diff --git a/advisories/github-reviewed/2022/05/GHSA-5v5w-44w6-q5hv/GHSA-5v5w-44w6-q5hv.json b/advisories/github-reviewed/2022/05/GHSA-5v5w-44w6-q5hv/GHSA-5v5w-44w6-q5hv.json index e802b575b3b..3dd47d33ede 100644 --- a/advisories/github-reviewed/2022/05/GHSA-5v5w-44w6-q5hv/GHSA-5v5w-44w6-q5hv.json +++ b/advisories/github-reviewed/2022/05/GHSA-5v5w-44w6-q5hv/GHSA-5v5w-44w6-q5hv.json @@ -1,14 +1,19 @@ { "schema_version": "1.4.0", "id": "GHSA-5v5w-44w6-q5hv", - "modified": "2022-07-01T13:43:01Z", + "modified": "2025-04-13T23:11:16Z", "published": "2022-05-17T04:47:27Z", "aliases": [ "CVE-2014-2829" ], "summary": "Erlang Solutions MongooseIM vulnerable to denial of service (DoS) via crafted XMPP stream", "details": "Erlang Solutions MongooseIM through 1.3.1 rev. 2 does not properly restrict the processing of compressed XML elements, which allows remote attackers to cause a denial of service (resource consumption) via a crafted XMPP stream, aka an \"xmppbomb\" attack.", - "severity": [], + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N" + } + ], "affected": [ { "package": { @@ -52,7 +57,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-770" + ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2022-07-01T13:43:01Z", diff --git a/advisories/github-reviewed/2022/05/GHSA-gw2q-cgvq-9g3v/GHSA-gw2q-cgvq-9g3v.json b/advisories/github-reviewed/2022/05/GHSA-gw2q-cgvq-9g3v/GHSA-gw2q-cgvq-9g3v.json index 06ffea87e7b..f220a0a0fc3 100644 --- a/advisories/github-reviewed/2022/05/GHSA-gw2q-cgvq-9g3v/GHSA-gw2q-cgvq-9g3v.json +++ b/advisories/github-reviewed/2022/05/GHSA-gw2q-cgvq-9g3v/GHSA-gw2q-cgvq-9g3v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gw2q-cgvq-9g3v", - "modified": "2024-10-21T21:56:31Z", + "modified": "2025-04-13T23:10:38Z", "published": "2022-05-17T01:37:42Z", "aliases": [ "CVE-2012-6131" diff --git a/advisories/github-reviewed/2022/05/GHSA-mccq-3m7h-fjxg/GHSA-mccq-3m7h-fjxg.json b/advisories/github-reviewed/2022/05/GHSA-mccq-3m7h-fjxg/GHSA-mccq-3m7h-fjxg.json index 7b3088670d6..523504bc199 100644 --- a/advisories/github-reviewed/2022/05/GHSA-mccq-3m7h-fjxg/GHSA-mccq-3m7h-fjxg.json +++ b/advisories/github-reviewed/2022/05/GHSA-mccq-3m7h-fjxg/GHSA-mccq-3m7h-fjxg.json @@ -1,14 +1,19 @@ { "schema_version": "1.4.0", "id": "GHSA-mccq-3m7h-fjxg", - "modified": "2024-10-21T21:27:02Z", + "modified": "2025-04-13T23:10:28Z", "published": "2022-05-17T01:37:42Z", "aliases": [ "CVE-2012-6130" ], "summary": "Roundup Cross-site Scripting (XSS) vulnerability", "details": "Cross-site scripting (XSS) vulnerability in the history display in Roundup before 1.4.20 allows remote attackers to inject arbitrary web script or HTML via a username, related to generating a link.", - "severity": [], + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N" + } + ], "affected": [ { "package": {