diff --git a/advisories/github-reviewed/2018/10/GHSA-r4x2-3cq5-hqvp/GHSA-r4x2-3cq5-hqvp.json b/advisories/github-reviewed/2018/10/GHSA-r4x2-3cq5-hqvp/GHSA-r4x2-3cq5-hqvp.json index 9a5bd44c58d..7ee1270af83 100644 --- a/advisories/github-reviewed/2018/10/GHSA-r4x2-3cq5-hqvp/GHSA-r4x2-3cq5-hqvp.json +++ b/advisories/github-reviewed/2018/10/GHSA-r4x2-3cq5-hqvp/GHSA-r4x2-3cq5-hqvp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r4x2-3cq5-hqvp", - "modified": "2023-12-08T23:02:17Z", + "modified": "2024-02-23T18:01:23Z", "published": "2018-10-17T16:32:32Z", "aliases": [ "CVE-2018-8014" @@ -100,6 +100,22 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-8014" }, + { + "type": "WEB", + "url": "https://github.com/apache/tomcat/commit/5877390a9605f56d9bd6859a54ccbfb16374a78b" + }, + { + "type": "WEB", + "url": "https://github.com/apache/tomcat/commit/60f596a21fd6041335a3a1a4015d4512439cecb5" + }, + { + "type": "WEB", + "url": "https://github.com/apache/tomcat/commit/d83a76732e6804739b81d8b2056365307637b42d" + }, + { + "type": "WEB", + "url": "https://github.com/apache/tomcat80/commit/2c9d8433bd3247a2856d4b2555447108758e813e" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2018:2469" diff --git a/advisories/github-reviewed/2022/05/GHSA-gmg5-r3c4-3fm9/GHSA-gmg5-r3c4-3fm9.json b/advisories/github-reviewed/2022/05/GHSA-gmg5-r3c4-3fm9/GHSA-gmg5-r3c4-3fm9.json index db318f53d9a..339a3b921e2 100644 --- a/advisories/github-reviewed/2022/05/GHSA-gmg5-r3c4-3fm9/GHSA-gmg5-r3c4-3fm9.json +++ b/advisories/github-reviewed/2022/05/GHSA-gmg5-r3c4-3fm9/GHSA-gmg5-r3c4-3fm9.json @@ -1,13 +1,14 @@ { "schema_version": "1.4.0", "id": "GHSA-gmg5-r3c4-3fm9", - "modified": "2023-01-23T14:12:23Z", + "modified": "2024-02-23T18:00:56Z", "published": "2022-05-24T16:47:42Z", + "withdrawn": "2024-02-23T18:00:56Z", "aliases": [ "CVE-2019-10226" ], - "summary": "Fat Free CRM Cross-site Scripting vulnerability", - "details": "HTML Injection has been discovered in the v0.19.0 version of the Fat Free CRM product via an authenticated request to the /comments URI.", + "summary": "Withdrawn Advisory: Fat Free CRM Cross-site Scripting vulnerability", + "details": "## Withdrawn\nThis advisory has been withdrawn because the CVE has been disputed and the underlying vulnerability is likely invalid. This link is maintained to preserve external references.\n\n[According to maintainers of Fat Free CRM](https://github.com/github/advisory-database/pull/3599), the CRM comment feature allows certain HTML markup, but santizes the output when rendered to page. This allows safe tags (such as `