From 7d1b791b09279dcc312a4304d30617fdd8257572 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 22 Dec 2023 22:25:06 +0000 Subject: [PATCH] Publish Advisories GHSA-rw54-6826-c8j5 GHSA-w8vh-p74j-x9xp --- .../GHSA-rw54-6826-c8j5.json | 23 ++++++++++++++++--- .../GHSA-w8vh-p74j-x9xp.json | 10 +++++--- 2 files changed, 27 insertions(+), 6 deletions(-) diff --git a/advisories/github-reviewed/2023/12/GHSA-rw54-6826-c8j5/GHSA-rw54-6826-c8j5.json b/advisories/github-reviewed/2023/12/GHSA-rw54-6826-c8j5/GHSA-rw54-6826-c8j5.json index 5482c8c3293..87fd1e28a60 100644 --- a/advisories/github-reviewed/2023/12/GHSA-rw54-6826-c8j5/GHSA-rw54-6826-c8j5.json +++ b/advisories/github-reviewed/2023/12/GHSA-rw54-6826-c8j5/GHSA-rw54-6826-c8j5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rw54-6826-c8j5", - "modified": "2023-12-18T19:34:20Z", + "modified": "2023-12-22T22:24:09Z", "published": "2023-12-18T19:34:20Z", "aliases": [ "CVE-2023-50714" @@ -40,6 +40,10 @@ "type": "WEB", "url": "https://github.com/yiisoft/yii2-authclient/security/advisories/GHSA-rw54-6826-c8j5" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50714" + }, { "type": "WEB", "url": "https://github.com/yiisoft/yii2-authclient/commit/721ed974bc44137437b0cdc8454e137fff8db213" @@ -47,15 +51,28 @@ { "type": "PACKAGE", "url": "https://github.com/yiisoft/yii2-authclient" + }, + { + "type": "WEB", + "url": "https://github.com/yiisoft/yii2-authclient/blob/0d1c3880f4d79e20aa1d77c012650b54e69695ff/src/OAuth1.php#L158" + }, + { + "type": "WEB", + "url": "https://github.com/yiisoft/yii2-authclient/blob/0d1c3880f4d79e20aa1d77c012650b54e69695ff/src/OAuth2.php#L121" + }, + { + "type": "WEB", + "url": "https://github.com/yiisoft/yii2-authclient/blob/0d1c3880f4d79e20aa1d77c012650b54e69695ff/src/OpenIdConnect.php#L420" } ], "database_specific": { "cwe_ids": [ - "CWE-287" + "CWE-287", + "CWE-347" ], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2023-12-18T19:34:20Z", - "nvd_published_at": null + "nvd_published_at": "2023-12-22T19:15:09Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2023/12/GHSA-w8vh-p74j-x9xp/GHSA-w8vh-p74j-x9xp.json b/advisories/github-reviewed/2023/12/GHSA-w8vh-p74j-x9xp/GHSA-w8vh-p74j-x9xp.json index cbb6d09af10..9ef6c7cbaff 100644 --- a/advisories/github-reviewed/2023/12/GHSA-w8vh-p74j-x9xp/GHSA-w8vh-p74j-x9xp.json +++ b/advisories/github-reviewed/2023/12/GHSA-w8vh-p74j-x9xp/GHSA-w8vh-p74j-x9xp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w8vh-p74j-x9xp", - "modified": "2023-12-18T20:01:00Z", + "modified": "2023-12-22T22:23:51Z", "published": "2023-12-18T20:01:00Z", "aliases": [ "CVE-2023-50708" @@ -43,6 +43,10 @@ "type": "WEB", "url": "https://github.com/yiisoft/yii2-authclient/security/advisories/GHSA-w8vh-p74j-x9xp" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-50708" + }, { "type": "WEB", "url": "https://github.com/yiisoft/yii2-authclient/commit/dabddf2154ab7e7703740205a069202554089248" @@ -66,11 +70,11 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-203" ], "severity": "LOW", "github_reviewed": true, "github_reviewed_at": "2023-12-18T20:01:00Z", - "nvd_published_at": null + "nvd_published_at": "2023-12-22T19:15:08Z" } } \ No newline at end of file