diff --git a/advisories/github-reviewed/2024/04/GHSA-cjwg-qfpm-7377/GHSA-cjwg-qfpm-7377.json b/advisories/github-reviewed/2024/04/GHSA-cjwg-qfpm-7377/GHSA-cjwg-qfpm-7377.json index 1d972a12657..8ad37446881 100644 --- a/advisories/github-reviewed/2024/04/GHSA-cjwg-qfpm-7377/GHSA-cjwg-qfpm-7377.json +++ b/advisories/github-reviewed/2024/04/GHSA-cjwg-qfpm-7377/GHSA-cjwg-qfpm-7377.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cjwg-qfpm-7377", - "modified": "2024-05-01T07:37:41Z", + "modified": "2024-09-05T18:37:58Z", "published": "2024-04-26T00:30:35Z", "aliases": [ "CVE-2024-33664" @@ -51,6 +51,10 @@ { "type": "PACKAGE", "url": "https://github.com/mpdavis/python-jose" + }, + { + "type": "WEB", + "url": "https://www.vicarius.io/vsociety/posts/jwt-bomb-in-python-jose-cve-2024-33664" } ], "database_specific": { diff --git a/advisories/github-reviewed/2024/05/GHSA-76v2-48w6-crxr/GHSA-76v2-48w6-crxr.json b/advisories/github-reviewed/2024/05/GHSA-76v2-48w6-crxr/GHSA-76v2-48w6-crxr.json index 30c838c08c8..8c6e9749b72 100644 --- a/advisories/github-reviewed/2024/05/GHSA-76v2-48w6-crxr/GHSA-76v2-48w6-crxr.json +++ b/advisories/github-reviewed/2024/05/GHSA-76v2-48w6-crxr/GHSA-76v2-48w6-crxr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-76v2-48w6-crxr", - "modified": "2024-05-15T19:48:34Z", + "modified": "2024-09-05T18:38:00Z", "published": "2024-05-15T18:30:35Z", "aliases": [ "CVE-2024-28087" @@ -44,6 +44,10 @@ "type": "WEB", "url": "https://github.com/bonitasoft/bonita-engine/commit/1b3ac00f0178bfcfe8f01811a249b1893f0b1da1" }, + { + "type": "WEB", + "url": "https://documentation.bonitasoft.com/bonita/2024.1/release-notes#_fixes_in_bonita_2024_1_u0_2024_04_11" + }, { "type": "WEB", "url": "https://documentation.bonitasoft.com/bonita/latest/release-notes#_fixes_in_bonita_2024_1_2024_04_11" @@ -55,6 +59,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-284", "CWE-639" ], "severity": "MODERATE", diff --git a/advisories/github-reviewed/2024/08/GHSA-5866-49gr-22v4/GHSA-5866-49gr-22v4.json b/advisories/github-reviewed/2024/08/GHSA-5866-49gr-22v4/GHSA-5866-49gr-22v4.json index 9e01ed3c822..592f097dd89 100644 --- a/advisories/github-reviewed/2024/08/GHSA-5866-49gr-22v4/GHSA-5866-49gr-22v4.json +++ b/advisories/github-reviewed/2024/08/GHSA-5866-49gr-22v4/GHSA-5866-49gr-22v4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5866-49gr-22v4", - "modified": "2024-08-02T12:33:16Z", + "modified": "2024-09-05T18:38:47Z", "published": "2024-08-02T12:33:15Z", "aliases": [ "CVE-2024-41946" @@ -11,7 +11,7 @@ "severity": [ { "type": "CVSS_V3", - "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" }, { "type": "CVSS_V4", diff --git a/advisories/github-reviewed/2024/08/GHSA-r55c-59qm-vjw6/GHSA-r55c-59qm-vjw6.json b/advisories/github-reviewed/2024/08/GHSA-r55c-59qm-vjw6/GHSA-r55c-59qm-vjw6.json index ee40e4df973..f01b9b0655d 100644 --- a/advisories/github-reviewed/2024/08/GHSA-r55c-59qm-vjw6/GHSA-r55c-59qm-vjw6.json +++ b/advisories/github-reviewed/2024/08/GHSA-r55c-59qm-vjw6/GHSA-r55c-59qm-vjw6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r55c-59qm-vjw6", - "modified": "2024-08-01T22:05:10Z", + "modified": "2024-09-05T18:38:26Z", "published": "2024-08-01T22:05:10Z", "aliases": [ "CVE-2024-41123" @@ -11,7 +11,7 @@ "severity": [ { "type": "CVSS_V3", - "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" }, { "type": "CVSS_V4", diff --git a/advisories/github-reviewed/2024/09/GHSA-4jcv-vp96-94xr/GHSA-4jcv-vp96-94xr.json b/advisories/github-reviewed/2024/09/GHSA-4jcv-vp96-94xr/GHSA-4jcv-vp96-94xr.json index 9c90b43f31d..677b4737366 100644 --- a/advisories/github-reviewed/2024/09/GHSA-4jcv-vp96-94xr/GHSA-4jcv-vp96-94xr.json +++ b/advisories/github-reviewed/2024/09/GHSA-4jcv-vp96-94xr/GHSA-4jcv-vp96-94xr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4jcv-vp96-94xr", - "modified": "2024-09-05T16:37:56Z", + "modified": "2024-09-05T18:39:00Z", "published": "2024-09-05T16:37:56Z", "aliases": [ "CVE-2024-24759" @@ -44,6 +44,10 @@ "type": "WEB", "url": "https://github.com/mindsdb/mindsdb/security/advisories/GHSA-4jcv-vp96-94xr" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24759" + }, { "type": "WEB", "url": "https://github.com/mindsdb/mindsdb/commit/5f7496481bd3db1d06a2d2e62c0dce960a1fe12b" @@ -61,6 +65,6 @@ "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2024-09-05T16:37:56Z", - "nvd_published_at": null + "nvd_published_at": "2024-09-05T17:15:12Z" } } \ No newline at end of file