Publish Advisories

GHSA-5x5q-cqf6-gj8r
GHSA-cq38-jh5f-37mq
GHSA-rrqf-w74j-24ff
This commit is contained in:
advisory-database[bot]
2024-09-04 21:36:13 +00:00
parent e8e5dd1176
commit cccc927bcb
3 changed files with 31 additions and 6 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5x5q-cqf6-gj8r",
"modified": "2024-09-04T17:03:02Z",
"modified": "2024-09-04T21:35:00Z",
"published": "2024-08-29T18:31:36Z",
"aliases": [
"CVE-2024-44930"
@@ -67,7 +67,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-348"
"CWE-348",
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": true,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cq38-jh5f-37mq",
"modified": "2024-09-04T20:18:19Z",
"modified": "2024-09-04T21:34:54Z",
"published": "2024-09-04T20:18:18Z",
"aliases": [
"CVE-2024-45395"
@@ -47,6 +47,10 @@
"type": "WEB",
"url": "https://github.com/sigstore/sigstore-go/security/advisories/GHSA-cq38-jh5f-37mq"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45395"
},
{
"type": "WEB",
"url": "https://github.com/sigstore/sigstore-go/commit/01e70e89e58226286d7977b4dba43b6be472b12c"
@@ -54,6 +58,18 @@
{
"type": "PACKAGE",
"url": "https://github.com/sigstore/sigstore-go"
},
{
"type": "WEB",
"url": "https://github.com/sigstore/sigstore-go/blob/725e508ed4933e6f5b5206e32af4bbe76f587b54/pkg/verify/signature.go#L183-L193"
},
{
"type": "WEB",
"url": "https://github.com/sigstore/sigstore-go/blob/725e508ed4933e6f5b5206e32af4bbe76f587b54/pkg/verify/tlog.go#L74-L178"
},
{
"type": "WEB",
"url": "https://github.com/sigstore/sigstore-go/blob/725e508ed4933e6f5b5206e32af4bbe76f587b54/pkg/verify/tsa.go#L59-L68"
}
],
"database_specific": {
@@ -63,6 +79,6 @@
"severity": "LOW",
"github_reviewed": true,
"github_reviewed_at": "2024-09-04T20:18:18Z",
"nvd_published_at": null
"nvd_published_at": "2024-09-04T21:15:14Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rrqf-w74j-24ff",
"modified": "2024-09-04T20:24:53Z",
"modified": "2024-09-04T21:34:47Z",
"published": "2024-09-04T17:19:14Z",
"aliases": [
"CVE-2024-45399"
@@ -44,6 +44,14 @@
"type": "WEB",
"url": "https://github.com/indico/indico/security/advisories/GHSA-rrqf-w74j-24ff"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45399"
},
{
"type": "WEB",
"url": "https://github.com/indico/flask-multipass/commit/0bdcf656d469e5f675cb56fd644d82fea3a97c2a"
},
{
"type": "WEB",
"url": "https://github.com/indico/indico/commit/7dcb573837b9fd09d95f74d1baeae225b164cc8f"
@@ -65,6 +73,6 @@
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-09-04T17:19:14Z",
"nvd_published_at": null
"nvd_published_at": "2024-09-04T20:15:09Z"
}
}