From 154a9443c47369b0ede37b113f2b765a4f4b2c92 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 16 May 2025 21:46:47 +0000 Subject: [PATCH] Publish GHSA-7cfr-5cjf-32p4 --- .../GHSA-7cfr-5cjf-32p4.json | 37 ++++++++++++++++--- 1 file changed, 31 insertions(+), 6 deletions(-) rename advisories/{unreviewed => github-reviewed}/2025/05/GHSA-7cfr-5cjf-32p4/GHSA-7cfr-5cjf-32p4.json (68%) diff --git a/advisories/unreviewed/2025/05/GHSA-7cfr-5cjf-32p4/GHSA-7cfr-5cjf-32p4.json b/advisories/github-reviewed/2025/05/GHSA-7cfr-5cjf-32p4/GHSA-7cfr-5cjf-32p4.json similarity index 68% rename from advisories/unreviewed/2025/05/GHSA-7cfr-5cjf-32p4/GHSA-7cfr-5cjf-32p4.json rename to advisories/github-reviewed/2025/05/GHSA-7cfr-5cjf-32p4/GHSA-7cfr-5cjf-32p4.json index 767b311fba6..a881f2d96d7 100644 --- a/advisories/unreviewed/2025/05/GHSA-7cfr-5cjf-32p4/GHSA-7cfr-5cjf-32p4.json +++ b/advisories/github-reviewed/2025/05/GHSA-7cfr-5cjf-32p4/GHSA-7cfr-5cjf-32p4.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-7cfr-5cjf-32p4", - "modified": "2025-05-16T06:30:24Z", + "modified": "2025-05-16T21:45:31Z", "published": "2025-05-16T06:30:24Z", "aliases": [ "CVE-2025-4759" ], + "summary": "lockfile-lint-api Vulnerable to Incorrect Behavior Order", "details": "Versions of the package lockfile-lint-api before 5.9.2 are vulnerable to Incorrect Behavior Order: Early Validation via the resolved attribute of the package URL validation which can be bypassed by extending the package name allowing an attacker to install other npm packages than the intended one.", "severity": [ { @@ -14,10 +15,30 @@ }, { "type": "CVSS_V4", - "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:L/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:L/E:P" + } + ], + "affected": [ + { + "package": { + "ecosystem": "npm", + "name": "lockfile-lint-api" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "5.9.2" + } + ] + } + ] } ], - "affected": [], "references": [ { "type": "ADVISORY", @@ -35,9 +56,13 @@ "type": "WEB", "url": "https://gist.github.com/Xavier59/881aef04940970dc3e738dcbff64151f" }, + { + "type": "PACKAGE", + "url": "https://github.com/lirantal/lockfile-lint" + }, { "type": "WEB", - "url": "https://github.com/lirantal/lockfile-lint/blob/89b5cad028df4d77bab2b73ac93bc61e392668ab/packages/lockfile-lint-api/src/validators/ValidatePackageNames.js%23L51-L63" + "url": "https://github.com/lirantal/lockfile-lint/blob/89b5cad028df4d77bab2b73ac93bc61e392668ab/packages/lockfile-lint-api/src/validators/ValidatePackageNames.js#L51-L63" }, { "type": "WEB", @@ -49,8 +74,8 @@ "CWE-179" ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2025-05-16T21:45:31Z", "nvd_published_at": "2025-05-16T05:15:38Z" } } \ No newline at end of file