Skip to content

File tree

8 files changed

+65
-17
lines changed

8 files changed

+65
-17
lines changed

advisories/github-reviewed/2022/06/GHSA-pg8v-g4xq-hww9/GHSA-pg8v-g4xq-hww9.json

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-pg8v-g4xq-hww9",
4-
"modified": "2022-07-07T17:13:54Z",
4+
"modified": "2025-11-04T16:39:03Z",
55
"published": "2022-06-25T00:00:54Z",
66
"aliases": [
77
"CVE-2022-32209"
@@ -64,6 +64,10 @@
6464
"type": "WEB",
6565
"url": "https://lists.debian.org/debian-lts-announce/2022/12/msg00012.html"
6666
},
67+
{
68+
"type": "WEB",
69+
"url": "https://lists.debian.org/debian-lts-announce/2024/09/msg00045.html"
70+
},
6771
{
6872
"type": "WEB",
6973
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AGRLWBEB3S5AU3D4TTROIS7O6QPHDTRH"

advisories/github-reviewed/2022/07/GHSA-wc69-rhjr-hc9g/GHSA-wc69-rhjr-hc9g.json

Lines changed: 29 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-wc69-rhjr-hc9g",
4-
"modified": "2022-09-14T19:29:44Z",
4+
"modified": "2025-11-04T16:38:46Z",
55
"published": "2022-07-06T18:38:49Z",
66
"aliases": [
77
"CVE-2022-31129"
@@ -84,36 +84,56 @@
8484
"url": "https://github.com/moment/moment/commit/9a3b5894f3d5d602948ac8a02e4ee528a49ca3a3"
8585
},
8686
{
87-
"type": "PACKAGE",
88-
"url": "https://github.com/moment/moment"
87+
"type": "WEB",
88+
"url": "https://security.netapp.com/advisory/ntap-20241108-0002"
8989
},
9090
{
9191
"type": "WEB",
92-
"url": "https://huntr.dev/bounties/f0952b67-f2ff-44a9-a9cd-99e0a87cb633"
92+
"url": "https://security.netapp.com/advisory/ntap-20221014-0003"
9393
},
9494
{
9595
"type": "WEB",
96-
"url": "https://lists.debian.org/debian-lts-announce/2023/01/msg00035.html"
96+
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZMX5YHELQVCGKKQVFXIYOTBMN23YYSRO"
9797
},
9898
{
9999
"type": "WEB",
100-
"url": "https://lists.fedoraproject.org/archives/list/[email protected]/message/6QIO6YNLTK2T7SPKDS4JEL45FANLNC2Q"
100+
"url": "https://lists.fedoraproject.org/archives/list/[email protected]/message/ORJX2LF6KMPIHP6B2P6KZIVKMLE3LVJ5"
101101
},
102102
{
103103
"type": "WEB",
104104
"url": "https://lists.fedoraproject.org/archives/list/[email protected]/message/IWY24RJA3SBJGA5N4CU4VBPHJPPPJL5O"
105105
},
106106
{
107107
"type": "WEB",
108-
"url": "https://lists.fedoraproject.org/archives/list/[email protected]/message/ORJX2LF6KMPIHP6B2P6KZIVKMLE3LVJ5"
108+
"url": "https://lists.fedoraproject.org/archives/list/[email protected]/message/6QIO6YNLTK2T7SPKDS4JEL45FANLNC2Q"
109109
},
110110
{
111111
"type": "WEB",
112-
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZMX5YHELQVCGKKQVFXIYOTBMN23YYSRO"
112+
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZMX5YHELQVCGKKQVFXIYOTBMN23YYSRO"
113113
},
114114
{
115115
"type": "WEB",
116-
"url": "https://security.netapp.com/advisory/ntap-20221014-0003"
116+
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ORJX2LF6KMPIHP6B2P6KZIVKMLE3LVJ5"
117+
},
118+
{
119+
"type": "WEB",
120+
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IWY24RJA3SBJGA5N4CU4VBPHJPPPJL5O"
121+
},
122+
{
123+
"type": "WEB",
124+
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6QIO6YNLTK2T7SPKDS4JEL45FANLNC2Q"
125+
},
126+
{
127+
"type": "WEB",
128+
"url": "https://lists.debian.org/debian-lts-announce/2023/01/msg00035.html"
129+
},
130+
{
131+
"type": "WEB",
132+
"url": "https://huntr.dev/bounties/f0952b67-f2ff-44a9-a9cd-99e0a87cb633"
133+
},
134+
{
135+
"type": "PACKAGE",
136+
"url": "https://github.com/moment/moment"
117137
}
118138
],
119139
"database_specific": {

advisories/github-reviewed/2022/09/GHSA-hwq7-5vv9-c6cf/GHSA-hwq7-5vv9-c6cf.json

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-hwq7-5vv9-c6cf",
4-
"modified": "2022-09-16T21:59:38Z",
4+
"modified": "2025-11-04T16:39:18Z",
55
"published": "2022-09-16T00:00:39Z",
66
"aliases": [
77
"CVE-2018-25047"
@@ -91,6 +91,10 @@
9191
"type": "WEB",
9292
"url": "https://lists.debian.org/debian-lts-announce/2023/01/msg00002.html"
9393
},
94+
{
95+
"type": "WEB",
96+
"url": "https://lists.debian.org/debian-lts-announce/2024/11/msg00013.html"
97+
},
9498
{
9599
"type": "WEB",
96100
"url": "https://security.gentoo.org/glsa/202209-09"

advisories/github-reviewed/2022/10/GHSA-vg46-2rrj-3647/GHSA-vg46-2rrj-3647.json

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-vg46-2rrj-3647",
4-
"modified": "2024-11-25T19:26:05Z",
4+
"modified": "2025-11-04T16:39:47Z",
55
"published": "2022-10-26T22:08:39Z",
66
"aliases": [
77
"CVE-2022-39348"
@@ -64,6 +64,10 @@
6464
"type": "WEB",
6565
"url": "https://lists.debian.org/debian-lts-announce/2022/11/msg00038.html"
6666
},
67+
{
68+
"type": "WEB",
69+
"url": "https://lists.debian.org/debian-lts-announce/2024/11/msg00028.html"
70+
},
6771
{
6872
"type": "WEB",
6973
"url": "https://security.gentoo.org/glsa/202301-02"

advisories/github-reviewed/2022/11/GHSA-562r-vg33-8x8h/GHSA-562r-vg33-8x8h.json

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-562r-vg33-8x8h",
4-
"modified": "2024-03-29T15:42:58Z",
4+
"modified": "2025-11-04T16:39:34Z",
55
"published": "2022-11-23T22:17:25Z",
66
"aliases": [
77
"CVE-2022-41946"
@@ -113,6 +113,10 @@
113113
"type": "WEB",
114114
"url": "https://lists.debian.org/debian-lts-announce/2022/12/msg00003.html"
115115
},
116+
{
117+
"type": "WEB",
118+
"url": "https://lists.debian.org/debian-lts-announce/2024/12/msg00017.html"
119+
},
116120
{
117121
"type": "WEB",
118122
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/25TY2L3RMVNOC7VAHJEAO7PTT6M6JJAD"

advisories/github-reviewed/2022/12/GHSA-228g-948r-83gx/GHSA-228g-948r-83gx.json

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-228g-948r-83gx",
4-
"modified": "2023-09-14T16:20:05Z",
4+
"modified": "2025-11-04T16:40:51Z",
55
"published": "2022-12-13T17:39:36Z",
66
"aliases": [
77
"CVE-2022-23515"
@@ -71,6 +71,10 @@
7171
{
7272
"type": "WEB",
7373
"url": "https://lists.debian.org/debian-lts-announce/2023/09/msg00011.html"
74+
},
75+
{
76+
"type": "WEB",
77+
"url": "https://lists.debian.org/debian-lts-announce/2024/09/msg00044.html"
7478
}
7579
],
7680
"database_specific": {

advisories/github-reviewed/2022/12/GHSA-486f-hjj9-9vhh/GHSA-486f-hjj9-9vhh.json

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,13 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-486f-hjj9-9vhh",
4-
"modified": "2022-12-13T17:36:28Z",
4+
"modified": "2025-11-04T16:40:28Z",
55
"published": "2022-12-13T17:36:28Z",
66
"aliases": [
77
"CVE-2022-23514"
88
],
99
"summary": "Inefficient Regular Expression Complexity in Loofah",
10-
"details": "## Summary\n\nLoofah `< 2.19.1` contains an inefficient regular expression that is susceptible to excessive backtracking when attempting to sanitize certain SVG attributes. This may lead to a denial of service through CPU resource consumption.\n\n\n## Mitigation\n\nUpgrade to Loofah `>= 2.19.1`.\n\n\n## Severity\n\nThe Loofah maintainers have evaluated this as [High Severity 7.5 (CVSS3.1)](https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).\n\n\n## References\n\n- [CWE - CWE-1333: Inefficient Regular Expression Complexity (4.9)](https://cwe.mitre.org/data/definitions/1333.html)\n- https://hackerone.com/reports/1684163\n\n\n## Credit\n\nThis vulnerability was responsibly reported by @ooooooo-q (https://github.com/ooooooo-q).\n",
10+
"details": "## Summary\n\nLoofah `< 2.19.1` contains an inefficient regular expression that is susceptible to excessive backtracking when attempting to sanitize certain SVG attributes. This may lead to a denial of service through CPU resource consumption.\n\n\n## Mitigation\n\nUpgrade to Loofah `>= 2.19.1`.\n\n\n## Severity\n\nThe Loofah maintainers have evaluated this as [High Severity 7.5 (CVSS3.1)](https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).\n\n\n## References\n\n- [CWE - CWE-1333: Inefficient Regular Expression Complexity (4.9)](https://cwe.mitre.org/data/definitions/1333.html)\n- https://hackerone.com/reports/1684163\n\n\n## Credit\n\nThis vulnerability was responsibly reported by @ooooooo-q (https://github.com/ooooooo-q).",
1111
"severity": [
1212
{
1313
"type": "CVSS_V3",
@@ -63,6 +63,10 @@
6363
{
6464
"type": "WEB",
6565
"url": "https://lists.debian.org/debian-lts-announce/2023/09/msg00011.html"
66+
},
67+
{
68+
"type": "WEB",
69+
"url": "https://lists.debian.org/debian-lts-announce/2024/09/msg00044.html"
6670
}
6771
],
6872
"database_specific": {

advisories/github-reviewed/2022/12/GHSA-hcpj-qp55-gfph/GHSA-hcpj-qp55-gfph.json

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-hcpj-qp55-gfph",
4-
"modified": "2024-11-18T16:26:28Z",
4+
"modified": "2025-11-04T16:40:11Z",
55
"published": "2022-12-06T06:30:17Z",
66
"aliases": [
77
"CVE-2022-24439"
@@ -95,6 +95,10 @@
9595
"type": "WEB",
9696
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AV5DV7GBLMOZT7U3Q4TDOJO5R6G3V6GH"
9797
},
98+
{
99+
"type": "WEB",
100+
"url": "https://lists.debian.org/debian-lts-announce/2024/10/msg00030.html"
101+
},
98102
{
99103
"type": "WEB",
100104
"url": "https://lists.debian.org/debian-lts-announce/2023/07/msg00024.html"

0 commit comments

Comments
 (0)