From dc0b8d5bdc7942f4818f31e18f4d25c9a0f64752 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 7 Oct 2024 21:08:20 +0000 Subject: [PATCH] Publish Advisories GHSA-4fjv-pmhg-3rfg GHSA-rv8h-p43r-4x5r --- .../GHSA-4fjv-pmhg-3rfg/GHSA-4fjv-pmhg-3rfg.json | 16 ++++++++++++++-- .../GHSA-rv8h-p43r-4x5r/GHSA-rv8h-p43r-4x5r.json | 12 ++++++++++-- 2 files changed, 24 insertions(+), 4 deletions(-) diff --git a/advisories/github-reviewed/2020/12/GHSA-4fjv-pmhg-3rfg/GHSA-4fjv-pmhg-3rfg.json b/advisories/github-reviewed/2020/12/GHSA-4fjv-pmhg-3rfg/GHSA-4fjv-pmhg-3rfg.json index 2e94d55fd92..b20854cd948 100644 --- a/advisories/github-reviewed/2020/12/GHSA-4fjv-pmhg-3rfg/GHSA-4fjv-pmhg-3rfg.json +++ b/advisories/github-reviewed/2020/12/GHSA-4fjv-pmhg-3rfg/GHSA-4fjv-pmhg-3rfg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4fjv-pmhg-3rfg", - "modified": "2021-01-08T21:10:33Z", + "modified": "2024-10-07T21:07:21Z", "published": "2020-12-04T16:47:12Z", "aliases": [ "CVE-2020-26244" @@ -12,6 +12,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N" } ], "affected": [ @@ -48,10 +52,18 @@ "type": "WEB", "url": "https://github.com/OpenIDC/pyoidc/commit/62f8d753fa17c8b1f29f8be639cf0b33afb02498" }, + { + "type": "PACKAGE", + "url": "https://github.com/OpenIDC/pyoidc" + }, { "type": "WEB", "url": "https://github.com/OpenIDC/pyoidc/releases/tag/1.2.1" }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/oic/PYSEC-2020-69.yaml" + }, { "type": "WEB", "url": "https://pypi.org/project/oic" @@ -62,7 +74,7 @@ "CWE-325", "CWE-347" ], - "severity": "MODERATE", + "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2020-12-02T20:06:06Z", "nvd_published_at": null diff --git a/advisories/github-reviewed/2022/05/GHSA-rv8h-p43r-4x5r/GHSA-rv8h-p43r-4x5r.json b/advisories/github-reviewed/2022/05/GHSA-rv8h-p43r-4x5r/GHSA-rv8h-p43r-4x5r.json index c15570b52c9..d17c35afc10 100644 --- a/advisories/github-reviewed/2022/05/GHSA-rv8h-p43r-4x5r/GHSA-rv8h-p43r-4x5r.json +++ b/advisories/github-reviewed/2022/05/GHSA-rv8h-p43r-4x5r/GHSA-rv8h-p43r-4x5r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rv8h-p43r-4x5r", - "modified": "2023-08-29T18:04:35Z", + "modified": "2024-10-07T21:06:35Z", "published": "2022-05-17T03:46:28Z", "aliases": [ "CVE-2013-4347" @@ -12,6 +12,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N" } ], "affected": [ @@ -72,6 +76,10 @@ "type": "PACKAGE", "url": "https://github.com/joestump/python-oauth2" }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/oauth2/PYSEC-2014-86.yaml" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2013/09/12/7" @@ -85,7 +93,7 @@ "cwe_ids": [ "CWE-330" ], - "severity": "LOW", + "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2023-08-29T18:04:35Z", "nvd_published_at": "2014-05-20T14:55:00Z"