diff --git a/advisories/github-reviewed/2019/12/GHSA-7xx3-m584-x994/GHSA-7xx3-m584-x994.json b/advisories/github-reviewed/2019/12/GHSA-7xx3-m584-x994/GHSA-7xx3-m584-x994.json index ef7c5ddec14..142e15e6baa 100644 --- a/advisories/github-reviewed/2019/12/GHSA-7xx3-m584-x994/GHSA-7xx3-m584-x994.json +++ b/advisories/github-reviewed/2019/12/GHSA-7xx3-m584-x994/GHSA-7xx3-m584-x994.json @@ -67,6 +67,10 @@ "type": "ADVISORY", "url": "https://github.com/advisories/GHSA-7xx3-m584-x994" }, + { + "type": "WEB", + "url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/puma/CVE-2019-16770.yml" + }, { "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2022/05/msg00034.html" diff --git a/advisories/github-reviewed/2020/02/GHSA-84j7-475p-hp8v/GHSA-84j7-475p-hp8v.json b/advisories/github-reviewed/2020/02/GHSA-84j7-475p-hp8v/GHSA-84j7-475p-hp8v.json index 2e661df91a0..63be05e7d6b 100644 --- a/advisories/github-reviewed/2020/02/GHSA-84j7-475p-hp8v/GHSA-84j7-475p-hp8v.json +++ b/advisories/github-reviewed/2020/02/GHSA-84j7-475p-hp8v/GHSA-84j7-475p-hp8v.json @@ -77,6 +77,10 @@ "type": "PACKAGE", "url": "https://github.com/puma/puma" }, + { + "type": "WEB", + "url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/puma/CVE-2020-5247.yml" + }, { "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2022/05/msg00034.html" diff --git a/advisories/github-reviewed/2020/03/GHSA-33vf-4xgg-9r58/GHSA-33vf-4xgg-9r58.json b/advisories/github-reviewed/2020/03/GHSA-33vf-4xgg-9r58/GHSA-33vf-4xgg-9r58.json index 1bd2f33cf14..29d7581ef81 100644 --- a/advisories/github-reviewed/2020/03/GHSA-33vf-4xgg-9r58/GHSA-33vf-4xgg-9r58.json +++ b/advisories/github-reviewed/2020/03/GHSA-33vf-4xgg-9r58/GHSA-33vf-4xgg-9r58.json @@ -71,6 +71,10 @@ "type": "WEB", "url": "https://github.com/puma/puma/commit/c22712fc93284a45a93f9ad7023888f3a65524f3" }, + { + "type": "WEB", + "url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/puma/CVE-2020-5249.yml" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BMJ3CGZ3DLBJ5WUUKMI5ZFXFJQMXJZIK/" diff --git a/advisories/github-reviewed/2020/05/GHSA-w64w-qqph-5gxm/GHSA-w64w-qqph-5gxm.json b/advisories/github-reviewed/2020/05/GHSA-w64w-qqph-5gxm/GHSA-w64w-qqph-5gxm.json index bf3e451c019..e03a8bcba74 100644 --- a/advisories/github-reviewed/2020/05/GHSA-w64w-qqph-5gxm/GHSA-w64w-qqph-5gxm.json +++ b/advisories/github-reviewed/2020/05/GHSA-w64w-qqph-5gxm/GHSA-w64w-qqph-5gxm.json @@ -67,6 +67,10 @@ "type": "WEB", "url": "https://github.com/puma/puma/blob/master/History.md#434435-and-31253126--2020-05-22" }, + { + "type": "WEB", + "url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/puma/CVE-2020-11077.yml" + }, { "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2020/10/msg00009.html" diff --git a/advisories/github-reviewed/2020/05/GHSA-x7jg-6pwg-fx5h/GHSA-x7jg-6pwg-fx5h.json b/advisories/github-reviewed/2020/05/GHSA-x7jg-6pwg-fx5h/GHSA-x7jg-6pwg-fx5h.json index a819ad9ce7a..6959121e3e0 100644 --- a/advisories/github-reviewed/2020/05/GHSA-x7jg-6pwg-fx5h/GHSA-x7jg-6pwg-fx5h.json +++ b/advisories/github-reviewed/2020/05/GHSA-x7jg-6pwg-fx5h/GHSA-x7jg-6pwg-fx5h.json @@ -71,6 +71,10 @@ "type": "WEB", "url": "https://github.com/puma/puma/blob/master/History.md#434435-and-31253126--2020-05-22" }, + { + "type": "WEB", + "url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/puma/CVE-2020-11076.yml" + }, { "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2020/10/msg00009.html" diff --git a/advisories/github-reviewed/2020/12/GHSA-49r3-2549-3633/GHSA-49r3-2549-3633.json b/advisories/github-reviewed/2020/12/GHSA-49r3-2549-3633/GHSA-49r3-2549-3633.json index 310d40384ba..bcaae7e0058 100644 --- a/advisories/github-reviewed/2020/12/GHSA-49r3-2549-3633/GHSA-49r3-2549-3633.json +++ b/advisories/github-reviewed/2020/12/GHSA-49r3-2549-3633/GHSA-49r3-2549-3633.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-49r3-2549-3633", - "modified": "2021-01-07T22:38:24Z", + "modified": "2023-05-04T19:54:39Z", "published": "2020-12-08T14:18:19Z", "aliases": [ "CVE-2020-26254" @@ -51,13 +51,17 @@ { "type": "WEB", "url": "https://github.com/nhosoya/omniauth-apple/blob/master/CHANGELOG.md#101---2020-12-03" + }, + { + "type": "WEB", + "url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/omniauth-apple/CVE-2020-26254.yml" } ], "database_specific": { "cwe_ids": [ "CWE-290" ], - "severity": "LOW", + "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2020-12-08T14:17:26Z", "nvd_published_at": null diff --git a/advisories/github-reviewed/2021/02/GHSA-qrqm-fpv6-6r8g/GHSA-qrqm-fpv6-6r8g.json b/advisories/github-reviewed/2021/02/GHSA-qrqm-fpv6-6r8g/GHSA-qrqm-fpv6-6r8g.json index e77b707dbd6..ef4f6bdce20 100644 --- a/advisories/github-reviewed/2021/02/GHSA-qrqm-fpv6-6r8g/GHSA-qrqm-fpv6-6r8g.json +++ b/advisories/github-reviewed/2021/02/GHSA-qrqm-fpv6-6r8g/GHSA-qrqm-fpv6-6r8g.json @@ -48,6 +48,10 @@ "type": "WEB", "url": "https://github.com/sparklemotion/mechanize/commit/66a6a1bfa653a5f13274a396a5e5441238656aa0" }, + { + "type": "WEB", + "url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/mechanize/CVE-2021-21289.yml" + }, { "type": "PACKAGE", "url": "https://github.com/sparklemotion/mechanize" diff --git a/advisories/github-reviewed/2021/09/GHSA-2rr5-8q37-2w7h/GHSA-2rr5-8q37-2w7h.json b/advisories/github-reviewed/2021/09/GHSA-2rr5-8q37-2w7h/GHSA-2rr5-8q37-2w7h.json index f3f9b281637..5bfcfb7a72f 100644 --- a/advisories/github-reviewed/2021/09/GHSA-2rr5-8q37-2w7h/GHSA-2rr5-8q37-2w7h.json +++ b/advisories/github-reviewed/2021/09/GHSA-2rr5-8q37-2w7h/GHSA-2rr5-8q37-2w7h.json @@ -51,6 +51,10 @@ "type": "WEB", "url": "https://github.com/sparklemotion/nokogiri/commit/5bf729ff3cc84709ee3c3248c981584088bf9f6d" }, + { + "type": "WEB", + "url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/nokogiri/CVE-2021-41098.yml" + }, { "type": "PACKAGE", "url": "https://github.com/sparklemotion/nokogiri" diff --git a/advisories/github-reviewed/2021/12/GHSA-xmgj-5fh3-xjmm/GHSA-xmgj-5fh3-xjmm.json b/advisories/github-reviewed/2021/12/GHSA-xmgj-5fh3-xjmm/GHSA-xmgj-5fh3-xjmm.json index 24b7ffbabdf..b02c08164c9 100644 --- a/advisories/github-reviewed/2021/12/GHSA-xmgj-5fh3-xjmm/GHSA-xmgj-5fh3-xjmm.json +++ b/advisories/github-reviewed/2021/12/GHSA-xmgj-5fh3-xjmm/GHSA-xmgj-5fh3-xjmm.json @@ -51,6 +51,10 @@ { "type": "PACKAGE", "url": "https://github.com/discourse/message_bus" + }, + { + "type": "WEB", + "url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/message_bus/CVE-2021-43840.yml" } ], "database_specific": { diff --git a/advisories/github-reviewed/2022/04/GHSA-crjr-9rc5-ghw8/GHSA-crjr-9rc5-ghw8.json b/advisories/github-reviewed/2022/04/GHSA-crjr-9rc5-ghw8/GHSA-crjr-9rc5-ghw8.json index cbb9268c090..50b3cb576a7 100644 --- a/advisories/github-reviewed/2022/04/GHSA-crjr-9rc5-ghw8/GHSA-crjr-9rc5-ghw8.json +++ b/advisories/github-reviewed/2022/04/GHSA-crjr-9rc5-ghw8/GHSA-crjr-9rc5-ghw8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-crjr-9rc5-ghw8", - "modified": "2022-12-21T14:59:45Z", + "modified": "2023-05-04T19:53:59Z", "published": "2022-04-11T21:18:06Z", "aliases": [ "CVE-2022-24836" @@ -48,6 +48,10 @@ "type": "WEB", "url": "https://github.com/sparklemotion/nokogiri/commit/e444525ef1634b675cd1cf52d39f4320ef0aecfd" }, + { + "type": "WEB", + "url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/nokogiri/CVE-2022-24836.yml" + }, { "type": "PACKAGE", "url": "https://github.com/sparklemotion/nokogiri" diff --git a/advisories/github-reviewed/2022/05/GHSA-xh29-r2w5-wx8m/GHSA-xh29-r2w5-wx8m.json b/advisories/github-reviewed/2022/05/GHSA-xh29-r2w5-wx8m/GHSA-xh29-r2w5-wx8m.json index 24637a16a82..f2ff879d166 100644 --- a/advisories/github-reviewed/2022/05/GHSA-xh29-r2w5-wx8m/GHSA-xh29-r2w5-wx8m.json +++ b/advisories/github-reviewed/2022/05/GHSA-xh29-r2w5-wx8m/GHSA-xh29-r2w5-wx8m.json @@ -48,6 +48,10 @@ "type": "WEB", "url": "https://github.com/sparklemotion/nokogiri/commit/db05ba9a1bd4b90aa6c76742cf6102a7c7297267" }, + { + "type": "WEB", + "url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/nokogiri/CVE-2022-29181.yml" + }, { "type": "PACKAGE", "url": "https://github.com/sparklemotion/nokogiri"