Skip to content

Commit 719c456

Browse files
authored
Merge pull request #1250 from jasnow/add-patched_versions
Added patched_version and evidence to 8 existing advisories @simi - Thanks for reviewing and approving this PR.
2 parents cb6460a + ca85891 commit 719c456

8 files changed

Lines changed: 106 additions & 26 deletions

File tree

‎gems/datagrid/CVE-2019-14281.yml‎

Lines changed: 22 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -2,13 +2,30 @@
22
gem: datagrid
33
cve: 2019-14281
44
ghsa: rqp5-pg7w-832p
5-
url: https://github.com/rubygems/rubygems.org/issues/2072
5+
url: https://nvd.nist.gov/vuln/detail/CVE-2019-14281
66
date: 2019-07-31
77
title: Code execution backdoor in datagrid
88
description: |
9-
The datagrid gem 1.0.6 for Ruby, as distributed on RubyGems.org, included
10-
a code-execution backdoor inserted by a third party.
9+
The datagrid gem 1.0.6 for Ruby, as distributed on RubyGems.org,
10+
included a code-execution backdoor inserted by a third party.
11+
cvss_v2: 7.5
12+
cvss_v3: 9.8
1113
unaffected_versions:
1214
- "< 1.0.6"
13-
- "> 1.0.6"
14-
cvss_v3: 9.8
15+
- "> 1.0.6, < 1.5.10"
16+
patched_versions:
17+
- "> 1.5.10"
18+
related:
19+
url:
20+
- https://nvd.nist.gov/vuln/detail/CVE-2019-14281
21+
- https://rubygems.org/gems/datagrid/versions/1.6.0
22+
- https://rubygems.org/gems/datagrid/versions
23+
- https://github.com/rubygems/rubygems.org/issues/2072
24+
- https://github.com/advisories/GHSA-rqp5-pg7w-832p
25+
notes: |
26+
- cvss_v2 and cvss_v3 (also GHSA URL) from nvd.nist.gov URL.
27+
- https://rubygems.org/gems/datagrid/versions/1.5.10 was yanked.
28+
- https://rubygems.org/gems/datagrid/versions/1.0.6 was yanked.
29+
- https://github.com/rubygems/rubygems.org/issues/2072 (please yank 1.0.6)
30+
- https://rubygems.org/gems/data_grid has only 0.0.1 and 0.0.2 release.
31+
- https://github.com/kkempin/data_grid has only 0.0.1.

‎gems/fog-dragonfly/CVE-2013-5671.yml‎

Lines changed: 18 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,24 @@ description: |
1111
failing to properly sanitize input passed via the imagemagickutils.rb script.
1212
This may allow a remote attacker to execute arbitrary commands.
1313
14-
This gem has been renamed. Please use "dragonfly" from now on.
14+
lib/dragonfly/imagemagickutils.rb in the fog-dragonfly gem 0.8.2
15+
for Ruby allows remote attackers to execute arbitrary commands
16+
via unspecified vectors.
17+
18+
NOTE: This gem has been renamed. Please use "dragonfly" 1.0.0 from now on.
1519
cvss_v2: 7.5
1620
patched_versions:
1721
- ">= 0.8.4"
22+
related:
23+
url:
24+
- https://nvd.nist.gov/vuln/detail/CVE-2013-5671
25+
- https://rubygems.org/gems/dragonfly/versions/1.0
26+
- http://seclists.org/fulldisclosure/2013/Sep/18
27+
- http://seclists.org/oss-sec/2013/q3/526
28+
- http://seclists.org/oss-sec/2013/q3/528
29+
- http://www.vapid.dhs.org/advisories/fog-dragonfly-0.8.2-cmd-inj.html
30+
- https://github.com/advisories/GHSA-qrgf-jqqm-x7xv
31+
notes: |
32+
- cvss_v2 from nvd.nist.gov URL.
33+
- https://rubygems.org/gems/fog-dragonfly has only 0.8.1 and 0.8.2
34+
releases. Now use (renamed) "dragonfly" from now on.

‎gems/iodine/CVE-2026-41146.yml‎

Lines changed: 7 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -258,14 +258,18 @@ description: |
258258
- The gem vendors a copy of the vulnerable parser in
259259
`ext/iodine/fio_json_parser.h`
260260
cvss_v4: 8.7
261+
patched_versions:
262+
- ">= 0.7.59"
261263
related:
262264
url:
263265
- https://nvd.nist.gov/vuln/detail/CVE-2026-41146
264-
- https://github.com/boazsegev/iodine/releases/tag/v0.7.58
266+
- https://rubygems.org/gems/iodine/versions/0.7.59
267+
- https://github.com/boazsegev/iodine/releases/tag/v0.7.59
268+
- https://github.com/boazsegev/iodine/compare/v0.7.58...v0.7.59
265269
- https://github.com/boazsegev/iodine/commit/0855989d74098d838b972520835cfc256bc479bc
266270
- https://github.com/boazsegev/facil.io/commit/5128747363055201d3ecf0e29bf0a961703c9fa0
267271
- https://github.com/boazsegev/facil.io/security/advisories/GHSA-2x79-gwq3-vxxm
268272
- https://github.com/advisories/GHSA-2x79-gwq3-vxxm
269273
notes: |
270-
- FYI: iodine commit above contains the unreleased patch.
271-
- Found GHSA's `patched_versions:` field is "0.7.59" but never released.
274+
- cvss_v4 from nvd.nist.gov URL.
275+
- FYI: iodine commit above in 0.7.59 release.

‎gems/openc3-cosmos-tool-iframe/CVE-2025-28382.yml‎

Lines changed: 10 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
gem: openc3-cosmos-tool-iframe
33
cve: 2025-28382
44
ghsa: cf8v-5mrc-jv7f
5-
url: https://github.com/advisories/GHSA-cf8v-5mrc-jv7f
5+
url: https://nvd.nist.gov/vuln/detail/CVE-2025-28382
66
title: OpenC3 COSMOS Vulnerable to Directory Traversal via
77
openc3-api/tables endpoint
88
date: 2025-06-13
@@ -12,10 +12,18 @@ description: |
1212
cvss_v3: 7.5
1313
unaffected_versions:
1414
- "< 6.0.0"
15-
notes: Never patched
15+
patched_versions:
16+
- ">= 6.1.0"
1617
related:
1718
url:
1819
- https://nvd.nist.gov/vuln/detail/CVE-2025-28382
20+
- https://rubygems.org/gems/openc3-cosmos-tool-iframe/versions/6.1.0
21+
- https://github.com/OpenC3/cosmos/releases/tag/v6.1.0
22+
- https://github.com/OpenC3/cosmos/pull/1828/changes/fc7e11310a7cdf9f1939886e1b29009db4d4b718
1923
- https://visionspace.com/openc3-cosmos-a-security-assessment-of-an-open-source-mission-framework
2024
- https://openc3.com
2125
- https://github.com/advisories/GHSA-cf8v-5mrc-jv7f
26+
notes: |
27+
- cvss_v3 from GHSA URL.
28+
- NOTE: gem name is "openc3-cosmos-tool-iframe" and repo name is "cosmos".
29+
- /tag/ URL has reference to CVE-2025-28382.

‎gems/openc3-cosmos-tool-iframe/CVE-2025-28384.yml‎

Lines changed: 10 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
gem: openc3-cosmos-tool-iframe
33
cve: 2025-28384
44
ghsa: p67j-387g-75wc
5-
url: https://github.com/advisories/GHSA-p67j-387g-75wc
5+
url: https://nvd.nist.gov/vuln/detail/CVE-2025-28384
66
title: OpenC3 COSMOS Vulnerable to Directory Traversal via
77
/script-api/scripts/ endpoint
88
date: 2025-06-13
@@ -12,10 +12,18 @@ description: |
1212
cvss_v3: 9.1
1313
unaffected_versions:
1414
- "< 6.0.0"
15-
notes: Never patched
15+
patched_versions:
16+
- ">= 6.1.0"
1617
related:
1718
url:
1819
- https://nvd.nist.gov/vuln/detail/CVE-2025-28384
20+
- https://rubygems.org/gems/openc3-cosmos-tool-iframe/versions/6.1.0
21+
- https://github.com/OpenC3/cosmos/releases/tag/v6.1.0
22+
- https://github.com/OpenC3/cosmos/pull/1828/changes/fc7e11310a7cdf9f1939886e1b29009db4d4b718
1923
- https://visionspace.com/openc3-cosmos-a-security-assessment-of-an-open-source-mission-framework
2024
- https://openc3.com
2125
- https://github.com/advisories/GHSA-p67j-387g-75wc
26+
notes: |
27+
- cvss_v3 from GHSA URL.
28+
- NOTE: gem name is "openc3-cosmos-tool-iframe" and repo name is "cosmos".
29+
- /tag/ URL has reference to CVE-2025-28384.

‎gems/oxidized-web/CVE-2019-25088.yml‎

Lines changed: 23 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -2,18 +2,34 @@
22
gem: oxidized-web
33
cve: 2019-25088
44
ghsa: 8qwh-rm6c-jv96
5-
url: https://github.com/ytti/oxidized-web/pull/195
5+
url: https://nvd.nist.gov/vuln/detail/CVE-2019-25088
66
title: Oxidized Web vulnerable to Cross-site Scripting
77
date: 2022-12-27
88
description: |
99
A vulnerability was found in ytti Oxidized Web. It has been classified
10-
as problematic. Affected is an unknown function of the file `lib/oxidized/web/views/conf_search.haml`.
11-
The manipulation of the argument `to_research` leads to cross site scripting. It
12-
is possible to launch the attack remotely. The name of the patch is 55ab9bdc68b03ebce9280b8746ef31d7fdedcc45.
13-
It is recommended to apply a patch to fix this issue. VDB-216870 is the identifier
14-
assigned to this vulnerability.
10+
as problematic. Affected is an unknown function of the file
11+
`lib/oxidized/web/views/conf_search.haml`.
12+
13+
The manipulation of the argument `to_research` leads to cross site
14+
scripting. It is possible to launch the attack remotely.
15+
The name of the patch is 55ab9bdc68b03ebce9280b8746ef31d7fdedcc45.
16+
17+
It is recommended to apply a patch to fix this issue.
18+
VDB-216870 is the identifier assigned to this vulnerability.
1519
cvss_v3: 5.4
20+
patched_versions:
21+
- ">= 0.14.0"
1622
related:
1723
url:
18-
- https://github.com/ytti/oxidized-web/commit/55ab9bdc68b03ebce9280b8746ef31d7fdedcc45
24+
- https://nvd.nist.gov/vuln/detail/CVE-2019-25088
25+
- https://rubygems.org/gems/oxidized-web/versions/0.14.0
26+
- https://github.com/ytti/oxidized-web/releases#release-0.14.0
27+
- https://github.com/ytti/oxidized-web/compare/0.13.1...0.14.0
28+
- https://github.com/ytti/oxidized-web/pull/195
29+
- https://github.com/ytti/oxidized-web/pull/195/changes/12c07e69168bb5b4dfd4dbfed857491ed095dfd0
1930
- https://vuldb.com/?id.216870
31+
- https://github.com/advisories/GHSA-8qwh-rm6c-jv96
32+
notes: |
33+
- cvss_v3 from GHSA URL.
34+
- PR#195: [escape user input to fix XSS "vulnerability"]
35+
- See /changes/ UR (fix)L in /compare/ URL.

‎gems/pay/GHSA-mjgf-xj26-9qf9.yml‎

Lines changed: 7 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -43,11 +43,13 @@ patched_versions:
4343
related:
4444
url:
4545
- https://advisories.gitlab.com/gem/pay/GHSA-mjgf-xj26-9qf9
46+
- https://rubygems.org/gems/pay/versions/11.6.2
47+
- https://github.com/pay-rails/pay/releases/tag/v11.6.2
48+
- https://github.com/pay-rails/pay/commit/ba6494109d88209fba2a4df2d9d6373fe81ed805
49+
- https://github.com/pay-rails/pay/issues/1232
50+
- https://github.com/rubysec/ruby-advisory-db/pull/1158
4651
- https://github.com/pay-rails/pay/security/advisories/GHSA-mjgf-xj26-9qf9
4752
- https://github.com/advisories/GHSA-mjgf-xj26-9qf9
4853
notes: |
49-
- Fixed in 11.6.2.
50-
- https://github.com/pay-rails/pay/releases/tag/v11.6.2
51-
- https://rubygems.org/gems/pay/versions/11.6.2
52-
- cvss_v3 value comes from project advisory.
53-
- No cve value, so missing cvss_v2 and cvss_v4 values.
54+
- cvss_v3 from GHSA URL.
55+
- No cve in GHSA URL.

‎gems/spina/CVE-2024-7106.yml‎

Lines changed: 9 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -24,12 +24,20 @@ description: |
2424
cvss_v2: 5.0
2525
cvss_v3: 4.3
2626
cvss_v4: 6.9
27-
notes: Never patched
27+
patched_versions:
28+
- ">= 2.21.0"
2829
related:
2930
url:
3031
- https://nvd.nist.gov/vuln/detail/CVE-2024-7106
32+
- https://github.com/SpinaCMS/Spina/compare/v2.21.0...main
33+
- https://github.com/SpinaCMS/Spina/commit/ccc3f5d2f76423561d17acf522baddb5c3fa8d43
34+
- https://github.com/SpinaCMS/Spina/pull/1441/changes/a22b1d6530d8166e0de7117ce3885100b2dbe461
35+
- https://github.com/SpinaCMS/Spina/pull/1441
36+
- https://github.com/SpinaCMS/Spina/issues/1381
3137
- https://github.com/topsky979/Security-Collections/blob/main/cve3/README.md
3238
- https://vuldb.com/?ctiid.272431
3339
- https://vuldb.com/?id.272431
3440
- https://vuldb.com/?submit.376769
3541
- https://github.com/advisories/GHSA-wqw3-p83g-r24v
42+
notes: |
43+
- See CVE reference in /compare/v2.21.0 URL.

0 commit comments

Comments
 (0)