Publish Advisories

GHSA-m7p8-9w66-9frm
GHSA-mq35-wqvf-r23c
This commit is contained in:
advisory-database[bot]
2023-01-23 21:25:24 +00:00
parent 8e75bdf774
commit db185e6b1c
2 changed files with 4 additions and 12 deletions
@@ -1,12 +1,12 @@
{
"schema_version": "1.3.0",
"id": "GHSA-m7p8-9w66-9frm",
"modified": "2021-09-15T18:19:25Z",
"modified": "2023-01-23T21:24:13Z",
"published": "2018-01-06T01:11:34Z",
"aliases": [
"CVE-2017-17718"
],
"summary": "Moderate severity vulnerability that affects net-ldap",
"summary": "net-ldap Improper Certificate Validation vulnerability",
"details": "The Net::LDAP (aka net-ldap) gem before 0.16.0 for Ruby has Missing SSL Certificate Validation.",
"severity": [
{
@@ -48,10 +48,6 @@
"type": "WEB",
"url": "https://github.com/ruby-ldap/ruby-net-ldap/pull/279"
},
{
"type": "ADVISORY",
"url": "https://github.com/advisories/GHSA-m7p8-9w66-9frm"
},
{
"type": "PACKAGE",
"url": "https://github.com/ruby-ldap/ruby-net-ldap"
@@ -1,12 +1,12 @@
{
"schema_version": "1.3.0",
"id": "GHSA-mq35-wqvf-r23c",
"modified": "2022-04-26T18:04:31Z",
"modified": "2023-01-23T21:24:55Z",
"published": "2018-06-05T21:32:06Z",
"aliases": [
"CVE-2018-11627"
],
"summary": "Sinatra has XSS via 400 Bad Request page via params parser exception",
"summary": "Sinatra Cross-site Scripting vulnerability",
"details": "Sinatra before 2.0.2 has XSS via the 400 Bad Request page that occurs upon a params parser exception.",
"severity": [
{
@@ -56,10 +56,6 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2019:0315"
},
{
"type": "ADVISORY",
"url": "https://github.com/advisories/GHSA-mq35-wqvf-r23c"
},
{
"type": "PACKAGE",
"url": "https://github.com/sinatra/sinatra"