From 5e50a0350d79ad43bc9fe400467a78cf44730d57 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 26 Jan 2024 21:35:25 +0000 Subject: [PATCH] Publish Advisories GHSA-4m77-cmpx-vjc4 GHSA-5xfx-55x4-j223 GHSA-gvc7-gjrw-hj65 GHSA-rhhj-5436-95vf --- .../GHSA-4m77-cmpx-vjc4/GHSA-4m77-cmpx-vjc4.json | 14 +++++++++++--- .../GHSA-5xfx-55x4-j223/GHSA-5xfx-55x4-j223.json | 6 +++--- .../GHSA-gvc7-gjrw-hj65/GHSA-gvc7-gjrw-hj65.json | 7 +++++-- .../GHSA-rhhj-5436-95vf/GHSA-rhhj-5436-95vf.json | 10 +++++++--- 4 files changed, 26 insertions(+), 11 deletions(-) diff --git a/advisories/github-reviewed/2024/01/GHSA-4m77-cmpx-vjc4/GHSA-4m77-cmpx-vjc4.json b/advisories/github-reviewed/2024/01/GHSA-4m77-cmpx-vjc4/GHSA-4m77-cmpx-vjc4.json index ccaf8eaebb1..b839616da29 100644 --- a/advisories/github-reviewed/2024/01/GHSA-4m77-cmpx-vjc4/GHSA-4m77-cmpx-vjc4.json +++ b/advisories/github-reviewed/2024/01/GHSA-4m77-cmpx-vjc4/GHSA-4m77-cmpx-vjc4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4m77-cmpx-vjc4", - "modified": "2024-01-19T20:24:09Z", + "modified": "2024-01-26T21:34:15Z", "published": "2024-01-19T20:24:09Z", "aliases": [ "CVE-2024-22420" @@ -65,10 +65,18 @@ "type": "WEB", "url": "https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-4m77-cmpx-vjc4" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22420" + }, { "type": "WEB", "url": "https://github.com/jupyterlab/jupyterlab/commit/dda0033cd49449572d077bbecd33b18d8d05f48a" }, + { + "type": "WEB", + "url": "https://github.com/jupyterlab/jupyterlab/commit/e1b3aabab603878e46add445a3114e838411d2df" + }, { "type": "PACKAGE", "url": "https://github.com/jupyterlab/jupyterlab" @@ -76,11 +84,11 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-79" ], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2024-01-19T20:24:09Z", - "nvd_published_at": null + "nvd_published_at": "2024-01-19T21:15:09Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2024/01/GHSA-5xfx-55x4-j223/GHSA-5xfx-55x4-j223.json b/advisories/github-reviewed/2024/01/GHSA-5xfx-55x4-j223/GHSA-5xfx-55x4-j223.json index b36e186c538..3ea473f767b 100644 --- a/advisories/github-reviewed/2024/01/GHSA-5xfx-55x4-j223/GHSA-5xfx-55x4-j223.json +++ b/advisories/github-reviewed/2024/01/GHSA-5xfx-55x4-j223/GHSA-5xfx-55x4-j223.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5xfx-55x4-j223", - "modified": "2024-01-19T16:02:32Z", + "modified": "2024-01-26T21:34:11Z", "published": "2024-01-18T15:30:37Z", "aliases": [ "CVE-2024-0669" @@ -11,7 +11,7 @@ "severity": [ { "type": "CVSS_V3", - "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" } ], "affected": [ @@ -56,7 +56,7 @@ "cwe_ids": [ "CWE-1021" ], - "severity": "MODERATE", + "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2024-01-19T16:02:32Z", "nvd_published_at": "2024-01-18T13:15:09Z" diff --git a/advisories/github-reviewed/2024/01/GHSA-gvc7-gjrw-hj65/GHSA-gvc7-gjrw-hj65.json b/advisories/github-reviewed/2024/01/GHSA-gvc7-gjrw-hj65/GHSA-gvc7-gjrw-hj65.json index 2c885dbcfcb..fecc884622b 100644 --- a/advisories/github-reviewed/2024/01/GHSA-gvc7-gjrw-hj65/GHSA-gvc7-gjrw-hj65.json +++ b/advisories/github-reviewed/2024/01/GHSA-gvc7-gjrw-hj65/GHSA-gvc7-gjrw-hj65.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gvc7-gjrw-hj65", - "modified": "2024-01-23T14:36:13Z", + "modified": "2024-01-26T21:34:27Z", "published": "2024-01-19T21:30:36Z", "aliases": [ "CVE-2024-23680" @@ -9,7 +9,10 @@ "summary": "Improper Verification of Cryptographic Signature in aws-encryption-sdk-java", "details": "AWS Encryption SDK for Java versions 2.0.0 to 2.2.0 and less than 1.9.0 incorrectly validates some invalid ECDSA signatures. \n\n\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } ], "affected": [ { diff --git a/advisories/github-reviewed/2024/01/GHSA-rhhj-5436-95vf/GHSA-rhhj-5436-95vf.json b/advisories/github-reviewed/2024/01/GHSA-rhhj-5436-95vf/GHSA-rhhj-5436-95vf.json index d2d0f29edf3..988c98dcea8 100644 --- a/advisories/github-reviewed/2024/01/GHSA-rhhj-5436-95vf/GHSA-rhhj-5436-95vf.json +++ b/advisories/github-reviewed/2024/01/GHSA-rhhj-5436-95vf/GHSA-rhhj-5436-95vf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rhhj-5436-95vf", - "modified": "2024-01-22T21:27:26Z", + "modified": "2024-01-26T21:34:39Z", "published": "2024-01-21T18:30:34Z", "aliases": [ "CVE-2024-23731" @@ -9,7 +9,10 @@ "summary": "Code execution in Embedchain", "details": "The OpenAPI loader in Embedchain before 0.1.57 allows attackers to execute arbitrary code, related to the openapi.py yaml.load function argument.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ { @@ -56,9 +59,10 @@ ], "database_specific": { "cwe_ids": [ + "CWE-88", "CWE-94" ], - "severity": "HIGH", + "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2024-01-22T21:27:26Z", "nvd_published_at": "2024-01-21T17:15:44Z"