From 886f4533fd6601e2625783b527335a237a4c833b Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 18 Nov 2024 20:59:45 +0000 Subject: [PATCH] Publish GHSA-x6jf-c7wh-7m7w --- .../GHSA-x6jf-c7wh-7m7w/GHSA-x6jf-c7wh-7m7w.json | 15 +++++++++++++-- 1 file changed, 13 insertions(+), 2 deletions(-) diff --git a/advisories/github-reviewed/2022/05/GHSA-x6jf-c7wh-7m7w/GHSA-x6jf-c7wh-7m7w.json b/advisories/github-reviewed/2022/05/GHSA-x6jf-c7wh-7m7w/GHSA-x6jf-c7wh-7m7w.json index 8cb1c639ccc..09b2bb4d79f 100644 --- a/advisories/github-reviewed/2022/05/GHSA-x6jf-c7wh-7m7w/GHSA-x6jf-c7wh-7m7w.json +++ b/advisories/github-reviewed/2022/05/GHSA-x6jf-c7wh-7m7w/GHSA-x6jf-c7wh-7m7w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x6jf-c7wh-7m7w", - "modified": "2024-04-29T11:57:52Z", + "modified": "2024-11-18T20:57:58Z", "published": "2022-05-01T23:59:08Z", "aliases": [ "CVE-2008-3328" @@ -9,7 +9,14 @@ "summary": "Trac Cross-site Scripting (XSS) vulnerability", "details": "Cross-site scripting (XSS) vulnerability in the wiki engine in Trac before 0.10.5 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N" + } ], "affected": [ { @@ -41,6 +48,10 @@ "type": "WEB", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/44016" }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/trac/PYSEC-2008-5.yaml" + }, { "type": "WEB", "url": "https://web.archive.org/web/20140802031359/http://secunia.com/advisories/31231"