc6-232h.json +++ b/advisories/github-reviewed/2020/08/GHSA-c6h2-mpc6-232h/GHSA-c6h2-mpc6-232h.json @@ -38,10 +38,6 @@ "type": "WEB", "url": "https://github.com/skoranga/node-dns-sync/commit/d9abaae384b198db1095735ad9c1c73d7b890a0d" }, - { - "type": "WEB", - "url": "https://nodesecurity.io/advisories/dns-sync-command-injection" - }, { "type": "WEB", "url": "https://www.npmjs.com/advisories/153" diff --git a/advisories/github-reviewed/2020/08/GHSA-chgg-rrmv-5q7x/GHSA-chgg-rrmv-5q7x.json b/advisories/github-reviewed/2020/08/GHSA-chgg-rrmv-5q7x/GHSA-chgg-rrmv-5q7x.json index 8f2e5e8a333..9ab5c725474 100644 --- a/advisories/github-reviewed/2020/08/GHSA-chgg-rrmv-5q7x/GHSA-chgg-rrmv-5q7x.json +++ b/advisories/github-reviewed/2020/08/GHSA-chgg-rrmv-5q7x/GHSA-chgg-rrmv-5q7x.json @@ -41,10 +41,6 @@ { "type": "WEB", "url": "https://github.com/hokaccha/node-jwt-simple/commit/957957cfa44474049b4603b293569588ee9ffd97" - }, - { - "type": "WEB", - "url": "https://nodesecurity.io/advisories/87" } ], "database_specific": { diff --git a/advisories/github-reviewed/2020/08/GHSA-mpcx-8qqw-rmcq/GHSA-mpcx-8qqw-rmcq.json b/advisories/github-reviewed/2020/08/GHSA-mpcx-8qqw-rmcq/GHSA-mpcx-8qqw-rmcq.json index 97337519512..0e23a1280fb 100644 --- a/advisories/github-reviewed/2020/08/GHSA-mpcx-8qqw-rmcq/GHSA-mpcx-8qqw-rmcq.json +++ b/advisories/github-reviewed/2020/08/GHSA-mpcx-8qqw-rmcq/GHSA-mpcx-8qqw-rmcq.json @@ -41,10 +41,6 @@ { "type": "ADVISORY", "url": "https://github.com/advisories/GHSA-cgpp-wm2h-6hqx" - }, - { - "type": "WEB", - "url": "https://nodesecurity.io/advisories/115" } ], "database_specific": { diff --git a/advisories/github-reviewed/2020/08/GHSA-q9r2-f3vc-rjg8/GHSA-q9r2-f3vc-rjg8.json b/advisories/github-reviewed/2020/08/GHSA-q9r2-f3vc-rjg8/GHSA-q9r2-f3vc-rjg8.json index 969b9f28f5f..eb28f1f44fb 100644 --- a/advisories/github-reviewed/2020/08/GHSA-q9r2-f3vc-rjg8/GHSA-q9r2-f3vc-rjg8.json +++ b/advisories/github-reviewed/2020/08/GHSA-q9r2-f3vc-rjg8/GHSA-q9r2-f3vc-rjg8.json @@ -37,10 +37,6 @@ { "type": "WEB", "url": "https://hackerone.com/reports/319467" - }, - { - "type": "WEB", - "url": "https://nodesecurity.io/advisories/654" } ], "database_specific": { diff --git a/advisories/github-reviewed/2020/08/GHSA-qrg3-f6h6-vq8q/GHSA-qrg3-f6h6-vq8q.json b/advisories/github-reviewed/2020/08/GHSA-qrg3-f6h6-vq8q/GHSA-qrg3-f6h6-vq8q.json index e6d9d08c8f5..be39efe2049 100644 --- a/advisories/github-reviewed/2020/08/GHSA-qrg3-f6h6-vq8q/GHSA-qrg3-f6h6-vq8q.json +++ b/advisories/github-reviewed/2020/08/GHSA-qrg3-f6h6-vq8q/GHSA-qrg3-f6h6-vq8q.json @@ -37,10 +37,6 @@ { "type": "WEB", "url": "https://hackerone.com/reports/319532" - }, - { - "type": "WEB", - "url": "https://nodesecurity.io/advisories/593" } ], "database_specific": { diff --git a/advisories/github-reviewed/2020/08/GHSA-wx84-69jh-jjp2/GHSA-wx84-69jh-jjp2.json b/advisories/github-reviewed/2020/08/GHSA-wx84-69jh-jjp2/GHSA-wx84-69jh-jjp2.json index 61468d7cdc8..718cfd6dfc8 100644 --- a/advisories/github-reviewed/2020/08/GHSA-wx84-69jh-jjp2/GHSA-wx84-69jh-jjp2.json +++ b/advisories/github-reviewed/2020/08/GHSA-wx84-69jh-jjp2/GHSA-wx84-69jh-jjp2.json @@ -63,10 +63,6 @@ { "type": "WEB", "url": "https://github.com/joyent/node-sshpk/blob/v1.13.1/lib/formats/ssh.js#L17" - }, - { - "type": "WEB", - "url": "https://nodesecurity.io/advisories/606" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/05/GHSA-72p9-6gc7-q93r/GHSA-72p9-6gc7-q93r.json b/advisories/github-reviewed/2022/05/GHSA-72p9-6gc7-q93r/GHSA-72p9-6gc7-q93r.json similarity index 68% rename from advisories/unreviewed/2022/05/GHSA-72p9-6gc7-q93r/GHSA-72p9-6gc7-q93r.json rename to advisories/github-reviewed/2022/05/GHSA-72p9-6gc7-q93r/GHSA-72p9-6gc7-q93r.json index fced7728ac6..0be39078c79 100644 --- a/advisories/unreviewed/2022/05/GHSA-72p9-6gc7-q93r/GHSA-72p9-6gc7-q93r.json +++ b/advisories/github-reviewed/2022/05/GHSA-72p9-6gc7-q93r/GHSA-72p9-6gc7-q93r.json @@ -1,17 +1,36 @@ { "schema_version": "1.3.0", "id": "GHSA-72p9-6gc7-q93r", - "modified": "2022-05-17T04:42:41Z", + "modified": "2023-02-08T18:05:05Z", "published": "2022-05-17T04:42:41Z", "aliases": [ "CVE-2014-0056" ], + "summary": "OpenStack Neutron Improper Authentication vulnerability", "details": "The l3-agent in OpenStack Neutron 2012.2 before 2013.2.3 does not check the tenant id when creating ports, which allows remote authenticated users to plug ports into the routers of arbitrary tenants via the device id in a port-create command.", "severity": [ ], "affected": [ - + { + "package": { + "ecosystem": "PyPI", + "name": "neutron" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2012.2" + }, + { + "fixed": "2013.2.3" + } + ] + } + ] + } ], "references": [ { @@ -34,6 +53,10 @@ "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1063141" }, + { + "type": "PACKAGE", + "url": "https://opendev.org/openstack/neutron" + }, { "type": "WEB", "url": "http://rhn.redhat.com/errata/RHSA-2014-0516.html" @@ -51,9 +74,9 @@ "cwe_ids": [ "CWE-287" ], - "severity": "LOW", - "github_reviewed": false, - "github_reviewed_at": null, + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2023-02-08T18:05:05Z", "nvd_published_at": "2014-05-08T14:29:00Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-78cj-2m29-q5r9/GHSA-78cj-2m29-q5r9.json b/advisories/github-reviewed/2022/05/GHSA-78cj-2m29-q5r9/GHSA-78cj-2m29-q5r9.json similarity index 59% rename from advisories/unreviewed/2022/05/GHSA-78cj-2m29-q5r9/GHSA-78cj-2m29-q5r9.json rename to advisories/github-reviewed/2022/05/GHSA-78cj-2m29-q5r9/GHSA-78cj-2m29-q5r9.json index fa1f5b807fc..96288111ee5 100644 --- a/advisories/unreviewed/2022/05/GHSA-78cj-2m29-q5r9/GHSA-78cj-2m29-q5r9.json +++ b/advisories/github-reviewed/2022/05/GHSA-78cj-2m29-q5r9/GHSA-78cj-2m29-q5r9.json @@ -1,17 +1,55 @@ { "schema_version": "1.3.0", "id": "GHSA-78cj-2m29-q5r9", - "modified": "2022-05-05T02:48:48Z", + "modified": "2023-02-08T18:06:03Z", "published": "2022-05-05T02:48:48Z", "aliases": [ "CVE-2013-0329" ], + "summary": "Jenkins Cross-Site Request Forgery vulnerability", "details": "Unspecified vulnerability in Jenkins before 1.502 and LTS before 1.480.3 allows remote attackers to bypass the CSRF protection mechanism via unknown attack vectors.", "severity": [ ], "affected": [ - + { + "package": { + "ecosystem": "Maven", + "name": "org.jenkins-ci.main:jenkins-core" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "1.481" + }, + { + "fixed": "1.502" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "org.jenkins-ci.main:jenkins-core" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.480.3" + } + ] + } + ] + } ], "references": [ { @@ -49,11 +87,11 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], - "severity": "HIGH", - "github_reviewed": false, - "github_reviewed_at": null, + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2023-02-08T18:06:03Z", "nvd_published_at": "2013-03-19T14:55:00Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-cmg8-5c63-pg95/GHSA-cmg8-5c63-pg95.json b/advisories/github-reviewed/2022/05/GHSA-cmg8-5c63-pg95/GHSA-cmg8-5c63-pg95.json similarity index 65% rename from advisories/unreviewed/2022/05/GHSA-cmg8-5c63-pg95/GHSA-cmg8-5c63-pg95.json rename to advisories/github-reviewed/2022/05/GHSA-cmg8-5c63-pg95/GHSA-cmg8-5c63-pg95.json index 5e003c67264..64da94c23b0 100644 --- a/advisories/unreviewed/2022/05/GHSA-cmg8-5c63-pg95/GHSA-cmg8-5c63-pg95.json +++ b/advisories/github-reviewed/2022/05/GHSA-cmg8-5c63-pg95/GHSA-cmg8-5c63-pg95.json @@ -1,17 +1,36 @@ { "schema_version": "1.3.0", "id": "GHSA-cmg8-5c63-pg95", - "modified": "2022-05-14T02:09:21Z", + "modified": "2023-02-08T18:04:43Z", "published": "2022-05-14T02:09:21Z", "aliases": [ "CVE-2014-0157" ], + "summary": "OpenStack Dashboard (aka Horizon) vulnerable to Cross-site Scripting", "details": "Cross-site scripting (XSS) vulnerability in the Horizon Orchestration dashboard in OpenStack Dashboard (aka Horizon) 2013.2 before 2013.2.4 and icehouse before icehouse-rc2 allows remote attackers to inject arbitrary web script or HTML via the description field of a Heat template.", "severity": [ ], "affected": [ - + { + "package": { + "ecosystem": "PyPI", + "name": "horizon" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2013.2" + }, + { + "fixed": "2013.2.4" + } + ] + } + ] + } ], "references": [ { @@ -34,6 +53,14 @@ "type": "WEB", "url": "https://launchpad.net/bugs/1289033" }, + { + "type": "PACKAGE", + "url": "https://opendev.org/openstack/horizon" + }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20200228185211/http://www.securityfocus.com/bid/66706" + }, { "type": "WEB", "url": "http://lists.opensuse.org/opensuse-updates/2015-01/msg00040.html" @@ -41,10 +68,6 @@ { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2014/04/08/8" - }, - { - "type": "WEB", - "url": "http://www.securityfocus.com/bid/66706" } ], "database_specific": { @@ -52,8 +75,8 @@ "CWE-79" ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2023-02-08T18:04:43Z", "nvd_published_at": "2014-04-15T14:55:00Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-p258-xmh3-72pv/GHSA-p258-xmh3-72pv.json b/advisories/github-reviewed/2022/05/GHSA-p258-xmh3-72pv/GHSA-p258-xmh3-72pv.json similarity index 68% rename from advisories/unreviewed/2022/05/GHSA-p258-xmh3-72pv/GHSA-p258-xmh3-72pv.json rename to advisories/github-reviewed/2022/05/GHSA-p258-xmh3-72pv/GHSA-p258-xmh3-72pv.json index 51523d46577..40bfd2026ce 100644 --- a/advisories/unreviewed/2022/05/GHSA-p258-xmh3-72pv/GHSA-p258-xmh3-72pv.json +++ b/advisories/github-reviewed/2022/05/GHSA-p258-xmh3-72pv/GHSA-p258-xmh3-72pv.json @@ -1,17 +1,36 @@ { "schema_version": "1.3.0", "id": "GHSA-p258-xmh3-72pv", - "modified": "2022-05-17T04:41:34Z", + "modified": "2023-02-08T18:04:25Z", "published": "2022-05-17T04:41:34Z", "aliases": [ "CVE-2014-0167" ], + "summary": "OpenStack Compute (Nova) allows remote authenticated users to gain privileges via API requests", "details": "The Nova EC2 API security group implementation in OpenStack Compute (Nova) 2013.1 before 2013.2.4 and icehouse before icehouse-rc2 does not enforce RBAC policies for (1) add_rules, (2) remove_rules, (3) destroy, and other unspecified methods in compute/api.py when using non-default policies, which allows remote authenticated users to gain privileges via these API requests.", "severity": [ ], "affected": [ - + { + "package": { + "ecosystem": "PyPI", + "name": "nova" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2013.1.0" + }, + { + "fixed": "2013.2.4" + } + ] + } + ] + } ], "references": [ { @@ -34,6 +53,10 @@ "type": "WEB", "url": "https://launchpad.net/bugs/1290537" }, + { + "type": "PACKAGE", + "url": "https://opendev.org/openstack/nova" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2014/04/09/26" @@ -48,8 +71,8 @@ ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2023-02-08T18:04:25Z", "nvd_published_at": "2014-04-15T14:55:00Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-rqhg-cxfr-8xqw/GHSA-rqhg-cxfr-8xqw.json b/advisories/github-reviewed/2022/05/GHSA-rqhg-cxfr-8xqw/GHSA-rqhg-cxfr-8xqw.json similarity index 61% rename from advisories/unreviewed/2022/05/GHSA-rqhg-cxfr-8xqw/GHSA-rqhg-cxfr-8xqw.json rename to advisories/github-reviewed/2022/05/GHSA-rqhg-cxfr-8xqw/GHSA-rqhg-cxfr-8xqw.json index 9260f45b65b..96860c3ab74 100644 --- a/advisories/unreviewed/2022/05/GHSA-rqhg-cxfr-8xqw/GHSA-rqhg-cxfr-8xqw.json +++ b/advisories/github-reviewed/2022/05/GHSA-rqhg-cxfr-8xqw/GHSA-rqhg-cxfr-8xqw.json @@ -1,17 +1,55 @@ { "schema_version": "1.3.0", "id": "GHSA-rqhg-cxfr-8xqw", - "modified": "2022-05-05T02:48:48Z", + "modified": "2023-02-08T18:05:41Z", "published": "2022-05-05T02:48:48Z", "aliases": [ "CVE-2013-0327" ], + "summary": "Jenkins Cross-Site Request Forgery vulnerability", "details": "Cross-site request forgery (CSRF) vulnerability in Jenkins master in Jenkins before 1.502 and LTS before 1.480.3 allows remote attackers to hijack the authentication of users via unknown vectors.", "severity": [ ], "affected": [ - + { + "package": { + "ecosystem": "Maven", + "name": "org.jenkins-ci.main:jenkins-core" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "1.481" + }, + { + "fixed": "1.502" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "org.jenkins-ci.main:jenkins-core" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.480.3" + } + ] + } + ] + } ], "references": [ { @@ -52,8 +90,8 @@ "CWE-352" ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2023-02-08T18:05:41Z", "nvd_published_at": "2013-03-19T14:55:00Z" } } \ No newline at end of file