From 7908df085ddbc6ce94c3d8ee975ea2127c1b4ea8 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Sat, 15 Mar 2025 20:48:25 +0000 Subject: [PATCH] Publish Advisories GHSA-9jxq-5x44-gx23 GHSA-6m2c-76ff-6vrf GHSA-xc76-5pf9-mx8m --- .../GHSA-9jxq-5x44-gx23.json | 19 ++++++++++++--- .../GHSA-6m2c-76ff-6vrf.json | 24 ++++++++++++++++++- .../GHSA-xc76-5pf9-mx8m.json | 2 +- 3 files changed, 40 insertions(+), 5 deletions(-) diff --git a/advisories/github-reviewed/2025/02/GHSA-9jxq-5x44-gx23/GHSA-9jxq-5x44-gx23.json b/advisories/github-reviewed/2025/02/GHSA-9jxq-5x44-gx23/GHSA-9jxq-5x44-gx23.json index 31d486abb16..337549c3a76 100644 --- a/advisories/github-reviewed/2025/02/GHSA-9jxq-5x44-gx23/GHSA-9jxq-5x44-gx23.json +++ b/advisories/github-reviewed/2025/02/GHSA-9jxq-5x44-gx23/GHSA-9jxq-5x44-gx23.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9jxq-5x44-gx23", - "modified": "2025-02-14T18:03:14Z", + "modified": "2025-03-15T20:47:38Z", "published": "2025-02-14T18:03:14Z", "aliases": [ "CVE-2025-1057" @@ -43,10 +43,22 @@ "type": "WEB", "url": "https://github.com/keylime/keylime/security/advisories/GHSA-9jxq-5x44-gx23" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1057" + }, { "type": "WEB", "url": "https://github.com/keylime/keylime/commit/e08b10d86c3717006774e787542c190e2ba24fc7" }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2025-1057" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2343894" + }, { "type": "PACKAGE", "url": "https://github.com/keylime/keylime" @@ -54,11 +66,12 @@ ], "database_specific": { "cwe_ids": [ - "CWE-1287" + "CWE-1287", + "CWE-704" ], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2025-02-14T18:03:14Z", - "nvd_published_at": null + "nvd_published_at": "2025-03-15T09:15:10Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2025/03/GHSA-6m2c-76ff-6vrf/GHSA-6m2c-76ff-6vrf.json b/advisories/github-reviewed/2025/03/GHSA-6m2c-76ff-6vrf/GHSA-6m2c-76ff-6vrf.json index e4bbf3243f3..bbd9a4c0cc4 100644 --- a/advisories/github-reviewed/2025/03/GHSA-6m2c-76ff-6vrf/GHSA-6m2c-76ff-6vrf.json +++ b/advisories/github-reviewed/2025/03/GHSA-6m2c-76ff-6vrf/GHSA-6m2c-76ff-6vrf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6m2c-76ff-6vrf", - "modified": "2025-03-14T21:16:47Z", + "modified": "2025-03-15T20:47:02Z", "published": "2025-03-14T19:56:14Z", "aliases": [ "CVE-2025-2000" @@ -55,6 +55,28 @@ "database_specific": { "last_known_affected_version_range": "<= 1.4.1" } + }, + { + "package": { + "ecosystem": "PyPI", + "name": "qiskit" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.0.0rc1" + }, + { + "fixed": "2.0.0rc2" + } + ] + } + ], + "versions": [ + "2.0.0rc1" + ] } ], "references": [ diff --git a/advisories/github-reviewed/2025/03/GHSA-xc76-5pf9-mx8m/GHSA-xc76-5pf9-mx8m.json b/advisories/github-reviewed/2025/03/GHSA-xc76-5pf9-mx8m/GHSA-xc76-5pf9-mx8m.json index faa4eee83b6..c619a2a9372 100644 --- a/advisories/github-reviewed/2025/03/GHSA-xc76-5pf9-mx8m/GHSA-xc76-5pf9-mx8m.json +++ b/advisories/github-reviewed/2025/03/GHSA-xc76-5pf9-mx8m/GHSA-xc76-5pf9-mx8m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xc76-5pf9-mx8m", - "modified": "2025-03-14T17:31:07Z", + "modified": "2025-03-15T20:47:15Z", "published": "2025-03-14T17:31:07Z", "aliases": [ "CVE-2025-29776"