Skip to content

Commit 2cbafec

Browse files
committed
Add PR#2021 and fixed indents
1 parent 0e0c8e9 commit 2cbafec

20 files changed

+170
-174
lines changed

gems/alchemy_cms/CVE-2018-18307.yml

Lines changed: 10 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -10,16 +10,16 @@ description: |
1010
via the /admin/pictures image filename field.
1111
cvss_v3: 5.9
1212
unaffected_versions:
13-
- "< 4.1.0"
13+
- "< 4.1.0"
1414
patched_versions:
15-
- ">= 7.4.10"
15+
- ">= 7.4.10"
1616
related:
1717
url:
18-
- https://nvd.nist.gov/vuln/detail/CVE-2018-18307
19-
- http://packetstormsecurity.com/files/149787/Alchemy-CMS-4.1-Stable-Cross-Site-Scripting.html
20-
- https://github.com/AlchemyCMS/alchemy_cms/blob/4.1-stable/app/controllers/alchemy/admin/base_controller.rb#L15
21-
- https://github.com/AlchemyCMS/alchemy_cms/blob/4.1-stable/app/controllers/alchemy/admin/pictures_controller.rb#L5
22-
- https://github.com/AlchemyCMS/alchemy_cms/blob/4.1-stable/app/controllers/alchemy/admin/resources_controller.rb#L21
23-
- https://github.com/AlchemyCMS/alchemy_cms/pull/3375
24-
- https://github.com/AlchemyCMS/alchemy_cms/releases/tag/v7.4.10
25-
- https://github.com/advisories/GHSA-7mj4-2984-955f
18+
- https://nvd.nist.gov/vuln/detail/CVE-2018-18307
19+
- http://packetstormsecurity.com/files/149787/Alchemy-CMS-4.1-Stable-Cross-Site-Scripting.html
20+
- https://github.com/AlchemyCMS/alchemy_cms/blob/4.1-stable/app/controllers/alchemy/admin/base_controller.rb#L15
21+
- https://github.com/AlchemyCMS/alchemy_cms/blob/4.1-stable/app/controllers/alchemy/admin/pictures_controller.rb#L5
22+
- https://github.com/AlchemyCMS/alchemy_cms/blob/4.1-stable/app/controllers/alchemy/admin/resources_controller.rb#L21
23+
- https://github.com/AlchemyCMS/alchemy_cms/pull/3375
24+
- https://github.com/AlchemyCMS/alchemy_cms/releases/tag/v7.4.10
25+
- https://github.com/advisories/GHSA-7mj4-2984-955f

gems/ckeditor/CVE-2020-27193.yml

Lines changed: 9 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -11,14 +11,14 @@ description: |
1111
a user to copy and paste crafted HTML code into one of editor inputs.
1212
cvss_v3: 6.1
1313
patched_versions:
14-
- ">= 5.1.2"
14+
- ">= 5.1.2"
1515
related:
1616
url:
17-
- https://nvd.nist.gov/vuln/detail/CVE-2020-27193
18-
- https://ckeditor.com/blog/CKEditor-4.15.1-with-a-security-patch-released/
19-
- https://ckeditor.com/cke4/release/CKEditor-4.15.1
20-
- https://ckeditor.com/ckeditor-4/download/
21-
- https://www.oracle.com//security-alerts/cpujul2021.html
22-
- https://www.oracle.com/security-alerts/cpuApr2021.html
23-
- https://www.oracle.com/security-alerts/cpuoct2021.html
24-
- https://github.com/advisories/GHSA-4m44-5j2g-xf64
17+
- https://nvd.nist.gov/vuln/detail/CVE-2020-27193
18+
- https://ckeditor.com/blog/CKEditor-4.15.1-with-a-security-patch-released/
19+
- https://ckeditor.com/cke4/release/CKEditor-4.15.1
20+
- https://ckeditor.com/ckeditor-4/download/
21+
- https://www.oracle.com//security-alerts/cpujul2021.html
22+
- https://www.oracle.com/security-alerts/cpuApr2021.html
23+
- https://www.oracle.com/security-alerts/cpuoct2021.html
24+
- https://github.com/advisories/GHSA-4m44-5j2g-xf64

gems/ckeditor/CVE-2020-9281.yml

Lines changed: 12 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -11,17 +11,17 @@ description: |
1111
through a crafted "protected" comment (with the cke_protected syntax).
1212
cvss_v3: 6.1
1313
patched_versions:
14-
- ">= 5.1.2"
14+
- ">= 5.1.2"
1515
related:
1616
url:
17-
- https://nvd.nist.gov/vuln/detail/CVE-2020-9281
18-
- https://github.com/ckeditor/ckeditor4
19-
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7OJ4BSS3VEAEXPNSOOUAXX6RDNECGZNO/
20-
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/L322YA73LCV3TO7ORY45WQDAFJVNKXBE/
21-
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/M4HHYQ6N452XTCIROFMJOTYEUWSB6FR4/
22-
- https://www.oracle.com/security-alerts/cpujan2021.html
23-
- https://www.oracle.com/security-alerts/cpuoct2020.html
24-
- https://www.oracle.com/security-alerts/cpuApr2021.html
25-
- https://www.oracle.com/security-alerts/cpuoct2021.html
26-
- https://www.oracle.com/security-alerts/cpujan2022.html
27-
- https://github.com/advisories/GHSA-vcjf-mgcg-jxjq
17+
- https://nvd.nist.gov/vuln/detail/CVE-2020-9281
18+
- https://github.com/ckeditor/ckeditor4
19+
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7OJ4BSS3VEAEXPNSOOUAXX6RDNECGZNO/
20+
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/L322YA73LCV3TO7ORY45WQDAFJVNKXBE/
21+
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/M4HHYQ6N452XTCIROFMJOTYEUWSB6FR4/
22+
- https://www.oracle.com/security-alerts/cpujan2021.html
23+
- https://www.oracle.com/security-alerts/cpuoct2020.html
24+
- https://www.oracle.com/security-alerts/cpuApr2021.html
25+
- https://www.oracle.com/security-alerts/cpuoct2021.html
26+
- https://www.oracle.com/security-alerts/cpujan2022.html
27+
- https://github.com/advisories/GHSA-vcjf-mgcg-jxjq

gems/ckeditor/CVE-2021-26272.yml

Lines changed: 8 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -11,13 +11,13 @@ description: |
1111
then press Enter or Space (in the Autolink plugin).
1212
cvss_v3: 6.5
1313
patched_versions:
14-
- ">= 5.1.2"
14+
- ">= 5.1.2"
1515
related:
1616
url:
17-
- https://nvd.nist.gov/vuln/detail/CVE-2021-26272
18-
- https://ckeditor.com/blog/CKEditor-4.16-with-improved-image-pasting-High-Contrast-support-and-a-new-color-API/#security-comes-first
19-
- https://github.com/ckeditor/ckeditor4/blob/major/CHANGES.md#ckeditor-416
20-
- https://www.oracle.com//security-alerts/cpujul2021.html
21-
- https://www.oracle.com/security-alerts/cpuoct2021.html
22-
- https://www.oracle.com/security-alerts/cpujan2022.html
23-
- https://github.com/advisories/GHSA-wpvm-wqr4-p7cw
17+
- https://nvd.nist.gov/vuln/detail/CVE-2021-26272
18+
- https://ckeditor.com/blog/CKEditor-4.16-with-improved-image-pasting-High-Contrast-support-and-a-new-color-API/#security-comes-first
19+
- https://github.com/ckeditor/ckeditor4/blob/major/CHANGES.md#ckeditor-416
20+
- https://www.oracle.com//security-alerts/cpujul2021.html
21+
- https://www.oracle.com/security-alerts/cpuoct2021.html
22+
- https://www.oracle.com/security-alerts/cpujan2022.html
23+
- https://github.com/advisories/GHSA-wpvm-wqr4-p7cw

gems/ckeditor/CVE-2021-32808.yml

Lines changed: 11 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -23,17 +23,17 @@ description: |
2323
The CKEditor 4 team would like to thank Anton Subbotin ([skavans](https://github.com/skavans)) for recognizing and reporting this vulnerability.
2424
cvss_v3: 7.6
2525
unaffected_versions:
26-
- "< 5.1.2"
26+
- "< 5.1.2"
2727
patched_versions:
28-
- ">= 5.1.2"
28+
- ">= 5.1.2"
2929
related:
3030
url:
31-
- https://github.com/ckeditor/ckeditor4/security/advisories/GHSA-6226-h7ff-ch6c
32-
- https://nvd.nist.gov/vuln/detail/CVE-2021-32808
33-
- https://github.com/ckeditor/ckeditor4/releases/tag/4.16.2
34-
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NYA354LJP47KCVJMTUO77ZCX3ZK42G3T/
35-
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UVOYN2WKDPLKCNILIGEZM236ABQASLGW/
36-
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WAGNWHFIQAVCP537KFFS2A2GDG66J7XD/
37-
- https://www.oracle.com/security-alerts/cpuoct2021.html
38-
- https://www.oracle.com/security-alerts/cpujan2022.html
39-
- https://github.com/advisories/GHSA-6226-h7ff-ch6c
31+
- https://github.com/ckeditor/ckeditor4/security/advisories/GHSA-6226-h7ff-ch6c
32+
- https://nvd.nist.gov/vuln/detail/CVE-2021-32808
33+
- https://github.com/ckeditor/ckeditor4/releases/tag/4.16.2
34+
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NYA354LJP47KCVJMTUO77ZCX3ZK42G3T/
35+
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UVOYN2WKDPLKCNILIGEZM236ABQASLGW/
36+
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WAGNWHFIQAVCP537KFFS2A2GDG66J7XD/
37+
- https://www.oracle.com/security-alerts/cpuoct2021.html
38+
- https://www.oracle.com/security-alerts/cpujan2022.html
39+
- https://github.com/advisories/GHSA-6226-h7ff-ch6c

gems/ckeditor/CVE-2021-32809.yml

Lines changed: 10 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -31,16 +31,16 @@ description: |
3131
The CKEditor 4 team would like to thank Anton Subbotin ([skavans](https://github.com/skavans)) for recognizing and reporting this vulnerability.
3232
cvss_v3: 4.6
3333
unaffected_versions:
34-
- "< 4.1.2"
34+
- "< 4.1.2"
3535
patched_versions:
36-
- ">= 5.1.2"
36+
- ">= 5.1.2"
3737
related:
3838
url:
39-
- https://github.com/ckeditor/ckeditor4/security/advisories/GHSA-7889-rm5j-hpgg
40-
- https://nvd.nist.gov/vuln/detail/CVE-2021-32809
41-
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NYA354LJP47KCVJMTUO77ZCX3ZK42G3T/
42-
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UVOYN2WKDPLKCNILIGEZM236ABQASLGW/
43-
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WAGNWHFIQAVCP537KFFS2A2GDG66J7XD/
44-
- https://www.oracle.com/security-alerts/cpuoct2021.html
45-
- https://www.oracle.com/security-alerts/cpujan2022.html
46-
- https://github.com/advisories/GHSA-7889-rm5j-hpgg
39+
- https://github.com/ckeditor/ckeditor4/security/advisories/GHSA-7889-rm5j-hpgg
40+
- https://nvd.nist.gov/vuln/detail/CVE-2021-32809
41+
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NYA354LJP47KCVJMTUO77ZCX3ZK42G3T/
42+
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UVOYN2WKDPLKCNILIGEZM236ABQASLGW/
43+
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WAGNWHFIQAVCP537KFFS2A2GDG66J7XD/
44+
- https://www.oracle.com/security-alerts/cpuoct2021.html
45+
- https://www.oracle.com/security-alerts/cpujan2022.html
46+
- https://github.com/advisories/GHSA-7889-rm5j-hpgg

gems/ckeditor/CVE-2021-33829.yml

Lines changed: 13 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -11,19 +11,19 @@ description: |
1111
executable JavaScript code through a crafted comment because `--!>` is mishandled.
1212
cvss_v3: 6.1
1313
unaffected_versions:
14-
- "< 5.1.1"
14+
- "< 5.1.1"
1515
patched_versions:
16-
- ">= 5.1.2"
16+
- ">= 5.1.2"
1717
related:
1818
url:
19-
- https://nvd.nist.gov/vuln/detail/CVE-2021-33829
20-
- https://ckeditor.com/blog/ckeditor-4.16.1-with-accessibility-enhancements/#improvements-for-comments-in-html-parser
21-
- https://www.npmjs.com/package/ckeditor4
22-
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NYA354LJP47KCVJMTUO77ZCX3ZK42G3T/
23-
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UVOYN2WKDPLKCNILIGEZM236ABQASLGW/
24-
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WAGNWHFIQAVCP537KFFS2A2GDG66J7XD/
25-
- https://www.drupal.org/sa-core-2021-003
26-
- https://lists.debian.org/debian-lts-announce/2021/11/msg00007.html
27-
- https://github.com/FriendsOfPHP/security-advisories/blob/master/drupal/core/CVE-2021-33829.yaml
28-
- https://github.com/FriendsOfPHP/security-advisories/blob/master/drupal/drupal/CVE-2021-33829.yaml
29-
- https://github.com/advisories/GHSA-rgx6-rjj4-c388
19+
- https://nvd.nist.gov/vuln/detail/CVE-2021-33829
20+
- https://ckeditor.com/blog/ckeditor-4.16.1-with-accessibility-enhancements/#improvements-for-comments-in-html-parser
21+
- https://www.npmjs.com/package/ckeditor4
22+
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NYA354LJP47KCVJMTUO77ZCX3ZK42G3T/
23+
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UVOYN2WKDPLKCNILIGEZM236ABQASLGW/
24+
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WAGNWHFIQAVCP537KFFS2A2GDG66J7XD/
25+
- https://www.drupal.org/sa-core-2021-003
26+
- https://lists.debian.org/debian-lts-announce/2021/11/msg00007.html
27+
- https://github.com/FriendsOfPHP/security-advisories/blob/master/drupal/core/CVE-2021-33829.yaml
28+
- https://github.com/FriendsOfPHP/security-advisories/blob/master/drupal/drupal/CVE-2021-33829.yaml
29+
- https://github.com/advisories/GHSA-rgx6-rjj4-c388

gems/ckeditor/CVE-2021-37695.yml

Lines changed: 11 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -30,16 +30,16 @@ description: |
3030
The CKEditor 4 team would like to thank Mika Kulmala ([kulmik](https://github.com/kulmik)) for recognizing and reporting this vulnerability.
3131
cvss_v3: 7.3
3232
patched_versions:
33-
- ">= 5.1.2"
33+
- ">= 5.1.2"
3434
related:
3535
url:
36-
- https://github.com/ckeditor/ckeditor4/security/advisories/GHSA-m94c-37g6-cjhc
37-
- https://nvd.nist.gov/vuln/detail/CVE-2021-37695
38-
- https://github.com/ckeditor/ckeditor4/commit/de3c001540715f9c3801aaa38a1917de46cfcf58
39-
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NYA354LJP47KCVJMTUO77ZCX3ZK42G3T/
40-
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UVOYN2WKDPLKCNILIGEZM236ABQASLGW/
41-
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WAGNWHFIQAVCP537KFFS2A2GDG66J7XD/
42-
- https://www.oracle.com/security-alerts/cpuoct2021.html
43-
- https://lists.debian.org/debian-lts-announce/2021/11/msg00007.html
44-
- https://www.oracle.com/security-alerts/cpujan2022.html
45-
- https://github.com/advisories/GHSA-m94c-37g6-cjhc
36+
- https://github.com/ckeditor/ckeditor4/security/advisories/GHSA-m94c-37g6-cjhc
37+
- https://nvd.nist.gov/vuln/detail/CVE-2021-37695
38+
- https://github.com/ckeditor/ckeditor4/commit/de3c001540715f9c3801aaa38a1917de46cfcf58
39+
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NYA354LJP47KCVJMTUO77ZCX3ZK42G3T/
40+
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UVOYN2WKDPLKCNILIGEZM236ABQASLGW/
41+
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WAGNWHFIQAVCP537KFFS2A2GDG66J7XD/
42+
- https://www.oracle.com/security-alerts/cpuoct2021.html
43+
- https://lists.debian.org/debian-lts-announce/2021/11/msg00007.html
44+
- https://www.oracle.com/security-alerts/cpujan2022.html
45+
- https://github.com/advisories/GHSA-m94c-37g6-cjhc

gems/ckeditor/CVE-2021-41164.yml

Lines changed: 11 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -23,16 +23,16 @@ description: |
2323
The CKEditor 4 team would like to thank Maurice Dauer ([laytonctf](https://twitter.com/laytonctf)) for recognizing and reporting this vulnerability.
2424
cvss_v3: 8.2
2525
patched_versions:
26-
- ">= 5.1.2"
26+
- ">= 5.1.2"
2727
related:
2828
url:
29-
- https://github.com/ckeditor/ckeditor4/security/advisories/GHSA-pvmx-g8h5-cprj
30-
- https://github.com/ckeditor/ckeditor4/blob/major/CHANGES.md#ckeditor-417
31-
- https://nvd.nist.gov/vuln/detail/CVE-2021-41164
32-
- https://www.drupal.org/sa-core-2021-011
33-
- https://www.oracle.com/security-alerts/cpujan2022.html
34-
- https://www.oracle.com/security-alerts/cpuapr2022.html
35-
- https://www.oracle.com/security-alerts/cpujul2022.html
36-
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WOZGMCYDB2OKKULFXZKM6V7JJW4ZZHJP/
37-
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VR76VBN5GW5QUBJFHVXRX36UZ6YTCMW6/
38-
- https://github.com/advisories/GHSA-pvmx-g8h5-cprj
29+
- https://github.com/ckeditor/ckeditor4/security/advisories/GHSA-pvmx-g8h5-cprj
30+
- https://github.com/ckeditor/ckeditor4/blob/major/CHANGES.md#ckeditor-417
31+
- https://nvd.nist.gov/vuln/detail/CVE-2021-41164
32+
- https://www.drupal.org/sa-core-2021-011
33+
- https://www.oracle.com/security-alerts/cpujan2022.html
34+
- https://www.oracle.com/security-alerts/cpuapr2022.html
35+
- https://www.oracle.com/security-alerts/cpujul2022.html
36+
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WOZGMCYDB2OKKULFXZKM6V7JJW4ZZHJP/
37+
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VR76VBN5GW5QUBJFHVXRX36UZ6YTCMW6/
38+
- https://github.com/advisories/GHSA-pvmx-g8h5-cprj

gems/ckeditor/CVE-2021-41165.yml

Lines changed: 9 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -22,14 +22,14 @@ description: |
2222
The CKEditor 4 team would like to thank William Bowling ([wbowling](https://github.com/wbowling)) for recognizing and reporting this vulnerability.
2323
cvss_v3: 8.2
2424
patched_versions:
25-
- ">= 5.1.2"
25+
- ">= 5.1.2"
2626
related:
2727
url:
28-
- https://github.com/ckeditor/ckeditor4/security/advisories/GHSA-7h26-63m7-qhf2
29-
- https://github.com/ckeditor/ckeditor4/blob/major/CHANGES.md#ckeditor-417
30-
- https://nvd.nist.gov/vuln/detail/CVE-2021-41165
31-
- https://www.drupal.org/sa-core-2021-011
32-
- https://www.oracle.com/security-alerts/cpujan2022.html
33-
- https://www.oracle.com/security-alerts/cpuapr2022.html
34-
- https://www.oracle.com/security-alerts/cpujul2022.html
35-
- https://github.com/advisories/GHSA-7h26-63m7-qhf2
28+
- https://github.com/ckeditor/ckeditor4/security/advisories/GHSA-7h26-63m7-qhf2
29+
- https://github.com/ckeditor/ckeditor4/blob/major/CHANGES.md#ckeditor-417
30+
- https://nvd.nist.gov/vuln/detail/CVE-2021-41165
31+
- https://www.drupal.org/sa-core-2021-011
32+
- https://www.oracle.com/security-alerts/cpujan2022.html
33+
- https://www.oracle.com/security-alerts/cpuapr2022.html
34+
- https://www.oracle.com/security-alerts/cpujul2022.html
35+
- https://github.com/advisories/GHSA-7h26-63m7-qhf2

0 commit comments

Comments
 (0)