From 65290d120a4bed8f34c072c845307518171d9566 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 7 Mar 2025 21:35:32 +0000 Subject: [PATCH] Publish Advisories GHSA-273w-7fxj-pcp6 GHSA-786g-xv8v-9h93 GHSA-79jp-m64f-pgrc GHSA-qppj-fm5r-hxr3 --- .../GHSA-273w-7fxj-pcp6.json | 2 +- .../GHSA-786g-xv8v-9h93.json | 2 +- .../GHSA-79jp-m64f-pgrc.json | 2 +- .../GHSA-qppj-fm5r-hxr3.json | 118 ++++++++++-------- 4 files changed, 72 insertions(+), 52 deletions(-) diff --git a/advisories/github-reviewed/2023/03/GHSA-273w-7fxj-pcp6/GHSA-273w-7fxj-pcp6.json b/advisories/github-reviewed/2023/03/GHSA-273w-7fxj-pcp6/GHSA-273w-7fxj-pcp6.json index 834cd9106d2..2bde2051188 100644 --- a/advisories/github-reviewed/2023/03/GHSA-273w-7fxj-pcp6/GHSA-273w-7fxj-pcp6.json +++ b/advisories/github-reviewed/2023/03/GHSA-273w-7fxj-pcp6/GHSA-273w-7fxj-pcp6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-273w-7fxj-pcp6", - "modified": "2023-03-13T15:35:50Z", + "modified": "2025-03-07T21:32:22Z", "published": "2023-03-06T21:30:18Z", "aliases": [ "CVE-2021-36395" diff --git a/advisories/github-reviewed/2023/03/GHSA-786g-xv8v-9h93/GHSA-786g-xv8v-9h93.json b/advisories/github-reviewed/2023/03/GHSA-786g-xv8v-9h93/GHSA-786g-xv8v-9h93.json index b14c498edbd..1386cc92197 100644 --- a/advisories/github-reviewed/2023/03/GHSA-786g-xv8v-9h93/GHSA-786g-xv8v-9h93.json +++ b/advisories/github-reviewed/2023/03/GHSA-786g-xv8v-9h93/GHSA-786g-xv8v-9h93.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-786g-xv8v-9h93", - "modified": "2023-03-13T19:16:01Z", + "modified": "2025-03-07T21:32:45Z", "published": "2023-03-07T00:30:26Z", "aliases": [ "CVE-2021-36398" diff --git a/advisories/github-reviewed/2023/03/GHSA-79jp-m64f-pgrc/GHSA-79jp-m64f-pgrc.json b/advisories/github-reviewed/2023/03/GHSA-79jp-m64f-pgrc/GHSA-79jp-m64f-pgrc.json index 233e1b8d7f3..011d68d7fdc 100644 --- a/advisories/github-reviewed/2023/03/GHSA-79jp-m64f-pgrc/GHSA-79jp-m64f-pgrc.json +++ b/advisories/github-reviewed/2023/03/GHSA-79jp-m64f-pgrc/GHSA-79jp-m64f-pgrc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-79jp-m64f-pgrc", - "modified": "2023-03-13T19:15:59Z", + "modified": "2025-03-07T21:32:36Z", "published": "2023-03-07T00:30:26Z", "aliases": [ "CVE-2021-36399" diff --git a/advisories/github-reviewed/2023/10/GHSA-qppj-fm5r-hxr3/GHSA-qppj-fm5r-hxr3.json b/advisories/github-reviewed/2023/10/GHSA-qppj-fm5r-hxr3/GHSA-qppj-fm5r-hxr3.json index 698f629269d..1a94b6fb0e6 100644 --- a/advisories/github-reviewed/2023/10/GHSA-qppj-fm5r-hxr3/GHSA-qppj-fm5r-hxr3.json +++ b/advisories/github-reviewed/2023/10/GHSA-qppj-fm5r-hxr3/GHSA-qppj-fm5r-hxr3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qppj-fm5r-hxr3", - "modified": "2024-12-20T18:36:24Z", + "modified": "2025-03-07T21:33:50Z", "published": "2023-10-10T21:28:24Z", "aliases": [ "CVE-2023-44487" @@ -528,26 +528,26 @@ "type": "WEB", "url": "https://github.com/dotnet/announcements/issues/277" }, - { - "type": "WEB", - "url": "https://github.com/varnishcache/varnish-cache/issues/3996" - }, { "type": "WEB", "url": "https://github.com/eclipse/jetty.project/issues/10679" }, - { - "type": "WEB", - "url": "https://github.com/Azure/AKS/issues/3947" - }, { "type": "WEB", "url": "https://github.com/etcd-io/etcd/issues/16740" }, + { + "type": "WEB", + "url": "https://github.com/Azure/AKS/issues/3947" + }, { "type": "WEB", "url": "https://github.com/golang/go/issues/63417" }, + { + "type": "WEB", + "url": "https://github.com/varnishcache/varnish-cache/issues/3996" + }, { "type": "WEB", "url": "https://github.com/tempesta-tech/tempesta/issues/1986" @@ -566,11 +566,11 @@ }, { "type": "WEB", - "url": "https://github.com/ninenines/cowboy/issues/1615" + "url": "https://github.com/junkurihara/rust-rpxy/issues/97" }, { "type": "WEB", - "url": "https://github.com/junkurihara/rust-rpxy/issues/97" + "url": "https://github.com/ninenines/cowboy/issues/1615" }, { "type": "WEB", @@ -606,11 +606,11 @@ }, { "type": "WEB", - "url": "https://github.com/kubernetes/kubernetes/pull/121120" + "url": "https://github.com/envoyproxy/envoy/pull/30055" }, { "type": "WEB", - "url": "https://github.com/envoyproxy/envoy/pull/30055" + "url": "https://github.com/kubernetes/kubernetes/pull/121120" }, { "type": "WEB", @@ -618,11 +618,11 @@ }, { "type": "WEB", - "url": "https://github.com/projectcontour/contour/pull/5826" + "url": "https://github.com/grpc/grpc-go/pull/6703" }, { "type": "WEB", - "url": "https://github.com/grpc/grpc-go/pull/6703" + "url": "https://github.com/projectcontour/contour/pull/5826" }, { "type": "WEB", @@ -652,10 +652,6 @@ "type": "WEB", "url": "https://github.com/netty/netty/commit/58f75f665aa81a8cbcf6ffa74820042a285c5e61" }, - { - "type": "WEB", - "url": "https://mailman.nginx.org/pipermail/nginx-devel/2023-October/S36Q5HBXR7CAIMPLLPRSSSYR4PCMWILK.html" - }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JIZSEFC3YKCGABA2BZW6ZJRMDZJMB7PJ" @@ -686,7 +682,11 @@ }, { "type": "WEB", - "url": "https://my.f5.com/manage/s/article/K000137106" + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2MBEPPC36UBVOZZNAXFHKLFGSLCMN5LI" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-44487" }, { "type": "WEB", @@ -710,23 +710,7 @@ }, { "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WLPRQ5TWUQQXYWBJM7ECYDAIL2YVKIUH" - }, - { - "type": "WEB", - "url": "https://lists.w3.org/Archives/Public/ietf-http-wg/2023OctDec/0025.html" - }, - { - "type": "WEB", - "url": "https://martinthomson.github.io/h2-stream-limits/draft-thomson-httpbis-h2-stream-limits.html" - }, - { - "type": "WEB", - "url": "https://msrc.microsoft.com/blog/2023/10/microsoft-response-to-distributed-denial-of-service-ddos-attacks-against-http/2" - }, - { - "type": "WEB", - "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-44487" + "url": "https://access.redhat.com/security/cve/cve-2023-44487" }, { "type": "WEB", @@ -736,10 +720,26 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZKQSIKIAT5TJ3WSLU3RDBQ35YX4GY4V3" }, + { + "type": "WEB", + "url": "https://lists.w3.org/Archives/Public/ietf-http-wg/2023OctDec/0025.html" + }, + { + "type": "WEB", + "url": "https://mailman.nginx.org/pipermail/nginx-devel/2023-October/S36Q5HBXR7CAIMPLLPRSSSYR4PCMWILK.html" + }, + { + "type": "WEB", + "url": "https://martinthomson.github.io/h2-stream-limits/draft-thomson-httpbis-h2-stream-limits.html" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZB43REMKRQR62NJEI7I5NQ4FSXNLBKRT" }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/blog/2023/10/microsoft-response-to-distributed-denial-of-service-ddos-attacks-against-http/2" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XFOIBB4YFICHDM7IBOP7PWXW3FX4HLL2" @@ -752,6 +752,10 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WLPRQ5TWUQQXYWBJM7ECYDAIL2YVKIUH" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WE2I52RHNNU42PX6NZ2RBUHSFFJ2LVZX" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VSRDIV77HNKUSM7SJC5BKE5JSHLHU2NK" @@ -778,7 +782,7 @@ }, { "type": "WEB", - "url": "https://netty.io/news/2023/10/10/4-1-100-Final.html" + "url": "https://ubuntu.com/security/CVE-2023-44487" }, { "type": "WEB", @@ -848,6 +852,14 @@ "type": "WEB", "url": "https://www.vicarius.io/vsociety/posts/rapid-reset-cve-2023-44487-dos-in-http2-understanding-the-root-cause" }, + { + "type": "WEB", + "url": "https://my.f5.com/manage/s/article/K000137106" + }, + { + "type": "WEB", + "url": "https://netty.io/news/2023/10/10/4-1-100-Final.html" + }, { "type": "WEB", "url": "https://news.ycombinator.com/item?id=37830987" @@ -912,14 +924,6 @@ "type": "WEB", "url": "https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.81" }, - { - "type": "WEB", - "url": "https://ubuntu.com/security/CVE-2023-44487" - }, - { - "type": "WEB", - "url": "https://discuss.hashicorp.com/t/hcsec-2023-32-vault-consul-and-boundary-affected-by-http-2-rapid-reset-denial-of-service-vulnerability-cve-2023-44487/59715" - }, { "type": "WEB", "url": "https://edg.io/lp/blog/resets-leaks-ddos-and-the-tale-of-a-hidden-cve" @@ -982,11 +986,11 @@ }, { "type": "WEB", - "url": "https://lists.debian.org/debian-lts-announce/2023/11/msg00001.html" + "url": "https://github.com/grpc/grpc/releases/tag/v1.59.2" }, { "type": "WEB", - "url": "https://access.redhat.com/security/cve/cve-2023-44487" + "url": "https://github.com/icing/mod_h2/blob/0a864782af0a942aa2ad4ed960a6b32cd35bcf0a/mod_http2/README.md?plain=1#L239-L244" }, { "type": "WEB", @@ -1052,6 +1056,10 @@ "type": "WEB", "url": "https://community.traefik.io/t/is-traefik-vulnerable-to-cve-2023-44487/20125" }, + { + "type": "WEB", + "url": "https://discuss.hashicorp.com/t/hcsec-2023-32-vault-consul-and-boundary-affected-by-http-2-rapid-reset-denial-of-service-vulnerability-cve-2023-44487/59715" + }, { "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2023/11/msg00012.html" @@ -1118,7 +1126,7 @@ }, { "type": "WEB", - "url": "https://github.com/icing/mod_h2/blob/0a864782af0a942aa2ad4ed960a6b32cd35bcf0a/mod_http2/README.md?plain=1#L239-L244" + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WLPRQ5TWUQQXYWBJM7ECYDAIL2YVKIUH" }, { "type": "WEB", @@ -1184,6 +1192,18 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2023/10/msg00047.html" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2023/11/msg00001.html" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2023/10/10/6" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2023/10/10/7" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2023/10/13/4"