diff --git a/advisories/github-reviewed/2020/09/GHSA-22q9-hqm5-mhmc/GHSA-22q9-hqm5-mhmc.json b/advisories/github-reviewed/2020/09/GHSA-22q9-hqm5-mhmc/GHSA-22q9-hqm5-mhmc.json
index e90a074f999..284b16fb947 100644
--- a/advisories/github-reviewed/2020/09/GHSA-22q9-hqm5-mhmc/GHSA-22q9-hqm5-mhmc.json
+++ b/advisories/github-reviewed/2020/09/GHSA-22q9-hqm5-mhmc/GHSA-22q9-hqm5-mhmc.json
@@ -3,14 +3,10 @@
"id": "GHSA-22q9-hqm5-mhmc",
"modified": "2021-09-28T17:01:08Z",
"published": "2020-09-11T21:22:24Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Cross-Site Scripting in swagger-ui",
"details": "Versions of `swagger-ui` prior to 2.2.1 are vulnerable to Cross-Site Scripting (XSS). The package fails to encode output in GET requests. The request is meant to respond with Content-Type `application/json` which does not trigger the vulnerability but if the web server changes the header to `text/html` it may allow attackers to execute arbitrary JavaScript.\n\n\n## Recommendation\n\nUpgrade to version 2.2.1 or later.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
diff --git a/advisories/github-reviewed/2020/09/GHSA-388g-jwpg-x6j4/GHSA-388g-jwpg-x6j4.json b/advisories/github-reviewed/2020/09/GHSA-388g-jwpg-x6j4/GHSA-388g-jwpg-x6j4.json
index bb7f24ab81e..fea6dc27ab2 100644
--- a/advisories/github-reviewed/2020/09/GHSA-388g-jwpg-x6j4/GHSA-388g-jwpg-x6j4.json
+++ b/advisories/github-reviewed/2020/09/GHSA-388g-jwpg-x6j4/GHSA-388g-jwpg-x6j4.json
@@ -3,9 +3,7 @@
"id": "GHSA-388g-jwpg-x6j4",
"modified": "2021-09-28T17:00:22Z",
"published": "2020-09-11T21:20:14Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Cross-Site Scripting in swagger-ui",
"details": "Versions of `swagger-ui` prior to 3.0.13 are vulnerable to Cross-Site Scripting (XSS). The package fails to sanitize YAML files imported from URLs or copied-pasted. This may allow attackers to execute arbitrary JavaScript.\n\n\n## Recommendation\n\nUpgrade to version 3.0.13 or later.",
"severity": [
diff --git a/advisories/github-reviewed/2020/09/GHSA-3f95-w5h5-fq86/GHSA-3f95-w5h5-fq86.json b/advisories/github-reviewed/2020/09/GHSA-3f95-w5h5-fq86/GHSA-3f95-w5h5-fq86.json
index fe39333fba3..ac92278a3ce 100644
--- a/advisories/github-reviewed/2020/09/GHSA-3f95-w5h5-fq86/GHSA-3f95-w5h5-fq86.json
+++ b/advisories/github-reviewed/2020/09/GHSA-3f95-w5h5-fq86/GHSA-3f95-w5h5-fq86.json
@@ -3,14 +3,10 @@
"id": "GHSA-3f95-w5h5-fq86",
"modified": "2020-08-31T18:43:27Z",
"published": "2020-09-11T21:22:24Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Prototype Pollution in mergify",
"details": "All versions of `mergify` are vulnerable to Prototype Pollution. The `mergify()` function allows attackers to modify the prototype of Object causing the addition or modification of an existing property that will exist on all objects.\n\n\n\n\n## Recommendation\n\nNo fix is currently available. Consider using an alternative module as the package is deprecated.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
diff --git a/advisories/github-reviewed/2020/09/GHSA-48gc-5j93-5cfq/GHSA-48gc-5j93-5cfq.json b/advisories/github-reviewed/2020/09/GHSA-48gc-5j93-5cfq/GHSA-48gc-5j93-5cfq.json
index 4c091e78c47..c49b24e2ae1 100644
--- a/advisories/github-reviewed/2020/09/GHSA-48gc-5j93-5cfq/GHSA-48gc-5j93-5cfq.json
+++ b/advisories/github-reviewed/2020/09/GHSA-48gc-5j93-5cfq/GHSA-48gc-5j93-5cfq.json
@@ -3,14 +3,10 @@
"id": "GHSA-48gc-5j93-5cfq",
"modified": "2020-08-31T18:42:15Z",
"published": "2020-09-11T21:15:54Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Path Traversal in serve",
"details": "Versions of `serve` prior to 10.1.2 are vulnerable to Path Traversal. Explicitly ignored folders can be accessed through relative paths, which allows attackers to access hidden folders and files.\n\n\n## Recommendation\n\nUpgrade to version 10.1.2 or later.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
diff --git a/advisories/github-reviewed/2020/09/GHSA-4q2f-8g74-qm56/GHSA-4q2f-8g74-qm56.json b/advisories/github-reviewed/2020/09/GHSA-4q2f-8g74-qm56/GHSA-4q2f-8g74-qm56.json
index 483befeab3a..eb1bbdf1160 100644
--- a/advisories/github-reviewed/2020/09/GHSA-4q2f-8g74-qm56/GHSA-4q2f-8g74-qm56.json
+++ b/advisories/github-reviewed/2020/09/GHSA-4q2f-8g74-qm56/GHSA-4q2f-8g74-qm56.json
@@ -3,14 +3,10 @@
"id": "GHSA-4q2f-8g74-qm56",
"modified": "2020-08-31T18:45:01Z",
"published": "2020-09-03T17:18:05Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Cross-Site Scripting in takeapeek",
"details": "All versions of `takeapeek` are vulnerable to Cross-Site Scripting (XSS). The package fails to sanitize filenames, allowing attackers to execute arbitrary JavaScript in the victim's browser through files with names containing malicious code.\n\n\n## Recommendation\n\nNo fix is currently available. Consider using an alternative package until a fix is made available.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
diff --git a/advisories/github-reviewed/2020/09/GHSA-5634-rv46-48jf/GHSA-5634-rv46-48jf.json b/advisories/github-reviewed/2020/09/GHSA-5634-rv46-48jf/GHSA-5634-rv46-48jf.json
index cf8ba6ff7a9..3445a15e781 100644
--- a/advisories/github-reviewed/2020/09/GHSA-5634-rv46-48jf/GHSA-5634-rv46-48jf.json
+++ b/advisories/github-reviewed/2020/09/GHSA-5634-rv46-48jf/GHSA-5634-rv46-48jf.json
@@ -3,14 +3,10 @@
"id": "GHSA-5634-rv46-48jf",
"modified": "2020-08-31T18:44:51Z",
"published": "2020-09-03T17:13:45Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Cross-Site Scripting in bleach",
"details": "All versions of `bleach` are vulnerable to Cross-Site Scripting. It is possible to bypass the package's HTML sanitization with payloads such as `\"<script>alert('xss');script>\"` regardless of the passed options. This may allow attackers to execute arbitrary JavaScript in the victim's browser.\n\n\n## Recommendation\n\nNo fix is currently available. Consider using an alternative package until a fix is made available.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
diff --git a/advisories/github-reviewed/2020/09/GHSA-588m-9qg5-35pq/GHSA-588m-9qg5-35pq.json b/advisories/github-reviewed/2020/09/GHSA-588m-9qg5-35pq/GHSA-588m-9qg5-35pq.json
index d5cc6128b25..731aa45d3f3 100644
--- a/advisories/github-reviewed/2020/09/GHSA-588m-9qg5-35pq/GHSA-588m-9qg5-35pq.json
+++ b/advisories/github-reviewed/2020/09/GHSA-588m-9qg5-35pq/GHSA-588m-9qg5-35pq.json
@@ -3,9 +3,7 @@
"id": "GHSA-588m-9qg5-35pq",
"modified": "2021-09-28T22:06:18Z",
"published": "2020-09-03T17:19:09Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Reverse Tabnabbing in quill",
"details": "Versions of `quill` prior to 1.3.7 are vulnerable to [Reverse Tabnabbing](https://www.owasp.org/index.php/Reverse_Tabnabbing). The package uses `target='_blank'` in anchor tags, allowing attackers to access `window.opener` for the original page when opening links. This is commonly used for phishing attacks.\n\n\n## Recommendation\n\nNo fix is currently available. Consider using an alternative package until a fix is made available.",
"severity": [
diff --git a/advisories/github-reviewed/2020/09/GHSA-5g6j-8hv4-vfgj/GHSA-5g6j-8hv4-vfgj.json b/advisories/github-reviewed/2020/09/GHSA-5g6j-8hv4-vfgj/GHSA-5g6j-8hv4-vfgj.json
index d9c97492af2..60ea9b3726d 100644
--- a/advisories/github-reviewed/2020/09/GHSA-5g6j-8hv4-vfgj/GHSA-5g6j-8hv4-vfgj.json
+++ b/advisories/github-reviewed/2020/09/GHSA-5g6j-8hv4-vfgj/GHSA-5g6j-8hv4-vfgj.json
@@ -3,14 +3,10 @@
"id": "GHSA-5g6j-8hv4-vfgj",
"modified": "2020-08-31T18:43:22Z",
"published": "2020-09-11T21:21:19Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Cross-Site Scripting in node-red",
"details": "Versions of `node-red` prior to 0.18.6 are vulnerable to Cross-Site Scripting (XSS). The package fails to sanitize the `name` field in new items, allowing attackers to execute arbitrary JavaScript in the victim's browser.\n\n\n## Recommendation\n\nUpgrade to version 0.18.6 or later.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
diff --git a/advisories/github-reviewed/2020/09/GHSA-6879-xr95-5gf4/GHSA-6879-xr95-5gf4.json b/advisories/github-reviewed/2020/09/GHSA-6879-xr95-5gf4/GHSA-6879-xr95-5gf4.json
index 5505ad51370..e0e9686a729 100644
--- a/advisories/github-reviewed/2020/09/GHSA-6879-xr95-5gf4/GHSA-6879-xr95-5gf4.json
+++ b/advisories/github-reviewed/2020/09/GHSA-6879-xr95-5gf4/GHSA-6879-xr95-5gf4.json
@@ -3,9 +3,7 @@
"id": "GHSA-6879-xr95-5gf4",
"modified": "2021-09-30T17:16:35Z",
"published": "2020-09-03T17:20:15Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Malicious Package in malicious-do-not-install",
"details": "All versions of `malicious-do-not-install` contain malicious code. The package copies the contents of `/etc/passwd` and `/etc/shadow` to files in the local `/tmp/` folder.\n\n\n## Recommendation\n\nRemove the package from your environment and rotate affected credentials.",
"severity": [
diff --git a/advisories/github-reviewed/2020/09/GHSA-6m6m-j2hm-pxrg/GHSA-6m6m-j2hm-pxrg.json b/advisories/github-reviewed/2020/09/GHSA-6m6m-j2hm-pxrg/GHSA-6m6m-j2hm-pxrg.json
index d90a7dcf920..34117ecf8dc 100644
--- a/advisories/github-reviewed/2020/09/GHSA-6m6m-j2hm-pxrg/GHSA-6m6m-j2hm-pxrg.json
+++ b/advisories/github-reviewed/2020/09/GHSA-6m6m-j2hm-pxrg/GHSA-6m6m-j2hm-pxrg.json
@@ -3,9 +3,7 @@
"id": "GHSA-6m6m-j2hm-pxrg",
"modified": "2021-09-30T19:33:36Z",
"published": "2020-09-03T17:37:05Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Malicious Package in cicada-render",
"details": "All versions of `cicada-render` contain malicious code. The package uploads system information to a remote server, downloads a file and executes it.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.",
"severity": [
diff --git a/advisories/github-reviewed/2020/09/GHSA-8m5v-f2wp-wqr9/GHSA-8m5v-f2wp-wqr9.json b/advisories/github-reviewed/2020/09/GHSA-8m5v-f2wp-wqr9/GHSA-8m5v-f2wp-wqr9.json
index 659a2161e81..e1cf97bc858 100644
--- a/advisories/github-reviewed/2020/09/GHSA-8m5v-f2wp-wqr9/GHSA-8m5v-f2wp-wqr9.json
+++ b/advisories/github-reviewed/2020/09/GHSA-8m5v-f2wp-wqr9/GHSA-8m5v-f2wp-wqr9.json
@@ -3,9 +3,7 @@
"id": "GHSA-8m5v-f2wp-wqr9",
"modified": "2021-09-30T17:50:11Z",
"published": "2020-09-03T17:30:36Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Malicious Package in ali-contributors",
"details": "All versions of `ali-contributors` contain malicious code. The package uploads system information to a remote server, downloads a file and executes it.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.",
"severity": [
diff --git a/advisories/github-reviewed/2020/09/GHSA-8q2c-2396-hf7j/GHSA-8q2c-2396-hf7j.json b/advisories/github-reviewed/2020/09/GHSA-8q2c-2396-hf7j/GHSA-8q2c-2396-hf7j.json
index ffaecc83f45..a40dbcd0d08 100644
--- a/advisories/github-reviewed/2020/09/GHSA-8q2c-2396-hf7j/GHSA-8q2c-2396-hf7j.json
+++ b/advisories/github-reviewed/2020/09/GHSA-8q2c-2396-hf7j/GHSA-8q2c-2396-hf7j.json
@@ -3,9 +3,7 @@
"id": "GHSA-8q2c-2396-hf7j",
"modified": "2021-09-30T19:31:14Z",
"published": "2020-09-03T17:34:55Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Malicious Package in appx-compiler",
"details": "All versions of `appx-compiler` contain malicious code. The package uploads system information to a remote server, downloads a file and executes it.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.",
"severity": [
diff --git a/advisories/github-reviewed/2020/09/GHSA-9pcf-h8q9-63f6/GHSA-9pcf-h8q9-63f6.json b/advisories/github-reviewed/2020/09/GHSA-9pcf-h8q9-63f6/GHSA-9pcf-h8q9-63f6.json
index f1464a82860..48def277da7 100644
--- a/advisories/github-reviewed/2020/09/GHSA-9pcf-h8q9-63f6/GHSA-9pcf-h8q9-63f6.json
+++ b/advisories/github-reviewed/2020/09/GHSA-9pcf-h8q9-63f6/GHSA-9pcf-h8q9-63f6.json
@@ -3,14 +3,10 @@
"id": "GHSA-9pcf-h8q9-63f6",
"modified": "2020-08-31T18:44:49Z",
"published": "2020-09-03T17:12:41Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Sandbox Breakout / Arbitrary Code Execution in safe-eval",
"details": "All versions of `safe-eval` are vulnerable to Sandbox Escape leading to Remote Code Execution. A payload chaining a function's callee and caller constructors can escape the sandbox and execute arbitrary code. \n\nFor example, the payload \n```\n((() => { \nconst targetKey = Object.keys(this)[0]; \nObject.defineProperty(this, targetKey, { \nget: function() { \nreturn arguments.callee.caller.constructor( \n\"return global.process.mainModule.require('child_process').execSync('pwd').toString()\" \n)(); \n} \n}); \n})();```\nmay be used to print the `pwd` to the console.\n\n\n## Recommendation\n\nNo fix is currently available. Consider using an alternative package until a fix is made available.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
@@ -36,9 +32,7 @@
}
],
"database_specific": {
- "cwe_ids": [
-
- ],
+ "cwe_ids": [],
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2020-08-31T18:44:49Z",
diff --git a/advisories/github-reviewed/2020/09/GHSA-9qgh-7pgp-hp7r/GHSA-9qgh-7pgp-hp7r.json b/advisories/github-reviewed/2020/09/GHSA-9qgh-7pgp-hp7r/GHSA-9qgh-7pgp-hp7r.json
index 1c6cab9bdc2..5c42ecf17e6 100644
--- a/advisories/github-reviewed/2020/09/GHSA-9qgh-7pgp-hp7r/GHSA-9qgh-7pgp-hp7r.json
+++ b/advisories/github-reviewed/2020/09/GHSA-9qgh-7pgp-hp7r/GHSA-9qgh-7pgp-hp7r.json
@@ -3,14 +3,10 @@
"id": "GHSA-9qgh-7pgp-hp7r",
"modified": "2020-08-31T18:44:42Z",
"published": "2020-09-03T17:10:31Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Cross-Site Scripting in graylog-web-interface",
"details": "All versions of `graylog-web-interface` are vulnerable to Cross-Site Scripting (XSS). The package fails to escape output on the `TypeAhead` and `QueryInput` components, which may allow attackers to execute arbitrary JavaScript on the victim's browser.\n\n\n## Recommendation\n\nNo fix is currently available. Consider using an alternative package until a fix is made available.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
diff --git a/advisories/github-reviewed/2020/09/GHSA-9r3m-mhfm-39cm/GHSA-9r3m-mhfm-39cm.json b/advisories/github-reviewed/2020/09/GHSA-9r3m-mhfm-39cm/GHSA-9r3m-mhfm-39cm.json
index d5d8a99a072..30a9de0c788 100644
--- a/advisories/github-reviewed/2020/09/GHSA-9r3m-mhfm-39cm/GHSA-9r3m-mhfm-39cm.json
+++ b/advisories/github-reviewed/2020/09/GHSA-9r3m-mhfm-39cm/GHSA-9r3m-mhfm-39cm.json
@@ -3,14 +3,10 @@
"id": "GHSA-9r3m-mhfm-39cm",
"modified": "2020-08-31T18:42:08Z",
"published": "2020-09-11T21:10:29Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Incorrect Calculation in bigint-money",
"details": "Versions of `bigint-money` prior to 0.6.2 are vulnerable to an Incorrect Calculation. The package incorrectly rounded certain numbers, which could have drastic consequences due to its usage in financial systems.\n\n\n## Recommendation\n\nUpgrade to version 0.6.2 or later.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
diff --git a/advisories/github-reviewed/2020/09/GHSA-9v62-24cr-58cx/GHSA-9v62-24cr-58cx.json b/advisories/github-reviewed/2020/09/GHSA-9v62-24cr-58cx/GHSA-9v62-24cr-58cx.json
index a3531444844..38f866ae9dd 100644
--- a/advisories/github-reviewed/2020/09/GHSA-9v62-24cr-58cx/GHSA-9v62-24cr-58cx.json
+++ b/advisories/github-reviewed/2020/09/GHSA-9v62-24cr-58cx/GHSA-9v62-24cr-58cx.json
@@ -3,9 +3,7 @@
"id": "GHSA-9v62-24cr-58cx",
"modified": "2021-09-28T16:08:17Z",
"published": "2020-09-11T21:12:39Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Denial of Service in node-sass",
"details": "Affected versions of `node-sass` are vulnerable to Denial of Service (DoS). Crafted objects passed to the `renderSync` function may trigger C++ assertions in `CustomImporterBridge::get_importer_entry` and `CustomImporterBridge::post_process_return_value` that crash the Node process. This may allow attackers to crash the system's running Node process and lead to Denial of Service.\n\n\n## Recommendation\n\nUpgrade to version 4.13.1 or later",
"severity": [
diff --git a/advisories/github-reviewed/2020/09/GHSA-c53x-wwx2-pg96/GHSA-c53x-wwx2-pg96.json b/advisories/github-reviewed/2020/09/GHSA-c53x-wwx2-pg96/GHSA-c53x-wwx2-pg96.json
index 29753196084..0cbfe7e6106 100644
--- a/advisories/github-reviewed/2020/09/GHSA-c53x-wwx2-pg96/GHSA-c53x-wwx2-pg96.json
+++ b/advisories/github-reviewed/2020/09/GHSA-c53x-wwx2-pg96/GHSA-c53x-wwx2-pg96.json
@@ -3,9 +3,7 @@
"id": "GHSA-c53x-wwx2-pg96",
"modified": "2021-09-28T17:27:43Z",
"published": "2020-09-03T17:03:58Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Cross-Site Scripting in @berslucas/liljs",
"details": "Versions of `@berslucas/liljs` prior to 1.0.2 are vulnerable to Cross-Site Scripting (XSS). The package uses the unsafe `innerHTML` function without sanitizing input, which may allow attackers to execute arbitrary JavaScript on the victim's browser.\n\n\n## Recommendation\n\nUpgrade to version 1.0.2 or later.",
"severity": [
diff --git a/advisories/github-reviewed/2020/09/GHSA-cpgr-wmr9-qxv4/GHSA-cpgr-wmr9-qxv4.json b/advisories/github-reviewed/2020/09/GHSA-cpgr-wmr9-qxv4/GHSA-cpgr-wmr9-qxv4.json
index b86d8e25ec2..581630ac747 100644
--- a/advisories/github-reviewed/2020/09/GHSA-cpgr-wmr9-qxv4/GHSA-cpgr-wmr9-qxv4.json
+++ b/advisories/github-reviewed/2020/09/GHSA-cpgr-wmr9-qxv4/GHSA-cpgr-wmr9-qxv4.json
@@ -3,14 +3,10 @@
"id": "GHSA-cpgr-wmr9-qxv4",
"modified": "2020-08-31T18:43:20Z",
"published": "2020-09-11T21:20:14Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Cross-Site Scripting in serve",
"details": "Versions of `serve` prior to 10.0.2 are vulnerable to Cross-Site Scripting (XSS). The package fails to sanitize filenames, allowing attackers to execute arbitrary JavaScript in the victim's browser through files with names containing malicious code.\n\n\n## Recommendation\n\nUpgrade to version 10.0.2 or later.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
diff --git a/advisories/github-reviewed/2020/09/GHSA-crf7-fvjx-863q/GHSA-crf7-fvjx-863q.json b/advisories/github-reviewed/2020/09/GHSA-crf7-fvjx-863q/GHSA-crf7-fvjx-863q.json
index 8c88dc2d9c1..1ab2b04516b 100644
--- a/advisories/github-reviewed/2020/09/GHSA-crf7-fvjx-863q/GHSA-crf7-fvjx-863q.json
+++ b/advisories/github-reviewed/2020/09/GHSA-crf7-fvjx-863q/GHSA-crf7-fvjx-863q.json
@@ -3,14 +3,10 @@
"id": "GHSA-crf7-fvjx-863q",
"modified": "2020-08-31T18:44:37Z",
"published": "2020-09-03T17:09:26Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Path Traversal in zero",
"details": "Versions of `zero` prior to 1.0.6 are vulnerable to Path Traversal. Due to insufficient input sanitization in URLs, attackers can access server files by using relative paths when fetching files. \n\n\n## Recommendation\n\nUpgrade to version 1.0.6 or later.\n",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
diff --git a/advisories/github-reviewed/2020/09/GHSA-crpm-fm48-chj7/GHSA-crpm-fm48-chj7.json b/advisories/github-reviewed/2020/09/GHSA-crpm-fm48-chj7/GHSA-crpm-fm48-chj7.json
index bff5cb685fb..e85746628f1 100644
--- a/advisories/github-reviewed/2020/09/GHSA-crpm-fm48-chj7/GHSA-crpm-fm48-chj7.json
+++ b/advisories/github-reviewed/2020/09/GHSA-crpm-fm48-chj7/GHSA-crpm-fm48-chj7.json
@@ -3,14 +3,10 @@
"id": "GHSA-crpm-fm48-chj7",
"modified": "2020-08-31T18:42:11Z",
"published": "2020-09-11T21:13:44Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "SQL Injection in resquel",
"details": "All versions of `resquel` are vulnerable to SQL Injection. Query parameters are not properly sanitized, allowing attackers to inject SQL statements and execute arbitrary SQL queries\n\n\n## Recommendation\n\nNo fix is currently available. Consider using an alternative package until a fix is made available.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
diff --git a/advisories/github-reviewed/2020/09/GHSA-crr2-ph72-c52g/GHSA-crr2-ph72-c52g.json b/advisories/github-reviewed/2020/09/GHSA-crr2-ph72-c52g/GHSA-crr2-ph72-c52g.json
index 8692a5557fd..c4e89f97764 100644
--- a/advisories/github-reviewed/2020/09/GHSA-crr2-ph72-c52g/GHSA-crr2-ph72-c52g.json
+++ b/advisories/github-reviewed/2020/09/GHSA-crr2-ph72-c52g/GHSA-crr2-ph72-c52g.json
@@ -3,9 +3,7 @@
"id": "GHSA-crr2-ph72-c52g",
"modified": "2021-09-30T17:44:05Z",
"published": "2020-09-03T17:27:22Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Malicious Package in my-very-own-package",
"details": "All versions of `my-very-own-package` contain malicious code. The package sends the output of `process.versions`, `process.arch` and `process.platform` to a remote server in a postinstall script.\n\n\n## Recommendation\n\nRemove the package from your environment. There are no further signs of compromise.",
"severity": [
diff --git a/advisories/github-reviewed/2020/09/GHSA-fgp6-8g62-qx6w/GHSA-fgp6-8g62-qx6w.json b/advisories/github-reviewed/2020/09/GHSA-fgp6-8g62-qx6w/GHSA-fgp6-8g62-qx6w.json
index 907df617a62..8e356248265 100644
--- a/advisories/github-reviewed/2020/09/GHSA-fgp6-8g62-qx6w/GHSA-fgp6-8g62-qx6w.json
+++ b/advisories/github-reviewed/2020/09/GHSA-fgp6-8g62-qx6w/GHSA-fgp6-8g62-qx6w.json
@@ -3,9 +3,7 @@
"id": "GHSA-fgp6-8g62-qx6w",
"modified": "2021-09-30T21:58:23Z",
"published": "2020-09-03T17:01:45Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Malicious Package in smartsearchwp",
"details": "All versions of `smartsearchwp` contain malicious code. The package is malware intended to steal credentials from websites it is loaded in. It traverses DOM elements looking for fields such as `username` and `password` and uploads it to a remote server. The package also port-scans the local gateway and uploads the information to the remote server. It has a feature to fetch commands from the remote server and execute them with `eval`. The npm security team analysis found several bugs in the malware that prevent it from actually performing its actions. The malicious code is also not invoked upon installation or require; it would require transpiling TypeScript code and using it in a website.\n\n\n\n## Recommendation\n\nRemove the package from your environment. There is no indication of further compromise.",
"severity": [
diff --git a/advisories/github-reviewed/2020/09/GHSA-g8vp-6hv4-m67c/GHSA-g8vp-6hv4-m67c.json b/advisories/github-reviewed/2020/09/GHSA-g8vp-6hv4-m67c/GHSA-g8vp-6hv4-m67c.json
index c413f69ee05..0ea7b1af5ba 100644
--- a/advisories/github-reviewed/2020/09/GHSA-g8vp-6hv4-m67c/GHSA-g8vp-6hv4-m67c.json
+++ b/advisories/github-reviewed/2020/09/GHSA-g8vp-6hv4-m67c/GHSA-g8vp-6hv4-m67c.json
@@ -3,14 +3,10 @@
"id": "GHSA-g8vp-6hv4-m67c",
"modified": "2020-08-31T18:43:32Z",
"published": "2020-09-11T21:23:29Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Command Injection in entitlements",
"details": "Versions of `entitlements` prior to 1.3.0 are vulnerable to Command Injection. The package does not validate input on the `entitlements` function and concatenates it to an exec call, allowing attackers to run arbitrary commands in the system.\n\n\n## Recommendation\n\nUpgrade to version 1.3.0 or later.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
diff --git a/advisories/github-reviewed/2020/09/GHSA-g9wf-393q-4w38/GHSA-g9wf-393q-4w38.json b/advisories/github-reviewed/2020/09/GHSA-g9wf-393q-4w38/GHSA-g9wf-393q-4w38.json
index e4bf5ec6e74..eb3da261de0 100644
--- a/advisories/github-reviewed/2020/09/GHSA-g9wf-393q-4w38/GHSA-g9wf-393q-4w38.json
+++ b/advisories/github-reviewed/2020/09/GHSA-g9wf-393q-4w38/GHSA-g9wf-393q-4w38.json
@@ -3,9 +3,7 @@
"id": "GHSA-g9wf-393q-4w38",
"modified": "2021-09-30T17:44:24Z",
"published": "2020-09-03T17:28:26Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Malicious Package in only-test-not-install",
"details": "All versions of `only-test-not-install` contain malicious code. The package deletes the folder `~/test` from the system as a postinstall script.\n\n\n## Recommendation\n\nRemove the package from your environment. There are no further signs of compromise.",
"severity": [
diff --git a/advisories/github-reviewed/2020/09/GHSA-gfm8-g3vm-53jh/GHSA-gfm8-g3vm-53jh.json b/advisories/github-reviewed/2020/09/GHSA-gfm8-g3vm-53jh/GHSA-gfm8-g3vm-53jh.json
index 4b77ecc47a9..fc4ce1588bf 100644
--- a/advisories/github-reviewed/2020/09/GHSA-gfm8-g3vm-53jh/GHSA-gfm8-g3vm-53jh.json
+++ b/advisories/github-reviewed/2020/09/GHSA-gfm8-g3vm-53jh/GHSA-gfm8-g3vm-53jh.json
@@ -3,9 +3,7 @@
"id": "GHSA-gfm8-g3vm-53jh",
"modified": "2021-09-30T17:16:55Z",
"published": "2020-09-03T17:21:19Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Malicious Package in leetlog",
"details": "Versions 0.1.2 and 0.1.3 of `leetlog` contain malicious code. The package adds an arbitrary hardcoded SSH key identified as `hacker@evilmachine` to the system's `authorized_keys`\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.",
"severity": [
diff --git a/advisories/github-reviewed/2020/09/GHSA-gvff-25cc-4f66/GHSA-gvff-25cc-4f66.json b/advisories/github-reviewed/2020/09/GHSA-gvff-25cc-4f66/GHSA-gvff-25cc-4f66.json
index 67d7e9f923d..9615eadde1f 100644
--- a/advisories/github-reviewed/2020/09/GHSA-gvff-25cc-4f66/GHSA-gvff-25cc-4f66.json
+++ b/advisories/github-reviewed/2020/09/GHSA-gvff-25cc-4f66/GHSA-gvff-25cc-4f66.json
@@ -3,14 +3,10 @@
"id": "GHSA-gvff-25cc-4f66",
"modified": "2020-08-31T18:44:58Z",
"published": "2020-09-03T17:15:56Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Path Traversal in restify-swagger-jsdoc",
"details": "Versions of `restify-swagger-jsdoc` prior to 3.2.1 are vulnerable to Path Traversal. The package fails to properly sanitize URLs, which may allow attackers to access server files outside the `swagger-ui` folder by using relative paths. \n\n\n\n## Recommendation\n\nUpgrade to version 3.2.1 or later.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
diff --git a/advisories/github-reviewed/2020/09/GHSA-h3m2-h22h-695r/GHSA-h3m2-h22h-695r.json b/advisories/github-reviewed/2020/09/GHSA-h3m2-h22h-695r/GHSA-h3m2-h22h-695r.json
index dcf09a66389..7c6af0d46e4 100644
--- a/advisories/github-reviewed/2020/09/GHSA-h3m2-h22h-695r/GHSA-h3m2-h22h-695r.json
+++ b/advisories/github-reviewed/2020/09/GHSA-h3m2-h22h-695r/GHSA-h3m2-h22h-695r.json
@@ -3,9 +3,7 @@
"id": "GHSA-h3m2-h22h-695r",
"modified": "2021-09-30T17:49:52Z",
"published": "2020-09-03T17:29:31Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Malicious Package in ali-contributor",
"details": "All versions of `ali-contributor` contain malicious code. The package uploads system information to a remote server, downloads a file and executes it.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.",
"severity": [
diff --git a/advisories/github-reviewed/2020/09/GHSA-h97g-4mx7-5p2p/GHSA-h97g-4mx7-5p2p.json b/advisories/github-reviewed/2020/09/GHSA-h97g-4mx7-5p2p/GHSA-h97g-4mx7-5p2p.json
index 529ed6157fd..1b17e3d66aa 100644
--- a/advisories/github-reviewed/2020/09/GHSA-h97g-4mx7-5p2p/GHSA-h97g-4mx7-5p2p.json
+++ b/advisories/github-reviewed/2020/09/GHSA-h97g-4mx7-5p2p/GHSA-h97g-4mx7-5p2p.json
@@ -3,14 +3,10 @@
"id": "GHSA-h97g-4mx7-5p2p",
"modified": "2021-09-28T21:18:57Z",
"published": "2020-09-03T17:11:36Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Open Redirect in apostrophe",
"details": "Versions of `apostrophe` prior to 2.92.0 are vulnerable to Open Redirect. The package redirected requests to third-party websites if escaped URLs followed by a trailing `/` were appended at the end.\n\n\n\n## Recommendation\n\nUpdate to version 2.92.0 or later.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
diff --git a/advisories/github-reviewed/2020/09/GHSA-hq8g-qq57-5275/GHSA-hq8g-qq57-5275.json b/advisories/github-reviewed/2020/09/GHSA-hq8g-qq57-5275/GHSA-hq8g-qq57-5275.json
index 4cb12f1daf1..db881e03157 100644
--- a/advisories/github-reviewed/2020/09/GHSA-hq8g-qq57-5275/GHSA-hq8g-qq57-5275.json
+++ b/advisories/github-reviewed/2020/09/GHSA-hq8g-qq57-5275/GHSA-hq8g-qq57-5275.json
@@ -3,14 +3,10 @@
"id": "GHSA-hq8g-qq57-5275",
"modified": "2020-08-31T18:43:13Z",
"published": "2020-09-11T21:24:33Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "SQL Injection in untitled-model",
"details": "All versions of `untitled-model` re vulnerable to SQL Injection. Query parameters are not properly sanitized allowing attackers to inject SQL statements and execute arbitrary SQL queries.\n\n\n## Recommendation\n\nNo fix is currently available. Consider using an alternative package until a fix is made available.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
diff --git a/advisories/github-reviewed/2020/09/GHSA-j4vm-hg8g-g9qv/GHSA-j4vm-hg8g-g9qv.json b/advisories/github-reviewed/2020/09/GHSA-j4vm-hg8g-g9qv/GHSA-j4vm-hg8g-g9qv.json
index 41af8611fc9..c698ce2a744 100644
--- a/advisories/github-reviewed/2020/09/GHSA-j4vm-hg8g-g9qv/GHSA-j4vm-hg8g-g9qv.json
+++ b/advisories/github-reviewed/2020/09/GHSA-j4vm-hg8g-g9qv/GHSA-j4vm-hg8g-g9qv.json
@@ -3,9 +3,7 @@
"id": "GHSA-j4vm-hg8g-g9qv",
"modified": "2021-09-30T18:39:55Z",
"published": "2020-09-03T17:33:50Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Malicious Package in antd-cloud",
"details": "All versions of `antd-cloud` contain malicious code. The package uploads system information to a remote server, downloads a file and executes it.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.",
"severity": [
diff --git a/advisories/github-reviewed/2020/09/GHSA-j6v9-xgvh-f796/GHSA-j6v9-xgvh-f796.json b/advisories/github-reviewed/2020/09/GHSA-j6v9-xgvh-f796/GHSA-j6v9-xgvh-f796.json
index 4ad0ec1c29f..f37fd0b32dc 100644
--- a/advisories/github-reviewed/2020/09/GHSA-j6v9-xgvh-f796/GHSA-j6v9-xgvh-f796.json
+++ b/advisories/github-reviewed/2020/09/GHSA-j6v9-xgvh-f796/GHSA-j6v9-xgvh-f796.json
@@ -3,14 +3,10 @@
"id": "GHSA-j6v9-xgvh-f796",
"modified": "2020-08-31T18:42:04Z",
"published": "2020-09-11T21:11:34Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Command Injection in wxchangba",
"details": "All versions of `wxchangba` are vulnerable to Command Injection. The package does not validate user input on the `reqPostMaterial` function, passing contents of the `file` parameter to an exec call. This may allow attackers to run arbitrary commands in the system.\n\n\n## Recommendation\n\nNo fix is currently available. Consider using an alternative module until a fix is made available.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
diff --git a/advisories/github-reviewed/2020/09/GHSA-j8r2-2x94-2q67/GHSA-j8r2-2x94-2q67.json b/advisories/github-reviewed/2020/09/GHSA-j8r2-2x94-2q67/GHSA-j8r2-2x94-2q67.json
index 8ff304fe636..dc7958536c3 100644
--- a/advisories/github-reviewed/2020/09/GHSA-j8r2-2x94-2q67/GHSA-j8r2-2x94-2q67.json
+++ b/advisories/github-reviewed/2020/09/GHSA-j8r2-2x94-2q67/GHSA-j8r2-2x94-2q67.json
@@ -3,14 +3,10 @@
"id": "GHSA-j8r2-2x94-2q67",
"modified": "2021-09-28T16:59:50Z",
"published": "2020-09-11T21:19:09Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Cross-Site Scripting in diagram-js-direct-editing",
"details": "Versions of `diagram-js-direct-editing` prior to 1.4.3 are vulnerable to Cross-Site Scripting. The package fails to sanitize input from the clipboard, allowing attackers to execute arbitrary JavaScript in the victim's browser.\n\n\n## Recommendation\n\nUpgrade to version 1.4.3 or later.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
diff --git a/advisories/github-reviewed/2020/09/GHSA-jfx5-7mr2-g8hg/GHSA-jfx5-7mr2-g8hg.json b/advisories/github-reviewed/2020/09/GHSA-jfx5-7mr2-g8hg/GHSA-jfx5-7mr2-g8hg.json
index d0643a64221..63788d4734d 100644
--- a/advisories/github-reviewed/2020/09/GHSA-jfx5-7mr2-g8hg/GHSA-jfx5-7mr2-g8hg.json
+++ b/advisories/github-reviewed/2020/09/GHSA-jfx5-7mr2-g8hg/GHSA-jfx5-7mr2-g8hg.json
@@ -3,9 +3,7 @@
"id": "GHSA-jfx5-7mr2-g8hg",
"modified": "2021-09-30T18:35:26Z",
"published": "2020-09-03T17:31:41Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Malicious Package in alico",
"details": "All versions of `alico` contain malicious code. The package uploads system information to a remote server, downloads a file and executes it.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.",
"severity": [
diff --git a/advisories/github-reviewed/2020/09/GHSA-m9r7-q9fc-qwx5/GHSA-m9r7-q9fc-qwx5.json b/advisories/github-reviewed/2020/09/GHSA-m9r7-q9fc-qwx5/GHSA-m9r7-q9fc-qwx5.json
index ddc48954f01..99126633784 100644
--- a/advisories/github-reviewed/2020/09/GHSA-m9r7-q9fc-qwx5/GHSA-m9r7-q9fc-qwx5.json
+++ b/advisories/github-reviewed/2020/09/GHSA-m9r7-q9fc-qwx5/GHSA-m9r7-q9fc-qwx5.json
@@ -3,9 +3,7 @@
"id": "GHSA-m9r7-q9fc-qwx5",
"modified": "2021-09-30T17:43:47Z",
"published": "2020-09-03T17:22:24Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Malicious Package in maybemaliciouspackage",
"details": "All versions of `maybemaliciouspackage` contain malicious code. The package prints the system's SSH keys to the console as a postinstall script.\n\n\n## Recommendation\n\nRemove the package from your environment. There are no further signs of compromise.",
"severity": [
diff --git a/advisories/github-reviewed/2020/09/GHSA-qjfh-xc44-rm9x/GHSA-qjfh-xc44-rm9x.json b/advisories/github-reviewed/2020/09/GHSA-qjfh-xc44-rm9x/GHSA-qjfh-xc44-rm9x.json
index acd5dfca5bf..f7fc3fa8fc4 100644
--- a/advisories/github-reviewed/2020/09/GHSA-qjfh-xc44-rm9x/GHSA-qjfh-xc44-rm9x.json
+++ b/advisories/github-reviewed/2020/09/GHSA-qjfh-xc44-rm9x/GHSA-qjfh-xc44-rm9x.json
@@ -3,14 +3,10 @@
"id": "GHSA-qjfh-xc44-rm9x",
"modified": "2020-08-31T18:43:54Z",
"published": "2020-09-03T16:49:43Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Path Traversal in file-static-server",
"details": "All versions of `file-static-server` are vulnerable to Path Traversal. Due to insufficient input sanitization in URLs, attackers can access server files by using relative paths when fetching files. \n\n\n## Recommendation\n\nNo fix is currently available. Consider using an alternative module until a fix is made available.\n",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
diff --git a/advisories/github-reviewed/2020/09/GHSA-r32x-jhw5-g48p/GHSA-r32x-jhw5-g48p.json b/advisories/github-reviewed/2020/09/GHSA-r32x-jhw5-g48p/GHSA-r32x-jhw5-g48p.json
index a08866c6dc3..8afcc5e350b 100644
--- a/advisories/github-reviewed/2020/09/GHSA-r32x-jhw5-g48p/GHSA-r32x-jhw5-g48p.json
+++ b/advisories/github-reviewed/2020/09/GHSA-r32x-jhw5-g48p/GHSA-r32x-jhw5-g48p.json
@@ -3,14 +3,10 @@
"id": "GHSA-r32x-jhw5-g48p",
"modified": "2021-09-28T21:17:47Z",
"published": "2020-09-03T17:08:20Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Cross-Site Scripting in eco",
"details": "All versions of `eco` are vulnerable to Cross-Site Scripting (XSS). The package's default `__escape` implementation fails to escape single quotes, which may allow attackers to execute arbitrary JavaScript on the victim's browser.\n\n\n## Recommendation\n\nNo fix is currently available. Consider using an alternative package until a fix is made available.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
diff --git a/advisories/github-reviewed/2020/09/GHSA-r3xc-47qg-h929/GHSA-r3xc-47qg-h929.json b/advisories/github-reviewed/2020/09/GHSA-r3xc-47qg-h929/GHSA-r3xc-47qg-h929.json
index 48fe8a8fcad..ea54599ae79 100644
--- a/advisories/github-reviewed/2020/09/GHSA-r3xc-47qg-h929/GHSA-r3xc-47qg-h929.json
+++ b/advisories/github-reviewed/2020/09/GHSA-r3xc-47qg-h929/GHSA-r3xc-47qg-h929.json
@@ -3,14 +3,10 @@
"id": "GHSA-r3xc-47qg-h929",
"modified": "2021-09-28T17:38:45Z",
"published": "2020-09-03T17:06:09Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Cross-Site Scripting in @ionic/core",
"details": "Versions of `@ionic/core` prior to 4.0.3, 4.1.3, 4.2.1 or 4.3.1 are vulnerable to Cross-Site Scripting (XSS). The package uses the unsafe `innerHTML` function without sanitizing input, which may allow attackers to execute arbitrary JavaScript on the victim's browser. This issue affects the components:\n- `.message`\n- `.placeholder`\n- `.loadingText`\n- `.pullingText`\n- `.refershingText`\n\n\n## Recommendation\n\n- If you are using @ionic/core 4.0.x, upgrade to 4.0.3 or later.\n- If you are using @ionic/core 4.1.x, upgrade to 4.1.3 or later.\n- If you are using @ionic/core 4.2.x, upgrade to 4.2.1 or later.\n- If you are using @ionic/core 4.3.x, upgrade to 4.3.1 or later.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
diff --git a/advisories/github-reviewed/2020/09/GHSA-rjhc-w3fj-j6x9/GHSA-rjhc-w3fj-j6x9.json b/advisories/github-reviewed/2020/09/GHSA-rjhc-w3fj-j6x9/GHSA-rjhc-w3fj-j6x9.json
index 644f9ef19f5..3b508576184 100644
--- a/advisories/github-reviewed/2020/09/GHSA-rjhc-w3fj-j6x9/GHSA-rjhc-w3fj-j6x9.json
+++ b/advisories/github-reviewed/2020/09/GHSA-rjhc-w3fj-j6x9/GHSA-rjhc-w3fj-j6x9.json
@@ -3,9 +3,7 @@
"id": "GHSA-rjhc-w3fj-j6x9",
"modified": "2021-09-30T18:35:42Z",
"published": "2020-09-03T17:32:45Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Malicious Package in alipayjsapi",
"details": "All versions of `alipayjsapi` contain malicious code. The package uploads system information to a remote server, downloads a file and executes it.\n\n\n## Recommendation\n\nAny computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different computer.\n\nThe package should be removed, but as full control of the computer may have been given to an outside entity, there is no guarantee that removing the package will remove all malicious software resulting from installing it.",
"severity": [
diff --git a/advisories/github-reviewed/2020/09/GHSA-v6gv-fg46-h89j/GHSA-v6gv-fg46-h89j.json b/advisories/github-reviewed/2020/09/GHSA-v6gv-fg46-h89j/GHSA-v6gv-fg46-h89j.json
index 0c7ad88fa2c..e023cf54fde 100644
--- a/advisories/github-reviewed/2020/09/GHSA-v6gv-fg46-h89j/GHSA-v6gv-fg46-h89j.json
+++ b/advisories/github-reviewed/2020/09/GHSA-v6gv-fg46-h89j/GHSA-v6gv-fg46-h89j.json
@@ -3,14 +3,10 @@
"id": "GHSA-v6gv-fg46-h89j",
"modified": "2020-08-31T18:43:51Z",
"published": "2020-09-03T16:48:36Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Sensitive Data Exposure in put",
"details": "All versions of `put` are vulnerable to Uninitialized Memory Exposure. The package incorrectly calculates the allocated Buffer size and does not trim the bytes written, which may allow attackers to access uninitialized memory containing sensitive data. This vulnerability only affects versions of Node.js <=6.x.\n\n\n## Recommendation\n\nUpgrade your Node.js version or consider using an alternative package.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
diff --git a/advisories/github-reviewed/2020/09/GHSA-v7cp-5326-54fh/GHSA-v7cp-5326-54fh.json b/advisories/github-reviewed/2020/09/GHSA-v7cp-5326-54fh/GHSA-v7cp-5326-54fh.json
index 26aa7c574b8..0df2dd23932 100644
--- a/advisories/github-reviewed/2020/09/GHSA-v7cp-5326-54fh/GHSA-v7cp-5326-54fh.json
+++ b/advisories/github-reviewed/2020/09/GHSA-v7cp-5326-54fh/GHSA-v7cp-5326-54fh.json
@@ -3,14 +3,10 @@
"id": "GHSA-v7cp-5326-54fh",
"modified": "2020-08-31T18:43:34Z",
"published": "2020-09-03T16:45:15Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Path Traversal in bruteser",
"details": "Versions of `bruteser` prior to 0.1.0 are vulnerable to Path Traversal. The package fails to sanitize URLs, allowing attackers to access server files outside of the served folder using relative paths.\n\n\n## Recommendation\n\nUpgrade to version 0.1.0 or later.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
diff --git a/advisories/github-reviewed/2020/09/GHSA-v86x-f47q-f7f4/GHSA-v86x-f47q-f7f4.json b/advisories/github-reviewed/2020/09/GHSA-v86x-f47q-f7f4/GHSA-v86x-f47q-f7f4.json
index 80218f2741c..dfd67e0b3dd 100644
--- a/advisories/github-reviewed/2020/09/GHSA-v86x-f47q-f7f4/GHSA-v86x-f47q-f7f4.json
+++ b/advisories/github-reviewed/2020/09/GHSA-v86x-f47q-f7f4/GHSA-v86x-f47q-f7f4.json
@@ -3,14 +3,10 @@
"id": "GHSA-v86x-f47q-f7f4",
"modified": "2020-08-31T18:42:01Z",
"published": "2020-09-11T21:09:24Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Unauthorized File Access in atompm",
"details": "Versions of `atompm` prior to 0.8.2 are vulnerable to Unauthorized File Access. The package fails to sanitize relative paths in the URL for file downloads, allowing attackers to download arbitrary files from the system.\n\n\n## Recommendation\n\nUpgrade to version 0.8.2 or later.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
diff --git a/advisories/github-reviewed/2020/09/GHSA-v9wp-8r97-v6xg/GHSA-v9wp-8r97-v6xg.json b/advisories/github-reviewed/2020/09/GHSA-v9wp-8r97-v6xg/GHSA-v9wp-8r97-v6xg.json
index fe4046ba7bb..21d17bc76bc 100644
--- a/advisories/github-reviewed/2020/09/GHSA-v9wp-8r97-v6xg/GHSA-v9wp-8r97-v6xg.json
+++ b/advisories/github-reviewed/2020/09/GHSA-v9wp-8r97-v6xg/GHSA-v9wp-8r97-v6xg.json
@@ -3,14 +3,10 @@
"id": "GHSA-v9wp-8r97-v6xg",
"modified": "2020-08-31T18:44:56Z",
"published": "2020-09-03T17:17:00Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Cross-Site Scripting in jquery.json-viewer",
"details": "Versions of `jquery.json-viewer` prior to 1.3.0 are vulnerable to Cross-Site Scripting (XSS). The package insufficiently sanitizes user input when creating links, and concatenates the user input in an `` tag. This allows attackers to create malicious links with JSON payloads such as: \n```\n{\n \"foo\": \"https://bar.com\\\" onmouseover=alert('xss') \\\"\"\n}\n```\n\nThis may lead to arbitrary JavaScript execution in a victim's browser.\n\n\n## Recommendation\n\nUpgrade to version 1.3.0 or later.",
- "severity": [
-
- ],
+ "severity": [],
"affected": [
{
"package": {
diff --git a/advisories/github-reviewed/2020/09/GHSA-vp93-gcx5-4w52/GHSA-vp93-gcx5-4w52.json b/advisories/github-reviewed/2020/09/GHSA-vp93-gcx5-4w52/GHSA-vp93-gcx5-4w52.json
index 35fae074c27..71faa05cc59 100644
--- a/advisories/github-reviewed/2020/09/GHSA-vp93-gcx5-4w52/GHSA-vp93-gcx5-4w52.json
+++ b/advisories/github-reviewed/2020/09/GHSA-vp93-gcx5-4w52/GHSA-vp93-gcx5-4w52.json
@@ -3,14 +3,10 @@
"id": "GHSA-vp93-gcx5-4w52",
"modified": "2021-09-28T17:00:47Z",
"published": "2020-09-11T21:21:19Z",
- "aliases": [
-
- ],
+ "aliases": [],
"summary": "Cross-Site Scripting in swagger-ui",
"details": "Versions of `swagger-ui` prior to 2.2.1 are vulnerable to Cross-Site Scripting (XSS). The package fails to sanitize JSON schemas, allowing attackers to execute arbitrary JavaScript using `