From 9be4b4571fbb6c478d1d41d114c73a83d5122766 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 9 Jan 2025 15:38:44 +0000 Subject: [PATCH] Publish Advisories GHSA-c6qg-cjj8-47qp GHSA-pj73-v5mw-pm9j GHSA-4g8v-vg43-wpgf GHSA-h2wm-p2vg-6pw4 GHSA-xp5h-f8jf-rc8q --- .../GHSA-c6qg-cjj8-47qp.json | 16 +++++++++++-- .../GHSA-pj73-v5mw-pm9j.json | 24 +++++++++++++++++-- .../GHSA-4g8v-vg43-wpgf.json | 12 ++++++++-- .../GHSA-h2wm-p2vg-6pw4.json | 12 ++++++++-- .../GHSA-xp5h-f8jf-rc8q.json | 20 ++++++++++++++-- 5 files changed, 74 insertions(+), 10 deletions(-) diff --git a/advisories/github-reviewed/2023/03/GHSA-c6qg-cjj8-47qp/GHSA-c6qg-cjj8-47qp.json b/advisories/github-reviewed/2023/03/GHSA-c6qg-cjj8-47qp/GHSA-c6qg-cjj8-47qp.json index f8598ef9b95..bf77aa25d40 100644 --- a/advisories/github-reviewed/2023/03/GHSA-c6qg-cjj8-47qp/GHSA-c6qg-cjj8-47qp.json +++ b/advisories/github-reviewed/2023/03/GHSA-c6qg-cjj8-47qp/GHSA-c6qg-cjj8-47qp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c6qg-cjj8-47qp", - "modified": "2023-08-18T21:04:07Z", + "modified": "2025-01-09T15:36:58Z", "published": "2023-03-15T21:36:02Z", "aliases": [ "CVE-2023-27539" @@ -73,6 +73,18 @@ { "type": "WEB", "url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/rack/CVE-2023-27539.yml" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2023/04/msg00017.html" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20231208-0016" + }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2023/dsa-5530" } ], "database_specific": { @@ -80,6 +92,6 @@ "severity": "LOW", "github_reviewed": true, "github_reviewed_at": "2023-03-15T21:36:02Z", - "nvd_published_at": null + "nvd_published_at": "2025-01-09T01:15:07Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2023/03/GHSA-pj73-v5mw-pm9j/GHSA-pj73-v5mw-pm9j.json b/advisories/github-reviewed/2023/03/GHSA-pj73-v5mw-pm9j/GHSA-pj73-v5mw-pm9j.json index c27b3ebb142..66f2afb572d 100644 --- a/advisories/github-reviewed/2023/03/GHSA-pj73-v5mw-pm9j/GHSA-pj73-v5mw-pm9j.json +++ b/advisories/github-reviewed/2023/03/GHSA-pj73-v5mw-pm9j/GHSA-pj73-v5mw-pm9j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pj73-v5mw-pm9j", - "modified": "2023-03-15T21:36:01Z", + "modified": "2025-01-09T15:37:10Z", "published": "2023-03-15T21:36:01Z", "aliases": [ "CVE-2023-28120" @@ -54,6 +54,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28120" }, + { + "type": "WEB", + "url": "https://github.com/rails/rails/commit/3cf23c3f891e2e81c977ea4ab83b62bc2a444b70" + }, { "type": "WEB", "url": "https://discuss.rubyonrails.org/t/cve-2023-28120-possible-xss-security-vulnerability-in-safebuffer-bytesplice/82469" @@ -61,6 +65,22 @@ { "type": "WEB", "url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/activesupport/CVE-2023-28120.yml" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UPV6PVCX4VDJHLFFT42EXBBSGAWZICOW" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZE5W4MH6IE4DV7GELDK6ISCSTFLHKSYO" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240202-0006" + }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2023/dsa-5389" } ], "database_specific": { @@ -70,6 +90,6 @@ "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2023-03-15T21:36:01Z", - "nvd_published_at": null + "nvd_published_at": "2025-01-09T01:15:07Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2023/06/GHSA-4g8v-vg43-wpgf/GHSA-4g8v-vg43-wpgf.json b/advisories/github-reviewed/2023/06/GHSA-4g8v-vg43-wpgf/GHSA-4g8v-vg43-wpgf.json index 96c7fe3469a..e644fb51361 100644 --- a/advisories/github-reviewed/2023/06/GHSA-4g8v-vg43-wpgf/GHSA-4g8v-vg43-wpgf.json +++ b/advisories/github-reviewed/2023/06/GHSA-4g8v-vg43-wpgf/GHSA-4g8v-vg43-wpgf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4g8v-vg43-wpgf", - "modified": "2023-06-29T15:03:16Z", + "modified": "2025-01-09T15:37:45Z", "published": "2023-06-29T15:03:16Z", "aliases": [ "CVE-2023-28362" @@ -50,10 +50,18 @@ } ], "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-28362" + }, { "type": "WEB", "url": "https://github.com/rails/rails/commit/1c3f93d1e90a3475f9ae2377ead25ccf11f71441" }, + { + "type": "WEB", + "url": "https://github.com/rails/rails/commit/69e37c84e3f77d75566424c7d0015172d6a6fac5" + }, { "type": "WEB", "url": "https://github.com/rails/rails/commit/c9ab9b32bcdcfd8bcd55907f6c7b20b4e004cc23" @@ -76,6 +84,6 @@ "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2023-06-29T15:03:16Z", - "nvd_published_at": null + "nvd_published_at": "2025-01-09T01:15:07Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2023/06/GHSA-h2wm-p2vg-6pw4/GHSA-h2wm-p2vg-6pw4.json b/advisories/github-reviewed/2023/06/GHSA-h2wm-p2vg-6pw4/GHSA-h2wm-p2vg-6pw4.json index c22953daf6a..d22ec44ada7 100644 --- a/advisories/github-reviewed/2023/06/GHSA-h2wm-p2vg-6pw4/GHSA-h2wm-p2vg-6pw4.json +++ b/advisories/github-reviewed/2023/06/GHSA-h2wm-p2vg-6pw4/GHSA-h2wm-p2vg-6pw4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h2wm-p2vg-6pw4", - "modified": "2023-06-20T14:21:48Z", + "modified": "2025-01-09T15:37:28Z", "published": "2023-06-09T22:40:54Z", "aliases": [ "CVE-2023-27531" @@ -31,10 +31,18 @@ } ], "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-27531" + }, { "type": "WEB", "url": "https://github.com/rails/kredis/commit/d576b7ae5c8d3d74eeb4bd84cad0aa64ffc299fa" }, + { + "type": "WEB", + "url": "https://discuss.rubyonrails.org/t/cve-2023-27531-possible-deserialization-of-untrusted-data-vulnerability-in-kredis-json/82467" + }, { "type": "WEB", "url": "https://discuss.rubyonrails.org/t/cve-2023-27531-possible-deserialization-of-untrusted-data-vulnerability-in-kredis-json/82467#post_1" @@ -59,6 +67,6 @@ "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2023-06-09T22:40:54Z", - "nvd_published_at": null + "nvd_published_at": "2025-01-09T01:15:07Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2023/06/GHSA-xp5h-f8jf-rc8q/GHSA-xp5h-f8jf-rc8q.json b/advisories/github-reviewed/2023/06/GHSA-xp5h-f8jf-rc8q/GHSA-xp5h-f8jf-rc8q.json index 0c4d2771ca5..8455dc44d03 100644 --- a/advisories/github-reviewed/2023/06/GHSA-xp5h-f8jf-rc8q/GHSA-xp5h-f8jf-rc8q.json +++ b/advisories/github-reviewed/2023/06/GHSA-xp5h-f8jf-rc8q/GHSA-xp5h-f8jf-rc8q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xp5h-f8jf-rc8q", - "modified": "2023-06-09T22:41:16Z", + "modified": "2025-01-09T15:37:19Z", "published": "2023-06-09T22:41:16Z", "aliases": [ "CVE-2023-23913" @@ -50,6 +50,10 @@ } ], "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-23913" + }, { "type": "WEB", "url": "https://github.com/rails/rails/commit/5037a13614d71727af8a175063bcf6ba1a74bdbd" @@ -58,6 +62,10 @@ "type": "WEB", "url": "https://github.com/rails/rails/commit/73009ea59a811b28e8ec2a9c9bc24635aa891214" }, + { + "type": "WEB", + "url": "https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1033263" + }, { "type": "WEB", "url": "https://discuss.rubyonrails.org/t/cve-2023-23913-dom-based-cross-site-scripting-in-rails-ujs-for-contenteditable-html-elements/82468" @@ -69,6 +77,14 @@ { "type": "WEB", "url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/actionview/CVE-2023-23913.yml" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20240605-0007" + }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2023/dsa-5389" } ], "database_specific": { @@ -78,6 +94,6 @@ "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2023-06-09T22:41:16Z", - "nvd_published_at": null + "nvd_published_at": "2025-01-09T01:15:07Z" } } \ No newline at end of file