diff --git a/advisories/unreviewed/2024/12/GHSA-8hvf-h3fh-qgpv/GHSA-8hvf-h3fh-qgpv.json b/advisories/unreviewed/2024/12/GHSA-8hvf-h3fh-qgpv/GHSA-8hvf-h3fh-qgpv.json new file mode 100644 index 00000000000..51262bb2f0f --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-8hvf-h3fh-qgpv/GHSA-8hvf-h3fh-qgpv.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8hvf-h3fh-qgpv", + "modified": "2024-12-15T06:32:50Z", + "published": "2024-12-15T06:32:50Z", + "aliases": [ + "CVE-2024-56082" + ], + "details": "ChatBar.tsx in Lumos before 1.0.17 parses raw HTML in Markdown because the markdown-to-jsx package is used without disableParsingRawHTML set to true.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56082" + }, + { + "type": "WEB", + "url": "https://github.com/andrewnguonly/Lumos/issues/193" + }, + { + "type": "WEB", + "url": "https://github.com/andrewnguonly/Lumos/releases/tag/1.0.17" + }, + { + "type": "WEB", + "url": "https://github.com/quantizor/markdown-to-jsx/blob/4fa87d89ad87f97b2d9e56cb969d12f9a838f3ac/README.md?plain=1#L535-L537" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-15T05:15:05Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-cpgh-chqx-qm3c/GHSA-cpgh-chqx-qm3c.json b/advisories/unreviewed/2024/12/GHSA-cpgh-chqx-qm3c/GHSA-cpgh-chqx-qm3c.json new file mode 100644 index 00000000000..2613383dc33 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-cpgh-chqx-qm3c/GHSA-cpgh-chqx-qm3c.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cpgh-chqx-qm3c", + "modified": "2024-12-15T06:32:50Z", + "published": "2024-12-15T06:32:50Z", + "aliases": [ + "CVE-2024-55969" + ], + "details": "DocIO in Syncfusion Essential Studio for ASP.NET MVC before 27.1.55 throws XMLException during the resaving of a DOCX document with an external reference XML, aka I640714.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55969" + }, + { + "type": "WEB", + "url": "https://ej2.syncfusion.com/aspnetmvc/documentation/release-notes/27.1.55?type=all" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-15T04:15:04Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/12/GHSA-hx59-p22r-49rv/GHSA-hx59-p22r-49rv.json b/advisories/unreviewed/2024/12/GHSA-hx59-p22r-49rv/GHSA-hx59-p22r-49rv.json new file mode 100644 index 00000000000..6fe30602d94 --- /dev/null +++ b/advisories/unreviewed/2024/12/GHSA-hx59-p22r-49rv/GHSA-hx59-p22r-49rv.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hx59-p22r-49rv", + "modified": "2024-12-15T06:32:50Z", + "published": "2024-12-15T06:32:50Z", + "aliases": [ + "CVE-2024-56074" + ], + "details": "gitingest before 9996a06 mishandles symbolic links that point outside of the base directory.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56074" + }, + { + "type": "WEB", + "url": "https://github.com/cyclotruc/gitingest/pull/23" + }, + { + "type": "WEB", + "url": "https://github.com/cyclotruc/gitingest/commit/9996a06a94450497c1abb35997f5e6cbc9b571ff" + }, + { + "type": "WEB", + "url": "https://github.com/cyclotruc/gitingest/blob/9996a06a94450497c1abb35997f5e6cbc9b571ff/src/ingest.py#L22-L30" + }, + { + "type": "WEB", + "url": "https://github.com/cyclotruc/gitingest/blob/9996a06a94450497c1abb35997f5e6cbc9b571ff/src/ingest.py#L99-L100" + }, + { + "type": "WEB", + "url": "https://gitingest.com" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-12-15T04:15:05Z" + } +} \ No newline at end of file