From 1aeb8fe37a7b70f5bc688a955d5825b5c33003a9 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 24 Apr 2025 21:33:07 +0000 Subject: [PATCH] Publish Advisories GHSA-7hfw-w75q-mqr2 GHSA-j2jg-m77h-283j GHSA-m7q8-qfg8-w5hc GHSA-qj7j-xm3v-qchm GHSA-4rm9-7435-8cv9 GHSA-55m8-7g34-6frr GHSA-xgqr-2mpj-w9qv GHSA-mm53-x3wx-jgr2 GHSA-58rr-37rr-r6h5 GHSA-jqrq-gqwg-r8r5 GHSA-j85x-732x-xq8q GHSA-2x8c-95vh-gfv4 GHSA-h4hx-5g7m-p3hc GHSA-583r-5m7h-h9qf GHSA-7928-xx56-23g7 GHSA-794f-v4rm-x7r5 GHSA-99q6-5j8j-4wv8 GHSA-mqx7-237c-8fxx GHSA-mw98-rfjc-q8w9 GHSA-r77m-qpx3-mpgm GHSA-rgw7-rhh8-mgf9 GHSA-wp4q-9jq4-gv74 --- .../GHSA-7hfw-w75q-mqr2.json | 2 +- .../GHSA-j2jg-m77h-283j.json | 2 +- .../GHSA-m7q8-qfg8-w5hc.json | 2 +- .../GHSA-qj7j-xm3v-qchm.json | 3 +- .../GHSA-4rm9-7435-8cv9.json | 2 +- .../GHSA-55m8-7g34-6frr.json | 4 +- .../GHSA-xgqr-2mpj-w9qv.json | 6 ++- .../GHSA-mm53-x3wx-jgr2.json | 6 ++- .../GHSA-58rr-37rr-r6h5.json | 10 ++++- .../GHSA-jqrq-gqwg-r8r5.json | 10 ++++- .../GHSA-j85x-732x-xq8q.json | 6 ++- .../GHSA-2x8c-95vh-gfv4.json | 14 ++++++- .../GHSA-h4hx-5g7m-p3hc.json | 10 ++++- .../GHSA-583r-5m7h-h9qf.json | 36 +++++++++++++++++ .../GHSA-7928-xx56-23g7.json | 36 +++++++++++++++++ .../GHSA-794f-v4rm-x7r5.json | 14 ++++++- .../GHSA-99q6-5j8j-4wv8.json | 33 +++++++++++++++ .../GHSA-mqx7-237c-8fxx.json | 40 +++++++++++++++++++ .../GHSA-mw98-rfjc-q8w9.json | 36 +++++++++++++++++ .../GHSA-r77m-qpx3-mpgm.json | 36 +++++++++++++++++ .../GHSA-rgw7-rhh8-mgf9.json | 33 +++++++++++++++ .../GHSA-wp4q-9jq4-gv74.json | 6 ++- 22 files changed, 332 insertions(+), 15 deletions(-) create mode 100644 advisories/unreviewed/2025/04/GHSA-583r-5m7h-h9qf/GHSA-583r-5m7h-h9qf.json create mode 100644 advisories/unreviewed/2025/04/GHSA-7928-xx56-23g7/GHSA-7928-xx56-23g7.json create mode 100644 advisories/unreviewed/2025/04/GHSA-99q6-5j8j-4wv8/GHSA-99q6-5j8j-4wv8.json create mode 100644 advisories/unreviewed/2025/04/GHSA-mqx7-237c-8fxx/GHSA-mqx7-237c-8fxx.json create mode 100644 advisories/unreviewed/2025/04/GHSA-mw98-rfjc-q8w9/GHSA-mw98-rfjc-q8w9.json create mode 100644 advisories/unreviewed/2025/04/GHSA-r77m-qpx3-mpgm/GHSA-r77m-qpx3-mpgm.json create mode 100644 advisories/unreviewed/2025/04/GHSA-rgw7-rhh8-mgf9/GHSA-rgw7-rhh8-mgf9.json diff --git a/advisories/unreviewed/2022/11/GHSA-7hfw-w75q-mqr2/GHSA-7hfw-w75q-mqr2.json b/advisories/unreviewed/2022/11/GHSA-7hfw-w75q-mqr2/GHSA-7hfw-w75q-mqr2.json index 4867675401c..67d1db1f421 100644 --- a/advisories/unreviewed/2022/11/GHSA-7hfw-w75q-mqr2/GHSA-7hfw-w75q-mqr2.json +++ b/advisories/unreviewed/2022/11/GHSA-7hfw-w75q-mqr2/GHSA-7hfw-w75q-mqr2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7hfw-w75q-mqr2", - "modified": "2022-12-02T18:30:28Z", + "modified": "2025-04-24T21:31:43Z", "published": "2022-11-30T15:30:27Z", "aliases": [ "CVE-2022-38802" diff --git a/advisories/unreviewed/2022/11/GHSA-j2jg-m77h-283j/GHSA-j2jg-m77h-283j.json b/advisories/unreviewed/2022/11/GHSA-j2jg-m77h-283j/GHSA-j2jg-m77h-283j.json index 9346d92eec9..cb226cc0a42 100644 --- a/advisories/unreviewed/2022/11/GHSA-j2jg-m77h-283j/GHSA-j2jg-m77h-283j.json +++ b/advisories/unreviewed/2022/11/GHSA-j2jg-m77h-283j/GHSA-j2jg-m77h-283j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j2jg-m77h-283j", - "modified": "2022-12-02T18:30:28Z", + "modified": "2025-04-24T21:31:43Z", "published": "2022-11-30T15:30:27Z", "aliases": [ "CVE-2022-38803" diff --git a/advisories/unreviewed/2022/11/GHSA-m7q8-qfg8-w5hc/GHSA-m7q8-qfg8-w5hc.json b/advisories/unreviewed/2022/11/GHSA-m7q8-qfg8-w5hc/GHSA-m7q8-qfg8-w5hc.json index 7b292071341..7f5403b8a98 100644 --- a/advisories/unreviewed/2022/11/GHSA-m7q8-qfg8-w5hc/GHSA-m7q8-qfg8-w5hc.json +++ b/advisories/unreviewed/2022/11/GHSA-m7q8-qfg8-w5hc/GHSA-m7q8-qfg8-w5hc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m7q8-qfg8-w5hc", - "modified": "2022-12-02T15:30:25Z", + "modified": "2025-04-24T21:31:43Z", "published": "2022-11-30T15:30:27Z", "aliases": [ "CVE-2022-38801" diff --git a/advisories/unreviewed/2022/11/GHSA-qj7j-xm3v-qchm/GHSA-qj7j-xm3v-qchm.json b/advisories/unreviewed/2022/11/GHSA-qj7j-xm3v-qchm/GHSA-qj7j-xm3v-qchm.json index 309934e4245..2d3f9eba0e3 100644 --- a/advisories/unreviewed/2022/11/GHSA-qj7j-xm3v-qchm/GHSA-qj7j-xm3v-qchm.json +++ b/advisories/unreviewed/2022/11/GHSA-qj7j-xm3v-qchm/GHSA-qj7j-xm3v-qchm.json @@ -34,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-668" + "CWE-668", + "CWE-732" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/12/GHSA-4rm9-7435-8cv9/GHSA-4rm9-7435-8cv9.json b/advisories/unreviewed/2022/12/GHSA-4rm9-7435-8cv9/GHSA-4rm9-7435-8cv9.json index 4c50ca06d2d..6f30fd9e395 100644 --- a/advisories/unreviewed/2022/12/GHSA-4rm9-7435-8cv9/GHSA-4rm9-7435-8cv9.json +++ b/advisories/unreviewed/2022/12/GHSA-4rm9-7435-8cv9/GHSA-4rm9-7435-8cv9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4rm9-7435-8cv9", - "modified": "2022-12-05T21:30:42Z", + "modified": "2025-04-24T21:31:44Z", "published": "2022-12-02T18:30:28Z", "aliases": [ "CVE-2022-45480" diff --git a/advisories/unreviewed/2022/12/GHSA-55m8-7g34-6frr/GHSA-55m8-7g34-6frr.json b/advisories/unreviewed/2022/12/GHSA-55m8-7g34-6frr/GHSA-55m8-7g34-6frr.json index c1486b39e89..de5d6916f25 100644 --- a/advisories/unreviewed/2022/12/GHSA-55m8-7g34-6frr/GHSA-55m8-7g34-6frr.json +++ b/advisories/unreviewed/2022/12/GHSA-55m8-7g34-6frr/GHSA-55m8-7g34-6frr.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-78" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/07/GHSA-xgqr-2mpj-w9qv/GHSA-xgqr-2mpj-w9qv.json b/advisories/unreviewed/2023/07/GHSA-xgqr-2mpj-w9qv/GHSA-xgqr-2mpj-w9qv.json index 5ca87ff5429..1a5ebfacf0c 100644 --- a/advisories/unreviewed/2023/07/GHSA-xgqr-2mpj-w9qv/GHSA-xgqr-2mpj-w9qv.json +++ b/advisories/unreviewed/2023/07/GHSA-xgqr-2mpj-w9qv/GHSA-xgqr-2mpj-w9qv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xgqr-2mpj-w9qv", - "modified": "2024-04-04T05:43:55Z", + "modified": "2025-04-24T21:31:46Z", "published": "2023-07-06T21:14:58Z", "aliases": [ "CVE-2023-2745" @@ -31,6 +31,10 @@ "type": "WEB", "url": "https://wordpress.org/news/2023/05/wordpress-6-2-1-maintenance-security-release" }, + { + "type": "WEB", + "url": "https://www.exploit-db.com/exploits/52274" + }, { "type": "WEB", "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/edcf46b6-368e-49c0-b2c3-99bf6e2d358f?source=cve" diff --git a/advisories/unreviewed/2023/08/GHSA-mm53-x3wx-jgr2/GHSA-mm53-x3wx-jgr2.json b/advisories/unreviewed/2023/08/GHSA-mm53-x3wx-jgr2/GHSA-mm53-x3wx-jgr2.json index e616da77fda..4fb4ce072ba 100644 --- a/advisories/unreviewed/2023/08/GHSA-mm53-x3wx-jgr2/GHSA-mm53-x3wx-jgr2.json +++ b/advisories/unreviewed/2023/08/GHSA-mm53-x3wx-jgr2/GHSA-mm53-x3wx-jgr2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mm53-x3wx-jgr2", - "modified": "2025-04-23T18:30:45Z", + "modified": "2025-04-24T21:31:47Z", "published": "2023-08-28T21:31:06Z", "aliases": [ "CVE-2023-39810" @@ -38,6 +38,10 @@ { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2025/04/23/3" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/04/24/2" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/11/GHSA-58rr-37rr-r6h5/GHSA-58rr-37rr-r6h5.json b/advisories/unreviewed/2023/11/GHSA-58rr-37rr-r6h5/GHSA-58rr-37rr-r6h5.json index 3f08d88278d..9fd641dd123 100644 --- a/advisories/unreviewed/2023/11/GHSA-58rr-37rr-r6h5/GHSA-58rr-37rr-r6h5.json +++ b/advisories/unreviewed/2023/11/GHSA-58rr-37rr-r6h5/GHSA-58rr-37rr-r6h5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-58rr-37rr-r6h5", - "modified": "2023-11-14T21:30:54Z", + "modified": "2025-04-24T21:31:47Z", "published": "2023-11-14T21:30:54Z", "aliases": [ "CVE-2023-41425" @@ -23,6 +23,14 @@ "type": "WEB", "url": "https://gist.github.com/prodigiousMind/fc69a79629c4ba9ee88a7ad526043413" }, + { + "type": "WEB", + "url": "https://packetstorm.news/files/id/190575" + }, + { + "type": "WEB", + "url": "https://www.exploit-db.com/exploits/52271" + }, { "type": "WEB", "url": "http://wondercms.com" diff --git a/advisories/unreviewed/2024/02/GHSA-jqrq-gqwg-r8r5/GHSA-jqrq-gqwg-r8r5.json b/advisories/unreviewed/2024/02/GHSA-jqrq-gqwg-r8r5/GHSA-jqrq-gqwg-r8r5.json index 52ec029d1c7..c216ae117b8 100644 --- a/advisories/unreviewed/2024/02/GHSA-jqrq-gqwg-r8r5/GHSA-jqrq-gqwg-r8r5.json +++ b/advisories/unreviewed/2024/02/GHSA-jqrq-gqwg-r8r5/GHSA-jqrq-gqwg-r8r5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jqrq-gqwg-r8r5", - "modified": "2024-03-01T06:33:06Z", + "modified": "2025-04-24T21:31:47Z", "published": "2024-02-13T18:38:23Z", "aliases": [ "CVE-2024-21338" @@ -26,6 +26,14 @@ { "type": "WEB", "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21338" + }, + { + "type": "WEB", + "url": "https://packetstorm.news/files/id/190586" + }, + { + "type": "WEB", + "url": "https://www.exploit-db.com/exploits/52275" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/06/GHSA-j85x-732x-xq8q/GHSA-j85x-732x-xq8q.json b/advisories/unreviewed/2024/06/GHSA-j85x-732x-xq8q/GHSA-j85x-732x-xq8q.json index fd9620dbcc5..cfc9dd68834 100644 --- a/advisories/unreviewed/2024/06/GHSA-j85x-732x-xq8q/GHSA-j85x-732x-xq8q.json +++ b/advisories/unreviewed/2024/06/GHSA-j85x-732x-xq8q/GHSA-j85x-732x-xq8q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j85x-732x-xq8q", - "modified": "2024-07-03T18:44:14Z", + "modified": "2025-04-24T21:31:47Z", "published": "2024-06-06T21:30:38Z", "aliases": [ "CVE-2024-32752" @@ -30,6 +30,10 @@ { "type": "WEB", "url": "https://www.johnsoncontrols.com/-/media/jci/cyber-solutions/product-security-advisories/2024/jci-psa-2024-06.pdf" + }, + { + "type": "WEB", + "url": "https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/07/GHSA-2x8c-95vh-gfv4/GHSA-2x8c-95vh-gfv4.json b/advisories/unreviewed/2024/07/GHSA-2x8c-95vh-gfv4/GHSA-2x8c-95vh-gfv4.json index ff343e564e0..c0c24e41532 100644 --- a/advisories/unreviewed/2024/07/GHSA-2x8c-95vh-gfv4/GHSA-2x8c-95vh-gfv4.json +++ b/advisories/unreviewed/2024/07/GHSA-2x8c-95vh-gfv4/GHSA-2x8c-95vh-gfv4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2x8c-95vh-gfv4", - "modified": "2024-07-30T03:30:51Z", + "modified": "2025-04-24T21:31:48Z", "published": "2024-07-01T15:32:33Z", "aliases": [ "CVE-2024-6387" @@ -103,6 +103,10 @@ "type": "WEB", "url": "https://www.arista.com/en/support/advisories-notices/security-advisory/19904-security-advisory-0100" }, + { + "type": "WEB", + "url": "https://www.exploit-db.com/exploits/52269" + }, { "type": "WEB", "url": "https://www.freebsd.org/security/advisories/FreeBSD-SA-24:04.openssh.asc" @@ -127,6 +131,10 @@ "type": "WEB", "url": "https://www.theregister.com/2024/07/01/regresshion_openssh" }, + { + "type": "WEB", + "url": "https://www.vicarius.io/vsociety/posts/regresshion-an-openssh-regression-error-cve-2024-6387" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:4340" @@ -207,6 +215,10 @@ "type": "WEB", "url": "https://news.ycombinator.com/item?id=40843778" }, + { + "type": "WEB", + "url": "https://packetstorm.news/files/id/190587" + }, { "type": "WEB", "url": "http://seclists.org/fulldisclosure/2024/Jul/18" diff --git a/advisories/unreviewed/2024/12/GHSA-h4hx-5g7m-p3hc/GHSA-h4hx-5g7m-p3hc.json b/advisories/unreviewed/2024/12/GHSA-h4hx-5g7m-p3hc/GHSA-h4hx-5g7m-p3hc.json index d1f74b6debe..86792390a62 100644 --- a/advisories/unreviewed/2024/12/GHSA-h4hx-5g7m-p3hc/GHSA-h4hx-5g7m-p3hc.json +++ b/advisories/unreviewed/2024/12/GHSA-h4hx-5g7m-p3hc/GHSA-h4hx-5g7m-p3hc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h4hx-5g7m-p3hc", - "modified": "2024-12-12T03:33:05Z", + "modified": "2025-04-24T21:31:47Z", "published": "2024-12-12T03:33:05Z", "aliases": [ "CVE-2024-49138" @@ -22,6 +22,14 @@ { "type": "WEB", "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49138" + }, + { + "type": "WEB", + "url": "https://packetstorm.news/files/id/190585" + }, + { + "type": "WEB", + "url": "https://www.exploit-db.com/exploits/52270" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/04/GHSA-583r-5m7h-h9qf/GHSA-583r-5m7h-h9qf.json b/advisories/unreviewed/2025/04/GHSA-583r-5m7h-h9qf/GHSA-583r-5m7h-h9qf.json new file mode 100644 index 00000000000..443aea5ce4e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-583r-5m7h-h9qf/GHSA-583r-5m7h-h9qf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-583r-5m7h-h9qf", + "modified": "2025-04-24T21:31:48Z", + "published": "2025-04-24T21:31:48Z", + "aliases": [ + "CVE-2024-30127" + ], + "details": "Missing \"no cache\" headers in HCL Leap permits sensitive data to be cached.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-30127" + }, + { + "type": "WEB", + "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0119900" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-524" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-24T21:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7928-xx56-23g7/GHSA-7928-xx56-23g7.json b/advisories/unreviewed/2025/04/GHSA-7928-xx56-23g7/GHSA-7928-xx56-23g7.json new file mode 100644 index 00000000000..cb37d118ac1 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7928-xx56-23g7/GHSA-7928-xx56-23g7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7928-xx56-23g7", + "modified": "2025-04-24T21:31:47Z", + "published": "2025-04-24T21:31:47Z", + "aliases": [ + "CVE-2022-44759" + ], + "details": "Improper sanitization of SVG files in HCL Leap\nallows client-side script injection in deployed applications.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-44759" + }, + { + "type": "WEB", + "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0119900" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-24T21:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-794f-v4rm-x7r5/GHSA-794f-v4rm-x7r5.json b/advisories/unreviewed/2025/04/GHSA-794f-v4rm-x7r5/GHSA-794f-v4rm-x7r5.json index 33b78de6485..f3568f56239 100644 --- a/advisories/unreviewed/2025/04/GHSA-794f-v4rm-x7r5/GHSA-794f-v4rm-x7r5.json +++ b/advisories/unreviewed/2025/04/GHSA-794f-v4rm-x7r5/GHSA-794f-v4rm-x7r5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-794f-v4rm-x7r5", - "modified": "2025-04-11T09:30:24Z", + "modified": "2025-04-24T21:31:47Z", "published": "2025-04-11T09:30:24Z", "aliases": [ "CVE-2025-3512" @@ -22,6 +22,18 @@ { "type": "WEB", "url": "https://codereview.qt-project.org/c/qt/qtbase/+/635546" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/04/24/4" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/04/24/5" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/04/24/6" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/04/GHSA-99q6-5j8j-4wv8/GHSA-99q6-5j8j-4wv8.json b/advisories/unreviewed/2025/04/GHSA-99q6-5j8j-4wv8/GHSA-99q6-5j8j-4wv8.json new file mode 100644 index 00000000000..fe52d655f1f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-99q6-5j8j-4wv8/GHSA-99q6-5j8j-4wv8.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-99q6-5j8j-4wv8", + "modified": "2025-04-24T21:31:48Z", + "published": "2025-04-24T21:31:48Z", + "aliases": [ + "CVE-2025-29529" + ], + "details": "ITC Systems Multiplan/Matrix OneCard platform v3.7.4.1002 was discovered to contain a SQL injection vulnerability via the component Forgotpassword.aspx.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29529" + }, + { + "type": "WEB", + "url": "https://github.com/chamilo/chamilo-lms/commit/beb07770d674fcc9db6df0e59aab107678c28682" + }, + { + "type": "WEB", + "url": "https://github.com/Yoshik0xF6/CVE-2025-29529" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-24T21:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-mqx7-237c-8fxx/GHSA-mqx7-237c-8fxx.json b/advisories/unreviewed/2025/04/GHSA-mqx7-237c-8fxx/GHSA-mqx7-237c-8fxx.json new file mode 100644 index 00000000000..5e283f049d5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-mqx7-237c-8fxx/GHSA-mqx7-237c-8fxx.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mqx7-237c-8fxx", + "modified": "2025-04-24T21:31:47Z", + "published": "2025-04-24T21:31:47Z", + "aliases": [ + "CVE-2025-26382" + ], + "details": "Under certain circumstances the iSTAR Configuration Utility (ICU) tool could have a buffer overflow issue", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26382" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-25-114-05" + }, + { + "type": "WEB", + "url": "https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-24T20:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-mw98-rfjc-q8w9/GHSA-mw98-rfjc-q8w9.json b/advisories/unreviewed/2025/04/GHSA-mw98-rfjc-q8w9/GHSA-mw98-rfjc-q8w9.json new file mode 100644 index 00000000000..00ce2813a8f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-mw98-rfjc-q8w9/GHSA-mw98-rfjc-q8w9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mw98-rfjc-q8w9", + "modified": "2025-04-24T21:31:47Z", + "published": "2025-04-24T21:31:47Z", + "aliases": [ + "CVE-2022-44760" + ], + "details": "Unsafe default file type filter policy in HCL\nLeap allows execution of unsafe JavaScript in deployed applications.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-44760" + }, + { + "type": "WEB", + "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0119900" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-24T21:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-r77m-qpx3-mpgm/GHSA-r77m-qpx3-mpgm.json b/advisories/unreviewed/2025/04/GHSA-r77m-qpx3-mpgm/GHSA-r77m-qpx3-mpgm.json new file mode 100644 index 00000000000..a90d0c5870b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-r77m-qpx3-mpgm/GHSA-r77m-qpx3-mpgm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r77m-qpx3-mpgm", + "modified": "2025-04-24T21:31:47Z", + "published": "2025-04-24T21:31:47Z", + "aliases": [ + "CVE-2023-37516" + ], + "details": "Missing \"no cache\" headers in HCL Leap permits user directory information to be cached.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37516" + }, + { + "type": "WEB", + "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0119900" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-524" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-24T21:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rgw7-rhh8-mgf9/GHSA-rgw7-rhh8-mgf9.json b/advisories/unreviewed/2025/04/GHSA-rgw7-rhh8-mgf9/GHSA-rgw7-rhh8-mgf9.json new file mode 100644 index 00000000000..cdfb67c2363 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rgw7-rhh8-mgf9/GHSA-rgw7-rhh8-mgf9.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rgw7-rhh8-mgf9", + "modified": "2025-04-24T21:31:48Z", + "published": "2025-04-24T21:31:48Z", + "aliases": [ + "CVE-2025-25777" + ], + "details": "Insecure Direct Object Reference (IDOR) in Codeastro Bus Ticket Booking System v1.0 allows unauthorized access to user profiles. By manipulating the user ID in the URL, an attacker can access another user's profile without proper authentication or authorization checks.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25777" + }, + { + "type": "WEB", + "url": "https://codeastro.com/bus-ticket-booking-system-in-php-codeigniter-with-source-code" + }, + { + "type": "WEB", + "url": "https://github.com/arunmodi/Vulnerability-Research/tree/main/CVE-2025-25777" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-24T21:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-wp4q-9jq4-gv74/GHSA-wp4q-9jq4-gv74.json b/advisories/unreviewed/2025/04/GHSA-wp4q-9jq4-gv74/GHSA-wp4q-9jq4-gv74.json index f5b7509a8fe..e1aab46afc3 100644 --- a/advisories/unreviewed/2025/04/GHSA-wp4q-9jq4-gv74/GHSA-wp4q-9jq4-gv74.json +++ b/advisories/unreviewed/2025/04/GHSA-wp4q-9jq4-gv74/GHSA-wp4q-9jq4-gv74.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wp4q-9jq4-gv74", - "modified": "2025-04-24T00:31:19Z", + "modified": "2025-04-24T21:31:47Z", "published": "2025-04-23T18:30:57Z", "aliases": [ "CVE-2025-46394" @@ -34,6 +34,10 @@ { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2025/04/23/5" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/04/24/3" } ], "database_specific": {