diff --git a/advisories/github-reviewed/2019/04/GHSA-6c3j-c64m-qhgq/GHSA-6c3j-c64m-qhgq.json b/advisories/github-reviewed/2019/04/GHSA-6c3j-c64m-qhgq/GHSA-6c3j-c64m-qhgq.json index 2b7390b43bf..5ecbd54320b 100644 --- a/advisories/github-reviewed/2019/04/GHSA-6c3j-c64m-qhgq/GHSA-6c3j-c64m-qhgq.json +++ b/advisories/github-reviewed/2019/04/GHSA-6c3j-c64m-qhgq/GHSA-6c3j-c64m-qhgq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6c3j-c64m-qhgq", - "modified": "2023-09-05T12:30:00Z", + "modified": "2024-04-22T19:44:42Z", "published": "2019-04-26T16:29:11Z", "aliases": [ "CVE-2019-11358" @@ -139,6 +139,10 @@ "type": "WEB", "url": "https://github.com/jquery/jquery/pull/4333" }, + { + "type": "WEB", + "url": "https://github.com/jquery/jquery/commit/753d591aea698e57d6db58c9f722cd0808619b1b" + }, { "type": "WEB", "url": "https://github.com/django/django/commit/34ec52269ade54af31a021b12969913129571a3f" @@ -153,76 +157,96 @@ }, { "type": "WEB", - "url": "https://github.com/jquery/jquery/commit/753d591aea698e57d6db58c9f722cd0808619b1b" - }, - { - "type": "WEB", - "url": "https://www.debian.org/security/2019/dsa-4460" - }, - { - "type": "WEB", - "url": "https://www.debian.org/security/2019/dsa-4434" - }, - { - "type": "WEB", - "url": "https://web.archive.org/web/20190824065237/http://www.securityfocus.com/bid/108023" - }, - { - "type": "WEB", - "url": "https://supportportal.juniper.net/s/article/2021-07-Security-Bulletin-Junos-OS-Multiple-J-Web-vulnerabilities-resolved-in-Junos-OS-21-2R1" - }, - { - "type": "WEB", - "url": "https://snyk.io/vuln/SNYK-JS-JQUERY-174006" - }, - { - "type": "WEB", - "url": "https://security.snyk.io/vuln/SNYK-DOTNET-JQUERY-450226" - }, - { - "type": "WEB", - "url": "https://security.netapp.com/advisory/ntap-20190919-0001" - }, - { - "type": "WEB", - "url": "https://seclists.org/bugtraq/2019/May/18" - }, - { - "type": "WEB", - "url": "https://seclists.org/bugtraq/2019/Jun/12" - }, - { - "type": "WEB", - "url": "https://seclists.org/bugtraq/2019/Apr/32" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WZW27UCJ5CYFL4KFFFMYMIBNMIU2ALG5" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RLXRX23725JL366CNZGJZ7AQQB7LHQ6F" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QV3PKZC3PQCO3273HAT76PAQZFBEO4KP" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KYH3OAGR2RTCHRA5NOKX2TES7SNQMWGO" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5IABSKTYZ5JUGL735UKGXL5YPRYOPUYI" + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WZW27UCJ5CYFL4KFFFMYMIBNMIU2ALG5" }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4UOAZIFCSZ3ENEFOR5IXX6NFAD3HV7FA" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5IABSKTYZ5JUGL735UKGXL5YPRYOPUYI" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KYH3OAGR2RTCHRA5NOKX2TES7SNQMWGO" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QV3PKZC3PQCO3273HAT76PAQZFBEO4KP" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RLXRX23725JL366CNZGJZ7AQQB7LHQ6F" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WZW27UCJ5CYFL4KFFFMYMIBNMIU2ALG5" + }, + { + "type": "WEB", + "url": "https://seclists.org/bugtraq/2019/Apr/32" + }, + { + "type": "WEB", + "url": "https://seclists.org/bugtraq/2019/Jun/12" + }, + { + "type": "WEB", + "url": "https://seclists.org/bugtraq/2019/May/18" + }, { "type": "WEB", "url": "https://www.tenable.com/security/tns-2020-02" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RLXRX23725JL366CNZGJZ7AQQB7LHQ6F" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QV3PKZC3PQCO3273HAT76PAQZFBEO4KP" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KYH3OAGR2RTCHRA5NOKX2TES7SNQMWGO" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5IABSKTYZ5JUGL735UKGXL5YPRYOPUYI" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4UOAZIFCSZ3ENEFOR5IXX6NFAD3HV7FA" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2023/08/msg00040.html" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2020/02/msg00024.html" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2019/05/msg00029.html" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2019/05/msg00006.html" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b@%3Ccommits.nifi.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b%40%3Ccommits.nifi.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/rac25da84ecdcd36f6de5ad0d255f4e967209bbbebddb285e231da37d@%3Cissues.flink.apache.org%3E" + }, { "type": "WEB", "url": "https://www.tenable.com/security/tns-2019-08" @@ -287,30 +311,82 @@ "type": "WEB", "url": "https://www.djangoproject.com/weblog/2019/jun/03/security-releases" }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2019/dsa-4460" + }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2019/dsa-4434" + }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20190824065237/http://www.securityfocus.com/bid/108023" + }, + { + "type": "WEB", + "url": "https://supportportal.juniper.net/s/article/2021-07-Security-Bulletin-Junos-OS-Multiple-J-Web-vulnerabilities-resolved-in-Junos-OS-21-2R1" + }, + { + "type": "WEB", + "url": "https://snyk.io/vuln/SNYK-JS-JQUERY-174006" + }, + { + "type": "WEB", + "url": "https://security.snyk.io/vuln/SNYK-DOTNET-JQUERY-450226" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20190919-0001" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/88fb0362fd40e5b605ea8149f63241537b8b6fb5bfa315391fc5cbb7@%3Ccommits.airflow.apache.org%3E" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/88fb0362fd40e5b605ea8149f63241537b8b6fb5bfa315391fc5cbb7%40%3Ccommits.airflow.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/6097cdbd6f0a337bedd9bb5cc441b2d525ff002a96531de367e4259f@%3Ccommits.airflow.apache.org%3E" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/6097cdbd6f0a337bedd9bb5cc441b2d525ff002a96531de367e4259f%40%3Ccommits.airflow.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/5928aa293e39d248266472210c50f176cac1535220f2486e6a7fa844@%3Ccommits.airflow.apache.org%3E" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/5928aa293e39d248266472210c50f176cac1535220f2486e6a7fa844%40%3Ccommits.airflow.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/08720ef215ee7ab3386c05a1a90a7d1c852bf0706f176a7816bf65fc@%3Ccommits.airflow.apache.org%3E" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/08720ef215ee7ab3386c05a1a90a7d1c852bf0706f176a7816bf65fc%40%3Ccommits.airflow.apache.org%3E" + }, { "type": "WEB", "url": "https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44601" @@ -357,72 +433,96 @@ }, { "type": "WEB", - "url": "https://lists.debian.org/debian-lts-announce/2023/08/msg00040.html" - }, - { - "type": "WEB", - "url": "https://lists.debian.org/debian-lts-announce/2020/02/msg00024.html" - }, - { - "type": "WEB", - "url": "https://lists.debian.org/debian-lts-announce/2019/05/msg00029.html" - }, - { - "type": "WEB", - "url": "https://lists.debian.org/debian-lts-announce/2019/05/msg00006.html" - }, - { - "type": "WEB", - "url": "https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b@%3Ccommits.nifi.apache.org%3E" - }, - { - "type": "WEB", - "url": "https://lists.apache.org/thread.html/rac25da84ecdcd36f6de5ad0d255f4e967209bbbebddb285e231da37d@%3Cissues.flink.apache.org%3E" + "url": "https://lists.apache.org/thread.html/rac25da84ecdcd36f6de5ad0d255f4e967209bbbebddb285e231da37d%40%3Cissues.flink.apache.org%3E" }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/r7e8ebccb7c022e41295f6fdb7b971209b83702339f872ddd8cf8bf73@%3Cissues.flink.apache.org%3E" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r7e8ebccb7c022e41295f6fdb7b971209b83702339f872ddd8cf8bf73%40%3Cissues.flink.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/r7d64895cc4dff84d0becfc572b20c0e4bf9bfa7b10c6f5f73e783734@%3Cdev.storm.apache.org%3E" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r7d64895cc4dff84d0becfc572b20c0e4bf9bfa7b10c6f5f73e783734%40%3Cdev.storm.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/r7aac081cbddb6baa24b75e74abf0929bf309b176755a53e3ed810355@%3Cdev.flink.apache.org%3E" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r7aac081cbddb6baa24b75e74abf0929bf309b176755a53e3ed810355%40%3Cdev.flink.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/r41b5bfe009c845f67d4f68948cc9419ac2d62e287804aafd72892b08@%3Cissues.flink.apache.org%3E" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r41b5bfe009c845f67d4f68948cc9419ac2d62e287804aafd72892b08%40%3Cissues.flink.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/r38f0d1aa3c923c22977fe7376508f030f22e22c1379fbb155bf29766@%3Cdev.syncope.apache.org%3E" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r38f0d1aa3c923c22977fe7376508f030f22e22c1379fbb155bf29766%40%3Cdev.syncope.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/r2baacab6e0acb5a2092eb46ae04fd6c3e8277b4fd79b1ffb7f3254fa@%3Cissues.flink.apache.org%3E" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r2baacab6e0acb5a2092eb46ae04fd6c3e8277b4fd79b1ffb7f3254fa%40%3Cissues.flink.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/r2041a75d3fc09dec55adfd95d598b38d22715303f65c997c054844c9@%3Cissues.flink.apache.org%3E" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r2041a75d3fc09dec55adfd95d598b38d22715303f65c997c054844c9%40%3Cissues.flink.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3@%3Ccommits.nifi.apache.org%3E" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3%40%3Ccommits.nifi.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/ba79cf1658741e9f146e4c59b50aee56656ea95d841d358d006c18b6@%3Ccommits.roller.apache.org%3E" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/ba79cf1658741e9f146e4c59b50aee56656ea95d841d358d006c18b6%40%3Ccommits.roller.apache.org%3E" + }, { "type": "WEB", "url": "https://lists.apache.org/thread.html/b736d0784cf02f5a30fbb4c5902762a15ad6d47e17e2c5a17b7d6205@%3Ccommits.airflow.apache.org%3E" }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/b736d0784cf02f5a30fbb4c5902762a15ad6d47e17e2c5a17b7d6205%40%3Ccommits.airflow.apache.org%3E" + }, { "type": "WEB", "url": "http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00006.html" diff --git a/advisories/unreviewed/2022/04/GHSA-ffhq-g856-9f2p/GHSA-ffhq-g856-9f2p.json b/advisories/github-reviewed/2022/04/GHSA-ffhq-g856-9f2p/GHSA-ffhq-g856-9f2p.json similarity index 71% rename from advisories/unreviewed/2022/04/GHSA-ffhq-g856-9f2p/GHSA-ffhq-g856-9f2p.json rename to advisories/github-reviewed/2022/04/GHSA-ffhq-g856-9f2p/GHSA-ffhq-g856-9f2p.json index 0f2001d0f0e..7114e1dea6b 100644 --- a/advisories/unreviewed/2022/04/GHSA-ffhq-g856-9f2p/GHSA-ffhq-g856-9f2p.json +++ b/advisories/github-reviewed/2022/04/GHSA-ffhq-g856-9f2p/GHSA-ffhq-g856-9f2p.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-ffhq-g856-9f2p", - "modified": "2024-03-21T03:34:12Z", + "modified": "2024-04-22T19:43:49Z", "published": "2022-04-13T00:00:22Z", "aliases": [ "CVE-2022-28397" ], + "summary": "Arbitrary file upload in Ghost", "details": "An arbitrary file upload vulnerability in the file upload module of Ghost CMS v4.42.0 allows attackers to execute arbitrary code via a crafted file.", "severity": [ { @@ -14,7 +15,25 @@ } ], "affected": [ - + { + "package": { + "ecosystem": "npm", + "name": "ghost" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "4.42.0" + } + ] + } + ] + } ], "references": [ { @@ -51,8 +70,8 @@ "CWE-434" ], "severity": "CRITICAL", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-04-22T19:43:49Z", "nvd_published_at": "2022-04-12T17:15:00Z" } } \ No newline at end of file