Publish Advisories

GHSA-7hfw-w75q-mqr2
GHSA-j2jg-m77h-283j
GHSA-m7q8-qfg8-w5hc
GHSA-qj7j-xm3v-qchm
GHSA-4rm9-7435-8cv9
GHSA-55m8-7g34-6frr
GHSA-xgqr-2mpj-w9qv
GHSA-mm53-x3wx-jgr2
GHSA-58rr-37rr-r6h5
GHSA-jqrq-gqwg-r8r5
GHSA-j85x-732x-xq8q
GHSA-2x8c-95vh-gfv4
GHSA-h4hx-5g7m-p3hc
GHSA-583r-5m7h-h9qf
GHSA-7928-xx56-23g7
GHSA-794f-v4rm-x7r5
GHSA-99q6-5j8j-4wv8
GHSA-mqx7-237c-8fxx
GHSA-mw98-rfjc-q8w9
GHSA-r77m-qpx3-mpgm
GHSA-rgw7-rhh8-mgf9
GHSA-wp4q-9jq4-gv74
This commit is contained in:
advisory-database[bot]
2025-04-24 21:33:07 +00:00
parent cf2b65bda6
commit 1aeb8fe37a
22 changed files with 332 additions and 15 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7hfw-w75q-mqr2",
"modified": "2022-12-02T18:30:28Z",
"modified": "2025-04-24T21:31:43Z",
"published": "2022-11-30T15:30:27Z",
"aliases": [
"CVE-2022-38802"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j2jg-m77h-283j",
"modified": "2022-12-02T18:30:28Z",
"modified": "2025-04-24T21:31:43Z",
"published": "2022-11-30T15:30:27Z",
"aliases": [
"CVE-2022-38803"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m7q8-qfg8-w5hc",
"modified": "2022-12-02T15:30:25Z",
"modified": "2025-04-24T21:31:43Z",
"published": "2022-11-30T15:30:27Z",
"aliases": [
"CVE-2022-38801"
@@ -34,7 +34,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-668"
"CWE-668",
"CWE-732"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4rm9-7435-8cv9",
"modified": "2022-12-05T21:30:42Z",
"modified": "2025-04-24T21:31:44Z",
"published": "2022-12-02T18:30:28Z",
"aliases": [
"CVE-2022-45480"
@@ -25,7 +25,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-78"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xgqr-2mpj-w9qv",
"modified": "2024-04-04T05:43:55Z",
"modified": "2025-04-24T21:31:46Z",
"published": "2023-07-06T21:14:58Z",
"aliases": [
"CVE-2023-2745"
@@ -31,6 +31,10 @@
"type": "WEB",
"url": "https://wordpress.org/news/2023/05/wordpress-6-2-1-maintenance-security-release"
},
{
"type": "WEB",
"url": "https://www.exploit-db.com/exploits/52274"
},
{
"type": "WEB",
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/edcf46b6-368e-49c0-b2c3-99bf6e2d358f?source=cve"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mm53-x3wx-jgr2",
"modified": "2025-04-23T18:30:45Z",
"modified": "2025-04-24T21:31:47Z",
"published": "2023-08-28T21:31:06Z",
"aliases": [
"CVE-2023-39810"
@@ -38,6 +38,10 @@
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2025/04/23/3"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2025/04/24/2"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-58rr-37rr-r6h5",
"modified": "2023-11-14T21:30:54Z",
"modified": "2025-04-24T21:31:47Z",
"published": "2023-11-14T21:30:54Z",
"aliases": [
"CVE-2023-41425"
@@ -23,6 +23,14 @@
"type": "WEB",
"url": "https://gist.github.com/prodigiousMind/fc69a79629c4ba9ee88a7ad526043413"
},
{
"type": "WEB",
"url": "https://packetstorm.news/files/id/190575"
},
{
"type": "WEB",
"url": "https://www.exploit-db.com/exploits/52271"
},
{
"type": "WEB",
"url": "http://wondercms.com"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jqrq-gqwg-r8r5",
"modified": "2024-03-01T06:33:06Z",
"modified": "2025-04-24T21:31:47Z",
"published": "2024-02-13T18:38:23Z",
"aliases": [
"CVE-2024-21338"
@@ -26,6 +26,14 @@
{
"type": "WEB",
"url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21338"
},
{
"type": "WEB",
"url": "https://packetstorm.news/files/id/190586"
},
{
"type": "WEB",
"url": "https://www.exploit-db.com/exploits/52275"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j85x-732x-xq8q",
"modified": "2024-07-03T18:44:14Z",
"modified": "2025-04-24T21:31:47Z",
"published": "2024-06-06T21:30:38Z",
"aliases": [
"CVE-2024-32752"
@@ -30,6 +30,10 @@
{
"type": "WEB",
"url": "https://www.johnsoncontrols.com/-/media/jci/cyber-solutions/product-security-advisories/2024/jci-psa-2024-06.pdf"
},
{
"type": "WEB",
"url": "https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2x8c-95vh-gfv4",
"modified": "2024-07-30T03:30:51Z",
"modified": "2025-04-24T21:31:48Z",
"published": "2024-07-01T15:32:33Z",
"aliases": [
"CVE-2024-6387"
@@ -103,6 +103,10 @@
"type": "WEB",
"url": "https://www.arista.com/en/support/advisories-notices/security-advisory/19904-security-advisory-0100"
},
{
"type": "WEB",
"url": "https://www.exploit-db.com/exploits/52269"
},
{
"type": "WEB",
"url": "https://www.freebsd.org/security/advisories/FreeBSD-SA-24:04.openssh.asc"
@@ -127,6 +131,10 @@
"type": "WEB",
"url": "https://www.theregister.com/2024/07/01/regresshion_openssh"
},
{
"type": "WEB",
"url": "https://www.vicarius.io/vsociety/posts/regresshion-an-openssh-regression-error-cve-2024-6387"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:4340"
@@ -207,6 +215,10 @@
"type": "WEB",
"url": "https://news.ycombinator.com/item?id=40843778"
},
{
"type": "WEB",
"url": "https://packetstorm.news/files/id/190587"
},
{
"type": "WEB",
"url": "http://seclists.org/fulldisclosure/2024/Jul/18"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h4hx-5g7m-p3hc",
"modified": "2024-12-12T03:33:05Z",
"modified": "2025-04-24T21:31:47Z",
"published": "2024-12-12T03:33:05Z",
"aliases": [
"CVE-2024-49138"
@@ -22,6 +22,14 @@
{
"type": "WEB",
"url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49138"
},
{
"type": "WEB",
"url": "https://packetstorm.news/files/id/190585"
},
{
"type": "WEB",
"url": "https://www.exploit-db.com/exploits/52270"
}
],
"database_specific": {
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-583r-5m7h-h9qf",
"modified": "2025-04-24T21:31:48Z",
"published": "2025-04-24T21:31:48Z",
"aliases": [
"CVE-2024-30127"
],
"details": "Missing \"no cache\" headers in HCL Leap permits sensitive data to be cached.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30127"
},
{
"type": "WEB",
"url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0119900"
}
],
"database_specific": {
"cwe_ids": [
"CWE-524"
],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-24T21:15:21Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7928-xx56-23g7",
"modified": "2025-04-24T21:31:47Z",
"published": "2025-04-24T21:31:47Z",
"aliases": [
"CVE-2022-44759"
],
"details": "Improper sanitization of SVG files in HCL Leap\nallows client-side script injection in deployed applications.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-44759"
},
{
"type": "WEB",
"url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0119900"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-24T21:15:20Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-794f-v4rm-x7r5",
"modified": "2025-04-11T09:30:24Z",
"modified": "2025-04-24T21:31:47Z",
"published": "2025-04-11T09:30:24Z",
"aliases": [
"CVE-2025-3512"
@@ -22,6 +22,18 @@
{
"type": "WEB",
"url": "https://codereview.qt-project.org/c/qt/qtbase/+/635546"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2025/04/24/4"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2025/04/24/5"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2025/04/24/6"
}
],
"database_specific": {
@@ -0,0 +1,33 @@
{
"schema_version": "1.4.0",
"id": "GHSA-99q6-5j8j-4wv8",
"modified": "2025-04-24T21:31:48Z",
"published": "2025-04-24T21:31:48Z",
"aliases": [
"CVE-2025-29529"
],
"details": "ITC Systems Multiplan/Matrix OneCard platform v3.7.4.1002 was discovered to contain a SQL injection vulnerability via the component Forgotpassword.aspx.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29529"
},
{
"type": "WEB",
"url": "https://github.com/chamilo/chamilo-lms/commit/beb07770d674fcc9db6df0e59aab107678c28682"
},
{
"type": "WEB",
"url": "https://github.com/Yoshik0xF6/CVE-2025-29529"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-24T21:15:24Z"
}
}
@@ -0,0 +1,40 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mqx7-237c-8fxx",
"modified": "2025-04-24T21:31:47Z",
"published": "2025-04-24T21:31:47Z",
"aliases": [
"CVE-2025-26382"
],
"details": "Under certain circumstances the iSTAR Configuration Utility (ICU) tool could have a buffer overflow issue",
"severity": [
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26382"
},
{
"type": "WEB",
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-25-114-05"
},
{
"type": "WEB",
"url": "https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories"
}
],
"database_specific": {
"cwe_ids": [
"CWE-121"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-24T20:15:31Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mw98-rfjc-q8w9",
"modified": "2025-04-24T21:31:47Z",
"published": "2025-04-24T21:31:47Z",
"aliases": [
"CVE-2022-44760"
],
"details": "Unsafe default file type filter policy in HCL\nLeap allows execution of unsafe JavaScript in deployed applications.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-44760"
},
{
"type": "WEB",
"url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0119900"
}
],
"database_specific": {
"cwe_ids": [
"CWE-434"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-24T21:15:20Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r77m-qpx3-mpgm",
"modified": "2025-04-24T21:31:47Z",
"published": "2025-04-24T21:31:47Z",
"aliases": [
"CVE-2023-37516"
],
"details": "Missing \"no cache\" headers in HCL Leap permits user directory information to be cached.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37516"
},
{
"type": "WEB",
"url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0119900"
}
],
"database_specific": {
"cwe_ids": [
"CWE-524"
],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-24T21:15:21Z"
}
}

Some files were not shown because too many files have changed in this diff Show More