Skip to content

Commit 6434583

Browse files
jasnowpostmodern
authored andcommitted
GHSA SYNC: Updated 2 fields in 1 existing advisory + 1 brand new advisory
1 parent 098479f commit 6434583

File tree

2 files changed

+27
-0
lines changed

2 files changed

+27
-0
lines changed

gems/measured/GHSA-29g5-m8v7-v564.yml

Lines changed: 25 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,25 @@
1+
---
2+
gem: measured
3+
ghsa: 29g5-m8v7-v564
4+
url: https://github.com/Shopify/measured/security/advisories/GHSA-29g5-m8v7-v564
5+
title: Measured is vulnerable to Path Traversal attacks during
6+
class initialization
7+
date: 2025-07-15
8+
description: |
9+
### Impact
10+
11+
A path traversal vulnerability exists where an attacker
12+
with access to manipulate inputs when initializing the
13+
`Measured::Cache::Json class` would be able to instruct
14+
the library to read arbitrary files.
15+
16+
### Patches
17+
18+
Users should update to the latest version.
19+
patched_versions:
20+
- ">= 3.2.1"
21+
related:
22+
url:
23+
- https://github.com/Shopify/measured/security/advisories/GHSA-29g5-m8v7-v564
24+
- https://github.com/Shopify/measured/commit/d6319985a2304d97c085e3dc45c98af554f4be76
25+
- https://github.com/advisories/GHSA-29g5-m8v7-v564

gems/resolv/CVE-2025-24294.yml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,7 @@
11
---
22
gem: resolv
33
cve: 2025-24294
4+
ghsa: xh69-987w-hrp8
45
url: https://www.ruby-lang.org/en/news/2025/07/08/dos-resolv-cve-2025-24294
56
title: Possible Denial of Service in resolv gem
67
date: 2025-07-09
@@ -35,6 +36,7 @@ description: |
3536
3637
## History
3738
Originally published at 2025-07-08 07:00:00 (UTC)
39+
cvss_v3: 5.3
3840
patched_versions:
3941
- "~> 0.2.2"
4042
- "~> 0.3.0"

0 commit comments

Comments
 (0)