diff --git a/advisories/github-reviewed/2021/02/GHSA-c497-v8pv-ch6x/GHSA-c497-v8pv-ch6x.json b/advisories/github-reviewed/2021/02/GHSA-c497-v8pv-ch6x/GHSA-c497-v8pv-ch6x.json index 0430fa38a4a..7d3184c4fbb 100644 --- a/advisories/github-reviewed/2021/02/GHSA-c497-v8pv-ch6x/GHSA-c497-v8pv-ch6x.json +++ b/advisories/github-reviewed/2021/02/GHSA-c497-v8pv-ch6x/GHSA-c497-v8pv-ch6x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c497-v8pv-ch6x", - "modified": "2021-02-01T06:29:54Z", + "modified": "2023-08-08T19:28:27Z", "published": "2021-02-01T15:01:14Z", "aliases": [ "CVE-2021-23329" @@ -9,7 +9,10 @@ "summary": "Prototype pollution in nested-object-assign", "details": "The package nested-object-assign before 1.0.4 is vulnerable to Prototype Pollution via the default function.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } ], "affected": [ { diff --git a/advisories/github-reviewed/2021/02/GHSA-f5c9-x9j6-87qp/GHSA-f5c9-x9j6-87qp.json b/advisories/github-reviewed/2021/02/GHSA-f5c9-x9j6-87qp/GHSA-f5c9-x9j6-87qp.json index 77674bdb72a..42c67ce0f70 100644 --- a/advisories/github-reviewed/2021/02/GHSA-f5c9-x9j6-87qp/GHSA-f5c9-x9j6-87qp.json +++ b/advisories/github-reviewed/2021/02/GHSA-f5c9-x9j6-87qp/GHSA-f5c9-x9j6-87qp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f5c9-x9j6-87qp", - "modified": "2021-02-03T07:41:22Z", + "modified": "2023-08-08T19:28:24Z", "published": "2021-02-05T20:43:08Z", "aliases": [ "CVE-2021-25912" @@ -9,7 +9,10 @@ "summary": "Prototype pollution in dotty", "details": "Prototype pollution vulnerability in 'dotty' before version 0.1.1 allows attackers to cause a denial of service and may lead to remote code execution.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ { @@ -17,6 +20,11 @@ "ecosystem": "npm", "name": "dotty" }, + "ecosystem_specific": { + "affected_functions": [ + "" + ] + }, "ranges": [ { "type": "ECOSYSTEM", @@ -54,7 +62,7 @@ "cwe_ids": [ "CWE-400" ], - "severity": "MODERATE", + "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2021-02-03T07:41:22Z", "nvd_published_at": "2021-02-02T19:15:00Z" diff --git a/advisories/github-reviewed/2023/06/GHSA-jv4x-j47q-6qvp/GHSA-jv4x-j47q-6qvp.json b/advisories/github-reviewed/2023/06/GHSA-jv4x-j47q-6qvp/GHSA-jv4x-j47q-6qvp.json index 69b5e50fc69..811a63c37e3 100644 --- a/advisories/github-reviewed/2023/06/GHSA-jv4x-j47q-6qvp/GHSA-jv4x-j47q-6qvp.json +++ b/advisories/github-reviewed/2023/06/GHSA-jv4x-j47q-6qvp/GHSA-jv4x-j47q-6qvp.json @@ -47,6 +47,14 @@ { "type": "PACKAGE", "url": "https://github.com/amplafi/htmlcleaner" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2023/08/msg00007.html" + }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2023/dsa-5471" } ], "database_specific": { diff --git a/advisories/github-reviewed/2023/08/GHSA-wmwf-49vv-p3mr/GHSA-wmwf-49vv-p3mr.json b/advisories/github-reviewed/2023/08/GHSA-wmwf-49vv-p3mr/GHSA-wmwf-49vv-p3mr.json index b4e0d4fa871..396d48a984d 100644 --- a/advisories/github-reviewed/2023/08/GHSA-wmwf-49vv-p3mr/GHSA-wmwf-49vv-p3mr.json +++ b/advisories/github-reviewed/2023/08/GHSA-wmwf-49vv-p3mr/GHSA-wmwf-49vv-p3mr.json @@ -48,6 +48,10 @@ "type": "WEB", "url": "https://github.com/sulu/sulu/commit/5f6c98ba030b2005793e2dc647cc938937ea889b" }, + { + "type": "WEB", + "url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/sulu/sulu/CVE-2023-39343.yaml" + }, { "type": "PACKAGE", "url": "https://github.com/sulu/sulu"