Publish Advisories

GHSA-4w53-6jvp-gg52
GHSA-r3w4-36x6-7r99
GHSA-wchx-rm6h-7jf6
This commit is contained in:
advisory-database[bot]
2024-05-14 22:32:07 +00:00
parent 230ade32e8
commit fc90463e6d
3 changed files with 154 additions and 4 deletions
File diff suppressed because one or more lines are too long
@@ -0,0 +1,62 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r3w4-36x6-7r99",
"modified": "2024-05-14T22:30:46Z",
"published": "2024-05-14T22:30:45Z",
"aliases": [
],
"summary": "Nokogiri updates packaged libxml2 to v2.12.7 to resolve CVE-2024-34459",
"details": "## Summary\n\nNokogiri v1.16.5 upgrades its dependency libxml2 to\n[2.12.7](https://gitlab.gnome.org/GNOME/libxml2/-/releases/v2.12.7) from 2.12.6.\n\nlibxml2 v2.12.7 addresses CVE-2024-34459:\n\n- described at https://gitlab.gnome.org/GNOME/libxml2/-/issues/720\n- patched by https://gitlab.gnome.org/GNOME/libxml2/-/commit/2876ac53\n\n## Impact\n\nThere is no impact to Nokogiri users because the issue is present only\nin libxml2's `xmllint` tool which Nokogiri does not provide or expose.\n\n## Timeline\n\n- 2024-05-13 05:57 EDT, libxml2 2.12.7 release is announced\n- 2024-05-13 08:30 EDT, nokogiri maintainers begin triage\n- 2024-05-13 10:05 EDT, nokogiri [v1.16.5 is released](https://github.com/sparklemotion/nokogiri/releases/tag/v1.16.5)\n and this GHSA made public\n",
"severity": [
],
"affected": [
{
"package": {
"ecosystem": "RubyGems",
"name": "nokogiri"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "1.16.5"
}
]
}
]
}
],
"references": [
{
"type": "WEB",
"url": "https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-r95h-9x8f-r3f7"
},
{
"type": "WEB",
"url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/nokogiri/GHSA-r95h-9x8f-r3f7.yml"
},
{
"type": "PACKAGE",
"url": "https://github.com/sparklemotion/nokogiri"
},
{
"type": "WEB",
"url": "https://gitlab.gnome.org/GNOME/libxml2/-/issues/720"
}
],
"database_specific": {
"cwe_ids": [
"CWE-119"
],
"severity": "LOW",
"github_reviewed": true,
"github_reviewed_at": "2024-05-14T22:30:45Z",
"nvd_published_at": null
}
}
@@ -1,11 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wchx-rm6h-7jf6",
"modified": "2024-05-14T18:31:05Z",
"modified": "2024-05-14T22:31:39Z",
"published": "2024-05-14T18:31:05Z",
"aliases": [
"CVE-2024-30054"
],
"summary": "Microsoft Power BI Client JavaScript SDK Information Disclosure Vulnerability",
"details": "Microsoft Power BI Client JavaScript SDK Information Disclosure Vulnerability",
"severity": [
{
@@ -14,13 +15,35 @@
}
],
"affected": [
{
"package": {
"ecosystem": "NuGet",
"name": "Microsoft.PowerBI.JavaScript"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.23.0"
}
]
}
]
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30054"
},
{
"type": "PACKAGE",
"url": "https://github.com/microsoft/PowerBI-JavaScript"
},
{
"type": "WEB",
"url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30054"
@@ -31,8 +54,8 @@
"CWE-20"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"github_reviewed": true,
"github_reviewed_at": "2024-05-14T22:31:39Z",
"nvd_published_at": "2024-05-14T17:17:22Z"
}
}