Skip to content

Commit 62b1023

Browse files
jasnowRubySec CI
authored andcommitted
Updated advisory posts against rubysec/ruby-advisory-db@d93447c
1 parent 9981717 commit 62b1023

4 files changed

Lines changed: 7 additions & 0 deletions

File tree

advisories/_posts/2019-10-31-CVE-2019-13117.md

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -72,13 +72,16 @@ advisory:
7272
disclosed.
7373
7474
Patched with commit https://gitlab.gnome.org/GNOME/libxslt/commit/2232473733b7313d67de8836ea3b29eec6e8e285
75+
cvss_v2: 5.0
76+
cvss_v3: 5.3
7577
patched_versions:
7678
- ">= 1.10.5"
7779
related:
7880
cve:
7981
- 2019-13118
8082
- 2019-18197
8183
url:
84+
- https://nvd.nist.gov/vuln/detail/CVE-2019-13117
8285
- https://groups.google.com/d/msg/ruby-security-ann/-Wq4aouIA3Q/yc76ZHemBgAJ
8386
- https://usn.ubuntu.com/4164-1/
8487
- https://gitlab.gnome.org/GNOME/libxslt/commit/c5eb6cf3aba0af048596106ed839b4ae17ecbcb1

advisories/_posts/2024-10-15-CVE-2024-47889.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -52,5 +52,6 @@ advisory:
5252
related:
5353
url:
5454
- https://github.com/rails/rails/security/advisories/GHSA-h47h-mwp9-c6q6
55+
- https://discuss.rubyonrails.org/t/cve-2024-47889-possible-redos-vulnerability-in-block-format-in-action-mailer/87695
5556
- https://github.com/advisories/GHSA-h47h-mwp9-c6q6
5657
---

advisories/_posts/2026-03-05-CVE-2026-27820.md

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -43,12 +43,14 @@ advisory:
4343
4444
Thanks to calysteon for reporting this issue. Also thanks to
4545
nobu for creating the patch.
46+
cvss_v3: 9.8
4647
patched_versions:
4748
- "~> 3.0.1"
4849
- "~> 3.1.2"
4950
- ">= 3.2.3"
5051
related:
5152
url:
53+
- https://nvd.nist.gov/vuln/detail/CVE-2026-27820
5254
- https://www.ruby-lang.org/en/news/2026/03/05/buffer-overflow-zlib-cve-2026-27820
5355
- https://rubygems.org/gems/zlib/versions/3.2.3
5456
- https://rubygems.org/gems/zlib/versions/3.1.2

advisories/_posts/2026-05-27-CVE-2026-47736.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -58,6 +58,7 @@ advisory:
5858
- https://github.com/puma/puma/pull/2654
5959
- https://github.com/puma/puma/issues/2651
6060
- https://rubyweekly.com/issues/803
61+
- https://advisories.gitlab.com/gem/puma/CVE-2026-47736
6162
- https://github.com/puma/puma/security/advisories/GHSA-qpgp-93vx-g8v8
6263
notes: |
6364
- https://www.cve.org/CVERecord/SearchResults?query=CVE-2026-47736 (reserved)

0 commit comments

Comments
 (0)