diff --git a/advisories/github-reviewed/2022/02/GHSA-mmjr-5q74-p3m4/GHSA-mmjr-5q74-p3m4.json b/advisories/github-reviewed/2022/02/GHSA-mmjr-5q74-p3m4/GHSA-mmjr-5q74-p3m4.json index 446e41b13c3..0743888dffd 100644 --- a/advisories/github-reviewed/2022/02/GHSA-mmjr-5q74-p3m4/GHSA-mmjr-5q74-p3m4.json +++ b/advisories/github-reviewed/2022/02/GHSA-mmjr-5q74-p3m4/GHSA-mmjr-5q74-p3m4.json @@ -71,6 +71,63 @@ ] } ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "drupal/drupal" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "8.0.0" + }, + { + "fixed": "8.8.10" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "drupal/drupal" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "8.9.0" + }, + { + "fixed": "8.9.6" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "drupal/drupal" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "9.0.0" + }, + { + "fixed": "9.0.6" + } + ] + } + ] } ], "references": [ @@ -82,6 +139,14 @@ "type": "WEB", "url": "https://github.com/drupal/core/commit/f93a37b713b59f8d24e826bc74378099853eef3d" }, + { + "type": "WEB", + "url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/drupal/core/CVE-2020-13670.yaml" + }, + { + "type": "WEB", + "url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/drupal/drupal/CVE-2020-13670.yaml" + }, { "type": "PACKAGE", "url": "https://github.com/drupal/core" diff --git a/advisories/github-reviewed/2022/05/GHSA-g78h-pf65-46rv/GHSA-g78h-pf65-46rv.json b/advisories/github-reviewed/2022/05/GHSA-g78h-pf65-46rv/GHSA-g78h-pf65-46rv.json index 66c1d7ac62d..54b907d1435 100644 --- a/advisories/github-reviewed/2022/05/GHSA-g78h-pf65-46rv/GHSA-g78h-pf65-46rv.json +++ b/advisories/github-reviewed/2022/05/GHSA-g78h-pf65-46rv/GHSA-g78h-pf65-46rv.json @@ -15,25 +15,6 @@ } ], "affected": [ - { - "package": { - "ecosystem": "Packagist", - "name": "drupal/core" - }, - "ranges": [ - { - "type": "ECOSYSTEM", - "events": [ - { - "introduced": "8.0" - }, - { - "fixed": "8.4.7" - } - ] - } - ] - }, { "package": { "ecosystem": "Packagist", @@ -71,6 +52,63 @@ ] } ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "drupal/core" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "8.0" + }, + { + "fixed": "8.4.7" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "drupal/drupal" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "8.0" + }, + { + "fixed": "8.4.7" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "drupal/drupal" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "8.5" + }, + { + "fixed": "8.5.2" + } + ] + } + ] } ], "references": [ @@ -78,6 +116,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9861" }, + { + "type": "WEB", + "url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/drupal/core/CVE-2018-9861.yaml" + }, + { + "type": "WEB", + "url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/drupal/drupal/CVE-2018-9861.yaml" + }, { "type": "WEB", "url": "https://github.com/ckeditor/ckeditor-dev/blob/master/CHANGES.md" diff --git a/advisories/github-reviewed/2022/10/GHSA-5hw4-m7f3-hhx8/GHSA-5hw4-m7f3-hhx8.json b/advisories/github-reviewed/2022/10/GHSA-5hw4-m7f3-hhx8/GHSA-5hw4-m7f3-hhx8.json index 5345103784b..fd7442d468a 100644 --- a/advisories/github-reviewed/2022/10/GHSA-5hw4-m7f3-hhx8/GHSA-5hw4-m7f3-hhx8.json +++ b/advisories/github-reviewed/2022/10/GHSA-5hw4-m7f3-hhx8/GHSA-5hw4-m7f3-hhx8.json @@ -33,6 +33,63 @@ ] } ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "fooman/tcpdf" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "6.2.22" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "la-haute-societe/tcpdf" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "6.2.22" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "spoonity/tcpdf" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "6.2.22" + } + ] + } + ] } ], "references": [ @@ -52,6 +109,22 @@ "type": "WEB", "url": "https://contao.org/en/news/security-vulnerability-cve-2018-17057.html" }, + { + "type": "WEB", + "url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/fooman/tcpdf/CVE-2018-17057.yaml" + }, + { + "type": "WEB", + "url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/la-haute-societe/tcpdf/CVE-2018-17057.yaml" + }, + { + "type": "WEB", + "url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/spoonity/tcpdf/CVE-2018-17057.yaml" + }, + { + "type": "WEB", + "url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/tecnickcom/tcpdf/CVE-2018-17057.yaml" + }, { "type": "WEB", "url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/wallabag/tcpdf/CVE-2018-17057.yaml" diff --git a/advisories/github-reviewed/2024/01/GHSA-xq62-62c9-22mg/GHSA-xq62-62c9-22mg.json b/advisories/github-reviewed/2024/01/GHSA-xq62-62c9-22mg/GHSA-xq62-62c9-22mg.json deleted file mode 100644 index 4df8bee365c..00000000000 --- a/advisories/github-reviewed/2024/01/GHSA-xq62-62c9-22mg/GHSA-xq62-62c9-22mg.json +++ /dev/null @@ -1,68 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-xq62-62c9-22mg", - "modified": "2024-01-11T15:43:15Z", - "published": "2024-01-11T15:43:15Z", - "aliases": [ - "CVE-2019-6342" - ], - "summary": "Drupal Improper Access Control", - "details": "An access bypass vulnerability exists when the experimental Workspaces module in Drupal 8 core is enabled. This can be mitigated by disabling the Workspaces module. It does not affect any release other than Drupal 8.7.4.", - "severity": [ - { - "type": "CVSS_V3", - "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" - } - ], - "affected": [ - { - "package": { - "ecosystem": "Packagist", - "name": "drupal/core" - }, - "ranges": [ - { - "type": "ECOSYSTEM", - "events": [ - { - "introduced": "8.7.4" - }, - { - "fixed": "8.7.5" - } - ] - } - ], - "versions": [ - "8.7.4" - ] - } - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-6342" - }, - { - "type": "WEB", - "url": "https://github.com/drupal/core/commit/bac9bde22bb545ff72570d8a46055c6c6e70e7c5" - }, - { - "type": "PACKAGE", - "url": "https://github.com/drupal/core" - }, - { - "type": "WEB", - "url": "https://www.drupal.org/sa-core-2019-008" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-284" - ], - "severity": "CRITICAL", - "github_reviewed": true, - "github_reviewed_at": "2024-01-11T15:43:15Z", - "nvd_published_at": "2020-05-28T21:15:00Z" - } -} \ No newline at end of file