From 6e0266630a905244f7ea28c043bba0784359b3dd Mon Sep 17 00:00:00 2001 From: justmurphy <96064251+justmurphy@users.noreply.github.com> Date: Tue, 1 Feb 2022 08:38:28 -0500 Subject: [PATCH 1/4] Add 7Signal Sapphire --- data/cisagov_Non-Alphabet.yml | 31 +++++++++++++++++++++++++++++++ 1 file changed, 31 insertions(+) diff --git a/data/cisagov_Non-Alphabet.yml b/data/cisagov_Non-Alphabet.yml index 082f969..03ae811 100644 --- a/data/cisagov_Non-Alphabet.yml +++ b/data/cisagov_Non-Alphabet.yml @@ -125,6 +125,37 @@ software: references: - '' last_updated: '2021-12-15T00:00:00' + - vendor: 7Signal + product: Sapphire + cves: + cve-2021-4104: + investigated: true + affected_versions: [] + fixed_versions: [] + unaffected_versions: + - '' + cve-2021-44228: + investigated: true + affected_versions: [] + fixed_versions: + - '' + unaffected_versions: [] + cve-2021-45046: + investigated: false + affected_versions: [] + fixed_versions: [] + unaffected_versions: [] + cve-2021-45105: + investigated: false + affected_versions: [] + fixed_versions: [] + unaffected_versions: [] + vendor_links: + - https://www.7signal.com/info/se-release-notes + notes: '' + references: + - '' + last_updated: '2021-12-15T00:00:00' - vendor: 7-Zip product: '' cves: From 91e10546b14f17c82c8f542ea6dadf5b97c80227 Mon Sep 17 00:00:00 2001 From: cisagovbot <65734717+cisagovbot@users.noreply.github.com> Date: Tue, 1 Feb 2022 13:40:36 +0000 Subject: [PATCH 2/4] Update the software list --- SOFTWARE-LIST.md | 1 + data/cisagov.yml | 31 ++++++++++++++++++++++++++++++ data/cisagov_Non-Alphabet.yml | 36 +++++++++++++++++------------------ 3 files changed, 50 insertions(+), 18 deletions(-) diff --git a/SOFTWARE-LIST.md b/SOFTWARE-LIST.md index 2151d17..760bdcb 100644 --- a/SOFTWARE-LIST.md +++ b/SOFTWARE-LIST.md @@ -27,6 +27,7 @@ NOTE: This file is automatically generated. To submit updates, please refer to | 3CX | | | | Unknown | [link](https://www.3cx.com/community/threads/log4j-vulnerability-cve-2021-44228.86436/#post-407911) | | | [cisagov](https://github.com/cisagov/log4j-affected-db) | 2022-01-12 | | 3M Health Information Systems | CGS | | | Unknown | [link](https://support.3mhis.com/app/account/updates/ri/5210) | This advisory is available to customer only and has not been reviewed by CISA. | | [cisagov](https://github.com/cisagov/log4j-affected-db) | 2021-12-15 | | 7-Zip | | | | Unknown | [link](https://sourceforge.net/p/sevenzip/discussion/45797/thread/b977bbd4d1) | | | [cisagov](https://github.com/cisagov/log4j-affected-db) | 2022-01-12 | +| 7Signal | Sapphire | | | Fixed | [link](https://www.7signal.com/info/se-release-notes) | | | [cisagov](https://github.com/cisagov/log4j-affected-db) | 2021-12-15 | | ABB | | | | Unknown | [link](https://search.abb.com/library/Download.aspx?DocumentID=9ADB012621&LanguageCode=en&DocumentPartId=&Action=Launch) | | | [cisagov](https://github.com/cisagov/log4j-affected-db) | 2022-01-12 | | ABB | ABB Remote Service | ABB Remote Platform (RAP) | | Affected | | | | [cisagov](https://github.com/cisagov/log4j-affected-db) | 2022-01-12 | | ABB | AlarmInsight Cloud | AlarmInsight KPI Dashboards 1.0.0 | | Affected | | | | [cisagov](https://github.com/cisagov/log4j-affected-db) | 2022-01-12 | diff --git a/data/cisagov.yml b/data/cisagov.yml index f7a7b7c..380af0c 100644 --- a/data/cisagov.yml +++ b/data/cisagov.yml @@ -154,6 +154,37 @@ software: references: - '' last_updated: '2022-01-12T07:18:50+00:00' + - vendor: 7Signal + product: Sapphire + cves: + cve-2021-4104: + investigated: true + affected_versions: [] + fixed_versions: [] + unaffected_versions: + - '' + cve-2021-44228: + investigated: true + affected_versions: [] + fixed_versions: + - '' + unaffected_versions: [] + cve-2021-45046: + investigated: false + affected_versions: [] + fixed_versions: [] + unaffected_versions: [] + cve-2021-45105: + investigated: false + affected_versions: [] + fixed_versions: [] + unaffected_versions: [] + vendor_links: + - https://www.7signal.com/info/se-release-notes + notes: '' + references: + - '' + last_updated: '2021-12-15T00:00:00' - vendor: ABB product: '' cves: diff --git a/data/cisagov_Non-Alphabet.yml b/data/cisagov_Non-Alphabet.yml index 03ae811..55687fc 100644 --- a/data/cisagov_Non-Alphabet.yml +++ b/data/cisagov_Non-Alphabet.yml @@ -125,20 +125,18 @@ software: references: - '' last_updated: '2021-12-15T00:00:00' - - vendor: 7Signal - product: Sapphire + - vendor: 7-Zip + product: '' cves: cve-2021-4104: - investigated: true + investigated: false affected_versions: [] fixed_versions: [] - unaffected_versions: - - '' + unaffected_versions: [] cve-2021-44228: - investigated: true + investigated: false affected_versions: [] - fixed_versions: - - '' + fixed_versions: [] unaffected_versions: [] cve-2021-45046: investigated: false @@ -151,23 +149,25 @@ software: fixed_versions: [] unaffected_versions: [] vendor_links: - - https://www.7signal.com/info/se-release-notes + - https://sourceforge.net/p/sevenzip/discussion/45797/thread/b977bbd4d1 notes: '' references: - '' - last_updated: '2021-12-15T00:00:00' - - vendor: 7-Zip - product: '' + last_updated: '2022-01-12T07:18:50+00:00' + - vendor: 7Signal + product: Sapphire cves: cve-2021-4104: - investigated: false + investigated: true affected_versions: [] fixed_versions: [] - unaffected_versions: [] + unaffected_versions: + - '' cve-2021-44228: - investigated: false + investigated: true affected_versions: [] - fixed_versions: [] + fixed_versions: + - '' unaffected_versions: [] cve-2021-45046: investigated: false @@ -180,9 +180,9 @@ software: fixed_versions: [] unaffected_versions: [] vendor_links: - - https://sourceforge.net/p/sevenzip/discussion/45797/thread/b977bbd4d1 + - https://www.7signal.com/info/se-release-notes notes: '' references: - '' - last_updated: '2022-01-12T07:18:50+00:00' + last_updated: '2021-12-15T00:00:00' ... From 6accd8374795f1e2cce6c07cd9dbc399bd2ddac9 Mon Sep 17 00:00:00 2001 From: justmurphy <96064251+justmurphy@users.noreply.github.com> Date: Tue, 1 Feb 2022 08:52:55 -0500 Subject: [PATCH 3/4] Update 7Signal entry --- data/cisagov_Non-Alphabet.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/data/cisagov_Non-Alphabet.yml b/data/cisagov_Non-Alphabet.yml index 55687fc..0a182af 100644 --- a/data/cisagov_Non-Alphabet.yml +++ b/data/cisagov_Non-Alphabet.yml @@ -181,8 +181,8 @@ software: unaffected_versions: [] vendor_links: - https://www.7signal.com/info/se-release-notes - notes: '' + notes: Fix released 2021-12-14 references: - '' - last_updated: '2021-12-15T00:00:00' + last_updated: '2021-12-14T00:00:00' ... From d83314541cc9708e13dcf88c23f11df57200c1cc Mon Sep 17 00:00:00 2001 From: cisagovbot <65734717+cisagovbot@users.noreply.github.com> Date: Tue, 1 Feb 2022 13:59:06 +0000 Subject: [PATCH 4/4] Update the software list --- SOFTWARE-LIST.md | 2 +- data/cisagov.yml | 4 ++-- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/SOFTWARE-LIST.md b/SOFTWARE-LIST.md index 760bdcb..b38cb65 100644 --- a/SOFTWARE-LIST.md +++ b/SOFTWARE-LIST.md @@ -27,7 +27,7 @@ NOTE: This file is automatically generated. To submit updates, please refer to | 3CX | | | | Unknown | [link](https://www.3cx.com/community/threads/log4j-vulnerability-cve-2021-44228.86436/#post-407911) | | | [cisagov](https://github.com/cisagov/log4j-affected-db) | 2022-01-12 | | 3M Health Information Systems | CGS | | | Unknown | [link](https://support.3mhis.com/app/account/updates/ri/5210) | This advisory is available to customer only and has not been reviewed by CISA. | | [cisagov](https://github.com/cisagov/log4j-affected-db) | 2021-12-15 | | 7-Zip | | | | Unknown | [link](https://sourceforge.net/p/sevenzip/discussion/45797/thread/b977bbd4d1) | | | [cisagov](https://github.com/cisagov/log4j-affected-db) | 2022-01-12 | -| 7Signal | Sapphire | | | Fixed | [link](https://www.7signal.com/info/se-release-notes) | | | [cisagov](https://github.com/cisagov/log4j-affected-db) | 2021-12-15 | +| 7Signal | Sapphire | | | Fixed | [link](https://www.7signal.com/info/se-release-notes) | Fix released 2021-12-14 | | [cisagov](https://github.com/cisagov/log4j-affected-db) | 2021-12-14 | | ABB | | | | Unknown | [link](https://search.abb.com/library/Download.aspx?DocumentID=9ADB012621&LanguageCode=en&DocumentPartId=&Action=Launch) | | | [cisagov](https://github.com/cisagov/log4j-affected-db) | 2022-01-12 | | ABB | ABB Remote Service | ABB Remote Platform (RAP) | | Affected | | | | [cisagov](https://github.com/cisagov/log4j-affected-db) | 2022-01-12 | | ABB | AlarmInsight Cloud | AlarmInsight KPI Dashboards 1.0.0 | | Affected | | | | [cisagov](https://github.com/cisagov/log4j-affected-db) | 2022-01-12 | diff --git a/data/cisagov.yml b/data/cisagov.yml index 380af0c..fec6c78 100644 --- a/data/cisagov.yml +++ b/data/cisagov.yml @@ -181,10 +181,10 @@ software: unaffected_versions: [] vendor_links: - https://www.7signal.com/info/se-release-notes - notes: '' + notes: Fix released 2021-12-14 references: - '' - last_updated: '2021-12-15T00:00:00' + last_updated: '2021-12-14T00:00:00' - vendor: ABB product: '' cves: