diff --git a/advisories/github-reviewed/2022/05/GHSA-4x83-5gw5-q346/GHSA-4x83-5gw5-q346.json b/advisories/github-reviewed/2022/05/GHSA-4x83-5gw5-q346/GHSA-4x83-5gw5-q346.json index 563b3acfbb0..a05cc8f24fd 100644 --- a/advisories/github-reviewed/2022/05/GHSA-4x83-5gw5-q346/GHSA-4x83-5gw5-q346.json +++ b/advisories/github-reviewed/2022/05/GHSA-4x83-5gw5-q346/GHSA-4x83-5gw5-q346.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4x83-5gw5-q346", - "modified": "2024-04-29T11:42:27Z", + "modified": "2024-11-19T18:32:44Z", "published": "2022-05-02T03:17:24Z", "aliases": [ "CVE-2009-0668" @@ -9,7 +9,14 @@ "summary": "Zope Object Database (ZODB) vulnerable to arbitrary Python code execution in ZEO storage servers", "details": "Unspecified vulnerability in Zope Object Database (ZODB) before 3.8.2, when certain Zope Enterprise Objects (ZEO) database sharing is enabled, allows remote attackers to execute arbitrary Python code via vectors involving the ZEO network protocol.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N" + } ], "affected": [ { @@ -41,6 +48,10 @@ "type": "WEB", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/52377" }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/zodb3/PYSEC-2009-8.yaml" + }, { "type": "PACKAGE", "url": "https://github.com/zopefoundation/ZODB3" @@ -70,7 +81,7 @@ "cwe_ids": [ "CWE-94" ], - "severity": "MODERATE", + "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2024-04-29T11:42:27Z", "nvd_published_at": "2009-08-07T19:30:00Z" diff --git a/advisories/github-reviewed/2022/05/GHSA-5432-c996-hvhj/GHSA-5432-c996-hvhj.json b/advisories/github-reviewed/2022/05/GHSA-5432-c996-hvhj/GHSA-5432-c996-hvhj.json index 7e04f2fa78a..5602182a6f7 100644 --- a/advisories/github-reviewed/2022/05/GHSA-5432-c996-hvhj/GHSA-5432-c996-hvhj.json +++ b/advisories/github-reviewed/2022/05/GHSA-5432-c996-hvhj/GHSA-5432-c996-hvhj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5432-c996-hvhj", - "modified": "2024-04-01T19:46:18Z", + "modified": "2024-11-19T18:33:25Z", "published": "2022-05-02T03:17:24Z", "aliases": [ "CVE-2009-0669" @@ -9,7 +9,14 @@ "summary": "Zope Object Database (ZODB) Authentication bypass in ZEO storage servers", "details": "Zope Object Database (ZODB) before 3.8.2, when certain Zope Enterprise Objects (ZEO) database sharing is enabled, allows remote attackers to bypass authentication via vectors involving the ZEO network protocol.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:L/SI:L/SA:N" + } ], "affected": [ { @@ -41,6 +48,10 @@ "type": "WEB", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/52379" }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/zodb3/PYSEC-2009-9.yaml" + }, { "type": "PACKAGE", "url": "https://github.com/zopefoundation/ZODB3" @@ -49,29 +60,9 @@ "type": "WEB", "url": "http://mail.zope.org/pipermail/zope-announce/2009-August/002220.html" }, - { - "type": "WEB", - "url": "http://osvdb.org/56826" - }, { "type": "WEB", "url": "http://pypi.python.org/pypi/ZODB3/3.8.2#whats-new-in-zodb-3-8-2" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/36204" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/36205" - }, - { - "type": "WEB", - "url": "http://www.securityfocus.com/bid/35987" - }, - { - "type": "WEB", - "url": "http://www.vupen.com/english/advisories/2009/2217" } ], "database_specific": {