From f68f7ebf01aca9f4edf5dd00999c49519ed7c4f8 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 21 Jan 2025 17:55:11 +0000 Subject: [PATCH] Publish Advisories GHSA-4hwq-4cpm-8vmx GHSA-3whq-64q2-qfj6 GHSA-5jrj-52x8-m64h GHSA-r56x-j438-vw5m GHSA-xchq-w5r3-4wg3 GHSA-92xg-gmrq-5c3w GHSA-3f84-rpwh-47g6 GHSA-576c-3j53-r9jj GHSA-77xq-6g77-h274 GHSA-89v2-pqfv-c5r9 GHSA-9298-4cf8-g4wj --- .../02/GHSA-4hwq-4cpm-8vmx/GHSA-4hwq-4cpm-8vmx.json | 6 +++++- .../04/GHSA-3whq-64q2-qfj6/GHSA-3whq-64q2-qfj6.json | 6 +++++- .../04/GHSA-5jrj-52x8-m64h/GHSA-5jrj-52x8-m64h.json | 6 +++++- .../04/GHSA-r56x-j438-vw5m/GHSA-r56x-j438-vw5m.json | 6 +++++- .../04/GHSA-xchq-w5r3-4wg3/GHSA-xchq-w5r3-4wg3.json | 6 +++++- .../09/GHSA-92xg-gmrq-5c3w/GHSA-92xg-gmrq-5c3w.json | 10 +++++++++- .../10/GHSA-3f84-rpwh-47g6/GHSA-3f84-rpwh-47g6.json | 10 +++++++++- .../10/GHSA-576c-3j53-r9jj/GHSA-576c-3j53-r9jj.json | 6 +++++- .../10/GHSA-77xq-6g77-h274/GHSA-77xq-6g77-h274.json | 6 +++++- .../10/GHSA-89v2-pqfv-c5r9/GHSA-89v2-pqfv-c5r9.json | 6 +++++- .../10/GHSA-9298-4cf8-g4wj/GHSA-9298-4cf8-g4wj.json | 6 +++++- 11 files changed, 63 insertions(+), 11 deletions(-) diff --git a/advisories/github-reviewed/2024/02/GHSA-4hwq-4cpm-8vmx/GHSA-4hwq-4cpm-8vmx.json b/advisories/github-reviewed/2024/02/GHSA-4hwq-4cpm-8vmx/GHSA-4hwq-4cpm-8vmx.json index 795ad1424e6..40f13aadd15 100644 --- a/advisories/github-reviewed/2024/02/GHSA-4hwq-4cpm-8vmx/GHSA-4hwq-4cpm-8vmx.json +++ b/advisories/github-reviewed/2024/02/GHSA-4hwq-4cpm-8vmx/GHSA-4hwq-4cpm-8vmx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4hwq-4cpm-8vmx", - "modified": "2024-10-09T19:31:00Z", + "modified": "2025-01-21T17:54:09Z", "published": "2024-02-26T20:11:35Z", "aliases": [ "CVE-2024-24564" @@ -51,6 +51,10 @@ "type": "WEB", "url": "https://github.com/vyperlang/vyper/commit/3d9c537142fb99b2672f21e2057f5f202cde194f" }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/vyper/PYSEC-2024-205.yaml" + }, { "type": "PACKAGE", "url": "https://github.com/vyperlang/vyper" diff --git a/advisories/github-reviewed/2024/04/GHSA-3whq-64q2-qfj6/GHSA-3whq-64q2-qfj6.json b/advisories/github-reviewed/2024/04/GHSA-3whq-64q2-qfj6/GHSA-3whq-64q2-qfj6.json index dfd83da5d18..ee05f7ed806 100644 --- a/advisories/github-reviewed/2024/04/GHSA-3whq-64q2-qfj6/GHSA-3whq-64q2-qfj6.json +++ b/advisories/github-reviewed/2024/04/GHSA-3whq-64q2-qfj6/GHSA-3whq-64q2-qfj6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3whq-64q2-qfj6", - "modified": "2024-06-18T15:08:56Z", + "modified": "2025-01-21T17:53:51Z", "published": "2024-04-25T19:50:50Z", "aliases": [ "CVE-2024-32647" @@ -44,6 +44,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32647" }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/vyper/PYSEC-2024-208.yaml" + }, { "type": "PACKAGE", "url": "https://github.com/vyperlang/vyper" diff --git a/advisories/github-reviewed/2024/04/GHSA-5jrj-52x8-m64h/GHSA-5jrj-52x8-m64h.json b/advisories/github-reviewed/2024/04/GHSA-5jrj-52x8-m64h/GHSA-5jrj-52x8-m64h.json index eb605e44003..d19b4c0e219 100644 --- a/advisories/github-reviewed/2024/04/GHSA-5jrj-52x8-m64h/GHSA-5jrj-52x8-m64h.json +++ b/advisories/github-reviewed/2024/04/GHSA-5jrj-52x8-m64h/GHSA-5jrj-52x8-m64h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5jrj-52x8-m64h", - "modified": "2024-06-18T15:04:13Z", + "modified": "2025-01-21T17:53:44Z", "published": "2024-04-25T19:50:16Z", "aliases": [ "CVE-2024-32649" @@ -48,6 +48,10 @@ "type": "WEB", "url": "https://github.com/vyperlang/vyper/pull/2914" }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/vyper/PYSEC-2024-209.yaml" + }, { "type": "PACKAGE", "url": "https://github.com/vyperlang/vyper" diff --git a/advisories/github-reviewed/2024/04/GHSA-r56x-j438-vw5m/GHSA-r56x-j438-vw5m.json b/advisories/github-reviewed/2024/04/GHSA-r56x-j438-vw5m/GHSA-r56x-j438-vw5m.json index 02314110172..ab2298be618 100644 --- a/advisories/github-reviewed/2024/04/GHSA-r56x-j438-vw5m/GHSA-r56x-j438-vw5m.json +++ b/advisories/github-reviewed/2024/04/GHSA-r56x-j438-vw5m/GHSA-r56x-j438-vw5m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r56x-j438-vw5m", - "modified": "2024-06-18T15:02:55Z", + "modified": "2025-01-21T17:53:57Z", "published": "2024-04-25T19:51:41Z", "aliases": [ "CVE-2024-32646" @@ -48,6 +48,10 @@ "type": "WEB", "url": "https://github.com/vyperlang/vyper/pull/2914" }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/vyper/PYSEC-2024-207.yaml" + }, { "type": "PACKAGE", "url": "https://github.com/vyperlang/vyper" diff --git a/advisories/github-reviewed/2024/04/GHSA-xchq-w5r3-4wg3/GHSA-xchq-w5r3-4wg3.json b/advisories/github-reviewed/2024/04/GHSA-xchq-w5r3-4wg3/GHSA-xchq-w5r3-4wg3.json index 9745d8c6f70..f493c0987e6 100644 --- a/advisories/github-reviewed/2024/04/GHSA-xchq-w5r3-4wg3/GHSA-xchq-w5r3-4wg3.json +++ b/advisories/github-reviewed/2024/04/GHSA-xchq-w5r3-4wg3/GHSA-xchq-w5r3-4wg3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xchq-w5r3-4wg3", - "modified": "2024-06-18T15:01:23Z", + "modified": "2025-01-21T17:54:04Z", "published": "2024-04-25T19:53:10Z", "aliases": [ "CVE-2024-32645" @@ -44,6 +44,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32645" }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/vyper/PYSEC-2024-206.yaml" + }, { "type": "PACKAGE", "url": "https://github.com/vyperlang/vyper" diff --git a/advisories/github-reviewed/2024/09/GHSA-92xg-gmrq-5c3w/GHSA-92xg-gmrq-5c3w.json b/advisories/github-reviewed/2024/09/GHSA-92xg-gmrq-5c3w/GHSA-92xg-gmrq-5c3w.json index f3d1e3a9f8a..bfa4ac3eb8a 100644 --- a/advisories/github-reviewed/2024/09/GHSA-92xg-gmrq-5c3w/GHSA-92xg-gmrq-5c3w.json +++ b/advisories/github-reviewed/2024/09/GHSA-92xg-gmrq-5c3w/GHSA-92xg-gmrq-5c3w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-92xg-gmrq-5c3w", - "modified": "2024-09-09T18:16:43Z", + "modified": "2025-01-21T17:53:29Z", "published": "2024-09-07T09:30:31Z", "aliases": [ "CVE-2024-45034" @@ -56,9 +56,17 @@ "type": "PACKAGE", "url": "https://github.com/apache/airflow" }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/apache-airflow/PYSEC-2024-212.yaml" + }, { "type": "WEB", "url": "https://lists.apache.org/thread/b4fcw33vh60yfg9990n5vmc7sy2dcgjx" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/09/06/3" } ], "database_specific": { diff --git a/advisories/github-reviewed/2024/10/GHSA-3f84-rpwh-47g6/GHSA-3f84-rpwh-47g6.json b/advisories/github-reviewed/2024/10/GHSA-3f84-rpwh-47g6/GHSA-3f84-rpwh-47g6.json index b20955efc8e..95ffaa6f5a5 100644 --- a/advisories/github-reviewed/2024/10/GHSA-3f84-rpwh-47g6/GHSA-3f84-rpwh-47g6.json +++ b/advisories/github-reviewed/2024/10/GHSA-3f84-rpwh-47g6/GHSA-3f84-rpwh-47g6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3f84-rpwh-47g6", - "modified": "2024-10-29T20:00:26Z", + "modified": "2025-01-21T17:53:27Z", "published": "2024-10-29T14:33:00Z", "aliases": [ "CVE-2024-49769" @@ -63,6 +63,14 @@ { "type": "PACKAGE", "url": "https://github.com/Pylons/waitress" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/waitress/PYSEC-2024-211.yaml" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2024/11/msg00012.html" } ], "database_specific": { diff --git a/advisories/github-reviewed/2024/10/GHSA-576c-3j53-r9jj/GHSA-576c-3j53-r9jj.json b/advisories/github-reviewed/2024/10/GHSA-576c-3j53-r9jj/GHSA-576c-3j53-r9jj.json index 8da30090621..902afb436dd 100644 --- a/advisories/github-reviewed/2024/10/GHSA-576c-3j53-r9jj/GHSA-576c-3j53-r9jj.json +++ b/advisories/github-reviewed/2024/10/GHSA-576c-3j53-r9jj/GHSA-576c-3j53-r9jj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-576c-3j53-r9jj", - "modified": "2024-10-11T15:34:23Z", + "modified": "2025-01-21T17:53:33Z", "published": "2024-10-10T22:01:44Z", "aliases": [ "CVE-2024-47167" @@ -51,6 +51,10 @@ { "type": "PACKAGE", "url": "https://github.com/gradio-app/gradio" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/gradio/PYSEC-2024-215.yaml" } ], "database_specific": { diff --git a/advisories/github-reviewed/2024/10/GHSA-77xq-6g77-h274/GHSA-77xq-6g77-h274.json b/advisories/github-reviewed/2024/10/GHSA-77xq-6g77-h274/GHSA-77xq-6g77-h274.json index 1cba985a841..855492a133e 100644 --- a/advisories/github-reviewed/2024/10/GHSA-77xq-6g77-h274/GHSA-77xq-6g77-h274.json +++ b/advisories/github-reviewed/2024/10/GHSA-77xq-6g77-h274/GHSA-77xq-6g77-h274.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-77xq-6g77-h274", - "modified": "2024-10-11T15:33:40Z", + "modified": "2025-01-21T17:53:30Z", "published": "2024-10-10T21:27:47Z", "aliases": [ "CVE-2024-47164" @@ -55,6 +55,10 @@ { "type": "PACKAGE", "url": "https://github.com/gradio-app/gradio" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/gradio/PYSEC-2024-213.yaml" } ], "database_specific": { diff --git a/advisories/github-reviewed/2024/10/GHSA-89v2-pqfv-c5r9/GHSA-89v2-pqfv-c5r9.json b/advisories/github-reviewed/2024/10/GHSA-89v2-pqfv-c5r9/GHSA-89v2-pqfv-c5r9.json index 7a2295911d6..7c7e226fc79 100644 --- a/advisories/github-reviewed/2024/10/GHSA-89v2-pqfv-c5r9/GHSA-89v2-pqfv-c5r9.json +++ b/advisories/github-reviewed/2024/10/GHSA-89v2-pqfv-c5r9/GHSA-89v2-pqfv-c5r9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-89v2-pqfv-c5r9", - "modified": "2024-10-11T15:34:03Z", + "modified": "2025-01-21T17:53:31Z", "published": "2024-10-10T21:36:36Z", "aliases": [ "CVE-2024-47165" @@ -51,6 +51,10 @@ { "type": "PACKAGE", "url": "https://github.com/gradio-app/gradio" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/gradio/PYSEC-2024-214.yaml" } ], "database_specific": { diff --git a/advisories/github-reviewed/2024/10/GHSA-9298-4cf8-g4wj/GHSA-9298-4cf8-g4wj.json b/advisories/github-reviewed/2024/10/GHSA-9298-4cf8-g4wj/GHSA-9298-4cf8-g4wj.json index c5639817eb9..c5b6fdfea8d 100644 --- a/advisories/github-reviewed/2024/10/GHSA-9298-4cf8-g4wj/GHSA-9298-4cf8-g4wj.json +++ b/advisories/github-reviewed/2024/10/GHSA-9298-4cf8-g4wj/GHSA-9298-4cf8-g4wj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9298-4cf8-g4wj", - "modified": "2024-10-29T20:00:21Z", + "modified": "2025-01-21T17:53:26Z", "published": "2024-10-29T14:45:03Z", "aliases": [ "CVE-2024-49768" @@ -55,6 +55,10 @@ { "type": "PACKAGE", "url": "https://github.com/Pylons/waitress" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/waitress/PYSEC-2024-210.yaml" } ], "database_specific": {