@@ -19,69 +19,69 @@ <h1>security-checker</h1>
19
19
* CVE-2022-41343: Remote file inclusion
20
20
https://github.com/advisories/GHSA-6x28-7h8c-chx4
21
21
22
- * CVE-2023-23924: Dompdf vulnerable to URI validation failure on SVG parsing
23
- https://github.com/advisories/GHSA-3cw5-7cxw-v5qg
24
-
25
- * CVE-2014-5013: Remote Code Execution (complement of CVE-2014-2383)
26
- https://github.com/dompdf/dompdf/releases/tag/v0.6.2
22
+ * CVE-2022-0085: Server-Side Request Forgery in dompdf/dompdf
23
+ https://github.com/advisories/GHSA-pf6p-25r2-fx45
27
24
28
25
* CVE-2014-5012: Denial Of Service Vector
29
26
https://github.com/dompdf/dompdf/releases/tag/v0.6.2
30
27
31
28
* CVE-2014-5011: Information Disclosure
32
29
https://github.com/dompdf/dompdf/releases/tag/v0.6.2
33
30
34
- * CVE-2022-0085: Server-Side Request Forgery in dompdf/dompdf
35
- https://github.com/advisories/GHSA-pf6p-25r2-fx45
31
+ * CVE-2023-23924: Dompdf vulnerable to URI validation failure on SVG parsing
32
+ https://github.com/advisories/GHSA-3cw5-7cxw-v5qg
33
+
34
+ * CVE-2014-5013: Remote Code Execution (complement of CVE-2014-2383)
35
+ https://github.com/dompdf/dompdf/releases/tag/v0.6.2
36
36
37
37
drupal/core (8.9.13)
38
38
--------------------
39
39
40
- * CVE-2021-33829: Drupal core - Critical - Cross-site scripting - SA-CORE-2021-003
41
- https://www.drupal.org/sa-core-2021-003
42
-
43
- * CVE-2022-25277: Drupal core - Critical - Arbitrary PHP code execution - SA-CORE-2022-014
44
- https://www.drupal.org/sa-core-2022-014
40
+ * CVE-2022-25278: Drupal core - Moderately critical - Access Bypass - SA-CORE-2022-013
41
+ https://www.drupal.org/sa-core-2022-013
45
42
46
43
* CVE-2020-13672: Drupal core - Critical - Cross-site scripting - SA-CORE-2021-002
47
44
https://www.drupal.org/sa-core-2021-002
48
45
49
46
* Drupal core - Moderately critical - Third-party libraries - SA-CORE-2021-005
50
47
https://www.drupal.org/sa-core-2021-005
51
48
52
- * CVE-2022-25278: Drupal core - Moderately critical - Access Bypass - SA-CORE-2022-013
53
- https://www.drupal.org/sa-core-2022-013
49
+ * CVE-2022-25277: Drupal core - Critical - Arbitrary PHP code execution - SA-CORE-2022-014
50
+ https://www.drupal.org/sa-core-2022-014
51
+
52
+ * CVE-2021-33829: Drupal core - Critical - Cross-site scripting - SA-CORE-2021-003
53
+ https://www.drupal.org/sa-core-2021-003
54
54
55
55
* CVE-2022-25275: Drupal core - Moderately critical - Information Disclosure - SA-CORE-2022-012
56
56
https://www.drupal.org/sa-core-2022-012
57
57
58
58
guzzlehttp/guzzle (6.5.4)
59
59
-------------------------
60
60
61
- * CVE-2022-31091: Change in port should be considered a change in origin
62
- https://github.com/guzzle/guzzle/security/advisories/GHSA-q559-8m2m-g699
61
+ * CVE-2022-31090: CURLOPT_HTTPAUTH option not cleared on change of origin
62
+ https://github.com/guzzle/guzzle/security/advisories/GHSA-25mq-v84q-4j7r
63
+
64
+ * CVE-2022-31042: Failure to strip the Cookie header on change in host or HTTP downgrade
65
+ https://github.com/guzzle/guzzle/security/advisories/GHSA-f2wf-25xc-69c9
63
66
64
67
* CVE-2022-29248: Cross-domain cookie leakage
65
68
https://github.com/guzzle/guzzle/security/advisories/GHSA-cwmx-hcrq-mhc3
66
69
70
+ * CVE-2022-31091: Change in port should be considered a change in origin
71
+ https://github.com/guzzle/guzzle/security/advisories/GHSA-q559-8m2m-g699
72
+
67
73
* CVE-2022-31043: Fix failure to strip Authorization header on HTTP downgrade
68
74
https://github.com/guzzle/guzzle/security/advisories/GHSA-w248-ffj2-4v5q
69
75
70
- * CVE-2022-31042: Failure to strip the Cookie header on change in host or HTTP downgrade
71
- https://github.com/guzzle/guzzle/security/advisories/GHSA-f2wf-25xc-69c9
72
-
73
- * CVE-2022-31090: CURLOPT_HTTPAUTH option not cleared on change of origin
74
- https://github.com/guzzle/guzzle/security/advisories/GHSA-25mq-v84q-4j7r
75
-
76
76
guzzlehttp/psr7 (1.6.1)
77
77
-----------------------
78
78
79
- * CVE-2023-29197: Improper header validation
80
- https://github.com/guzzle/psr7/security/advisories/GHSA-wxmh-65f7-jcvw
81
-
82
79
* CVE-2022-24775: Inproper parsing of HTTP headers
83
80
https://github.com/guzzle/psr7/security/advisories/GHSA-q7rv-6hp3-vh96
84
81
82
+ * CVE-2023-29197: Improper header validation
83
+ https://github.com/guzzle/psr7/security/advisories/GHSA-wxmh-65f7-jcvw
84
+
85
85
laminas/laminas-diactoros (1.8.7p2)
86
86
-----------------------------------
87
87
0 commit comments