From 32647c0b161f0f49a2a4d9621d00727cc027f791 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 24 Apr 2025 21:42:10 +0000 Subject: [PATCH] Publish Advisories GHSA-4vrv-93c7-m92j GHSA-wgrm-67xf-hhpq GHSA-vqfr-h8mv-ghfj --- .../GHSA-4vrv-93c7-m92j.json | 3 ++- .../GHSA-wgrm-67xf-hhpq.json | 22 +++++++++++++++++-- .../GHSA-vqfr-h8mv-ghfj.json | 8 +++++-- 3 files changed, 28 insertions(+), 5 deletions(-) diff --git a/advisories/github-reviewed/2023/07/GHSA-4vrv-93c7-m92j/GHSA-4vrv-93c7-m92j.json b/advisories/github-reviewed/2023/07/GHSA-4vrv-93c7-m92j/GHSA-4vrv-93c7-m92j.json index 7c4d305ed83..f575411decb 100644 --- a/advisories/github-reviewed/2023/07/GHSA-4vrv-93c7-m92j/GHSA-4vrv-93c7-m92j.json +++ b/advisories/github-reviewed/2023/07/GHSA-4vrv-93c7-m92j/GHSA-4vrv-93c7-m92j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4vrv-93c7-m92j", - "modified": "2023-07-06T21:36:19Z", + "modified": "2025-04-24T21:40:56Z", "published": "2023-07-06T19:24:04Z", "aliases": [ "CVE-2022-24441" @@ -71,6 +71,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-78", "CWE-94" ], "severity": "HIGH", diff --git a/advisories/github-reviewed/2024/05/GHSA-wgrm-67xf-hhpq/GHSA-wgrm-67xf-hhpq.json b/advisories/github-reviewed/2024/05/GHSA-wgrm-67xf-hhpq/GHSA-wgrm-67xf-hhpq.json index 02c9ea2d1f2..63369fbcc9a 100644 --- a/advisories/github-reviewed/2024/05/GHSA-wgrm-67xf-hhpq/GHSA-wgrm-67xf-hhpq.json +++ b/advisories/github-reviewed/2024/05/GHSA-wgrm-67xf-hhpq/GHSA-wgrm-67xf-hhpq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wgrm-67xf-hhpq", - "modified": "2025-01-22T18:45:03Z", + "modified": "2025-04-24T21:41:22Z", "published": "2024-05-07T10:25:08Z", "aliases": [ "CVE-2024-4367" @@ -47,6 +47,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4367" }, + { + "type": "WEB", + "url": "https://github.com/gogs/gogs/issues/7928" + }, { "type": "WEB", "url": "https://github.com/mozilla/pdf.js/pull/18015" @@ -59,10 +63,18 @@ "type": "WEB", "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1893645" }, + { + "type": "WEB", + "url": "https://codeanlabs.com/blog/research/cve-2024-4367-arbitrary-js-execution-in-pdf-js" + }, { "type": "PACKAGE", "url": "https://github.com/mozilla/pdf.js" }, + { + "type": "WEB", + "url": "https://github.com/mozilla/pdf.js/releases/tag/v4.2.67" + }, { "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2024/05/msg00010.html" @@ -71,6 +83,10 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2024/05/msg00012.html" }, + { + "type": "WEB", + "url": "https://www.exploit-db.com/exploits/52273" + }, { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2024-21" @@ -89,7 +105,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-754" + ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2024-05-07T10:25:08Z", diff --git a/advisories/github-reviewed/2025/04/GHSA-vqfr-h8mv-ghfj/GHSA-vqfr-h8mv-ghfj.json b/advisories/github-reviewed/2025/04/GHSA-vqfr-h8mv-ghfj/GHSA-vqfr-h8mv-ghfj.json index ed7ddd78942..deb41ece84c 100644 --- a/advisories/github-reviewed/2025/04/GHSA-vqfr-h8mv-ghfj/GHSA-vqfr-h8mv-ghfj.json +++ b/advisories/github-reviewed/2025/04/GHSA-vqfr-h8mv-ghfj/GHSA-vqfr-h8mv-ghfj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vqfr-h8mv-ghfj", - "modified": "2025-04-24T16:59:21Z", + "modified": "2025-04-24T21:41:36Z", "published": "2025-04-24T16:07:56Z", "aliases": [ "CVE-2025-43859" @@ -40,6 +40,10 @@ "type": "WEB", "url": "https://github.com/python-hyper/h11/security/advisories/GHSA-vqfr-h8mv-ghfj" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43859" + }, { "type": "WEB", "url": "https://github.com/python-hyper/h11/commit/114803a29ce50116dc47951c690ad4892b1a36ed" @@ -56,6 +60,6 @@ "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2025-04-24T16:07:56Z", - "nvd_published_at": null + "nvd_published_at": "2025-04-24T19:15:47Z" } } \ No newline at end of file