diff --git a/advisories/github-reviewed/2022/05/GHSA-vpqp-hx68-p2wx/GHSA-vpqp-hx68-p2wx.json b/advisories/github-reviewed/2022/05/GHSA-vpqp-hx68-p2wx/GHSA-vpqp-hx68-p2wx.json index df633841cac..fdf39df9df8 100644 --- a/advisories/github-reviewed/2022/05/GHSA-vpqp-hx68-p2wx/GHSA-vpqp-hx68-p2wx.json +++ b/advisories/github-reviewed/2022/05/GHSA-vpqp-hx68-p2wx/GHSA-vpqp-hx68-p2wx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vpqp-hx68-p2wx", - "modified": "2022-07-08T19:12:30Z", + "modified": "2024-10-28T14:37:29Z", "published": "2022-05-14T01:08:23Z", "aliases": [ "CVE-2013-2217" @@ -9,7 +9,14 @@ "summary": "Improper Link Resolution Before File Access in Suds", "details": "cache.py in Suds 0.4, when tempdir is set to None, allows local users to redirect SOAP queries and possibly have other unspecified impact via a symlink attack on a cache file with a predictable name in /tmp/suds/.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N" + } ], "affected": [ { @@ -33,6 +40,25 @@ "database_specific": { "last_known_affected_version_range": "<= 0.4" } + }, + { + "package": { + "ecosystem": "PyPI", + "name": "suds-py3" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.4.4.1" + } + ] + } + ] } ], "references": [ @@ -48,6 +74,10 @@ "type": "ADVISORY", "url": "https://github.com/advisories/GHSA-vpqp-hx68-p2wx" }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/suds-py3/PYSEC-2013-33.yaml" + }, { "type": "WEB", "url": "https://github.com/pypa/advisory-database/tree/main/vulns/suds/PYSEC-2013-32.yaml" @@ -69,7 +99,7 @@ "cwe_ids": [ "CWE-59" ], - "severity": "LOW", + "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2022-07-08T19:12:30Z", "nvd_published_at": "2013-09-23T20:55:00Z" diff --git a/advisories/github-reviewed/2022/12/GHSA-xmc3-9m9j-w9x4/GHSA-xmc3-9m9j-w9x4.json b/advisories/github-reviewed/2022/12/GHSA-xmc3-9m9j-w9x4/GHSA-xmc3-9m9j-w9x4.json index b0057f83f0e..9c491c363ea 100644 --- a/advisories/github-reviewed/2022/12/GHSA-xmc3-9m9j-w9x4/GHSA-xmc3-9m9j-w9x4.json +++ b/advisories/github-reviewed/2022/12/GHSA-xmc3-9m9j-w9x4/GHSA-xmc3-9m9j-w9x4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xmc3-9m9j-w9x4", - "modified": "2024-05-01T16:25:56Z", + "modified": "2024-10-28T14:37:58Z", "published": "2022-12-27T12:30:20Z", "aliases": [ "CVE-2021-4286" @@ -12,6 +12,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N" } ], "affected": [ @@ -56,6 +60,10 @@ "type": "WEB", "url": "https://github.com/cocagne/pysrp/releases/tag/1.0.17" }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/srp/PYSEC-2022-43014.yaml" + }, { "type": "WEB", "url": "https://vuldb.com/?ctiid.216875" diff --git a/advisories/github-reviewed/2023/02/GHSA-p24m-863f-fm6q/GHSA-p24m-863f-fm6q.json b/advisories/github-reviewed/2023/02/GHSA-p24m-863f-fm6q/GHSA-p24m-863f-fm6q.json index c713cde9000..16ba5a61042 100644 --- a/advisories/github-reviewed/2023/02/GHSA-p24m-863f-fm6q/GHSA-p24m-863f-fm6q.json +++ b/advisories/github-reviewed/2023/02/GHSA-p24m-863f-fm6q/GHSA-p24m-863f-fm6q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p24m-863f-fm6q", - "modified": "2023-02-15T17:42:42Z", + "modified": "2024-10-28T14:38:20Z", "published": "2023-02-15T17:42:42Z", "aliases": [ "CVE-2023-25578" @@ -12,6 +12,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N" } ], "affected": [ @@ -48,6 +52,10 @@ "type": "WEB", "url": "https://github.com/starlite-api/starlite/commit/9674fe803628f986c03fe60769048cbc55b5bf83" }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/starlite/PYSEC-2023-49.yaml" + }, { "type": "PACKAGE", "url": "https://github.com/starlite-api/starlite"