From 8bed429805aaba9c7210c31122dd4fe76f7f0851 Mon Sep 17 00:00:00 2001 From: Damien Neil Date: Wed, 28 Feb 2024 17:16:07 -0800 Subject: [PATCH] data/excluded: batch add 23 excluded reports Adds excluded reports: - data/excluded/GO-2024-2550.yaml - data/excluded/GO-2024-2553.yaml - data/excluded/GO-2024-2552.yaml - data/excluded/GO-2024-2548.yaml - data/excluded/GO-2024-2546.yaml - data/excluded/GO-2024-2545.yaml - data/excluded/GO-2024-2544.yaml - data/excluded/GO-2024-2543.yaml - data/excluded/GO-2024-2542.yaml - data/excluded/GO-2024-2565.yaml - data/excluded/GO-2024-2564.yaml - data/excluded/GO-2024-2563.yaml - data/excluded/GO-2024-2562.yaml - data/excluded/GO-2024-2560.yaml - data/excluded/GO-2024-2559.yaml - data/excluded/GO-2024-2558.yaml - data/excluded/GO-2024-2557.yaml - data/excluded/GO-2024-2556.yaml - data/excluded/GO-2024-2551.yaml - data/excluded/GO-2024-2549.yaml - data/excluded/GO-2024-2541.yaml - data/excluded/GO-2024-2540.yaml - data/excluded/GO-2024-2539.yaml Fixes golang/vulndb#2550 Fixes golang/vulndb#2553 Fixes golang/vulndb#2552 Fixes golang/vulndb#2548 Fixes golang/vulndb#2546 Fixes golang/vulndb#2545 Fixes golang/vulndb#2544 Fixes golang/vulndb#2543 Fixes golang/vulndb#2542 Fixes golang/vulndb#2565 Fixes golang/vulndb#2564 Fixes golang/vulndb#2563 Fixes golang/vulndb#2562 Fixes golang/vulndb#2560 Fixes golang/vulndb#2559 Fixes golang/vulndb#2558 Fixes golang/vulndb#2557 Fixes golang/vulndb#2556 Fixes golang/vulndb#2551 Fixes golang/vulndb#2549 Fixes golang/vulndb#2541 Fixes golang/vulndb#2540 Fixes golang/vulndb#2539 Change-Id: Ie1c613943bec12cf2ac8137a19ba24aba5972910 Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/568036 LUCI-TryBot-Result: Go LUCI Reviewed-by: Tatiana Bradley --- data/excluded/GO-2024-2539.yaml | 8 ++++++++ data/excluded/GO-2024-2540.yaml | 8 ++++++++ data/excluded/GO-2024-2541.yaml | 8 ++++++++ data/excluded/GO-2024-2542.yaml | 6 ++++++ data/excluded/GO-2024-2543.yaml | 6 ++++++ data/excluded/GO-2024-2544.yaml | 6 ++++++ data/excluded/GO-2024-2545.yaml | 6 ++++++ data/excluded/GO-2024-2546.yaml | 6 ++++++ data/excluded/GO-2024-2548.yaml | 6 ++++++ data/excluded/GO-2024-2549.yaml | 8 ++++++++ data/excluded/GO-2024-2550.yaml | 8 ++++++++ data/excluded/GO-2024-2551.yaml | 8 ++++++++ data/excluded/GO-2024-2552.yaml | 6 ++++++ data/excluded/GO-2024-2553.yaml | 6 ++++++ data/excluded/GO-2024-2556.yaml | 8 ++++++++ data/excluded/GO-2024-2557.yaml | 8 ++++++++ data/excluded/GO-2024-2558.yaml | 8 ++++++++ data/excluded/GO-2024-2559.yaml | 8 ++++++++ data/excluded/GO-2024-2560.yaml | 8 ++++++++ data/excluded/GO-2024-2562.yaml | 8 ++++++++ data/excluded/GO-2024-2563.yaml | 8 ++++++++ data/excluded/GO-2024-2564.yaml | 8 ++++++++ data/excluded/GO-2024-2565.yaml | 8 ++++++++ 23 files changed, 168 insertions(+) create mode 100644 data/excluded/GO-2024-2539.yaml create mode 100644 data/excluded/GO-2024-2540.yaml create mode 100644 data/excluded/GO-2024-2541.yaml create mode 100644 data/excluded/GO-2024-2542.yaml create mode 100644 data/excluded/GO-2024-2543.yaml create mode 100644 data/excluded/GO-2024-2544.yaml create mode 100644 data/excluded/GO-2024-2545.yaml create mode 100644 data/excluded/GO-2024-2546.yaml create mode 100644 data/excluded/GO-2024-2548.yaml create mode 100644 data/excluded/GO-2024-2549.yaml create mode 100644 data/excluded/GO-2024-2550.yaml create mode 100644 data/excluded/GO-2024-2551.yaml create mode 100644 data/excluded/GO-2024-2552.yaml create mode 100644 data/excluded/GO-2024-2553.yaml create mode 100644 data/excluded/GO-2024-2556.yaml create mode 100644 data/excluded/GO-2024-2557.yaml create mode 100644 data/excluded/GO-2024-2558.yaml create mode 100644 data/excluded/GO-2024-2559.yaml create mode 100644 data/excluded/GO-2024-2560.yaml create mode 100644 data/excluded/GO-2024-2562.yaml create mode 100644 data/excluded/GO-2024-2563.yaml create mode 100644 data/excluded/GO-2024-2564.yaml create mode 100644 data/excluded/GO-2024-2565.yaml diff --git a/data/excluded/GO-2024-2539.yaml b/data/excluded/GO-2024-2539.yaml new file mode 100644 index 00000000..a3dc1dfb --- /dev/null +++ b/data/excluded/GO-2024-2539.yaml @@ -0,0 +1,8 @@ +id: GO-2024-2539 +excluded: EFFECTIVELY_PRIVATE +modules: + - module: github.com/mattermost/mattermost-plugin-jira +cves: + - CVE-2024-23319 +ghsas: + - GHSA-4fp6-574p-fc35 diff --git a/data/excluded/GO-2024-2540.yaml b/data/excluded/GO-2024-2540.yaml new file mode 100644 index 00000000..7c08e8c2 --- /dev/null +++ b/data/excluded/GO-2024-2540.yaml @@ -0,0 +1,8 @@ +id: GO-2024-2540 +excluded: EFFECTIVELY_PRIVATE +modules: + - module: github.com/mattermost/mattermost-plugin-jira +cves: + - CVE-2024-24774 +ghsas: + - GHSA-qr8f-cjw7-838m diff --git a/data/excluded/GO-2024-2541.yaml b/data/excluded/GO-2024-2541.yaml new file mode 100644 index 00000000..3b42586b --- /dev/null +++ b/data/excluded/GO-2024-2541.yaml @@ -0,0 +1,8 @@ +id: GO-2024-2541 +excluded: EFFECTIVELY_PRIVATE +modules: + - module: github.com/mattermost/mattermost/server/v8 +cves: + - CVE-2024-1402 +ghsas: + - GHSA-32h7-7j94-8fc2 diff --git a/data/excluded/GO-2024-2542.yaml b/data/excluded/GO-2024-2542.yaml new file mode 100644 index 00000000..5a9721cf --- /dev/null +++ b/data/excluded/GO-2024-2542.yaml @@ -0,0 +1,6 @@ +id: GO-2024-2542 +excluded: NOT_GO_CODE +modules: + - module: github.com/envoyproxy/envoy +cves: + - CVE-2024-23322 diff --git a/data/excluded/GO-2024-2543.yaml b/data/excluded/GO-2024-2543.yaml new file mode 100644 index 00000000..c2b7cbd6 --- /dev/null +++ b/data/excluded/GO-2024-2543.yaml @@ -0,0 +1,6 @@ +id: GO-2024-2543 +excluded: NOT_GO_CODE +modules: + - module: github.com/envoyproxy/envoy +cves: + - CVE-2024-23323 diff --git a/data/excluded/GO-2024-2544.yaml b/data/excluded/GO-2024-2544.yaml new file mode 100644 index 00000000..87bd5024 --- /dev/null +++ b/data/excluded/GO-2024-2544.yaml @@ -0,0 +1,6 @@ +id: GO-2024-2544 +excluded: NOT_GO_CODE +modules: + - module: github.com/envoyproxy/envoy +cves: + - CVE-2024-23324 diff --git a/data/excluded/GO-2024-2545.yaml b/data/excluded/GO-2024-2545.yaml new file mode 100644 index 00000000..3b2f9302 --- /dev/null +++ b/data/excluded/GO-2024-2545.yaml @@ -0,0 +1,6 @@ +id: GO-2024-2545 +excluded: NOT_GO_CODE +modules: + - module: github.com/envoyproxy/envoy +cves: + - CVE-2024-23325 diff --git a/data/excluded/GO-2024-2546.yaml b/data/excluded/GO-2024-2546.yaml new file mode 100644 index 00000000..eaee3dce --- /dev/null +++ b/data/excluded/GO-2024-2546.yaml @@ -0,0 +1,6 @@ +id: GO-2024-2546 +excluded: NOT_GO_CODE +modules: + - module: github.com/envoyproxy/envoy +cves: + - CVE-2024-23327 diff --git a/data/excluded/GO-2024-2548.yaml b/data/excluded/GO-2024-2548.yaml new file mode 100644 index 00000000..0af5cc7a --- /dev/null +++ b/data/excluded/GO-2024-2548.yaml @@ -0,0 +1,6 @@ +id: GO-2024-2548 +excluded: NOT_GO_CODE +modules: + - module: github.com/svix/svix-webhooks +cves: + - CVE-2024-21491 diff --git a/data/excluded/GO-2024-2549.yaml b/data/excluded/GO-2024-2549.yaml new file mode 100644 index 00000000..ef937804 --- /dev/null +++ b/data/excluded/GO-2024-2549.yaml @@ -0,0 +1,8 @@ +id: GO-2024-2549 +excluded: EFFECTIVELY_PRIVATE +modules: + - module: github.com/greenpau/caddy-security +cves: + - CVE-2023-52430 +ghsas: + - GHSA-xwmv-cx7p-fqfc diff --git a/data/excluded/GO-2024-2550.yaml b/data/excluded/GO-2024-2550.yaml new file mode 100644 index 00000000..b9c378c7 --- /dev/null +++ b/data/excluded/GO-2024-2550.yaml @@ -0,0 +1,8 @@ +id: GO-2024-2550 +excluded: NOT_IMPORTABLE +modules: + - module: github.com/mongodb/mongo-tools +cves: + - CVE-2020-7924 +ghsas: + - GHSA-6cwm-wm82-hgrw diff --git a/data/excluded/GO-2024-2551.yaml b/data/excluded/GO-2024-2551.yaml new file mode 100644 index 00000000..a48f918f --- /dev/null +++ b/data/excluded/GO-2024-2551.yaml @@ -0,0 +1,8 @@ +id: GO-2024-2551 +excluded: EFFECTIVELY_PRIVATE +modules: + - module: github.com/grafana/grafana +cves: + - CVE-2023-6152 +ghsas: + - GHSA-3hv4-r2fm-h27f diff --git a/data/excluded/GO-2024-2552.yaml b/data/excluded/GO-2024-2552.yaml new file mode 100644 index 00000000..326d1694 --- /dev/null +++ b/data/excluded/GO-2024-2552.yaml @@ -0,0 +1,6 @@ +id: GO-2024-2552 +excluded: NOT_GO_CODE +modules: + - module: gitlab.nic.cz/knot/knot-resolver +cves: + - CVE-2023-50387 diff --git a/data/excluded/GO-2024-2553.yaml b/data/excluded/GO-2024-2553.yaml new file mode 100644 index 00000000..e6cb1d2c --- /dev/null +++ b/data/excluded/GO-2024-2553.yaml @@ -0,0 +1,6 @@ +id: GO-2024-2553 +excluded: NOT_GO_CODE +modules: + - module: gitlab.nic.cz/knot/knot-resolver +cves: + - CVE-2023-50868 diff --git a/data/excluded/GO-2024-2556.yaml b/data/excluded/GO-2024-2556.yaml new file mode 100644 index 00000000..977410d9 --- /dev/null +++ b/data/excluded/GO-2024-2556.yaml @@ -0,0 +1,8 @@ +id: GO-2024-2556 +excluded: EFFECTIVELY_PRIVATE +modules: + - module: github.com/elastic/apm-server +cves: + - CVE-2024-23448 +ghsas: + - GHSA-8r33-q5j5-rh7g diff --git a/data/excluded/GO-2024-2557.yaml b/data/excluded/GO-2024-2557.yaml new file mode 100644 index 00000000..5f98d96b --- /dev/null +++ b/data/excluded/GO-2024-2557.yaml @@ -0,0 +1,8 @@ +id: GO-2024-2557 +excluded: EFFECTIVELY_PRIVATE +modules: + - module: github.com/greenpau/caddy-security +cves: + - CVE-2024-21492 +ghsas: + - GHSA-vp66-gf7w-9m4x diff --git a/data/excluded/GO-2024-2558.yaml b/data/excluded/GO-2024-2558.yaml new file mode 100644 index 00000000..e1ce0bd6 --- /dev/null +++ b/data/excluded/GO-2024-2558.yaml @@ -0,0 +1,8 @@ +id: GO-2024-2558 +excluded: EFFECTIVELY_PRIVATE +modules: + - module: github.com/greenpau/caddy-security +cves: + - CVE-2024-21494 +ghsas: + - GHSA-vj36-3ccr-6563 diff --git a/data/excluded/GO-2024-2559.yaml b/data/excluded/GO-2024-2559.yaml new file mode 100644 index 00000000..0113193b --- /dev/null +++ b/data/excluded/GO-2024-2559.yaml @@ -0,0 +1,8 @@ +id: GO-2024-2559 +excluded: EFFECTIVELY_PRIVATE +modules: + - module: github.com/greenpau/caddy-security +cves: + - CVE-2024-21496 +ghsas: + - GHSA-ff72-ff42-c3gw diff --git a/data/excluded/GO-2024-2560.yaml b/data/excluded/GO-2024-2560.yaml new file mode 100644 index 00000000..809c6f01 --- /dev/null +++ b/data/excluded/GO-2024-2560.yaml @@ -0,0 +1,8 @@ +id: GO-2024-2560 +excluded: EFFECTIVELY_PRIVATE +modules: + - module: github.com/greenpau/caddy-security +cves: + - CVE-2024-21497 +ghsas: + - GHSA-8hp3-rmr7-xh88 diff --git a/data/excluded/GO-2024-2562.yaml b/data/excluded/GO-2024-2562.yaml new file mode 100644 index 00000000..8be0efe6 --- /dev/null +++ b/data/excluded/GO-2024-2562.yaml @@ -0,0 +1,8 @@ +id: GO-2024-2562 +excluded: EFFECTIVELY_PRIVATE +modules: + - module: github.com/greenpau/caddy-security +cves: + - CVE-2024-21499 +ghsas: + - GHSA-r969-783f-6jqr diff --git a/data/excluded/GO-2024-2563.yaml b/data/excluded/GO-2024-2563.yaml new file mode 100644 index 00000000..bfcac479 --- /dev/null +++ b/data/excluded/GO-2024-2563.yaml @@ -0,0 +1,8 @@ +id: GO-2024-2563 +excluded: EFFECTIVELY_PRIVATE +modules: + - module: github.com/greenpau/caddy-security +cves: + - CVE-2024-21500 +ghsas: + - GHSA-vfph-hjfv-cpv2 diff --git a/data/excluded/GO-2024-2564.yaml b/data/excluded/GO-2024-2564.yaml new file mode 100644 index 00000000..3f74b409 --- /dev/null +++ b/data/excluded/GO-2024-2564.yaml @@ -0,0 +1,8 @@ +id: GO-2024-2564 +excluded: EFFECTIVELY_PRIVATE +modules: + - module: github.com/greenpau/caddy-security +cves: + - CVE-2024-21493 +ghsas: + - GHSA-8h95-jcp5-pjpr diff --git a/data/excluded/GO-2024-2565.yaml b/data/excluded/GO-2024-2565.yaml new file mode 100644 index 00000000..8d116794 --- /dev/null +++ b/data/excluded/GO-2024-2565.yaml @@ -0,0 +1,8 @@ +id: GO-2024-2565 +excluded: EFFECTIVELY_PRIVATE +modules: + - module: github.com/greenpau/caddy-security +cves: + - CVE-2024-21495 +ghsas: + - GHSA-c7vf-m394-m4x4