Publish Advisories

GHSA-c6qg-cjj8-47qp
GHSA-pj73-v5mw-pm9j
GHSA-4g8v-vg43-wpgf
GHSA-h2wm-p2vg-6pw4
GHSA-xp5h-f8jf-rc8q
This commit is contained in:
advisory-database[bot]
2025-01-09 15:38:44 +00:00
parent 42b3b48d88
commit 9be4b4571f
5 changed files with 74 additions and 10 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c6qg-cjj8-47qp",
"modified": "2023-08-18T21:04:07Z",
"modified": "2025-01-09T15:36:58Z",
"published": "2023-03-15T21:36:02Z",
"aliases": [
"CVE-2023-27539"
@@ -73,6 +73,18 @@
{
"type": "WEB",
"url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/rack/CVE-2023-27539.yml"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2023/04/msg00017.html"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20231208-0016"
},
{
"type": "WEB",
"url": "https://www.debian.org/security/2023/dsa-5530"
}
],
"database_specific": {
@@ -80,6 +92,6 @@
"severity": "LOW",
"github_reviewed": true,
"github_reviewed_at": "2023-03-15T21:36:02Z",
"nvd_published_at": null
"nvd_published_at": "2025-01-09T01:15:07Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pj73-v5mw-pm9j",
"modified": "2023-03-15T21:36:01Z",
"modified": "2025-01-09T15:37:10Z",
"published": "2023-03-15T21:36:01Z",
"aliases": [
"CVE-2023-28120"
@@ -54,6 +54,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28120"
},
{
"type": "WEB",
"url": "https://github.com/rails/rails/commit/3cf23c3f891e2e81c977ea4ab83b62bc2a444b70"
},
{
"type": "WEB",
"url": "https://discuss.rubyonrails.org/t/cve-2023-28120-possible-xss-security-vulnerability-in-safebuffer-bytesplice/82469"
@@ -61,6 +65,22 @@
{
"type": "WEB",
"url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/activesupport/CVE-2023-28120.yml"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UPV6PVCX4VDJHLFFT42EXBBSGAWZICOW"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZE5W4MH6IE4DV7GELDK6ISCSTFLHKSYO"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20240202-0006"
},
{
"type": "WEB",
"url": "https://www.debian.org/security/2023/dsa-5389"
}
],
"database_specific": {
@@ -70,6 +90,6 @@
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2023-03-15T21:36:01Z",
"nvd_published_at": null
"nvd_published_at": "2025-01-09T01:15:07Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4g8v-vg43-wpgf",
"modified": "2023-06-29T15:03:16Z",
"modified": "2025-01-09T15:37:45Z",
"published": "2023-06-29T15:03:16Z",
"aliases": [
"CVE-2023-28362"
@@ -50,10 +50,18 @@
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28362"
},
{
"type": "WEB",
"url": "https://github.com/rails/rails/commit/1c3f93d1e90a3475f9ae2377ead25ccf11f71441"
},
{
"type": "WEB",
"url": "https://github.com/rails/rails/commit/69e37c84e3f77d75566424c7d0015172d6a6fac5"
},
{
"type": "WEB",
"url": "https://github.com/rails/rails/commit/c9ab9b32bcdcfd8bcd55907f6c7b20b4e004cc23"
@@ -76,6 +84,6 @@
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2023-06-29T15:03:16Z",
"nvd_published_at": null
"nvd_published_at": "2025-01-09T01:15:07Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h2wm-p2vg-6pw4",
"modified": "2023-06-20T14:21:48Z",
"modified": "2025-01-09T15:37:28Z",
"published": "2023-06-09T22:40:54Z",
"aliases": [
"CVE-2023-27531"
@@ -31,10 +31,18 @@
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27531"
},
{
"type": "WEB",
"url": "https://github.com/rails/kredis/commit/d576b7ae5c8d3d74eeb4bd84cad0aa64ffc299fa"
},
{
"type": "WEB",
"url": "https://discuss.rubyonrails.org/t/cve-2023-27531-possible-deserialization-of-untrusted-data-vulnerability-in-kredis-json/82467"
},
{
"type": "WEB",
"url": "https://discuss.rubyonrails.org/t/cve-2023-27531-possible-deserialization-of-untrusted-data-vulnerability-in-kredis-json/82467#post_1"
@@ -59,6 +67,6 @@
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2023-06-09T22:40:54Z",
"nvd_published_at": null
"nvd_published_at": "2025-01-09T01:15:07Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xp5h-f8jf-rc8q",
"modified": "2023-06-09T22:41:16Z",
"modified": "2025-01-09T15:37:19Z",
"published": "2023-06-09T22:41:16Z",
"aliases": [
"CVE-2023-23913"
@@ -50,6 +50,10 @@
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23913"
},
{
"type": "WEB",
"url": "https://github.com/rails/rails/commit/5037a13614d71727af8a175063bcf6ba1a74bdbd"
@@ -58,6 +62,10 @@
"type": "WEB",
"url": "https://github.com/rails/rails/commit/73009ea59a811b28e8ec2a9c9bc24635aa891214"
},
{
"type": "WEB",
"url": "https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1033263"
},
{
"type": "WEB",
"url": "https://discuss.rubyonrails.org/t/cve-2023-23913-dom-based-cross-site-scripting-in-rails-ujs-for-contenteditable-html-elements/82468"
@@ -69,6 +77,14 @@
{
"type": "WEB",
"url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/actionview/CVE-2023-23913.yml"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20240605-0007"
},
{
"type": "WEB",
"url": "https://www.debian.org/security/2023/dsa-5389"
}
],
"database_specific": {
@@ -78,6 +94,6 @@
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2023-06-09T22:41:16Z",
"nvd_published_at": null
"nvd_published_at": "2025-01-09T01:15:07Z"
}
}