diff --git a/advisories/unreviewed/2023/10/GHSA-57cr-rq3f-ppmx/GHSA-57cr-rq3f-ppmx.json b/advisories/github-reviewed/2023/10/GHSA-57cr-rq3f-ppmx/GHSA-57cr-rq3f-ppmx.json similarity index 59% rename from advisories/unreviewed/2023/10/GHSA-57cr-rq3f-ppmx/GHSA-57cr-rq3f-ppmx.json rename to advisories/github-reviewed/2023/10/GHSA-57cr-rq3f-ppmx/GHSA-57cr-rq3f-ppmx.json index bb38aaf393a..c5c140caa41 100644 --- a/advisories/unreviewed/2023/10/GHSA-57cr-rq3f-ppmx/GHSA-57cr-rq3f-ppmx.json +++ b/advisories/github-reviewed/2023/10/GHSA-57cr-rq3f-ppmx/GHSA-57cr-rq3f-ppmx.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-57cr-rq3f-ppmx", - "modified": "2023-10-20T18:30:58Z", + "modified": "2023-10-20T23:03:16Z", "published": "2023-10-20T18:30:58Z", "aliases": [ "CVE-2023-5690" ], + "summary": "modoboa Cross-Site Request Forgery vulnerability", "details": "Cross-Site Request Forgery (CSRF) in GitHub repository modoboa/modoboa prior to 2.2.2.", "severity": [ { @@ -14,7 +15,25 @@ } ], "affected": [ - + { + "package": { + "ecosystem": "PyPI", + "name": "modoboa" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.2.2" + } + ] + } + ] + } ], "references": [ { @@ -25,6 +44,10 @@ "type": "WEB", "url": "https://github.com/modoboa/modoboa/commit/23e4c25511c66c0548da001236f47e19e3f9e4d9" }, + { + "type": "PACKAGE", + "url": "https://github.com/modoboa/modoboa" + }, { "type": "WEB", "url": "https://huntr.com/bounties/980c75a5-d978-4b0e-9bcc-2b2682c97e01" @@ -35,8 +58,8 @@ "CWE-352" ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2023-10-20T23:03:16Z", "nvd_published_at": null } } \ No newline at end of file diff --git a/advisories/unreviewed/2023/10/GHSA-9wj3-cfq8-wpvj/GHSA-9wj3-cfq8-wpvj.json b/advisories/github-reviewed/2023/10/GHSA-9wj3-cfq8-wpvj/GHSA-9wj3-cfq8-wpvj.json similarity index 59% rename from advisories/unreviewed/2023/10/GHSA-9wj3-cfq8-wpvj/GHSA-9wj3-cfq8-wpvj.json rename to advisories/github-reviewed/2023/10/GHSA-9wj3-cfq8-wpvj/GHSA-9wj3-cfq8-wpvj.json index 8cf6b987b47..b700d4eab4f 100644 --- a/advisories/unreviewed/2023/10/GHSA-9wj3-cfq8-wpvj/GHSA-9wj3-cfq8-wpvj.json +++ b/advisories/github-reviewed/2023/10/GHSA-9wj3-cfq8-wpvj/GHSA-9wj3-cfq8-wpvj.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-9wj3-cfq8-wpvj", - "modified": "2023-10-20T18:30:57Z", + "modified": "2023-10-20T23:02:47Z", "published": "2023-10-20T18:30:57Z", "aliases": [ "CVE-2023-5689" ], + "summary": "modoboa Cross-site Scripting vulnerability", "details": "Cross-site Scripting (XSS) - DOM in GitHub repository modoboa/modoboa prior to 2.2.2.", "severity": [ { @@ -14,7 +15,25 @@ } ], "affected": [ - + { + "package": { + "ecosystem": "PyPI", + "name": "modoboa" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.2.2" + } + ] + } + ] + } ], "references": [ { @@ -25,6 +44,10 @@ "type": "WEB", "url": "https://github.com/modoboa/modoboa/commit/d33d3cd2d11dbfebd8162c46e2c2a9873919a967" }, + { + "type": "PACKAGE", + "url": "https://github.com/modoboa/modoboa" + }, { "type": "WEB", "url": "https://huntr.com/bounties/24835833-3421-412b-bafb-1b7ea3cf60e6" @@ -35,8 +58,8 @@ "CWE-79" ], "severity": "HIGH", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2023-10-20T23:02:47Z", "nvd_published_at": null } } \ No newline at end of file