From 8a41b62b14e1073ba2473f496764819f22bcb0b7 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 25 Oct 2024 21:35:04 +0000 Subject: [PATCH] Publish Advisories GHSA-9vxf-mcm6-5m42 GHSA-ch4c-278q-5654 GHSA-cw2v-wv4g-w4p6 GHSA-mjw4-xvx6-3grg GHSA-mp5p-g2jv-r8qw GHSA-vq4h-xrwc-m639 --- .../09/GHSA-9vxf-mcm6-5m42/GHSA-9vxf-mcm6-5m42.json | 10 +++++++++- .../09/GHSA-ch4c-278q-5654/GHSA-ch4c-278q-5654.json | 12 ++++++++++-- .../09/GHSA-cw2v-wv4g-w4p6/GHSA-cw2v-wv4g-w4p6.json | 6 +++++- .../09/GHSA-mjw4-xvx6-3grg/GHSA-mjw4-xvx6-3grg.json | 12 ++++++++++-- .../09/GHSA-mp5p-g2jv-r8qw/GHSA-mp5p-g2jv-r8qw.json | 12 ++++++++++-- .../09/GHSA-vq4h-xrwc-m639/GHSA-vq4h-xrwc-m639.json | 10 +++++++++- 6 files changed, 53 insertions(+), 9 deletions(-) diff --git a/advisories/github-reviewed/2022/09/GHSA-9vxf-mcm6-5m42/GHSA-9vxf-mcm6-5m42.json b/advisories/github-reviewed/2022/09/GHSA-9vxf-mcm6-5m42/GHSA-9vxf-mcm6-5m42.json index 80b34bdfe4c..dbbae3314ea 100644 --- a/advisories/github-reviewed/2022/09/GHSA-9vxf-mcm6-5m42/GHSA-9vxf-mcm6-5m42.json +++ b/advisories/github-reviewed/2022/09/GHSA-9vxf-mcm6-5m42/GHSA-9vxf-mcm6-5m42.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9vxf-mcm6-5m42", - "modified": "2022-09-22T22:43:34Z", + "modified": "2024-10-25T21:34:03Z", "published": "2022-09-22T00:00:21Z", "aliases": [ "CVE-2022-3233" @@ -12,6 +12,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N" } ], "affected": [ @@ -48,6 +52,10 @@ "type": "PACKAGE", "url": "https://github.com/ikus060/rdiffweb" }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/rdiffweb/PYSEC-2022-285.yaml" + }, { "type": "WEB", "url": "https://huntr.dev/bounties/5ec206e0-eca0-4957-9af4-fdd9185d1db3" diff --git a/advisories/github-reviewed/2022/09/GHSA-ch4c-278q-5654/GHSA-ch4c-278q-5654.json b/advisories/github-reviewed/2022/09/GHSA-ch4c-278q-5654/GHSA-ch4c-278q-5654.json index f82779956d2..ea0a99158ed 100644 --- a/advisories/github-reviewed/2022/09/GHSA-ch4c-278q-5654/GHSA-ch4c-278q-5654.json +++ b/advisories/github-reviewed/2022/09/GHSA-ch4c-278q-5654/GHSA-ch4c-278q-5654.json @@ -1,17 +1,21 @@ { "schema_version": "1.4.0", "id": "GHSA-ch4c-278q-5654", - "modified": "2022-09-16T21:35:08Z", + "modified": "2024-10-25T21:32:58Z", "published": "2022-09-14T00:00:51Z", "aliases": [ "CVE-2022-3175" ], - "summary": "rdiffweb 2.4.1 Missing Custom Error Page", + "summary": "rdiffweb Missing Custom Error Page", "details": "rdiffweb version 2.4.1 is set to a default and leaks error information. Version 2.4.2 fixes this issue.", "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N" } ], "affected": [ @@ -47,6 +51,10 @@ "type": "WEB", "url": "https://github.com/ikus060/rdiffweb/commit/233befc33bdc45d4838c773d5aed4408720504c5" }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-ch4c-278q-5654" + }, { "type": "PACKAGE", "url": "https://github.com/ikus060/rdiffweb" diff --git a/advisories/github-reviewed/2022/09/GHSA-cw2v-wv4g-w4p6/GHSA-cw2v-wv4g-w4p6.json b/advisories/github-reviewed/2022/09/GHSA-cw2v-wv4g-w4p6/GHSA-cw2v-wv4g-w4p6.json index e9ba9bbcaf5..7fdbd4f5549 100644 --- a/advisories/github-reviewed/2022/09/GHSA-cw2v-wv4g-w4p6/GHSA-cw2v-wv4g-w4p6.json +++ b/advisories/github-reviewed/2022/09/GHSA-cw2v-wv4g-w4p6/GHSA-cw2v-wv4g-w4p6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cw2v-wv4g-w4p6", - "modified": "2022-09-22T17:20:09Z", + "modified": "2024-10-25T21:33:52Z", "published": "2022-09-18T00:00:30Z", "aliases": [ "CVE-2022-3232" @@ -12,6 +12,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N" } ], "affected": [ diff --git a/advisories/github-reviewed/2022/09/GHSA-mjw4-xvx6-3grg/GHSA-mjw4-xvx6-3grg.json b/advisories/github-reviewed/2022/09/GHSA-mjw4-xvx6-3grg/GHSA-mjw4-xvx6-3grg.json index 2ab2c601945..b37abf2ad0b 100644 --- a/advisories/github-reviewed/2022/09/GHSA-mjw4-xvx6-3grg/GHSA-mjw4-xvx6-3grg.json +++ b/advisories/github-reviewed/2022/09/GHSA-mjw4-xvx6-3grg/GHSA-mjw4-xvx6-3grg.json @@ -1,17 +1,21 @@ { "schema_version": "1.4.0", "id": "GHSA-mjw4-xvx6-3grg", - "modified": "2022-09-16T21:35:41Z", + "modified": "2024-10-25T21:32:37Z", "published": "2022-09-14T00:00:51Z", "aliases": [ "CVE-2022-3174" ], - "summary": "rdiffweb 2.4.1 vulnerable to Sensitive Cookie in HTTPS Session Without 'Secure' Attribute", + "summary": "rdiffweb vulnerable to Sensitive Cookie in HTTPS Session Without 'Secure' Attribute", "details": "rdiffweb version 2.4.1 is vulnerable to Sensitive Cookie in HTTPS Session Without 'Secure' Attribute. This makes it so that a user's cookies can be sent to the server with an unencrypted request over the HTTP protocol. Version 2.4.2 contains a fix for the issue.", "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N" } ], "affected": [ @@ -47,6 +51,10 @@ "type": "WEB", "url": "https://github.com/ikus060/rdiffweb/commit/f2de2371c5e13ce1c6fd6f9a1ed3e5d46b93cd7e" }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-mjw4-xvx6-3grg" + }, { "type": "PACKAGE", "url": "https://github.com/ikus060/rdiffweb" diff --git a/advisories/github-reviewed/2022/09/GHSA-mp5p-g2jv-r8qw/GHSA-mp5p-g2jv-r8qw.json b/advisories/github-reviewed/2022/09/GHSA-mp5p-g2jv-r8qw/GHSA-mp5p-g2jv-r8qw.json index 48c02a4eebf..cecd5c7a7f9 100644 --- a/advisories/github-reviewed/2022/09/GHSA-mp5p-g2jv-r8qw/GHSA-mp5p-g2jv-r8qw.json +++ b/advisories/github-reviewed/2022/09/GHSA-mp5p-g2jv-r8qw/GHSA-mp5p-g2jv-r8qw.json @@ -1,17 +1,21 @@ { "schema_version": "1.4.0", "id": "GHSA-mp5p-g2jv-r8qw", - "modified": "2022-09-16T21:36:30Z", + "modified": "2024-10-25T21:32:14Z", "published": "2022-09-14T00:00:43Z", "aliases": [ "CVE-2022-3179" ], - "summary": "rdiffweb 2.4.1 contains Weak Password Requirements", + "summary": "rdiffweb contains Weak Password Requirements", "details": "rdiffweb version 2.4.1 has no password policy or password checking, which could make users vulnerable to brute force password guessing attacks. Version 2.4.2 enforces minimum and maximum password lengths.", "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" } ], "affected": [ @@ -47,6 +51,10 @@ "type": "WEB", "url": "https://github.com/ikus060/rdiffweb/commit/233befc33bdc45d4838c773d5aed4408720504c5" }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-mp5p-g2jv-r8qw" + }, { "type": "PACKAGE", "url": "https://github.com/ikus060/rdiffweb" diff --git a/advisories/github-reviewed/2022/09/GHSA-vq4h-xrwc-m639/GHSA-vq4h-xrwc-m639.json b/advisories/github-reviewed/2022/09/GHSA-vq4h-xrwc-m639/GHSA-vq4h-xrwc-m639.json index e3fdd3d7337..aed7bcbeafa 100644 --- a/advisories/github-reviewed/2022/09/GHSA-vq4h-xrwc-m639/GHSA-vq4h-xrwc-m639.json +++ b/advisories/github-reviewed/2022/09/GHSA-vq4h-xrwc-m639/GHSA-vq4h-xrwc-m639.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vq4h-xrwc-m639", - "modified": "2022-09-16T21:56:47Z", + "modified": "2024-10-25T21:33:32Z", "published": "2022-09-16T00:00:39Z", "aliases": [ "CVE-2022-3221" @@ -12,6 +12,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" } ], "affected": [ @@ -44,6 +48,10 @@ "type": "WEB", "url": "https://github.com/ikus060/rdiffweb/commit/9125f5a2d918fed0f3fc1c86fa94cd1779ed9f73" }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-vq4h-xrwc-m639" + }, { "type": "PACKAGE", "url": "https://github.com/ikus060/rdiffweb"