From 6fcb410b975fb76cf820ee90658f50c2fe50b27a Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 29 May 2025 21:37:09 +0000 Subject: [PATCH] Publish Advisories GHSA-9mc6-vgmq-x6xf GHSA-c65p-x677-fgj6 --- .../2022/09/GHSA-9mc6-vgmq-x6xf/GHSA-9mc6-vgmq-x6xf.json | 4 ++-- .../2025/05/GHSA-c65p-x677-fgj6/GHSA-c65p-x677-fgj6.json | 6 +++++- 2 files changed, 7 insertions(+), 3 deletions(-) diff --git a/advisories/github-reviewed/2022/09/GHSA-9mc6-vgmq-x6xf/GHSA-9mc6-vgmq-x6xf.json b/advisories/github-reviewed/2022/09/GHSA-9mc6-vgmq-x6xf/GHSA-9mc6-vgmq-x6xf.json index 9fee8d5eebb..92c1de6554b 100644 --- a/advisories/github-reviewed/2022/09/GHSA-9mc6-vgmq-x6xf/GHSA-9mc6-vgmq-x6xf.json +++ b/advisories/github-reviewed/2022/09/GHSA-9mc6-vgmq-x6xf/GHSA-9mc6-vgmq-x6xf.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-9mc6-vgmq-x6xf", - "modified": "2022-12-06T22:31:23Z", + "modified": "2025-05-29T21:35:54Z", "published": "2022-09-22T00:00:28Z", "aliases": [ "CVE-2022-41238" ], "summary": "Lack of authentication mechanism in Jenkins DotCi Plugin webhook", - "details": "DotCi Plugin provides a webhook endpoint at `/githook/` that can be used to trigger builds of the job for a GitHub repository.\n\nIn DotCi Plugin 2.40.00 and earlier, this endpoint can be accessed without authentication.\n\nThis allows unauthenticated attackers to trigger builds of jobs corresponding to the attacker-specified repository for attacker-specified commits.\n\nThis plugin has been suspended. ", + "details": "DotCi Plugin provides a webhook endpoint at `/githook/` that can be used to trigger builds of the job for a GitHub repository.\n\nIn DotCi Plugin 2.40.00 and earlier, this endpoint can be accessed without authentication.\n\nThis allows unauthenticated attackers to trigger builds of jobs corresponding to the attacker-specified repository for attacker-specified commits.\n\nThis plugin has been suspended.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2025/05/GHSA-c65p-x677-fgj6/GHSA-c65p-x677-fgj6.json b/advisories/github-reviewed/2025/05/GHSA-c65p-x677-fgj6/GHSA-c65p-x677-fgj6.json index 174c9eabc2b..0053e9e4ff6 100644 --- a/advisories/github-reviewed/2025/05/GHSA-c65p-x677-fgj6/GHSA-c65p-x677-fgj6.json +++ b/advisories/github-reviewed/2025/05/GHSA-c65p-x677-fgj6/GHSA-c65p-x677-fgj6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c65p-x677-fgj6", - "modified": "2025-05-29T21:27:46Z", + "modified": "2025-05-29T21:36:24Z", "published": "2025-05-28T18:03:41Z", "aliases": [ "CVE-2025-46722" @@ -52,6 +52,10 @@ "type": "WEB", "url": "https://github.com/vllm-project/vllm/commit/99404f53c72965b41558aceb1bc2380875f5d848" }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/vllm/PYSEC-2025-43.yaml" + }, { "type": "PACKAGE", "url": "https://github.com/vllm-project/vllm"