From 6c54c7ce69cf1545606edfd950d37012ee4e5484 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 14 Mar 2025 20:27:19 +0000 Subject: [PATCH] Publish Advisories GHSA-mr4x-c4v9-x729 GHSA-c9h6-v78w-52wj GHSA-q99m-qcv4-fpm7 --- .../2018/12/GHSA-mr4x-c4v9-x729/GHSA-mr4x-c4v9-x729.json | 4 ++-- .../2024/04/GHSA-c9h6-v78w-52wj/GHSA-c9h6-v78w-52wj.json | 4 ++-- .../2024/10/GHSA-q99m-qcv4-fpm7/GHSA-q99m-qcv4-fpm7.json | 6 +++++- 3 files changed, 9 insertions(+), 5 deletions(-) diff --git a/advisories/github-reviewed/2018/12/GHSA-mr4x-c4v9-x729/GHSA-mr4x-c4v9-x729.json b/advisories/github-reviewed/2018/12/GHSA-mr4x-c4v9-x729/GHSA-mr4x-c4v9-x729.json index 141d7a2c2f5..94def1f2707 100644 --- a/advisories/github-reviewed/2018/12/GHSA-mr4x-c4v9-x729/GHSA-mr4x-c4v9-x729.json +++ b/advisories/github-reviewed/2018/12/GHSA-mr4x-c4v9-x729/GHSA-mr4x-c4v9-x729.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mr4x-c4v9-x729", - "modified": "2024-11-18T16:26:08Z", + "modified": "2025-03-14T20:26:12Z", "published": "2018-12-20T22:01:46Z", "aliases": [ "CVE-2018-1000814" @@ -79,6 +79,6 @@ "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2020-06-16T21:47:02Z", - "nvd_published_at": null + "nvd_published_at": "2018-12-20T15:29:00Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2024/04/GHSA-c9h6-v78w-52wj/GHSA-c9h6-v78w-52wj.json b/advisories/github-reviewed/2024/04/GHSA-c9h6-v78w-52wj/GHSA-c9h6-v78w-52wj.json index e749264fc7f..ca767193d92 100644 --- a/advisories/github-reviewed/2024/04/GHSA-c9h6-v78w-52wj/GHSA-c9h6-v78w-52wj.json +++ b/advisories/github-reviewed/2024/04/GHSA-c9h6-v78w-52wj/GHSA-c9h6-v78w-52wj.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-c9h6-v78w-52wj", - "modified": "2024-04-25T22:22:57Z", + "modified": "2025-03-14T20:25:54Z", "published": "2024-04-17T18:25:29Z", "aliases": [ "CVE-2023-6787" ], "summary": "Keycloak vulnerable to session hijacking via re-authentication", - "details": "A flaw was found in Keycloak. An active keycloak session can be hijacked by initiating a new authentication (having the query parameter prompt=login) and forcing the user to enter his credentials once again. If the user cancels this re-authentication by clicking Restart login, the account takeover could take place as the new session, with a different SUB, will have the same SID as the previous session.\n\n", + "details": "A flaw was found in Keycloak. An active keycloak session can be hijacked by initiating a new authentication (having the query parameter prompt=login) and forcing the user to enter his credentials once again. If the user cancels this re-authentication by clicking Restart login, the account takeover could take place as the new session, with a different SUB, will have the same SID as the previous session.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2024/10/GHSA-q99m-qcv4-fpm7/GHSA-q99m-qcv4-fpm7.json b/advisories/github-reviewed/2024/10/GHSA-q99m-qcv4-fpm7/GHSA-q99m-qcv4-fpm7.json index 980580ab12f..403230dadb3 100644 --- a/advisories/github-reviewed/2024/10/GHSA-q99m-qcv4-fpm7/GHSA-q99m-qcv4-fpm7.json +++ b/advisories/github-reviewed/2024/10/GHSA-q99m-qcv4-fpm7/GHSA-q99m-qcv4-fpm7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q99m-qcv4-fpm7", - "modified": "2024-11-01T19:52:51Z", + "modified": "2025-03-14T20:26:23Z", "published": "2024-10-18T06:30:32Z", "aliases": [ "CVE-2024-9264" @@ -106,6 +106,10 @@ { "type": "WEB", "url": "https://grafana.com/security/security-advisories/cve-2024-9264" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250314-0007" } ], "database_specific": {