From cba19590aa507386ede23c8f1ceab9875ca4b336 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 9 May 2023 16:23:02 +0000 Subject: [PATCH] Publish Advisories GHSA-4wm2-cwcf-wwvp GHSA-c6mm-2g84-v4m7 --- .../GHSA-4wm2-cwcf-wwvp/GHSA-4wm2-cwcf-wwvp.json | 4 ++++ .../GHSA-c6mm-2g84-v4m7/GHSA-c6mm-2g84-v4m7.json | 15 +++++++++++++-- 2 files changed, 17 insertions(+), 2 deletions(-) diff --git a/advisories/github-reviewed/2023/05/GHSA-4wm2-cwcf-wwvp/GHSA-4wm2-cwcf-wwvp.json b/advisories/github-reviewed/2023/05/GHSA-4wm2-cwcf-wwvp/GHSA-4wm2-cwcf-wwvp.json index f7d1abaed2f..a67c378d578 100644 --- a/advisories/github-reviewed/2023/05/GHSA-4wm2-cwcf-wwvp/GHSA-4wm2-cwcf-wwvp.json +++ b/advisories/github-reviewed/2023/05/GHSA-4wm2-cwcf-wwvp/GHSA-4wm2-cwcf-wwvp.json @@ -78,6 +78,10 @@ "type": "WEB", "url": "https://github.com/tauri-apps/tauri/security/advisories/GHSA-4wm2-cwcf-wwvp" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31134" + }, { "type": "WEB", "url": "https://github.com/tauri-apps/tauri/commit/9c0593c33af52cd9e00ec784d15f63efebdf039c" diff --git a/advisories/github-reviewed/2023/05/GHSA-c6mm-2g84-v4m7/GHSA-c6mm-2g84-v4m7.json b/advisories/github-reviewed/2023/05/GHSA-c6mm-2g84-v4m7/GHSA-c6mm-2g84-v4m7.json index f7196f0ce80..8242e8b1414 100644 --- a/advisories/github-reviewed/2023/05/GHSA-c6mm-2g84-v4m7/GHSA-c6mm-2g84-v4m7.json +++ b/advisories/github-reviewed/2023/05/GHSA-c6mm-2g84-v4m7/GHSA-c6mm-2g84-v4m7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c6mm-2g84-v4m7", - "modified": "2023-05-05T23:10:44Z", + "modified": "2023-05-09T16:20:41Z", "published": "2023-05-05T23:10:44Z", "aliases": [ "CVE-2023-31143" @@ -9,7 +9,10 @@ "summary": "Mage-ai missing user authentication", "details": "### Impact\n\nYou may be impacted if you're using Mage with user authentication enabled. The terminal could be accessed by users who are not signed in or do not have editor permissions.\n\n### Patches\n\nThe vulnerability has been resolved in Mage version 0.8.72.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N" + } ], "affected": [ { @@ -37,6 +40,14 @@ "type": "WEB", "url": "https://github.com/mage-ai/mage-ai/security/advisories/GHSA-c6mm-2g84-v4m7" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31143" + }, + { + "type": "WEB", + "url": "https://github.com/mage-ai/mage-ai/commit/f63cd00f6a3be372397d37a4c9a49bfaf50d7650" + }, { "type": "PACKAGE", "url": "https://github.com/mage-ai/mage-ai"