From e5e3551a08be8eb25886f257f6a04e6ce07d6fc5 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 16 May 2023 15:50:06 +0000 Subject: [PATCH] Publish Advisories GHSA-8xww-x3g3-6jcv GHSA-9445-4cr6-336r GHSA-hq7p-j377-6v63 GHSA-j6gc-792m-qgm2 --- .../2023/01/GHSA-8xww-x3g3-6jcv/GHSA-8xww-x3g3-6jcv.json | 6 +++++- .../2023/01/GHSA-9445-4cr6-336r/GHSA-9445-4cr6-336r.json | 6 +++++- .../2023/01/GHSA-hq7p-j377-6v63/GHSA-hq7p-j377-6v63.json | 6 +++++- .../2023/01/GHSA-j6gc-792m-qgm2/GHSA-j6gc-792m-qgm2.json | 6 +++++- 4 files changed, 20 insertions(+), 4 deletions(-) diff --git a/advisories/github-reviewed/2023/01/GHSA-8xww-x3g3-6jcv/GHSA-8xww-x3g3-6jcv.json b/advisories/github-reviewed/2023/01/GHSA-8xww-x3g3-6jcv/GHSA-8xww-x3g3-6jcv.json index 314725aff86..c92e172c6a5 100644 --- a/advisories/github-reviewed/2023/01/GHSA-8xww-x3g3-6jcv/GHSA-8xww-x3g3-6jcv.json +++ b/advisories/github-reviewed/2023/01/GHSA-8xww-x3g3-6jcv/GHSA-8xww-x3g3-6jcv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8xww-x3g3-6jcv", - "modified": "2023-02-10T22:05:47Z", + "modified": "2023-05-16T15:48:14Z", "published": "2023-01-18T18:20:51Z", "aliases": [ "CVE-2023-22795" @@ -60,6 +60,10 @@ "type": "WEB", "url": "https://discuss.rubyonrails.org/t/cve-2023-22795-possible-redos-based-dos-vulnerability-in-action-dispatch/82118" }, + { + "type": "PACKAGE", + "url": "https://github.com/rails/rails" + }, { "type": "WEB", "url": "https://github.com/rails/rails/releases/tag/v7.0.4.1" diff --git a/advisories/github-reviewed/2023/01/GHSA-9445-4cr6-336r/GHSA-9445-4cr6-336r.json b/advisories/github-reviewed/2023/01/GHSA-9445-4cr6-336r/GHSA-9445-4cr6-336r.json index 946393f2f50..f0285205ca3 100644 --- a/advisories/github-reviewed/2023/01/GHSA-9445-4cr6-336r/GHSA-9445-4cr6-336r.json +++ b/advisories/github-reviewed/2023/01/GHSA-9445-4cr6-336r/GHSA-9445-4cr6-336r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9445-4cr6-336r", - "modified": "2023-02-21T20:05:50Z", + "modified": "2023-05-16T15:48:51Z", "published": "2023-01-18T18:21:23Z", "aliases": [ "CVE-2023-22797" @@ -44,6 +44,10 @@ "type": "WEB", "url": "https://discuss.rubyonrails.org/t/cve-2023-22799-possible-redos-based-dos-vulnerability-in-globalid/82127" }, + { + "type": "PACKAGE", + "url": "https://github.com/rails/rails" + }, { "type": "WEB", "url": "https://github.com/rails/rails/releases/tag/v7.0.4.1" diff --git a/advisories/github-reviewed/2023/01/GHSA-hq7p-j377-6v63/GHSA-hq7p-j377-6v63.json b/advisories/github-reviewed/2023/01/GHSA-hq7p-j377-6v63/GHSA-hq7p-j377-6v63.json index 4cb6df129e9..975aff7592e 100644 --- a/advisories/github-reviewed/2023/01/GHSA-hq7p-j377-6v63/GHSA-hq7p-j377-6v63.json +++ b/advisories/github-reviewed/2023/01/GHSA-hq7p-j377-6v63/GHSA-hq7p-j377-6v63.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hq7p-j377-6v63", - "modified": "2023-03-14T16:03:58Z", + "modified": "2023-05-16T15:47:47Z", "published": "2023-01-18T18:20:19Z", "aliases": [ "CVE-2023-22794" @@ -86,6 +86,10 @@ "type": "WEB", "url": "https://discuss.rubyonrails.org/t/cve-2023-22794-sql-injection-vulnerability-via-activerecord-comments/82117" }, + { + "type": "PACKAGE", + "url": "https://github.com/rails/rails" + }, { "type": "WEB", "url": "https://github.com/rails/rails/releases/tag/v7.0.4.1" diff --git a/advisories/github-reviewed/2023/01/GHSA-j6gc-792m-qgm2/GHSA-j6gc-792m-qgm2.json b/advisories/github-reviewed/2023/01/GHSA-j6gc-792m-qgm2/GHSA-j6gc-792m-qgm2.json index dc1756ba3b2..105b62a1177 100644 --- a/advisories/github-reviewed/2023/01/GHSA-j6gc-792m-qgm2/GHSA-j6gc-792m-qgm2.json +++ b/advisories/github-reviewed/2023/01/GHSA-j6gc-792m-qgm2/GHSA-j6gc-792m-qgm2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j6gc-792m-qgm2", - "modified": "2023-02-10T22:06:06Z", + "modified": "2023-05-16T15:49:20Z", "published": "2023-01-18T18:23:20Z", "aliases": [ "CVE-2023-22796" @@ -79,6 +79,10 @@ "type": "WEB", "url": "https://discuss.rubyonrails.org/t/cve-2023-22796-possible-redos-based-dos-vulnerability-in-active-supports-underscore/82116" }, + { + "type": "PACKAGE", + "url": "https://github.com/rails/rails" + }, { "type": "WEB", "url": "https://github.com/rails/rails/releases/tag/v7.0.4.1"