From ce24c22d961fcb205a798b2bacbed671b68d7e42 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 22 Nov 2024 20:17:12 +0000 Subject: [PATCH] Publish Advisories GHSA-8w48-m6hx-rjw2 GHSA-cf9m-q836-vf26 GHSA-f836-7jqw-3684 GHSA-hr8g-f6r6-mr22 GHSA-pwgm-jvqv-6v8p GHSA-qqr6-vm23-m488 GHSA-vwxc-3cfr-37jq GHSA-qmhj-m29v-gvmr --- .../GHSA-8w48-m6hx-rjw2.json | 14 ++++- .../GHSA-cf9m-q836-vf26.json | 6 +- .../GHSA-f836-7jqw-3684.json | 55 +++++-------------- .../GHSA-hr8g-f6r6-mr22.json | 6 +- .../GHSA-pwgm-jvqv-6v8p.json | 14 ++--- .../GHSA-qqr6-vm23-m488.json | 54 ++++++++++++++++-- .../GHSA-vwxc-3cfr-37jq.json | 39 ++++++++++--- .../GHSA-qmhj-m29v-gvmr.json | 6 +- 8 files changed, 128 insertions(+), 66 deletions(-) rename advisories/{unreviewed => github-reviewed}/2022/05/GHSA-f836-7jqw-3684/GHSA-f836-7jqw-3684.json (56%) rename advisories/{unreviewed => github-reviewed}/2022/05/GHSA-qqr6-vm23-m488/GHSA-qqr6-vm23-m488.json (56%) rename advisories/{unreviewed => github-reviewed}/2022/05/GHSA-vwxc-3cfr-37jq/GHSA-vwxc-3cfr-37jq.json (62%) diff --git a/advisories/github-reviewed/2022/05/GHSA-8w48-m6hx-rjw2/GHSA-8w48-m6hx-rjw2.json b/advisories/github-reviewed/2022/05/GHSA-8w48-m6hx-rjw2/GHSA-8w48-m6hx-rjw2.json index 80950da2abb..012a1ad55f8 100644 --- a/advisories/github-reviewed/2022/05/GHSA-8w48-m6hx-rjw2/GHSA-8w48-m6hx-rjw2.json +++ b/advisories/github-reviewed/2022/05/GHSA-8w48-m6hx-rjw2/GHSA-8w48-m6hx-rjw2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8w48-m6hx-rjw2", - "modified": "2024-01-15T18:14:23Z", + "modified": "2024-11-22T20:15:48Z", "published": "2022-05-17T05:37:39Z", "aliases": [ "CVE-2011-3587" @@ -68,6 +68,10 @@ "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=742297" }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/products-plonehotfix20110928/PYSEC-2011-26.yaml" + }, { "type": "PACKAGE", "url": "https://github.com/zopefoundation/Zope" @@ -80,6 +84,10 @@ "type": "WEB", "url": "http://plone.org/products/plone-hotfix/releases/20110928" }, + { + "type": "WEB", + "url": "http://plone.org/products/plone-hotfix/releases/20110928/PloneHotfix20110928-1.0.zip" + }, { "type": "WEB", "url": "http://plone.org/products/plone/security/advisories/20110928" @@ -87,6 +95,10 @@ { "type": "WEB", "url": "http://pypi.python.org/pypi/Products.PloneHotfix20110928/1.0" + }, + { + "type": "WEB", + "url": "http://zope2.zope.org/news/security-vulnerability-announcement-cve-2011-3587" } ], "database_specific": { diff --git a/advisories/github-reviewed/2022/05/GHSA-cf9m-q836-vf26/GHSA-cf9m-q836-vf26.json b/advisories/github-reviewed/2022/05/GHSA-cf9m-q836-vf26/GHSA-cf9m-q836-vf26.json index 453f1eb0683..4147ff43fea 100644 --- a/advisories/github-reviewed/2022/05/GHSA-cf9m-q836-vf26/GHSA-cf9m-q836-vf26.json +++ b/advisories/github-reviewed/2022/05/GHSA-cf9m-q836-vf26/GHSA-cf9m-q836-vf26.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cf9m-q836-vf26", - "modified": "2023-08-16T23:22:49Z", + "modified": "2024-11-22T20:14:42Z", "published": "2022-05-17T04:50:15Z", "aliases": [ "CVE-2014-0006" @@ -90,6 +90,10 @@ "type": "WEB", "url": "https://github.com/openstack/swift" }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/swift/PYSEC-2014-116.yaml" + }, { "type": "WEB", "url": "http://rhn.redhat.com/errata/RHSA-2014-0232.html" diff --git a/advisories/unreviewed/2022/05/GHSA-f836-7jqw-3684/GHSA-f836-7jqw-3684.json b/advisories/github-reviewed/2022/05/GHSA-f836-7jqw-3684/GHSA-f836-7jqw-3684.json similarity index 56% rename from advisories/unreviewed/2022/05/GHSA-f836-7jqw-3684/GHSA-f836-7jqw-3684.json rename to advisories/github-reviewed/2022/05/GHSA-f836-7jqw-3684/GHSA-f836-7jqw-3684.json index 2043e1751af..99a84b4dc29 100644 --- a/advisories/unreviewed/2022/05/GHSA-f836-7jqw-3684/GHSA-f836-7jqw-3684.json +++ b/advisories/github-reviewed/2022/05/GHSA-f836-7jqw-3684/GHSA-f836-7jqw-3684.json @@ -1,17 +1,26 @@ { "schema_version": "1.4.0", "id": "GHSA-f836-7jqw-3684", - "modified": "2022-05-01T06:59:15Z", + "modified": "2024-11-22T20:15:58Z", "published": "2022-05-01T06:59:15Z", "aliases": [ "CVE-2006-2458" ], + "summary": "Libextractor multiple heap-based buffer overflows", "details": "Multiple heap-based buffer overflows in Libextractor 0.5.13 and earlier allow remote attackers to execute arbitrary code via (1) the asf_read_header function in the ASF plugin (plugins/asfextractor.c), and (2) the parse_trak_atom function in the QT plugin (plugins/qtextractor.c).", "severity": [ ], "affected": [ - + { + "package": { + "ecosystem": "PyPI", + "name": "extractor" + }, + "versions": [ + "0.5" + ] + } ], "references": [ { @@ -28,32 +37,12 @@ }, { "type": "WEB", - "url": "http://gnunet.org/libextractor" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/20150" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/20160" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/20326" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/20457" + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/extractor/PYSEC-2006-4.yaml" }, { "type": "WEB", "url": "http://securityreason.com/securityalert/916" }, - { - "type": "WEB", - "url": "http://securitytracker.com/id?1016118" - }, { "type": "WEB", "url": "http://www.debian.org/security/2006/dsa-1081" @@ -61,22 +50,6 @@ { "type": "WEB", "url": "http://www.gentoo.org/security/en/glsa/glsa-200605-14.xml" - }, - { - "type": "WEB", - "url": "http://www.novell.com/linux/security/advisories/2006-06-02.html" - }, - { - "type": "WEB", - "url": "http://www.securityfocus.com/archive/1/434288/100/0/threaded" - }, - { - "type": "WEB", - "url": "http://www.securityfocus.com/bid/18021" - }, - { - "type": "WEB", - "url": "http://www.vupen.com/english/advisories/2006/1848" } ], "database_specific": { @@ -84,8 +57,8 @@ ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-11-22T20:15:58Z", "nvd_published_at": "2006-05-18T23:02:00Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2022/05/GHSA-hr8g-f6r6-mr22/GHSA-hr8g-f6r6-mr22.json b/advisories/github-reviewed/2022/05/GHSA-hr8g-f6r6-mr22/GHSA-hr8g-f6r6-mr22.json index 130be9e1384..79cecec1497 100644 --- a/advisories/github-reviewed/2022/05/GHSA-hr8g-f6r6-mr22/GHSA-hr8g-f6r6-mr22.json +++ b/advisories/github-reviewed/2022/05/GHSA-hr8g-f6r6-mr22/GHSA-hr8g-f6r6-mr22.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hr8g-f6r6-mr22", - "modified": "2024-04-02T20:39:05Z", + "modified": "2024-11-22T20:16:10Z", "published": "2022-05-26T00:01:27Z", "aliases": [ "CVE-2022-30595" @@ -44,6 +44,10 @@ "type": "WEB", "url": "https://github.com/python-pillow/Pillow/commit/c846cc881ebe34e3518412c2e3636433d9947280" }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2022-43145.yaml" + }, { "type": "PACKAGE", "url": "https://github.com/python-pillow/Pillow" diff --git a/advisories/github-reviewed/2022/05/GHSA-pwgm-jvqv-6v8p/GHSA-pwgm-jvqv-6v8p.json b/advisories/github-reviewed/2022/05/GHSA-pwgm-jvqv-6v8p/GHSA-pwgm-jvqv-6v8p.json index 66525bf6768..3ec6ba54a1c 100644 --- a/advisories/github-reviewed/2022/05/GHSA-pwgm-jvqv-6v8p/GHSA-pwgm-jvqv-6v8p.json +++ b/advisories/github-reviewed/2022/05/GHSA-pwgm-jvqv-6v8p/GHSA-pwgm-jvqv-6v8p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pwgm-jvqv-6v8p", - "modified": "2024-05-14T17:25:59Z", + "modified": "2024-11-22T20:15:03Z", "published": "2022-05-17T05:37:14Z", "aliases": [ "CVE-2011-4030" @@ -85,6 +85,10 @@ "type": "PACKAGE", "url": "https://github.com/plone/Plone" }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/products-plonehotfix20110928/PYSEC-2011-27.yaml" + }, { "type": "WEB", "url": "http://plone.org/products/plone-hotfix/releases/20110928" @@ -96,14 +100,6 @@ { "type": "WEB", "url": "http://pypi.python.org/pypi/Products.PloneHotfix20110928/1.0" - }, - { - "type": "WEB", - "url": "http://secunia.com/advisories/46323" - }, - { - "type": "WEB", - "url": "http://www.securityfocus.com/bid/50287" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/05/GHSA-qqr6-vm23-m488/GHSA-qqr6-vm23-m488.json b/advisories/github-reviewed/2022/05/GHSA-qqr6-vm23-m488/GHSA-qqr6-vm23-m488.json similarity index 56% rename from advisories/unreviewed/2022/05/GHSA-qqr6-vm23-m488/GHSA-qqr6-vm23-m488.json rename to advisories/github-reviewed/2022/05/GHSA-qqr6-vm23-m488/GHSA-qqr6-vm23-m488.json index 82da11bc8ed..dbf515515e2 100644 --- a/advisories/unreviewed/2022/05/GHSA-qqr6-vm23-m488/GHSA-qqr6-vm23-m488.json +++ b/advisories/github-reviewed/2022/05/GHSA-qqr6-vm23-m488/GHSA-qqr6-vm23-m488.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-qqr6-vm23-m488", - "modified": "2022-05-14T03:02:50Z", + "modified": "2024-11-22T20:15:21Z", "published": "2022-05-14T03:02:50Z", "aliases": [ "CVE-2018-1000516" ], + "summary": "Galaxy cross-site scripting (XSS)", "details": "The Galaxy Project Galaxy version v14.10 contains a CWE-79: Improper Neutralization of Input During Web Page Generation vulnerability in Many templates used in the Galaxy server did not properly sanitize user's input, which would allow for cross-site scripting (XSS) attacks. In this form of attack, a malicious person can create a URL which, when opened by a Galaxy user or administrator, would allow the malicious user to execute arbitrary Javascript. that can result in Arbitrary JavaScript code execution. This attack appear to be exploitable via The victim must interact with component on page witch contains injected JavaScript code.. This vulnerability appears to have been fixed in v14.10.1, v15.01.", "severity": [ { @@ -14,7 +15,44 @@ } ], "affected": [ - + { + "package": { + "ecosystem": "PyPI", + "name": "galaxy-app" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "14.10.1" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "PyPI", + "name": "galaxy-app" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "15.0" + }, + { + "fixed": "15.01" + } + ] + } + ] + } ], "references": [ { @@ -24,6 +62,14 @@ { "type": "WEB", "url": "https://galaxyproject.org/archive/dev-news-briefs/2015-01-13/#security" + }, + { + "type": "PACKAGE", + "url": "https://github.com/galaxyproject/galaxy" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/galaxy-app/PYSEC-2018-149.yaml" } ], "database_specific": { @@ -31,8 +77,8 @@ "CWE-79" ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-11-22T20:15:21Z", "nvd_published_at": "2018-06-26T16:29:00Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-vwxc-3cfr-37jq/GHSA-vwxc-3cfr-37jq.json b/advisories/github-reviewed/2022/05/GHSA-vwxc-3cfr-37jq/GHSA-vwxc-3cfr-37jq.json similarity index 62% rename from advisories/unreviewed/2022/05/GHSA-vwxc-3cfr-37jq/GHSA-vwxc-3cfr-37jq.json rename to advisories/github-reviewed/2022/05/GHSA-vwxc-3cfr-37jq/GHSA-vwxc-3cfr-37jq.json index 0ca2449c9e8..dafe5c133f1 100644 --- a/advisories/unreviewed/2022/05/GHSA-vwxc-3cfr-37jq/GHSA-vwxc-3cfr-37jq.json +++ b/advisories/github-reviewed/2022/05/GHSA-vwxc-3cfr-37jq/GHSA-vwxc-3cfr-37jq.json @@ -1,23 +1,50 @@ { "schema_version": "1.4.0", "id": "GHSA-vwxc-3cfr-37jq", - "modified": "2022-05-04T00:27:48Z", + "modified": "2024-11-22T20:16:20Z", "published": "2022-05-04T00:27:48Z", "aliases": [ "CVE-2012-0054" ], + "summary": "GoLismero symlink attack", "details": "libs/updater.py in GoLismero 0.6.3, and other versions before Git revision 2b3bb43d6867, as used in backtrack and possibly other products, allows local users to overwrite arbitrary files via a symlink attack on GoLismero-controlled files, as demonstrated using Admin/changes.dat.", "severity": [ ], "affected": [ - + { + "package": { + "ecosystem": "PyPI", + "name": "golismero" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "0.6.3" + } + ] + } + ] + } ], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2012-0054" }, + { + "type": "PACKAGE", + "url": "https://github.com/golismero/golismero" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/golismero/PYSEC-2012-31.yaml" + }, { "type": "WEB", "url": "http://code.google.com/p/golismero/source/detail?r=2b3bb43d68676efd687361f7de29380189031ab8" @@ -29,10 +56,6 @@ { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2012/01/17/7" - }, - { - "type": "WEB", - "url": "http://www.osvdb.org/78472" } ], "database_specific": { @@ -40,8 +63,8 @@ "CWE-59" ], "severity": "LOW", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-11-22T20:16:20Z", "nvd_published_at": "2012-03-19T19:55:00Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2022/08/GHSA-qmhj-m29v-gvmr/GHSA-qmhj-m29v-gvmr.json b/advisories/github-reviewed/2022/08/GHSA-qmhj-m29v-gvmr/GHSA-qmhj-m29v-gvmr.json index 7490712a389..41c7df8bf6f 100644 --- a/advisories/github-reviewed/2022/08/GHSA-qmhj-m29v-gvmr/GHSA-qmhj-m29v-gvmr.json +++ b/advisories/github-reviewed/2022/08/GHSA-qmhj-m29v-gvmr/GHSA-qmhj-m29v-gvmr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qmhj-m29v-gvmr", - "modified": "2022-08-18T14:18:37Z", + "modified": "2024-11-22T20:16:31Z", "published": "2022-08-18T14:18:37Z", "aliases": [ "CVE-2022-36024" @@ -54,6 +54,10 @@ { "type": "PACKAGE", "url": "https://github.com/Pycord-Development/pycord" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/py-cord/PYSEC-2022-43146.yaml" } ], "database_specific": {