From 1548a4075b05f0728803c5c598881c7c64a37bd0 Mon Sep 17 00:00:00 2001 From: Luca Lusso Date: Fri, 15 Sep 2023 12:44:46 +0200 Subject: [PATCH] refs #000: Update security-checker.html --- tests/expected_reports/security-checker.html | 24 ++++++++++---------- 1 file changed, 12 insertions(+), 12 deletions(-) diff --git a/tests/expected_reports/security-checker.html b/tests/expected_reports/security-checker.html index 7cbcf34..4440234 100644 --- a/tests/expected_reports/security-checker.html +++ b/tests/expected_reports/security-checker.html @@ -4,15 +4,24 @@

security-checker

composer/composer (1.10.22) --------------------------- - * CVE-2022-24828: Missing input validation can lead to command execution in composer - https://github.com/composer/composer/security/advisories/GHSA-x7cr-6qr6-2hh6 - * CVE-2021-41116: Improper escaping of command arguments on Windows leading to command injection https://github.com/composer/composer/security/advisories/GHSA-frqg-7g38-6gcf + * CVE-2022-24828: Missing input validation can lead to command execution in composer + https://github.com/composer/composer/security/advisories/GHSA-x7cr-6qr6-2hh6 + dompdf/dompdf (0.6.1) --------------------- + * CVE-2022-28368: Remote code injection via remote fonts + https://github.com/advisories/GHSA-x752-qjv4-c4hc + + * CVE-2022-41343: Remote file inclusion + https://github.com/advisories/GHSA-6x28-7h8c-chx4 + + * CVE-2022-0085: Server-Side Request Forgery in dompdf/dompdf + https://github.com/advisories/GHSA-pf6p-25r2-fx45 + * CVE-2023-23924: Dompdf vulnerable to URI validation failure on SVG parsing https://github.com/advisories/GHSA-3cw5-7cxw-v5qg @@ -22,15 +31,6 @@

security-checker

* CVE-2014-5011: Information Disclosure https://github.com/dompdf/dompdf/releases/tag/v0.6.2 - * CVE-2022-0085: Server-Side Request Forgery in dompdf/dompdf - https://github.com/advisories/GHSA-pf6p-25r2-fx45 - - * CVE-2022-41343: Remote file inclusion - https://github.com/advisories/GHSA-6x28-7h8c-chx4 - - * CVE-2022-28368: Remote code injection via remote fonts - https://github.com/advisories/GHSA-x752-qjv4-c4hc - * CVE-2014-5013: Remote Code Execution (complement of CVE-2014-2383) https://github.com/dompdf/dompdf/releases/tag/v0.6.2