diff --git a/advisories/github-reviewed/2024/01/GHSA-3p77-wg4c-qm24/GHSA-3p77-wg4c-qm24.json b/advisories/github-reviewed/2024/01/GHSA-3p77-wg4c-qm24/GHSA-3p77-wg4c-qm24.json index 86c0459b38f..a5412619e56 100644 --- a/advisories/github-reviewed/2024/01/GHSA-3p77-wg4c-qm24/GHSA-3p77-wg4c-qm24.json +++ b/advisories/github-reviewed/2024/01/GHSA-3p77-wg4c-qm24/GHSA-3p77-wg4c-qm24.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-3p77-wg4c-qm24", - "modified": "2024-01-26T20:28:30Z", + "modified": "2025-05-30T16:31:28Z", "published": "2024-01-19T21:30:36Z", "aliases": [ "CVE-2024-23689" ], "summary": "Exposure of sensitive information in ClickHouse", - "details": "Exposure of sensitive information in exceptions in ClickHouse's clickhouse-r2dbc, com.clickhouse:clickhouse-jdbc, and com.clickhouse:clickhouse-client versions less than 0.4.6 allows unauthorized users to gain access to client certificate passwords via client exception logs. This occurs when 'sslkey' is specified and an exception, such as a ClickHouseException or SQLException, is thrown during database operations; the certificate password is then included in the logged exception message.\n\n", + "details": "Exposure of sensitive information in exceptions in ClickHouse's clickhouse-r2dbc, com.clickhouse:clickhouse-jdbc, and com.clickhouse:clickhouse-client versions less than 0.4.6 allows unauthorized users to gain access to client certificate passwords via client exception logs. This occurs when 'sslkey' is specified and an exception, such as a ClickHouseException or SQLException, is thrown during database operations; the certificate password is then included in the logged exception message.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/github-reviewed/2024/01/GHSA-4hrp-m3f2-643j/GHSA-4hrp-m3f2-643j.json b/advisories/github-reviewed/2024/01/GHSA-4hrp-m3f2-643j/GHSA-4hrp-m3f2-643j.json index 772426a7095..293dfea6911 100644 --- a/advisories/github-reviewed/2024/01/GHSA-4hrp-m3f2-643j/GHSA-4hrp-m3f2-643j.json +++ b/advisories/github-reviewed/2024/01/GHSA-4hrp-m3f2-643j/GHSA-4hrp-m3f2-643j.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-4hrp-m3f2-643j", - "modified": "2024-01-29T22:30:31Z", + "modified": "2025-05-30T16:30:44Z", "published": "2024-01-19T21:30:36Z", "aliases": [ "CVE-2024-23679" ], "summary": "Session fixation in Enonic XP", - "details": "Enonic XP versions less than 7.7.4 are vulnerable to a session fixation issue. An remote and unauthenticated attacker can use prior sessions due to the lack of invalidating session attributes.\n\n", + "details": "Enonic XP versions less than 7.7.4 are vulnerable to a session fixation issue. An remote and unauthenticated attacker can use prior sessions due to the lack of invalidating session attributes.", "severity": [ { "type": "CVSS_V3",