Publish GHSA-qjqp-xr96-cj99

This commit is contained in:
advisory-database[bot]
2024-06-03 17:26:39 +00:00
parent 0b9c7cb7fb
commit 8f640d44bf
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qjqp-xr96-cj99",
"modified": "2024-05-15T14:20:37Z",
"modified": "2024-06-03T17:24:56Z",
"published": "2024-05-07T16:49:24Z",
"aliases": [
"CVE-2024-34341"
@@ -52,6 +52,44 @@
]
}
]
},
{
"package": {
"ecosystem": "RubyGems",
"name": "actiontext"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "7.0.0.alpha1"
},
{
"fixed": "7.0.8.3"
}
]
}
]
},
{
"package": {
"ecosystem": "RubyGems",
"name": "actiontext"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "7.1.0.beta1"
},
{
"fixed": "7.1.3.3"
}
]
}
]
}
],
"references": [
@@ -79,6 +117,22 @@
"type": "WEB",
"url": "https://github.com/basecamp/trix/commit/841ff19b53f349915100bca8fcb488214ff93554"
},
{
"type": "WEB",
"url": "https://github.com/rails/rails/commit/07e6c88cc4defe6f6b8d28e79eb13a518e15b14c"
},
{
"type": "WEB",
"url": "https://github.com/rails/rails/commit/260cb392fc1ee91d0b749cff08d1c8d54b230bd3"
},
{
"type": "WEB",
"url": "https://github.com/rails/rails/commit/73fac32511eefdd45d8f00fecc2b8cc5408ea6d5"
},
{
"type": "WEB",
"url": "https://discuss.rubyonrails.org/t/xss-vulnerabilities-in-trix-editor/85803"
},
{
"type": "PACKAGE",
"url": "https://github.com/basecamp/trix"
@@ -86,6 +140,18 @@
{
"type": "WEB",
"url": "https://github.com/basecamp/trix/releases/tag/v2.1.1"
},
{
"type": "WEB",
"url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/actiontext/CVE-2024-34341.yml"
},
{
"type": "WEB",
"url": "https://rubyonrails.org/2024/5/17/Rails-Versions-7-0-8-2-and-7-1-3-3-have-been-released"
},
{
"type": "WEB",
"url": "https://rubyonrails.org/2024/5/17/Rails-Versions-7-0-8-3-has-been-released"
}
],
"database_specific": {