From 11d62271d99e39f5e07a8636764119ca7d590109 Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" <41898282+github-actions[bot]@users.noreply.github.com> Date: Wed, 14 Feb 2024 20:22:49 -0500 Subject: [PATCH] Synchronize IDs (2024-02-15) (#1889) Co-authored-by: amousset <329388+amousset@users.noreply.github.com> --- crates/libgit2-sys/RUSTSEC-2024-0013.md | 3 ++- crates/pqc_kyber/RUSTSEC-2023-0079.md | 1 + crates/serde-json-wasm/RUSTSEC-2024-0012.md | 1 + crates/snow/RUSTSEC-2024-0011.md | 1 + crates/svix/RUSTSEC-2024-0010.md | 2 +- 5 files changed, 6 insertions(+), 2 deletions(-) diff --git a/crates/libgit2-sys/RUSTSEC-2024-0013.md b/crates/libgit2-sys/RUSTSEC-2024-0013.md index a574e04..daf4f9b 100644 --- a/crates/libgit2-sys/RUSTSEC-2024-0013.md +++ b/crates/libgit2-sys/RUSTSEC-2024-0013.md @@ -7,7 +7,8 @@ url = "https://github.com/rust-lang/git2-rs/pull/1017" references = ["https://github.com/libgit2/libgit2/releases/tag/v1.7.2"] categories = ["denial-of-service", "code-execution", "memory-corruption"] cvss = "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L" -related = ["GHSA-j2v7-4f6v-gpg8", "CVE-2024-24577", "GHSA-54mf-x2rh-hq9v", "CVE-2024-24575"] +related = ["CVE-2024-24575", "CVE-2024-24577", "GHSA-54mf-x2rh-hq9v", "GHSA-j2v7-4f6v-gpg8"] +aliases = ["GHSA-22q8-ghmq-63vf"] [affected.functions] "libgit2_sys::git_revparse_single" = ["< 0.16.2, >= 0.13.0"] diff --git a/crates/pqc_kyber/RUSTSEC-2023-0079.md b/crates/pqc_kyber/RUSTSEC-2023-0079.md index bed2bf5..750ea49 100644 --- a/crates/pqc_kyber/RUSTSEC-2023-0079.md +++ b/crates/pqc_kyber/RUSTSEC-2023-0079.md @@ -8,6 +8,7 @@ references = ["https://kyberslash.cr.yp.to/faq.html", "https://kyberslash.cr.yp. categories = ["crypto-failure"] cvss = "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N" keywords = ["timing-attack"] +aliases = ["GHSA-x5j2-g63m-f8g4"] [affected] diff --git a/crates/serde-json-wasm/RUSTSEC-2024-0012.md b/crates/serde-json-wasm/RUSTSEC-2024-0012.md index 7b30a02..0097882 100644 --- a/crates/serde-json-wasm/RUSTSEC-2024-0012.md +++ b/crates/serde-json-wasm/RUSTSEC-2024-0012.md @@ -5,6 +5,7 @@ package = "serde-json-wasm" date = "2024-01-24" categories = ["denial-of-service"] keywords = ["stack-overflow", "json"] +aliases = ["GHSA-rr69-rxr6-8qwf"] [versions] patched = [">= 1.0.1", ">= 0.5.2, < 1.0.0"] diff --git a/crates/snow/RUSTSEC-2024-0011.md b/crates/snow/RUSTSEC-2024-0011.md index a1a8e12..de2c38a 100644 --- a/crates/snow/RUSTSEC-2024-0011.md +++ b/crates/snow/RUSTSEC-2024-0011.md @@ -6,6 +6,7 @@ date = "2024-01-23" url = "https://github.com/mcginty/snow/security/advisories/GHSA-7g9j-g5jg-3vv3" categories = ["denial-of-service"] keywords = ["noise", "nonce", "state"] +aliases = ["GHSA-7g9j-g5jg-3vv3"] [versions] patched = [">= 0.9.5"] diff --git a/crates/svix/RUSTSEC-2024-0010.md b/crates/svix/RUSTSEC-2024-0010.md index 5a5e1ef..3b5af98 100644 --- a/crates/svix/RUSTSEC-2024-0010.md +++ b/crates/svix/RUSTSEC-2024-0010.md @@ -5,7 +5,7 @@ package = "svix" date = "2024-02-06" url = "https://github.com/svix/svix-webhooks/pull/1190" categories = ["crypto-failure"] -aliases = ["GHSA-w277-wpqf-rcfv"] +aliases = ["CVE-2024-21491", "GHSA-747x-5m58-mq97", "GHSA-w277-wpqf-rcfv"] [affected] functions = { "svix::webhooks::Webhook::verify" = ["< 1.17.0"] }