Publish Advisories

GHSA-q58g-455p-8vw9
GHSA-cfjv-5498-mph5
GHSA-wh98-p28r-vrc9
GHSA-7x6q-3v3m-cwjg
GHSA-88qf-5f3v-pm6m
This commit is contained in:
advisory-database[bot]
2023-05-04 19:49:44 +00:00
parent 150fb66eb8
commit ba16fa25f3
5 changed files with 29 additions and 5 deletions
@@ -52,6 +52,10 @@
"type": "PACKAGE",
"url": "https://github.com/excon/excon"
},
{
"type": "WEB",
"url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/excon/CVE-2019-16779.yml"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2020/01/msg00015.html"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cfjv-5498-mph5",
"modified": "2021-10-04T21:16:44Z",
"modified": "2023-05-04T19:48:00Z",
"published": "2020-09-11T15:19:57Z",
"aliases": [
"CVE-2020-15169"
@@ -77,6 +77,14 @@
"type": "PACKAGE",
"url": "https://github.com/rails/rails"
},
{
"type": "WEB",
"url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/actionview/CVE-2020-15169.yml"
},
{
"type": "WEB",
"url": "https://groups.google.com/g/rubyonrails-security/c/b-C9kSGXYrc"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2020/10/msg00015.html"
@@ -125,6 +125,14 @@
"type": "PACKAGE",
"url": "https://github.com/rails/rails"
},
{
"type": "WEB",
"url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/actionpack/CVE-2022-23633.yml"
},
{
"type": "WEB",
"url": "https://groups.google.com/g/ruby-security-ann/c/FkTM-_7zSNA/m/K2RiMJBlBAAJ"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2022/09/msg00002.html"
@@ -59,7 +59,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-283"
"CWE-283",
"CWE-863"
],
"severity": "LOW",
"github_reviewed": true,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-88qf-5f3v-pm6m",
"modified": "2023-04-24T22:45:54Z",
"modified": "2023-05-04T19:48:35Z",
"published": "2023-04-24T18:30:31Z",
"aliases": [
"CVE-2023-29566"
@@ -9,7 +9,10 @@
"summary": "Remote code execution in dawnsparks-node-tesseract",
"details": "dawnsparks-node-tesseract before 0.4.1 was discovered to contain a remote code execution (RCE) vulnerability via the child_process function.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [
{
@@ -56,7 +59,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-77"
],
"severity": "CRITICAL",
"github_reviewed": true,