From 4c6db5ec00710bf014d23886626c1e1a7ff09109 Mon Sep 17 00:00:00 2001 From: Weston Steimel Date: Tue, 21 May 2024 15:16:30 +0100 Subject: [PATCH] conversion for wolfssl records Signed-off-by: Weston Steimel --- data/anchore/2023/CVE-2023-6935.json | 38 ++++++++++++++++++++++++++++ data/anchore/2023/CVE-2023-6936.json | 38 ++++++++++++++++++++++++++++ data/anchore/2023/CVE-2023-6937.json | 38 ++++++++++++++++++++++++++++ data/anchore/2024/CVE-2024-0901.json | 38 ++++++++++++++++++++++++++++ 4 files changed, 152 insertions(+) create mode 100644 data/anchore/2023/CVE-2023-6935.json create mode 100644 data/anchore/2023/CVE-2023-6936.json create mode 100644 data/anchore/2023/CVE-2023-6937.json create mode 100644 data/anchore/2024/CVE-2024-0901.json diff --git a/data/anchore/2023/CVE-2023-6935.json b/data/anchore/2023/CVE-2023-6935.json new file mode 100644 index 00000000..bd5979d1 --- /dev/null +++ b/data/anchore/2023/CVE-2023-6935.json @@ -0,0 +1,38 @@ +{ + "additionalMetadata": { + "cna": "wolfssl", + "cveId": "CVE-2023-6935", + "reason": "Added CPE configurations because not yet analyzed by NVD.", + "references": [ + "https://www.wolfssl.com/docs/security-vulnerabilities/", + "https://people.redhat.com/~hkario/marvin/" + ], + "solutions": [ + "Upgrade wolfSSL to 5.6.6" + ] + }, + "adp": { + "affected": [ + { + "cpes": [ + "cpe:2.3:a:wolfssl:wolfssl:*:*:*:*:*:*:*:*" + ], + "product": "wolfSSL", + "repo": "https://github.com/wolfSSL/wolfssl", + "vendor": "wolfSSL", + "versions": [ + { + "lessThan": "5.6.6", + "status": "affected", + "version": "3.12.2", + "versionType": "semver" + } + ] + } + ], + "providerMetadata": { + "orgId": "00000000-0000-4000-8000-000000000000", + "shortName": "anchoreadp" + } + } +} \ No newline at end of file diff --git a/data/anchore/2023/CVE-2023-6936.json b/data/anchore/2023/CVE-2023-6936.json new file mode 100644 index 00000000..2b9bea11 --- /dev/null +++ b/data/anchore/2023/CVE-2023-6936.json @@ -0,0 +1,38 @@ +{ + "additionalMetadata": { + "cna": "wolfssl", + "cveId": "CVE-2023-6936", + "reason": "Added CPE configurations because not yet analyzed by NVD.", + "references": [ + "https://www.wolfssl.com/docs/security-vulnerabilities/", + "https://github.com/wolfSSL/wolfssl/pull/6949/" + ], + "solutions": [ + "The fix for this issue is located in the following GitHub Pull Request: https://github.com/wolfSSL/wolfssl/pull/6949/ https://github.com/wolfSSL/wolfssl/pull/6949/ \n\n" + ] + }, + "adp": { + "affected": [ + { + "cpes": [ + "cpe:2.3:a:wolfssl:wolfssl:*:*:*:*:*:*:*:*" + ], + "product": "wolfSSL", + "repo": "https://github.com/wolfSSL/wolfssl", + "vendor": "wolfSSL", + "versions": [ + { + "lessThan": "5.6.6", + "status": "affected", + "version": "0", + "versionType": "semver" + } + ] + } + ], + "providerMetadata": { + "orgId": "00000000-0000-4000-8000-000000000000", + "shortName": "anchoreadp" + } + } +} \ No newline at end of file diff --git a/data/anchore/2023/CVE-2023-6937.json b/data/anchore/2023/CVE-2023-6937.json new file mode 100644 index 00000000..3c716c24 --- /dev/null +++ b/data/anchore/2023/CVE-2023-6937.json @@ -0,0 +1,38 @@ +{ + "additionalMetadata": { + "cna": "wolfssl", + "cveId": "CVE-2023-6937", + "reason": "Added CPE configurations because not yet analyzed by NVD.", + "references": [ + "https://github.com/wolfSSL/wolfssl/pull/7029", + "https://www.wolfssl.com/docs/security-vulnerabilities/" + ], + "solutions": [ + "The fix for this issue is located in the following GitHub Pull Request: https://github.com/wolfSSL/wolfssl/pull/7029 https://github.com/wolfSSL/wolfssl/pull/7029 .\n\n" + ] + }, + "adp": { + "affected": [ + { + "cpes": [ + "cpe:2.3:a:wolfssl:wolfssl:*:*:*:*:*:*:*:*" + ], + "product": "wolfSSL", + "repo": "https://github.com/wolfSSL/wolfssl", + "vendor": "wolfSSL", + "versions": [ + { + "lessThan": "5.6.6", + "status": "affected", + "version": "0", + "versionType": "semver" + } + ] + } + ], + "providerMetadata": { + "orgId": "00000000-0000-4000-8000-000000000000", + "shortName": "anchoreadp" + } + } +} \ No newline at end of file diff --git a/data/anchore/2024/CVE-2024-0901.json b/data/anchore/2024/CVE-2024-0901.json new file mode 100644 index 00000000..c320fd16 --- /dev/null +++ b/data/anchore/2024/CVE-2024-0901.json @@ -0,0 +1,38 @@ +{ + "additionalMetadata": { + "cna": "wolfssl", + "cveId": "CVE-2024-0901", + "reason": "Added CPE configurations because not yet analyzed by NVD.", + "references": [ + "https://github.com/wolfSSL/wolfssl/pull/7099", + "https://github.com/wolfSSL/wolfssl/issues/7089" + ], + "solutions": [ + "Update wolfSSL to 5.7.0 or apply the fix located in:  https://github.com/wolfSSL/wolfssl/pull/7099 .\n" + ] + }, + "adp": { + "affected": [ + { + "cpes": [ + "cpe:2.3:a:wolfssl:wolfssl:*:*:*:*:*:*:*:*" + ], + "product": "wolfSSL", + "repo": "https://github.com/wolfSSL/wolfssl", + "vendor": "wolfSSL", + "versions": [ + { + "lessThan": "5.7.0", + "status": "affected", + "version": "3.12.2", + "versionType": "semver" + } + ] + } + ], + "providerMetadata": { + "orgId": "00000000-0000-4000-8000-000000000000", + "shortName": "anchoreadp" + } + } +} \ No newline at end of file