Publish Advisories

GHSA-cvpc-8phh-8f45
GHSA-mgfv-m47x-4wqp
GHSA-mgfv-m47x-4wqp
This commit is contained in:
advisory-database[bot]
2024-10-28 15:03:24 +00:00
parent af863215fc
commit e8e1640e0b
3 changed files with 90 additions and 47 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cvpc-8phh-8f45",
"modified": "2024-08-27T22:44:30Z",
"modified": "2024-10-28T15:02:07Z",
"published": "2020-09-25T18:28:49Z",
"aliases": [
"CVE-2020-15211"
@@ -404,10 +404,6 @@
"type": "WEB",
"url": "https://github.com/tensorflow/tensorflow/blob/0e68f4d3295eb0281a517c3662f6698992b7b2cf/tensorflow/lite/core/subgraph.cc#L566-L580"
},
{
"type": "WEB",
"url": "https://github.com/tensorflow/tensorflow/releases/tag/v2.3.1"
},
{
"type": "WEB",
"url": "https://github.com/tensorflow/tensorflow/blob/0e68f4d3295eb0281a517c3662f6698992b7b2cf/tensorflow/lite/c/common.h#L82"
@@ -416,6 +412,22 @@
"type": "PACKAGE",
"url": "https://github.com/tensorflow/tensorflow"
},
{
"type": "WEB",
"url": "https://github.com/pypa/advisory-database/tree/main/vulns/tensorflow/PYSEC-2020-134.yaml"
},
{
"type": "WEB",
"url": "https://github.com/tensorflow/tensorflow/releases/tag/v2.3.1"
},
{
"type": "WEB",
"url": "https://github.com/pypa/advisory-database/tree/main/vulns/tensorflow-gpu/PYSEC-2020-326.yaml"
},
{
"type": "WEB",
"url": "https://github.com/pypa/advisory-database/tree/main/vulns/tensorflow-cpu/PYSEC-2020-291.yaml"
},
{
"type": "WEB",
"url": "http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00065.html"
@@ -0,0 +1,73 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mgfv-m47x-4wqp",
"modified": "2024-10-28T15:01:50Z",
"published": "2024-10-26T21:30:47Z",
"aliases": [
"CVE-2020-26311"
],
"summary": "useragent Regular Expression Denial of Service vulnerability",
"details": "Useragent is a user agent parser for Node.js. All versions as of time of publication contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS).",
"severity": [
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green"
}
],
"affected": [
{
"package": {
"ecosystem": "npm",
"name": "useragent"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.3.0"
}
]
}
]
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2020-26311"
},
{
"type": "WEB",
"url": "https://github.com/3rd-Eden/useragent/issues/167"
},
{
"type": "WEB",
"url": "https://github.com/3rd-Eden/useragent/commit/4c3ee79358bea72d88fe78ac98f4f861db40b89b"
},
{
"type": "PACKAGE",
"url": "https://github.com/3rd-Eden/useragent"
},
{
"type": "WEB",
"url": "https://github.com/3rd-Eden/useragent/blob/ffa906f923183c85fbb9e6c90f19345e2bd3c52a/lib/regexps.js#L5568"
},
{
"type": "ADVISORY",
"url": "https://securitylab.github.com/advisories/GHSL-2020-312-redos-useragent"
}
],
"database_specific": {
"cwe_ids": [
"CWE-1333"
],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-10-28T15:01:50Z",
"nvd_published_at": "2024-10-26T21:15:14Z"
}
}
@@ -1,42 +0,0 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mgfv-m47x-4wqp",
"modified": "2024-10-26T21:30:47Z",
"published": "2024-10-26T21:30:47Z",
"aliases": [
"CVE-2020-26311"
],
"details": "Useragent is a user agent parser for Node.js. All versions as of time of publication contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, no patches are available.",
"severity": [
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Green"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2020-26311"
},
{
"type": "WEB",
"url": "https://github.com/3rd-Eden/useragent/issues/167"
},
{
"type": "ADVISORY",
"url": "https://securitylab.github.com/advisories/GHSL-2020-312-redos-useragent"
}
],
"database_specific": {
"cwe_ids": [
"CWE-1333"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-26T21:15:14Z"
}
}