From 75e4aa53b1a9023a05a1136434cc1e3a24a4f4cb Mon Sep 17 00:00:00 2001 From: "octo-sts[bot]" <157150467+octo-sts@users.noreply.github.com> Date: Tue, 24 Dec 2024 08:08:28 +0000 Subject: [PATCH 1/2] Adding Advisory GHSA-gmj6-6f8f-6699 for checkov --- checkov.advisories.yaml | 18 ++++++++++++++++++ 1 file changed, 18 insertions(+) diff --git a/checkov.advisories.yaml b/checkov.advisories.yaml index d7f0f17339..d9f6ae6380 100644 --- a/checkov.advisories.yaml +++ b/checkov.advisories.yaml @@ -238,6 +238,24 @@ advisories: data: fixed-version: 3.0.34-r1 + - id: CGA-q48p-2qpp-m58h + aliases: + - CVE-2024-56201 + - GHSA-gmj6-6f8f-6699 + events: + - timestamp: 2024-12-24T08:08:22Z + type: detection + data: + type: scan/v1 + data: + subpackageName: checkov + componentID: ae6375fd23f53aee + componentName: jinja2 + componentVersion: 3.1.4 + componentType: python + componentLocation: /usr/share/app/checkov/.venv/lib/python3.11/site-packages/jinja2-3.1.4.dist-info/METADATA, /usr/share/app/checkov/.venv/lib/python3.11/site-packages/jinja2-3.1.4.dist-info/RECORD + scanner: grype + - id: CGA-qc2h-qqvx-x87c aliases: - CVE-2024-5569 From d403d6e6640ec9f7e2aed8115bb1575022cdc0e8 Mon Sep 17 00:00:00 2001 From: "octo-sts[bot]" <157150467+octo-sts@users.noreply.github.com> Date: Tue, 24 Dec 2024 08:08:34 +0000 Subject: [PATCH 2/2] Adding Advisory GHSA-q2x7-8rv6-6q7h for checkov --- checkov.advisories.yaml | 18 ++++++++++++++++++ 1 file changed, 18 insertions(+) diff --git a/checkov.advisories.yaml b/checkov.advisories.yaml index d9f6ae6380..b194692e54 100644 --- a/checkov.advisories.yaml +++ b/checkov.advisories.yaml @@ -26,6 +26,24 @@ advisories: data: fixed-version: 3.0.34-r1 + - id: CGA-4qcp-6r5p-mjg3 + aliases: + - CVE-2024-56326 + - GHSA-q2x7-8rv6-6q7h + events: + - timestamp: 2024-12-24T08:08:28Z + type: detection + data: + type: scan/v1 + data: + subpackageName: checkov + componentID: ae6375fd23f53aee + componentName: jinja2 + componentVersion: 3.1.4 + componentType: python + componentLocation: /usr/share/app/checkov/.venv/lib/python3.11/site-packages/jinja2-3.1.4.dist-info/METADATA, /usr/share/app/checkov/.venv/lib/python3.11/site-packages/jinja2-3.1.4.dist-info/RECORD + scanner: grype + - id: CGA-5fg5-6gpx-x74f aliases: - CVE-2024-30251