diff --git a/advisories/unreviewed/2023/04/GHSA-354q-38f3-jh4j/GHSA-354q-38f3-jh4j.json b/advisories/unreviewed/2023/04/GHSA-354q-38f3-jh4j/GHSA-354q-38f3-jh4j.json index a02e57bec13..9b15cc4f5d3 100644 --- a/advisories/unreviewed/2023/04/GHSA-354q-38f3-jh4j/GHSA-354q-38f3-jh4j.json +++ b/advisories/unreviewed/2023/04/GHSA-354q-38f3-jh4j/GHSA-354q-38f3-jh4j.json @@ -36,6 +36,10 @@ { "type": "WEB", "url": "https://lore.kernel.org/lkml/ZD1xyZxb3rHot8PV@redhat.com/t/" + }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2023/dsa-5448" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/04/GHSA-f886-x4w4-9rwj/GHSA-f886-x4w4-9rwj.json b/advisories/unreviewed/2023/04/GHSA-f886-x4w4-9rwj/GHSA-f886-x4w4-9rwj.json index 940df5da239..467ad4a262e 100644 --- a/advisories/unreviewed/2023/04/GHSA-f886-x4w4-9rwj/GHSA-f886-x4w4-9rwj.json +++ b/advisories/unreviewed/2023/04/GHSA-f886-x4w4-9rwj/GHSA-f886-x4w4-9rwj.json @@ -32,6 +32,10 @@ { "type": "WEB", "url": "https://lore.kernel.org/all/CA+UBctCu7fXn4q41O_3=id1+OdyQ85tZY1x+TkT-6OVBL6KAUw@mail.gmail.com/" + }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2023/dsa-5448" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/05/GHSA-7jf7-rx7v-xwqq/GHSA-7jf7-rx7v-xwqq.json b/advisories/unreviewed/2023/05/GHSA-7jf7-rx7v-xwqq/GHSA-7jf7-rx7v-xwqq.json index 420ceed4cb6..1eadb39a07f 100644 --- a/advisories/unreviewed/2023/05/GHSA-7jf7-rx7v-xwqq/GHSA-7jf7-rx7v-xwqq.json +++ b/advisories/unreviewed/2023/05/GHSA-7jf7-rx7v-xwqq/GHSA-7jf7-rx7v-xwqq.json @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20230622-0001/" }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2023/dsa-5448" + }, { "type": "WEB", "url": "https://www.zerodayinitiative.com/advisories/ZDI-23-547/" diff --git a/advisories/unreviewed/2023/06/GHSA-295v-9m5g-79q9/GHSA-295v-9m5g-79q9.json b/advisories/unreviewed/2023/06/GHSA-295v-9m5g-79q9/GHSA-295v-9m5g-79q9.json index 67133961767..549f2c6dab0 100644 --- a/advisories/unreviewed/2023/06/GHSA-295v-9m5g-79q9/GHSA-295v-9m5g-79q9.json +++ b/advisories/unreviewed/2023/06/GHSA-295v-9m5g-79q9/GHSA-295v-9m5g-79q9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-295v-9m5g-79q9", - "modified": "2023-06-28T21:30:29Z", + "modified": "2023-07-06T06:30:17Z", "published": "2023-06-28T21:30:29Z", "aliases": [ "CVE-2023-3090" @@ -28,6 +28,10 @@ { "type": "WEB", "url": "https://kernel.dance/90cbed5247439a966b645b34eb0a2e037836ea8e" + }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2023/dsa-5448" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/06/GHSA-7jpg-h873-5g68/GHSA-7jpg-h873-5g68.json b/advisories/unreviewed/2023/06/GHSA-7jpg-h873-5g68/GHSA-7jpg-h873-5g68.json index 8f67f46113b..74330cd5dc3 100644 --- a/advisories/unreviewed/2023/06/GHSA-7jpg-h873-5g68/GHSA-7jpg-h873-5g68.json +++ b/advisories/unreviewed/2023/06/GHSA-7jpg-h873-5g68/GHSA-7jpg-h873-5g68.json @@ -29,6 +29,10 @@ "type": "WEB", "url": "https://git.kernel.org/linus/4d56304e5827c8cc8cc18c75343d283af7c4825c" }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2023/dsa-5448" + }, { "type": "WEB", "url": "https://www.openwall.com/lists/oss-security/2023/06/07/1" diff --git a/advisories/unreviewed/2023/06/GHSA-fhf9-47gc-m9wc/GHSA-fhf9-47gc-m9wc.json b/advisories/unreviewed/2023/06/GHSA-fhf9-47gc-m9wc/GHSA-fhf9-47gc-m9wc.json index 1e03ed2d88e..7f8e2ede0fa 100644 --- a/advisories/unreviewed/2023/06/GHSA-fhf9-47gc-m9wc/GHSA-fhf9-47gc-m9wc.json +++ b/advisories/unreviewed/2023/06/GHSA-fhf9-47gc-m9wc/GHSA-fhf9-47gc-m9wc.json @@ -28,6 +28,10 @@ { "type": "WEB", "url": "https://www.papercut.com/" + }, + { + "type": "WEB", + "url": "https://www.papercut.com/kb/Main/SecurityBulletinJune2023" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/06/GHSA-h6hv-h4xf-gmgh/GHSA-h6hv-h4xf-gmgh.json b/advisories/unreviewed/2023/06/GHSA-h6hv-h4xf-gmgh/GHSA-h6hv-h4xf-gmgh.json index 41fb5945b5f..1fbf0e20011 100644 --- a/advisories/unreviewed/2023/06/GHSA-h6hv-h4xf-gmgh/GHSA-h6hv-h4xf-gmgh.json +++ b/advisories/unreviewed/2023/06/GHSA-h6hv-h4xf-gmgh/GHSA-h6hv-h4xf-gmgh.json @@ -28,6 +28,10 @@ { "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2214348" + }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2023/dsa-5448" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/06/GHSA-r2p2-3cx2-xc3r/GHSA-r2p2-3cx2-xc3r.json b/advisories/unreviewed/2023/06/GHSA-r2p2-3cx2-xc3r/GHSA-r2p2-3cx2-xc3r.json index 67e8804b5a0..cb7cc5f8dcb 100644 --- a/advisories/unreviewed/2023/06/GHSA-r2p2-3cx2-xc3r/GHSA-r2p2-3cx2-xc3r.json +++ b/advisories/unreviewed/2023/06/GHSA-r2p2-3cx2-xc3r/GHSA-r2p2-3cx2-xc3r.json @@ -24,6 +24,10 @@ { "type": "WEB", "url": "https://lore.kernel.org/lkml/1682238502-1892-1-git-send-email-yangpc@wangsu.com/T/" + }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2023/dsa-5448" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/06/GHSA-vj8j-762w-6jmv/GHSA-vj8j-762w-6jmv.json b/advisories/unreviewed/2023/06/GHSA-vj8j-762w-6jmv/GHSA-vj8j-762w-6jmv.json index ec4d50a3cc5..8a4dbfa093b 100644 --- a/advisories/unreviewed/2023/06/GHSA-vj8j-762w-6jmv/GHSA-vj8j-762w-6jmv.json +++ b/advisories/unreviewed/2023/06/GHSA-vj8j-762w-6jmv/GHSA-vj8j-762w-6jmv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vj8j-762w-6jmv", - "modified": "2023-06-28T21:30:30Z", + "modified": "2023-07-06T06:30:17Z", "published": "2023-06-28T21:30:30Z", "aliases": [ "CVE-2023-3390" @@ -28,6 +28,10 @@ { "type": "WEB", "url": "https://kernel.dance/1240eb93f0616b21c675416516ff3d74798fdc97" + }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2023/dsa-5448" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/07/GHSA-3jvv-m32r-4hpf/GHSA-3jvv-m32r-4hpf.json b/advisories/unreviewed/2023/07/GHSA-3jvv-m32r-4hpf/GHSA-3jvv-m32r-4hpf.json new file mode 100644 index 00000000000..6379f75bb23 --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-3jvv-m32r-4hpf/GHSA-3jvv-m32r-4hpf.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3jvv-m32r-4hpf", + "modified": "2023-07-06T06:30:17Z", + "published": "2023-07-06T06:30:17Z", + "aliases": [ + "CVE-2023-26138" + ], + "details": "All versions of the package drogonframework/drogon are vulnerable to CRLF Injection when untrusted user input is used to set request headers in the addHeader function. An attacker can add the \\r\\n (carriage return line feeds) characters and inject additional headers in the request sent.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26138" + }, + { + "type": "WEB", + "url": "https://gist.github.com/dellalibera/d2abd809f32ec6c61be1f41d80edf61b" + }, + { + "type": "WEB", + "url": "https://security.snyk.io/vuln/SNYK-UNMANAGED-DROGONFRAMEWORKDROGON-5665555" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2023/07/GHSA-73h3-w2hp-q47q/GHSA-73h3-w2hp-q47q.json b/advisories/unreviewed/2023/07/GHSA-73h3-w2hp-q47q/GHSA-73h3-w2hp-q47q.json new file mode 100644 index 00000000000..a1ed9e3f3ff --- /dev/null +++ b/advisories/unreviewed/2023/07/GHSA-73h3-w2hp-q47q/GHSA-73h3-w2hp-q47q.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-73h3-w2hp-q47q", + "modified": "2023-07-06T06:30:17Z", + "published": "2023-07-06T06:30:17Z", + "aliases": [ + "CVE-2023-26137" + ], + "details": "All versions of the package drogonframework/drogon are vulnerable to HTTP Response Splitting when untrusted user input is used to build header values in the addHeader and addCookie functions. An attacker can add the \\r\\n (carriage return line feeds) characters to end the HTTP response headers and inject malicious content.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-26137" + }, + { + "type": "WEB", + "url": "https://gist.github.com/dellalibera/666d67165830ded052a1ede2d2c0b02a" + }, + { + "type": "WEB", + "url": "https://security.snyk.io/vuln/SNYK-UNMANAGED-DROGONFRAMEWORKDROGON-5665554" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": null + } +} \ No newline at end of file