diff --git a/advisories/github-reviewed/2024/05/GHSA-6fg2-hvj9-832f/GHSA-6fg2-hvj9-832f.json b/advisories/github-reviewed/2024/05/GHSA-6fg2-hvj9-832f/GHSA-6fg2-hvj9-832f.json index d71f1e8b412..bb6fd8f3821 100644 --- a/advisories/github-reviewed/2024/05/GHSA-6fg2-hvj9-832f/GHSA-6fg2-hvj9-832f.json +++ b/advisories/github-reviewed/2024/05/GHSA-6fg2-hvj9-832f/GHSA-6fg2-hvj9-832f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6fg2-hvj9-832f", - "modified": "2024-05-03T20:31:38Z", + "modified": "2024-07-03T22:06:25Z", "published": "2024-05-03T18:30:36Z", "aliases": [ "CVE-2024-33398" @@ -9,7 +9,10 @@ "summary": "piraeus-operator allows attacker to impersonate service account", "details": "There is a ClusterRole in piraeus-operator v2.5.0 and earlier which has been granted list secrets permission, which allows an attacker to impersonate the service account bound to this ClusterRole and use its high-risk privileges to list confidential information across the cluster.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } ], "affected": [ { @@ -56,9 +59,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], - "severity": "MODERATE", + "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2024-05-03T20:31:38Z", "nvd_published_at": "2024-05-03T16:15:11Z" diff --git a/advisories/github-reviewed/2024/05/GHSA-hr2r-w6wc-25pv/GHSA-hr2r-w6wc-25pv.json b/advisories/github-reviewed/2024/05/GHSA-hr2r-w6wc-25pv/GHSA-hr2r-w6wc-25pv.json index 38f3d1a9551..621dc23f5f4 100644 --- a/advisories/github-reviewed/2024/05/GHSA-hr2r-w6wc-25pv/GHSA-hr2r-w6wc-25pv.json +++ b/advisories/github-reviewed/2024/05/GHSA-hr2r-w6wc-25pv/GHSA-hr2r-w6wc-25pv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hr2r-w6wc-25pv", - "modified": "2024-05-06T14:24:09Z", + "modified": "2024-07-03T22:06:51Z", "published": "2024-05-04T06:30:31Z", "aliases": [ "CVE-2024-34461" @@ -9,7 +9,10 @@ "summary": "Zenario uses Twig filters insecurely in the Twig Snippet plugin", "details": "Zenario before 9.5.60437 uses Twig filters insecurely in the Twig Snippet plugin, and in the site-wide HEAD and BODY elements, enabling code execution by a designer or an administrator.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ { @@ -54,7 +57,7 @@ "cwe_ids": [ ], - "severity": "MODERATE", + "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2024-05-06T14:24:09Z", "nvd_published_at": "2024-05-04T05:15:06Z" diff --git a/advisories/github-reviewed/2024/05/GHSA-vjc4-3vgx-pq9h/GHSA-vjc4-3vgx-pq9h.json b/advisories/github-reviewed/2024/05/GHSA-vjc4-3vgx-pq9h/GHSA-vjc4-3vgx-pq9h.json index 6b17ad8d671..0474e385aac 100644 --- a/advisories/github-reviewed/2024/05/GHSA-vjc4-3vgx-pq9h/GHSA-vjc4-3vgx-pq9h.json +++ b/advisories/github-reviewed/2024/05/GHSA-vjc4-3vgx-pq9h/GHSA-vjc4-3vgx-pq9h.json @@ -52,7 +52,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], "severity": "MODERATE", "github_reviewed": true,