File tree 5 files changed +48
-11
lines changed
advisories/github-reviewed/2025/01
5 files changed +48
-11
lines changed Original file line number Diff line number Diff line change 1
1
{
2
2
"schema_version" : " 1.4.0" ,
3
3
"id" : " GHSA-8vmr-h7h5-cqhg" ,
4
- "modified" : " 2025-01-16T19:05:01Z " ,
4
+ "modified" : " 2025-01-16T22:35:37Z " ,
5
5
"published" : " 2025-01-16T19:05:01Z" ,
6
6
"aliases" : [
7
7
" CVE-2024-36402"
40
40
"type" : " WEB" ,
41
41
"url" : " https://github.com/t2bot/matrix-media-repo/security/advisories/GHSA-8vmr-h7h5-cqhg"
42
42
},
43
+ {
44
+ "type" : " ADVISORY" ,
45
+ "url" : " https://nvd.nist.gov/vuln/detail/CVE-2024-36402"
46
+ },
43
47
{
44
48
"type" : " WEB" ,
45
49
"url" : " https://github.com/matrix-org/matrix-spec-proposals/pull/3916"
56
60
"severity" : " MODERATE" ,
57
61
"github_reviewed" : true ,
58
62
"github_reviewed_at" : " 2025-01-16T19:05:01Z" ,
59
- "nvd_published_at" : null
63
+ "nvd_published_at" : " 2025-01-16T20:15:32Z "
60
64
}
61
65
}
Original file line number Diff line number Diff line change 1
1
{
2
2
"schema_version" : " 1.4.0" ,
3
3
"id" : " GHSA-gp86-q8hg-fpxj" ,
4
- "modified" : " 2025-01-16T19:07:43Z " ,
4
+ "modified" : " 2025-01-16T22:36:04Z " ,
5
5
"published" : " 2025-01-16T19:07:43Z" ,
6
6
"aliases" : [
7
7
" CVE-2024-52791"
43
43
"type" : " WEB" ,
44
44
"url" : " https://github.com/t2bot/matrix-media-repo/security/advisories/GHSA-gp86-q8hg-fpxj"
45
45
},
46
+ {
47
+ "type" : " ADVISORY" ,
48
+ "url" : " https://nvd.nist.gov/vuln/detail/CVE-2024-52791"
49
+ },
46
50
{
47
51
"type" : " PACKAGE" ,
48
52
"url" : " https://github.com/t2bot/matrix-media-repo"
59
63
"severity" : " MODERATE" ,
60
64
"github_reviewed" : true ,
61
65
"github_reviewed_at" : " 2025-01-16T19:07:43Z" ,
62
- "nvd_published_at" : null
66
+ "nvd_published_at" : " 2025-01-16T20:15:32Z "
63
67
}
64
68
}
Original file line number Diff line number Diff line change 1
1
{
2
2
"schema_version" : " 1.4.0" ,
3
3
"id" : " GHSA-r6jg-jfv6-2fjv" ,
4
- "modified" : " 2025-01-16T19 :35:02Z " ,
4
+ "modified" : " 2025-01-16T22 :35:55Z " ,
5
5
"published" : " 2025-01-16T19:35:02Z" ,
6
6
"aliases" : [
7
7
" CVE-2024-52602"
43
43
"type" : " WEB" ,
44
44
"url" : " https://github.com/t2bot/matrix-media-repo/security/advisories/GHSA-r6jg-jfv6-2fjv"
45
45
},
46
+ {
47
+ "type" : " ADVISORY" ,
48
+ "url" : " https://nvd.nist.gov/vuln/detail/CVE-2024-52602"
49
+ },
46
50
{
47
51
"type" : " PACKAGE" ,
48
52
"url" : " https://github.com/t2bot/matrix-media-repo"
49
53
},
50
54
{
51
55
"type" : " WEB" ,
52
56
"url" : " https://github.com/t2bot/matrix-media-repo/releases/tag/v1.3.8"
57
+ },
58
+ {
59
+ "type" : " WEB" ,
60
+ "url" : " https://learn.snyk.io/lesson/ssrf-server-side-request-forgery"
61
+ },
62
+ {
63
+ "type" : " WEB" ,
64
+ "url" : " https://owasp.org/www-community/attacks/Server_Side_Request_Forgery"
65
+ },
66
+ {
67
+ "type" : " WEB" ,
68
+ "url" : " https://www.agwa.name/blog/post/preventing_server_side_request_forgery_in_golang"
53
69
}
54
70
],
55
71
"database_specific" : {
59
75
"severity" : " MODERATE" ,
60
76
"github_reviewed" : true ,
61
77
"github_reviewed_at" : " 2025-01-16T19:35:02Z" ,
62
- "nvd_published_at" : null
78
+ "nvd_published_at" : " 2025-01-16T20:15:32Z "
63
79
}
64
80
}
Original file line number Diff line number Diff line change 1
1
{
2
2
"schema_version" : " 1.4.0" ,
3
3
"id" : " GHSA-rcxc-wjgw-579r" ,
4
- "modified" : " 2025-01-16T19:35:09Z " ,
4
+ "modified" : " 2025-01-16T22:36:15Z " ,
5
5
"published" : " 2025-01-16T19:35:09Z" ,
6
6
"aliases" : [
7
7
" CVE-2024-56515"
43
43
"type" : " WEB" ,
44
44
"url" : " https://github.com/t2bot/matrix-media-repo/security/advisories/GHSA-rcxc-wjgw-579r"
45
45
},
46
+ {
47
+ "type" : " ADVISORY" ,
48
+ "url" : " https://nvd.nist.gov/vuln/detail/CVE-2024-56515"
49
+ },
46
50
{
47
51
"type" : " PACKAGE" ,
48
52
"url" : " https://github.com/t2bot/matrix-media-repo"
54
58
],
55
59
"database_specific" : {
56
60
"cwe_ids" : [
57
- " CWE-434"
61
+ " CWE-434" ,
62
+ " CWE-502"
58
63
],
59
64
"severity" : " MODERATE" ,
60
65
"github_reviewed" : true ,
61
66
"github_reviewed_at" : " 2025-01-16T19:35:09Z" ,
62
- "nvd_published_at" : null
67
+ "nvd_published_at" : " 2025-01-16T20:15:33Z "
63
68
}
64
69
}
Original file line number Diff line number Diff line change 1
1
{
2
2
"schema_version" : " 1.4.0" ,
3
3
"id" : " GHSA-vc2m-hw89-qjxf" ,
4
- "modified" : " 2025-01-16T19:05:12Z " ,
4
+ "modified" : " 2025-01-16T22:35:46Z " ,
5
5
"published" : " 2025-01-16T19:05:12Z" ,
6
6
"aliases" : [
7
7
" CVE-2024-36403"
40
40
"type" : " WEB" ,
41
41
"url" : " https://github.com/t2bot/matrix-media-repo/security/advisories/GHSA-vc2m-hw89-qjxf"
42
42
},
43
+ {
44
+ "type" : " ADVISORY" ,
45
+ "url" : " https://nvd.nist.gov/vuln/detail/CVE-2024-36403"
46
+ },
47
+ {
48
+ "type" : " WEB" ,
49
+ "url" : " https://en.wikipedia.org/wiki/Leaky_bucket#As_a_meter"
50
+ },
43
51
{
44
52
"type" : " PACKAGE" ,
45
53
"url" : " https://github.com/t2bot/matrix-media-repo"
52
60
"severity" : " MODERATE" ,
53
61
"github_reviewed" : true ,
54
62
"github_reviewed_at" : " 2025-01-16T19:05:12Z" ,
55
- "nvd_published_at" : null
63
+ "nvd_published_at" : " 2025-01-16T20:15:32Z "
56
64
}
57
65
}
You can’t perform that action at this time.
0 commit comments