"-Synchronized-Data."

This commit is contained in:
CVE Team 2021-07-25 14:00:56 +00:00
parent 8a9934d19c
commit 40cc4d2005
No known key found for this signature in database
GPG Key ID: 5708902F06FEF743
3 changed files with 39 additions and 13 deletions

View File

@ -48,28 +48,34 @@
"references": {
"reference_data": [
{
"refsource": "CONFIRM",
"url": "https://snyk.io/vuln/SNYK-JS-JSZIP-1251497"
"refsource": "MISC",
"url": "https://snyk.io/vuln/SNYK-JS-JSZIP-1251497",
"name": "https://snyk.io/vuln/SNYK-JS-JSZIP-1251497"
},
{
"refsource": "CONFIRM",
"url": "https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1251498"
"refsource": "MISC",
"url": "https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1251498",
"name": "https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1251498"
},
{
"refsource": "CONFIRM",
"url": "https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-1251499"
"refsource": "MISC",
"url": "https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-1251499",
"name": "https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-1251499"
},
{
"refsource": "CONFIRM",
"url": "https://github.com/Stuk/jszip/blob/master/lib/object.js%23L88"
"refsource": "MISC",
"url": "https://github.com/Stuk/jszip/blob/master/lib/object.js%23L88",
"name": "https://github.com/Stuk/jszip/blob/master/lib/object.js%23L88"
},
{
"refsource": "CONFIRM",
"url": "https://github.com/Stuk/jszip/commit/22357494f424178cb416cdb7d93b26dd4f824b36"
"refsource": "MISC",
"url": "https://github.com/Stuk/jszip/commit/22357494f424178cb416cdb7d93b26dd4f824b36",
"name": "https://github.com/Stuk/jszip/commit/22357494f424178cb416cdb7d93b26dd4f824b36"
},
{
"refsource": "CONFIRM",
"url": "https://github.com/Stuk/jszip/pull/766"
"refsource": "MISC",
"url": "https://github.com/Stuk/jszip/pull/766",
"name": "https://github.com/Stuk/jszip/pull/766"
}
]
},
@ -77,7 +83,7 @@
"description_data": [
{
"lang": "eng",
"value": "This affects the package jszip before 3.7.0.\n Crafting a new zip file with filenames set to Object prototype values (e.g __proto__, toString, etc) results in a returned object with a modified prototype instance.\r\n\r\n"
"value": "This affects the package jszip before 3.7.0. Crafting a new zip file with filenames set to Object prototype values (e.g __proto__, toString, etc) results in a returned object with a modified prototype instance."
}
]
},

View File

@ -57,6 +57,16 @@
"refsource": "MISC",
"name": "https://www.open-xchange.com"
},
{
"refsource": "FULLDISC",
"name": "20210716 Open-Xchange Security Advisory 2021-07-15",
"url": "http://seclists.org/fulldisclosure/2021/Jul/33"
},
{
"refsource": "MISC",
"name": "http://packetstormsecurity.com/files/163527/OX-App-Suite-OX-Guard-OX-Documents-SSRF-Cross-Site-Scripting.html",
"url": "http://packetstormsecurity.com/files/163527/OX-App-Suite-OX-Guard-OX-Documents-SSRF-Cross-Site-Scripting.html"
},
{
"refsource": "CONFIRM",
"name": "http://seclists.org/fulldisclosure/2021/Jul/33",

View File

@ -57,6 +57,16 @@
"refsource": "MISC",
"name": "https://www.open-xchange.com"
},
{
"refsource": "FULLDISC",
"name": "20210716 Open-Xchange Security Advisory 2021-07-15",
"url": "http://seclists.org/fulldisclosure/2021/Jul/33"
},
{
"refsource": "MISC",
"name": "http://packetstormsecurity.com/files/163527/OX-App-Suite-OX-Guard-OX-Documents-SSRF-Cross-Site-Scripting.html",
"url": "http://packetstormsecurity.com/files/163527/OX-App-Suite-OX-Guard-OX-Documents-SSRF-Cross-Site-Scripting.html"
},
{
"refsource": "CONFIRM",
"name": "https://seclists.org/fulldisclosure/2021/Jul/33",