Publish Advisories

GHSA-2j66-vp53-phjj
GHSA-46h9-fw88-xg28
GHSA-4f5w-327f-jw8g
GHSA-f736-vrhg-567q
GHSA-rx59-94qj-gp9f
This commit is contained in:
advisory-database[bot]
2025-04-21 12:32:01 +00:00
parent ca7dbd7ae7
commit 1d6b17cbea
5 changed files with 122 additions and 2 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2j66-vp53-phjj",
"modified": "2024-08-08T15:31:26Z",
"modified": "2025-04-21T12:30:23Z",
"published": "2024-06-16T03:30:34Z",
"aliases": [
"CVE-2024-38428"
@@ -23,9 +23,17 @@
"type": "WEB",
"url": "https://git.savannah.gnu.org/cgit/wget.git/commit/?id=ed0c7c7e0e8f7298352646b2fd6e06a11e242ace"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2025/04/msg00029.html"
},
{
"type": "WEB",
"url": "https://lists.gnu.org/archive/html/bug-wget/2024-06/msg00005.html"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20241115-0005"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-46h9-fw88-xg28",
"modified": "2025-04-15T12:30:24Z",
"modified": "2025-04-21T12:30:24Z",
"published": "2025-04-14T18:31:49Z",
"aliases": [
"CVE-2025-22371"
@@ -19,6 +19,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22371"
},
{
"type": "WEB",
"url": "https://basec.sicomm.net"
},
{
"type": "WEB",
"url": "https://basec.sicomm.net/login"
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4f5w-327f-jw8g",
"modified": "2025-04-21T12:30:24Z",
"published": "2025-04-21T12:30:24Z",
"aliases": [
"CVE-2025-3838"
],
"details": "An Improper Authorization vulnerability was identified in the EOL OVA based connect component which is deployed for installation purposes in the customer internal network. Under certain conditions, this could allow a bad actor to gain unauthorized access to the local db containing weakly hashed credentials of the installer. This EOL component was deprecated in September 2023 with end of support extended till January 2024.",
"severity": [
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3838"
},
{
"type": "WEB",
"url": "https://saviynt.com/trust-compliance-security"
}
],
"database_specific": {
"cwe_ids": [
"CWE-327"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-21T10:15:15Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f736-vrhg-567q",
"modified": "2025-04-21T12:30:24Z",
"published": "2025-04-21T12:30:24Z",
"aliases": [
"CVE-2025-3837"
],
"details": "An improper input validation vulnerability is identified in the End of Life (EOL) OVA based connect component which is deployed for installation purposes in the customer internal network. This EOL component was deprecated in September 2023 with end of support extended till January 2024. Under certain circumstances, an actor can manipulate a specific request parameter and inject code execution payload which could lead to a remote code execution on the infrastructure hosting this component.",
"severity": [
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3837"
},
{
"type": "WEB",
"url": "https://saviynt.com/trust-compliance-security"
}
],
"database_specific": {
"cwe_ids": [
"CWE-20"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-21T10:15:15Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rx59-94qj-gp9f",
"modified": "2025-04-21T12:30:24Z",
"published": "2025-04-21T12:30:24Z",
"aliases": [
"CVE-2025-3840"
],
"details": "An improper neutralization of input vulnerability was identified in the End of Life (EOL) OVA based connect installer component which is deployed for installation purposes in a customer network. This EOL component was deprecated in September 2023 with end of support extended till January 2024. An actor can manipulate the action parameter of the login form to inject malicious scripts which would lead to a XSS attack under certain conditions.",
"severity": [
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3840"
},
{
"type": "WEB",
"url": "https://saviynt.com/trust-compliance-security"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-21T10:15:15Z"
}
}