From 75413ad44dc339c4fefcc686ba50b9ac5bcabde6 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 13 Sep 2024 20:06:45 +0000 Subject: [PATCH] Publish Advisories GHSA-4r9h-x77w-mffv GHSA-cf7p-gm2m-833m --- .../GHSA-4r9h-x77w-mffv/GHSA-4r9h-x77w-mffv.json | 14 +++++++++++++- .../GHSA-cf7p-gm2m-833m/GHSA-cf7p-gm2m-833m.json | 15 ++++++++++++++- 2 files changed, 27 insertions(+), 2 deletions(-) diff --git a/advisories/github-reviewed/2022/12/GHSA-4r9h-x77w-mffv/GHSA-4r9h-x77w-mffv.json b/advisories/github-reviewed/2022/12/GHSA-4r9h-x77w-mffv/GHSA-4r9h-x77w-mffv.json index bde0870ffe8..7d6da343171 100644 --- a/advisories/github-reviewed/2022/12/GHSA-4r9h-x77w-mffv/GHSA-4r9h-x77w-mffv.json +++ b/advisories/github-reviewed/2022/12/GHSA-4r9h-x77w-mffv/GHSA-4r9h-x77w-mffv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4r9h-x77w-mffv", - "modified": "2022-12-21T17:23:08Z", + "modified": "2024-09-13T20:05:21Z", "published": "2022-12-15T21:30:26Z", "aliases": [ "CVE-2022-4527" @@ -12,6 +12,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N" } ], "affected": [ @@ -48,10 +52,18 @@ "type": "PACKAGE", "url": "https://github.com/collective/collective.task" }, + { + "type": "WEB", + "url": "https://github.com/collective/collective.task/releases/tag/3.0.10" + }, { "type": "WEB", "url": "https://github.com/collective/collective.task/releases/tag/3.0.9" }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/collective-task/PYSEC-2022-42990.yaml" + }, { "type": "WEB", "url": "https://vuldb.com/?id.215907" diff --git a/advisories/github-reviewed/2023/07/GHSA-cf7p-gm2m-833m/GHSA-cf7p-gm2m-833m.json b/advisories/github-reviewed/2023/07/GHSA-cf7p-gm2m-833m/GHSA-cf7p-gm2m-833m.json index a9eef70fc6f..88fe50ca91f 100644 --- a/advisories/github-reviewed/2023/07/GHSA-cf7p-gm2m-833m/GHSA-cf7p-gm2m-833m.json +++ b/advisories/github-reviewed/2023/07/GHSA-cf7p-gm2m-833m/GHSA-cf7p-gm2m-833m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cf7p-gm2m-833m", - "modified": "2023-08-15T20:39:56Z", + "modified": "2024-09-13T20:06:10Z", "published": "2023-07-14T21:31:08Z", "aliases": [ "CVE-2023-38325" @@ -12,6 +12,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N" } ], "affected": [ @@ -20,6 +24,11 @@ "ecosystem": "PyPI", "name": "cryptography" }, + "ecosystem_specific": { + "affected_functions": [ + "cryptography.hazmat.primitives.serialization.ssh.SSHCertificateBuilder.sign" + ] + }, "ranges": [ { "type": "ECOSYSTEM", @@ -68,6 +77,10 @@ "type": "WEB", "url": "https://github.com/pypa/advisory-database/tree/main/vulns/cryptography/PYSEC-2023-112.yaml" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NMCCTYY3CSNQBFFYYC5DAV6KATHWCUZK" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NMCCTYY3CSNQBFFYYC5DAV6KATHWCUZK"