From 5a2518cfe366e3ee2476d8a6e000a6e27ba2cb9f Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 21 Dec 2023 15:55:25 +0000 Subject: [PATCH] Publish Advisories GHSA-3pjv-r7w4-2cf5 GHSA-45x7-px36-x8w8 --- .../GHSA-3pjv-r7w4-2cf5.json | 10 ++++-- .../GHSA-45x7-px36-x8w8.json | 36 +++++++++++++++++++ 2 files changed, 43 insertions(+), 3 deletions(-) diff --git a/advisories/github-reviewed/2023/12/GHSA-3pjv-r7w4-2cf5/GHSA-3pjv-r7w4-2cf5.json b/advisories/github-reviewed/2023/12/GHSA-3pjv-r7w4-2cf5/GHSA-3pjv-r7w4-2cf5.json index 3ee5e173e83..c8e19118efd 100644 --- a/advisories/github-reviewed/2023/12/GHSA-3pjv-r7w4-2cf5/GHSA-3pjv-r7w4-2cf5.json +++ b/advisories/github-reviewed/2023/12/GHSA-3pjv-r7w4-2cf5/GHSA-3pjv-r7w4-2cf5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3pjv-r7w4-2cf5", - "modified": "2023-12-20T21:12:37Z", + "modified": "2023-12-21T15:53:49Z", "published": "2023-12-20T21:12:09Z", "aliases": [ "CVE-2023-46131" @@ -97,6 +97,10 @@ "type": "WEB", "url": "https://github.com/grails/grails-core/security/advisories/GHSA-3pjv-r7w4-2cf5" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-46131" + }, { "type": "WEB", "url": "https://github.com/grails/grails-core/issues/13302" @@ -120,11 +124,11 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-400" ], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2023-12-20T21:12:09Z", - "nvd_published_at": null + "nvd_published_at": "2023-12-21T00:15:25Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2023/12/GHSA-45x7-px36-x8w8/GHSA-45x7-px36-x8w8.json b/advisories/github-reviewed/2023/12/GHSA-45x7-px36-x8w8/GHSA-45x7-px36-x8w8.json index 152f4f80f8a..afac82a94da 100644 --- a/advisories/github-reviewed/2023/12/GHSA-45x7-px36-x8w8/GHSA-45x7-px36-x8w8.json +++ b/advisories/github-reviewed/2023/12/GHSA-45x7-px36-x8w8/GHSA-45x7-px36-x8w8.json @@ -82,6 +82,18 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-48795" }, + { + "type": "WEB", + "url": "https://github.com/apache/mina-sshd/issues/445" + }, + { + "type": "WEB", + "url": "https://github.com/hierynomus/sshj/issues/916" + }, + { + "type": "WEB", + "url": "https://github.com/janmojzis/tinyssh/issues/81" + }, { "type": "WEB", "url": "https://github.com/mwiede/jsch/issues/457" @@ -194,10 +206,22 @@ "type": "WEB", "url": "https://github.com/mwiede/jsch/compare/jsch-0.2.14...jsch-0.2.15" }, + { + "type": "WEB", + "url": "https://github.com/net-ssh/net-ssh/blob/2e65064a52d73396bfc3806c9196fc8108f33cd8/CHANGES.txt#L14-L16" + }, { "type": "WEB", "url": "https://github.com/openssh/openssh-portable/commits/master" }, + { + "type": "WEB", + "url": "https://github.com/proftpd/proftpd/blob/0a7ea9b0ba9fcdf368374a226370d08f10397d99/RELEASE_NOTES" + }, + { + "type": "WEB", + "url": "https://github.com/proftpd/proftpd/blob/d21e7a2e47e9b38f709bec58e3fa711f759ad0e1/RELEASE_NOTES" + }, { "type": "WEB", "url": "https://github.com/proftpd/proftpd/blob/master/RELEASE_NOTES" @@ -278,6 +302,10 @@ "type": "WEB", "url": "https://security-tracker.debian.org/tracker/source-package/proftpd-dfsg" }, + { + "type": "WEB", + "url": "https://security-tracker.debian.org/tracker/source-package/trilead-ssh2" + }, { "type": "WEB", "url": "https://thorntech.com/cve-2023-48795-and-sftp-gateway/" @@ -322,6 +350,10 @@ "type": "WEB", "url": "https://www.openwall.com/lists/oss-security/2023/12/18/2" }, + { + "type": "WEB", + "url": "https://www.openwall.com/lists/oss-security/2023/12/20/3" + }, { "type": "WEB", "url": "https://www.paramiko.org/changelog.html" @@ -338,6 +370,10 @@ "type": "WEB", "url": "https://www.terrapin-attack.com" }, + { + "type": "WEB", + "url": "http://packetstormsecurity.com/files/176280/Terrapin-SSH-Connection-Weakening.html" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2023/12/18/3"