diff --git a/gems/datagrid/CVE-2019-14281.yml b/gems/datagrid/CVE-2019-14281.yml index c376ba6da6..675b874a54 100644 --- a/gems/datagrid/CVE-2019-14281.yml +++ b/gems/datagrid/CVE-2019-14281.yml @@ -2,13 +2,30 @@ gem: datagrid cve: 2019-14281 ghsa: rqp5-pg7w-832p -url: https://github.com/rubygems/rubygems.org/issues/2072 +url: https://nvd.nist.gov/vuln/detail/CVE-2019-14281 date: 2019-07-31 title: Code execution backdoor in datagrid description: | - The datagrid gem 1.0.6 for Ruby, as distributed on RubyGems.org, included - a code-execution backdoor inserted by a third party. + The datagrid gem 1.0.6 for Ruby, as distributed on RubyGems.org, + included a code-execution backdoor inserted by a third party. +cvss_v2: 7.5 +cvss_v3: 9.8 unaffected_versions: - "< 1.0.6" - - "> 1.0.6" -cvss_v3: 9.8 + - "> 1.0.6, < 1.5.10" +patched_versions: + - "> 1.5.10" +related: + url: + - https://nvd.nist.gov/vuln/detail/CVE-2019-14281 + - https://rubygems.org/gems/datagrid/versions/1.6.0 + - https://rubygems.org/gems/datagrid/versions + - https://github.com/rubygems/rubygems.org/issues/2072 + - https://github.com/advisories/GHSA-rqp5-pg7w-832p +notes: | + - cvss_v2 and cvss_v3 (also GHSA URL) from nvd.nist.gov URL. + - https://rubygems.org/gems/datagrid/versions/1.5.10 was yanked. + - https://rubygems.org/gems/datagrid/versions/1.0.6 was yanked. + - https://github.com/rubygems/rubygems.org/issues/2072 (please yank 1.0.6) + - https://rubygems.org/gems/data_grid has only 0.0.1 and 0.0.2 release. + - https://github.com/kkempin/data_grid has only 0.0.1. diff --git a/gems/fog-dragonfly/CVE-2013-5671.yml b/gems/fog-dragonfly/CVE-2013-5671.yml index 6664313f64..e8a03231df 100644 --- a/gems/fog-dragonfly/CVE-2013-5671.yml +++ b/gems/fog-dragonfly/CVE-2013-5671.yml @@ -11,7 +11,24 @@ description: | failing to properly sanitize input passed via the imagemagickutils.rb script. This may allow a remote attacker to execute arbitrary commands. - This gem has been renamed. Please use "dragonfly" from now on. + lib/dragonfly/imagemagickutils.rb in the fog-dragonfly gem 0.8.2 + for Ruby allows remote attackers to execute arbitrary commands + via unspecified vectors. + + NOTE: This gem has been renamed. Please use "dragonfly" 1.0.0 from now on. cvss_v2: 7.5 patched_versions: - ">= 0.8.4" +related: + url: + - https://nvd.nist.gov/vuln/detail/CVE-2013-5671 + - https://rubygems.org/gems/dragonfly/versions/1.0 + - http://seclists.org/fulldisclosure/2013/Sep/18 + - http://seclists.org/oss-sec/2013/q3/526 + - http://seclists.org/oss-sec/2013/q3/528 + - http://www.vapid.dhs.org/advisories/fog-dragonfly-0.8.2-cmd-inj.html + - https://github.com/advisories/GHSA-qrgf-jqqm-x7xv +notes: | + - cvss_v2 from nvd.nist.gov URL. + - https://rubygems.org/gems/fog-dragonfly has only 0.8.1 and 0.8.2 + releases. Now use (renamed) "dragonfly" from now on. diff --git a/gems/iodine/CVE-2026-41146.yml b/gems/iodine/CVE-2026-41146.yml index 47da704ef6..83cd085467 100644 --- a/gems/iodine/CVE-2026-41146.yml +++ b/gems/iodine/CVE-2026-41146.yml @@ -258,14 +258,18 @@ description: | - The gem vendors a copy of the vulnerable parser in `ext/iodine/fio_json_parser.h` cvss_v4: 8.7 +patched_versions: + - ">= 0.7.59" related: url: - https://nvd.nist.gov/vuln/detail/CVE-2026-41146 - - https://github.com/boazsegev/iodine/releases/tag/v0.7.58 + - https://rubygems.org/gems/iodine/versions/0.7.59 + - https://github.com/boazsegev/iodine/releases/tag/v0.7.59 + - https://github.com/boazsegev/iodine/compare/v0.7.58...v0.7.59 - https://github.com/boazsegev/iodine/commit/0855989d74098d838b972520835cfc256bc479bc - https://github.com/boazsegev/facil.io/commit/5128747363055201d3ecf0e29bf0a961703c9fa0 - https://github.com/boazsegev/facil.io/security/advisories/GHSA-2x79-gwq3-vxxm - https://github.com/advisories/GHSA-2x79-gwq3-vxxm notes: | - - FYI: iodine commit above contains the unreleased patch. - - Found GHSA's `patched_versions:` field is "0.7.59" but never released. + - cvss_v4 from nvd.nist.gov URL. + - FYI: iodine commit above in 0.7.59 release. diff --git a/gems/openc3-cosmos-tool-iframe/CVE-2025-28382.yml b/gems/openc3-cosmos-tool-iframe/CVE-2025-28382.yml index 3091835361..4a84011166 100644 --- a/gems/openc3-cosmos-tool-iframe/CVE-2025-28382.yml +++ b/gems/openc3-cosmos-tool-iframe/CVE-2025-28382.yml @@ -2,7 +2,7 @@ gem: openc3-cosmos-tool-iframe cve: 2025-28382 ghsa: cf8v-5mrc-jv7f -url: https://github.com/advisories/GHSA-cf8v-5mrc-jv7f +url: https://nvd.nist.gov/vuln/detail/CVE-2025-28382 title: OpenC3 COSMOS Vulnerable to Directory Traversal via openc3-api/tables endpoint date: 2025-06-13 @@ -12,10 +12,18 @@ description: | cvss_v3: 7.5 unaffected_versions: - "< 6.0.0" -notes: Never patched +patched_versions: + - ">= 6.1.0" related: url: - https://nvd.nist.gov/vuln/detail/CVE-2025-28382 + - https://rubygems.org/gems/openc3-cosmos-tool-iframe/versions/6.1.0 + - https://github.com/OpenC3/cosmos/releases/tag/v6.1.0 + - https://github.com/OpenC3/cosmos/pull/1828/changes/fc7e11310a7cdf9f1939886e1b29009db4d4b718 - https://visionspace.com/openc3-cosmos-a-security-assessment-of-an-open-source-mission-framework - https://openc3.com - https://github.com/advisories/GHSA-cf8v-5mrc-jv7f +notes: | + - cvss_v3 from GHSA URL. + - NOTE: gem name is "openc3-cosmos-tool-iframe" and repo name is "cosmos". + - /tag/ URL has reference to CVE-2025-28382. diff --git a/gems/openc3-cosmos-tool-iframe/CVE-2025-28384.yml b/gems/openc3-cosmos-tool-iframe/CVE-2025-28384.yml index 8d900ac248..542689c53a 100644 --- a/gems/openc3-cosmos-tool-iframe/CVE-2025-28384.yml +++ b/gems/openc3-cosmos-tool-iframe/CVE-2025-28384.yml @@ -2,7 +2,7 @@ gem: openc3-cosmos-tool-iframe cve: 2025-28384 ghsa: p67j-387g-75wc -url: https://github.com/advisories/GHSA-p67j-387g-75wc +url: https://nvd.nist.gov/vuln/detail/CVE-2025-28384 title: OpenC3 COSMOS Vulnerable to Directory Traversal via /script-api/scripts/ endpoint date: 2025-06-13 @@ -12,10 +12,18 @@ description: | cvss_v3: 9.1 unaffected_versions: - "< 6.0.0" -notes: Never patched +patched_versions: + - ">= 6.1.0" related: url: - https://nvd.nist.gov/vuln/detail/CVE-2025-28384 + - https://rubygems.org/gems/openc3-cosmos-tool-iframe/versions/6.1.0 + - https://github.com/OpenC3/cosmos/releases/tag/v6.1.0 + - https://github.com/OpenC3/cosmos/pull/1828/changes/fc7e11310a7cdf9f1939886e1b29009db4d4b718 - https://visionspace.com/openc3-cosmos-a-security-assessment-of-an-open-source-mission-framework - https://openc3.com - https://github.com/advisories/GHSA-p67j-387g-75wc +notes: | + - cvss_v3 from GHSA URL. + - NOTE: gem name is "openc3-cosmos-tool-iframe" and repo name is "cosmos". + - /tag/ URL has reference to CVE-2025-28384. diff --git a/gems/oxidized-web/CVE-2019-25088.yml b/gems/oxidized-web/CVE-2019-25088.yml index 733fa653ce..bab93eff14 100644 --- a/gems/oxidized-web/CVE-2019-25088.yml +++ b/gems/oxidized-web/CVE-2019-25088.yml @@ -2,18 +2,34 @@ gem: oxidized-web cve: 2019-25088 ghsa: 8qwh-rm6c-jv96 -url: https://github.com/ytti/oxidized-web/pull/195 +url: https://nvd.nist.gov/vuln/detail/CVE-2019-25088 title: Oxidized Web vulnerable to Cross-site Scripting date: 2022-12-27 description: | A vulnerability was found in ytti Oxidized Web. It has been classified - as problematic. Affected is an unknown function of the file `lib/oxidized/web/views/conf_search.haml`. - The manipulation of the argument `to_research` leads to cross site scripting. It - is possible to launch the attack remotely. The name of the patch is 55ab9bdc68b03ebce9280b8746ef31d7fdedcc45. - It is recommended to apply a patch to fix this issue. VDB-216870 is the identifier - assigned to this vulnerability. + as problematic. Affected is an unknown function of the file + `lib/oxidized/web/views/conf_search.haml`. + + The manipulation of the argument `to_research` leads to cross site + scripting. It is possible to launch the attack remotely. + The name of the patch is 55ab9bdc68b03ebce9280b8746ef31d7fdedcc45. + + It is recommended to apply a patch to fix this issue. + VDB-216870 is the identifier assigned to this vulnerability. cvss_v3: 5.4 +patched_versions: + - ">= 0.14.0" related: url: - - https://github.com/ytti/oxidized-web/commit/55ab9bdc68b03ebce9280b8746ef31d7fdedcc45 + - https://nvd.nist.gov/vuln/detail/CVE-2019-25088 + - https://rubygems.org/gems/oxidized-web/versions/0.14.0 + - https://github.com/ytti/oxidized-web/releases#release-0.14.0 + - https://github.com/ytti/oxidized-web/compare/0.13.1...0.14.0 + - https://github.com/ytti/oxidized-web/pull/195 + - https://github.com/ytti/oxidized-web/pull/195/changes/12c07e69168bb5b4dfd4dbfed857491ed095dfd0 - https://vuldb.com/?id.216870 + - https://github.com/advisories/GHSA-8qwh-rm6c-jv96 +notes: | + - cvss_v3 from GHSA URL. + - PR#195: [escape user input to fix XSS "vulnerability"] + - See /changes/ UR (fix)L in /compare/ URL. diff --git a/gems/pay/GHSA-mjgf-xj26-9qf9.yml b/gems/pay/GHSA-mjgf-xj26-9qf9.yml index b963484c85..9ec2a3e3b5 100644 --- a/gems/pay/GHSA-mjgf-xj26-9qf9.yml +++ b/gems/pay/GHSA-mjgf-xj26-9qf9.yml @@ -43,11 +43,13 @@ patched_versions: related: url: - https://advisories.gitlab.com/gem/pay/GHSA-mjgf-xj26-9qf9 + - https://rubygems.org/gems/pay/versions/11.6.2 + - https://github.com/pay-rails/pay/releases/tag/v11.6.2 + - https://github.com/pay-rails/pay/commit/ba6494109d88209fba2a4df2d9d6373fe81ed805 + - https://github.com/pay-rails/pay/issues/1232 + - https://github.com/rubysec/ruby-advisory-db/pull/1158 - https://github.com/pay-rails/pay/security/advisories/GHSA-mjgf-xj26-9qf9 - https://github.com/advisories/GHSA-mjgf-xj26-9qf9 notes: | - - Fixed in 11.6.2. - - https://github.com/pay-rails/pay/releases/tag/v11.6.2 - - https://rubygems.org/gems/pay/versions/11.6.2 - - cvss_v3 value comes from project advisory. - - No cve value, so missing cvss_v2 and cvss_v4 values. + - cvss_v3 from GHSA URL. + - No cve in GHSA URL. diff --git a/gems/spina/CVE-2024-7106.yml b/gems/spina/CVE-2024-7106.yml index feb3f3c01e..901d269494 100644 --- a/gems/spina/CVE-2024-7106.yml +++ b/gems/spina/CVE-2024-7106.yml @@ -24,12 +24,20 @@ description: | cvss_v2: 5.0 cvss_v3: 4.3 cvss_v4: 6.9 -notes: Never patched +patched_versions: + - ">= 2.21.0" related: url: - https://nvd.nist.gov/vuln/detail/CVE-2024-7106 + - https://github.com/SpinaCMS/Spina/compare/v2.21.0...main + - https://github.com/SpinaCMS/Spina/commit/ccc3f5d2f76423561d17acf522baddb5c3fa8d43 + - https://github.com/SpinaCMS/Spina/pull/1441/changes/a22b1d6530d8166e0de7117ce3885100b2dbe461 + - https://github.com/SpinaCMS/Spina/pull/1441 + - https://github.com/SpinaCMS/Spina/issues/1381 - https://github.com/topsky979/Security-Collections/blob/main/cve3/README.md - https://vuldb.com/?ctiid.272431 - https://vuldb.com/?id.272431 - https://vuldb.com/?submit.376769 - https://github.com/advisories/GHSA-wqw3-p83g-r24v +notes: | + - See CVE reference in /compare/v2.21.0 URL.