Skip to content

Commit 9a7c059

Browse files
1 parent 97e2a29 commit 9a7c059

8 files changed

Lines changed: 94 additions & 17 deletions

File tree

advisories/github-reviewed/2026/03/GHSA-62ch-j6x7-722j/GHSA-62ch-j6x7-722j.json

Lines changed: 14 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-62ch-j6x7-722j",
4-
"modified": "2026-03-23T20:38:16Z",
4+
"modified": "2026-03-25T20:46:06Z",
55
"published": "2026-03-23T20:38:16Z",
66
"aliases": [
77
"CVE-2026-32299"
@@ -65,9 +65,21 @@
6565
"type": "WEB",
6666
"url": "https://github.com/opensource-workshop/connect-cms/security/advisories/GHSA-62ch-j6x7-722j"
6767
},
68+
{
69+
"type": "ADVISORY",
70+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32299"
71+
},
6872
{
6973
"type": "PACKAGE",
7074
"url": "https://github.com/opensource-workshop/connect-cms"
75+
},
76+
{
77+
"type": "WEB",
78+
"url": "https://github.com/opensource-workshop/connect-cms/releases/tag/v1.41.1"
79+
},
80+
{
81+
"type": "WEB",
82+
"url": "https://github.com/opensource-workshop/connect-cms/releases/tag/v2.41.1"
7183
}
7284
],
7385
"database_specific": {
@@ -77,6 +89,6 @@
7789
"severity": "HIGH",
7890
"github_reviewed": true,
7991
"github_reviewed_at": "2026-03-23T20:38:16Z",
80-
"nvd_published_at": null
92+
"nvd_published_at": "2026-03-23T22:16:27Z"
8193
}
8294
}

advisories/github-reviewed/2026/03/GHSA-89vf-4333-qx8v/GHSA-89vf-4333-qx8v.json

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-89vf-4333-qx8v",
4-
"modified": "2026-03-23T20:53:28Z",
4+
"modified": "2026-03-25T20:47:31Z",
55
"published": "2026-03-23T20:53:28Z",
66
"aliases": [
77
"CVE-2026-33170"
@@ -78,6 +78,10 @@
7878
"type": "WEB",
7979
"url": "https://github.com/rails/rails/security/advisories/GHSA-89vf-4333-qx8v"
8080
},
81+
{
82+
"type": "ADVISORY",
83+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33170"
84+
},
8185
{
8286
"type": "WEB",
8387
"url": "https://github.com/rails/rails/commit/50d732af3b7c8aaf63cbcca0becbc00279b215b7"
@@ -114,6 +118,6 @@
114118
"severity": "MODERATE",
115119
"github_reviewed": true,
116120
"github_reviewed_at": "2026-03-23T20:53:28Z",
117-
"nvd_published_at": null
121+
"nvd_published_at": "2026-03-24T00:16:28Z"
118122
}
119123
}

advisories/github-reviewed/2026/03/GHSA-j5q5-j9gm-2w5c/GHSA-j5q5-j9gm-2w5c.json

Lines changed: 34 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-j5q5-j9gm-2w5c",
4-
"modified": "2026-03-18T20:20:10Z",
4+
"modified": "2026-03-25T20:48:04Z",
55
"published": "2026-03-18T20:20:10Z",
66
"aliases": [
77
"CVE-2026-33211"
@@ -116,6 +116,38 @@
116116
"type": "WEB",
117117
"url": "https://github.com/tektoncd/pipeline/security/advisories/GHSA-j5q5-j9gm-2w5c"
118118
},
119+
{
120+
"type": "ADVISORY",
121+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33211"
122+
},
123+
{
124+
"type": "WEB",
125+
"url": "https://github.com/tektoncd/pipeline/commit/10fa538f9a2b6d01c75138f1ed7ba3da0e34687c"
126+
},
127+
{
128+
"type": "WEB",
129+
"url": "https://github.com/tektoncd/pipeline/commit/318006c4e3a5"
130+
},
131+
{
132+
"type": "WEB",
133+
"url": "https://github.com/tektoncd/pipeline/commit/3ca7bc6e6dd1d97f80b84f78370d91edaf023cbd"
134+
},
135+
{
136+
"type": "WEB",
137+
"url": "https://github.com/tektoncd/pipeline/commit/961388fcf3374bc7656d28ab58ca84987e0a75ae"
138+
},
139+
{
140+
"type": "WEB",
141+
"url": "https://github.com/tektoncd/pipeline/commit/b1fee65b88aa969069c14c120045e97c37d9ee5e"
142+
},
143+
{
144+
"type": "WEB",
145+
"url": "https://github.com/tektoncd/pipeline/commit/cdb4e1e97a4f3170f9bc2cbfff83a6c8107bc3db"
146+
},
147+
{
148+
"type": "WEB",
149+
"url": "https://github.com/tektoncd/pipeline/commit/ec7755031a183b345cf9e64bea0e0505c1b9cb78"
150+
},
119151
{
120152
"type": "PACKAGE",
121153
"url": "https://github.com/tektoncd/pipeline"
@@ -128,6 +160,6 @@
128160
"severity": "CRITICAL",
129161
"github_reviewed": true,
130162
"github_reviewed_at": "2026-03-18T20:20:10Z",
131-
"nvd_published_at": null
163+
"nvd_published_at": "2026-03-24T00:16:29Z"
132164
}
133165
}

advisories/github-reviewed/2026/03/GHSA-jh46-85jr-6ph9/GHSA-jh46-85jr-6ph9.json

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-jh46-85jr-6ph9",
4-
"modified": "2026-03-23T20:36:49Z",
4+
"modified": "2026-03-25T20:45:55Z",
55
"published": "2026-03-23T20:36:49Z",
66
"aliases": [
77
"CVE-2026-32279"
@@ -65,6 +65,10 @@
6565
"type": "WEB",
6666
"url": "https://github.com/opensource-workshop/connect-cms/security/advisories/GHSA-jh46-85jr-6ph9"
6767
},
68+
{
69+
"type": "ADVISORY",
70+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32279"
71+
},
6872
{
6973
"type": "WEB",
7074
"url": "https://github.com/opensource-workshop/connect-cms/commit/4a1a64a8f768a53e06a4239e25782d9e2e88fc63"
@@ -93,6 +97,6 @@
9397
"severity": "MODERATE",
9498
"github_reviewed": true,
9599
"github_reviewed_at": "2026-03-23T20:36:49Z",
96-
"nvd_published_at": null
100+
"nvd_published_at": "2026-03-23T22:16:27Z"
97101
}
98102
}

advisories/github-reviewed/2026/03/GHSA-pgm4-439c-5jp6/GHSA-pgm4-439c-5jp6.json

Lines changed: 12 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,14 +1,19 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-pgm4-439c-5jp6",
4-
"modified": "2026-03-23T20:45:15Z",
4+
"modified": "2026-03-25T20:46:51Z",
55
"published": "2026-03-23T20:45:15Z",
66
"aliases": [
77
"CVE-2026-33167"
88
],
99
"summary": "Rails has a possible XSS vulnerability in its Action Pack debug exceptions",
1010
"details": "### Impact\nThe debug exceptions page does not properly escape exception messages. A carefully crafted exception message could inject arbitrary HTML and JavaScript into the page, leading to XSS. This affects applications with detailed exception pages enabled (`config.consider_all_requests_local = true`), which is the default in development.\n\n### Releases\nThe fixed releases are available at the normal locations.",
11-
"severity": [],
11+
"severity": [
12+
{
13+
"type": "CVSS_V4",
14+
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
15+
}
16+
],
1217
"affected": [
1318
{
1419
"package": {
@@ -35,6 +40,10 @@
3540
"type": "WEB",
3641
"url": "https://github.com/rails/rails/security/advisories/GHSA-pgm4-439c-5jp6"
3742
},
43+
{
44+
"type": "ADVISORY",
45+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33167"
46+
},
3847
{
3948
"type": "WEB",
4049
"url": "https://github.com/rails/rails/commit/6752711c8c31d79ba50d13af6a6698a3b85415e0"
@@ -55,6 +64,6 @@
5564
"severity": "LOW",
5665
"github_reviewed": true,
5766
"github_reviewed_at": "2026-03-23T20:45:15Z",
58-
"nvd_published_at": null
67+
"nvd_published_at": "2026-03-23T23:17:12Z"
5968
}
6069
}

advisories/github-reviewed/2026/03/GHSA-qcfx-2mfw-w4cg/GHSA-qcfx-2mfw-w4cg.json

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-qcfx-2mfw-w4cg",
4-
"modified": "2026-03-23T20:54:16Z",
4+
"modified": "2026-03-25T20:47:53Z",
55
"published": "2026-03-23T20:54:16Z",
66
"aliases": [
77
"CVE-2026-33173"
@@ -78,6 +78,10 @@
7878
"type": "WEB",
7979
"url": "https://github.com/rails/rails/security/advisories/GHSA-qcfx-2mfw-w4cg"
8080
},
81+
{
82+
"type": "ADVISORY",
83+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33173"
84+
},
8185
{
8286
"type": "WEB",
8387
"url": "https://github.com/rails/rails/commit/707c0f1f41f067fdf96d54e99d43b28dfaae7e53"
@@ -114,6 +118,6 @@
114118
"severity": "MODERATE",
115119
"github_reviewed": true,
116120
"github_reviewed_at": "2026-03-23T20:54:16Z",
117-
"nvd_published_at": null
121+
"nvd_published_at": "2026-03-24T00:16:28Z"
118122
}
119123
}

advisories/github-reviewed/2026/03/GHSA-qr6x-wvxr-8hm9/GHSA-qr6x-wvxr-8hm9.json

Lines changed: 10 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-qr6x-wvxr-8hm9",
4-
"modified": "2026-03-23T20:39:10Z",
4+
"modified": "2026-03-25T20:46:16Z",
55
"published": "2026-03-23T20:39:10Z",
66
"aliases": [
77
"CVE-2026-32300"
@@ -65,6 +65,10 @@
6565
"type": "WEB",
6666
"url": "https://github.com/opensource-workshop/connect-cms/security/advisories/GHSA-qr6x-wvxr-8hm9"
6767
},
68+
{
69+
"type": "ADVISORY",
70+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-32300"
71+
},
6872
{
6973
"type": "WEB",
7074
"url": "https://github.com/opensource-workshop/connect-cms/commit/7c9951738c62a1d51b91e9956d1eb756c5d52cce"
@@ -76,6 +80,10 @@
7680
{
7781
"type": "WEB",
7882
"url": "https://github.com/opensource-workshop/connect-cms/releases/tag/v1.41.1"
83+
},
84+
{
85+
"type": "WEB",
86+
"url": "https://github.com/opensource-workshop/connect-cms/releases/tag/v2.41.1"
7987
}
8088
],
8189
"database_specific": {
@@ -86,6 +94,6 @@
8694
"severity": "HIGH",
8795
"github_reviewed": true,
8896
"github_reviewed_at": "2026-03-23T20:39:10Z",
89-
"nvd_published_at": null
97+
"nvd_published_at": "2026-03-23T22:16:27Z"
9098
}
9199
}

advisories/github-reviewed/2026/03/GHSA-rm2q-f7jv-3cfp/GHSA-rm2q-f7jv-3cfp.json

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-rm2q-f7jv-3cfp",
4-
"modified": "2026-03-23T20:43:43Z",
4+
"modified": "2026-03-25T20:46:37Z",
55
"published": "2026-03-23T20:43:43Z",
66
"aliases": [
77
"CVE-2026-33046"
@@ -40,6 +40,10 @@
4040
"type": "WEB",
4141
"url": "https://github.com/indico/indico/security/advisories/GHSA-rm2q-f7jv-3cfp"
4242
},
43+
{
44+
"type": "ADVISORY",
45+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33046"
46+
},
4347
{
4448
"type": "WEB",
4549
"url": "https://github.com/indico/indico/commit/0adb70f0ed66e129361d447868f5f3eb90dc5e96"
@@ -73,6 +77,6 @@
7377
"severity": "HIGH",
7478
"github_reviewed": true,
7579
"github_reviewed_at": "2026-03-23T20:43:43Z",
76-
"nvd_published_at": null
80+
"nvd_published_at": "2026-03-23T23:17:12Z"
7781
}
7882
}

0 commit comments

Comments
 (0)