diff --git a/advisories/github-reviewed/2021/04/GHSA-5wrh-4jwv-5w78/GHSA-5wrh-4jwv-5w78.json b/advisories/github-reviewed/2021/04/GHSA-5wrh-4jwv-5w78/GHSA-5wrh-4jwv-5w78.json index 40884fc970d..0dabc26b2f7 100644 --- a/advisories/github-reviewed/2021/04/GHSA-5wrh-4jwv-5w78/GHSA-5wrh-4jwv-5w78.json +++ b/advisories/github-reviewed/2021/04/GHSA-5wrh-4jwv-5w78/GHSA-5wrh-4jwv-5w78.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5wrh-4jwv-5w78", - "modified": "2021-08-31T21:07:35Z", + "modified": "2024-09-30T20:28:18Z", "published": "2021-04-13T15:13:08Z", "aliases": [ "CVE-2021-21392" @@ -12,6 +12,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N" } ], "affected": [ @@ -28,7 +32,7 @@ "introduced": "0" }, { - "fixed": "1.28.0" + "fixed": "1.28.0rc1" } ] } @@ -48,10 +52,18 @@ "type": "WEB", "url": "https://github.com/matrix-org/synapse/pull/9240" }, + { + "type": "WEB", + "url": "https://github.com/matrix-org/synapse/commit/4ca054a4eaa714d0befb4fc30b19a1131e52c9cc" + }, { "type": "PACKAGE", "url": "https://github.com/matrix-org/synapse" }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/matrix-synapse/PYSEC-2021-25.yaml" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TNNAJOZNMVMXM6AS7RFFKB4QLUJ4IFEY" @@ -65,7 +77,7 @@ "cwe_ids": [ "CWE-601" ], - "severity": "MODERATE", + "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2021-04-12T21:51:49Z", "nvd_published_at": "2021-04-12T22:15:00Z" diff --git a/advisories/github-reviewed/2022/06/GHSA-22p3-qrh9-cx32/GHSA-22p3-qrh9-cx32.json b/advisories/github-reviewed/2022/06/GHSA-22p3-qrh9-cx32/GHSA-22p3-qrh9-cx32.json index 4c83616399b..de7d6541057 100644 --- a/advisories/github-reviewed/2022/06/GHSA-22p3-qrh9-cx32/GHSA-22p3-qrh9-cx32.json +++ b/advisories/github-reviewed/2022/06/GHSA-22p3-qrh9-cx32/GHSA-22p3-qrh9-cx32.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-22p3-qrh9-cx32", - "modified": "2022-06-29T21:51:23Z", + "modified": "2024-09-30T20:29:11Z", "published": "2022-06-29T21:51:23Z", "aliases": [ "CVE-2022-31052" @@ -12,6 +12,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N" } ], "affected": [ @@ -73,7 +77,7 @@ "cwe_ids": [ "CWE-674" ], - "severity": "MODERATE", + "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2022-06-29T21:51:23Z", "nvd_published_at": "2022-06-28T17:15:00Z"