From c7205ebdd0c53422ad4df37f9dbdefad097c75aa Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 14 Mar 2024 21:42:49 +0000 Subject: [PATCH] Publish Advisories GHSA-242p-4v39-2v8g GHSA-cxjh-pqwp-8mfp --- .../GHSA-242p-4v39-2v8g.json | 6 +++++- .../GHSA-cxjh-pqwp-8mfp.json | 18 +++++++++++++++--- 2 files changed, 20 insertions(+), 4 deletions(-) diff --git a/advisories/github-reviewed/2024/03/GHSA-242p-4v39-2v8g/GHSA-242p-4v39-2v8g.json b/advisories/github-reviewed/2024/03/GHSA-242p-4v39-2v8g/GHSA-242p-4v39-2v8g.json index df1a85038a7..ff00d18e807 100644 --- a/advisories/github-reviewed/2024/03/GHSA-242p-4v39-2v8g/GHSA-242p-4v39-2v8g.json +++ b/advisories/github-reviewed/2024/03/GHSA-242p-4v39-2v8g/GHSA-242p-4v39-2v8g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-242p-4v39-2v8g", - "modified": "2024-03-12T15:39:47Z", + "modified": "2024-03-14T21:40:41Z", "published": "2024-03-12T15:39:46Z", "aliases": [ "CVE-2024-28199" @@ -242,6 +242,10 @@ { "type": "PACKAGE", "url": "https://github.com/phlex-ruby/phlex" + }, + { + "type": "WEB", + "url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/phlex/CVE-2024-28199.yml" } ], "database_specific": { diff --git a/advisories/github-reviewed/2024/03/GHSA-cxjh-pqwp-8mfp/GHSA-cxjh-pqwp-8mfp.json b/advisories/github-reviewed/2024/03/GHSA-cxjh-pqwp-8mfp/GHSA-cxjh-pqwp-8mfp.json index cb137cf7262..389af557637 100644 --- a/advisories/github-reviewed/2024/03/GHSA-cxjh-pqwp-8mfp/GHSA-cxjh-pqwp-8mfp.json +++ b/advisories/github-reviewed/2024/03/GHSA-cxjh-pqwp-8mfp/GHSA-cxjh-pqwp-8mfp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cxjh-pqwp-8mfp", - "modified": "2024-03-14T17:19:42Z", + "modified": "2024-03-14T21:42:07Z", "published": "2024-03-14T17:19:42Z", "aliases": [ "CVE-2024-28849" @@ -43,10 +43,22 @@ "type": "WEB", "url": "https://github.com/follow-redirects/follow-redirects/security/advisories/GHSA-cxjh-pqwp-8mfp" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-28849" + }, + { + "type": "WEB", + "url": "https://github.com/psf/requests/issues/1885" + }, { "type": "WEB", "url": "https://github.com/follow-redirects/follow-redirects/commit/c4f847f85176991f95ab9c88af63b1294de8649b" }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2390009" + }, { "type": "WEB", "url": "https://fetch.spec.whatwg.org/#authentication-entries" @@ -58,11 +70,11 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-200" ], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2024-03-14T17:19:42Z", - "nvd_published_at": null + "nvd_published_at": "2024-03-14T17:15:52Z" } } \ No newline at end of file