diff --git a/advisories/github-reviewed/2021/06/GHSA-4mg4-wvmx-5332/GHSA-4mg4-wvmx-5332.json b/advisories/github-reviewed/2021/06/GHSA-4mg4-wvmx-5332/GHSA-4mg4-wvmx-5332.json index 3e20cdc12d8..c1390266d6a 100644 --- a/advisories/github-reviewed/2021/06/GHSA-4mg4-wvmx-5332/GHSA-4mg4-wvmx-5332.json +++ b/advisories/github-reviewed/2021/06/GHSA-4mg4-wvmx-5332/GHSA-4mg4-wvmx-5332.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4mg4-wvmx-5332", - "modified": "2021-05-27T21:39:48Z", + "modified": "2024-10-18T21:49:19Z", "published": "2021-06-15T16:11:47Z", "aliases": [ "CVE-2021-33510" @@ -12,6 +12,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N" } ], "affected": [ @@ -40,6 +44,18 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-33510" }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-4mg4-wvmx-5332" + }, + { + "type": "PACKAGE", + "url": "https://github.com/plone/Plone" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/plone/PYSEC-2021-82.yaml" + }, { "type": "WEB", "url": "https://plone.org/security/hotfix/20210518/server-side-request-forgery-via-event-ical-url" diff --git a/advisories/github-reviewed/2021/06/GHSA-gc9g-67cq-p7v4/GHSA-gc9g-67cq-p7v4.json b/advisories/github-reviewed/2021/06/GHSA-gc9g-67cq-p7v4/GHSA-gc9g-67cq-p7v4.json index d72ec5b7ef5..65a26631f4d 100644 --- a/advisories/github-reviewed/2021/06/GHSA-gc9g-67cq-p7v4/GHSA-gc9g-67cq-p7v4.json +++ b/advisories/github-reviewed/2021/06/GHSA-gc9g-67cq-p7v4/GHSA-gc9g-67cq-p7v4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gc9g-67cq-p7v4", - "modified": "2021-05-27T21:47:01Z", + "modified": "2024-10-18T21:48:44Z", "published": "2021-06-15T16:12:04Z", "aliases": [ "CVE-2021-33511" @@ -12,6 +12,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N" } ], "affected": [ @@ -40,6 +44,18 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-33511" }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-gc9g-67cq-p7v4" + }, + { + "type": "PACKAGE", + "url": "https://github.com/plone/Plone" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/plone/PYSEC-2021-83.yaml" + }, { "type": "WEB", "url": "https://plone.org/security/hotfix/20210518/server-side-request-forgery-via-lxml-parser" diff --git a/advisories/github-reviewed/2021/06/GHSA-hm2p-fhwx-9285/GHSA-hm2p-fhwx-9285.json b/advisories/github-reviewed/2021/06/GHSA-hm2p-fhwx-9285/GHSA-hm2p-fhwx-9285.json index e5172685a7c..7062d760c06 100644 --- a/advisories/github-reviewed/2021/06/GHSA-hm2p-fhwx-9285/GHSA-hm2p-fhwx-9285.json +++ b/advisories/github-reviewed/2021/06/GHSA-hm2p-fhwx-9285/GHSA-hm2p-fhwx-9285.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hm2p-fhwx-9285", - "modified": "2021-05-27T21:32:19Z", + "modified": "2024-10-18T21:49:59Z", "published": "2021-06-15T16:11:38Z", "aliases": [ "CVE-2021-33509" @@ -12,6 +12,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H" } ], "affected": [ @@ -40,6 +44,18 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-33509" }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-hm2p-fhwx-9285" + }, + { + "type": "PACKAGE", + "url": "https://github.com/plone/Plone" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/plone/PYSEC-2021-81.yaml" + }, { "type": "WEB", "url": "https://plone.org/security/hotfix/20210518/writing-arbitrary-files-via-docutils-and-python-script" diff --git a/advisories/github-reviewed/2024/10/GHSA-rr8j-7w34-xp5j/GHSA-rr8j-7w34-xp5j.json b/advisories/github-reviewed/2024/10/GHSA-rr8j-7w34-xp5j/GHSA-rr8j-7w34-xp5j.json index b496084d591..e8981f0ea0c 100644 --- a/advisories/github-reviewed/2024/10/GHSA-rr8j-7w34-xp5j/GHSA-rr8j-7w34-xp5j.json +++ b/advisories/github-reviewed/2024/10/GHSA-rr8j-7w34-xp5j/GHSA-rr8j-7w34-xp5j.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-rr8j-7w34-xp5j", - "modified": "2024-10-11T16:52:47Z", + "modified": "2024-10-18T21:48:29Z", "published": "2024-10-10T21:30:43Z", "aliases": [ "CVE-2024-9180" ], "summary": "Vault Community Edition privilege escalation vulnerability", - "details": "A privileged Vault operator with write permissions to the root namespace’s identity endpoint could escalate their privileges to Vault’s root policy. Fixed in Vault Community Edition 1.18.0 and Vault Enterprise 1.18.0, 1.17.7, 1.16.11, and 1.15.16.", + "details": "A privileged Vault operator with write permissions to the root namespace’s identity endpoint could escalate their privileges to Vault’s root policy. Fixed in Vault Community Edition 1.18.0 and Vault Enterprise 1.18.0, 1.17.7, 1.16.11, and 1.15.16", "severity": [ { "type": "CVSS_V3",