From c3a6609eb102f712ddab18d12a0fe2c175c6c93e Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 6 Sep 2024 20:18:03 +0000 Subject: [PATCH] Publish Advisories GHSA-77g3-3j5w-64w4 GHSA-qg47-5px9-32g7 --- .../GHSA-77g3-3j5w-64w4.json | 34 ++++++++++++++++--- .../GHSA-qg47-5px9-32g7.json | 14 +++++++- 2 files changed, 42 insertions(+), 6 deletions(-) diff --git a/advisories/github-reviewed/2021/04/GHSA-77g3-3j5w-64w4/GHSA-77g3-3j5w-64w4.json b/advisories/github-reviewed/2021/04/GHSA-77g3-3j5w-64w4/GHSA-77g3-3j5w-64w4.json index 1589a467268..ce5c5575854 100644 --- a/advisories/github-reviewed/2021/04/GHSA-77g3-3j5w-64w4/GHSA-77g3-3j5w-64w4.json +++ b/advisories/github-reviewed/2021/04/GHSA-77g3-3j5w-64w4/GHSA-77g3-3j5w-64w4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-77g3-3j5w-64w4", - "modified": "2021-08-31T21:10:36Z", + "modified": "2024-09-06T20:16:43Z", "published": "2021-04-07T20:36:46Z", "aliases": [ "CVE-2020-10685" @@ -12,6 +12,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N" } ], "affected": [ @@ -25,7 +29,7 @@ "type": "ECOSYSTEM", "events": [ { - "introduced": "2.7.0" + "introduced": "2.7.0a1" }, { "fixed": "2.7.17" @@ -44,7 +48,7 @@ "type": "ECOSYSTEM", "events": [ { - "introduced": "2.8.0" + "introduced": "2.8.0a1" }, { "fixed": "2.8.11" @@ -63,7 +67,7 @@ "type": "ECOSYSTEM", "events": [ { - "introduced": "2.9.0" + "introduced": "2.9.0a1" }, { "fixed": "2.9.7" @@ -82,14 +86,34 @@ "type": "WEB", "url": "https://github.com/ansible/ansible/pull/68433" }, + { + "type": "WEB", + "url": "https://github.com/ansible/ansible/commit/4e1fe80e681fa466626e9dea53efe6b0253ea1b2" + }, + { + "type": "WEB", + "url": "https://github.com/ansible/ansible/commit/51d2514753544a9d58cd7524e27e696b2c944fb5" + }, + { + "type": "WEB", + "url": "https://github.com/ansible/ansible/commit/e1273b6faf036ed84e4f4edee85b888a4e256aee" + }, { "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-10685" }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-77g3-3j5w-64w4" + }, { "type": "PACKAGE", "url": "https://github.com/ansible/ansible" }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/ansible/PYSEC-2020-1.yaml" + }, { "type": "WEB", "url": "https://security.gentoo.org/glsa/202006-11" @@ -105,7 +129,7 @@ "CWE-459", "CWE-668" ], - "severity": "LOW", + "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2021-04-05T14:11:30Z", "nvd_published_at": "2020-05-11T14:15:00Z" diff --git a/advisories/github-reviewed/2022/05/GHSA-qg47-5px9-32g7/GHSA-qg47-5px9-32g7.json b/advisories/github-reviewed/2022/05/GHSA-qg47-5px9-32g7/GHSA-qg47-5px9-32g7.json index 3fc228965e3..d384abb0530 100644 --- a/advisories/github-reviewed/2022/05/GHSA-qg47-5px9-32g7/GHSA-qg47-5px9-32g7.json +++ b/advisories/github-reviewed/2022/05/GHSA-qg47-5px9-32g7/GHSA-qg47-5px9-32g7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qg47-5px9-32g7", - "modified": "2023-08-07T20:09:00Z", + "modified": "2024-09-06T20:17:25Z", "published": "2022-05-17T19:57:32Z", "aliases": [ "CVE-2014-4657" @@ -12,6 +12,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" } ], "affected": [ @@ -49,10 +53,18 @@ "type": "WEB", "url": "https://github.com/ansible/ansible/commit/998793fd0ab55705d57527a38cee5e83f535974c" }, + { + "type": "PACKAGE", + "url": "https://github.com/ansible/ansible" + }, { "type": "WEB", "url": "https://github.com/ansible/ansible/blob/release1.5.5/CHANGELOG.md" }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/ansible/PYSEC-2020-199.yaml" + }, { "type": "WEB", "url": "https://web.archive.org/web/20210120133852/https://www.securityfocus.com/bid/68232"