diff --git a/advisories/github-reviewed/2022/09/GHSA-9mc6-vgmq-x6xf/GHSA-9mc6-vgmq-x6xf.json b/advisories/github-reviewed/2022/09/GHSA-9mc6-vgmq-x6xf/GHSA-9mc6-vgmq-x6xf.json index 9fee8d5eebb..92c1de6554b 100644 --- a/advisories/github-reviewed/2022/09/GHSA-9mc6-vgmq-x6xf/GHSA-9mc6-vgmq-x6xf.json +++ b/advisories/github-reviewed/2022/09/GHSA-9mc6-vgmq-x6xf/GHSA-9mc6-vgmq-x6xf.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-9mc6-vgmq-x6xf", - "modified": "2022-12-06T22:31:23Z", + "modified": "2025-05-29T21:35:54Z", "published": "2022-09-22T00:00:28Z", "aliases": [ "CVE-2022-41238" ], "summary": "Lack of authentication mechanism in Jenkins DotCi Plugin webhook", - "details": "DotCi Plugin provides a webhook endpoint at `/githook/` that can be used to trigger builds of the job for a GitHub repository.\n\nIn DotCi Plugin 2.40.00 and earlier, this endpoint can be accessed without authentication.\n\nThis allows unauthenticated attackers to trigger builds of jobs corresponding to the attacker-specified repository for attacker-specified commits.\n\nThis plugin has been suspended. ", + "details": "DotCi Plugin provides a webhook endpoint at `/githook/` that can be used to trigger builds of the job for a GitHub repository.\n\nIn DotCi Plugin 2.40.00 and earlier, this endpoint can be accessed without authentication.\n\nThis allows unauthenticated attackers to trigger builds of jobs corresponding to the attacker-specified repository for attacker-specified commits.\n\nThis plugin has been suspended.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2025/05/GHSA-c65p-x677-fgj6/GHSA-c65p-x677-fgj6.json b/advisories/github-reviewed/2025/05/GHSA-c65p-x677-fgj6/GHSA-c65p-x677-fgj6.json index 174c9eabc2b..0053e9e4ff6 100644 --- a/advisories/github-reviewed/2025/05/GHSA-c65p-x677-fgj6/GHSA-c65p-x677-fgj6.json +++ b/advisories/github-reviewed/2025/05/GHSA-c65p-x677-fgj6/GHSA-c65p-x677-fgj6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c65p-x677-fgj6", - "modified": "2025-05-29T21:27:46Z", + "modified": "2025-05-29T21:36:24Z", "published": "2025-05-28T18:03:41Z", "aliases": [ "CVE-2025-46722" @@ -52,6 +52,10 @@ "type": "WEB", "url": "https://github.com/vllm-project/vllm/commit/99404f53c72965b41558aceb1bc2380875f5d848" }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2025-43.yaml" + }, { "type": "PACKAGE", "url": "https://github.com/vllm-project/vllm"