"-Synchronized-Data."

This commit is contained in:
CVE Team 2020-12-11 11:01:50 +00:00
parent 75048f746a
commit 4f6b702898
No known key found for this signature in database
GPG Key ID: 5708902F06FEF743
2 changed files with 14 additions and 10 deletions

View File

@ -48,12 +48,14 @@
"references": {
"reference_data": [
{
"refsource": "CONFIRM",
"url": "https://snyk.io/vuln/SNYK-JS-INI-1048974"
"refsource": "MISC",
"url": "https://snyk.io/vuln/SNYK-JS-INI-1048974",
"name": "https://snyk.io/vuln/SNYK-JS-INI-1048974"
},
{
"refsource": "CONFIRM",
"url": "https://github.com/npm/ini/commit/56d2805e07ccd94e2ba0984ac9240ff02d44b6f1"
"refsource": "MISC",
"url": "https://github.com/npm/ini/commit/56d2805e07ccd94e2ba0984ac9240ff02d44b6f1",
"name": "https://github.com/npm/ini/commit/56d2805e07ccd94e2ba0984ac9240ff02d44b6f1"
}
]
},
@ -61,7 +63,7 @@
"description_data": [
{
"lang": "eng",
"value": "This affects the package ini before 1.3.6.\n If an attacker submits a malicious INI file to an application that parses it with ini.parse, they will pollute the prototype on the application. This can be exploited further depending on the context.\r\n\r\n"
"value": "This affects the package ini before 1.3.6. If an attacker submits a malicious INI file to an application that parses it with ini.parse, they will pollute the prototype on the application. This can be exploited further depending on the context."
}
]
},

View File

@ -48,12 +48,14 @@
"references": {
"reference_data": [
{
"refsource": "CONFIRM",
"url": "https://snyk.io/vuln/SNYK-PHP-SPATIEBROWSERSHOT-1037064"
"refsource": "MISC",
"url": "https://snyk.io/vuln/SNYK-PHP-SPATIEBROWSERSHOT-1037064",
"name": "https://snyk.io/vuln/SNYK-PHP-SPATIEBROWSERSHOT-1037064"
},
{
"refsource": "CONFIRM",
"url": "https://github.com/spatie/browsershot/issues/441%23issue-735049731"
"refsource": "MISC",
"url": "https://github.com/spatie/browsershot/issues/441%23issue-735049731",
"name": "https://github.com/spatie/browsershot/issues/441%23issue-735049731"
}
]
},
@ -61,7 +63,7 @@
"description_data": [
{
"lang": "eng",
"value": "This affects the package spatie/browsershot from 0.0.0.\n By specifying a URL in the file:// protocol an attacker is able to include arbitrary files in the resultant PDF.\n"
"value": "This affects the package spatie/browsershot from 0.0.0. By specifying a URL in the file:// protocol an attacker is able to include arbitrary files in the resultant PDF."
}
]
},