From cbe1224ad18bf128599f993f95cce040f7c4acd0 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 28 Feb 2025 17:22:09 +0000 Subject: [PATCH] Publish GHSA-phg3-gv66-q38x --- .../GHSA-phg3-gv66-q38x.json | 94 ++++++++++++++++++- 1 file changed, 91 insertions(+), 3 deletions(-) diff --git a/advisories/github-reviewed/2025/02/GHSA-phg3-gv66-q38x/GHSA-phg3-gv66-q38x.json b/advisories/github-reviewed/2025/02/GHSA-phg3-gv66-q38x/GHSA-phg3-gv66-q38x.json index 897866aec09..3b2fdf580cc 100644 --- a/advisories/github-reviewed/2025/02/GHSA-phg3-gv66-q38x/GHSA-phg3-gv66-q38x.json +++ b/advisories/github-reviewed/2025/02/GHSA-phg3-gv66-q38x/GHSA-phg3-gv66-q38x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-phg3-gv66-q38x", - "modified": "2025-02-27T18:31:07Z", + "modified": "2025-02-28T17:19:59Z", "published": "2025-02-13T15:31:25Z", "aliases": [ "CVE-2025-1247" @@ -25,7 +25,7 @@ "type": "ECOSYSTEM", "events": [ { - "introduced": "0" + "introduced": "3.16.0.CR1" }, { "fixed": "3.18.2" @@ -44,7 +44,7 @@ "type": "ECOSYSTEM", "events": [ { - "introduced": "0" + "introduced": "3.16.0.CR1" }, { "fixed": "3.18.2" @@ -52,6 +52,82 @@ ] } ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "io.quarkus:quarkus-rest" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.9.0.CR1" + }, + { + "fixed": "3.15.3.1" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "io.quarkus:quarkus-rest-deployment" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "3.9.0.CR1" + }, + { + "fixed": "3.15.3.1" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "io.quarkus:quarkus-rest" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.8.6.1" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "io.quarkus:quarkus-rest-deployment" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.8.6.1" + } + ] + } + ] } ], "references": [ @@ -67,6 +143,14 @@ "type": "WEB", "url": "https://github.com/quarkusio/quarkus/commit/02ff9ed45c3928edf2a0f8b906543606fed7cd53" }, + { + "type": "WEB", + "url": "https://github.com/quarkusio/quarkus/commit/d8df15cec17dc5d085efc372d77cbef1341ae071" + }, + { + "type": "WEB", + "url": "https://github.com/quarkusio/quarkus/commit/f42166ee7041ed09b7183d5dbf3ece2439b16676" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:1884" @@ -86,6 +170,10 @@ { "type": "PACKAGE", "url": "https://github.com/quarkusio/quarkus" + }, + { + "type": "WEB", + "url": "https://quarkus.io/blog/cve-fixes-feb-2025" } ], "database_specific": {