Publish Advisories

GHSA-v84f-6r39-cpfc
GHSA-c866-8gpw-p3mv
GHSA-6q97-8v3g-rpxw
GHSA-jwcg-wv5x-vg3g
GHSA-6375-pg5j-8wph
GHSA-g54f-66mw-hv66
GHSA-h355-hm5h-cm8h
GHSA-j827-6rgf-9629
GHSA-mpch-89gm-hm83
GHSA-rw3j-574h-mrcq
GHSA-wc43-73w7-x2f5
This commit is contained in:
advisory-database[bot]
2024-09-26 21:11:51 +00:00
parent 2320d40f84
commit ff2b7111d9
11 changed files with 127 additions and 17 deletions
@@ -89,7 +89,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-20"
"CWE-20",
"CWE-323"
],
"severity": "MODERATE",
"github_reviewed": true,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c866-8gpw-p3mv",
"modified": "2024-02-09T15:08:40Z",
"modified": "2024-09-26T21:10:36Z",
"published": "2024-02-08T21:30:38Z",
"aliases": [
"CVE-2024-1329"
@@ -114,6 +114,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-59",
"CWE-610"
],
"severity": "HIGH",
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6q97-8v3g-rpxw",
"modified": "2024-06-12T19:45:11Z",
"modified": "2024-09-26T21:11:10Z",
"published": "2024-06-12T15:31:45Z",
"aliases": [
"CVE-2024-36265"
@@ -33,6 +33,22 @@
]
}
]
},
{
"package": {
"ecosystem": "PyPI",
"name": "apache-submarine"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0.8.0"
}
]
}
]
}
],
"references": [
@@ -44,6 +60,10 @@
"type": "PACKAGE",
"url": "https://github.com/apache/submarine"
},
{
"type": "WEB",
"url": "https://github.com/pypa/advisory-database/tree/main/vulns/apache-submarine/PYSEC-2024-98.yaml"
},
{
"type": "WEB",
"url": "https://lists.apache.org/thread/prckhhst19qxof064hsm8cccxtofvflz"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jwcg-wv5x-vg3g",
"modified": "2024-09-26T16:31:14Z",
"modified": "2024-09-26T21:11:09Z",
"published": "2024-06-12T15:31:44Z",
"aliases": [
"CVE-2024-36264"
@@ -33,6 +33,22 @@
]
}
]
},
{
"package": {
"ecosystem": "PyPI",
"name": "apache-submarine"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0.8.0"
}
]
}
]
}
],
"references": [
@@ -52,6 +68,10 @@
"type": "PACKAGE",
"url": "https://github.com/apache/submarine"
},
{
"type": "WEB",
"url": "https://github.com/pypa/advisory-database/tree/main/vulns/apache-submarine/PYSEC-2024-97.yaml"
},
{
"type": "WEB",
"url": "https://issues.apache.org/jira/browse/SUBMARINE-1417"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6375-pg5j-8wph",
"modified": "2024-09-25T18:51:16Z",
"modified": "2024-09-26T21:10:27Z",
"published": "2024-09-25T03:30:36Z",
"aliases": [
"CVE-2024-46935"
@@ -9,6 +9,10 @@
"summary": "Denial of service in rocket chat message parser",
"details": "Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier is vulnerable to denial of service (DoS). Attackers who craft messages with specific characters may crash the workspace due to an issue in the message parser.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g54f-66mw-hv66",
"modified": "2024-09-26T18:16:13Z",
"modified": "2024-09-26T21:11:07Z",
"published": "2024-09-26T18:16:13Z",
"aliases": [
"CVE-2024-47171"
@@ -44,6 +44,10 @@
"type": "WEB",
"url": "https://github.com/agnaistic/agnai/security/advisories/GHSA-g54f-66mw-hv66"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47171"
},
{
"type": "PACKAGE",
"url": "https://github.com/agnaistic/agnai"
@@ -65,6 +69,6 @@
"severity": "LOW",
"github_reviewed": true,
"github_reviewed_at": "2024-09-26T18:16:13Z",
"nvd_published_at": null
"nvd_published_at": "2024-09-26T18:15:10Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h355-hm5h-cm8h",
"modified": "2024-09-26T18:07:52Z",
"modified": "2024-09-26T21:11:05Z",
"published": "2024-09-26T18:07:52Z",
"aliases": [
"CVE-2024-47170"
@@ -44,6 +44,10 @@
"type": "WEB",
"url": "https://github.com/agnaistic/agnai/security/advisories/GHSA-h355-hm5h-cm8h"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47170"
},
{
"type": "PACKAGE",
"url": "https://github.com/agnaistic/agnai"
@@ -57,6 +61,6 @@
"severity": "LOW",
"github_reviewed": true,
"github_reviewed_at": "2024-09-26T18:07:52Z",
"nvd_published_at": null
"nvd_published_at": "2024-09-26T18:15:10Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j827-6rgf-9629",
"modified": "2024-09-26T17:54:24Z",
"modified": "2024-09-26T21:11:02Z",
"published": "2024-09-26T17:54:24Z",
"aliases": [
"CVE-2024-47075"
@@ -44,6 +44,10 @@
"type": "WEB",
"url": "https://github.com/layui/layui/security/advisories/GHSA-j827-6rgf-9629"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47075"
},
{
"type": "WEB",
"url": "https://github.com/layui/layui/commit/f756b41d63bf3d488a2cb042918638c9851bf2b0"
@@ -64,6 +68,6 @@
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-09-26T17:54:24Z",
"nvd_published_at": null
"nvd_published_at": "2024-09-26T18:15:08Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mpch-89gm-hm83",
"modified": "2024-09-26T18:05:12Z",
"modified": "2024-09-26T21:11:04Z",
"published": "2024-09-26T18:05:12Z",
"aliases": [
"CVE-2024-47169"
@@ -44,6 +44,10 @@
"type": "WEB",
"url": "https://github.com/agnaistic/agnai/security/advisories/GHSA-mpch-89gm-hm83"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47169"
},
{
"type": "PACKAGE",
"url": "https://github.com/agnaistic/agnai"
@@ -58,6 +62,6 @@
"severity": "CRITICAL",
"github_reviewed": true,
"github_reviewed_at": "2024-09-26T18:05:12Z",
"nvd_published_at": null
"nvd_published_at": "2024-09-26T18:15:10Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rw3j-574h-mrcq",
"modified": "2024-09-26T17:38:30Z",
"modified": "2024-09-26T21:10:59Z",
"published": "2024-09-26T17:38:30Z",
"aliases": [
"CVE-2024-39319"
@@ -123,6 +123,50 @@
"type": "WEB",
"url": "https://github.com/aimeos/ai-controller-frontend/security/advisories/GHSA-rw3j-574h-mrcq"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39319"
},
{
"type": "WEB",
"url": "https://github.com/aimeos/ai-controller-frontend/commit/2ad5c062a629af374da470a319914c321c9bfee2"
},
{
"type": "WEB",
"url": "https://github.com/aimeos/ai-controller-frontend/commit/53eebdc51fae34440dfd768a7811c169c7779aa9"
},
{
"type": "WEB",
"url": "https://github.com/aimeos/ai-controller-frontend/commit/5833db6d18a889b94dc036dfb84b6f5cca73fbac"
},
{
"type": "WEB",
"url": "https://github.com/aimeos/ai-controller-frontend/commit/6ea6b82f5a1fc18c574cb6f97225930d139b14a5"
},
{
"type": "WEB",
"url": "https://github.com/aimeos/ai-controller-frontend/commit/700da5ea2b622724b68c8684346bf74ac3bbca9b"
},
{
"type": "WEB",
"url": "https://github.com/aimeos/ai-controller-frontend/commit/7c93139f86eff9ec26b117a8918e06ce6cc0000f"
},
{
"type": "WEB",
"url": "https://github.com/aimeos/ai-controller-frontend/commit/ae7baa3f2fbf594c2c1e4b1aae83364a84b241a6"
},
{
"type": "WEB",
"url": "https://github.com/aimeos/ai-controller-frontend/commit/cd8c95aa4663f54bd66a69c5952f2e42405426f3"
},
{
"type": "WEB",
"url": "https://github.com/aimeos/ai-controller-frontend/commit/d4eac06f3a25330c089d8be4397f2ab1936dd9bb"
},
{
"type": "WEB",
"url": "https://github.com/aimeos/ai-controller-frontend/commit/f7c6a9ce2a6f5a9ad4af31313508870a78398f85"
},
{
"type": "PACKAGE",
"url": "https://github.com/aimeos/ai-controller-frontend"
@@ -135,6 +179,6 @@
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-09-26T17:38:30Z",
"nvd_published_at": null
"nvd_published_at": "2024-09-26T16:15:07Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wc43-73w7-x2f5",
"modified": "2024-09-26T17:49:17Z",
"modified": "2024-09-26T21:11:01Z",
"published": "2024-09-26T17:49:17Z",
"aliases": [
"CVE-2024-45042"
@@ -47,6 +47,10 @@
"type": "WEB",
"url": "https://github.com/ory/kratos/security/advisories/GHSA-wc43-73w7-x2f5"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45042"
},
{
"type": "PACKAGE",
"url": "https://github.com/ory/kratos"
@@ -59,6 +63,6 @@
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-09-26T17:49:17Z",
"nvd_published_at": null
"nvd_published_at": "2024-09-26T18:15:07Z"
}
}