diff --git a/advisories/github-reviewed/2024/06/GHSA-2p57-rm9w-gvfp/GHSA-2p57-rm9w-gvfp.json b/advisories/github-reviewed/2024/06/GHSA-2p57-rm9w-gvfp/GHSA-2p57-rm9w-gvfp.json index 70372727694..d8f74afe41b 100644 --- a/advisories/github-reviewed/2024/06/GHSA-2p57-rm9w-gvfp/GHSA-2p57-rm9w-gvfp.json +++ b/advisories/github-reviewed/2024/06/GHSA-2p57-rm9w-gvfp/GHSA-2p57-rm9w-gvfp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2p57-rm9w-gvfp", - "modified": "2024-06-02T22:29:29Z", + "modified": "2024-09-03T19:59:01Z", "published": "2024-06-02T22:29:29Z", "aliases": [ "CVE-2024-29415" @@ -9,7 +9,10 @@ "summary": "ip SSRF improper categorization in isPublic", "details": "The ip package through 2.0.1 for Node.js might allow SSRF because some IP addresses (such as 127.1, 01200034567, 012.1.2.3, 000:0:0000::01, and ::fFFf:127.0.0.1) are improperly categorized as globally routable via isPublic. NOTE: this issue exists because of an incomplete fix for CVE-2023-42282.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ { diff --git a/advisories/github-reviewed/2024/07/GHSA-9v2f-6vcg-3hgv/GHSA-9v2f-6vcg-3hgv.json b/advisories/github-reviewed/2024/07/GHSA-9v2f-6vcg-3hgv/GHSA-9v2f-6vcg-3hgv.json index 19e4ec10eb7..b6a10dd9274 100644 --- a/advisories/github-reviewed/2024/07/GHSA-9v2f-6vcg-3hgv/GHSA-9v2f-6vcg-3hgv.json +++ b/advisories/github-reviewed/2024/07/GHSA-9v2f-6vcg-3hgv/GHSA-9v2f-6vcg-3hgv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9v2f-6vcg-3hgv", - "modified": "2024-07-03T20:05:21Z", + "modified": "2024-09-03T19:59:03Z", "published": "2024-07-01T21:31:15Z", "aliases": [ "CVE-2024-39236" @@ -30,9 +30,17 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39236" }, + { + "type": "WEB", + "url": "https://github.com/gradio-app/gradio/issues/8853" + }, { "type": "WEB", "url": "https://github.com/Aaron911/PoC/blob/main/Gradio.md" + }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-9v2f-6vcg-3hgv" } ], "database_specific": {