From ba16fa25f3b34b73a8a929af1e48eb9dfe53194a Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 4 May 2023 19:49:44 +0000 Subject: [PATCH] Publish Advisories GHSA-q58g-455p-8vw9 GHSA-cfjv-5498-mph5 GHSA-wh98-p28r-vrc9 GHSA-7x6q-3v3m-cwjg GHSA-88qf-5f3v-pm6m --- .../12/GHSA-q58g-455p-8vw9/GHSA-q58g-455p-8vw9.json | 4 ++++ .../09/GHSA-cfjv-5498-mph5/GHSA-cfjv-5498-mph5.json | 10 +++++++++- .../02/GHSA-wh98-p28r-vrc9/GHSA-wh98-p28r-vrc9.json | 8 ++++++++ .../04/GHSA-7x6q-3v3m-cwjg/GHSA-7x6q-3v3m-cwjg.json | 3 ++- .../04/GHSA-88qf-5f3v-pm6m/GHSA-88qf-5f3v-pm6m.json | 9 ++++++--- 5 files changed, 29 insertions(+), 5 deletions(-) diff --git a/advisories/github-reviewed/2019/12/GHSA-q58g-455p-8vw9/GHSA-q58g-455p-8vw9.json b/advisories/github-reviewed/2019/12/GHSA-q58g-455p-8vw9/GHSA-q58g-455p-8vw9.json index de36ba580e2..461fc5bae63 100644 --- a/advisories/github-reviewed/2019/12/GHSA-q58g-455p-8vw9/GHSA-q58g-455p-8vw9.json +++ b/advisories/github-reviewed/2019/12/GHSA-q58g-455p-8vw9/GHSA-q58g-455p-8vw9.json @@ -52,6 +52,10 @@ "type": "PACKAGE", "url": "https://github.com/excon/excon" }, + { + "type": "WEB", + "url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/excon/CVE-2019-16779.yml" + }, { "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2020/01/msg00015.html" diff --git a/advisories/github-reviewed/2020/09/GHSA-cfjv-5498-mph5/GHSA-cfjv-5498-mph5.json b/advisories/github-reviewed/2020/09/GHSA-cfjv-5498-mph5/GHSA-cfjv-5498-mph5.json index c5425142b08..7792c5e67a1 100644 --- a/advisories/github-reviewed/2020/09/GHSA-cfjv-5498-mph5/GHSA-cfjv-5498-mph5.json +++ b/advisories/github-reviewed/2020/09/GHSA-cfjv-5498-mph5/GHSA-cfjv-5498-mph5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cfjv-5498-mph5", - "modified": "2021-10-04T21:16:44Z", + "modified": "2023-05-04T19:48:00Z", "published": "2020-09-11T15:19:57Z", "aliases": [ "CVE-2020-15169" @@ -77,6 +77,14 @@ "type": "PACKAGE", "url": "https://github.com/rails/rails" }, + { + "type": "WEB", + "url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/actionview/CVE-2020-15169.yml" + }, + { + "type": "WEB", + "url": "https://groups.google.com/g/rubyonrails-security/c/b-C9kSGXYrc" + }, { "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2020/10/msg00015.html" diff --git a/advisories/github-reviewed/2022/02/GHSA-wh98-p28r-vrc9/GHSA-wh98-p28r-vrc9.json b/advisories/github-reviewed/2022/02/GHSA-wh98-p28r-vrc9/GHSA-wh98-p28r-vrc9.json index 6ef352d317d..1254ae8a355 100644 --- a/advisories/github-reviewed/2022/02/GHSA-wh98-p28r-vrc9/GHSA-wh98-p28r-vrc9.json +++ b/advisories/github-reviewed/2022/02/GHSA-wh98-p28r-vrc9/GHSA-wh98-p28r-vrc9.json @@ -125,6 +125,14 @@ "type": "PACKAGE", "url": "https://github.com/rails/rails" }, + { + "type": "WEB", + "url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/actionpack/CVE-2022-23633.yml" + }, + { + "type": "WEB", + "url": "https://groups.google.com/g/ruby-security-ann/c/FkTM-_7zSNA/m/K2RiMJBlBAAJ" + }, { "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2022/09/msg00002.html" diff --git a/advisories/github-reviewed/2023/04/GHSA-7x6q-3v3m-cwjg/GHSA-7x6q-3v3m-cwjg.json b/advisories/github-reviewed/2023/04/GHSA-7x6q-3v3m-cwjg/GHSA-7x6q-3v3m-cwjg.json index 9b3456ed8e1..e5d7051b4be 100644 --- a/advisories/github-reviewed/2023/04/GHSA-7x6q-3v3m-cwjg/GHSA-7x6q-3v3m-cwjg.json +++ b/advisories/github-reviewed/2023/04/GHSA-7x6q-3v3m-cwjg/GHSA-7x6q-3v3m-cwjg.json @@ -59,7 +59,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-283" + "CWE-283", + "CWE-863" ], "severity": "LOW", "github_reviewed": true, diff --git a/advisories/github-reviewed/2023/04/GHSA-88qf-5f3v-pm6m/GHSA-88qf-5f3v-pm6m.json b/advisories/github-reviewed/2023/04/GHSA-88qf-5f3v-pm6m/GHSA-88qf-5f3v-pm6m.json index ec65a635273..7342bb0aa12 100644 --- a/advisories/github-reviewed/2023/04/GHSA-88qf-5f3v-pm6m/GHSA-88qf-5f3v-pm6m.json +++ b/advisories/github-reviewed/2023/04/GHSA-88qf-5f3v-pm6m/GHSA-88qf-5f3v-pm6m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-88qf-5f3v-pm6m", - "modified": "2023-04-24T22:45:54Z", + "modified": "2023-05-04T19:48:35Z", "published": "2023-04-24T18:30:31Z", "aliases": [ "CVE-2023-29566" @@ -9,7 +9,10 @@ "summary": "Remote code execution in dawnsparks-node-tesseract", "details": "dawnsparks-node-tesseract before 0.4.1 was discovered to contain a remote code execution (RCE) vulnerability via the child_process function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ { @@ -56,7 +59,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-77" ], "severity": "CRITICAL", "github_reviewed": true,