From 80c03ab7593b72dd5fea03fcb568109e32725db4 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 3 Apr 2025 14:29:23 +0000 Subject: [PATCH] Publish Advisories GHSA-9wrq-xvmp-xjc8 GHSA-rvpq-5xqx-pfpp GHSA-586p-749j-fhwp GHSA-7p9f-6x8j-gxxp --- .../GHSA-9wrq-xvmp-xjc8.json | 26 +++----------- .../GHSA-rvpq-5xqx-pfpp.json | 34 +++++-------------- .../GHSA-586p-749j-fhwp.json | 6 +++- .../GHSA-7p9f-6x8j-gxxp.json | 6 +++- 4 files changed, 24 insertions(+), 48 deletions(-) diff --git a/advisories/github-reviewed/2017/10/GHSA-9wrq-xvmp-xjc8/GHSA-9wrq-xvmp-xjc8.json b/advisories/github-reviewed/2017/10/GHSA-9wrq-xvmp-xjc8/GHSA-9wrq-xvmp-xjc8.json index 6df9bdddcf2..6f295a3c62a 100644 --- a/advisories/github-reviewed/2017/10/GHSA-9wrq-xvmp-xjc8/GHSA-9wrq-xvmp-xjc8.json +++ b/advisories/github-reviewed/2017/10/GHSA-9wrq-xvmp-xjc8/GHSA-9wrq-xvmp-xjc8.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-9wrq-xvmp-xjc8", - "modified": "2021-12-01T19:40:37Z", + "modified": "2025-04-03T14:26:59Z", "published": "2017-10-24T18:33:38Z", "aliases": [ "CVE-2006-4112" ], - "summary": "High severity vulnerability that affects rails.", + "summary": "Rails Denial of Service vulnerability", "details": "Unspecified vulnerability in the \"dependency resolution mechanism\" in Ruby on Rails 1.1.0 through 1.1.5 allows remote attackers to execute arbitrary Ruby code via a URL that is not properly handled in the routing code, which leads to a denial of service (application hang) or \"data loss,\" a different vulnerability than CVE-2006-4111.", "severity": [], "affected": [ @@ -39,10 +39,6 @@ "type": "WEB", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/28364" }, - { - "type": "ADVISORY", - "url": "https://github.com/advisories/GHSA-9wrq-xvmp-xjc8" - }, { "type": "PACKAGE", "url": "https://github.com/rails/rails" @@ -53,19 +49,15 @@ }, { "type": "WEB", - "url": "http://secunia.com/advisories/21424" + "url": "https://web.archive.org/web/20200301174340/http://www.securityfocus.com/bid/19454" }, { "type": "WEB", - "url": "http://secunia.com/advisories/21466" + "url": "https://web.archive.org/web/20200804225700/http://www.securityfocus.com/archive/1/442934/100/0/threaded" }, { "type": "WEB", - "url": "http://secunia.com/advisories/21749" - }, - { - "type": "WEB", - "url": "http://securitytracker.com/id?1016673" + "url": "https://web.archive.org/web/20200808083046/http://securitytracker.com/id?1016673" }, { "type": "WEB", @@ -82,14 +74,6 @@ { "type": "WEB", "url": "http://www.novell.com/linux/security/advisories/2006_21_sr.html" - }, - { - "type": "WEB", - "url": "http://www.securityfocus.com/archive/1/442934/100/0/threaded" - }, - { - "type": "WEB", - "url": "http://www.securityfocus.com/bid/19454" } ], "database_specific": { diff --git a/advisories/github-reviewed/2017/10/GHSA-rvpq-5xqx-pfpp/GHSA-rvpq-5xqx-pfpp.json b/advisories/github-reviewed/2017/10/GHSA-rvpq-5xqx-pfpp/GHSA-rvpq-5xqx-pfpp.json index fca41bb9ecb..43f8f4eb7af 100644 --- a/advisories/github-reviewed/2017/10/GHSA-rvpq-5xqx-pfpp/GHSA-rvpq-5xqx-pfpp.json +++ b/advisories/github-reviewed/2017/10/GHSA-rvpq-5xqx-pfpp/GHSA-rvpq-5xqx-pfpp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rvpq-5xqx-pfpp", - "modified": "2023-05-11T13:57:05Z", + "modified": "2025-04-03T14:27:51Z", "published": "2017-10-24T18:33:38Z", "aliases": [ "CVE-2006-4111" @@ -35,10 +35,6 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2006-4111" }, - { - "type": "ADVISORY", - "url": "https://github.com/advisories/GHSA-rvpq-5xqx-pfpp" - }, { "type": "WEB", "url": "https://github.com/presidentbeef/rails-security-history/blob/master/vulnerabilities.md" @@ -51,22 +47,18 @@ "type": "WEB", "url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/rails/CVE-2006-4111.yml" }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20200301174340/http://www.securityfocus.com/bid/19454" + }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20200808083046/http://securitytracker.com/id?1016673" + }, { "type": "WEB", "url": "http://blog.koehntopp.de/archives/1367-Ruby-On-Rails-Mandatory-Mystery-Patch.html" }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/21466" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/21749" - }, - { - "type": "WEB", - "url": "http://securitytracker.com/id?1016673" - }, { "type": "WEB", "url": "http://weblog.rubyonrails.org/2006/8/9/rails-1-1-5-mandatory-security-patch-and-other-tidbits" @@ -78,14 +70,6 @@ { "type": "WEB", "url": "http://www.novell.com/linux/security/advisories/2006_21_sr.html" - }, - { - "type": "WEB", - "url": "http://www.securityfocus.com/bid/19454" - }, - { - "type": "WEB", - "url": "http://www.vupen.com/english/advisories/2006/3237" } ], "database_specific": { diff --git a/advisories/github-reviewed/2024/10/GHSA-586p-749j-fhwp/GHSA-586p-749j-fhwp.json b/advisories/github-reviewed/2024/10/GHSA-586p-749j-fhwp/GHSA-586p-749j-fhwp.json index 0a032eb8378..1804a9c9c29 100644 --- a/advisories/github-reviewed/2024/10/GHSA-586p-749j-fhwp/GHSA-586p-749j-fhwp.json +++ b/advisories/github-reviewed/2024/10/GHSA-586p-749j-fhwp/GHSA-586p-749j-fhwp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-586p-749j-fhwp", - "modified": "2025-03-20T19:36:09Z", + "modified": "2025-04-03T14:28:08Z", "published": "2024-10-09T15:32:21Z", "aliases": [ "CVE-2024-9675" @@ -64,6 +64,10 @@ "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-9675" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:3301" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:2710" diff --git a/advisories/github-reviewed/2024/11/GHSA-7p9f-6x8j-gxxp/GHSA-7p9f-6x8j-gxxp.json b/advisories/github-reviewed/2024/11/GHSA-7p9f-6x8j-gxxp/GHSA-7p9f-6x8j-gxxp.json index 23ebb29c9c1..dad2fdbdd2d 100644 --- a/advisories/github-reviewed/2024/11/GHSA-7p9f-6x8j-gxxp/GHSA-7p9f-6x8j-gxxp.json +++ b/advisories/github-reviewed/2024/11/GHSA-7p9f-6x8j-gxxp/GHSA-7p9f-6x8j-gxxp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7p9f-6x8j-gxxp", - "modified": "2025-03-04T22:21:53Z", + "modified": "2025-04-03T14:28:29Z", "published": "2024-11-26T21:50:30Z", "aliases": [ "CVE-2024-8676" @@ -102,6 +102,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:1908" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:3297" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-8676"