Publish Advisories

GHSA-4xqv-47rm-37mm
GHSA-8xq9-g7ch-35hg
GHSA-p8pc-3f7w-jr5q
GHSA-pmvv-57rg-5g86
GHSA-w455-mfq9-hf74
GHSA-cxwf-qc32-375f
This commit is contained in:
advisory-database[bot]
2024-11-13 23:25:45 +00:00
parent dc6fc83199
commit b6c2da6fe9
6 changed files with 46 additions and 6 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4xqv-47rm-37mm",
"modified": "2024-10-31T13:53:04Z",
"modified": "2024-11-13T23:24:16Z",
"published": "2024-10-02T19:29:35Z",
"aliases": [
"CVE-2024-47529"
@@ -56,6 +56,25 @@
]
}
]
},
{
"package": {
"ecosystem": "PyPI",
"name": "openc3"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "5.19.0"
}
]
}
]
}
],
"references": [
@@ -75,6 +94,10 @@
"type": "PACKAGE",
"url": "https://github.com/OpenC3/cosmos"
},
{
"type": "WEB",
"url": "https://github.com/pypa/advisory-database/tree/main/vulns/openc3/PYSEC-2024-121.yaml"
},
{
"type": "ADVISORY",
"url": "https://securitylab.github.com/advisories/GHSL-2024-127_GHSL-2024-129_OpenC3_COSMOS"
@@ -90,7 +90,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-285"
"CWE-285",
"CWE-863"
],
"severity": "HIGH",
"github_reviewed": true,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p8pc-3f7w-jr5q",
"modified": "2024-10-28T14:44:05Z",
"modified": "2024-11-13T23:24:36Z",
"published": "2024-10-26T21:30:46Z",
"aliases": [
"CVE-2020-26304"
@@ -9,6 +9,10 @@
"summary": "Foundation Regular Expression Denial of Service vulnerability",
"details": "Foundation is a front-end framework. Versions 6.3.3 and prior contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, it is unknown if any fixes are available.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pmvv-57rg-5g86",
"modified": "2024-10-28T14:44:58Z",
"modified": "2024-11-13T23:24:33Z",
"published": "2024-10-26T21:30:46Z",
"aliases": [
"CVE-2020-26305"
@@ -9,6 +9,10 @@
"summary": "CommonRegexJS Regular Expression Denial of Service vulnerability",
"details": "CommonRegexJS is a CommonRegex port for JavaScript. All available versions contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, no known patches are available.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w455-mfq9-hf74",
"modified": "2024-10-28T14:40:03Z",
"modified": "2024-11-13T23:24:39Z",
"published": "2024-10-26T21:30:46Z",
"aliases": [
"CVE-2020-26303"
@@ -9,6 +9,10 @@
"summary": "insane vulnerable to Regular Expression Denial of Service",
"details": "insane is a whitelist-oriented HTML sanitizer. Versions 2.6.2 and prior contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, no known patches are available.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cxwf-qc32-375f",
"modified": "2024-11-13T18:57:16Z",
"modified": "2024-11-13T23:24:27Z",
"published": "2024-11-12T19:52:22Z",
"aliases": [
"CVE-2024-43415"
@@ -75,6 +75,10 @@
"type": "PACKAGE",
"url": "https://github.com/decidim-ice/decidim-module-decidim_awesome"
},
{
"type": "WEB",
"url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/decidim-decidim_awesome/CVE-2024-43415.yml"
},
{
"type": "WEB",
"url": "https://pentest.ait.ac.at/security-advisory/decidim-awesome-sql-injection-in-adminaccountability"