From 1d6b17cbea08266813f9fb607937d1e6c4e5a049 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 21 Apr 2025 12:32:01 +0000 Subject: [PATCH] Publish Advisories GHSA-2j66-vp53-phjj GHSA-46h9-fw88-xg28 GHSA-4f5w-327f-jw8g GHSA-f736-vrhg-567q GHSA-rx59-94qj-gp9f --- .../GHSA-2j66-vp53-phjj.json | 10 +++++- .../GHSA-46h9-fw88-xg28.json | 6 +++- .../GHSA-4f5w-327f-jw8g.json | 36 +++++++++++++++++++ .../GHSA-f736-vrhg-567q.json | 36 +++++++++++++++++++ .../GHSA-rx59-94qj-gp9f.json | 36 +++++++++++++++++++ 5 files changed, 122 insertions(+), 2 deletions(-) create mode 100644 advisories/unreviewed/2025/04/GHSA-4f5w-327f-jw8g/GHSA-4f5w-327f-jw8g.json create mode 100644 advisories/unreviewed/2025/04/GHSA-f736-vrhg-567q/GHSA-f736-vrhg-567q.json create mode 100644 advisories/unreviewed/2025/04/GHSA-rx59-94qj-gp9f/GHSA-rx59-94qj-gp9f.json diff --git a/advisories/unreviewed/2024/06/GHSA-2j66-vp53-phjj/GHSA-2j66-vp53-phjj.json b/advisories/unreviewed/2024/06/GHSA-2j66-vp53-phjj/GHSA-2j66-vp53-phjj.json index 68a6c3df487..0562afed758 100644 --- a/advisories/unreviewed/2024/06/GHSA-2j66-vp53-phjj/GHSA-2j66-vp53-phjj.json +++ b/advisories/unreviewed/2024/06/GHSA-2j66-vp53-phjj/GHSA-2j66-vp53-phjj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2j66-vp53-phjj", - "modified": "2024-08-08T15:31:26Z", + "modified": "2025-04-21T12:30:23Z", "published": "2024-06-16T03:30:34Z", "aliases": [ "CVE-2024-38428" @@ -23,9 +23,17 @@ "type": "WEB", "url": "https://git.savannah.gnu.org/cgit/wget.git/commit/?id=ed0c7c7e0e8f7298352646b2fd6e06a11e242ace" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2025/04/msg00029.html" + }, { "type": "WEB", "url": "https://lists.gnu.org/archive/html/bug-wget/2024-06/msg00005.html" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20241115-0005" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/04/GHSA-46h9-fw88-xg28/GHSA-46h9-fw88-xg28.json b/advisories/unreviewed/2025/04/GHSA-46h9-fw88-xg28/GHSA-46h9-fw88-xg28.json index 92c78e96c70..dd7aca66adb 100644 --- a/advisories/unreviewed/2025/04/GHSA-46h9-fw88-xg28/GHSA-46h9-fw88-xg28.json +++ b/advisories/unreviewed/2025/04/GHSA-46h9-fw88-xg28/GHSA-46h9-fw88-xg28.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-46h9-fw88-xg28", - "modified": "2025-04-15T12:30:24Z", + "modified": "2025-04-21T12:30:24Z", "published": "2025-04-14T18:31:49Z", "aliases": [ "CVE-2025-22371" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22371" }, + { + "type": "WEB", + "url": "https://basec.sicomm.net" + }, { "type": "WEB", "url": "https://basec.sicomm.net/login" diff --git a/advisories/unreviewed/2025/04/GHSA-4f5w-327f-jw8g/GHSA-4f5w-327f-jw8g.json b/advisories/unreviewed/2025/04/GHSA-4f5w-327f-jw8g/GHSA-4f5w-327f-jw8g.json new file mode 100644 index 00000000000..cb767ca2fe3 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4f5w-327f-jw8g/GHSA-4f5w-327f-jw8g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4f5w-327f-jw8g", + "modified": "2025-04-21T12:30:24Z", + "published": "2025-04-21T12:30:24Z", + "aliases": [ + "CVE-2025-3838" + ], + "details": "An Improper Authorization vulnerability was identified in the EOL OVA based connect component which is deployed for installation purposes in the customer internal network. Under certain conditions, this could allow a bad actor to gain unauthorized access to the local db containing weakly hashed credentials of the installer. This EOL component was deprecated in September 2023 with end of support extended till January 2024.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3838" + }, + { + "type": "WEB", + "url": "https://saviynt.com/trust-compliance-security" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-327" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-21T10:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-f736-vrhg-567q/GHSA-f736-vrhg-567q.json b/advisories/unreviewed/2025/04/GHSA-f736-vrhg-567q/GHSA-f736-vrhg-567q.json new file mode 100644 index 00000000000..c0d793616e4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-f736-vrhg-567q/GHSA-f736-vrhg-567q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f736-vrhg-567q", + "modified": "2025-04-21T12:30:24Z", + "published": "2025-04-21T12:30:24Z", + "aliases": [ + "CVE-2025-3837" + ], + "details": "An improper input validation vulnerability is identified in the End of Life (EOL) OVA based connect component which is deployed for installation purposes in the customer internal network. This EOL component was deprecated in September 2023 with end of support extended till January 2024. Under certain circumstances, an actor can manipulate a specific request parameter and inject code execution payload which could lead to a remote code execution on the infrastructure hosting this component.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3837" + }, + { + "type": "WEB", + "url": "https://saviynt.com/trust-compliance-security" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-21T10:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rx59-94qj-gp9f/GHSA-rx59-94qj-gp9f.json b/advisories/unreviewed/2025/04/GHSA-rx59-94qj-gp9f/GHSA-rx59-94qj-gp9f.json new file mode 100644 index 00000000000..40215019245 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rx59-94qj-gp9f/GHSA-rx59-94qj-gp9f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rx59-94qj-gp9f", + "modified": "2025-04-21T12:30:24Z", + "published": "2025-04-21T12:30:24Z", + "aliases": [ + "CVE-2025-3840" + ], + "details": "An improper neutralization of input vulnerability was identified in the End of Life (EOL) OVA based connect installer component which is deployed for installation purposes in a customer network. This EOL component was deprecated in September 2023 with end of support extended till January 2024. An actor can manipulate the action parameter of the login form to inject malicious scripts which would lead to a XSS attack under certain conditions.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3840" + }, + { + "type": "WEB", + "url": "https://saviynt.com/trust-compliance-security" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-21T10:15:15Z" + } +} \ No newline at end of file