From bc0fe9fad12d3bb5164a90a7ac4bd64bc1e3a25b Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 16 Oct 2024 21:38:28 +0000 Subject: [PATCH] Publish GHSA-7fqm-jm52-f9vc --- .../GHSA-7fqm-jm52-f9vc/GHSA-7fqm-jm52-f9vc.json | 15 +++++++++++++-- 1 file changed, 13 insertions(+), 2 deletions(-) diff --git a/advisories/github-reviewed/2022/09/GHSA-7fqm-jm52-f9vc/GHSA-7fqm-jm52-f9vc.json b/advisories/github-reviewed/2022/09/GHSA-7fqm-jm52-f9vc/GHSA-7fqm-jm52-f9vc.json index a61f3ca8ada..b3e6eeaecfe 100644 --- a/advisories/github-reviewed/2022/09/GHSA-7fqm-jm52-f9vc/GHSA-7fqm-jm52-f9vc.json +++ b/advisories/github-reviewed/2022/09/GHSA-7fqm-jm52-f9vc/GHSA-7fqm-jm52-f9vc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7fqm-jm52-f9vc", - "modified": "2022-09-30T05:37:28Z", + "modified": "2024-10-16T21:36:40Z", "published": "2022-09-29T00:00:19Z", "aliases": [ "CVE-2022-3292" @@ -9,7 +9,14 @@ "summary": "rdiffweb vulnerable to Use of Cache Containing Sensitive Information", "details": "rdiffweb prior to version 2.4.9 is vulnerable to Use of Cache Containing Sensitive Information. Due to improper cache control, an attacker can view sensitive information even if they are not logged into an account. Version 2.4.9 contains a patch for this issue.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N" + } ], "affected": [ { @@ -45,6 +52,10 @@ "type": "PACKAGE", "url": "https://github.com/ikus060/rdiffweb" }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/rdiffweb/PYSEC-2022-296.yaml" + }, { "type": "WEB", "url": "https://huntr.dev/bounties/e9309018-e94f-4e15-b7d1-5d38b6021c5d"