Skip to content

Commit 1e1158b

Browse files
Advisory Database Sync
1 parent d9a8177 commit 1e1158b

42 files changed

Lines changed: 919 additions & 59 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

advisories/unreviewed/2024/01/GHSA-cx8g-4cf5-cjv3/GHSA-cx8g-4cf5-cjv3.json

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-cx8g-4cf5-cjv3",
4-
"modified": "2026-03-26T21:31:19Z",
4+
"modified": "2026-04-08T15:31:42Z",
55
"published": "2024-01-25T21:32:14Z",
66
"aliases": [
77
"CVE-2023-52356"
@@ -75,6 +75,10 @@
7575
"type": "WEB",
7676
"url": "https://access.redhat.com/security/cve/CVE-2023-52356"
7777
},
78+
{
79+
"type": "WEB",
80+
"url": "https://access.redhat.com/errata/RHSA-2026:7081"
81+
},
7882
{
7983
"type": "WEB",
8084
"url": "https://access.redhat.com/errata/RHSA-2026:5958"

advisories/unreviewed/2024/07/GHSA-6gjw-r684-5cqg/GHSA-6gjw-r684-5cqg.json

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-6gjw-r684-5cqg",
4-
"modified": "2024-07-04T09:32:49Z",
4+
"modified": "2026-04-08T15:31:42Z",
55
"published": "2024-07-04T09:32:49Z",
66
"aliases": [
77
"CVE-2024-1182"
@@ -30,6 +30,10 @@
3030
{
3131
"type": "WEB",
3232
"url": "https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2024-004_en.pdf"
33+
},
34+
{
35+
"type": "WEB",
36+
"url": "https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2024-004_en.pdf"
3337
}
3438
],
3539
"database_specific": {

advisories/unreviewed/2024/07/GHSA-m7g5-qwgm-89mc/GHSA-m7g5-qwgm-89mc.json

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-m7g5-qwgm-89mc",
4-
"modified": "2024-07-04T09:32:49Z",
4+
"modified": "2026-04-08T15:31:42Z",
55
"published": "2024-07-04T09:32:49Z",
66
"aliases": [
77
"CVE-2024-1574"
@@ -30,6 +30,10 @@
3030
{
3131
"type": "WEB",
3232
"url": "https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2024-004_en.pdf"
33+
},
34+
{
35+
"type": "WEB",
36+
"url": "https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2024-004_en.pdf"
3337
}
3438
],
3539
"database_specific": {

advisories/unreviewed/2024/11/GHSA-4gc8-mmm3-6xff/GHSA-4gc8-mmm3-6xff.json

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-4gc8-mmm3-6xff",
4-
"modified": "2024-12-06T06:30:57Z",
4+
"modified": "2026-04-08T15:31:42Z",
55
"published": "2024-11-29T03:31:04Z",
66
"aliases": [
77
"CVE-2024-8299"
@@ -30,6 +30,10 @@
3030
{
3131
"type": "WEB",
3232
"url": "https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2024-010_en.pdf"
33+
},
34+
{
35+
"type": "WEB",
36+
"url": "https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2024-010_en.pdf"
3337
}
3438
],
3539
"database_specific": {

advisories/unreviewed/2024/11/GHSA-grq9-8qm8-vhjr/GHSA-grq9-8qm8-vhjr.json

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-grq9-8qm8-vhjr",
4-
"modified": "2024-12-06T06:30:57Z",
4+
"modified": "2026-04-08T15:31:42Z",
55
"published": "2024-11-29T03:31:04Z",
66
"aliases": [
77
"CVE-2024-9852"
@@ -30,6 +30,10 @@
3030
{
3131
"type": "WEB",
3232
"url": "https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2024-010_en.pdf"
33+
},
34+
{
35+
"type": "WEB",
36+
"url": "https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2024-010_en.pdf"
3337
}
3438
],
3539
"database_specific": {

advisories/unreviewed/2026/03/GHSA-h46w-ffvp-4pw5/GHSA-h46w-ffvp-4pw5.json

Lines changed: 9 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-h46w-ffvp-4pw5",
4-
"modified": "2026-03-17T00:31:34Z",
4+
"modified": "2026-04-08T15:31:42Z",
55
"published": "2026-03-16T18:32:04Z",
66
"aliases": [
77
"CVE-2026-4224"
@@ -31,6 +31,14 @@
3131
"type": "WEB",
3232
"url": "https://github.com/python/cpython/commit/196edfb06a7458377d4d0f4b3cd41724c1f3bd4a"
3333
},
34+
{
35+
"type": "WEB",
36+
"url": "https://github.com/python/cpython/commit/642865ddf4b232da1f3b1f7abcfa3254c4bfe785"
37+
},
38+
{
39+
"type": "WEB",
40+
"url": "https://github.com/python/cpython/commit/af856a7177326ac25d9f66cc6dd28b554d914fee"
41+
},
3442
{
3543
"type": "WEB",
3644
"url": "https://github.com/python/cpython/commit/e0a8a6da90597a924b300debe045cdb4628ee1f3"

advisories/unreviewed/2026/03/GHSA-xrqh-48jh-pjv2/GHSA-xrqh-48jh-pjv2.json

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-xrqh-48jh-pjv2",
4-
"modified": "2026-04-06T12:32:09Z",
4+
"modified": "2026-04-08T15:31:42Z",
55
"published": "2026-03-13T21:31:51Z",
66
"aliases": [
77
"CVE-2026-4111"
@@ -35,6 +35,10 @@
3535
"type": "WEB",
3636
"url": "https://access.redhat.com/errata/RHSA-2026:6647"
3737
},
38+
{
39+
"type": "WEB",
40+
"url": "https://access.redhat.com/errata/RHSA-2026:7093"
41+
},
3842
{
3943
"type": "WEB",
4044
"url": "https://access.redhat.com/security/cve/CVE-2026-4111"

advisories/unreviewed/2026/04/GHSA-264c-x5mq-ppr2/GHSA-264c-x5mq-ppr2.json

Lines changed: 8 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,18 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-264c-x5mq-ppr2",
4-
"modified": "2026-04-08T09:31:35Z",
4+
"modified": "2026-04-08T15:31:43Z",
55
"published": "2026-04-08T09:31:35Z",
66
"aliases": [
77
"CVE-2026-39696"
88
],
99
"details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elfsight Elfsight WhatsApp Chat CC elfsight-whatsapp-chat allows DOM-Based XSS.This issue affects Elfsight WhatsApp Chat CC: from n/a through <= 1.2.0.",
10-
"severity": [],
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L"
14+
}
15+
],
1116
"affected": [],
1217
"references": [
1318
{
@@ -23,7 +28,7 @@
2328
"cwe_ids": [
2429
"CWE-79"
2530
],
26-
"severity": null,
31+
"severity": "MODERATE",
2732
"github_reviewed": false,
2833
"github_reviewed_at": null,
2934
"nvd_published_at": "2026-04-08T09:16:42Z"
Lines changed: 40 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,40 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-28p4-crp9-2q2x",
4+
"modified": "2026-04-08T15:31:44Z",
5+
"published": "2026-04-08T15:31:44Z",
6+
"aliases": [
7+
"CVE-2025-57854"
8+
],
9+
"details": "A container privilege escalation flaw was found in certain OpenShift Update Service (OSUS) images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who can execute commands within an affected container, even as a non-root user, may be able to leverage their membership in the root group to modify the /etc/passwd file. This could allow the attacker to add a new user with any arbitrary UID, including UID 0, leading to full root privileges within the container.",
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H"
14+
}
15+
],
16+
"affected": [],
17+
"references": [
18+
{
19+
"type": "ADVISORY",
20+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-57854"
21+
},
22+
{
23+
"type": "WEB",
24+
"url": "https://access.redhat.com/security/cve/CVE-2025-57854"
25+
},
26+
{
27+
"type": "WEB",
28+
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2391107"
29+
}
30+
],
31+
"database_specific": {
32+
"cwe_ids": [
33+
"CWE-276"
34+
],
35+
"severity": "MODERATE",
36+
"github_reviewed": false,
37+
"github_reviewed_at": null,
38+
"nvd_published_at": "2026-04-08T14:16:26Z"
39+
}
40+
}

advisories/unreviewed/2026/04/GHSA-38gq-23v5-5q4r/GHSA-38gq-23v5-5q4r.json

Lines changed: 8 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,18 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-38gq-23v5-5q4r",
4-
"modified": "2026-04-08T09:31:36Z",
4+
"modified": "2026-04-08T15:31:43Z",
55
"published": "2026-04-08T09:31:36Z",
66
"aliases": [
77
"CVE-2026-39716"
88
],
99
"details": "Missing Authorization vulnerability in CKThemes Flipmart flipmart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Flipmart: from n/a through <= 2.8.",
10-
"severity": [],
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
14+
}
15+
],
1116
"affected": [],
1217
"references": [
1318
{
@@ -23,7 +28,7 @@
2328
"cwe_ids": [
2429
"CWE-862"
2530
],
26-
"severity": null,
31+
"severity": "MODERATE",
2732
"github_reviewed": false,
2833
"github_reviewed_at": null,
2934
"nvd_published_at": "2026-04-08T09:16:44Z"

0 commit comments

Comments
 (0)