diff --git a/advisories/github-reviewed/2023/09/GHSA-v84f-6r39-cpfc/GHSA-v84f-6r39-cpfc.json b/advisories/github-reviewed/2023/09/GHSA-v84f-6r39-cpfc/GHSA-v84f-6r39-cpfc.json index 886e98c6971..b765dae198a 100644 --- a/advisories/github-reviewed/2023/09/GHSA-v84f-6r39-cpfc/GHSA-v84f-6r39-cpfc.json +++ b/advisories/github-reviewed/2023/09/GHSA-v84f-6r39-cpfc/GHSA-v84f-6r39-cpfc.json @@ -89,7 +89,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-323" ], "severity": "MODERATE", "github_reviewed": true, diff --git a/advisories/github-reviewed/2024/02/GHSA-c866-8gpw-p3mv/GHSA-c866-8gpw-p3mv.json b/advisories/github-reviewed/2024/02/GHSA-c866-8gpw-p3mv/GHSA-c866-8gpw-p3mv.json index 1e6536fe5ff..cd39054f891 100644 --- a/advisories/github-reviewed/2024/02/GHSA-c866-8gpw-p3mv/GHSA-c866-8gpw-p3mv.json +++ b/advisories/github-reviewed/2024/02/GHSA-c866-8gpw-p3mv/GHSA-c866-8gpw-p3mv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c866-8gpw-p3mv", - "modified": "2024-02-09T15:08:40Z", + "modified": "2024-09-26T21:10:36Z", "published": "2024-02-08T21:30:38Z", "aliases": [ "CVE-2024-1329" @@ -114,6 +114,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-59", "CWE-610" ], "severity": "HIGH", diff --git a/advisories/github-reviewed/2024/06/GHSA-6q97-8v3g-rpxw/GHSA-6q97-8v3g-rpxw.json b/advisories/github-reviewed/2024/06/GHSA-6q97-8v3g-rpxw/GHSA-6q97-8v3g-rpxw.json index c33e817d880..6ce11fa4aa5 100644 --- a/advisories/github-reviewed/2024/06/GHSA-6q97-8v3g-rpxw/GHSA-6q97-8v3g-rpxw.json +++ b/advisories/github-reviewed/2024/06/GHSA-6q97-8v3g-rpxw/GHSA-6q97-8v3g-rpxw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6q97-8v3g-rpxw", - "modified": "2024-06-12T19:45:11Z", + "modified": "2024-09-26T21:11:10Z", "published": "2024-06-12T15:31:45Z", "aliases": [ "CVE-2024-36265" @@ -33,6 +33,22 @@ ] } ] + }, + { + "package": { + "ecosystem": "PyPI", + "name": "apache-submarine" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0.8.0" + } + ] + } + ] } ], "references": [ @@ -44,6 +60,10 @@ "type": "PACKAGE", "url": "https://github.com/apache/submarine" }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/apache-submarine/PYSEC-2024-98.yaml" + }, { "type": "WEB", "url": "https://lists.apache.org/thread/prckhhst19qxof064hsm8cccxtofvflz" diff --git a/advisories/github-reviewed/2024/06/GHSA-jwcg-wv5x-vg3g/GHSA-jwcg-wv5x-vg3g.json b/advisories/github-reviewed/2024/06/GHSA-jwcg-wv5x-vg3g/GHSA-jwcg-wv5x-vg3g.json index cef61ede0cc..e867902b4d0 100644 --- a/advisories/github-reviewed/2024/06/GHSA-jwcg-wv5x-vg3g/GHSA-jwcg-wv5x-vg3g.json +++ b/advisories/github-reviewed/2024/06/GHSA-jwcg-wv5x-vg3g/GHSA-jwcg-wv5x-vg3g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jwcg-wv5x-vg3g", - "modified": "2024-09-26T16:31:14Z", + "modified": "2024-09-26T21:11:09Z", "published": "2024-06-12T15:31:44Z", "aliases": [ "CVE-2024-36264" @@ -33,6 +33,22 @@ ] } ] + }, + { + "package": { + "ecosystem": "PyPI", + "name": "apache-submarine" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0.8.0" + } + ] + } + ] } ], "references": [ @@ -52,6 +68,10 @@ "type": "PACKAGE", "url": "https://github.com/apache/submarine" }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/apache-submarine/PYSEC-2024-97.yaml" + }, { "type": "WEB", "url": "https://issues.apache.org/jira/browse/SUBMARINE-1417" diff --git a/advisories/github-reviewed/2024/09/GHSA-6375-pg5j-8wph/GHSA-6375-pg5j-8wph.json b/advisories/github-reviewed/2024/09/GHSA-6375-pg5j-8wph/GHSA-6375-pg5j-8wph.json index cb03eb48aec..c48d96465de 100644 --- a/advisories/github-reviewed/2024/09/GHSA-6375-pg5j-8wph/GHSA-6375-pg5j-8wph.json +++ b/advisories/github-reviewed/2024/09/GHSA-6375-pg5j-8wph/GHSA-6375-pg5j-8wph.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6375-pg5j-8wph", - "modified": "2024-09-25T18:51:16Z", + "modified": "2024-09-26T21:10:27Z", "published": "2024-09-25T03:30:36Z", "aliases": [ "CVE-2024-46935" @@ -9,6 +9,10 @@ "summary": "Denial of service in rocket chat message parser", "details": "Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier is vulnerable to denial of service (DoS). Attackers who craft messages with specific characters may crash the workspace due to an issue in the message parser.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N" diff --git a/advisories/github-reviewed/2024/09/GHSA-g54f-66mw-hv66/GHSA-g54f-66mw-hv66.json b/advisories/github-reviewed/2024/09/GHSA-g54f-66mw-hv66/GHSA-g54f-66mw-hv66.json index eda03221d5a..a6222b9ab04 100644 --- a/advisories/github-reviewed/2024/09/GHSA-g54f-66mw-hv66/GHSA-g54f-66mw-hv66.json +++ b/advisories/github-reviewed/2024/09/GHSA-g54f-66mw-hv66/GHSA-g54f-66mw-hv66.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g54f-66mw-hv66", - "modified": "2024-09-26T18:16:13Z", + "modified": "2024-09-26T21:11:07Z", "published": "2024-09-26T18:16:13Z", "aliases": [ "CVE-2024-47171" @@ -44,6 +44,10 @@ "type": "WEB", "url": "https://github.com/agnaistic/agnai/security/advisories/GHSA-g54f-66mw-hv66" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47171" + }, { "type": "PACKAGE", "url": "https://github.com/agnaistic/agnai" @@ -65,6 +69,6 @@ "severity": "LOW", "github_reviewed": true, "github_reviewed_at": "2024-09-26T18:16:13Z", - "nvd_published_at": null + "nvd_published_at": "2024-09-26T18:15:10Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2024/09/GHSA-h355-hm5h-cm8h/GHSA-h355-hm5h-cm8h.json b/advisories/github-reviewed/2024/09/GHSA-h355-hm5h-cm8h/GHSA-h355-hm5h-cm8h.json index cc21874fa9b..1bb6e469f00 100644 --- a/advisories/github-reviewed/2024/09/GHSA-h355-hm5h-cm8h/GHSA-h355-hm5h-cm8h.json +++ b/advisories/github-reviewed/2024/09/GHSA-h355-hm5h-cm8h/GHSA-h355-hm5h-cm8h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h355-hm5h-cm8h", - "modified": "2024-09-26T18:07:52Z", + "modified": "2024-09-26T21:11:05Z", "published": "2024-09-26T18:07:52Z", "aliases": [ "CVE-2024-47170" @@ -44,6 +44,10 @@ "type": "WEB", "url": "https://github.com/agnaistic/agnai/security/advisories/GHSA-h355-hm5h-cm8h" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47170" + }, { "type": "PACKAGE", "url": "https://github.com/agnaistic/agnai" @@ -57,6 +61,6 @@ "severity": "LOW", "github_reviewed": true, "github_reviewed_at": "2024-09-26T18:07:52Z", - "nvd_published_at": null + "nvd_published_at": "2024-09-26T18:15:10Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2024/09/GHSA-j827-6rgf-9629/GHSA-j827-6rgf-9629.json b/advisories/github-reviewed/2024/09/GHSA-j827-6rgf-9629/GHSA-j827-6rgf-9629.json index d851190c74f..7bae2ead14a 100644 --- a/advisories/github-reviewed/2024/09/GHSA-j827-6rgf-9629/GHSA-j827-6rgf-9629.json +++ b/advisories/github-reviewed/2024/09/GHSA-j827-6rgf-9629/GHSA-j827-6rgf-9629.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j827-6rgf-9629", - "modified": "2024-09-26T17:54:24Z", + "modified": "2024-09-26T21:11:02Z", "published": "2024-09-26T17:54:24Z", "aliases": [ "CVE-2024-47075" @@ -44,6 +44,10 @@ "type": "WEB", "url": "https://github.com/layui/layui/security/advisories/GHSA-j827-6rgf-9629" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47075" + }, { "type": "WEB", "url": "https://github.com/layui/layui/commit/f756b41d63bf3d488a2cb042918638c9851bf2b0" @@ -64,6 +68,6 @@ "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2024-09-26T17:54:24Z", - "nvd_published_at": null + "nvd_published_at": "2024-09-26T18:15:08Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2024/09/GHSA-mpch-89gm-hm83/GHSA-mpch-89gm-hm83.json b/advisories/github-reviewed/2024/09/GHSA-mpch-89gm-hm83/GHSA-mpch-89gm-hm83.json index 17b35722b90..040857c3d34 100644 --- a/advisories/github-reviewed/2024/09/GHSA-mpch-89gm-hm83/GHSA-mpch-89gm-hm83.json +++ b/advisories/github-reviewed/2024/09/GHSA-mpch-89gm-hm83/GHSA-mpch-89gm-hm83.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mpch-89gm-hm83", - "modified": "2024-09-26T18:05:12Z", + "modified": "2024-09-26T21:11:04Z", "published": "2024-09-26T18:05:12Z", "aliases": [ "CVE-2024-47169" @@ -44,6 +44,10 @@ "type": "WEB", "url": "https://github.com/agnaistic/agnai/security/advisories/GHSA-mpch-89gm-hm83" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47169" + }, { "type": "PACKAGE", "url": "https://github.com/agnaistic/agnai" @@ -58,6 +62,6 @@ "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2024-09-26T18:05:12Z", - "nvd_published_at": null + "nvd_published_at": "2024-09-26T18:15:10Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2024/09/GHSA-rw3j-574h-mrcq/GHSA-rw3j-574h-mrcq.json b/advisories/github-reviewed/2024/09/GHSA-rw3j-574h-mrcq/GHSA-rw3j-574h-mrcq.json index 51cfa292a80..d7b51fdf9c7 100644 --- a/advisories/github-reviewed/2024/09/GHSA-rw3j-574h-mrcq/GHSA-rw3j-574h-mrcq.json +++ b/advisories/github-reviewed/2024/09/GHSA-rw3j-574h-mrcq/GHSA-rw3j-574h-mrcq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rw3j-574h-mrcq", - "modified": "2024-09-26T17:38:30Z", + "modified": "2024-09-26T21:10:59Z", "published": "2024-09-26T17:38:30Z", "aliases": [ "CVE-2024-39319" @@ -123,6 +123,50 @@ "type": "WEB", "url": "https://github.com/aimeos/ai-controller-frontend/security/advisories/GHSA-rw3j-574h-mrcq" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39319" + }, + { + "type": "WEB", + "url": "https://github.com/aimeos/ai-controller-frontend/commit/2ad5c062a629af374da470a319914c321c9bfee2" + }, + { + "type": "WEB", + "url": "https://github.com/aimeos/ai-controller-frontend/commit/53eebdc51fae34440dfd768a7811c169c7779aa9" + }, + { + "type": "WEB", + "url": "https://github.com/aimeos/ai-controller-frontend/commit/5833db6d18a889b94dc036dfb84b6f5cca73fbac" + }, + { + "type": "WEB", + "url": "https://github.com/aimeos/ai-controller-frontend/commit/6ea6b82f5a1fc18c574cb6f97225930d139b14a5" + }, + { + "type": "WEB", + "url": "https://github.com/aimeos/ai-controller-frontend/commit/700da5ea2b622724b68c8684346bf74ac3bbca9b" + }, + { + "type": "WEB", + "url": "https://github.com/aimeos/ai-controller-frontend/commit/7c93139f86eff9ec26b117a8918e06ce6cc0000f" + }, + { + "type": "WEB", + "url": "https://github.com/aimeos/ai-controller-frontend/commit/ae7baa3f2fbf594c2c1e4b1aae83364a84b241a6" + }, + { + "type": "WEB", + "url": "https://github.com/aimeos/ai-controller-frontend/commit/cd8c95aa4663f54bd66a69c5952f2e42405426f3" + }, + { + "type": "WEB", + "url": "https://github.com/aimeos/ai-controller-frontend/commit/d4eac06f3a25330c089d8be4397f2ab1936dd9bb" + }, + { + "type": "WEB", + "url": "https://github.com/aimeos/ai-controller-frontend/commit/f7c6a9ce2a6f5a9ad4af31313508870a78398f85" + }, { "type": "PACKAGE", "url": "https://github.com/aimeos/ai-controller-frontend" @@ -135,6 +179,6 @@ "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2024-09-26T17:38:30Z", - "nvd_published_at": null + "nvd_published_at": "2024-09-26T16:15:07Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2024/09/GHSA-wc43-73w7-x2f5/GHSA-wc43-73w7-x2f5.json b/advisories/github-reviewed/2024/09/GHSA-wc43-73w7-x2f5/GHSA-wc43-73w7-x2f5.json index bc7f2086dfd..1a12dbe64b3 100644 --- a/advisories/github-reviewed/2024/09/GHSA-wc43-73w7-x2f5/GHSA-wc43-73w7-x2f5.json +++ b/advisories/github-reviewed/2024/09/GHSA-wc43-73w7-x2f5/GHSA-wc43-73w7-x2f5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wc43-73w7-x2f5", - "modified": "2024-09-26T17:49:17Z", + "modified": "2024-09-26T21:11:01Z", "published": "2024-09-26T17:49:17Z", "aliases": [ "CVE-2024-45042" @@ -47,6 +47,10 @@ "type": "WEB", "url": "https://github.com/ory/kratos/security/advisories/GHSA-wc43-73w7-x2f5" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45042" + }, { "type": "PACKAGE", "url": "https://github.com/ory/kratos" @@ -59,6 +63,6 @@ "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2024-09-26T17:49:17Z", - "nvd_published_at": null + "nvd_published_at": "2024-09-26T18:15:07Z" } } \ No newline at end of file