diff --git a/advisories/github-reviewed/2019/07/GHSA-j3jp-gvr5-7hwq/GHSA-j3jp-gvr5-7hwq.json b/advisories/github-reviewed/2019/07/GHSA-j3jp-gvr5-7hwq/GHSA-j3jp-gvr5-7hwq.json index 2ffd3579933..a36b2637838 100644 --- a/advisories/github-reviewed/2019/07/GHSA-j3jp-gvr5-7hwq/GHSA-j3jp-gvr5-7hwq.json +++ b/advisories/github-reviewed/2019/07/GHSA-j3jp-gvr5-7hwq/GHSA-j3jp-gvr5-7hwq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j3jp-gvr5-7hwq", - "modified": "2022-09-17T00:18:27Z", + "modified": "2024-10-25T20:48:05Z", "published": "2019-07-30T20:47:25Z", "aliases": [ "CVE-2019-13611" @@ -12,6 +12,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" } ], "affected": [ @@ -58,6 +62,10 @@ { "type": "PACKAGE", "url": "https://github.com/miguelgrinberg/python-engineio" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/python-engineio/PYSEC-2019-170.yaml" } ], "database_specific": { diff --git a/advisories/github-reviewed/2020/03/GHSA-qh62-ch95-63wh/GHSA-qh62-ch95-63wh.json b/advisories/github-reviewed/2020/03/GHSA-qh62-ch95-63wh/GHSA-qh62-ch95-63wh.json index 0700a38a769..45fa4fee70c 100644 --- a/advisories/github-reviewed/2020/03/GHSA-qh62-ch95-63wh/GHSA-qh62-ch95-63wh.json +++ b/advisories/github-reviewed/2020/03/GHSA-qh62-ch95-63wh/GHSA-qh62-ch95-63wh.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-qh62-ch95-63wh", - "modified": "2020-06-16T20:41:56Z", + "modified": "2024-10-25T20:48:46Z", "published": "2020-03-13T20:05:10Z", "withdrawn": "2020-06-16T20:25:44Z", "aliases": [ ], - "summary": "python-gnupg allows context-dependent attackers to trick gnupg to decrypt other ciphertext than intended", + "summary": "Duplicate Advisory: python-gnupg allows context-dependent attackers to trick gnupg to decrypt other ciphertext than intended", "details": "**Withdrawn:** Duplicate of GHSA-2fch-jvg5-crf6", "severity": [ @@ -46,14 +46,34 @@ "type": "WEB", "url": "https://blog.hackeriet.no/cve-2019-6690-python-gnupg-vulnerability" }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-2fch-jvg5-crf6" + }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-qh62-ch95-63wh" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/python-gnupg/PYSEC-2019-115.yaml" + }, { "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2019/02/msg00021.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3WMV6XNPPL3VB3RQRFFOBCJ3AGWC4K47" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/W6KYZMN2PWXY4ENZVJUVTGFBVYEVY7II" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X4VFRUG56542LTYK4444TPJBGR57MT25" + }, { "type": "WEB", "url": "https://pypi.org/project/python-gnupg/#history" diff --git a/advisories/github-reviewed/2022/05/GHSA-qwqv-j7jr-4hp6/GHSA-qwqv-j7jr-4hp6.json b/advisories/github-reviewed/2022/05/GHSA-qwqv-j7jr-4hp6/GHSA-qwqv-j7jr-4hp6.json index 7efc1e56b75..05f1d2dcbfd 100644 --- a/advisories/github-reviewed/2022/05/GHSA-qwqv-j7jr-4hp6/GHSA-qwqv-j7jr-4hp6.json +++ b/advisories/github-reviewed/2022/05/GHSA-qwqv-j7jr-4hp6/GHSA-qwqv-j7jr-4hp6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qwqv-j7jr-4hp6", - "modified": "2024-03-21T16:30:19Z", + "modified": "2024-10-25T20:49:07Z", "published": "2022-05-06T00:00:54Z", "aliases": [ "CVE-2022-30284" @@ -12,6 +12,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" } ], "affected": [ @@ -20,11 +24,6 @@ "ecosystem": "PyPI", "name": "python-libnmap" }, - "ecosystem_specific": { - "affected_functions": [ - "libnmap.process.NmapProcess.get_command_line" - ] - }, "ranges": [ { "type": "ECOSYSTEM", @@ -52,6 +51,10 @@ "type": "WEB", "url": "https://github.com/savon-noir/python-libnmap/commit/c36fecde90017befeb4853396d0e2aac93c95b64" }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/python-libnmap/PYSEC-2022-42999.yaml" + }, { "type": "PACKAGE", "url": "https://github.com/savon-noir/python-libnmap"