diff --git a/advisories/github-reviewed/2024/01/GHSA-76cc-p55w-63g3/GHSA-76cc-p55w-63g3.json b/advisories/github-reviewed/2024/01/GHSA-76cc-p55w-63g3/GHSA-76cc-p55w-63g3.json index b51f5875320..2f0f5705079 100644 --- a/advisories/github-reviewed/2024/01/GHSA-76cc-p55w-63g3/GHSA-76cc-p55w-63g3.json +++ b/advisories/github-reviewed/2024/01/GHSA-76cc-p55w-63g3/GHSA-76cc-p55w-63g3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-76cc-p55w-63g3", - "modified": "2024-07-08T19:39:41Z", + "modified": "2024-09-06T21:40:26Z", "published": "2024-01-03T21:29:09Z", "withdrawn": "2024-01-23T12:50:23Z", "aliases": [ diff --git a/advisories/github-reviewed/2024/01/GHSA-c9v7-wmwj-vf6x/GHSA-c9v7-wmwj-vf6x.json b/advisories/github-reviewed/2024/01/GHSA-c9v7-wmwj-vf6x/GHSA-c9v7-wmwj-vf6x.json index 15f889e903f..846ec6edf83 100644 --- a/advisories/github-reviewed/2024/01/GHSA-c9v7-wmwj-vf6x/GHSA-c9v7-wmwj-vf6x.json +++ b/advisories/github-reviewed/2024/01/GHSA-c9v7-wmwj-vf6x/GHSA-c9v7-wmwj-vf6x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c9v7-wmwj-vf6x", - "modified": "2024-07-08T19:40:00Z", + "modified": "2024-09-06T21:40:24Z", "published": "2024-01-03T21:29:33Z", "withdrawn": "2024-01-23T12:50:08Z", "aliases": [ diff --git a/advisories/github-reviewed/2024/01/GHSA-hw4x-mcx5-9q36/GHSA-hw4x-mcx5-9q36.json b/advisories/github-reviewed/2024/01/GHSA-hw4x-mcx5-9q36/GHSA-hw4x-mcx5-9q36.json index b83a36487ba..79a12153c4c 100644 --- a/advisories/github-reviewed/2024/01/GHSA-hw4x-mcx5-9q36/GHSA-hw4x-mcx5-9q36.json +++ b/advisories/github-reviewed/2024/01/GHSA-hw4x-mcx5-9q36/GHSA-hw4x-mcx5-9q36.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hw4x-mcx5-9q36", - "modified": "2024-07-08T19:39:16Z", + "modified": "2024-09-06T21:40:28Z", "published": "2024-01-03T21:28:37Z", "withdrawn": "2024-01-23T12:50:39Z", "aliases": [ diff --git a/advisories/github-reviewed/2024/01/GHSA-vfxf-76hv-v4w4/GHSA-vfxf-76hv-v4w4.json b/advisories/github-reviewed/2024/01/GHSA-vfxf-76hv-v4w4/GHSA-vfxf-76hv-v4w4.json index 6d301f35263..8e433406460 100644 --- a/advisories/github-reviewed/2024/01/GHSA-vfxf-76hv-v4w4/GHSA-vfxf-76hv-v4w4.json +++ b/advisories/github-reviewed/2024/01/GHSA-vfxf-76hv-v4w4/GHSA-vfxf-76hv-v4w4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vfxf-76hv-v4w4", - "modified": "2024-07-08T19:40:23Z", + "modified": "2024-09-06T21:40:14Z", "published": "2024-01-03T21:30:17Z", "withdrawn": "2024-01-23T12:49:53Z", "aliases": [ diff --git a/advisories/github-reviewed/2024/02/GHSA-r4fm-g65h-cr54/GHSA-r4fm-g65h-cr54.json b/advisories/github-reviewed/2024/02/GHSA-r4fm-g65h-cr54/GHSA-r4fm-g65h-cr54.json index 622679ac39f..3f5b0e9c0a5 100644 --- a/advisories/github-reviewed/2024/02/GHSA-r4fm-g65h-cr54/GHSA-r4fm-g65h-cr54.json +++ b/advisories/github-reviewed/2024/02/GHSA-r4fm-g65h-cr54/GHSA-r4fm-g65h-cr54.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r4fm-g65h-cr54", - "modified": "2024-07-08T20:31:16Z", + "modified": "2024-09-06T21:40:17Z", "published": "2024-02-29T12:31:06Z", "aliases": [ "CVE-2024-1952" @@ -44,6 +44,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1952" }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-r4fm-g65h-cr54" + }, { "type": "PACKAGE", "url": "https://github.com/mattermost/mattermost" diff --git a/advisories/github-reviewed/2024/07/GHSA-h63h-5c77-77p5/GHSA-h63h-5c77-77p5.json b/advisories/github-reviewed/2024/07/GHSA-h63h-5c77-77p5/GHSA-h63h-5c77-77p5.json index a74cd4e621d..84ae5171cc4 100644 --- a/advisories/github-reviewed/2024/07/GHSA-h63h-5c77-77p5/GHSA-h63h-5c77-77p5.json +++ b/advisories/github-reviewed/2024/07/GHSA-h63h-5c77-77p5/GHSA-h63h-5c77-77p5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h63h-5c77-77p5", - "modified": "2024-07-31T20:20:30Z", + "modified": "2024-09-06T21:41:22Z", "published": "2024-07-31T15:24:37Z", "aliases": [ "CVE-2024-37901" @@ -114,6 +114,7 @@ "database_specific": { "cwe_ids": [ "CWE-862", + "CWE-94", "CWE-95" ], "severity": "CRITICAL", diff --git a/advisories/github-reviewed/2024/07/GHSA-wf3x-jccf-5g5g/GHSA-wf3x-jccf-5g5g.json b/advisories/github-reviewed/2024/07/GHSA-wf3x-jccf-5g5g/GHSA-wf3x-jccf-5g5g.json index 214003d5042..8c4a2381561 100644 --- a/advisories/github-reviewed/2024/07/GHSA-wf3x-jccf-5g5g/GHSA-wf3x-jccf-5g5g.json +++ b/advisories/github-reviewed/2024/07/GHSA-wf3x-jccf-5g5g/GHSA-wf3x-jccf-5g5g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wf3x-jccf-5g5g", - "modified": "2024-07-31T20:20:27Z", + "modified": "2024-09-06T21:41:20Z", "published": "2024-07-31T15:21:06Z", "aliases": [ "CVE-2024-37900" @@ -140,6 +140,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-94", "CWE-96" ], "severity": "MODERATE", diff --git a/advisories/github-reviewed/2024/09/GHSA-6xx4-x46f-f897/GHSA-6xx4-x46f-f897.json b/advisories/github-reviewed/2024/09/GHSA-6xx4-x46f-f897/GHSA-6xx4-x46f-f897.json index 2e78e4caffa..d31d8863c33 100644 --- a/advisories/github-reviewed/2024/09/GHSA-6xx4-x46f-f897/GHSA-6xx4-x46f-f897.json +++ b/advisories/github-reviewed/2024/09/GHSA-6xx4-x46f-f897/GHSA-6xx4-x46f-f897.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6xx4-x46f-f897", - "modified": "2024-09-03T21:01:54Z", + "modified": "2024-09-06T21:41:35Z", "published": "2024-09-03T21:01:53Z", "aliases": [ "CVE-2024-45388" @@ -37,6 +37,25 @@ ] } ] + }, + { + "package": { + "ecosystem": "Go", + "name": "github.com/SpectoLabs/hoverfly" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.10.3" + } + ] + } + ] } ], "references": [ diff --git a/advisories/github-reviewed/2024/09/GHSA-7q74-g774-7x3g/GHSA-7q74-g774-7x3g.json b/advisories/github-reviewed/2024/09/GHSA-7q74-g774-7x3g/GHSA-7q74-g774-7x3g.json index 1d48b3d8ec7..3559f5a8ef3 100644 --- a/advisories/github-reviewed/2024/09/GHSA-7q74-g774-7x3g/GHSA-7q74-g774-7x3g.json +++ b/advisories/github-reviewed/2024/09/GHSA-7q74-g774-7x3g/GHSA-7q74-g774-7x3g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7q74-g774-7x3g", - "modified": "2024-09-05T21:19:37Z", + "modified": "2024-09-06T21:41:48Z", "published": "2024-09-05T21:19:36Z", "aliases": [ @@ -30,6 +30,70 @@ ] } ] + }, + { + "package": { + "ecosystem": "Go", + "name": "github.com/cosmos/interchain-security" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Go", + "name": "github.com/cosmos/interchain-security/v2" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Go", + "name": "github.com/cosmos/interchain-security/v3" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Go", + "name": "github.com/cosmos/interchain-security/v4" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ] } ], "references": [ diff --git a/advisories/github-reviewed/2024/09/GHSA-jjxf-26c9-77gm/GHSA-jjxf-26c9-77gm.json b/advisories/github-reviewed/2024/09/GHSA-jjxf-26c9-77gm/GHSA-jjxf-26c9-77gm.json index 0fbe0773bd5..209d017f416 100644 --- a/advisories/github-reviewed/2024/09/GHSA-jjxf-26c9-77gm/GHSA-jjxf-26c9-77gm.json +++ b/advisories/github-reviewed/2024/09/GHSA-jjxf-26c9-77gm/GHSA-jjxf-26c9-77gm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jjxf-26c9-77gm", - "modified": "2024-09-04T17:02:27Z", + "modified": "2024-09-06T21:41:33Z", "published": "2024-09-02T06:30:49Z", "aliases": [ "CVE-2024-8365" @@ -48,6 +48,10 @@ "type": "WEB", "url": "https://discuss.hashicorp.com/t/hcsec-2024-18-vault-leaks-client-token-and-token-accessor-in-audit-devices" }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-jjxf-26c9-77gm" + }, { "type": "PACKAGE", "url": "github.com/hashicorp/vault"