Skip to content

Commit

Permalink
enrich misc github records
Browse files Browse the repository at this point in the history
Signed-off-by: Weston Steimel <[email protected]>
  • Loading branch information
westonsteimel committed May 28, 2024
1 parent be8abfc commit c65d776
Show file tree
Hide file tree
Showing 13 changed files with 453 additions and 0 deletions.
36 changes: 36 additions & 0 deletions data/anchore/2023/CVE-2023-6349.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,36 @@
{
"additionalMetadata": {
"cna": "google",
"cveId": "CVE-2023-6349",
"reason": "Added CPE configurations because not yet analyzed by NVD.",
"references": [
"https://crbug.com/webm/1642"
]
},
"adp": {
"affected": [
{
"collectionURL": "https://chromium.googlesource.com",
"cpes": [
"cpe:2.3:a:webmproject:libvpx:*:*:*:*:*:*:*:*"
],
"packageName": "libvpx",
"product": "libvpx",
"repo": "https://chromium.googlesource.com/webm/libvpx",
"vendor": "Chromium",
"versions": [
{
"lessThan": "1.13.1",
"status": "affected",
"version": "1.5.0",
"versionType": "semver"
}
]
}
],
"providerMetadata": {
"orgId": "00000000-0000-4000-8000-000000000000",
"shortName": "anchoreadp"
}
}
}
34 changes: 34 additions & 0 deletions data/anchore/2024/CVE-2024-27093.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,34 @@
{
"additionalMetadata": {
"cna": "github_m",
"cveId": "CVE-2024-27093",
"reason": "Added CPE configurations because not yet analyzed by NVD.",
"references": [
"https://github.com/stacklok/minder/commit/53868a878e93f29c43437f96dbc990b548e48d1d",
"https://github.com/stacklok/minder/security/advisories/GHSA-q6h8-4j2v-pjg4"
]
},
"adp": {
"affected": [
{
"cpes": [
"cpe:2.3:a:stacklok:minder:*:*:*:*:*:*:*:*"
],
"product": "minder",
"vendor": "stacklok",
"versions": [
{
"lessThan": "0.20240226.1425+ref.53868a8",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"providerMetadata": {
"orgId": "00000000-0000-4000-8000-000000000000",
"shortName": "anchoreadp"
}
}
}
36 changes: 36 additions & 0 deletions data/anchore/2024/CVE-2024-27308.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,36 @@
{
"additionalMetadata": {
"cna": "github_m",
"cveId": "CVE-2024-27308",
"reason": "Added CPE configurations because not yet analyzed by NVD.",
"references": [
"https://github.com/tokio-rs/mio/commit/90d4fe00df870acd3d38f3dc4face9aacab8fbb9",
"https://github.com/tokio-rs/mio/pull/1760",
"https://github.com/tokio-rs/mio/security/advisories/GHSA-r8w9-5wcg-vfj7",
"https://github.com/tokio-rs/tokio/issues/6369"
]
},
"adp": {
"affected": [
{
"cpes": [
"cpe:2.3:a:mio_project:mio:*:*:*:*:*:rust:*:*"
],
"product": "mio",
"vendor": "tokio-rs",
"versions": [
{
"lessThan": "0.8.11",
"status": "affected",
"version": "0.7.2",
"versionType": "custom"
}
]
}
],
"providerMetadata": {
"orgId": "00000000-0000-4000-8000-000000000000",
"shortName": "anchoreadp"
}
}
}
36 changes: 36 additions & 0 deletions data/anchore/2024/CVE-2024-27916.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,36 @@
{
"additionalMetadata": {
"cna": "github_m",
"cveId": "CVE-2024-27916",
"reason": "Added CPE configurations because not yet analyzed by NVD.",
"references": [
"https://github.com/stacklok/minder/blob/a115c8524fbd582b2b277eaadce024bebbded508/internal/controlplane/handlers_repositories.go#L277-L278",
"https://github.com/stacklok/minder/blob/main/internal/controlplane/handlers_repositories.go#L257-L299",
"https://github.com/stacklok/minder/commit/45750b4e9fb2de33365758366e06c19e999bd2eb",
"https://github.com/stacklok/minder/security/advisories/GHSA-v627-69v2-xx37"
]
},
"adp": {
"affected": [
{
"cpes": [
"cpe:2.3:a:stacklok:minder:*:*:*:*:*:*:*:*"
],
"product": "minder",
"vendor": "stacklok",
"versions": [
{
"lessThan": "0.0.33",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"providerMetadata": {
"orgId": "00000000-0000-4000-8000-000000000000",
"shortName": "anchoreadp"
}
}
}
36 changes: 36 additions & 0 deletions data/anchore/2024/CVE-2024-31455.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,36 @@
{
"additionalMetadata": {
"cna": "github_m",
"cveId": "CVE-2024-31455",
"reason": "Added CPE configurations because not yet analyzed by NVD.",
"references": [
"https://github.com/stacklok/minder/commit/11b6573ad62cfdd783a8bb52f3fce461466037f4",
"https://github.com/stacklok/minder/commit/5c381cfbf3e4b7ce040ed8511a1fae1a78a0014b",
"https://github.com/stacklok/minder/pull/2941",
"https://github.com/stacklok/minder/security/advisories/GHSA-ggp5-28x4-xcj9"
]
},
"adp": {
"affected": [
{
"cpes": [
"cpe:2.3:a:stacklok:minder:*:*:*:*:*:*:*:*"
],
"product": "minder",
"vendor": "stacklok",
"versions": [
{
"lessThan": "0.0.40",
"status": "affected",
"version": "0.0.39",
"versionType": "custom"
}
]
}
],
"providerMetadata": {
"orgId": "00000000-0000-4000-8000-000000000000",
"shortName": "anchoreadp"
}
}
}
34 changes: 34 additions & 0 deletions data/anchore/2024/CVE-2024-34084.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,34 @@
{
"additionalMetadata": {
"cna": "github_m",
"cveId": "CVE-2024-34084",
"reason": "Added CPE configurations because not yet analyzed by NVD.",
"references": [
"https://github.com/stacklok/minder/commit/3e5a527d2f1b535159206161d1d519602c75bd0d",
"https://github.com/stacklok/minder/security/advisories/GHSA-9c5w-9q3f-3hv7"
]
},
"adp": {
"affected": [
{
"cpes": [
"cpe:2.3:a:stacklok:minder:*:*:*:*:*:*:*:*"
],
"product": "minder",
"vendor": "stacklok",
"versions": [
{
"lessThan": "0.0.48",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"providerMetadata": {
"orgId": "00000000-0000-4000-8000-000000000000",
"shortName": "anchoreadp"
}
}
}
33 changes: 33 additions & 0 deletions data/anchore/2024/CVE-2024-35179.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,33 @@
{
"additionalMetadata": {
"cna": "github_m",
"cveId": "CVE-2024-35179",
"reason": "Added CPE configurations because not yet analyzed by NVD.",
"references": [
"https://github.com/stalwartlabs/mail-server/security/advisories/GHSA-5pfx-j27j-4c6h"
]
},
"adp": {
"affected": [
{
"cpes": [
"cpe:2.3:a:stalwartlabs:mail-server:*:*:*:*:*:*:*:*"
],
"product": "mail-server",
"vendor": "stalwartlabs",
"versions": [
{
"lessThan": "0.8.0",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"providerMetadata": {
"orgId": "00000000-0000-4000-8000-000000000000",
"shortName": "anchoreadp"
}
}
}
38 changes: 38 additions & 0 deletions data/anchore/2024/CVE-2024-35183.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,38 @@
{
"additionalMetadata": {
"cna": "github_m",
"cveId": "CVE-2024-35183",
"reason": "Added CPE configurations because not yet analyzed by NVD.",
"references": [
"https://github.com/wolfi-dev/wolfictl/blob/488b53823350caa706de3f01ec0eded9350c7da7/pkg/update/update.go#L143",
"https://github.com/wolfi-dev/wolfictl/blob/4dd6c95abb4bc0f9306350a8601057bd7a92bded/pkg/update/deps/cleanup.go#L49",
"https://github.com/wolfi-dev/wolfictl/blob/6d99909f7b1aa23f732d84dad054b02a61f530e6/pkg/git/git.go#L22",
"https://github.com/wolfi-dev/wolfictl/commit/0d06e1578300327c212dda26a5ab31d09352b9d0",
"https://github.com/wolfi-dev/wolfictl/commit/403e93569f46766b4e26e06cf9cd0cae5ee0c2a2",
"https://github.com/wolfi-dev/wolfictl/security/advisories/GHSA-8fg7-hp93-qhvr"
]
},
"adp": {
"affected": [
{
"cpes": [
"cpe:2.3:a:wolfi-dev:wolfictl:*:*:*:*:*:*:*:*"
],
"product": "wolfictl",
"vendor": "wolfi-dev",
"versions": [
{
"lessThan": "0.16.10",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"providerMetadata": {
"orgId": "00000000-0000-4000-8000-000000000000",
"shortName": "anchoreadp"
}
}
}
34 changes: 34 additions & 0 deletions data/anchore/2024/CVE-2024-35185.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,34 @@
{
"additionalMetadata": {
"cna": "github_m",
"cveId": "CVE-2024-35185",
"reason": "Added CPE configurations because not yet analyzed by NVD.",
"references": [
"https://github.com/stacklok/minder/commit/065049336aac0621ee00a0bb2211f8051d47c14b",
"https://github.com/stacklok/minder/security/advisories/GHSA-fjw8-3gp8-4cvx"
]
},
"adp": {
"affected": [
{
"cpes": [
"cpe:2.3:a:stacklok:minder:*:*:*:*:*:*:*:*"
],
"product": "minder",
"vendor": "stacklok",
"versions": [
{
"lessThan": "0.0.49",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"providerMetadata": {
"orgId": "00000000-0000-4000-8000-000000000000",
"shortName": "anchoreadp"
}
}
}
33 changes: 33 additions & 0 deletions data/anchore/2024/CVE-2024-35187.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,33 @@
{
"additionalMetadata": {
"cna": "github_m",
"cveId": "CVE-2024-35187",
"reason": "Added CPE configurations because not yet analyzed by NVD.",
"references": [
"https://github.com/stalwartlabs/mail-server/security/advisories/GHSA-rwp5-f854-ppg6"
]
},
"adp": {
"affected": [
{
"cpes": [
"cpe:2.3:a:stalwartlabs:mail-server:*:*:*:*:*:*:*:*"
],
"product": "mail-server",
"vendor": "stalwartlabs",
"versions": [
{
"lessThan": "0.8.0",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"providerMetadata": {
"orgId": "00000000-0000-4000-8000-000000000000",
"shortName": "anchoreadp"
}
}
}
Loading

0 comments on commit c65d776

Please sign in to comment.