From 2ed0b6bf12ce04fd9b5f3230e5dde028c132acd2 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 25 Oct 2024 21:37:28 +0000 Subject: [PATCH] Publish Advisories GHSA-m4fw-77v7-924m GHSA-6757-jp84-gxfx GHSA-pphf-f93w-gc84 GHSA-f9vj-2wh5-fj8j GHSA-mqr9-hjr8-2m9w GHSA-q34m-jh98-gwm2 --- .../GHSA-m4fw-77v7-924m.json | 12 +++++++++-- .../GHSA-6757-jp84-gxfx.json | 21 ++++++++++++------- .../GHSA-pphf-f93w-gc84.json | 2 +- .../GHSA-f9vj-2wh5-fj8j.json | 12 +++++++++-- .../GHSA-mqr9-hjr8-2m9w.json | 9 +++++--- .../GHSA-q34m-jh98-gwm2.json | 12 +++++++++-- 6 files changed, 50 insertions(+), 18 deletions(-) diff --git a/advisories/github-reviewed/2018/09/GHSA-m4fw-77v7-924m/GHSA-m4fw-77v7-924m.json b/advisories/github-reviewed/2018/09/GHSA-m4fw-77v7-924m/GHSA-m4fw-77v7-924m.json index 7d6a61259e0..0291e9ad1eb 100644 --- a/advisories/github-reviewed/2018/09/GHSA-m4fw-77v7-924m/GHSA-m4fw-77v7-924m.json +++ b/advisories/github-reviewed/2018/09/GHSA-m4fw-77v7-924m/GHSA-m4fw-77v7-924m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m4fw-77v7-924m", - "modified": "2023-08-31T21:35:38Z", + "modified": "2024-10-25T21:36:47Z", "published": "2018-09-13T15:47:57Z", "aliases": [ "CVE-2018-1000559" @@ -12,6 +12,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N" } ], "affected": [ @@ -28,7 +32,7 @@ "introduced": "0.11.0" }, { - "fixed": "1.4.0" + "fixed": "1.3.3" } ] } @@ -56,6 +60,10 @@ "type": "ADVISORY", "url": "https://github.com/advisories/GHSA-m4fw-77v7-924m" }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/qutebrowser/PYSEC-2018-26.yaml" + }, { "type": "PACKAGE", "url": "https://github.com/qutebrowser/qutebrowser" diff --git a/advisories/github-reviewed/2021/04/GHSA-6757-jp84-gxfx/GHSA-6757-jp84-gxfx.json b/advisories/github-reviewed/2021/04/GHSA-6757-jp84-gxfx/GHSA-6757-jp84-gxfx.json index bee1bea03d8..da080f3715b 100644 --- a/advisories/github-reviewed/2021/04/GHSA-6757-jp84-gxfx/GHSA-6757-jp84-gxfx.json +++ b/advisories/github-reviewed/2021/04/GHSA-6757-jp84-gxfx/GHSA-6757-jp84-gxfx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6757-jp84-gxfx", - "modified": "2022-07-29T18:40:16Z", + "modified": "2024-10-25T21:35:10Z", "published": "2021-04-20T16:14:24Z", "aliases": [ "CVE-2020-1747" @@ -12,6 +12,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" } ], "affected": [ @@ -20,13 +24,6 @@ "ecosystem": "PyPI", "name": "pyyaml" }, - "ecosystem_specific": { - "affected_functions": [ - "yaml.load", - "yaml.full_load", - "yaml.FullLoader" - ] - }, "ranges": [ { "type": "ECOSYSTEM", @@ -59,6 +56,14 @@ "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1747" }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-6757-jp84-gxfx" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/pyyaml/PYSEC-2020-96.yaml" + }, { "type": "PACKAGE", "url": "https://github.com/yaml/pyyaml" diff --git a/advisories/github-reviewed/2021/08/GHSA-pphf-f93w-gc84/GHSA-pphf-f93w-gc84.json b/advisories/github-reviewed/2021/08/GHSA-pphf-f93w-gc84/GHSA-pphf-f93w-gc84.json index 0c1b1af7d35..b312783956a 100644 --- a/advisories/github-reviewed/2021/08/GHSA-pphf-f93w-gc84/GHSA-pphf-f93w-gc84.json +++ b/advisories/github-reviewed/2021/08/GHSA-pphf-f93w-gc84/GHSA-pphf-f93w-gc84.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pphf-f93w-gc84", - "modified": "2021-08-19T18:48:04Z", + "modified": "2024-10-25T21:35:35Z", "published": "2021-08-25T20:51:47Z", "aliases": [ "CVE-2020-36217" diff --git a/advisories/github-reviewed/2024/10/GHSA-f9vj-2wh5-fj8j/GHSA-f9vj-2wh5-fj8j.json b/advisories/github-reviewed/2024/10/GHSA-f9vj-2wh5-fj8j/GHSA-f9vj-2wh5-fj8j.json index 65302dee61a..159b61d923e 100644 --- a/advisories/github-reviewed/2024/10/GHSA-f9vj-2wh5-fj8j/GHSA-f9vj-2wh5-fj8j.json +++ b/advisories/github-reviewed/2024/10/GHSA-f9vj-2wh5-fj8j/GHSA-f9vj-2wh5-fj8j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f9vj-2wh5-fj8j", - "modified": "2024-10-25T19:43:41Z", + "modified": "2024-10-25T21:35:11Z", "published": "2024-10-25T19:43:41Z", "aliases": [ "CVE-2024-49766" @@ -43,6 +43,10 @@ "type": "WEB", "url": "https://github.com/pallets/werkzeug/security/advisories/GHSA-f9vj-2wh5-fj8j" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49766" + }, { "type": "WEB", "url": "https://github.com/pallets/werkzeug/commit/2767bcb10a7dd1c297d812cc5e6d11a474c1f092" @@ -50,6 +54,10 @@ { "type": "PACKAGE", "url": "https://github.com/pallets/werkzeug" + }, + { + "type": "WEB", + "url": "https://github.com/pallets/werkzeug/releases/tag/3.0.6" } ], "database_specific": { @@ -59,6 +67,6 @@ "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2024-10-25T19:43:41Z", - "nvd_published_at": null + "nvd_published_at": "2024-10-25T20:15:04Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2024/10/GHSA-mqr9-hjr8-2m9w/GHSA-mqr9-hjr8-2m9w.json b/advisories/github-reviewed/2024/10/GHSA-mqr9-hjr8-2m9w/GHSA-mqr9-hjr8-2m9w.json index a36b4e89832..2c94ea74e43 100644 --- a/advisories/github-reviewed/2024/10/GHSA-mqr9-hjr8-2m9w/GHSA-mqr9-hjr8-2m9w.json +++ b/advisories/github-reviewed/2024/10/GHSA-mqr9-hjr8-2m9w/GHSA-mqr9-hjr8-2m9w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mqr9-hjr8-2m9w", - "modified": "2024-10-25T19:59:06Z", + "modified": "2024-10-25T21:35:13Z", "published": "2024-10-25T18:30:49Z", "aliases": [ "CVE-2023-26248" @@ -9,7 +9,10 @@ "summary": "Content Censorship in the InterPlanetary File System (IPFS) via Kademlia DHT abuse", "details": "The Kademlia DHT (go-libp2p-kad-dht 0.20.0 and earlier) used in IPFS (0.18.1 and earlier) assigns routing information for content (i.e., information about who holds the content) to be stored by peers whose peer IDs have a small DHT distance from the content ID. This allows an attacker to censor content by generating many Sybil peers whose peer IDs have a small distance from the content ID, thus hijacking the content resolution process.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ { @@ -48,7 +51,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-352" ], "severity": "MODERATE", "github_reviewed": true, diff --git a/advisories/github-reviewed/2024/10/GHSA-q34m-jh98-gwm2/GHSA-q34m-jh98-gwm2.json b/advisories/github-reviewed/2024/10/GHSA-q34m-jh98-gwm2/GHSA-q34m-jh98-gwm2.json index 93ce14ea407..8ae4b3d5544 100644 --- a/advisories/github-reviewed/2024/10/GHSA-q34m-jh98-gwm2/GHSA-q34m-jh98-gwm2.json +++ b/advisories/github-reviewed/2024/10/GHSA-q34m-jh98-gwm2/GHSA-q34m-jh98-gwm2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q34m-jh98-gwm2", - "modified": "2024-10-25T19:44:43Z", + "modified": "2024-10-25T21:35:40Z", "published": "2024-10-25T19:44:43Z", "aliases": [ "CVE-2024-49767" @@ -65,6 +65,10 @@ "type": "WEB", "url": "https://github.com/pallets/werkzeug/security/advisories/GHSA-q34m-jh98-gwm2" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49767" + }, { "type": "WEB", "url": "https://github.com/pallets/quart/commit/5e78c4169b8eb66b91ead3e62d44721b9e1644ee" @@ -76,6 +80,10 @@ { "type": "PACKAGE", "url": "https://github.com/pallets/werkzeug" + }, + { + "type": "WEB", + "url": "https://github.com/pallets/werkzeug/releases/tag/3.0.6" } ], "database_specific": { @@ -85,6 +93,6 @@ "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2024-10-25T19:44:43Z", - "nvd_published_at": null + "nvd_published_at": "2024-10-25T20:15:04Z" } } \ No newline at end of file