From 5688d7e32b418af593adda3ceaef0c73d5723a54 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 26 Jul 2024 21:38:11 +0000 Subject: [PATCH] Publish Advisories GHSA-ggpm-9qfx-mhwg GHSA-5357-c2jx-v7qh GHSA-5vgj-ggm4-fg62 GHSA-x72p-g37q-4xr9 --- .../2024/01/GHSA-ggpm-9qfx-mhwg/GHSA-ggpm-9qfx-mhwg.json | 6 +++++- .../2024/06/GHSA-5357-c2jx-v7qh/GHSA-5357-c2jx-v7qh.json | 6 +++++- .../2024/06/GHSA-5vgj-ggm4-fg62/GHSA-5vgj-ggm4-fg62.json | 6 +++++- .../2024/07/GHSA-x72p-g37q-4xr9/GHSA-x72p-g37q-4xr9.json | 5 +++-- 4 files changed, 18 insertions(+), 5 deletions(-) diff --git a/advisories/github-reviewed/2024/01/GHSA-ggpm-9qfx-mhwg/GHSA-ggpm-9qfx-mhwg.json b/advisories/github-reviewed/2024/01/GHSA-ggpm-9qfx-mhwg/GHSA-ggpm-9qfx-mhwg.json index 27fe0e4b56c..01c59844d93 100644 --- a/advisories/github-reviewed/2024/01/GHSA-ggpm-9qfx-mhwg/GHSA-ggpm-9qfx-mhwg.json +++ b/advisories/github-reviewed/2024/01/GHSA-ggpm-9qfx-mhwg/GHSA-ggpm-9qfx-mhwg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ggpm-9qfx-mhwg", - "modified": "2024-01-22T21:23:26Z", + "modified": "2024-07-26T21:37:07Z", "published": "2024-01-13T03:30:17Z", "aliases": [ "CVE-2023-46942" @@ -44,6 +44,10 @@ "type": "WEB", "url": "https://github.com/evershopcommerce/evershop/commit/6e16f046e0b95efa16431a5ea41c22215273e9dd" }, + { + "type": "WEB", + "url": "https://advisory.checkmarx.net/advisory/CVE-2023-46942" + }, { "type": "WEB", "url": "https://devhub.checkmarx.com/cve-details/CVE-2023-46942" diff --git a/advisories/github-reviewed/2024/06/GHSA-5357-c2jx-v7qh/GHSA-5357-c2jx-v7qh.json b/advisories/github-reviewed/2024/06/GHSA-5357-c2jx-v7qh/GHSA-5357-c2jx-v7qh.json index 63bbd96de5c..f7b6ab34002 100644 --- a/advisories/github-reviewed/2024/06/GHSA-5357-c2jx-v7qh/GHSA-5357-c2jx-v7qh.json +++ b/advisories/github-reviewed/2024/06/GHSA-5357-c2jx-v7qh/GHSA-5357-c2jx-v7qh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5357-c2jx-v7qh", - "modified": "2024-06-20T09:30:57Z", + "modified": "2024-07-26T21:36:55Z", "published": "2024-06-09T21:30:33Z", "aliases": [ "CVE-2024-37568" @@ -59,6 +59,10 @@ { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IZI7HYGN7VZAYFV6UV3SRLYF7QGERXIU" + }, + { + "type": "WEB", + "url": "https://www.vicarius.io/vsociety/posts/algorithm-confusion-in-lepture-authlib-cve-2024-37568" } ], "database_specific": { diff --git a/advisories/github-reviewed/2024/06/GHSA-5vgj-ggm4-fg62/GHSA-5vgj-ggm4-fg62.json b/advisories/github-reviewed/2024/06/GHSA-5vgj-ggm4-fg62/GHSA-5vgj-ggm4-fg62.json index 7fb08a34840..dd34d8aab83 100644 --- a/advisories/github-reviewed/2024/06/GHSA-5vgj-ggm4-fg62/GHSA-5vgj-ggm4-fg62.json +++ b/advisories/github-reviewed/2024/06/GHSA-5vgj-ggm4-fg62/GHSA-5vgj-ggm4-fg62.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5vgj-ggm4-fg62", - "modified": "2024-06-26T15:06:20Z", + "modified": "2024-07-26T21:36:47Z", "published": "2024-06-25T22:23:30Z", "aliases": [ "CVE-2024-38526" @@ -59,6 +59,10 @@ { "type": "WEB", "url": "https://sansec.io/research/polyfill-supply-chain-attack" + }, + { + "type": "WEB", + "url": "https://www.vicarius.io/vsociety/posts/polyfillio-in-pdoc-cve-2024-38526" } ], "database_specific": { diff --git a/advisories/github-reviewed/2024/07/GHSA-x72p-g37q-4xr9/GHSA-x72p-g37q-4xr9.json b/advisories/github-reviewed/2024/07/GHSA-x72p-g37q-4xr9/GHSA-x72p-g37q-4xr9.json index 775b06aa4f0..64f8dc128a8 100644 --- a/advisories/github-reviewed/2024/07/GHSA-x72p-g37q-4xr9/GHSA-x72p-g37q-4xr9.json +++ b/advisories/github-reviewed/2024/07/GHSA-x72p-g37q-4xr9/GHSA-x72p-g37q-4xr9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x72p-g37q-4xr9", - "modified": "2024-07-22T18:46:59Z", + "modified": "2024-07-26T21:37:16Z", "published": "2024-07-22T09:31:55Z", "aliases": [ "CVE-2024-40430" @@ -55,7 +55,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-323" + "CWE-323", + "CWE-639" ], "severity": "MODERATE", "github_reviewed": true,