From b6c2da6fe94c79f3520429c54fde60113d7f6cc8 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 13 Nov 2024 23:25:45 +0000 Subject: [PATCH] Publish Advisories GHSA-4xqv-47rm-37mm GHSA-8xq9-g7ch-35hg GHSA-p8pc-3f7w-jr5q GHSA-pmvv-57rg-5g86 GHSA-w455-mfq9-hf74 GHSA-cxwf-qc32-375f --- .../GHSA-4xqv-47rm-37mm.json | 25 ++++++++++++++++++- .../GHSA-8xq9-g7ch-35hg.json | 3 ++- .../GHSA-p8pc-3f7w-jr5q.json | 6 ++++- .../GHSA-pmvv-57rg-5g86.json | 6 ++++- .../GHSA-w455-mfq9-hf74.json | 6 ++++- .../GHSA-cxwf-qc32-375f.json | 6 ++++- 6 files changed, 46 insertions(+), 6 deletions(-) diff --git a/advisories/github-reviewed/2024/10/GHSA-4xqv-47rm-37mm/GHSA-4xqv-47rm-37mm.json b/advisories/github-reviewed/2024/10/GHSA-4xqv-47rm-37mm/GHSA-4xqv-47rm-37mm.json index 01b8a8d262a..53ff3b672d0 100644 --- a/advisories/github-reviewed/2024/10/GHSA-4xqv-47rm-37mm/GHSA-4xqv-47rm-37mm.json +++ b/advisories/github-reviewed/2024/10/GHSA-4xqv-47rm-37mm/GHSA-4xqv-47rm-37mm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4xqv-47rm-37mm", - "modified": "2024-10-31T13:53:04Z", + "modified": "2024-11-13T23:24:16Z", "published": "2024-10-02T19:29:35Z", "aliases": [ "CVE-2024-47529" @@ -56,6 +56,25 @@ ] } ] + }, + { + "package": { + "ecosystem": "PyPI", + "name": "openc3" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "5.19.0" + } + ] + } + ] } ], "references": [ @@ -75,6 +94,10 @@ "type": "PACKAGE", "url": "https://github.com/OpenC3/cosmos" }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/openc3/PYSEC-2024-121.yaml" + }, { "type": "ADVISORY", "url": "https://securitylab.github.com/advisories/GHSL-2024-127_GHSL-2024-129_OpenC3_COSMOS" diff --git a/advisories/github-reviewed/2024/10/GHSA-8xq9-g7ch-35hg/GHSA-8xq9-g7ch-35hg.json b/advisories/github-reviewed/2024/10/GHSA-8xq9-g7ch-35hg/GHSA-8xq9-g7ch-35hg.json index 7e38e69f717..a03a7bd8ba6 100644 --- a/advisories/github-reviewed/2024/10/GHSA-8xq9-g7ch-35hg/GHSA-8xq9-g7ch-35hg.json +++ b/advisories/github-reviewed/2024/10/GHSA-8xq9-g7ch-35hg/GHSA-8xq9-g7ch-35hg.json @@ -90,7 +90,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-285" + "CWE-285", + "CWE-863" ], "severity": "HIGH", "github_reviewed": true, diff --git a/advisories/github-reviewed/2024/10/GHSA-p8pc-3f7w-jr5q/GHSA-p8pc-3f7w-jr5q.json b/advisories/github-reviewed/2024/10/GHSA-p8pc-3f7w-jr5q/GHSA-p8pc-3f7w-jr5q.json index 5247a0b7991..4bc52e1a4ea 100644 --- a/advisories/github-reviewed/2024/10/GHSA-p8pc-3f7w-jr5q/GHSA-p8pc-3f7w-jr5q.json +++ b/advisories/github-reviewed/2024/10/GHSA-p8pc-3f7w-jr5q/GHSA-p8pc-3f7w-jr5q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p8pc-3f7w-jr5q", - "modified": "2024-10-28T14:44:05Z", + "modified": "2024-11-13T23:24:36Z", "published": "2024-10-26T21:30:46Z", "aliases": [ "CVE-2020-26304" @@ -9,6 +9,10 @@ "summary": "Foundation Regular Expression Denial of Service vulnerability", "details": "Foundation is a front-end framework. Versions 6.3.3 and prior contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, it is unknown if any fixes are available.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green" diff --git a/advisories/github-reviewed/2024/10/GHSA-pmvv-57rg-5g86/GHSA-pmvv-57rg-5g86.json b/advisories/github-reviewed/2024/10/GHSA-pmvv-57rg-5g86/GHSA-pmvv-57rg-5g86.json index 9a602a39fc5..d52fe2bedff 100644 --- a/advisories/github-reviewed/2024/10/GHSA-pmvv-57rg-5g86/GHSA-pmvv-57rg-5g86.json +++ b/advisories/github-reviewed/2024/10/GHSA-pmvv-57rg-5g86/GHSA-pmvv-57rg-5g86.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pmvv-57rg-5g86", - "modified": "2024-10-28T14:44:58Z", + "modified": "2024-11-13T23:24:33Z", "published": "2024-10-26T21:30:46Z", "aliases": [ "CVE-2020-26305" @@ -9,6 +9,10 @@ "summary": "CommonRegexJS Regular Expression Denial of Service vulnerability", "details": "CommonRegexJS is a CommonRegex port for JavaScript. All available versions contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, no known patches are available.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green" diff --git a/advisories/github-reviewed/2024/10/GHSA-w455-mfq9-hf74/GHSA-w455-mfq9-hf74.json b/advisories/github-reviewed/2024/10/GHSA-w455-mfq9-hf74/GHSA-w455-mfq9-hf74.json index 2bf60afde4f..fbfb869913a 100644 --- a/advisories/github-reviewed/2024/10/GHSA-w455-mfq9-hf74/GHSA-w455-mfq9-hf74.json +++ b/advisories/github-reviewed/2024/10/GHSA-w455-mfq9-hf74/GHSA-w455-mfq9-hf74.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w455-mfq9-hf74", - "modified": "2024-10-28T14:40:03Z", + "modified": "2024-11-13T23:24:39Z", "published": "2024-10-26T21:30:46Z", "aliases": [ "CVE-2020-26303" @@ -9,6 +9,10 @@ "summary": "insane vulnerable to Regular Expression Denial of Service", "details": "insane is a whitelist-oriented HTML sanitizer. Versions 2.6.2 and prior contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, no known patches are available.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green" diff --git a/advisories/github-reviewed/2024/11/GHSA-cxwf-qc32-375f/GHSA-cxwf-qc32-375f.json b/advisories/github-reviewed/2024/11/GHSA-cxwf-qc32-375f/GHSA-cxwf-qc32-375f.json index e7bbcc41e84..32d36d58e00 100644 --- a/advisories/github-reviewed/2024/11/GHSA-cxwf-qc32-375f/GHSA-cxwf-qc32-375f.json +++ b/advisories/github-reviewed/2024/11/GHSA-cxwf-qc32-375f/GHSA-cxwf-qc32-375f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cxwf-qc32-375f", - "modified": "2024-11-13T18:57:16Z", + "modified": "2024-11-13T23:24:27Z", "published": "2024-11-12T19:52:22Z", "aliases": [ "CVE-2024-43415" @@ -75,6 +75,10 @@ "type": "PACKAGE", "url": "https://github.com/decidim-ice/decidim-module-decidim_awesome" }, + { + "type": "WEB", + "url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/decidim-decidim_awesome/CVE-2024-43415.yml" + }, { "type": "WEB", "url": "https://pentest.ait.ac.at/security-advisory/decidim-awesome-sql-injection-in-adminaccountability"