diff --git a/advisories/github-reviewed/2020/09/GHSA-vwcg-7xqw-qcxw/GHSA-vwcg-7xqw-qcxw.json b/advisories/github-reviewed/2020/09/GHSA-vwcg-7xqw-qcxw/GHSA-vwcg-7xqw-qcxw.json index 170ab9b7ce9..e6391db64cb 100644 --- a/advisories/github-reviewed/2020/09/GHSA-vwcg-7xqw-qcxw/GHSA-vwcg-7xqw-qcxw.json +++ b/advisories/github-reviewed/2020/09/GHSA-vwcg-7xqw-qcxw/GHSA-vwcg-7xqw-qcxw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vwcg-7xqw-qcxw", - "modified": "2020-09-18T14:06:03Z", + "modified": "2024-10-21T20:25:05Z", "published": "2020-09-18T18:03:59Z", "aliases": [ "CVE-2020-25489" @@ -9,7 +9,14 @@ "summary": "Heap Overflow in PyMiniRacer", "details": "A heap overflow in Sqreen PyMiniRacer (aka Python Mini Racer) before 0.3.0 allows remote attackers to potentially exploit heap corruption.\n\nMore details on https://blog.sqreen.com/vulnerability-disclosure-finding-a-vulnerability-in-sqreens-php-agent-and-how-we-fixed-it/.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P" + } ], "affected": [ { @@ -49,6 +56,14 @@ "type": "WEB", "url": "https://blog.sqreen.com/vulnerability-disclosure-finding-a-vulnerability-in-sqreens-php-agent-and-how-we-fixed-it" }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/py-mini-racer/PYSEC-2020-93.yaml" + }, + { + "type": "PACKAGE", + "url": "https://github.com/sqreen/PyMiniRacer" + }, { "type": "WEB", "url": "https://github.com/sqreen/PyMiniRacer/compare/v0.2.0...v0.3.0" @@ -58,7 +73,7 @@ "cwe_ids": [ "CWE-119" ], - "severity": "MODERATE", + "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2020-09-18T14:06:03Z", "nvd_published_at": null diff --git a/advisories/github-reviewed/2022/09/GHSA-9xgj-fcgf-x6mw/GHSA-9xgj-fcgf-x6mw.json b/advisories/github-reviewed/2022/09/GHSA-9xgj-fcgf-x6mw/GHSA-9xgj-fcgf-x6mw.json index 18e57caaf33..6540c30109f 100644 --- a/advisories/github-reviewed/2022/09/GHSA-9xgj-fcgf-x6mw/GHSA-9xgj-fcgf-x6mw.json +++ b/advisories/github-reviewed/2022/09/GHSA-9xgj-fcgf-x6mw/GHSA-9xgj-fcgf-x6mw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9xgj-fcgf-x6mw", - "modified": "2022-10-11T18:36:17Z", + "modified": "2024-10-21T20:25:55Z", "published": "2022-09-16T19:26:59Z", "aliases": [ "CVE-2022-36069" @@ -12,6 +12,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P" } ], "affected": [