From 10ce279920971ecfdfc83767bdaa54db3ff75d07 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 27 Feb 2025 00:31:51 +0000 Subject: [PATCH] Publish Advisories GHSA-vgrx-vhjf-p7wv GHSA-393j-fpg3-h6c9 GHSA-fxgj-cfm7-w8hw GHSA-h2w6-c2hx-7jcf GHSA-jc9g-7x7r-c8w7 GHSA-mvh5-v533-3v55 GHSA-q8jx-8wr3-gv52 GHSA-x748-g8vm-gmhw GHSA-657j-69g5-mr77 GHSA-jhvx-96xq-qggm GHSA-659h-jrcq-w3wg GHSA-6pc8-5263-hvgq GHSA-7xmw-644w-wp3m GHSA-mjhr-3845-j2r5 --- .../GHSA-vgrx-vhjf-p7wv.json | 18 +++++++++- .../GHSA-393j-fpg3-h6c9.json | 4 +-- .../GHSA-fxgj-cfm7-w8hw.json | 4 +-- .../GHSA-h2w6-c2hx-7jcf.json | 4 +-- .../GHSA-jc9g-7x7r-c8w7.json | 4 +-- .../GHSA-mvh5-v533-3v55.json | 4 +-- .../GHSA-q8jx-8wr3-gv52.json | 4 +-- .../GHSA-x748-g8vm-gmhw.json | 1 + .../GHSA-657j-69g5-mr77.json | 6 +++- .../GHSA-jhvx-96xq-qggm.json | 6 +++- .../GHSA-659h-jrcq-w3wg.json | 25 ++++++++++++++ .../GHSA-6pc8-5263-hvgq.json | 29 ++++++++++++++++ .../GHSA-7xmw-644w-wp3m.json | 33 +++++++++++++++++++ .../GHSA-mjhr-3845-j2r5.json | 29 ++++++++++++++++ 14 files changed, 156 insertions(+), 15 deletions(-) create mode 100644 advisories/unreviewed/2025/02/GHSA-659h-jrcq-w3wg/GHSA-659h-jrcq-w3wg.json create mode 100644 advisories/unreviewed/2025/02/GHSA-6pc8-5263-hvgq/GHSA-6pc8-5263-hvgq.json create mode 100644 advisories/unreviewed/2025/02/GHSA-7xmw-644w-wp3m/GHSA-7xmw-644w-wp3m.json create mode 100644 advisories/unreviewed/2025/02/GHSA-mjhr-3845-j2r5/GHSA-mjhr-3845-j2r5.json diff --git a/advisories/unreviewed/2023/03/GHSA-vgrx-vhjf-p7wv/GHSA-vgrx-vhjf-p7wv.json b/advisories/unreviewed/2023/03/GHSA-vgrx-vhjf-p7wv/GHSA-vgrx-vhjf-p7wv.json index d7761d45bb6..7b47c858e23 100644 --- a/advisories/unreviewed/2023/03/GHSA-vgrx-vhjf-p7wv/GHSA-vgrx-vhjf-p7wv.json +++ b/advisories/unreviewed/2023/03/GHSA-vgrx-vhjf-p7wv/GHSA-vgrx-vhjf-p7wv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vgrx-vhjf-p7wv", - "modified": "2023-03-21T21:30:19Z", + "modified": "2025-02-27T00:30:24Z", "published": "2023-03-15T21:30:25Z", "aliases": [ "CVE-2023-28450" @@ -23,6 +23,14 @@ "type": "WEB", "url": "https://capec.mitre.org/data/definitions/495.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6UQ6LKDTLSSD64TBIZ3XEKBM2SWC63VV" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OU2ZT4ITSEOOR2CFBAHK4Z67KXJIEWQA" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6UQ6LKDTLSSD64TBIZ3XEKBM2SWC63VV" @@ -35,6 +43,14 @@ "type": "WEB", "url": "https://thekelleys.org.uk/dnsmasq/doc.html" }, + { + "type": "WEB", + "url": "https://thekelleys.org.uk/gitweb/?p=dnsmasq.git%3Ba=blob%3Bf=CHANGELOG" + }, + { + "type": "WEB", + "url": "https://thekelleys.org.uk/gitweb/?p=dnsmasq.git%3Ba=commit%3Bh=eb92fb32b746f2104b0f370b5b295bb8dd4bd5e5" + }, { "type": "WEB", "url": "https://thekelleys.org.uk/gitweb/?p=dnsmasq.git;a=blob;f=CHANGELOG" diff --git a/advisories/unreviewed/2023/11/GHSA-393j-fpg3-h6c9/GHSA-393j-fpg3-h6c9.json b/advisories/unreviewed/2023/11/GHSA-393j-fpg3-h6c9/GHSA-393j-fpg3-h6c9.json index 91ddda8579e..61076f701d0 100644 --- a/advisories/unreviewed/2023/11/GHSA-393j-fpg3-h6c9/GHSA-393j-fpg3-h6c9.json +++ b/advisories/unreviewed/2023/11/GHSA-393j-fpg3-h6c9/GHSA-393j-fpg3-h6c9.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-393j-fpg3-h6c9", - "modified": "2023-11-10T06:30:18Z", + "modified": "2025-02-27T00:30:25Z", "published": "2023-11-06T09:30:15Z", "aliases": [ "CVE-2023-45074" ], - "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Page Visit Counter Advanced Page Visit Counter – Most Wanted Analytics Plugin for WordPress allows SQL Injection.This issue affects Advanced Page Visit Counter – Most Wanted Analytics Plugin for WordPress: from n/a through 7.1.1.\n\n", + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Page Visit Counter Advanced Page Visit Counter – Most Wanted Analytics Plugin for WordPress allows SQL Injection.This issue affects Advanced Page Visit Counter – Most Wanted Analytics Plugin for WordPress: from n/a through 7.1.1.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/11/GHSA-fxgj-cfm7-w8hw/GHSA-fxgj-cfm7-w8hw.json b/advisories/unreviewed/2023/11/GHSA-fxgj-cfm7-w8hw/GHSA-fxgj-cfm7-w8hw.json index 365dbdb004e..420cfe16798 100644 --- a/advisories/unreviewed/2023/11/GHSA-fxgj-cfm7-w8hw/GHSA-fxgj-cfm7-w8hw.json +++ b/advisories/unreviewed/2023/11/GHSA-fxgj-cfm7-w8hw/GHSA-fxgj-cfm7-w8hw.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-fxgj-cfm7-w8hw", - "modified": "2024-10-10T18:31:07Z", + "modified": "2025-02-27T00:30:26Z", "published": "2023-11-09T15:30:30Z", "aliases": [ "CVE-2023-4612" ], - "details": "Improper Authentication vulnerability in Apereo CAS in jakarta.servlet.http.HttpServletRequest.getRemoteAddr method allows Multi-Factor Authentication bypass.This issue affects CAS: through 7.0.0-RC7. It is unknown whether in new versions the issue will be fixed. For the date of publication there is no patch, and the vendor does not treat it as a vulnerability.\n\n\n\n\n\n\n\n\n", + "details": "Improper Authentication vulnerability in Apereo CAS in jakarta.servlet.http.HttpServletRequest.getRemoteAddr method allows Multi-Factor Authentication bypass.This issue affects CAS: through 7.0.0-RC7. It is unknown whether in new versions the issue will be fixed. For the date of publication there is no patch, and the vendor does not treat it as a vulnerability.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/11/GHSA-h2w6-c2hx-7jcf/GHSA-h2w6-c2hx-7jcf.json b/advisories/unreviewed/2023/11/GHSA-h2w6-c2hx-7jcf/GHSA-h2w6-c2hx-7jcf.json index 68e46c19567..0e1c854e9c4 100644 --- a/advisories/unreviewed/2023/11/GHSA-h2w6-c2hx-7jcf/GHSA-h2w6-c2hx-7jcf.json +++ b/advisories/unreviewed/2023/11/GHSA-h2w6-c2hx-7jcf/GHSA-h2w6-c2hx-7jcf.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-h2w6-c2hx-7jcf", - "modified": "2023-11-10T06:30:18Z", + "modified": "2025-02-27T00:30:25Z", "published": "2023-11-06T09:30:15Z", "aliases": [ "CVE-2023-45069" ], - "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Video Gallery by Total-Soft Video Gallery – Best WordPress YouTube Gallery Plugin allows SQL Injection.This issue affects Video Gallery – Best WordPress YouTube Gallery Plugin: from n/a through 2.1.3.\n\n", + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Video Gallery by Total-Soft Video Gallery – Best WordPress YouTube Gallery Plugin allows SQL Injection.This issue affects Video Gallery – Best WordPress YouTube Gallery Plugin: from n/a through 2.1.3.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/11/GHSA-jc9g-7x7r-c8w7/GHSA-jc9g-7x7r-c8w7.json b/advisories/unreviewed/2023/11/GHSA-jc9g-7x7r-c8w7/GHSA-jc9g-7x7r-c8w7.json index 2fb80847852..2fe56d588ea 100644 --- a/advisories/unreviewed/2023/11/GHSA-jc9g-7x7r-c8w7/GHSA-jc9g-7x7r-c8w7.json +++ b/advisories/unreviewed/2023/11/GHSA-jc9g-7x7r-c8w7/GHSA-jc9g-7x7r-c8w7.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-jc9g-7x7r-c8w7", - "modified": "2023-11-14T18:30:22Z", + "modified": "2025-02-27T00:30:25Z", "published": "2023-11-06T12:30:24Z", "aliases": [ "CVE-2023-46823" ], - "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Avirtum ImageLinks Interactive Image Builder for WordPress allows SQL Injection.This issue affects ImageLinks Interactive Image Builder for WordPress: from n/a through 1.5.4.\n\n", + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Avirtum ImageLinks Interactive Image Builder for WordPress allows SQL Injection.This issue affects ImageLinks Interactive Image Builder for WordPress: from n/a through 1.5.4.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/11/GHSA-mvh5-v533-3v55/GHSA-mvh5-v533-3v55.json b/advisories/unreviewed/2023/11/GHSA-mvh5-v533-3v55/GHSA-mvh5-v533-3v55.json index 480b7defd98..2bece9e037f 100644 --- a/advisories/unreviewed/2023/11/GHSA-mvh5-v533-3v55/GHSA-mvh5-v533-3v55.json +++ b/advisories/unreviewed/2023/11/GHSA-mvh5-v533-3v55/GHSA-mvh5-v533-3v55.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-mvh5-v533-3v55", - "modified": "2023-11-10T06:30:18Z", + "modified": "2025-02-27T00:30:25Z", "published": "2023-11-06T09:30:15Z", "aliases": [ "CVE-2023-35911" ], - "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Creative Solutions Contact Form Generator : Creative form builder for WordPress allows SQL Injection.This issue affects Contact Form Generator : Creative form builder for WordPress: from n/a through 2.6.0.\n\n", + "details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Creative Solutions Contact Form Generator : Creative form builder for WordPress allows SQL Injection.This issue affects Contact Form Generator : Creative form builder for WordPress: from n/a through 2.6.0.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/11/GHSA-q8jx-8wr3-gv52/GHSA-q8jx-8wr3-gv52.json b/advisories/unreviewed/2023/11/GHSA-q8jx-8wr3-gv52/GHSA-q8jx-8wr3-gv52.json index 9758dbb35fe..d85685741ca 100644 --- a/advisories/unreviewed/2023/11/GHSA-q8jx-8wr3-gv52/GHSA-q8jx-8wr3-gv52.json +++ b/advisories/unreviewed/2023/11/GHSA-q8jx-8wr3-gv52/GHSA-q8jx-8wr3-gv52.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-q8jx-8wr3-gv52", - "modified": "2024-11-13T00:30:47Z", + "modified": "2025-02-27T00:30:25Z", "published": "2023-11-06T06:30:26Z", "aliases": [ "CVE-2023-4699" ], - "details": "Insufficient Verification of Data Authenticity vulnerability in Mitsubishi Electric Corporation MELSEC-F Series main modules and MELSEC iQ-F Series CPU modules allows a remote unauthenticated attacker to reset the memory of the products to factory default state and cause denial-of-service (DoS) condition on the products by sending specific packets.\n\n\n\n\n\n\n", + "details": "Insufficient Verification of Data Authenticity vulnerability in Mitsubishi Electric Corporation MELSEC-F Series main modules and MELSEC iQ-F Series CPU modules allows a remote unauthenticated attacker to reset the memory of the products to factory default state and cause denial-of-service (DoS) condition on the products by sending specific packets.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/11/GHSA-x748-g8vm-gmhw/GHSA-x748-g8vm-gmhw.json b/advisories/unreviewed/2023/11/GHSA-x748-g8vm-gmhw/GHSA-x748-g8vm-gmhw.json index ab02fdd955b..62a4f6076f2 100644 --- a/advisories/unreviewed/2023/11/GHSA-x748-g8vm-gmhw/GHSA-x748-g8vm-gmhw.json +++ b/advisories/unreviewed/2023/11/GHSA-x748-g8vm-gmhw/GHSA-x748-g8vm-gmhw.json @@ -27,6 +27,7 @@ "database_specific": { "cwe_ids": [ "CWE-284", + "CWE-683", "CWE-863" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/05/GHSA-657j-69g5-mr77/GHSA-657j-69g5-mr77.json b/advisories/unreviewed/2024/05/GHSA-657j-69g5-mr77/GHSA-657j-69g5-mr77.json index a319d59fdf3..db67ba35711 100644 --- a/advisories/unreviewed/2024/05/GHSA-657j-69g5-mr77/GHSA-657j-69g5-mr77.json +++ b/advisories/unreviewed/2024/05/GHSA-657j-69g5-mr77/GHSA-657j-69g5-mr77.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-657j-69g5-mr77", - "modified": "2024-05-23T06:30:45Z", + "modified": "2025-02-27T00:30:26Z", "published": "2024-05-23T06:30:45Z", "aliases": [ "CVE-2024-5235" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/05/GHSA-jhvx-96xq-qggm/GHSA-jhvx-96xq-qggm.json b/advisories/unreviewed/2024/05/GHSA-jhvx-96xq-qggm/GHSA-jhvx-96xq-qggm.json index c63535f860b..8e0431c66a7 100644 --- a/advisories/unreviewed/2024/05/GHSA-jhvx-96xq-qggm/GHSA-jhvx-96xq-qggm.json +++ b/advisories/unreviewed/2024/05/GHSA-jhvx-96xq-qggm/GHSA-jhvx-96xq-qggm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jhvx-96xq-qggm", - "modified": "2024-05-23T06:30:45Z", + "modified": "2025-02-27T00:30:26Z", "published": "2024-05-23T06:30:45Z", "aliases": [ "CVE-2024-5236" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2025/02/GHSA-659h-jrcq-w3wg/GHSA-659h-jrcq-w3wg.json b/advisories/unreviewed/2025/02/GHSA-659h-jrcq-w3wg/GHSA-659h-jrcq-w3wg.json new file mode 100644 index 00000000000..cf9109520ba --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-659h-jrcq-w3wg/GHSA-659h-jrcq-w3wg.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-659h-jrcq-w3wg", + "modified": "2025-02-27T00:30:27Z", + "published": "2025-02-27T00:30:27Z", + "aliases": [ + "CVE-2025-1460" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1460" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T23:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-6pc8-5263-hvgq/GHSA-6pc8-5263-hvgq.json b/advisories/unreviewed/2025/02/GHSA-6pc8-5263-hvgq/GHSA-6pc8-5263-hvgq.json new file mode 100644 index 00000000000..98006197d64 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-6pc8-5263-hvgq/GHSA-6pc8-5263-hvgq.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6pc8-5263-hvgq", + "modified": "2025-02-27T00:30:27Z", + "published": "2025-02-27T00:30:26Z", + "aliases": [ + "CVE-2024-55581" + ], + "details": "When AdaCore Ada Web Server 25.0.0 is linked with GnuTLS, the default behaviour of AWS.Client is vulnerable to a man-in-the-middle attack because of lack of verification of an HTTPS server's certificate (unless the using program specifies a TLS configuration).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55581" + }, + { + "type": "WEB", + "url": "https://docs.adacore.com/corp/security-advisories/SEC.AWS-0056-v1.pdf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T22:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-7xmw-644w-wp3m/GHSA-7xmw-644w-wp3m.json b/advisories/unreviewed/2025/02/GHSA-7xmw-644w-wp3m/GHSA-7xmw-644w-wp3m.json new file mode 100644 index 00000000000..556ac2b734f --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-7xmw-644w-wp3m/GHSA-7xmw-644w-wp3m.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7xmw-644w-wp3m", + "modified": "2025-02-27T00:30:27Z", + "published": "2025-02-27T00:30:27Z", + "aliases": [ + "CVE-2024-53573" + ], + "details": "Unifiedtransform v2.X is vulnerable to Incorrect Access Control. Unauthorized users can access and manipulate endpoints intended exclusively for administrative use. This issue specifically affects teacher/edit/{id}.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53573" + }, + { + "type": "WEB", + "url": "https://drive.google.com/file/d/14Or6QIpOeLEqdFm1mwxdE_NNCOwMmcFc/view" + }, + { + "type": "WEB", + "url": "https://www.getastra.com/blog/vulnerability/improper-access-control-in-school-management-system-unifiedtransform" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T22:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-mjhr-3845-j2r5/GHSA-mjhr-3845-j2r5.json b/advisories/unreviewed/2025/02/GHSA-mjhr-3845-j2r5/GHSA-mjhr-3845-j2r5.json new file mode 100644 index 00000000000..722fe533efb --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-mjhr-3845-j2r5/GHSA-mjhr-3845-j2r5.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mjhr-3845-j2r5", + "modified": "2025-02-27T00:30:27Z", + "published": "2025-02-27T00:30:27Z", + "aliases": [ + "CVE-2024-57040" + ], + "details": "TL-WR845N(UN)_V4_200909 and TL-WR845N(UN)_V4_190219 was discovered to contain a hardcoded password for the root account which can be obtained via a brute force attack.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57040" + }, + { + "type": "WEB", + "url": "https://security.iiita.ac.in/iot/hashed_password.pdf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T22:15:14Z" + } +} \ No newline at end of file