diff --git a/advisories/github-reviewed/2020/07/GHSA-2v5c-755p-p4gv/GHSA-2v5c-755p-p4gv.json b/advisories/github-reviewed/2020/07/GHSA-2v5c-755p-p4gv/GHSA-2v5c-755p-p4gv.json index 8f952c64819..b29509bf690 100644 --- a/advisories/github-reviewed/2020/07/GHSA-2v5c-755p-p4gv/GHSA-2v5c-755p-p4gv.json +++ b/advisories/github-reviewed/2020/07/GHSA-2v5c-755p-p4gv/GHSA-2v5c-755p-p4gv.json @@ -76,6 +76,10 @@ "type": "PACKAGE", "url": "https://github.com/faye/faye-websocket-ruby" }, + { + "type": "WEB", + "url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/faye-websocket/CVE-2020-15133.yml" + }, { "type": "ADVISORY", "url": "https://securitylab.github.com/advisories/GHSL-2020-094-igrigorik-em-http-request" diff --git a/advisories/github-reviewed/2020/07/GHSA-3q49-h8f9-9fr9/GHSA-3q49-h8f9-9fr9.json b/advisories/github-reviewed/2020/07/GHSA-3q49-h8f9-9fr9/GHSA-3q49-h8f9-9fr9.json index 471d639ded6..f5bee525979 100644 --- a/advisories/github-reviewed/2020/07/GHSA-3q49-h8f9-9fr9/GHSA-3q49-h8f9-9fr9.json +++ b/advisories/github-reviewed/2020/07/GHSA-3q49-h8f9-9fr9/GHSA-3q49-h8f9-9fr9.json @@ -72,6 +72,10 @@ "type": "WEB", "url": "https://blog.jcoglan.com/2020/07/31/missing-tls-verification-in-faye/" }, + { + "type": "WEB", + "url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/faye/CVE-2020-15134.yml" + }, { "type": "ADVISORY", "url": "https://securitylab.github.com/advisories/GHSL-2020-094-igrigorik-em-http-request" diff --git a/advisories/github-reviewed/2020/11/GHSA-23f7-99jx-m54r/GHSA-23f7-99jx-m54r.json b/advisories/github-reviewed/2020/11/GHSA-23f7-99jx-m54r/GHSA-23f7-99jx-m54r.json index 42ea04f58a6..1b60a782b8b 100644 --- a/advisories/github-reviewed/2020/11/GHSA-23f7-99jx-m54r/GHSA-23f7-99jx-m54r.json +++ b/advisories/github-reviewed/2020/11/GHSA-23f7-99jx-m54r/GHSA-23f7-99jx-m54r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-23f7-99jx-m54r", - "modified": "2021-01-07T22:48:40Z", + "modified": "2023-05-04T19:36:54Z", "published": "2020-11-13T15:47:50Z", "aliases": [ "CVE-2020-26222" @@ -71,6 +71,10 @@ "type": "WEB", "url": "https://github.com/dependabot/dependabot-core/commit/e089116abbe284425b976f7920e502b8e83a61b5" }, + { + "type": "WEB", + "url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/dependabot-omnibus/CVE-2020-26222.yml" + }, { "type": "WEB", "url": "https://rubygems.org/gems/dependabot-common" @@ -84,7 +88,7 @@ "cwe_ids": [ "CWE-74" ], - "severity": "LOW", + "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2020-11-13T15:47:18Z", "nvd_published_at": null