diff --git a/gems/mpxj/CVE-2026-61570.yml b/gems/mpxj/CVE-2026-61570.yml index 44006058ce..8618ecdf0f 100644 --- a/gems/mpxj/CVE-2026-61570.yml +++ b/gems/mpxj/CVE-2026-61570.yml @@ -2,7 +2,7 @@ gem: mpxj cve: 2026-61570 ghsa: 5vvx-3h34-f3gj -url: https://www.cve.org/CVERecord/SearchResults?query=CVE-2026-61570 +url: https://nvd.nist.gov/vuln/detail/CVE-2026-61570 title: XXE Vulnerability in MerlinReader date: 2026-06-22 description: | @@ -30,11 +30,13 @@ patched_versions: - ">= 16.4.1" related: url: - - https://www.cve.org/CVERecord/SearchResults?query=CVE-2026-61570 + - https://nvd.nist.gov/vuln/detail/CVE-2026-61570 - https://rubygems.org/gems/mpxj/versions/16.4.1 - https://github.com/joniles/mpxj/releases/tag/v16.4.1 + - https://github.com/joniles/mpxj/blob/master/CHANGELOG.md#1641-2026-06-22 + - https://osv.dev/vulnerability/GHSA-5vvx-3h34-f3gj - https://github.com/joniles/mpxj/security/advisories/GHSA-5vvx-3h34-f3gj + - https://github.com/advisories/GHSA-5vvx-3h34-f3gj notes: | - - CVE is reserved, but not published. - - cvss_v3 value from GHSA. - - data from gem release date. + - cvss_v3 from GHSA and nvd.nist.gov URLs. + - date from gem release date. diff --git a/gems/mpxj/GHSA-7952-gx68-cjqr.yml b/gems/mpxj/CVE-2026-65829.yml similarity index 61% rename from gems/mpxj/GHSA-7952-gx68-cjqr.yml rename to gems/mpxj/CVE-2026-65829.yml index 5f4095e81b..58b323479d 100644 --- a/gems/mpxj/GHSA-7952-gx68-cjqr.yml +++ b/gems/mpxj/CVE-2026-65829.yml @@ -1,7 +1,8 @@ --- gem: mpxj +cve: 2026-65829 ghsa: 7952-gx68-cjqr -url: https://github.com/joniles/mpxj/security/advisories/GHSA-7952-gx68-cjqr +url: https://nvd.nist.gov/vuln/detail/CVE-2026-65829 title: Potential Path Traversal Vulnerability in Primavera P3 PRX and SureTrak STX readers date: 2026-07-03 @@ -21,9 +22,13 @@ patched_versions: - ">= 16.5.0" related: url: + - https://nvd.nist.gov/vuln/detail/CVE-2026-65829 - https://rubygems.org/gems/mpxj/versions/16.5.0 - https://github.com/joniles/mpxj/releases/tag/v16.5.0 + - https://github.com/joniles/mpxj/blob/master/CHANGELOG.md#1650-2026-07-03 + - https://github.com/joniles/mpxj/commit/4347315afab1ef5a2907978a754fbc5b0ff58e6f - https://github.com/joniles/mpxj/security/advisories/GHSA-7952-gx68-cjqr + - https://github.com/advisories/GHSA-7952-gx68-cjqr notes: | - - No CVE. - - cvss_v3 value from GHSA + - cvss_v3 from GHSA and nvd.nist.gov URLs. + - date from rubygems.org URL. diff --git a/gems/spree_api/GHSA-4825-p4xm-pcf2.yml b/gems/spree_api/CVE-2026-94462.yml similarity index 78% rename from gems/spree_api/GHSA-4825-p4xm-pcf2.yml rename to gems/spree_api/CVE-2026-94462.yml index 596bd558c2..55894375fa 100644 --- a/gems/spree_api/GHSA-4825-p4xm-pcf2.yml +++ b/gems/spree_api/CVE-2026-94462.yml @@ -1,7 +1,8 @@ --- gem: spree_api +cve: 2026-94462 ghsa: 4825-p4xm-pcf2 -url: https://github.com/spree/spree/security/advisories/GHSA-4825-p4xm-pcf2 +url: https://nvd.nist.gov/vuln/detail/CVE-2026-94462 title: Broken Access Control in `PATCH /api/v3/store/carts/:id/associate` (IDOR) date: 2026-07-20 description: | @@ -53,13 +54,19 @@ patched_versions: - ">= 5.5.4" related: url: + - https://nvd.nist.gov/vuln/detail/CVE-2026-94462 - https://rubygems.org/gems/spree_api/versions/5.5.4 - - https://github.com/spree/spree/releases/tag/v5.5.4 + - https://github.com/spree/spree/releases/tag/v5.5.4 + - https://github.com/spree/spree/commit/af0d1a2d582a60d179de65b7d3ea024cb26426a8 - https://rubygems.org/gems/spree_api/versions/5.4.4 - - https://github.com/spree/spree/releases/tag/v5.4.4 + - https://github.com/spree/spree/releases/tag/v5.4.4 + - https://github.com/spree/spree/commit/8834230a1f47bb5988f23f45dbd162776cf592bd + - https://github.com/spree/spree/pull/14314 + - https://advisories.gitlab.com/gem/spree_api/CVE-2026-94462 + - https://osv.dev/vulnerability/GHSA-4825-p4xm-pcf2 - https://github.com/spree/spree/security/advisories/GHSA-4825-p4xm-pcf2 + - https://github.com/advisories/GHSA-4825-p4xm-pcf2 notes: | - NOTE: Gem name is "spree_api" but repo name is "spree". - - cvss_v3 from project GHSA - - No CVE in project GHSA + - cvss_v3 from GHSA and nvd.nist.gov URLs. - date field is rubygems.org release date.