From 6a8bfd1ba388cc6bd8d70203205331ccca814d5c Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 12 Nov 2024 19:24:08 +0000 Subject: [PATCH] Publish Advisories GHSA-m757-p8rv-4q93 GHSA-gppm-hq3p-h4rp GHSA-gr3c-q7xf-47vh --- .../GHSA-m757-p8rv-4q93.json | 7 +++-- .../GHSA-gppm-hq3p-h4rp.json | 12 ++++++-- .../GHSA-gr3c-q7xf-47vh.json | 28 +++++++++++++++++-- 3 files changed, 41 insertions(+), 6 deletions(-) diff --git a/advisories/github-reviewed/2024/03/GHSA-m757-p8rv-4q93/GHSA-m757-p8rv-4q93.json b/advisories/github-reviewed/2024/03/GHSA-m757-p8rv-4q93/GHSA-m757-p8rv-4q93.json index 32e6f298b31..f871bd462d0 100644 --- a/advisories/github-reviewed/2024/03/GHSA-m757-p8rv-4q93/GHSA-m757-p8rv-4q93.json +++ b/advisories/github-reviewed/2024/03/GHSA-m757-p8rv-4q93/GHSA-m757-p8rv-4q93.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m757-p8rv-4q93", - "modified": "2024-05-02T18:40:48Z", + "modified": "2024-11-12T19:22:59Z", "published": "2024-03-06T15:31:04Z", "aliases": [ "CVE-2023-50740" @@ -9,7 +9,10 @@ "summary": "Apache Linkis DataSource: DataSource module Oracle SQL Database Password Logged", "details": "In Apache Linkis <=1.4.0, The password is printed to the log when using the Oracle data source of the Linkis data source module. \nWe recommend users upgrade the version of Linkis to version 1.5.0\n", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } ], "affected": [ { diff --git a/advisories/github-reviewed/2024/11/GHSA-gppm-hq3p-h4rp/GHSA-gppm-hq3p-h4rp.json b/advisories/github-reviewed/2024/11/GHSA-gppm-hq3p-h4rp/GHSA-gppm-hq3p-h4rp.json index 5c7c52f8b36..a80cbcc3f6f 100644 --- a/advisories/github-reviewed/2024/11/GHSA-gppm-hq3p-h4rp/GHSA-gppm-hq3p-h4rp.json +++ b/advisories/github-reviewed/2024/11/GHSA-gppm-hq3p-h4rp/GHSA-gppm-hq3p-h4rp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gppm-hq3p-h4rp", - "modified": "2024-11-08T20:35:58Z", + "modified": "2024-11-12T19:23:19Z", "published": "2024-11-08T19:03:35Z", "aliases": [ "CVE-2024-52009" @@ -40,6 +40,10 @@ "type": "WEB", "url": "https://github.com/runatlantis/atlantis/security/advisories/GHSA-gppm-hq3p-h4rp" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52009" + }, { "type": "WEB", "url": "https://github.com/runatlantis/atlantis/issues/4060" @@ -48,6 +52,10 @@ "type": "WEB", "url": "https://github.com/runatlantis/atlantis/pull/4667" }, + { + "type": "WEB", + "url": "https://argo-cd.readthedocs.io/en/stable/operator-manual/security" + }, { "type": "PACKAGE", "url": "https://github.com/runatlantis/atlantis" @@ -64,6 +72,6 @@ "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2024-11-08T19:03:35Z", - "nvd_published_at": null + "nvd_published_at": "2024-11-08T23:15:05Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2024/11/GHSA-gr3c-q7xf-47vh/GHSA-gr3c-q7xf-47vh.json b/advisories/github-reviewed/2024/11/GHSA-gr3c-q7xf-47vh/GHSA-gr3c-q7xf-47vh.json index 4d3309b9de3..0ca6fb98954 100644 --- a/advisories/github-reviewed/2024/11/GHSA-gr3c-q7xf-47vh/GHSA-gr3c-q7xf-47vh.json +++ b/advisories/github-reviewed/2024/11/GHSA-gr3c-q7xf-47vh/GHSA-gr3c-q7xf-47vh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gr3c-q7xf-47vh", - "modified": "2024-11-08T18:49:15Z", + "modified": "2024-11-12T19:23:17Z", "published": "2024-11-08T18:49:15Z", "aliases": [ "CVE-2024-52007" @@ -135,10 +135,34 @@ } ], "references": [ + { + "type": "WEB", + "url": "https://github.com/hapifhir/org.hl7.fhir.core/security/advisories/GHSA-6cr6-ph3p-f5rf" + }, { "type": "WEB", "url": "https://github.com/hapifhir/org.hl7.fhir.core/security/advisories/GHSA-gr3c-q7xf-47vh" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52007" + }, + { + "type": "WEB", + "url": "https://github.com/hapifhir/org.hl7.fhir.core/issues/1571" + }, + { + "type": "WEB", + "url": "https://github.com/hapifhir/org.hl7.fhir.core/pull/1717" + }, + { + "type": "WEB", + "url": "https://cheatsheetseries.owasp.org/cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html#jaxp-documentbuilderfactory-saxparserfactory-and-dom4j" + }, + { + "type": "WEB", + "url": "https://cwe.mitre.org/data/definitions/611.html" + }, { "type": "PACKAGE", "url": "https://github.com/hapifhir/org.hl7.fhir.core" @@ -151,6 +175,6 @@ "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2024-11-08T18:49:15Z", - "nvd_published_at": null + "nvd_published_at": "2024-11-08T23:15:04Z" } } \ No newline at end of file