From 35d5fb3636280a07c459be30ea5e8df73a16c832 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 9 Jun 2023 20:10:46 +0000 Subject: [PATCH] Publish GHSA-78j3-7wpm-qhvp --- .../2017/10/GHSA-78j3-7wpm-qhvp/GHSA-78j3-7wpm-qhvp.json | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) diff --git a/advisories/github-reviewed/2017/10/GHSA-78j3-7wpm-qhvp/GHSA-78j3-7wpm-qhvp.json b/advisories/github-reviewed/2017/10/GHSA-78j3-7wpm-qhvp/GHSA-78j3-7wpm-qhvp.json index e509f271a74..90404b295cb 100644 --- a/advisories/github-reviewed/2017/10/GHSA-78j3-7wpm-qhvp/GHSA-78j3-7wpm-qhvp.json +++ b/advisories/github-reviewed/2017/10/GHSA-78j3-7wpm-qhvp/GHSA-78j3-7wpm-qhvp.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-78j3-7wpm-qhvp", - "modified": "2020-06-16T21:22:10Z", + "modified": "2023-06-09T20:09:31Z", "published": "2017-10-24T18:33:37Z", "aliases": [ "CVE-2013-1947" ], - "summary": "Critical severity vulnerability that affects kelredd-pruview", + "summary": "Shell Metacharacter Injection in kelredd-pruview", "details": "kelredd-pruview gem 0.3.8 for Ruby allows context-dependent attackers to execute arbitrary commands via shell metacharacters in a filename argument to (1) document.rb, (2) video.rb, or (3) video_image.rb.", "severity": [ @@ -41,6 +41,10 @@ "type": "ADVISORY", "url": "https://github.com/advisories/GHSA-78j3-7wpm-qhvp" }, + { + "type": "WEB", + "url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/kelredd-pruview/CVE-2013-1947.yml" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2013/04/10/3"