From ffef5846262dd0a38b0351bfa4c36284ae2af705 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 5 Feb 2024 11:15:00 +0000 Subject: [PATCH] Publish Advisories GHSA-g4m9-5hpf-hx72 GHSA-pqg8-crx9-g8m4 GHSA-m5vr-3m74-jwxp GHSA-rfcf-m67m-jcrq GHSA-2xhg-w2g5-w95x GHSA-q3j3-w37x-hq2q GHSA-qw36-p97w-vcqr --- .../GHSA-g4m9-5hpf-hx72.json | 56 ++++++++++++++++- .../GHSA-pqg8-crx9-g8m4.json | 52 +++++++++++++++- .../GHSA-m5vr-3m74-jwxp.json | 46 ++++++++++++++ .../GHSA-rfcf-m67m-jcrq.json | 35 ++++++++++- .../GHSA-2xhg-w2g5-w95x.json | 60 ++++++++++++++++++- .../GHSA-q3j3-w37x-hq2q.json | 33 +++++++++- .../GHSA-qw36-p97w-vcqr.json | 31 ++++++++++ 7 files changed, 307 insertions(+), 6 deletions(-) diff --git a/advisories/github-reviewed/2020/03/GHSA-g4m9-5hpf-hx72/GHSA-g4m9-5hpf-hx72.json b/advisories/github-reviewed/2020/03/GHSA-g4m9-5hpf-hx72/GHSA-g4m9-5hpf-hx72.json index 50e03ae3637..d4ace979131 100644 --- a/advisories/github-reviewed/2020/03/GHSA-g4m9-5hpf-hx72/GHSA-g4m9-5hpf-hx72.json +++ b/advisories/github-reviewed/2020/03/GHSA-g4m9-5hpf-hx72/GHSA-g4m9-5hpf-hx72.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g4m9-5hpf-hx72", - "modified": "2021-01-14T17:48:29Z", + "modified": "2024-02-05T11:13:15Z", "published": "2020-03-30T20:09:44Z", "aliases": [ "CVE-2020-5275" @@ -90,6 +90,44 @@ ] } ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "symfony/symfony" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "4.4.0" + }, + { + "fixed": "4.4.7" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "symfony/symfony" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "5.0.0" + }, + { + "fixed": "5.0.7" + } + ] + } + ] } ], "references": [ @@ -105,9 +143,25 @@ "type": "WEB", "url": "https://github.com/symfony/symfony/commit/c935e4a3fba6cc2ab463a6ca382858068d63cebf" }, + { + "type": "WEB", + "url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/security-http/CVE-2020-5275.yaml" + }, + { + "type": "WEB", + "url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/security/CVE-2020-5275.yaml" + }, + { + "type": "WEB", + "url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/symfony/CVE-2020-5275.yaml" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/C36JLPHUPKDFAX6D5WYFC4ALO2K7RDUQ/" + }, + { + "type": "WEB", + "url": "https://symfony.com/cve-2020-5275" } ], "database_specific": { diff --git a/advisories/github-reviewed/2020/05/GHSA-pqg8-crx9-g8m4/GHSA-pqg8-crx9-g8m4.json b/advisories/github-reviewed/2020/05/GHSA-pqg8-crx9-g8m4/GHSA-pqg8-crx9-g8m4.json index 43c68276feb..1de2d734e78 100644 --- a/advisories/github-reviewed/2020/05/GHSA-pqg8-crx9-g8m4/GHSA-pqg8-crx9-g8m4.json +++ b/advisories/github-reviewed/2020/05/GHSA-pqg8-crx9-g8m4/GHSA-pqg8-crx9-g8m4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pqg8-crx9-g8m4", - "modified": "2021-11-08T18:49:16Z", + "modified": "2024-02-05T11:13:08Z", "published": "2020-05-13T23:40:09Z", "aliases": [ "CVE-2020-11069" @@ -52,6 +52,44 @@ ] } ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "typo3/cms" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "10.0.0" + }, + { + "fixed": "10.4.2" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "typo3/cms" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "9.0.0" + }, + { + "fixed": "9.5.17" + } + ] + } + ] } ], "references": [ @@ -62,6 +100,18 @@ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-11069" + }, + { + "type": "WEB", + "url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms-core/CVE-2020-11069.yaml" + }, + { + "type": "WEB", + "url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms/CVE-2020-11069.yaml" + }, + { + "type": "WEB", + "url": "https://typo3.org/security/advisory/typo3-core-sa-2020-006" } ], "database_specific": { diff --git a/advisories/github-reviewed/2020/07/GHSA-m5vr-3m74-jwxp/GHSA-m5vr-3m74-jwxp.json b/advisories/github-reviewed/2020/07/GHSA-m5vr-3m74-jwxp/GHSA-m5vr-3m74-jwxp.json index ec7be16b776..a7b2ac9330d 100644 --- a/advisories/github-reviewed/2020/07/GHSA-m5vr-3m74-jwxp/GHSA-m5vr-3m74-jwxp.json +++ b/advisories/github-reviewed/2020/07/GHSA-m5vr-3m74-jwxp/GHSA-m5vr-3m74-jwxp.json @@ -52,6 +52,44 @@ ] } ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "typo3/cms" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "10.0.0" + }, + { + "fixed": "10.4.6" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "typo3/cms" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "9.0.0" + }, + { + "fixed": "9.5.20" + } + ] + } + ] } ], "references": [ @@ -71,6 +109,14 @@ "type": "WEB", "url": "https://github.com/TYPO3/TYPO3.CMS/commit/85d3e70dff35a99ef53f4b561114acfa9e5c47e1" }, + { + "type": "WEB", + "url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms-core/CVE-2020-15098.yaml" + }, + { + "type": "WEB", + "url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/typo3/cms/CVE-2020-15098.yaml" + }, { "type": "PACKAGE", "url": "https://github.com/TYPO3/TYPO3.CMS" diff --git a/advisories/github-reviewed/2021/06/GHSA-rfcf-m67m-jcrq/GHSA-rfcf-m67m-jcrq.json b/advisories/github-reviewed/2021/06/GHSA-rfcf-m67m-jcrq/GHSA-rfcf-m67m-jcrq.json index 76f57a4f892..cbcafa7c452 100644 --- a/advisories/github-reviewed/2021/06/GHSA-rfcf-m67m-jcrq/GHSA-rfcf-m67m-jcrq.json +++ b/advisories/github-reviewed/2021/06/GHSA-rfcf-m67m-jcrq/GHSA-rfcf-m67m-jcrq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rfcf-m67m-jcrq", - "modified": "2021-10-21T13:55:20Z", + "modified": "2024-02-05T11:13:38Z", "published": "2021-06-21T17:03:44Z", "aliases": [ "CVE-2021-32693" @@ -33,6 +33,25 @@ ] } ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "symfony/symfony" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "5.3.0" + }, + { + "fixed": "5.3.2" + } + ] + } + ] } ], "references": [ @@ -52,6 +71,14 @@ "type": "WEB", "url": "https://github.com/symfony/symfony/commit/3084764ad82f29dbb025df19978b9cbc3ab34728" }, + { + "type": "WEB", + "url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/security-http/CVE-2021-32693.yaml" + }, + { + "type": "WEB", + "url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/symfony/CVE-2021-32693.yaml" + }, { "type": "PACKAGE", "url": "https://github.com/symfony/security-http" @@ -59,13 +86,17 @@ { "type": "WEB", "url": "https://symfony.com/blog/cve-2021-32693-authentication-granted-to-all-firewalls-instead-of-just-one" + }, + { + "type": "WEB", + "url": "https://symfony.com/cve-2021-32693" } ], "database_specific": { "cwe_ids": [ "CWE-287" ], - "severity": "HIGH", + "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2021-06-18T20:33:08Z", "nvd_published_at": "2021-06-17T23:15:00Z" diff --git a/advisories/github-reviewed/2021/11/GHSA-2xhg-w2g5-w95x/GHSA-2xhg-w2g5-w95x.json b/advisories/github-reviewed/2021/11/GHSA-2xhg-w2g5-w95x/GHSA-2xhg-w2g5-w95x.json index 14aa6554210..dd0dfe85078 100644 --- a/advisories/github-reviewed/2021/11/GHSA-2xhg-w2g5-w95x/GHSA-2xhg-w2g5-w95x.json +++ b/advisories/github-reviewed/2021/11/GHSA-2xhg-w2g5-w95x/GHSA-2xhg-w2g5-w95x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2xhg-w2g5-w95x", - "modified": "2021-12-06T21:36:47Z", + "modified": "2024-02-05T11:14:05Z", "published": "2021-11-24T21:01:23Z", "aliases": [ "CVE-2021-41270" @@ -52,6 +52,44 @@ ] } ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "symfony/symfony" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "4.1.0" + }, + { + "fixed": "4.4.35" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "symfony/symfony" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "5.0.0" + }, + { + "fixed": "5.3.12" + } + ] + } + ] } ], "references": [ @@ -71,6 +109,14 @@ "type": "WEB", "url": "https://github.com/symfony/symfony/commit/3da6f2d45e7536ccb2a26f52fbaf340917e208a8" }, + { + "type": "WEB", + "url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/serializer/CVE-2021-41270.yaml" + }, + { + "type": "WEB", + "url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/symfony/CVE-2021-41270.yaml" + }, { "type": "PACKAGE", "url": "https://github.com/symfony/symfony" @@ -79,6 +125,14 @@ "type": "WEB", "url": "https://github.com/symfony/symfony/releases/tag/v5.3.12" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3BPT4SF6SIXFMZARDWED5T32J7JEH3EP/" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QSREFD2TJT5LWKM6S4MD3W26NQQ5WJUP/" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3BPT4SF6SIXFMZARDWED5T32J7JEH3EP/" @@ -86,6 +140,10 @@ { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QSREFD2TJT5LWKM6S4MD3W26NQQ5WJUP/" + }, + { + "type": "WEB", + "url": "https://symfony.com/cve-2021-41270" } ], "database_specific": { diff --git a/advisories/github-reviewed/2021/11/GHSA-q3j3-w37x-hq2q/GHSA-q3j3-w37x-hq2q.json b/advisories/github-reviewed/2021/11/GHSA-q3j3-w37x-hq2q/GHSA-q3j3-w37x-hq2q.json index bc2195c012d..1612f75764c 100644 --- a/advisories/github-reviewed/2021/11/GHSA-q3j3-w37x-hq2q/GHSA-q3j3-w37x-hq2q.json +++ b/advisories/github-reviewed/2021/11/GHSA-q3j3-w37x-hq2q/GHSA-q3j3-w37x-hq2q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q3j3-w37x-hq2q", - "modified": "2021-11-25T00:18:27Z", + "modified": "2024-02-05T11:13:47Z", "published": "2021-11-24T20:04:25Z", "aliases": [ "CVE-2021-41267" @@ -33,6 +33,25 @@ ] } ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "symfony/symfony" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "5.2.0" + }, + { + "fixed": "5.3.12" + } + ] + } + ] } ], "references": [ @@ -52,9 +71,21 @@ "type": "WEB", "url": "https://github.com/symfony/symfony/commit/95dcf51682029e89450aee86267e3d553aa7c487" }, + { + "type": "WEB", + "url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/http-kernel/CVE-2021-41267.yaml" + }, + { + "type": "WEB", + "url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/symfony/CVE-2021-41267.yaml" + }, { "type": "WEB", "url": "https://github.com/symfony/symfony/releases/tag/v5.3.12" + }, + { + "type": "WEB", + "url": "https://symfony.com/cve-2021-41267" } ], "database_specific": { diff --git a/advisories/github-reviewed/2021/11/GHSA-qw36-p97w-vcqr/GHSA-qw36-p97w-vcqr.json b/advisories/github-reviewed/2021/11/GHSA-qw36-p97w-vcqr/GHSA-qw36-p97w-vcqr.json index 4fa7f08027d..80d63f4bc80 100644 --- a/advisories/github-reviewed/2021/11/GHSA-qw36-p97w-vcqr/GHSA-qw36-p97w-vcqr.json +++ b/advisories/github-reviewed/2021/11/GHSA-qw36-p97w-vcqr/GHSA-qw36-p97w-vcqr.json @@ -33,6 +33,25 @@ ] } ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "symfony/symfony" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "5.3.0" + }, + { + "fixed": "5.3.12" + } + ] + } + ] } ], "references": [ @@ -52,6 +71,14 @@ "type": "WEB", "url": "https://github.com/symfony/symfony/commit/36a808b857cd3240244f4b224452fb1e70dc6dfc" }, + { + "type": "WEB", + "url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/security-bundle/CVE-2021-41268.yaml" + }, + { + "type": "WEB", + "url": "https://github.com/FriendsOfPHP/security-advisories/blob/master/symfony/symfony/CVE-2021-41268.yaml" + }, { "type": "PACKAGE", "url": "https://github.com/symfony/symfony" @@ -59,6 +86,10 @@ { "type": "WEB", "url": "https://github.com/symfony/symfony/releases/tag/v5.3.12" + }, + { + "type": "WEB", + "url": "https://symfony.com/cve-2021-41268" } ], "database_specific": {