From af863215fc0d293243842cc7d42e5f85752b6ae2 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 28 Oct 2024 14:58:36 +0000 Subject: [PATCH] Publish Advisories GHSA-x9j7-x98r-r4w2 GHSA-3phv-83cj-p8p7 GHSA-3phv-83cj-p8p7 --- .../GHSA-x9j7-x98r-r4w2.json | 16 +++- .../GHSA-3phv-83cj-p8p7.json | 73 +++++++++++++++++++ .../GHSA-3phv-83cj-p8p7.json | 42 ----------- 3 files changed, 87 insertions(+), 44 deletions(-) create mode 100644 advisories/github-reviewed/2024/10/GHSA-3phv-83cj-p8p7/GHSA-3phv-83cj-p8p7.json delete mode 100644 advisories/unreviewed/2024/10/GHSA-3phv-83cj-p8p7/GHSA-3phv-83cj-p8p7.json diff --git a/advisories/github-reviewed/2020/09/GHSA-x9j7-x98r-r4w2/GHSA-x9j7-x98r-r4w2.json b/advisories/github-reviewed/2020/09/GHSA-x9j7-x98r-r4w2/GHSA-x9j7-x98r-r4w2.json index 843e4ecc058..dcf0b9277b1 100644 --- a/advisories/github-reviewed/2020/09/GHSA-x9j7-x98r-r4w2/GHSA-x9j7-x98r-r4w2.json +++ b/advisories/github-reviewed/2020/09/GHSA-x9j7-x98r-r4w2/GHSA-x9j7-x98r-r4w2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x9j7-x98r-r4w2", - "modified": "2024-08-27T20:05:35Z", + "modified": "2024-10-28T14:55:40Z", "published": "2020-09-25T18:28:51Z", "aliases": [ "CVE-2020-15210" @@ -356,6 +356,18 @@ "type": "WEB", "url": "https://github.com/tensorflow/tensorflow/commit/f50a14b00560a383865c2273e4a9094add3888d5" }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/tensorflow-cpu/PYSEC-2020-290.yaml" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/tensorflow-gpu/PYSEC-2020-325.yaml" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/tensorflow/PYSEC-2020-133.yaml" + }, { "type": "PACKAGE", "url": "https://github.com/tensorflow/tensorflow" @@ -374,7 +386,7 @@ "CWE-20", "CWE-787" ], - "severity": "MODERATE", + "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2020-09-25T18:15:49Z", "nvd_published_at": "2020-09-25T19:15:00Z" diff --git a/advisories/github-reviewed/2024/10/GHSA-3phv-83cj-p8p7/GHSA-3phv-83cj-p8p7.json b/advisories/github-reviewed/2024/10/GHSA-3phv-83cj-p8p7/GHSA-3phv-83cj-p8p7.json new file mode 100644 index 00000000000..c1109d4500e --- /dev/null +++ b/advisories/github-reviewed/2024/10/GHSA-3phv-83cj-p8p7/GHSA-3phv-83cj-p8p7.json @@ -0,0 +1,73 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3phv-83cj-p8p7", + "modified": "2024-10-28T14:56:39Z", + "published": "2024-10-26T21:30:46Z", + "aliases": [ + "CVE-2020-26309" + ], + "summary": "nope-validator Regular Expression Denial of Service vulnerability", + "details": "Nope is a JavaScript validator. Versions 0.11.3 and prior contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). This vulnerability is fixed in 0.12.1.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green" + } + ], + "affected": [ + { + "package": { + "ecosystem": "npm", + "name": "nope-validator" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.12.1" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-26309" + }, + { + "type": "WEB", + "url": "https://github.com/ftonato/nope-validator/issues/352" + }, + { + "type": "WEB", + "url": "https://github.com/ftonato/nope-validator/commit/4564b7444dcd92769e5c5b80420469c9f18b7a05#diff-9c399c46fa266bcf2be2704fbb369181726959e148e95ab548a32ef9ca9e7d47R1" + }, + { + "type": "WEB", + "url": "https://github.com/ftonato/nope-validator/commit/c8af9f93abe8f4786f8f69d2b0518f8ca3652f44" + }, + { + "type": "PACKAGE", + "url": "https://github.com/ftonato/nope-validator" + }, + { + "type": "ADVISORY", + "url": "https://securitylab.github.com/advisories/GHSL-2020-303-redos-nope-validator" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1333" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-10-28T14:56:39Z", + "nvd_published_at": "2024-10-26T21:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/10/GHSA-3phv-83cj-p8p7/GHSA-3phv-83cj-p8p7.json b/advisories/unreviewed/2024/10/GHSA-3phv-83cj-p8p7/GHSA-3phv-83cj-p8p7.json deleted file mode 100644 index d0bc078cf54..00000000000 --- a/advisories/unreviewed/2024/10/GHSA-3phv-83cj-p8p7/GHSA-3phv-83cj-p8p7.json +++ /dev/null @@ -1,42 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-3phv-83cj-p8p7", - "modified": "2024-10-26T21:30:46Z", - "published": "2024-10-26T21:30:46Z", - "aliases": [ - "CVE-2020-26309" - ], - "details": "Validate.js provides a declarative way of validating javascript objects. Versions 0.11.3 and prior contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, it is unknown if any patches are available.", - "severity": [ - { - "type": "CVSS_V4", - "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Green" - } - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-26309" - }, - { - "type": "WEB", - "url": "https://github.com/ftonato/nope-validator/issues/352" - }, - { - "type": "ADVISORY", - "url": "https://securitylab.github.com/advisories/GHSL-2020-303-redos-nope-validator" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-1333" - ], - "severity": "HIGH", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2024-10-26T21:15:14Z" - } -} \ No newline at end of file