From 7e3f43a0af0e34f3b8d8c8f86b674c20166753b3 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 24 Jan 2024 19:19:40 +0000 Subject: [PATCH] Publish Advisories GHSA-qg54-694p-wgpp GHSA-5cqm-crxm-6qpv GHSA-4vf4-qmvg-mh7h GHSA-3m99-h3hp-w9j7 GHSA-vc47-6rqg-c7f5 GHSA-fg7x-g82r-94qc GHSA-hv5j-3h9f-99c2 GHSA-2492-xxqf-6h78 --- .../GHSA-qg54-694p-wgpp.json | 14 +++++++- .../GHSA-5cqm-crxm-6qpv.json | 12 +++++++ .../GHSA-4vf4-qmvg-mh7h.json | 12 +++++++ .../GHSA-3m99-h3hp-w9j7.json | 36 +++++++++++++++++++ .../GHSA-vc47-6rqg-c7f5.json | 19 +++++++++- .../GHSA-fg7x-g82r-94qc.json | 20 +++++++++++ .../GHSA-hv5j-3h9f-99c2.json | 16 +++++++++ .../GHSA-2492-xxqf-6h78.json | 4 +++ 8 files changed, 131 insertions(+), 2 deletions(-) diff --git a/advisories/github-reviewed/2021/11/GHSA-qg54-694p-wgpp/GHSA-qg54-694p-wgpp.json b/advisories/github-reviewed/2021/11/GHSA-qg54-694p-wgpp/GHSA-qg54-694p-wgpp.json index cc8c47bd2d4..176d4f9fbfc 100644 --- a/advisories/github-reviewed/2021/11/GHSA-qg54-694p-wgpp/GHSA-qg54-694p-wgpp.json +++ b/advisories/github-reviewed/2021/11/GHSA-qg54-694p-wgpp/GHSA-qg54-694p-wgpp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qg54-694p-wgpp", - "modified": "2023-05-16T16:07:35Z", + "modified": "2024-01-24T19:18:37Z", "published": "2021-11-16T00:32:30Z", "aliases": [ "CVE-2021-41817" @@ -113,6 +113,14 @@ "type": "WEB", "url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/date/CVE-2021-41817.yml" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IUXQCH6FRKANCVZO2Q7D2SQX33FP3KWN/" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UTOJGS5IEFDK3UOO7IY4OTTFGHGLSWZF/" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IUXQCH6FRKANCVZO2Q7D2SQX33FP3KWN/" @@ -121,6 +129,10 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UTOJGS5IEFDK3UOO7IY4OTTFGHGLSWZF/" }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202401-27" + }, { "type": "WEB", "url": "https://www.ruby-lang.org/en/news/2021/11/15/date-parsing-method-regexp-dos-cve-2021-41817/" diff --git a/advisories/github-reviewed/2021/12/GHSA-5cqm-crxm-6qpv/GHSA-5cqm-crxm-6qpv.json b/advisories/github-reviewed/2021/12/GHSA-5cqm-crxm-6qpv/GHSA-5cqm-crxm-6qpv.json index baecbf2e3e1..f0f4fd3b43f 100644 --- a/advisories/github-reviewed/2021/12/GHSA-5cqm-crxm-6qpv/GHSA-5cqm-crxm-6qpv.json +++ b/advisories/github-reviewed/2021/12/GHSA-5cqm-crxm-6qpv/GHSA-5cqm-crxm-6qpv.json @@ -110,6 +110,14 @@ "type": "WEB", "url": "https://groups.google.com/g/ruby-security-ann/c/4MQ568ZG47c" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IUXQCH6FRKANCVZO2Q7D2SQX33FP3KWN/" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UTOJGS5IEFDK3UOO7IY4OTTFGHGLSWZF/" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IUXQCH6FRKANCVZO2Q7D2SQX33FP3KWN/" @@ -122,6 +130,10 @@ "type": "WEB", "url": "https://security-tracker.debian.org/tracker/CVE-2021-41816" }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202401-27" + }, { "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20220303-0006/" diff --git a/advisories/github-reviewed/2022/01/GHSA-4vf4-qmvg-mh7h/GHSA-4vf4-qmvg-mh7h.json b/advisories/github-reviewed/2022/01/GHSA-4vf4-qmvg-mh7h/GHSA-4vf4-qmvg-mh7h.json index 74afc43aabe..a2feb1083fd 100644 --- a/advisories/github-reviewed/2022/01/GHSA-4vf4-qmvg-mh7h/GHSA-4vf4-qmvg-mh7h.json +++ b/advisories/github-reviewed/2022/01/GHSA-4vf4-qmvg-mh7h/GHSA-4vf4-qmvg-mh7h.json @@ -96,6 +96,14 @@ "type": "WEB", "url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/cgi/CVE-2021-41819.yml" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IUXQCH6FRKANCVZO2Q7D2SQX33FP3KWN/" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UTOJGS5IEFDK3UOO7IY4OTTFGHGLSWZF/" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IUXQCH6FRKANCVZO2Q7D2SQX33FP3KWN/" @@ -104,6 +112,10 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UTOJGS5IEFDK3UOO7IY4OTTFGHGLSWZF/" }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202401-27" + }, { "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20220121-0003/" diff --git a/advisories/github-reviewed/2022/05/GHSA-3m99-h3hp-w9j7/GHSA-3m99-h3hp-w9j7.json b/advisories/github-reviewed/2022/05/GHSA-3m99-h3hp-w9j7/GHSA-3m99-h3hp-w9j7.json index cb2b01aaf75..70a9ac86dbf 100644 --- a/advisories/github-reviewed/2022/05/GHSA-3m99-h3hp-w9j7/GHSA-3m99-h3hp-w9j7.json +++ b/advisories/github-reviewed/2022/05/GHSA-3m99-h3hp-w9j7/GHSA-3m99-h3hp-w9j7.json @@ -106,6 +106,42 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2014-3545" }, + { + "type": "WEB", + "url": "https://github.com/moodle/moodle/commit/155bc7547227dc2047cfc8630cbfe121888b359b" + }, + { + "type": "WEB", + "url": "https://github.com/moodle/moodle/commit/29005a5418894b76e62e44bbc2c9e4ddee8f5ce6" + }, + { + "type": "WEB", + "url": "https://github.com/moodle/moodle/commit/44f726a7b1d351b39bb2a6a30c1b30027fabd000" + }, + { + "type": "WEB", + "url": "https://github.com/moodle/moodle/commit/539a25ff03fae377758d62caefcc71a2418e9a84" + }, + { + "type": "WEB", + "url": "https://github.com/moodle/moodle/commit/5c6c172033e3fb4afce862f8b32b459f5c35ad19" + }, + { + "type": "WEB", + "url": "https://github.com/moodle/moodle/commit/66de66fe6a8ce8f491562edad0a14f26d4808cb4" + }, + { + "type": "WEB", + "url": "https://github.com/moodle/moodle/commit/770d3ce42669067eca2bcee22d142ed7fec08550" + }, + { + "type": "WEB", + "url": "https://github.com/moodle/moodle/commit/82b3260eab2db58dfa9510645fd2c60ee0ce142e" + }, + { + "type": "WEB", + "url": "https://github.com/moodle/moodle/commit/88ec9f308da6a4bc7a735458cdf72648357d501d" + }, { "type": "PACKAGE", "url": "https://github.com/moodle/moodle" diff --git a/advisories/github-reviewed/2022/11/GHSA-vc47-6rqg-c7f5/GHSA-vc47-6rqg-c7f5.json b/advisories/github-reviewed/2022/11/GHSA-vc47-6rqg-c7f5/GHSA-vc47-6rqg-c7f5.json index b5a59db4acc..c39a6081601 100644 --- a/advisories/github-reviewed/2022/11/GHSA-vc47-6rqg-c7f5/GHSA-vc47-6rqg-c7f5.json +++ b/advisories/github-reviewed/2022/11/GHSA-vc47-6rqg-c7f5/GHSA-vc47-6rqg-c7f5.json @@ -90,6 +90,18 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2023/06/msg00012.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DQR7LWED6VAPD5ATYOBZIGJQPCUBRJBX/" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/THVTYHHEOVLQFCFHWURZYO7PVUPBHRZD/" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YACE6ORF2QBXXBK2V2CM36D7TZMEJVAS/" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DQR7LWED6VAPD5ATYOBZIGJQPCUBRJBX/" @@ -102,6 +114,10 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YACE6ORF2QBXXBK2V2CM36D7TZMEJVAS/" }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202401-27" + }, { "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20221228-0004/" @@ -113,7 +129,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-436" + "CWE-436", + "CWE-74" ], "severity": "HIGH", "github_reviewed": true, diff --git a/advisories/github-reviewed/2023/03/GHSA-fg7x-g82r-94qc/GHSA-fg7x-g82r-94qc.json b/advisories/github-reviewed/2023/03/GHSA-fg7x-g82r-94qc/GHSA-fg7x-g82r-94qc.json index 6dca9c8fef0..80fad300159 100644 --- a/advisories/github-reviewed/2023/03/GHSA-fg7x-g82r-94qc/GHSA-fg7x-g82r-94qc.json +++ b/advisories/github-reviewed/2023/03/GHSA-fg7x-g82r-94qc/GHSA-fg7x-g82r-94qc.json @@ -63,6 +63,10 @@ "type": "PACKAGE", "url": "https://github.com/ruby/time" }, + { + "type": "WEB", + "url": "https://github.com/ruby/time/releases/" + }, { "type": "WEB", "url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/time/CVE-2023-28756.yml" @@ -71,6 +75,18 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2023/04/msg00033.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FFZANOQA4RYX7XCB42OO3P24DQKWHEKA/" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/G76GZG3RAGYF4P75YY7J7TGYAU7Z5E2T/" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WMIOPLBAAM3FEQNAXA2L7BDKOGSVUT5Z/" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FFZANOQA4RYX7XCB42OO3P24DQKWHEKA/" @@ -83,6 +99,10 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WMIOPLBAAM3FEQNAXA2L7BDKOGSVUT5Z/" }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202401-27" + }, { "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20230526-0004/" diff --git a/advisories/github-reviewed/2023/03/GHSA-hv5j-3h9f-99c2/GHSA-hv5j-3h9f-99c2.json b/advisories/github-reviewed/2023/03/GHSA-hv5j-3h9f-99c2/GHSA-hv5j-3h9f-99c2.json index 7af8305b218..af25fca4479 100644 --- a/advisories/github-reviewed/2023/03/GHSA-hv5j-3h9f-99c2/GHSA-hv5j-3h9f-99c2.json +++ b/advisories/github-reviewed/2023/03/GHSA-hv5j-3h9f-99c2/GHSA-hv5j-3h9f-99c2.json @@ -122,6 +122,18 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2023/04/msg00033.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FFZANOQA4RYX7XCB42OO3P24DQKWHEKA/" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/G76GZG3RAGYF4P75YY7J7TGYAU7Z5E2T/" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WMIOPLBAAM3FEQNAXA2L7BDKOGSVUT5Z/" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FFZANOQA4RYX7XCB42OO3P24DQKWHEKA/" @@ -134,6 +146,10 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WMIOPLBAAM3FEQNAXA2L7BDKOGSVUT5Z/" }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202401-27" + }, { "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20230526-0003/" diff --git a/advisories/github-reviewed/2023/11/GHSA-2492-xxqf-6h78/GHSA-2492-xxqf-6h78.json b/advisories/github-reviewed/2023/11/GHSA-2492-xxqf-6h78/GHSA-2492-xxqf-6h78.json index 3f9616c99a6..95f45187b3b 100644 --- a/advisories/github-reviewed/2023/11/GHSA-2492-xxqf-6h78/GHSA-2492-xxqf-6h78.json +++ b/advisories/github-reviewed/2023/11/GHSA-2492-xxqf-6h78/GHSA-2492-xxqf-6h78.json @@ -47,6 +47,10 @@ { "type": "PACKAGE", "url": "https://github.com/SwiftyEdit/SwiftyEdit" + }, + { + "type": "WEB", + "url": "https://mechaneus.github.io/CVE-2023-47350.html" } ], "database_specific": {