From e14aadb2409c6692fe9fb89834597b49f8e617d8 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 26 Jun 2024 15:21:35 +0000 Subject: [PATCH] Publish Advisories GHSA-22gh-3r9q-xf38 GHSA-37xq-q42p-rv3p --- .../2021/09/GHSA-22gh-3r9q-xf38/GHSA-22gh-3r9q-xf38.json | 2 +- .../2023/08/GHSA-37xq-q42p-rv3p/GHSA-37xq-q42p-rv3p.json | 4 ++-- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/advisories/github-reviewed/2021/09/GHSA-22gh-3r9q-xf38/GHSA-22gh-3r9q-xf38.json b/advisories/github-reviewed/2021/09/GHSA-22gh-3r9q-xf38/GHSA-22gh-3r9q-xf38.json index 2f44fd6a3b4..42ba60bd04a 100644 --- a/advisories/github-reviewed/2021/09/GHSA-22gh-3r9q-xf38/GHSA-22gh-3r9q-xf38.json +++ b/advisories/github-reviewed/2021/09/GHSA-22gh-3r9q-xf38/GHSA-22gh-3r9q-xf38.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-22gh-3r9q-xf38", - "modified": "2021-10-21T14:26:23Z", + "modified": "2024-06-26T15:20:26Z", "published": "2021-09-20T19:53:30Z", "aliases": [ "CVE-2021-39214" diff --git a/advisories/github-reviewed/2023/08/GHSA-37xq-q42p-rv3p/GHSA-37xq-q42p-rv3p.json b/advisories/github-reviewed/2023/08/GHSA-37xq-q42p-rv3p/GHSA-37xq-q42p-rv3p.json index 217e5469c9d..13e3a54bef4 100644 --- a/advisories/github-reviewed/2023/08/GHSA-37xq-q42p-rv3p/GHSA-37xq-q42p-rv3p.json +++ b/advisories/github-reviewed/2023/08/GHSA-37xq-q42p-rv3p/GHSA-37xq-q42p-rv3p.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-37xq-q42p-rv3p", - "modified": "2023-08-24T22:18:39Z", + "modified": "2024-06-26T15:20:09Z", "published": "2023-08-24T22:18:39Z", "aliases": [ ], "summary": "ntpd has Dependency on Vulnerable Third-Party Component", - "details": "### During startup, an attacker that can man-in-the-middle traffic to and from NTS key exchange servers can trigger a very expensive key validation process due to a vulnerability in webpki.\n\n### Impact\nThis vulnerability can lead to excessive cpu usage on startup on clients configured to use NTS\n\n### Patches\nAffected users are recommended to upgrade to version 0.3.7\n\n### References\nSee also https://github.com/rustsec/advisory-db/blob/main/crates/rustls-webpki/RUSTSEC-2023-0053.md\n", + "details": "During startup, an attacker that can man-in-the-middle traffic to and from NTS key exchange servers can trigger a very expensive key validation process due to a vulnerability in webpki.\n\n### Impact\nThis vulnerability can lead to excessive cpu usage on startup on clients configured to use NTS\n\n### Patches\nAffected users are recommended to upgrade to version 0.3.7\n\n### References\nSee also https://github.com/rustsec/advisory-db/blob/main/crates/rustls-webpki/RUSTSEC-2023-0053.md\n", "severity": [ { "type": "CVSS_V3",