Skip to content

Commit 7267f80

Browse files
jasnowRubySec CI
authored andcommitted
Updated advisory posts against rubysec/ruby-advisory-db@719c456
1 parent cfad0cc commit 7267f80

8 files changed

Lines changed: 105 additions & 26 deletions

‎advisories/_posts/2013-09-03-CVE-2013-5671.md‎

Lines changed: 18 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -18,8 +18,25 @@ advisory:
1818
failing to properly sanitize input passed via the imagemagickutils.rb script.
1919
This may allow a remote attacker to execute arbitrary commands.
2020
21-
This gem has been renamed. Please use "dragonfly" from now on.
21+
lib/dragonfly/imagemagickutils.rb in the fog-dragonfly gem 0.8.2
22+
for Ruby allows remote attackers to execute arbitrary commands
23+
via unspecified vectors.
24+
25+
NOTE: This gem has been renamed. Please use "dragonfly" 1.0.0 from now on.
2226
cvss_v2: 7.5
2327
patched_versions:
2428
- ">= 0.8.4"
29+
related:
30+
url:
31+
- https://nvd.nist.gov/vuln/detail/CVE-2013-5671
32+
- https://rubygems.org/gems/dragonfly/versions/1.0
33+
- http://seclists.org/fulldisclosure/2013/Sep/18
34+
- http://seclists.org/oss-sec/2013/q3/526
35+
- http://seclists.org/oss-sec/2013/q3/528
36+
- http://www.vapid.dhs.org/advisories/fog-dragonfly-0.8.2-cmd-inj.html
37+
- https://github.com/advisories/GHSA-qrgf-jqqm-x7xv
38+
notes: |
39+
- cvss_v2 from nvd.nist.gov URL.
40+
- https://rubygems.org/gems/fog-dragonfly has only 0.8.1 and 0.8.2
41+
releases. Now use (renamed) "dragonfly" from now on.
2542
---

‎advisories/_posts/2019-07-31-CVE-2019-14281.md‎

Lines changed: 22 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -8,14 +8,31 @@ advisory:
88
gem: datagrid
99
cve: 2019-14281
1010
ghsa: rqp5-pg7w-832p
11-
url: https://github.com/rubygems/rubygems.org/issues/2072
11+
url: https://nvd.nist.gov/vuln/detail/CVE-2019-14281
1212
date: 2019-07-31
1313
title: Code execution backdoor in datagrid
1414
description: |-
15-
The datagrid gem 1.0.6 for Ruby, as distributed on RubyGems.org, included
16-
a code-execution backdoor inserted by a third party.
15+
The datagrid gem 1.0.6 for Ruby, as distributed on RubyGems.org,
16+
included a code-execution backdoor inserted by a third party.
17+
cvss_v2: 7.5
18+
cvss_v3: 9.8
1719
unaffected_versions:
1820
- "< 1.0.6"
19-
- "> 1.0.6"
20-
cvss_v3: 9.8
21+
- "> 1.0.6, < 1.5.10"
22+
patched_versions:
23+
- "> 1.5.10"
24+
related:
25+
url:
26+
- https://nvd.nist.gov/vuln/detail/CVE-2019-14281
27+
- https://rubygems.org/gems/datagrid/versions/1.6.0
28+
- https://rubygems.org/gems/datagrid/versions
29+
- https://github.com/rubygems/rubygems.org/issues/2072
30+
- https://github.com/advisories/GHSA-rqp5-pg7w-832p
31+
notes: |
32+
- cvss_v2 and cvss_v3 (also GHSA URL) from nvd.nist.gov URL.
33+
- https://rubygems.org/gems/datagrid/versions/1.5.10 was yanked.
34+
- https://rubygems.org/gems/datagrid/versions/1.0.6 was yanked.
35+
- https://github.com/rubygems/rubygems.org/issues/2072 (please yank 1.0.6)
36+
- https://rubygems.org/gems/data_grid has only 0.0.1 and 0.0.2 release.
37+
- https://github.com/kkempin/data_grid has only 0.0.1.
2138
---

‎advisories/_posts/2022-12-27-CVE-2019-25088.md‎

Lines changed: 23 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -8,19 +8,35 @@ advisory:
88
gem: oxidized-web
99
cve: 2019-25088
1010
ghsa: 8qwh-rm6c-jv96
11-
url: https://github.com/ytti/oxidized-web/pull/195
11+
url: https://nvd.nist.gov/vuln/detail/CVE-2019-25088
1212
title: Oxidized Web vulnerable to Cross-site Scripting
1313
date: 2022-12-27
1414
description: |-
1515
A vulnerability was found in ytti Oxidized Web. It has been classified
16-
as problematic. Affected is an unknown function of the file `lib/oxidized/web/views/conf_search.haml`.
17-
The manipulation of the argument `to_research` leads to cross site scripting. It
18-
is possible to launch the attack remotely. The name of the patch is 55ab9bdc68b03ebce9280b8746ef31d7fdedcc45.
19-
It is recommended to apply a patch to fix this issue. VDB-216870 is the identifier
20-
assigned to this vulnerability.
16+
as problematic. Affected is an unknown function of the file
17+
`lib/oxidized/web/views/conf_search.haml`.
18+
19+
The manipulation of the argument `to_research` leads to cross site
20+
scripting. It is possible to launch the attack remotely.
21+
The name of the patch is 55ab9bdc68b03ebce9280b8746ef31d7fdedcc45.
22+
23+
It is recommended to apply a patch to fix this issue.
24+
VDB-216870 is the identifier assigned to this vulnerability.
2125
cvss_v3: 5.4
26+
patched_versions:
27+
- ">= 0.14.0"
2228
related:
2329
url:
24-
- https://github.com/ytti/oxidized-web/commit/55ab9bdc68b03ebce9280b8746ef31d7fdedcc45
30+
- https://nvd.nist.gov/vuln/detail/CVE-2019-25088
31+
- https://rubygems.org/gems/oxidized-web/versions/0.14.0
32+
- https://github.com/ytti/oxidized-web/releases#release-0.14.0
33+
- https://github.com/ytti/oxidized-web/compare/0.13.1...0.14.0
34+
- https://github.com/ytti/oxidized-web/pull/195
35+
- https://github.com/ytti/oxidized-web/pull/195/changes/12c07e69168bb5b4dfd4dbfed857491ed095dfd0
2536
- https://vuldb.com/?id.216870
37+
- https://github.com/advisories/GHSA-8qwh-rm6c-jv96
38+
notes: |
39+
- cvss_v3 from GHSA URL.
40+
- PR#195: [escape user input to fix XSS "vulnerability"]
41+
- See /changes/ UR (fix)L in /compare/ URL.
2642
---

‎advisories/_posts/2024-07-25-CVE-2024-7106.md‎

Lines changed: 8 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -30,13 +30,20 @@ advisory:
3030
cvss_v2: 5.0
3131
cvss_v3: 4.3
3232
cvss_v4: 6.9
33-
notes: Never patched
33+
patched_versions:
34+
- ">= 2.21.0"
3435
related:
3536
url:
3637
- https://nvd.nist.gov/vuln/detail/CVE-2024-7106
38+
- https://github.com/SpinaCMS/Spina/compare/v2.21.0...main
39+
- https://github.com/SpinaCMS/Spina/commit/ccc3f5d2f76423561d17acf522baddb5c3fa8d43
40+
- https://github.com/SpinaCMS/Spina/pull/1441/changes/a22b1d6530d8166e0de7117ce3885100b2dbe461
41+
- https://github.com/SpinaCMS/Spina/pull/1441
42+
- https://github.com/SpinaCMS/Spina/issues/1381
3743
- https://github.com/topsky979/Security-Collections/blob/main/cve3/README.md
3844
- https://vuldb.com/?ctiid.272431
3945
- https://vuldb.com/?id.272431
4046
- https://vuldb.com/?submit.376769
4147
- https://github.com/advisories/GHSA-wqw3-p83g-r24v
48+
notes: "- See CVE reference in /compare/v2.21.0 URL.\n"
4249
---

‎advisories/_posts/2025-06-13-CVE-2025-28382.md‎

Lines changed: 10 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,7 @@ advisory:
99
gem: openc3-cosmos-tool-iframe
1010
cve: 2025-28382
1111
ghsa: cf8v-5mrc-jv7f
12-
url: https://github.com/advisories/GHSA-cf8v-5mrc-jv7f
12+
url: https://nvd.nist.gov/vuln/detail/CVE-2025-28382
1313
title: OpenC3 COSMOS Vulnerable to Directory Traversal via openc3-api/tables endpoint
1414
date: 2025-06-13
1515
description: |-
@@ -18,11 +18,19 @@ advisory:
1818
cvss_v3: 7.5
1919
unaffected_versions:
2020
- "< 6.0.0"
21-
notes: Never patched
21+
patched_versions:
22+
- ">= 6.1.0"
2223
related:
2324
url:
2425
- https://nvd.nist.gov/vuln/detail/CVE-2025-28382
26+
- https://rubygems.org/gems/openc3-cosmos-tool-iframe/versions/6.1.0
27+
- https://github.com/OpenC3/cosmos/releases/tag/v6.1.0
28+
- https://github.com/OpenC3/cosmos/pull/1828/changes/fc7e11310a7cdf9f1939886e1b29009db4d4b718
2529
- https://visionspace.com/openc3-cosmos-a-security-assessment-of-an-open-source-mission-framework
2630
- https://openc3.com
2731
- https://github.com/advisories/GHSA-cf8v-5mrc-jv7f
32+
notes: |
33+
- cvss_v3 from GHSA URL.
34+
- NOTE: gem name is "openc3-cosmos-tool-iframe" and repo name is "cosmos".
35+
- /tag/ URL has reference to CVE-2025-28382.
2836
---

‎advisories/_posts/2025-06-13-CVE-2025-28384.md‎

Lines changed: 10 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,7 @@ advisory:
99
gem: openc3-cosmos-tool-iframe
1010
cve: 2025-28384
1111
ghsa: p67j-387g-75wc
12-
url: https://github.com/advisories/GHSA-p67j-387g-75wc
12+
url: https://nvd.nist.gov/vuln/detail/CVE-2025-28384
1313
title: OpenC3 COSMOS Vulnerable to Directory Traversal via /script-api/scripts/
1414
endpoint
1515
date: 2025-06-13
@@ -19,11 +19,19 @@ advisory:
1919
cvss_v3: 9.1
2020
unaffected_versions:
2121
- "< 6.0.0"
22-
notes: Never patched
22+
patched_versions:
23+
- ">= 6.1.0"
2324
related:
2425
url:
2526
- https://nvd.nist.gov/vuln/detail/CVE-2025-28384
27+
- https://rubygems.org/gems/openc3-cosmos-tool-iframe/versions/6.1.0
28+
- https://github.com/OpenC3/cosmos/releases/tag/v6.1.0
29+
- https://github.com/OpenC3/cosmos/pull/1828/changes/fc7e11310a7cdf9f1939886e1b29009db4d4b718
2630
- https://visionspace.com/openc3-cosmos-a-security-assessment-of-an-open-source-mission-framework
2731
- https://openc3.com
2832
- https://github.com/advisories/GHSA-p67j-387g-75wc
33+
notes: |
34+
- cvss_v3 from GHSA URL.
35+
- NOTE: gem name is "openc3-cosmos-tool-iframe" and repo name is "cosmos".
36+
- /tag/ URL has reference to CVE-2025-28384.
2937
---

‎advisories/_posts/2026-04-14-CVE-2026-41146.md‎

Lines changed: 7 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -265,15 +265,19 @@ advisory:
265265
- The gem vendors a copy of the vulnerable parser in
266266
`ext/iodine/fio_json_parser.h`
267267
cvss_v4: 8.7
268+
patched_versions:
269+
- ">= 0.7.59"
268270
related:
269271
url:
270272
- https://nvd.nist.gov/vuln/detail/CVE-2026-41146
271-
- https://github.com/boazsegev/iodine/releases/tag/v0.7.58
273+
- https://rubygems.org/gems/iodine/versions/0.7.59
274+
- https://github.com/boazsegev/iodine/releases/tag/v0.7.59
275+
- https://github.com/boazsegev/iodine/compare/v0.7.58...v0.7.59
272276
- https://github.com/boazsegev/iodine/commit/0855989d74098d838b972520835cfc256bc479bc
273277
- https://github.com/boazsegev/facil.io/commit/5128747363055201d3ecf0e29bf0a961703c9fa0
274278
- https://github.com/boazsegev/facil.io/security/advisories/GHSA-2x79-gwq3-vxxm
275279
- https://github.com/advisories/GHSA-2x79-gwq3-vxxm
276280
notes: |
277-
- FYI: iodine commit above contains the unreleased patch.
278-
- Found GHSA's `patched_versions:` field is "0.7.59" but never released.
281+
- cvss_v4 from nvd.nist.gov URL.
282+
- FYI: iodine commit above in 0.7.59 release.
279283
---

‎advisories/_posts/2026-07-01-GHSA-mjgf-xj26-9qf9.md‎

Lines changed: 7 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -50,12 +50,14 @@ advisory:
5050
related:
5151
url:
5252
- https://advisories.gitlab.com/gem/pay/GHSA-mjgf-xj26-9qf9
53+
- https://rubygems.org/gems/pay/versions/11.6.2
54+
- https://github.com/pay-rails/pay/releases/tag/v11.6.2
55+
- https://github.com/pay-rails/pay/commit/ba6494109d88209fba2a4df2d9d6373fe81ed805
56+
- https://github.com/pay-rails/pay/issues/1232
57+
- https://github.com/rubysec/ruby-advisory-db/pull/1158
5358
- https://github.com/pay-rails/pay/security/advisories/GHSA-mjgf-xj26-9qf9
5459
- https://github.com/advisories/GHSA-mjgf-xj26-9qf9
5560
notes: |
56-
- Fixed in 11.6.2.
57-
- https://github.com/pay-rails/pay/releases/tag/v11.6.2
58-
- https://rubygems.org/gems/pay/versions/11.6.2
59-
- cvss_v3 value comes from project advisory.
60-
- No cve value, so missing cvss_v2 and cvss_v4 values.
61+
- cvss_v3 from GHSA URL.
62+
- No cve in GHSA URL.
6163
---

0 commit comments

Comments
 (0)