From 1deaa93de2f6964fa9f79e23958bfd02fe7475c2 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 20 Mar 2025 12:34:24 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-9x24-7fgc-x3vc.json | 4 +- .../GHSA-8vf4-q8g2-79g5.json | 11 +++- .../GHSA-hw9j-mg68-r593.json | 4 +- .../GHSA-227r-w5j2-6243.json | 40 +++++++++++++ .../GHSA-22h9-9rvv-q9qg.json | 36 ++++++++++++ .../GHSA-29rg-m5qv-57gx.json | 36 ++++++++++++ .../GHSA-2c36-wq4v-5v3h.json | 36 ++++++++++++ .../GHSA-2mv8-c3hx-xq6v.json | 40 +++++++++++++ .../GHSA-2rr7-xrrm-67cf.json | 36 ++++++++++++ .../GHSA-2w2q-qp7m-7wrh.json | 36 ++++++++++++ .../GHSA-2xcr-p767-f3rv.json | 40 +++++++++++++ .../GHSA-2xf2-gjm6-g2c6.json | 36 ++++++++++++ .../GHSA-3248-f932-c76p.json | 36 ++++++++++++ .../GHSA-32g6-mg92-ghm2.json | 40 +++++++++++++ .../GHSA-332g-rf22-2vcg.json | 36 ++++++++++++ .../GHSA-339r-cjv9-x78g.json | 40 +++++++++++++ .../GHSA-34v4-5664-chqj.json | 36 ++++++++++++ .../GHSA-35p3-6j45-prwm.json | 36 ++++++++++++ .../GHSA-38mg-wm59-g64x.json | 36 ++++++++++++ .../GHSA-38r9-3j52-h92v.json | 36 ++++++++++++ .../GHSA-3c45-rpmq-6gfj.json | 36 ++++++++++++ .../GHSA-3j5r-3852-j63v.json | 36 ++++++++++++ .../GHSA-3p9q-7w63-3f8q.json | 36 ++++++++++++ .../GHSA-3ppw-4jp4-5852.json | 36 ++++++++++++ .../GHSA-3xq5-x4fj-rff7.json | 36 ++++++++++++ .../GHSA-43g4-487m-5q6m.json | 36 ++++++++++++ .../GHSA-43qf-4rqw-9q2g.json | 36 ++++++++++++ .../GHSA-4452-rwq3-2x44.json | 36 ++++++++++++ .../GHSA-44q8-52gx-27g8.json | 40 +++++++++++++ .../GHSA-45p5-8q33-98hw.json | 40 +++++++++++++ .../GHSA-47f6-5p7h-5f3h.json | 36 ++++++++++++ .../GHSA-49m6-vrr9-2cqm.json | 36 ++++++++++++ .../GHSA-49rx-72gp-wfgj.json | 36 ++++++++++++ .../GHSA-4cv3-v7pv-rfhf.json | 40 +++++++++++++ .../GHSA-4cxc-r29p-3327.json | 36 ++++++++++++ .../GHSA-4f3h-89pj-w84f.json | 36 ++++++++++++ .../GHSA-4g3f-9mfg-xxgh.json | 36 ++++++++++++ .../GHSA-4jr8-64gc-wqqx.json | 40 +++++++++++++ .../GHSA-4qcx-jx49-6qrh.json | 36 ++++++++++++ .../GHSA-4rj2-9gcx-5qhx.json | 40 +++++++++++++ .../GHSA-4rqf-8pfm-p36r.json | 40 +++++++++++++ .../GHSA-4v9f-r55g-g6hc.json | 40 +++++++++++++ .../GHSA-4vm5-r6m3-2448.json | 36 ++++++++++++ .../GHSA-4vmg-rw8f-92f9.json | 36 ++++++++++++ .../GHSA-4vqf-pwq6-3wh3.json | 36 ++++++++++++ .../GHSA-4w44-j4vc-r3rp.json | 36 ++++++++++++ .../GHSA-4wfj-v7c8-rwh4.json | 36 ++++++++++++ .../GHSA-53gh-p8jc-7rg8.json | 36 ++++++++++++ .../GHSA-54c7-72v9-gm27.json | 36 ++++++++++++ .../GHSA-54hh-fh2m-4396.json | 40 +++++++++++++ .../GHSA-564p-rx2q-4c8v.json | 36 ++++++++++++ .../GHSA-56p4-cfqw-jx4h.json | 36 ++++++++++++ .../GHSA-5c8j-g96x-cj78.json | 36 ++++++++++++ .../GHSA-5ccf-884p-4jjq.json | 36 ++++++++++++ .../GHSA-5chr-fjjv-38qv.json | 40 +++++++++++++ .../GHSA-5cpq-9538-jm2j.json | 36 ++++++++++++ .../GHSA-5fhx-jcwv-9wjj.json | 36 ++++++++++++ .../GHSA-5jmj-h3c5-682w.json | 40 +++++++++++++ .../GHSA-5mh3-rhm7-jxx3.json | 36 ++++++++++++ .../GHSA-5pfw-4vjf-fvc9.json | 36 ++++++++++++ .../GHSA-5v9m-57mq-qc75.json | 36 ++++++++++++ .../GHSA-5vqr-wprc-cpp7.json | 36 ++++++++++++ .../GHSA-5xg7-5662-8x7j.json | 36 ++++++++++++ .../GHSA-62xp-4pcv-pw3j.json | 40 +++++++++++++ .../GHSA-63gf-x2fr-8r32.json | 36 ++++++++++++ .../GHSA-64c5-jj57-f29g.json | 40 +++++++++++++ .../GHSA-64jp-4xjj-prcw.json | 40 +++++++++++++ .../GHSA-67hg-xcw3-33fm.json | 36 ++++++++++++ .../GHSA-6827-g8xf-36c7.json | 40 +++++++++++++ .../GHSA-69j6-4w2p-2887.json | 40 +++++++++++++ .../GHSA-6ch3-c5vc-j2r6.json | 36 ++++++++++++ .../GHSA-6f6x-f56q-5xgv.json | 36 ++++++++++++ .../GHSA-6fwx-j832-vvw6.json | 36 ++++++++++++ .../GHSA-6gmf-2369-c76c.json | 40 +++++++++++++ .../GHSA-6mf6-7j75-2m6f.json | 36 ++++++++++++ .../GHSA-6pvw-p9fg-rwxj.json | 40 +++++++++++++ .../GHSA-6rvg-6v2m-4j46.json | 40 +++++++++++++ .../GHSA-6v28-q95m-93qr.json | 36 ++++++++++++ .../GHSA-6vmm-pmxf-9784.json | 36 ++++++++++++ .../GHSA-6w2c-f4vg-j9hv.json | 36 ++++++++++++ .../GHSA-6w62-3jvj-mfj6.json | 36 ++++++++++++ .../GHSA-6w7p-xrvp-p7xv.json | 36 ++++++++++++ .../GHSA-6wj5-5pgr-jwq8.json | 36 ++++++++++++ .../GHSA-6xgj-c5fx-5v57.json | 36 ++++++++++++ .../GHSA-726r-vfh2-3vvj.json | 40 +++++++++++++ .../GHSA-73c8-qmph-r39f.json | 40 +++++++++++++ .../GHSA-73p4-hh43-4h48.json | 40 +++++++++++++ .../GHSA-745f-48gc-258q.json | 36 ++++++++++++ .../GHSA-747f-ww56-4q4h.json | 40 +++++++++++++ .../GHSA-749v-xf6w-5wcx.json | 48 ++++++++++++++++ .../GHSA-75px-35p4-qq6h.json | 36 ++++++++++++ .../GHSA-75v5-6885-59f9.json | 36 ++++++++++++ .../GHSA-775f-24cq-qg6p.json | 40 +++++++++++++ .../GHSA-77cj-rv5x-v6r2.json | 36 ++++++++++++ .../GHSA-79rp-v9rm-gxm8.json | 36 ++++++++++++ .../GHSA-7g3f-q846-q9hx.json | 36 ++++++++++++ .../GHSA-7gj6-22m4-qfhx.json | 36 ++++++++++++ .../GHSA-7h46-xxgg-f9q8.json | 36 ++++++++++++ .../GHSA-7hc9-vjg2-vpcr.json | 36 ++++++++++++ .../GHSA-7j9v-mc62-mcm5.json | 36 ++++++++++++ .../GHSA-7qq7-pvm9-x8rf.json | 36 ++++++++++++ .../GHSA-7rxf-gvfg-47g4.json | 36 ++++++++++++ .../GHSA-7v2w-h4gh-w5cv.json | 36 ++++++++++++ .../GHSA-7xmc-vhjp-qv5q.json | 36 ++++++++++++ .../GHSA-823j-2wj6-7jwh.json | 40 +++++++++++++ .../GHSA-82mg-566w-vpxp.json | 36 ++++++++++++ .../GHSA-85ff-r9hw-4grc.json | 40 +++++++++++++ .../GHSA-85jc-8h5p-8vw8.json | 36 ++++++++++++ .../GHSA-873w-8cph-rghj.json | 36 ++++++++++++ .../GHSA-879v-fggm-vxw2.json | 36 ++++++++++++ .../GHSA-89qx-m49c-8crf.json | 36 ++++++++++++ .../GHSA-8f78-f6p2-mjw7.json | 40 +++++++++++++ .../GHSA-8fw3-c8jq-g74q.json | 36 ++++++++++++ .../GHSA-8gfh-hxjj-c33j.json | 40 +++++++++++++ .../GHSA-8jhr-8vq6-2gp8.json | 40 +++++++++++++ .../GHSA-8pwp-phcg-h36g.json | 36 ++++++++++++ .../GHSA-8q24-hc9h-h952.json | 36 ++++++++++++ .../GHSA-8qff-6gwc-wph3.json | 36 ++++++++++++ .../GHSA-8v6j-vg6w-6wwj.json | 36 ++++++++++++ .../GHSA-8vgw-p6qm-5gr7.json | 34 +++++++++++ .../GHSA-8vjh-pxfw-4fqm.json | 36 ++++++++++++ .../GHSA-93qj-49fq-62jp.json | 36 ++++++++++++ .../GHSA-959v-wfjp-7c37.json | 36 ++++++++++++ .../GHSA-969w-gqqr-g6j3.json | 40 +++++++++++++ .../GHSA-96mw-rfcv-484q.json | 36 ++++++++++++ .../GHSA-96w2-hg6w-6xv2.json | 36 ++++++++++++ .../GHSA-97pg-wr4r-53wr.json | 36 ++++++++++++ .../GHSA-98fp-7v67-4v3q.json | 36 ++++++++++++ .../GHSA-9g44-gwvm-hc44.json | 36 ++++++++++++ .../GHSA-9gcr-28rp-cc24.json | 36 ++++++++++++ .../GHSA-9mhf-9hxp-8j3m.json | 36 ++++++++++++ .../GHSA-9vf8-xgwm-97r8.json | 36 ++++++++++++ .../GHSA-9vwq-rwcj-cmcg.json | 36 ++++++++++++ .../GHSA-9w5h-67gf-xvv8.json | 36 ++++++++++++ .../GHSA-9xvx-2953-c58g.json | 40 +++++++++++++ .../GHSA-c2qr-w9p6-cxgr.json | 40 +++++++++++++ .../GHSA-c2xf-763v-3rqh.json | 36 ++++++++++++ .../GHSA-c39q-wr4f-xpw7.json | 48 ++++++++++++++++ .../GHSA-c4cc-w454-4634.json | 36 ++++++++++++ .../GHSA-c7fq-p62p-wvpc.json | 36 ++++++++++++ .../GHSA-c85g-5883-vjj7.json | 36 ++++++++++++ .../GHSA-cfc5-c899-6ww2.json | 36 ++++++++++++ .../GHSA-cfvq-fj53-j2c7.json | 36 ++++++++++++ .../GHSA-cg4p-5qfm-pjjj.json | 36 ++++++++++++ .../GHSA-chf7-q7m5-fq92.json | 36 ++++++++++++ .../GHSA-cj47-qj6g-x7r4.json | 36 ++++++++++++ .../GHSA-cjjc-mf84-xp9f.json | 40 +++++++++++++ .../GHSA-cppx-6f25-3qxc.json | 36 ++++++++++++ .../GHSA-crh6-pj8c-xrhc.json | 36 ++++++++++++ .../GHSA-cvg9-334x-w586.json | 36 ++++++++++++ .../GHSA-cwc2-3f9g-phm3.json | 36 ++++++++++++ .../GHSA-cx66-wgv6-fpfh.json | 36 ++++++++++++ .../GHSA-f2v6-7vxr-j9g8.json | 36 ++++++++++++ .../GHSA-f3v2-jc5f-6328.json | 36 ++++++++++++ .../GHSA-f4hc-q562-cc5r.json | 36 ++++++++++++ .../GHSA-f64v-mwpx-gv6x.json | 36 ++++++++++++ .../GHSA-f6rh-g2v9-v6qp.json | 40 +++++++++++++ .../GHSA-fccc-8m69-8r78.json | 36 ++++++++++++ .../GHSA-ff5c-56m7-vc75.json | 36 ++++++++++++ .../GHSA-ffh5-w482-c7m5.json | 36 ++++++++++++ .../GHSA-fgqc-p7g9-x92w.json | 36 ++++++++++++ .../GHSA-fh2c-86xm-pm2x.json | 36 ++++++++++++ .../GHSA-fhfg-frx8-7458.json | 36 ++++++++++++ .../GHSA-fjcf-3j3r-78rp.json | 40 +++++++++++++ .../GHSA-fm93-g6xp-35xq.json | 36 ++++++++++++ .../GHSA-fqr7-jjqq-hpr6.json | 40 +++++++++++++ .../GHSA-fx47-jpv9-7hxr.json | 36 ++++++++++++ .../GHSA-fxpx-7wrq-8ggp.json | 40 +++++++++++++ .../GHSA-g394-qpx6-x7rr.json | 36 ++++++++++++ .../GHSA-g3mx-83mp-3rwc.json | 36 ++++++++++++ .../GHSA-g3p7-f346-26m6.json | 36 ++++++++++++ .../GHSA-g3v3-r244-mhhm.json | 36 ++++++++++++ .../GHSA-g44m-hpf4-vmrp.json | 36 ++++++++++++ .../GHSA-g48v-3p35-88jr.json | 36 ++++++++++++ .../GHSA-g5pg-73fc-hjwq.json | 40 +++++++++++++ .../GHSA-g9c4-qhpw-x7pw.json | 52 +++++++++++++++++ .../GHSA-gc79-m262-q226.json | 36 ++++++++++++ .../GHSA-gf99-rrrr-wjqh.json | 40 +++++++++++++ .../GHSA-gg5q-w3xv-q3f4.json | 48 ++++++++++++++++ .../GHSA-gggj-77q9-hf6x.json | 36 ++++++++++++ .../GHSA-gh22-g6w4-m562.json | 36 ++++++++++++ .../GHSA-gj27-76gq-5v3p.json | 36 ++++++++++++ .../GHSA-gjxm-x497-4h6h.json | 40 +++++++++++++ .../GHSA-gmqg-7635-v6cj.json | 40 +++++++++++++ .../GHSA-grjq-mg5m-r4jj.json | 36 ++++++++++++ .../GHSA-gv26-qw3h-8qvp.json | 36 ++++++++++++ .../GHSA-gvmg-6fvg-2jp2.json | 40 +++++++++++++ .../GHSA-gw2q-qw9j-rgv7.json | 40 +++++++++++++ .../GHSA-h254-g997-685c.json | 36 ++++++++++++ .../GHSA-h35f-g2pq-8xq7.json | 36 ++++++++++++ .../GHSA-h36j-8vv3-cj52.json | 36 ++++++++++++ .../GHSA-h4p8-798h-26f4.json | 36 ++++++++++++ .../GHSA-h4x7-365q-3rm3.json | 36 ++++++++++++ .../GHSA-h5h7-gc2g-vq79.json | 40 +++++++++++++ .../GHSA-h5jv-6xg2-9cv8.json | 40 +++++++++++++ .../GHSA-h5p2-273c-rxjp.json | 40 +++++++++++++ .../GHSA-h7xg-cmpp-48hf.json | 40 +++++++++++++ .../GHSA-h9jx-rcv4-cgqg.json | 36 ++++++++++++ .../GHSA-h9m7-c24m-gqr9.json | 36 ++++++++++++ .../GHSA-hc5x-x2vx-497g.json | 36 ++++++++++++ .../GHSA-hc9x-f65g-gjqh.json | 36 ++++++++++++ .../GHSA-hh3j-9m59-p8vc.json | 36 ++++++++++++ .../GHSA-hhr6-7642-8pmh.json | 36 ++++++++++++ .../GHSA-hhw5-29f6-hf4x.json | 36 ++++++++++++ .../GHSA-hjcr-w68h-rg2p.json | 36 ++++++++++++ .../GHSA-hm5x-x82r-982c.json | 36 ++++++++++++ .../GHSA-hq38-64gm-3w2c.json | 40 +++++++++++++ .../GHSA-hw3w-6mhf-rh8m.json | 36 ++++++++++++ .../GHSA-hw8j-hw49-752c.json | 36 ++++++++++++ .../GHSA-hx67-j5pj-h8ch.json | 40 +++++++++++++ .../GHSA-j274-m559-cj4j.json | 36 ++++++++++++ .../GHSA-j3jw-5w88-cqxr.json | 40 +++++++++++++ .../GHSA-j3wr-m6xh-64hg.json | 40 +++++++++++++ .../GHSA-j46h-c723-q9rm.json | 56 +++++++++++++++++++ .../GHSA-j4mc-gwfc-jcf5.json | 40 +++++++++++++ .../GHSA-j5fq-p3c6-93jm.json | 40 +++++++++++++ .../GHSA-j5qj-rg5j-j7c2.json | 36 ++++++++++++ .../GHSA-j8gf-4j8g-8mvp.json | 36 ++++++++++++ .../GHSA-j8x9-qc9m-rmhj.json | 40 +++++++++++++ .../GHSA-j9g7-mqhh-9hxf.json | 36 ++++++++++++ .../GHSA-j9rw-qm5f-r8xm.json | 36 ++++++++++++ .../GHSA-jccx-m9v4-9hwh.json | 40 +++++++++++++ .../GHSA-jfm2-hq55-pxgq.json | 40 +++++++++++++ .../GHSA-jg5r-v2h9-wfxx.json | 40 +++++++++++++ .../GHSA-jjcv-gwx7-hcx9.json | 40 +++++++++++++ .../GHSA-jjhp-4v9p-5fv8.json | 36 ++++++++++++ .../GHSA-jjm2-vhrm-92vg.json | 36 ++++++++++++ .../GHSA-jm82-665g-74jp.json | 36 ++++++++++++ .../GHSA-jm87-8wm6-fr27.json | 36 ++++++++++++ .../GHSA-jmgm-gx32-vp4w.json | 40 +++++++++++++ .../GHSA-jqgv-3ch9-c9qv.json | 40 +++++++++++++ .../GHSA-jrhc-9qg9-4qfq.json | 36 ++++++++++++ .../GHSA-jrhv-8gfh-55w6.json | 48 ++++++++++++++++ .../GHSA-jv2r-r6r9-hvhj.json | 36 ++++++++++++ .../GHSA-jvpf-xf32-2w4q.json | 40 +++++++++++++ .../GHSA-jw8w-84x3-c2r9.json | 40 +++++++++++++ .../GHSA-jx9r-x782-9r4m.json | 36 ++++++++++++ .../GHSA-m2g8-2vhm-m4cx.json | 36 ++++++++++++ .../GHSA-m2gm-4vg9-pcc4.json | 36 ++++++++++++ .../GHSA-m2v2-9gxp-2r53.json | 36 ++++++++++++ .../GHSA-m37h-8r48-2cxj.json | 36 ++++++++++++ .../GHSA-m47g-ghr5-3734.json | 36 ++++++++++++ .../GHSA-m62f-m76v-gfwr.json | 36 ++++++++++++ .../GHSA-m724-88wc-fpgh.json | 36 ++++++++++++ .../GHSA-m724-hqmc-ggpx.json | 36 ++++++++++++ .../GHSA-m74w-gj86-32q9.json | 36 ++++++++++++ .../GHSA-m76r-xqqj-mqmv.json | 36 ++++++++++++ .../GHSA-mc9m-5hw4-g3g6.json | 36 ++++++++++++ .../GHSA-mf57-6hg5-mrvm.json | 36 ++++++++++++ .../GHSA-mhmr-w8pp-75w5.json | 40 +++++++++++++ .../GHSA-mj67-2mvx-f778.json | 40 +++++++++++++ .../GHSA-mjvp-pg3h-wh59.json | 40 +++++++++++++ .../GHSA-mq4w-5hp5-6g52.json | 40 +++++++++++++ .../GHSA-mq78-p977-pwgv.json | 36 ++++++++++++ .../GHSA-mq8r-j55w-fv46.json | 40 +++++++++++++ .../GHSA-mqp7-6vh9-99r6.json | 40 +++++++++++++ .../GHSA-mrhh-3ggq-23p2.json | 36 ++++++++++++ .../GHSA-mrvr-7493-pfq3.json | 36 ++++++++++++ .../GHSA-mvp8-9qgw-vf58.json | 36 ++++++++++++ .../GHSA-p2f3-rm9r-rxgj.json | 40 +++++++++++++ .../GHSA-p2vc-m5fv-9w9m.json | 36 ++++++++++++ .../GHSA-p2wh-w96x-w232.json | 36 ++++++++++++ .../GHSA-p5vx-9hj8-cf4h.json | 36 ++++++++++++ .../GHSA-p6h7-hfj2-vmcf.json | 36 ++++++++++++ .../GHSA-p6x3-v6g3-7557.json | 36 ++++++++++++ .../GHSA-p868-p9pj-fvmr.json | 40 +++++++++++++ .../GHSA-p926-8677-385w.json | 36 ++++++++++++ .../GHSA-pgfv-gvc5-prfg.json | 36 ++++++++++++ .../GHSA-pgr7-mhp5-fgjp.json | 36 ++++++++++++ .../GHSA-ph84-8v89-25q8.json | 36 ++++++++++++ .../GHSA-pqwr-phvv-v49f.json | 36 ++++++++++++ .../GHSA-prpg-p95c-32fv.json | 36 ++++++++++++ .../GHSA-prx2-6cc4-7qq5.json | 40 +++++++++++++ .../GHSA-q36w-fgp3-q2gw.json | 36 ++++++++++++ .../GHSA-q3gw-8236-5jw4.json | 36 ++++++++++++ .../GHSA-q5v7-7r3x-m7hg.json | 36 ++++++++++++ .../GHSA-q67c-vgg7-pvrq.json | 36 ++++++++++++ .../GHSA-q6gg-j289-2hm4.json | 36 ++++++++++++ .../GHSA-q73m-3cg7-m23w.json | 36 ++++++++++++ .../GHSA-q88j-ff64-2m3q.json | 36 ++++++++++++ .../GHSA-q8pp-mmm3-9j9w.json | 40 +++++++++++++ .../GHSA-qccg-9m4q-xfm6.json | 36 ++++++++++++ .../GHSA-qg86-f892-m4hj.json | 36 ++++++++++++ .../GHSA-qgm6-wj98-3qh4.json | 40 +++++++++++++ .../GHSA-qhfv-rxrj-6w5f.json | 36 ++++++++++++ .../GHSA-qjq5-7g6p-p3vg.json | 40 +++++++++++++ .../GHSA-qv9p-39px-hfwc.json | 40 +++++++++++++ .../GHSA-qvg9-vp87-h3hr.json | 36 ++++++++++++ .../GHSA-r229-5wgf-f28g.json | 36 ++++++++++++ .../GHSA-r3hj-whx4-hvvj.json | 36 ++++++++++++ .../GHSA-r49j-4jpw-x35c.json | 36 ++++++++++++ .../GHSA-r4hm-vcvh-rm39.json | 36 ++++++++++++ .../GHSA-r9m5-fcw8-68f6.json | 40 +++++++++++++ .../GHSA-rc69-h6h5-3q4x.json | 36 ++++++++++++ .../GHSA-rm69-wvpv-r2w7.json | 36 ++++++++++++ .../GHSA-rqhc-x44r-f23j.json | 40 +++++++++++++ .../GHSA-rqrm-p43g-fpmq.json | 40 +++++++++++++ .../GHSA-rrfw-qqmx-gqwx.json | 40 +++++++++++++ .../GHSA-rv4f-crjq-xjf8.json | 36 ++++++++++++ .../GHSA-rvgh-pr46-x7gg.json | 36 ++++++++++++ .../GHSA-rvmr-crph-7vj2.json | 44 +++++++++++++++ .../GHSA-rxwh-3m8p-2qq5.json | 36 ++++++++++++ .../GHSA-v3f4-7pp9-6f99.json | 36 ++++++++++++ .../GHSA-v464-r2r9-www7.json | 36 ++++++++++++ .../GHSA-v5pj-jrpv-h6g2.json | 36 ++++++++++++ .../GHSA-v67x-89x7-mh47.json | 40 +++++++++++++ .../GHSA-vffc-qpx3-764c.json | 36 ++++++++++++ .../GHSA-vh85-qfmh-23mf.json | 40 +++++++++++++ .../GHSA-vhfq-gpqw-p5cw.json | 36 ++++++++++++ .../GHSA-vpg6-7cch-gq2j.json | 36 ++++++++++++ .../GHSA-vq2g-prvr-rgr4.json | 40 +++++++++++++ .../GHSA-vqqv-6pvc-4m7q.json | 40 +++++++++++++ .../GHSA-vrw3-r7jw-4785.json | 36 ++++++++++++ .../GHSA-vx9q-6hqp-j863.json | 40 +++++++++++++ .../GHSA-w3m9-crxx-972f.json | 36 ++++++++++++ .../GHSA-w466-2wfc-8g58.json | 36 ++++++++++++ .../GHSA-w4cv-4jm4-pg8h.json | 40 +++++++++++++ .../GHSA-w6hh-w36c-vxmw.json | 40 +++++++++++++ .../GHSA-w6r4-j5cm-c7fp.json | 40 +++++++++++++ .../GHSA-wcwp-9rcp-jvfg.json | 36 ++++++++++++ .../GHSA-wjpv-64v2-2qpq.json | 36 ++++++++++++ .../GHSA-wmc2-c6g2-9mf2.json | 36 ++++++++++++ .../GHSA-wr4v-pc76-3q4p.json | 40 +++++++++++++ .../GHSA-wwr9-4gmr-xvq9.json | 36 ++++++++++++ .../GHSA-wxpc-2674-rxvw.json | 36 ++++++++++++ .../GHSA-x2w2-frfv-4f2j.json | 40 +++++++++++++ .../GHSA-x48g-hm9c-ww42.json | 40 +++++++++++++ .../GHSA-x552-5vh8-qccx.json | 40 +++++++++++++ .../GHSA-x5xw-28w4-53j5.json | 36 ++++++++++++ .../GHSA-x757-hv69-jr45.json | 36 ++++++++++++ .../GHSA-x7c5-9r9g-pghj.json | 36 ++++++++++++ .../GHSA-x9hf-jr2h-w47p.json | 36 ++++++++++++ .../GHSA-xcp6-jv5m-jwrm.json | 40 +++++++++++++ .../GHSA-xfjg-gcvp-vw7p.json | 40 +++++++++++++ .../GHSA-xqgj-r6xv-9cw4.json | 36 ++++++++++++ .../GHSA-xv4c-2443-pc28.json | 36 ++++++++++++ .../GHSA-xx7c-j7h3-vjcq.json | 34 +++++++++++ 337 files changed, 12513 insertions(+), 6 deletions(-) create mode 100644 advisories/unreviewed/2025/03/GHSA-227r-w5j2-6243/GHSA-227r-w5j2-6243.json create mode 100644 advisories/unreviewed/2025/03/GHSA-22h9-9rvv-q9qg/GHSA-22h9-9rvv-q9qg.json create mode 100644 advisories/unreviewed/2025/03/GHSA-29rg-m5qv-57gx/GHSA-29rg-m5qv-57gx.json create mode 100644 advisories/unreviewed/2025/03/GHSA-2c36-wq4v-5v3h/GHSA-2c36-wq4v-5v3h.json create mode 100644 advisories/unreviewed/2025/03/GHSA-2mv8-c3hx-xq6v/GHSA-2mv8-c3hx-xq6v.json create mode 100644 advisories/unreviewed/2025/03/GHSA-2rr7-xrrm-67cf/GHSA-2rr7-xrrm-67cf.json create mode 100644 advisories/unreviewed/2025/03/GHSA-2w2q-qp7m-7wrh/GHSA-2w2q-qp7m-7wrh.json create mode 100644 advisories/unreviewed/2025/03/GHSA-2xcr-p767-f3rv/GHSA-2xcr-p767-f3rv.json create mode 100644 advisories/unreviewed/2025/03/GHSA-2xf2-gjm6-g2c6/GHSA-2xf2-gjm6-g2c6.json create mode 100644 advisories/unreviewed/2025/03/GHSA-3248-f932-c76p/GHSA-3248-f932-c76p.json create mode 100644 advisories/unreviewed/2025/03/GHSA-32g6-mg92-ghm2/GHSA-32g6-mg92-ghm2.json create mode 100644 advisories/unreviewed/2025/03/GHSA-332g-rf22-2vcg/GHSA-332g-rf22-2vcg.json create mode 100644 advisories/unreviewed/2025/03/GHSA-339r-cjv9-x78g/GHSA-339r-cjv9-x78g.json create mode 100644 advisories/unreviewed/2025/03/GHSA-34v4-5664-chqj/GHSA-34v4-5664-chqj.json create mode 100644 advisories/unreviewed/2025/03/GHSA-35p3-6j45-prwm/GHSA-35p3-6j45-prwm.json create mode 100644 advisories/unreviewed/2025/03/GHSA-38mg-wm59-g64x/GHSA-38mg-wm59-g64x.json create mode 100644 advisories/unreviewed/2025/03/GHSA-38r9-3j52-h92v/GHSA-38r9-3j52-h92v.json create mode 100644 advisories/unreviewed/2025/03/GHSA-3c45-rpmq-6gfj/GHSA-3c45-rpmq-6gfj.json create mode 100644 advisories/unreviewed/2025/03/GHSA-3j5r-3852-j63v/GHSA-3j5r-3852-j63v.json create mode 100644 advisories/unreviewed/2025/03/GHSA-3p9q-7w63-3f8q/GHSA-3p9q-7w63-3f8q.json create mode 100644 advisories/unreviewed/2025/03/GHSA-3ppw-4jp4-5852/GHSA-3ppw-4jp4-5852.json create mode 100644 advisories/unreviewed/2025/03/GHSA-3xq5-x4fj-rff7/GHSA-3xq5-x4fj-rff7.json create mode 100644 advisories/unreviewed/2025/03/GHSA-43g4-487m-5q6m/GHSA-43g4-487m-5q6m.json create mode 100644 advisories/unreviewed/2025/03/GHSA-43qf-4rqw-9q2g/GHSA-43qf-4rqw-9q2g.json create mode 100644 advisories/unreviewed/2025/03/GHSA-4452-rwq3-2x44/GHSA-4452-rwq3-2x44.json create mode 100644 advisories/unreviewed/2025/03/GHSA-44q8-52gx-27g8/GHSA-44q8-52gx-27g8.json create mode 100644 advisories/unreviewed/2025/03/GHSA-45p5-8q33-98hw/GHSA-45p5-8q33-98hw.json create mode 100644 advisories/unreviewed/2025/03/GHSA-47f6-5p7h-5f3h/GHSA-47f6-5p7h-5f3h.json create mode 100644 advisories/unreviewed/2025/03/GHSA-49m6-vrr9-2cqm/GHSA-49m6-vrr9-2cqm.json create mode 100644 advisories/unreviewed/2025/03/GHSA-49rx-72gp-wfgj/GHSA-49rx-72gp-wfgj.json create mode 100644 advisories/unreviewed/2025/03/GHSA-4cv3-v7pv-rfhf/GHSA-4cv3-v7pv-rfhf.json create mode 100644 advisories/unreviewed/2025/03/GHSA-4cxc-r29p-3327/GHSA-4cxc-r29p-3327.json create mode 100644 advisories/unreviewed/2025/03/GHSA-4f3h-89pj-w84f/GHSA-4f3h-89pj-w84f.json create mode 100644 advisories/unreviewed/2025/03/GHSA-4g3f-9mfg-xxgh/GHSA-4g3f-9mfg-xxgh.json create mode 100644 advisories/unreviewed/2025/03/GHSA-4jr8-64gc-wqqx/GHSA-4jr8-64gc-wqqx.json create mode 100644 advisories/unreviewed/2025/03/GHSA-4qcx-jx49-6qrh/GHSA-4qcx-jx49-6qrh.json create mode 100644 advisories/unreviewed/2025/03/GHSA-4rj2-9gcx-5qhx/GHSA-4rj2-9gcx-5qhx.json create mode 100644 advisories/unreviewed/2025/03/GHSA-4rqf-8pfm-p36r/GHSA-4rqf-8pfm-p36r.json create mode 100644 advisories/unreviewed/2025/03/GHSA-4v9f-r55g-g6hc/GHSA-4v9f-r55g-g6hc.json create mode 100644 advisories/unreviewed/2025/03/GHSA-4vm5-r6m3-2448/GHSA-4vm5-r6m3-2448.json create mode 100644 advisories/unreviewed/2025/03/GHSA-4vmg-rw8f-92f9/GHSA-4vmg-rw8f-92f9.json create mode 100644 advisories/unreviewed/2025/03/GHSA-4vqf-pwq6-3wh3/GHSA-4vqf-pwq6-3wh3.json create mode 100644 advisories/unreviewed/2025/03/GHSA-4w44-j4vc-r3rp/GHSA-4w44-j4vc-r3rp.json create mode 100644 advisories/unreviewed/2025/03/GHSA-4wfj-v7c8-rwh4/GHSA-4wfj-v7c8-rwh4.json create mode 100644 advisories/unreviewed/2025/03/GHSA-53gh-p8jc-7rg8/GHSA-53gh-p8jc-7rg8.json create mode 100644 advisories/unreviewed/2025/03/GHSA-54c7-72v9-gm27/GHSA-54c7-72v9-gm27.json create mode 100644 advisories/unreviewed/2025/03/GHSA-54hh-fh2m-4396/GHSA-54hh-fh2m-4396.json create mode 100644 advisories/unreviewed/2025/03/GHSA-564p-rx2q-4c8v/GHSA-564p-rx2q-4c8v.json create mode 100644 advisories/unreviewed/2025/03/GHSA-56p4-cfqw-jx4h/GHSA-56p4-cfqw-jx4h.json create mode 100644 advisories/unreviewed/2025/03/GHSA-5c8j-g96x-cj78/GHSA-5c8j-g96x-cj78.json create mode 100644 advisories/unreviewed/2025/03/GHSA-5ccf-884p-4jjq/GHSA-5ccf-884p-4jjq.json create mode 100644 advisories/unreviewed/2025/03/GHSA-5chr-fjjv-38qv/GHSA-5chr-fjjv-38qv.json create mode 100644 advisories/unreviewed/2025/03/GHSA-5cpq-9538-jm2j/GHSA-5cpq-9538-jm2j.json create mode 100644 advisories/unreviewed/2025/03/GHSA-5fhx-jcwv-9wjj/GHSA-5fhx-jcwv-9wjj.json create mode 100644 advisories/unreviewed/2025/03/GHSA-5jmj-h3c5-682w/GHSA-5jmj-h3c5-682w.json create mode 100644 advisories/unreviewed/2025/03/GHSA-5mh3-rhm7-jxx3/GHSA-5mh3-rhm7-jxx3.json create mode 100644 advisories/unreviewed/2025/03/GHSA-5pfw-4vjf-fvc9/GHSA-5pfw-4vjf-fvc9.json create mode 100644 advisories/unreviewed/2025/03/GHSA-5v9m-57mq-qc75/GHSA-5v9m-57mq-qc75.json create mode 100644 advisories/unreviewed/2025/03/GHSA-5vqr-wprc-cpp7/GHSA-5vqr-wprc-cpp7.json create mode 100644 advisories/unreviewed/2025/03/GHSA-5xg7-5662-8x7j/GHSA-5xg7-5662-8x7j.json create mode 100644 advisories/unreviewed/2025/03/GHSA-62xp-4pcv-pw3j/GHSA-62xp-4pcv-pw3j.json create mode 100644 advisories/unreviewed/2025/03/GHSA-63gf-x2fr-8r32/GHSA-63gf-x2fr-8r32.json create mode 100644 advisories/unreviewed/2025/03/GHSA-64c5-jj57-f29g/GHSA-64c5-jj57-f29g.json create mode 100644 advisories/unreviewed/2025/03/GHSA-64jp-4xjj-prcw/GHSA-64jp-4xjj-prcw.json create mode 100644 advisories/unreviewed/2025/03/GHSA-67hg-xcw3-33fm/GHSA-67hg-xcw3-33fm.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6827-g8xf-36c7/GHSA-6827-g8xf-36c7.json create mode 100644 advisories/unreviewed/2025/03/GHSA-69j6-4w2p-2887/GHSA-69j6-4w2p-2887.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6ch3-c5vc-j2r6/GHSA-6ch3-c5vc-j2r6.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6f6x-f56q-5xgv/GHSA-6f6x-f56q-5xgv.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6fwx-j832-vvw6/GHSA-6fwx-j832-vvw6.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6gmf-2369-c76c/GHSA-6gmf-2369-c76c.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6mf6-7j75-2m6f/GHSA-6mf6-7j75-2m6f.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6pvw-p9fg-rwxj/GHSA-6pvw-p9fg-rwxj.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6rvg-6v2m-4j46/GHSA-6rvg-6v2m-4j46.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6v28-q95m-93qr/GHSA-6v28-q95m-93qr.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6vmm-pmxf-9784/GHSA-6vmm-pmxf-9784.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6w2c-f4vg-j9hv/GHSA-6w2c-f4vg-j9hv.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6w62-3jvj-mfj6/GHSA-6w62-3jvj-mfj6.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6w7p-xrvp-p7xv/GHSA-6w7p-xrvp-p7xv.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6wj5-5pgr-jwq8/GHSA-6wj5-5pgr-jwq8.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6xgj-c5fx-5v57/GHSA-6xgj-c5fx-5v57.json create mode 100644 advisories/unreviewed/2025/03/GHSA-726r-vfh2-3vvj/GHSA-726r-vfh2-3vvj.json create mode 100644 advisories/unreviewed/2025/03/GHSA-73c8-qmph-r39f/GHSA-73c8-qmph-r39f.json create mode 100644 advisories/unreviewed/2025/03/GHSA-73p4-hh43-4h48/GHSA-73p4-hh43-4h48.json create mode 100644 advisories/unreviewed/2025/03/GHSA-745f-48gc-258q/GHSA-745f-48gc-258q.json create mode 100644 advisories/unreviewed/2025/03/GHSA-747f-ww56-4q4h/GHSA-747f-ww56-4q4h.json create mode 100644 advisories/unreviewed/2025/03/GHSA-749v-xf6w-5wcx/GHSA-749v-xf6w-5wcx.json create mode 100644 advisories/unreviewed/2025/03/GHSA-75px-35p4-qq6h/GHSA-75px-35p4-qq6h.json create mode 100644 advisories/unreviewed/2025/03/GHSA-75v5-6885-59f9/GHSA-75v5-6885-59f9.json create mode 100644 advisories/unreviewed/2025/03/GHSA-775f-24cq-qg6p/GHSA-775f-24cq-qg6p.json create mode 100644 advisories/unreviewed/2025/03/GHSA-77cj-rv5x-v6r2/GHSA-77cj-rv5x-v6r2.json create mode 100644 advisories/unreviewed/2025/03/GHSA-79rp-v9rm-gxm8/GHSA-79rp-v9rm-gxm8.json create mode 100644 advisories/unreviewed/2025/03/GHSA-7g3f-q846-q9hx/GHSA-7g3f-q846-q9hx.json create mode 100644 advisories/unreviewed/2025/03/GHSA-7gj6-22m4-qfhx/GHSA-7gj6-22m4-qfhx.json create mode 100644 advisories/unreviewed/2025/03/GHSA-7h46-xxgg-f9q8/GHSA-7h46-xxgg-f9q8.json create mode 100644 advisories/unreviewed/2025/03/GHSA-7hc9-vjg2-vpcr/GHSA-7hc9-vjg2-vpcr.json create mode 100644 advisories/unreviewed/2025/03/GHSA-7j9v-mc62-mcm5/GHSA-7j9v-mc62-mcm5.json create mode 100644 advisories/unreviewed/2025/03/GHSA-7qq7-pvm9-x8rf/GHSA-7qq7-pvm9-x8rf.json create mode 100644 advisories/unreviewed/2025/03/GHSA-7rxf-gvfg-47g4/GHSA-7rxf-gvfg-47g4.json create mode 100644 advisories/unreviewed/2025/03/GHSA-7v2w-h4gh-w5cv/GHSA-7v2w-h4gh-w5cv.json create mode 100644 advisories/unreviewed/2025/03/GHSA-7xmc-vhjp-qv5q/GHSA-7xmc-vhjp-qv5q.json create mode 100644 advisories/unreviewed/2025/03/GHSA-823j-2wj6-7jwh/GHSA-823j-2wj6-7jwh.json create mode 100644 advisories/unreviewed/2025/03/GHSA-82mg-566w-vpxp/GHSA-82mg-566w-vpxp.json create mode 100644 advisories/unreviewed/2025/03/GHSA-85ff-r9hw-4grc/GHSA-85ff-r9hw-4grc.json create mode 100644 advisories/unreviewed/2025/03/GHSA-85jc-8h5p-8vw8/GHSA-85jc-8h5p-8vw8.json create mode 100644 advisories/unreviewed/2025/03/GHSA-873w-8cph-rghj/GHSA-873w-8cph-rghj.json create mode 100644 advisories/unreviewed/2025/03/GHSA-879v-fggm-vxw2/GHSA-879v-fggm-vxw2.json create mode 100644 advisories/unreviewed/2025/03/GHSA-89qx-m49c-8crf/GHSA-89qx-m49c-8crf.json create mode 100644 advisories/unreviewed/2025/03/GHSA-8f78-f6p2-mjw7/GHSA-8f78-f6p2-mjw7.json create mode 100644 advisories/unreviewed/2025/03/GHSA-8fw3-c8jq-g74q/GHSA-8fw3-c8jq-g74q.json create mode 100644 advisories/unreviewed/2025/03/GHSA-8gfh-hxjj-c33j/GHSA-8gfh-hxjj-c33j.json create mode 100644 advisories/unreviewed/2025/03/GHSA-8jhr-8vq6-2gp8/GHSA-8jhr-8vq6-2gp8.json create mode 100644 advisories/unreviewed/2025/03/GHSA-8pwp-phcg-h36g/GHSA-8pwp-phcg-h36g.json create mode 100644 advisories/unreviewed/2025/03/GHSA-8q24-hc9h-h952/GHSA-8q24-hc9h-h952.json create mode 100644 advisories/unreviewed/2025/03/GHSA-8qff-6gwc-wph3/GHSA-8qff-6gwc-wph3.json create mode 100644 advisories/unreviewed/2025/03/GHSA-8v6j-vg6w-6wwj/GHSA-8v6j-vg6w-6wwj.json create mode 100644 advisories/unreviewed/2025/03/GHSA-8vgw-p6qm-5gr7/GHSA-8vgw-p6qm-5gr7.json create mode 100644 advisories/unreviewed/2025/03/GHSA-8vjh-pxfw-4fqm/GHSA-8vjh-pxfw-4fqm.json create mode 100644 advisories/unreviewed/2025/03/GHSA-93qj-49fq-62jp/GHSA-93qj-49fq-62jp.json create mode 100644 advisories/unreviewed/2025/03/GHSA-959v-wfjp-7c37/GHSA-959v-wfjp-7c37.json create mode 100644 advisories/unreviewed/2025/03/GHSA-969w-gqqr-g6j3/GHSA-969w-gqqr-g6j3.json create mode 100644 advisories/unreviewed/2025/03/GHSA-96mw-rfcv-484q/GHSA-96mw-rfcv-484q.json create mode 100644 advisories/unreviewed/2025/03/GHSA-96w2-hg6w-6xv2/GHSA-96w2-hg6w-6xv2.json create mode 100644 advisories/unreviewed/2025/03/GHSA-97pg-wr4r-53wr/GHSA-97pg-wr4r-53wr.json create mode 100644 advisories/unreviewed/2025/03/GHSA-98fp-7v67-4v3q/GHSA-98fp-7v67-4v3q.json create mode 100644 advisories/unreviewed/2025/03/GHSA-9g44-gwvm-hc44/GHSA-9g44-gwvm-hc44.json create mode 100644 advisories/unreviewed/2025/03/GHSA-9gcr-28rp-cc24/GHSA-9gcr-28rp-cc24.json create mode 100644 advisories/unreviewed/2025/03/GHSA-9mhf-9hxp-8j3m/GHSA-9mhf-9hxp-8j3m.json create mode 100644 advisories/unreviewed/2025/03/GHSA-9vf8-xgwm-97r8/GHSA-9vf8-xgwm-97r8.json create mode 100644 advisories/unreviewed/2025/03/GHSA-9vwq-rwcj-cmcg/GHSA-9vwq-rwcj-cmcg.json create mode 100644 advisories/unreviewed/2025/03/GHSA-9w5h-67gf-xvv8/GHSA-9w5h-67gf-xvv8.json create mode 100644 advisories/unreviewed/2025/03/GHSA-9xvx-2953-c58g/GHSA-9xvx-2953-c58g.json create mode 100644 advisories/unreviewed/2025/03/GHSA-c2qr-w9p6-cxgr/GHSA-c2qr-w9p6-cxgr.json create mode 100644 advisories/unreviewed/2025/03/GHSA-c2xf-763v-3rqh/GHSA-c2xf-763v-3rqh.json create mode 100644 advisories/unreviewed/2025/03/GHSA-c39q-wr4f-xpw7/GHSA-c39q-wr4f-xpw7.json create mode 100644 advisories/unreviewed/2025/03/GHSA-c4cc-w454-4634/GHSA-c4cc-w454-4634.json create mode 100644 advisories/unreviewed/2025/03/GHSA-c7fq-p62p-wvpc/GHSA-c7fq-p62p-wvpc.json create mode 100644 advisories/unreviewed/2025/03/GHSA-c85g-5883-vjj7/GHSA-c85g-5883-vjj7.json create mode 100644 advisories/unreviewed/2025/03/GHSA-cfc5-c899-6ww2/GHSA-cfc5-c899-6ww2.json create mode 100644 advisories/unreviewed/2025/03/GHSA-cfvq-fj53-j2c7/GHSA-cfvq-fj53-j2c7.json create mode 100644 advisories/unreviewed/2025/03/GHSA-cg4p-5qfm-pjjj/GHSA-cg4p-5qfm-pjjj.json create mode 100644 advisories/unreviewed/2025/03/GHSA-chf7-q7m5-fq92/GHSA-chf7-q7m5-fq92.json create mode 100644 advisories/unreviewed/2025/03/GHSA-cj47-qj6g-x7r4/GHSA-cj47-qj6g-x7r4.json create mode 100644 advisories/unreviewed/2025/03/GHSA-cjjc-mf84-xp9f/GHSA-cjjc-mf84-xp9f.json create mode 100644 advisories/unreviewed/2025/03/GHSA-cppx-6f25-3qxc/GHSA-cppx-6f25-3qxc.json create mode 100644 advisories/unreviewed/2025/03/GHSA-crh6-pj8c-xrhc/GHSA-crh6-pj8c-xrhc.json create mode 100644 advisories/unreviewed/2025/03/GHSA-cvg9-334x-w586/GHSA-cvg9-334x-w586.json create mode 100644 advisories/unreviewed/2025/03/GHSA-cwc2-3f9g-phm3/GHSA-cwc2-3f9g-phm3.json create mode 100644 advisories/unreviewed/2025/03/GHSA-cx66-wgv6-fpfh/GHSA-cx66-wgv6-fpfh.json create mode 100644 advisories/unreviewed/2025/03/GHSA-f2v6-7vxr-j9g8/GHSA-f2v6-7vxr-j9g8.json create mode 100644 advisories/unreviewed/2025/03/GHSA-f3v2-jc5f-6328/GHSA-f3v2-jc5f-6328.json create mode 100644 advisories/unreviewed/2025/03/GHSA-f4hc-q562-cc5r/GHSA-f4hc-q562-cc5r.json create mode 100644 advisories/unreviewed/2025/03/GHSA-f64v-mwpx-gv6x/GHSA-f64v-mwpx-gv6x.json create mode 100644 advisories/unreviewed/2025/03/GHSA-f6rh-g2v9-v6qp/GHSA-f6rh-g2v9-v6qp.json create mode 100644 advisories/unreviewed/2025/03/GHSA-fccc-8m69-8r78/GHSA-fccc-8m69-8r78.json create mode 100644 advisories/unreviewed/2025/03/GHSA-ff5c-56m7-vc75/GHSA-ff5c-56m7-vc75.json create mode 100644 advisories/unreviewed/2025/03/GHSA-ffh5-w482-c7m5/GHSA-ffh5-w482-c7m5.json create mode 100644 advisories/unreviewed/2025/03/GHSA-fgqc-p7g9-x92w/GHSA-fgqc-p7g9-x92w.json create mode 100644 advisories/unreviewed/2025/03/GHSA-fh2c-86xm-pm2x/GHSA-fh2c-86xm-pm2x.json create mode 100644 advisories/unreviewed/2025/03/GHSA-fhfg-frx8-7458/GHSA-fhfg-frx8-7458.json create mode 100644 advisories/unreviewed/2025/03/GHSA-fjcf-3j3r-78rp/GHSA-fjcf-3j3r-78rp.json create mode 100644 advisories/unreviewed/2025/03/GHSA-fm93-g6xp-35xq/GHSA-fm93-g6xp-35xq.json create mode 100644 advisories/unreviewed/2025/03/GHSA-fqr7-jjqq-hpr6/GHSA-fqr7-jjqq-hpr6.json create mode 100644 advisories/unreviewed/2025/03/GHSA-fx47-jpv9-7hxr/GHSA-fx47-jpv9-7hxr.json create mode 100644 advisories/unreviewed/2025/03/GHSA-fxpx-7wrq-8ggp/GHSA-fxpx-7wrq-8ggp.json create mode 100644 advisories/unreviewed/2025/03/GHSA-g394-qpx6-x7rr/GHSA-g394-qpx6-x7rr.json create mode 100644 advisories/unreviewed/2025/03/GHSA-g3mx-83mp-3rwc/GHSA-g3mx-83mp-3rwc.json create mode 100644 advisories/unreviewed/2025/03/GHSA-g3p7-f346-26m6/GHSA-g3p7-f346-26m6.json create mode 100644 advisories/unreviewed/2025/03/GHSA-g3v3-r244-mhhm/GHSA-g3v3-r244-mhhm.json create mode 100644 advisories/unreviewed/2025/03/GHSA-g44m-hpf4-vmrp/GHSA-g44m-hpf4-vmrp.json create mode 100644 advisories/unreviewed/2025/03/GHSA-g48v-3p35-88jr/GHSA-g48v-3p35-88jr.json create mode 100644 advisories/unreviewed/2025/03/GHSA-g5pg-73fc-hjwq/GHSA-g5pg-73fc-hjwq.json create mode 100644 advisories/unreviewed/2025/03/GHSA-g9c4-qhpw-x7pw/GHSA-g9c4-qhpw-x7pw.json create mode 100644 advisories/unreviewed/2025/03/GHSA-gc79-m262-q226/GHSA-gc79-m262-q226.json create mode 100644 advisories/unreviewed/2025/03/GHSA-gf99-rrrr-wjqh/GHSA-gf99-rrrr-wjqh.json create mode 100644 advisories/unreviewed/2025/03/GHSA-gg5q-w3xv-q3f4/GHSA-gg5q-w3xv-q3f4.json create mode 100644 advisories/unreviewed/2025/03/GHSA-gggj-77q9-hf6x/GHSA-gggj-77q9-hf6x.json create mode 100644 advisories/unreviewed/2025/03/GHSA-gh22-g6w4-m562/GHSA-gh22-g6w4-m562.json create mode 100644 advisories/unreviewed/2025/03/GHSA-gj27-76gq-5v3p/GHSA-gj27-76gq-5v3p.json create mode 100644 advisories/unreviewed/2025/03/GHSA-gjxm-x497-4h6h/GHSA-gjxm-x497-4h6h.json create mode 100644 advisories/unreviewed/2025/03/GHSA-gmqg-7635-v6cj/GHSA-gmqg-7635-v6cj.json create mode 100644 advisories/unreviewed/2025/03/GHSA-grjq-mg5m-r4jj/GHSA-grjq-mg5m-r4jj.json create mode 100644 advisories/unreviewed/2025/03/GHSA-gv26-qw3h-8qvp/GHSA-gv26-qw3h-8qvp.json create mode 100644 advisories/unreviewed/2025/03/GHSA-gvmg-6fvg-2jp2/GHSA-gvmg-6fvg-2jp2.json create mode 100644 advisories/unreviewed/2025/03/GHSA-gw2q-qw9j-rgv7/GHSA-gw2q-qw9j-rgv7.json create mode 100644 advisories/unreviewed/2025/03/GHSA-h254-g997-685c/GHSA-h254-g997-685c.json create mode 100644 advisories/unreviewed/2025/03/GHSA-h35f-g2pq-8xq7/GHSA-h35f-g2pq-8xq7.json create mode 100644 advisories/unreviewed/2025/03/GHSA-h36j-8vv3-cj52/GHSA-h36j-8vv3-cj52.json create mode 100644 advisories/unreviewed/2025/03/GHSA-h4p8-798h-26f4/GHSA-h4p8-798h-26f4.json create mode 100644 advisories/unreviewed/2025/03/GHSA-h4x7-365q-3rm3/GHSA-h4x7-365q-3rm3.json create mode 100644 advisories/unreviewed/2025/03/GHSA-h5h7-gc2g-vq79/GHSA-h5h7-gc2g-vq79.json create mode 100644 advisories/unreviewed/2025/03/GHSA-h5jv-6xg2-9cv8/GHSA-h5jv-6xg2-9cv8.json create mode 100644 advisories/unreviewed/2025/03/GHSA-h5p2-273c-rxjp/GHSA-h5p2-273c-rxjp.json create mode 100644 advisories/unreviewed/2025/03/GHSA-h7xg-cmpp-48hf/GHSA-h7xg-cmpp-48hf.json create mode 100644 advisories/unreviewed/2025/03/GHSA-h9jx-rcv4-cgqg/GHSA-h9jx-rcv4-cgqg.json create mode 100644 advisories/unreviewed/2025/03/GHSA-h9m7-c24m-gqr9/GHSA-h9m7-c24m-gqr9.json create mode 100644 advisories/unreviewed/2025/03/GHSA-hc5x-x2vx-497g/GHSA-hc5x-x2vx-497g.json create mode 100644 advisories/unreviewed/2025/03/GHSA-hc9x-f65g-gjqh/GHSA-hc9x-f65g-gjqh.json create mode 100644 advisories/unreviewed/2025/03/GHSA-hh3j-9m59-p8vc/GHSA-hh3j-9m59-p8vc.json create mode 100644 advisories/unreviewed/2025/03/GHSA-hhr6-7642-8pmh/GHSA-hhr6-7642-8pmh.json create mode 100644 advisories/unreviewed/2025/03/GHSA-hhw5-29f6-hf4x/GHSA-hhw5-29f6-hf4x.json create mode 100644 advisories/unreviewed/2025/03/GHSA-hjcr-w68h-rg2p/GHSA-hjcr-w68h-rg2p.json create mode 100644 advisories/unreviewed/2025/03/GHSA-hm5x-x82r-982c/GHSA-hm5x-x82r-982c.json create mode 100644 advisories/unreviewed/2025/03/GHSA-hq38-64gm-3w2c/GHSA-hq38-64gm-3w2c.json create mode 100644 advisories/unreviewed/2025/03/GHSA-hw3w-6mhf-rh8m/GHSA-hw3w-6mhf-rh8m.json create mode 100644 advisories/unreviewed/2025/03/GHSA-hw8j-hw49-752c/GHSA-hw8j-hw49-752c.json create mode 100644 advisories/unreviewed/2025/03/GHSA-hx67-j5pj-h8ch/GHSA-hx67-j5pj-h8ch.json create mode 100644 advisories/unreviewed/2025/03/GHSA-j274-m559-cj4j/GHSA-j274-m559-cj4j.json create mode 100644 advisories/unreviewed/2025/03/GHSA-j3jw-5w88-cqxr/GHSA-j3jw-5w88-cqxr.json create mode 100644 advisories/unreviewed/2025/03/GHSA-j3wr-m6xh-64hg/GHSA-j3wr-m6xh-64hg.json create mode 100644 advisories/unreviewed/2025/03/GHSA-j46h-c723-q9rm/GHSA-j46h-c723-q9rm.json create mode 100644 advisories/unreviewed/2025/03/GHSA-j4mc-gwfc-jcf5/GHSA-j4mc-gwfc-jcf5.json create mode 100644 advisories/unreviewed/2025/03/GHSA-j5fq-p3c6-93jm/GHSA-j5fq-p3c6-93jm.json create mode 100644 advisories/unreviewed/2025/03/GHSA-j5qj-rg5j-j7c2/GHSA-j5qj-rg5j-j7c2.json create mode 100644 advisories/unreviewed/2025/03/GHSA-j8gf-4j8g-8mvp/GHSA-j8gf-4j8g-8mvp.json create mode 100644 advisories/unreviewed/2025/03/GHSA-j8x9-qc9m-rmhj/GHSA-j8x9-qc9m-rmhj.json create mode 100644 advisories/unreviewed/2025/03/GHSA-j9g7-mqhh-9hxf/GHSA-j9g7-mqhh-9hxf.json create mode 100644 advisories/unreviewed/2025/03/GHSA-j9rw-qm5f-r8xm/GHSA-j9rw-qm5f-r8xm.json create mode 100644 advisories/unreviewed/2025/03/GHSA-jccx-m9v4-9hwh/GHSA-jccx-m9v4-9hwh.json create mode 100644 advisories/unreviewed/2025/03/GHSA-jfm2-hq55-pxgq/GHSA-jfm2-hq55-pxgq.json create mode 100644 advisories/unreviewed/2025/03/GHSA-jg5r-v2h9-wfxx/GHSA-jg5r-v2h9-wfxx.json create mode 100644 advisories/unreviewed/2025/03/GHSA-jjcv-gwx7-hcx9/GHSA-jjcv-gwx7-hcx9.json create mode 100644 advisories/unreviewed/2025/03/GHSA-jjhp-4v9p-5fv8/GHSA-jjhp-4v9p-5fv8.json create mode 100644 advisories/unreviewed/2025/03/GHSA-jjm2-vhrm-92vg/GHSA-jjm2-vhrm-92vg.json create mode 100644 advisories/unreviewed/2025/03/GHSA-jm82-665g-74jp/GHSA-jm82-665g-74jp.json create mode 100644 advisories/unreviewed/2025/03/GHSA-jm87-8wm6-fr27/GHSA-jm87-8wm6-fr27.json create mode 100644 advisories/unreviewed/2025/03/GHSA-jmgm-gx32-vp4w/GHSA-jmgm-gx32-vp4w.json create mode 100644 advisories/unreviewed/2025/03/GHSA-jqgv-3ch9-c9qv/GHSA-jqgv-3ch9-c9qv.json create mode 100644 advisories/unreviewed/2025/03/GHSA-jrhc-9qg9-4qfq/GHSA-jrhc-9qg9-4qfq.json create mode 100644 advisories/unreviewed/2025/03/GHSA-jrhv-8gfh-55w6/GHSA-jrhv-8gfh-55w6.json create mode 100644 advisories/unreviewed/2025/03/GHSA-jv2r-r6r9-hvhj/GHSA-jv2r-r6r9-hvhj.json create mode 100644 advisories/unreviewed/2025/03/GHSA-jvpf-xf32-2w4q/GHSA-jvpf-xf32-2w4q.json create mode 100644 advisories/unreviewed/2025/03/GHSA-jw8w-84x3-c2r9/GHSA-jw8w-84x3-c2r9.json create mode 100644 advisories/unreviewed/2025/03/GHSA-jx9r-x782-9r4m/GHSA-jx9r-x782-9r4m.json create mode 100644 advisories/unreviewed/2025/03/GHSA-m2g8-2vhm-m4cx/GHSA-m2g8-2vhm-m4cx.json create mode 100644 advisories/unreviewed/2025/03/GHSA-m2gm-4vg9-pcc4/GHSA-m2gm-4vg9-pcc4.json create mode 100644 advisories/unreviewed/2025/03/GHSA-m2v2-9gxp-2r53/GHSA-m2v2-9gxp-2r53.json create mode 100644 advisories/unreviewed/2025/03/GHSA-m37h-8r48-2cxj/GHSA-m37h-8r48-2cxj.json create mode 100644 advisories/unreviewed/2025/03/GHSA-m47g-ghr5-3734/GHSA-m47g-ghr5-3734.json create mode 100644 advisories/unreviewed/2025/03/GHSA-m62f-m76v-gfwr/GHSA-m62f-m76v-gfwr.json create mode 100644 advisories/unreviewed/2025/03/GHSA-m724-88wc-fpgh/GHSA-m724-88wc-fpgh.json create mode 100644 advisories/unreviewed/2025/03/GHSA-m724-hqmc-ggpx/GHSA-m724-hqmc-ggpx.json create mode 100644 advisories/unreviewed/2025/03/GHSA-m74w-gj86-32q9/GHSA-m74w-gj86-32q9.json create mode 100644 advisories/unreviewed/2025/03/GHSA-m76r-xqqj-mqmv/GHSA-m76r-xqqj-mqmv.json create mode 100644 advisories/unreviewed/2025/03/GHSA-mc9m-5hw4-g3g6/GHSA-mc9m-5hw4-g3g6.json create mode 100644 advisories/unreviewed/2025/03/GHSA-mf57-6hg5-mrvm/GHSA-mf57-6hg5-mrvm.json create mode 100644 advisories/unreviewed/2025/03/GHSA-mhmr-w8pp-75w5/GHSA-mhmr-w8pp-75w5.json create mode 100644 advisories/unreviewed/2025/03/GHSA-mj67-2mvx-f778/GHSA-mj67-2mvx-f778.json create mode 100644 advisories/unreviewed/2025/03/GHSA-mjvp-pg3h-wh59/GHSA-mjvp-pg3h-wh59.json create mode 100644 advisories/unreviewed/2025/03/GHSA-mq4w-5hp5-6g52/GHSA-mq4w-5hp5-6g52.json create mode 100644 advisories/unreviewed/2025/03/GHSA-mq78-p977-pwgv/GHSA-mq78-p977-pwgv.json create mode 100644 advisories/unreviewed/2025/03/GHSA-mq8r-j55w-fv46/GHSA-mq8r-j55w-fv46.json create mode 100644 advisories/unreviewed/2025/03/GHSA-mqp7-6vh9-99r6/GHSA-mqp7-6vh9-99r6.json create mode 100644 advisories/unreviewed/2025/03/GHSA-mrhh-3ggq-23p2/GHSA-mrhh-3ggq-23p2.json create mode 100644 advisories/unreviewed/2025/03/GHSA-mrvr-7493-pfq3/GHSA-mrvr-7493-pfq3.json create mode 100644 advisories/unreviewed/2025/03/GHSA-mvp8-9qgw-vf58/GHSA-mvp8-9qgw-vf58.json create mode 100644 advisories/unreviewed/2025/03/GHSA-p2f3-rm9r-rxgj/GHSA-p2f3-rm9r-rxgj.json create mode 100644 advisories/unreviewed/2025/03/GHSA-p2vc-m5fv-9w9m/GHSA-p2vc-m5fv-9w9m.json create mode 100644 advisories/unreviewed/2025/03/GHSA-p2wh-w96x-w232/GHSA-p2wh-w96x-w232.json create mode 100644 advisories/unreviewed/2025/03/GHSA-p5vx-9hj8-cf4h/GHSA-p5vx-9hj8-cf4h.json create mode 100644 advisories/unreviewed/2025/03/GHSA-p6h7-hfj2-vmcf/GHSA-p6h7-hfj2-vmcf.json create mode 100644 advisories/unreviewed/2025/03/GHSA-p6x3-v6g3-7557/GHSA-p6x3-v6g3-7557.json create mode 100644 advisories/unreviewed/2025/03/GHSA-p868-p9pj-fvmr/GHSA-p868-p9pj-fvmr.json create mode 100644 advisories/unreviewed/2025/03/GHSA-p926-8677-385w/GHSA-p926-8677-385w.json create mode 100644 advisories/unreviewed/2025/03/GHSA-pgfv-gvc5-prfg/GHSA-pgfv-gvc5-prfg.json create mode 100644 advisories/unreviewed/2025/03/GHSA-pgr7-mhp5-fgjp/GHSA-pgr7-mhp5-fgjp.json create mode 100644 advisories/unreviewed/2025/03/GHSA-ph84-8v89-25q8/GHSA-ph84-8v89-25q8.json create mode 100644 advisories/unreviewed/2025/03/GHSA-pqwr-phvv-v49f/GHSA-pqwr-phvv-v49f.json create mode 100644 advisories/unreviewed/2025/03/GHSA-prpg-p95c-32fv/GHSA-prpg-p95c-32fv.json create mode 100644 advisories/unreviewed/2025/03/GHSA-prx2-6cc4-7qq5/GHSA-prx2-6cc4-7qq5.json create mode 100644 advisories/unreviewed/2025/03/GHSA-q36w-fgp3-q2gw/GHSA-q36w-fgp3-q2gw.json create mode 100644 advisories/unreviewed/2025/03/GHSA-q3gw-8236-5jw4/GHSA-q3gw-8236-5jw4.json create mode 100644 advisories/unreviewed/2025/03/GHSA-q5v7-7r3x-m7hg/GHSA-q5v7-7r3x-m7hg.json create mode 100644 advisories/unreviewed/2025/03/GHSA-q67c-vgg7-pvrq/GHSA-q67c-vgg7-pvrq.json create mode 100644 advisories/unreviewed/2025/03/GHSA-q6gg-j289-2hm4/GHSA-q6gg-j289-2hm4.json create mode 100644 advisories/unreviewed/2025/03/GHSA-q73m-3cg7-m23w/GHSA-q73m-3cg7-m23w.json create mode 100644 advisories/unreviewed/2025/03/GHSA-q88j-ff64-2m3q/GHSA-q88j-ff64-2m3q.json create mode 100644 advisories/unreviewed/2025/03/GHSA-q8pp-mmm3-9j9w/GHSA-q8pp-mmm3-9j9w.json create mode 100644 advisories/unreviewed/2025/03/GHSA-qccg-9m4q-xfm6/GHSA-qccg-9m4q-xfm6.json create mode 100644 advisories/unreviewed/2025/03/GHSA-qg86-f892-m4hj/GHSA-qg86-f892-m4hj.json create mode 100644 advisories/unreviewed/2025/03/GHSA-qgm6-wj98-3qh4/GHSA-qgm6-wj98-3qh4.json create mode 100644 advisories/unreviewed/2025/03/GHSA-qhfv-rxrj-6w5f/GHSA-qhfv-rxrj-6w5f.json create mode 100644 advisories/unreviewed/2025/03/GHSA-qjq5-7g6p-p3vg/GHSA-qjq5-7g6p-p3vg.json create mode 100644 advisories/unreviewed/2025/03/GHSA-qv9p-39px-hfwc/GHSA-qv9p-39px-hfwc.json create mode 100644 advisories/unreviewed/2025/03/GHSA-qvg9-vp87-h3hr/GHSA-qvg9-vp87-h3hr.json create mode 100644 advisories/unreviewed/2025/03/GHSA-r229-5wgf-f28g/GHSA-r229-5wgf-f28g.json create mode 100644 advisories/unreviewed/2025/03/GHSA-r3hj-whx4-hvvj/GHSA-r3hj-whx4-hvvj.json create mode 100644 advisories/unreviewed/2025/03/GHSA-r49j-4jpw-x35c/GHSA-r49j-4jpw-x35c.json create mode 100644 advisories/unreviewed/2025/03/GHSA-r4hm-vcvh-rm39/GHSA-r4hm-vcvh-rm39.json create mode 100644 advisories/unreviewed/2025/03/GHSA-r9m5-fcw8-68f6/GHSA-r9m5-fcw8-68f6.json create mode 100644 advisories/unreviewed/2025/03/GHSA-rc69-h6h5-3q4x/GHSA-rc69-h6h5-3q4x.json create mode 100644 advisories/unreviewed/2025/03/GHSA-rm69-wvpv-r2w7/GHSA-rm69-wvpv-r2w7.json create mode 100644 advisories/unreviewed/2025/03/GHSA-rqhc-x44r-f23j/GHSA-rqhc-x44r-f23j.json create mode 100644 advisories/unreviewed/2025/03/GHSA-rqrm-p43g-fpmq/GHSA-rqrm-p43g-fpmq.json create mode 100644 advisories/unreviewed/2025/03/GHSA-rrfw-qqmx-gqwx/GHSA-rrfw-qqmx-gqwx.json create mode 100644 advisories/unreviewed/2025/03/GHSA-rv4f-crjq-xjf8/GHSA-rv4f-crjq-xjf8.json create mode 100644 advisories/unreviewed/2025/03/GHSA-rvgh-pr46-x7gg/GHSA-rvgh-pr46-x7gg.json create mode 100644 advisories/unreviewed/2025/03/GHSA-rvmr-crph-7vj2/GHSA-rvmr-crph-7vj2.json create mode 100644 advisories/unreviewed/2025/03/GHSA-rxwh-3m8p-2qq5/GHSA-rxwh-3m8p-2qq5.json create mode 100644 advisories/unreviewed/2025/03/GHSA-v3f4-7pp9-6f99/GHSA-v3f4-7pp9-6f99.json create mode 100644 advisories/unreviewed/2025/03/GHSA-v464-r2r9-www7/GHSA-v464-r2r9-www7.json create mode 100644 advisories/unreviewed/2025/03/GHSA-v5pj-jrpv-h6g2/GHSA-v5pj-jrpv-h6g2.json create mode 100644 advisories/unreviewed/2025/03/GHSA-v67x-89x7-mh47/GHSA-v67x-89x7-mh47.json create mode 100644 advisories/unreviewed/2025/03/GHSA-vffc-qpx3-764c/GHSA-vffc-qpx3-764c.json create mode 100644 advisories/unreviewed/2025/03/GHSA-vh85-qfmh-23mf/GHSA-vh85-qfmh-23mf.json create mode 100644 advisories/unreviewed/2025/03/GHSA-vhfq-gpqw-p5cw/GHSA-vhfq-gpqw-p5cw.json create mode 100644 advisories/unreviewed/2025/03/GHSA-vpg6-7cch-gq2j/GHSA-vpg6-7cch-gq2j.json create mode 100644 advisories/unreviewed/2025/03/GHSA-vq2g-prvr-rgr4/GHSA-vq2g-prvr-rgr4.json create mode 100644 advisories/unreviewed/2025/03/GHSA-vqqv-6pvc-4m7q/GHSA-vqqv-6pvc-4m7q.json create mode 100644 advisories/unreviewed/2025/03/GHSA-vrw3-r7jw-4785/GHSA-vrw3-r7jw-4785.json create mode 100644 advisories/unreviewed/2025/03/GHSA-vx9q-6hqp-j863/GHSA-vx9q-6hqp-j863.json create mode 100644 advisories/unreviewed/2025/03/GHSA-w3m9-crxx-972f/GHSA-w3m9-crxx-972f.json create mode 100644 advisories/unreviewed/2025/03/GHSA-w466-2wfc-8g58/GHSA-w466-2wfc-8g58.json create mode 100644 advisories/unreviewed/2025/03/GHSA-w4cv-4jm4-pg8h/GHSA-w4cv-4jm4-pg8h.json create mode 100644 advisories/unreviewed/2025/03/GHSA-w6hh-w36c-vxmw/GHSA-w6hh-w36c-vxmw.json create mode 100644 advisories/unreviewed/2025/03/GHSA-w6r4-j5cm-c7fp/GHSA-w6r4-j5cm-c7fp.json create mode 100644 advisories/unreviewed/2025/03/GHSA-wcwp-9rcp-jvfg/GHSA-wcwp-9rcp-jvfg.json create mode 100644 advisories/unreviewed/2025/03/GHSA-wjpv-64v2-2qpq/GHSA-wjpv-64v2-2qpq.json create mode 100644 advisories/unreviewed/2025/03/GHSA-wmc2-c6g2-9mf2/GHSA-wmc2-c6g2-9mf2.json create mode 100644 advisories/unreviewed/2025/03/GHSA-wr4v-pc76-3q4p/GHSA-wr4v-pc76-3q4p.json create mode 100644 advisories/unreviewed/2025/03/GHSA-wwr9-4gmr-xvq9/GHSA-wwr9-4gmr-xvq9.json create mode 100644 advisories/unreviewed/2025/03/GHSA-wxpc-2674-rxvw/GHSA-wxpc-2674-rxvw.json create mode 100644 advisories/unreviewed/2025/03/GHSA-x2w2-frfv-4f2j/GHSA-x2w2-frfv-4f2j.json create mode 100644 advisories/unreviewed/2025/03/GHSA-x48g-hm9c-ww42/GHSA-x48g-hm9c-ww42.json create mode 100644 advisories/unreviewed/2025/03/GHSA-x552-5vh8-qccx/GHSA-x552-5vh8-qccx.json create mode 100644 advisories/unreviewed/2025/03/GHSA-x5xw-28w4-53j5/GHSA-x5xw-28w4-53j5.json create mode 100644 advisories/unreviewed/2025/03/GHSA-x757-hv69-jr45/GHSA-x757-hv69-jr45.json create mode 100644 advisories/unreviewed/2025/03/GHSA-x7c5-9r9g-pghj/GHSA-x7c5-9r9g-pghj.json create mode 100644 advisories/unreviewed/2025/03/GHSA-x9hf-jr2h-w47p/GHSA-x9hf-jr2h-w47p.json create mode 100644 advisories/unreviewed/2025/03/GHSA-xcp6-jv5m-jwrm/GHSA-xcp6-jv5m-jwrm.json create mode 100644 advisories/unreviewed/2025/03/GHSA-xfjg-gcvp-vw7p/GHSA-xfjg-gcvp-vw7p.json create mode 100644 advisories/unreviewed/2025/03/GHSA-xqgj-r6xv-9cw4/GHSA-xqgj-r6xv-9cw4.json create mode 100644 advisories/unreviewed/2025/03/GHSA-xv4c-2443-pc28/GHSA-xv4c-2443-pc28.json create mode 100644 advisories/unreviewed/2025/03/GHSA-xx7c-j7h3-vjcq/GHSA-xx7c-j7h3-vjcq.json diff --git a/advisories/unreviewed/2024/03/GHSA-9x24-7fgc-x3vc/GHSA-9x24-7fgc-x3vc.json b/advisories/unreviewed/2024/03/GHSA-9x24-7fgc-x3vc/GHSA-9x24-7fgc-x3vc.json index 0e142a9be9c..9ed222139ba 100644 --- a/advisories/unreviewed/2024/03/GHSA-9x24-7fgc-x3vc/GHSA-9x24-7fgc-x3vc.json +++ b/advisories/unreviewed/2024/03/GHSA-9x24-7fgc-x3vc/GHSA-9x24-7fgc-x3vc.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-8vf4-q8g2-79g5/GHSA-8vf4-q8g2-79g5.json b/advisories/unreviewed/2024/04/GHSA-8vf4-q8g2-79g5/GHSA-8vf4-q8g2-79g5.json index df713b62b19..8b896403e05 100644 --- a/advisories/unreviewed/2024/04/GHSA-8vf4-q8g2-79g5/GHSA-8vf4-q8g2-79g5.json +++ b/advisories/unreviewed/2024/04/GHSA-8vf4-q8g2-79g5/GHSA-8vf4-q8g2-79g5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8vf4-q8g2-79g5", - "modified": "2024-06-26T00:31:36Z", + "modified": "2025-03-20T12:32:37Z", "published": "2024-04-04T09:30:35Z", "aliases": [ "CVE-2024-26787" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmmc: mmci: stm32: fix DMA API overlapping mappings warning\n\nTurning on CONFIG_DMA_API_DEBUG_SG results in the following warning:\n\nDMA-API: mmci-pl18x 48220000.mmc: cacheline tracking EEXIST,\noverlapping mappings aren't supported\nWARNING: CPU: 1 PID: 51 at kernel/dma/debug.c:568\nadd_dma_entry+0x234/0x2f4\nModules linked in:\nCPU: 1 PID: 51 Comm: kworker/1:2 Not tainted 6.1.28 #1\nHardware name: STMicroelectronics STM32MP257F-EV1 Evaluation Board (DT)\nWorkqueue: events_freezable mmc_rescan\nCall trace:\nadd_dma_entry+0x234/0x2f4\ndebug_dma_map_sg+0x198/0x350\n__dma_map_sg_attrs+0xa0/0x110\ndma_map_sg_attrs+0x10/0x2c\nsdmmc_idma_prep_data+0x80/0xc0\nmmci_prep_data+0x38/0x84\nmmci_start_data+0x108/0x2dc\nmmci_request+0xe4/0x190\n__mmc_start_request+0x68/0x140\nmmc_start_request+0x94/0xc0\nmmc_wait_for_req+0x70/0x100\nmmc_send_tuning+0x108/0x1ac\nsdmmc_execute_tuning+0x14c/0x210\nmmc_execute_tuning+0x48/0xec\nmmc_sd_init_uhs_card.part.0+0x208/0x464\nmmc_sd_init_card+0x318/0x89c\nmmc_attach_sd+0xe4/0x180\nmmc_rescan+0x244/0x320\n\nDMA API debug brings to light leaking dma-mappings as dma_map_sg and\ndma_unmap_sg are not correctly balanced.\n\nIf an error occurs in mmci_cmd_irq function, only mmci_dma_error\nfunction is called and as this API is not managed on stm32 variant,\ndma_unmap_sg is never called in this error path.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -45,7 +50,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-04T09:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-hw9j-mg68-r593/GHSA-hw9j-mg68-r593.json b/advisories/unreviewed/2024/04/GHSA-hw9j-mg68-r593/GHSA-hw9j-mg68-r593.json index 777d26e580a..f7e576c8596 100644 --- a/advisories/unreviewed/2024/04/GHSA-hw9j-mg68-r593/GHSA-hw9j-mg68-r593.json +++ b/advisories/unreviewed/2024/04/GHSA-hw9j-mg68-r593/GHSA-hw9j-mg68-r593.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-hw9j-mg68-r593", - "modified": "2024-04-07T18:30:30Z", + "modified": "2025-03-20T12:32:37Z", "published": "2024-04-07T18:30:30Z", "aliases": [ "CVE-2024-31296" ], - "details": "Authorization Bypass Through User-Controlled Key vulnerability in Repute Infosystems BookingPress.This issue affects BookingPress: from n/a through 1.0.81.\n\n", + "details": "Authorization Bypass Through User-Controlled Key vulnerability in Repute Infosystems BookingPress.This issue affects BookingPress: from n/a through 1.0.81.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2025/03/GHSA-227r-w5j2-6243/GHSA-227r-w5j2-6243.json b/advisories/unreviewed/2025/03/GHSA-227r-w5j2-6243/GHSA-227r-w5j2-6243.json new file mode 100644 index 00000000000..57a643f0652 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-227r-w5j2-6243/GHSA-227r-w5j2-6243.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-227r-w5j2-6243", + "modified": "2025-03-20T12:32:41Z", + "published": "2025-03-20T12:32:41Z", + "aliases": [ + "CVE-2024-11042" + ], + "details": "In invoke-ai/invokeai version v5.0.2, the web API `POST /api/v1/images/delete` is vulnerable to Arbitrary File Deletion. This vulnerability allows unauthorized attackers to delete arbitrary files on the server, potentially including critical or sensitive system files such as SSH keys, SQLite databases, and configuration files. This can impact the integrity and availability of applications relying on these files.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11042" + }, + { + "type": "WEB", + "url": "https://github.com/invoke-ai/invokeai/commit/5440c037674882b2ab7acd59087e9bb04b49657a" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/635535a7-c804-4789-ac3a-48d951263987" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-22h9-9rvv-q9qg/GHSA-22h9-9rvv-q9qg.json b/advisories/unreviewed/2025/03/GHSA-22h9-9rvv-q9qg/GHSA-22h9-9rvv-q9qg.json new file mode 100644 index 00000000000..2a95c73a4a0 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-22h9-9rvv-q9qg/GHSA-22h9-9rvv-q9qg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-22h9-9rvv-q9qg", + "modified": "2025-03-20T12:32:42Z", + "published": "2025-03-20T12:32:42Z", + "aliases": [ + "CVE-2024-11449" + ], + "details": "A vulnerability in haotian-liu/llava version 1.2.0 (LLaVA-1.6) allows for Server-Side Request Forgery (SSRF) through the /run/predict endpoint. An attacker can gain unauthorized access to internal networks or the AWS metadata endpoint by sending crafted requests that exploit insufficient validation of the path parameter. This flaw can lead to unauthorized network access, sensitive data exposure, and further exploitation within the network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11449" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/e96aba28-d564-4ecb-ab77-350511d2e1ee" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-29rg-m5qv-57gx/GHSA-29rg-m5qv-57gx.json b/advisories/unreviewed/2025/03/GHSA-29rg-m5qv-57gx/GHSA-29rg-m5qv-57gx.json new file mode 100644 index 00000000000..ea634179fb9 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-29rg-m5qv-57gx/GHSA-29rg-m5qv-57gx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-29rg-m5qv-57gx", + "modified": "2025-03-20T12:32:40Z", + "published": "2025-03-20T12:32:40Z", + "aliases": [ + "CVE-2024-10819" + ], + "details": "A Cross-Site Request Forgery (CSRF) vulnerability in version 3.83 of binary-husky/gpt_academic allows an attacker to trick a user into uploading files without their consent, exploiting their session. This can lead to unauthorized file uploads and potential system compromise. The uploaded file can contain malicious scripts, leading to stored Cross-Site Scripting (XSS) attacks. Through stored XSS, an attacker can steal information about the victim and perform any action on their behalf.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10819" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/45270c4b-a500-4374-a90b-37b604a3ace0" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-2c36-wq4v-5v3h/GHSA-2c36-wq4v-5v3h.json b/advisories/unreviewed/2025/03/GHSA-2c36-wq4v-5v3h/GHSA-2c36-wq4v-5v3h.json new file mode 100644 index 00000000000..20d5c91317a --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-2c36-wq4v-5v3h/GHSA-2c36-wq4v-5v3h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2c36-wq4v-5v3h", + "modified": "2025-03-20T12:32:47Z", + "published": "2025-03-20T12:32:46Z", + "aliases": [ + "CVE-2024-7819" + ], + "details": "A CORS misconfiguration in danswer-ai/danswer v1.4.1 allows attackers to steal sensitive information such as chat contents, API keys, and other data. This vulnerability occurs due to improper validation of the origin header, enabling malicious web pages to make unauthorized requests to the application's API.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7819" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/06a21857-e13f-4cf4-aa67-de11419a98c0" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-346" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-2mv8-c3hx-xq6v/GHSA-2mv8-c3hx-xq6v.json b/advisories/unreviewed/2025/03/GHSA-2mv8-c3hx-xq6v/GHSA-2mv8-c3hx-xq6v.json new file mode 100644 index 00000000000..0df44f27314 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-2mv8-c3hx-xq6v/GHSA-2mv8-c3hx-xq6v.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2mv8-c3hx-xq6v", + "modified": "2025-03-20T12:32:47Z", + "published": "2025-03-20T12:32:47Z", + "aliases": [ + "CVE-2024-8196" + ], + "details": "In mintplex-labs/anything-llm v1.5.11 desktop version for Windows, the application opens server port 3001 on 0.0.0.0 with no authentication by default. This vulnerability allows an attacker to gain full backend access, enabling them to perform actions such as deleting all data from the workspace.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8196" + }, + { + "type": "WEB", + "url": "https://github.com/mintplex-labs/anything-llm/commit/9bfe477f10b188bfe3508ac29105df80d4522ece" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/dbde1c71-7aa5-46f6-847a-d89793cf97a9" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-2rr7-xrrm-67cf/GHSA-2rr7-xrrm-67cf.json b/advisories/unreviewed/2025/03/GHSA-2rr7-xrrm-67cf/GHSA-2rr7-xrrm-67cf.json new file mode 100644 index 00000000000..cf48dc349ec --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-2rr7-xrrm-67cf/GHSA-2rr7-xrrm-67cf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2rr7-xrrm-67cf", + "modified": "2025-03-20T12:32:47Z", + "published": "2025-03-20T12:32:47Z", + "aliases": [ + "CVE-2024-8018" + ], + "details": "A vulnerability in imartinez/privategpt version 0.5.0 allows for a Denial of Service (DOS) attack. When uploading a file, if an attacker appends a large number of characters to the end of a multipart boundary, the system will continuously process these characters, rendering privateGPT inaccessible. This uncontrolled resource consumption can lead to prolonged unavailability of the service, disrupting operations and causing potential data inaccessibility and loss of productivity.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8018" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/0661fa3b-bea4-4156-abed-a65d51958505" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-2w2q-qp7m-7wrh/GHSA-2w2q-qp7m-7wrh.json b/advisories/unreviewed/2025/03/GHSA-2w2q-qp7m-7wrh/GHSA-2w2q-qp7m-7wrh.json new file mode 100644 index 00000000000..ec5848a58ee --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-2w2q-qp7m-7wrh/GHSA-2w2q-qp7m-7wrh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2w2q-qp7m-7wrh", + "modified": "2025-03-20T12:32:51Z", + "published": "2025-03-20T12:32:51Z", + "aliases": [ + "CVE-2024-9617" + ], + "details": "An IDOR vulnerability in danswer-ai/danswer v0.3.94 allows an attacker to view any files. The application does not verify whether the attacker is the creator of the file, allowing the attacker to directly call the GET /api/chat/file/{file_id} interface to view any user's file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9617" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/8f683ff6-3a99-41c6-b763-a8f7b73bd146" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-2xcr-p767-f3rv/GHSA-2xcr-p767-f3rv.json b/advisories/unreviewed/2025/03/GHSA-2xcr-p767-f3rv/GHSA-2xcr-p767-f3rv.json new file mode 100644 index 00000000000..327be64e31c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-2xcr-p767-f3rv/GHSA-2xcr-p767-f3rv.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2xcr-p767-f3rv", + "modified": "2025-03-20T12:32:53Z", + "published": "2025-03-20T12:32:53Z", + "aliases": [ + "CVE-2025-27888" + ], + "details": "Severity: medium (5.8) / important\n\nServer-Side Request Forgery (SSRF), Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache Druid.\n\nThis issue affects all previous Druid versions.\n\n\nWhen using the Druid management proxy, a request that has a specially crafted URL could be used to redirect the request to an arbitrary server instead. This has the potential for XSS or XSRF. The user is required to be authenticated for this exploit. The management proxy is enabled in Druid's out-of-box configuration. It may be disabled to mitigate this vulnerability. If the management proxy is disabled, some web console features will not work properly, but core functionality is unaffected.\n\n\nUsers are recommended to upgrade to Druid 31.0.2 or Druid 32.0.1, which fixes the issue.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27888" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/c0qo989pwtrqkjv6xfr0c30dnjq8vf39" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/03/19/7" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T12:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-2xf2-gjm6-g2c6/GHSA-2xf2-gjm6-g2c6.json b/advisories/unreviewed/2025/03/GHSA-2xf2-gjm6-g2c6/GHSA-2xf2-gjm6-g2c6.json new file mode 100644 index 00000000000..426e5389504 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-2xf2-gjm6-g2c6/GHSA-2xf2-gjm6-g2c6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2xf2-gjm6-g2c6", + "modified": "2025-03-20T12:32:47Z", + "published": "2025-03-20T12:32:47Z", + "aliases": [ + "CVE-2024-8063" + ], + "details": "A divide by zero vulnerability exists in ollama/ollama version v0.3.3. The vulnerability occurs when importing GGUF models with a crafted type for `block_count` in the Modelfile. This can lead to a denial of service (DoS) condition when the server processes the model, causing it to crash.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8063" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/fd8e1ed6-21d2-4c9e-8395-2098f11b7db9" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-369" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3248-f932-c76p/GHSA-3248-f932-c76p.json b/advisories/unreviewed/2025/03/GHSA-3248-f932-c76p/GHSA-3248-f932-c76p.json new file mode 100644 index 00000000000..42423ee1e9e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3248-f932-c76p/GHSA-3248-f932-c76p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3248-f932-c76p", + "modified": "2025-03-20T12:32:41Z", + "published": "2025-03-20T12:32:40Z", + "aliases": [ + "CVE-2024-10906" + ], + "details": "In version 0.6.0 of eosphoros-ai/db-gpt, the `uvicorn` app created by `dbgpt_server` uses an overly permissive instance of `CORSMiddleware` which sets the `Access-Control-Allow-Origin` to `*` for all requests. This configuration makes all endpoints exposed by the server vulnerable to Cross-Site Request Forgery (CSRF). An attacker can exploit this vulnerability to interact with any endpoints of the instance, even if the instance is not publicly exposed to the network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10906" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/8864aca5-a342-4dab-b866-b2882ba6f160" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-32g6-mg92-ghm2/GHSA-32g6-mg92-ghm2.json b/advisories/unreviewed/2025/03/GHSA-32g6-mg92-ghm2/GHSA-32g6-mg92-ghm2.json new file mode 100644 index 00000000000..454bdee8086 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-32g6-mg92-ghm2/GHSA-32g6-mg92-ghm2.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-32g6-mg92-ghm2", + "modified": "2025-03-20T12:32:52Z", + "published": "2025-03-20T12:32:52Z", + "aliases": [ + "CVE-2025-0508" + ], + "details": "A vulnerability in the SageMaker Workflow component of aws/sagemaker-python-sdk allows for the possibility of MD5 hash collisions in all versions. This can lead to workflows being inadvertently replaced due to the reuse of results from different configurations that produce the same MD5 hash. This issue can cause integrity problems within the pipeline, potentially leading to erroneous processing outcomes.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0508" + }, + { + "type": "WEB", + "url": "https://github.com/aws/sagemaker-python-sdk/commit/dcdd99f911e8b1a05d19cf1ad939b0fefae47864" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/eb056818-5b81-466f-81ee-916058d34af2" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-440" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-332g-rf22-2vcg/GHSA-332g-rf22-2vcg.json b/advisories/unreviewed/2025/03/GHSA-332g-rf22-2vcg/GHSA-332g-rf22-2vcg.json new file mode 100644 index 00000000000..aef5660646e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-332g-rf22-2vcg/GHSA-332g-rf22-2vcg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-332g-rf22-2vcg", + "modified": "2025-03-20T12:32:45Z", + "published": "2025-03-20T12:32:44Z", + "aliases": [ + "CVE-2024-6583" + ], + "details": "A path traversal vulnerability exists in the latest version of stangirard/quivr. This vulnerability allows an attacker to upload files to arbitrary paths in an S3 bucket by manipulating the file path in the upload request.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6583" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/c310b500-ec26-4121-8d3a-8e863181346f" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-23" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-339r-cjv9-x78g/GHSA-339r-cjv9-x78g.json b/advisories/unreviewed/2025/03/GHSA-339r-cjv9-x78g/GHSA-339r-cjv9-x78g.json new file mode 100644 index 00000000000..e5331d85d65 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-339r-cjv9-x78g/GHSA-339r-cjv9-x78g.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-339r-cjv9-x78g", + "modified": "2025-03-20T12:32:42Z", + "published": "2025-03-20T12:32:42Z", + "aliases": [ + "CVE-2024-11958" + ], + "details": "A SQL injection vulnerability exists in the `duckdb_retriever` component of the run-llama/llama_index repository, specifically in the latest version. The vulnerability arises from the construction of SQL queries without using prepared statements, allowing an attacker to inject arbitrary SQL code. This can lead to remote code execution (RCE) by installing the shellfs extension and executing malicious commands.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11958" + }, + { + "type": "WEB", + "url": "https://github.com/run-llama/llama_index/commit/35bd221e948e40458052d30c6ef2779bc965b6d0" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/8ddf66e1-f74c-4d53-992b-76bc45cacac1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-34v4-5664-chqj/GHSA-34v4-5664-chqj.json b/advisories/unreviewed/2025/03/GHSA-34v4-5664-chqj/GHSA-34v4-5664-chqj.json new file mode 100644 index 00000000000..b6e31569329 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-34v4-5664-chqj/GHSA-34v4-5664-chqj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-34v4-5664-chqj", + "modified": "2025-03-20T12:32:47Z", + "published": "2025-03-20T12:32:47Z", + "aliases": [ + "CVE-2024-8029" + ], + "details": "An XSS vulnerability was discovered in the upload file(s) process of imartinez/privategpt v0.5.0. Attackers can upload malicious SVG files, which execute JavaScript when victims click on the file link. This can lead to user data theft, session hijacking, malware distribution, and phishing attacks.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8029" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/5941dc63-a4db-4b04-8007-bcaa828106d0" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-35p3-6j45-prwm/GHSA-35p3-6j45-prwm.json b/advisories/unreviewed/2025/03/GHSA-35p3-6j45-prwm/GHSA-35p3-6j45-prwm.json new file mode 100644 index 00000000000..090a9e4b871 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-35p3-6j45-prwm/GHSA-35p3-6j45-prwm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-35p3-6j45-prwm", + "modified": "2025-03-20T12:32:44Z", + "published": "2025-03-20T12:32:44Z", + "aliases": [ + "CVE-2024-12778" + ], + "details": "A vulnerability in aimhubio/aim version 3.25.0 allows for a denial of service (DoS) attack. The issue arises when a large number of tracked metrics are retrieved simultaneously from the Aim web API, causing the web server to become unresponsive. The root cause is the lack of a limit on the number of metrics that can be requested per call, combined with the server's single-threaded nature, leading to excessive resource consumption and blocking of the server.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12778" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/892a9eee-0251-4e57-94a4-dad2e7f32715" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-38mg-wm59-g64x/GHSA-38mg-wm59-g64x.json b/advisories/unreviewed/2025/03/GHSA-38mg-wm59-g64x/GHSA-38mg-wm59-g64x.json new file mode 100644 index 00000000000..40d4900e8dc --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-38mg-wm59-g64x/GHSA-38mg-wm59-g64x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-38mg-wm59-g64x", + "modified": "2025-03-20T12:32:49Z", + "published": "2025-03-20T12:32:49Z", + "aliases": [ + "CVE-2024-8955" + ], + "details": "A Server-Side Request Forgery (SSRF) vulnerability exists in composiohq/composio version v0.4.4. This vulnerability allows an attacker to read the contents of any file in the system by exploiting the BROWSERTOOL_GOTO_PAGE and BROWSERTOOL_GET_PAGE_DETAILS actions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8955" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/13bc0399-2d9b-449e-95f2-6e9a7e39383d" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-643" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-38r9-3j52-h92v/GHSA-38r9-3j52-h92v.json b/advisories/unreviewed/2025/03/GHSA-38r9-3j52-h92v/GHSA-38r9-3j52-h92v.json new file mode 100644 index 00000000000..db200449b9a --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-38r9-3j52-h92v/GHSA-38r9-3j52-h92v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-38r9-3j52-h92v", + "modified": "2025-03-20T12:32:46Z", + "published": "2025-03-20T12:32:46Z", + "aliases": [ + "CVE-2024-7760" + ], + "details": "aimhubio/aim version 3.22.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the tracking server. The vulnerability is due to overly permissive CORS settings, allowing cross-origin requests from all origins. This enables CSRF attacks on all endpoints of the tracking server, which can be chained with other existing vulnerabilities such as remote code execution, denial of service, and arbitrary file read/write.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7760" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/2038df5f-4829-4040-8573-67bf9bb89229" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3c45-rpmq-6gfj/GHSA-3c45-rpmq-6gfj.json b/advisories/unreviewed/2025/03/GHSA-3c45-rpmq-6gfj/GHSA-3c45-rpmq-6gfj.json new file mode 100644 index 00000000000..3fba576b782 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3c45-rpmq-6gfj/GHSA-3c45-rpmq-6gfj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3c45-rpmq-6gfj", + "modified": "2025-03-20T12:32:44Z", + "published": "2025-03-20T12:32:44Z", + "aliases": [ + "CVE-2024-12869" + ], + "details": "In infiniflow/ragflow version v0.12.0, there is an improper authentication vulnerability that allows a user to view another user's invite list. This can lead to a privacy breach where users' personal or private information, such as email addresses or usernames in the invite list, could be exposed without their consent. This data leakage can facilitate further attacks, such as phishing or spam, and result in loss of trust and potential regulatory issues.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12869" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/768b1a56-1e79-416a-8445-65953568b04a" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3j5r-3852-j63v/GHSA-3j5r-3852-j63v.json b/advisories/unreviewed/2025/03/GHSA-3j5r-3852-j63v/GHSA-3j5r-3852-j63v.json new file mode 100644 index 00000000000..d57202e3039 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3j5r-3852-j63v/GHSA-3j5r-3852-j63v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3j5r-3852-j63v", + "modified": "2025-03-20T12:32:42Z", + "published": "2025-03-20T12:32:42Z", + "aliases": [ + "CVE-2024-11302" + ], + "details": "A missing check_access() function in the lollms_binding_infos module of the parisneo/lollms repository, version V14, allows attackers to add, modify, and remove bindings arbitrarily. This vulnerability affects the /install_binding and /reinstall_binding endpoints, among others, enabling unauthorized access and manipulation of binding settings without requiring the client_id value.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11302" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/e341304b-4651-4de9-b7b9-b89aead3b46e" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-304" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3p9q-7w63-3f8q/GHSA-3p9q-7w63-3f8q.json b/advisories/unreviewed/2025/03/GHSA-3p9q-7w63-3f8q/GHSA-3p9q-7w63-3f8q.json new file mode 100644 index 00000000000..4b4ac5adb91 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3p9q-7w63-3f8q/GHSA-3p9q-7w63-3f8q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3p9q-7w63-3f8q", + "modified": "2025-03-20T12:32:45Z", + "published": "2025-03-20T12:32:45Z", + "aliases": [ + "CVE-2024-7033" + ], + "details": "In version 0.3.8 of open-webui/open-webui, an arbitrary file write vulnerability exists in the download_model endpoint. When deployed on Windows, the application improperly handles file paths, allowing an attacker to manipulate the file path to write files to arbitrary locations on the server's filesystem. This can result in overwriting critical system or application files, causing denial of service, or potentially achieving remote code execution (RCE). RCE can allow an attacker to execute malicious code with the privileges of the user running the application, leading to a full system compromise.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7033" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/7078261f-8414-4bb7-9d72-a2a4d8bfd5d1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-29" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3ppw-4jp4-5852/GHSA-3ppw-4jp4-5852.json b/advisories/unreviewed/2025/03/GHSA-3ppw-4jp4-5852/GHSA-3ppw-4jp4-5852.json new file mode 100644 index 00000000000..f0bef529313 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3ppw-4jp4-5852/GHSA-3ppw-4jp4-5852.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3ppw-4jp4-5852", + "modified": "2025-03-20T12:32:47Z", + "published": "2025-03-20T12:32:47Z", + "aliases": [ + "CVE-2024-8101" + ], + "details": "A stored cross-site scripting (XSS) vulnerability exists in the Text Explorer component of aimhubio/aim version 3.23.0. The vulnerability arises due to the use of `dangerouslySetInnerHTML` without proper sanitization, allowing arbitrary JavaScript execution when rendering tracked texts. This can be exploited by injecting malicious HTML content during the training process, which is then rendered unsanitized in the Text Explorer.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8101" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/60cf2b93-a9a2-435e-a222-3d6abde26adb" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3xq5-x4fj-rff7/GHSA-3xq5-x4fj-rff7.json b/advisories/unreviewed/2025/03/GHSA-3xq5-x4fj-rff7/GHSA-3xq5-x4fj-rff7.json new file mode 100644 index 00000000000..3462c0d0dba --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3xq5-x4fj-rff7/GHSA-3xq5-x4fj-rff7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3xq5-x4fj-rff7", + "modified": "2025-03-20T12:32:40Z", + "published": "2025-03-20T12:32:40Z", + "aliases": [ + "CVE-2024-10902" + ], + "details": "In eosphoros-ai/db-gpt version v0.6.0, the web API `POST /v1/personal/agent/upload` is vulnerable to Arbitrary File Upload with Path Traversal. This vulnerability allows unauthorized attackers to upload arbitrary files to the victim's file system at any location. The impact of this vulnerability includes the potential for remote code execution (RCE) by writing malicious files, such as a malicious `__init__.py` in the Python's `/site-packages/` directory.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10902" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/f7fbf76e-aa1c-4106-b007-e9579f4f7d5f" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-73" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-43g4-487m-5q6m/GHSA-43g4-487m-5q6m.json b/advisories/unreviewed/2025/03/GHSA-43g4-487m-5q6m/GHSA-43g4-487m-5q6m.json new file mode 100644 index 00000000000..0300d9674ca --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-43g4-487m-5q6m/GHSA-43g4-487m-5q6m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-43g4-487m-5q6m", + "modified": "2025-03-20T12:32:46Z", + "published": "2025-03-20T12:32:46Z", + "aliases": [ + "CVE-2024-7053" + ], + "details": "A vulnerability in open-webui/open-webui version 0.3.8 allows an attacker with a user-level account to perform a session fixation attack. The session cookie for all users is set with the default `SameSite=Lax` and does not have the `Secure` flag enabled, allowing the session cookie to be sent over HTTP to a cross-origin domain. An attacker can exploit this by embedding a malicious markdown image in a chat, which, when viewed by an administrator, sends the admin's session cookie to the attacker's server. This can lead to a stealthy administrator account takeover, potentially resulting in remote code execution (RCE) due to the elevated privileges of administrator accounts.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7053" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/947f8191-0abf-4adf-b7c4-d4c19683aba2" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-43qf-4rqw-9q2g/GHSA-43qf-4rqw-9q2g.json b/advisories/unreviewed/2025/03/GHSA-43qf-4rqw-9q2g/GHSA-43qf-4rqw-9q2g.json new file mode 100644 index 00000000000..71055d05636 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-43qf-4rqw-9q2g/GHSA-43qf-4rqw-9q2g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-43qf-4rqw-9q2g", + "modified": "2025-03-20T12:32:45Z", + "published": "2025-03-20T12:32:45Z", + "aliases": [ + "CVE-2024-6866" + ], + "details": "corydolphin/flask-cors version 4.01 contains a vulnerability where the request path matching is case-insensitive due to the use of the `try_match` function, which is originally intended for matching hosts. This results in a mismatch because paths in URLs are case-sensitive, but the regex matching treats them as case-insensitive. This misconfiguration can lead to significant security vulnerabilities, allowing unauthorized origins to access paths meant to be restricted, resulting in data exposure and potential data leaks.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6866" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/808c11af-faee-43a8-824b-b5ab4f62b9e6" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-178" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-4452-rwq3-2x44/GHSA-4452-rwq3-2x44.json b/advisories/unreviewed/2025/03/GHSA-4452-rwq3-2x44/GHSA-4452-rwq3-2x44.json new file mode 100644 index 00000000000..84b4ea4740b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4452-rwq3-2x44/GHSA-4452-rwq3-2x44.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4452-rwq3-2x44", + "modified": "2025-03-20T12:32:41Z", + "published": "2025-03-20T12:32:41Z", + "aliases": [ + "CVE-2024-11031" + ], + "details": "In version 3.83 of binary-husky/gpt_academic, a Server-Side Request Forgery (SSRF) vulnerability exists in the Markdown_Translate.get_files_from_everything() API. This vulnerability is exploited through the HotReload(Markdown翻译中) plugin function, which allows downloading arbitrary web hosts by only checking if the link starts with 'http'. Attackers can exploit this vulnerability to abuse the victim GPT Academic's Gradio Web server's credentials to access unauthorized web resources.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11031" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/d27d89a7-7d54-45b9-a9eb-66c00bc56e02" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-44q8-52gx-27g8/GHSA-44q8-52gx-27g8.json b/advisories/unreviewed/2025/03/GHSA-44q8-52gx-27g8/GHSA-44q8-52gx-27g8.json new file mode 100644 index 00000000000..7c13d2358ac --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-44q8-52gx-27g8/GHSA-44q8-52gx-27g8.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-44q8-52gx-27g8", + "modified": "2025-03-20T12:32:42Z", + "published": "2025-03-20T12:32:42Z", + "aliases": [ + "CVE-2024-11300" + ], + "details": "In lunary-ai/lunary before version 1.6.3, an improper access control vulnerability exists where a user can access prompt data of another user. This issue affects version 1.6.2 and the main branch. The vulnerability allows unauthorized users to view sensitive prompt data by accessing specific URLs, leading to potential exposure of critical information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11300" + }, + { + "type": "WEB", + "url": "https://github.com/lunary-ai/lunary/commit/79dc370596d979b756f6ea0250d97a2d02385ecd" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/8dca7994-0d92-491e-a419-02adfe23ffa4" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-45p5-8q33-98hw/GHSA-45p5-8q33-98hw.json b/advisories/unreviewed/2025/03/GHSA-45p5-8q33-98hw/GHSA-45p5-8q33-98hw.json new file mode 100644 index 00000000000..61206e7dfe0 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-45p5-8q33-98hw/GHSA-45p5-8q33-98hw.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-45p5-8q33-98hw", + "modified": "2025-03-20T12:32:39Z", + "published": "2025-03-20T12:32:39Z", + "aliases": [ + "CVE-2024-10513" + ], + "details": "A path traversal vulnerability exists in the 'document uploads manager' feature of mintplex-labs/anything-llm, affecting the latest version prior to 1.2.2. This vulnerability allows users with the 'manager' role to access and manipulate the 'anythingllm.db' database file. By exploiting the vulnerable endpoint '/api/document/move-files', an attacker can move the database file to a publicly accessible directory, download it, and subsequently delete it. This can lead to unauthorized access to sensitive data, privilege escalation, and potential data loss.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10513" + }, + { + "type": "WEB", + "url": "https://github.com/mintplex-labs/anything-llm/commit/47a5c7126c20e2277ee56e2c7ee11990886a40a7" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/ad11cecf-161a-4fb1-986f-6f88272cbb9e" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-23" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-47f6-5p7h-5f3h/GHSA-47f6-5p7h-5f3h.json b/advisories/unreviewed/2025/03/GHSA-47f6-5p7h-5f3h/GHSA-47f6-5p7h-5f3h.json new file mode 100644 index 00000000000..920940ce8da --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-47f6-5p7h-5f3h/GHSA-47f6-5p7h-5f3h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-47f6-5p7h-5f3h", + "modified": "2025-03-20T12:32:45Z", + "published": "2025-03-20T12:32:45Z", + "aliases": [ + "CVE-2024-6854" + ], + "details": "In h2oai/h2o-3 version 3.46.0, the endpoint for exporting models does not restrict the export location, allowing an attacker to export a model to any file in the server's file structure, thereby overwriting it. This vulnerability can be exploited to overwrite any file on the target server with a trained model file, although the content of the overwrite is not controllable by the attacker.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6854" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/97d013f9-ac51-4c80-8dd7-8dfde11f33b2" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-36" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-49m6-vrr9-2cqm/GHSA-49m6-vrr9-2cqm.json b/advisories/unreviewed/2025/03/GHSA-49m6-vrr9-2cqm/GHSA-49m6-vrr9-2cqm.json new file mode 100644 index 00000000000..2ab12653d7e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-49m6-vrr9-2cqm/GHSA-49m6-vrr9-2cqm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-49m6-vrr9-2cqm", + "modified": "2025-03-20T12:32:52Z", + "published": "2025-03-20T12:32:52Z", + "aliases": [ + "CVE-2025-0453" + ], + "details": "In mlflow/mlflow version 2.17.2, the `/graphql` endpoint is vulnerable to a denial of service attack. An attacker can create large batches of queries that repeatedly request all runs from a given experiment. This can tie up all the workers allocated by MLFlow, rendering the application unable to respond to other requests. This vulnerability is due to uncontrolled resource consumption.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0453" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/788327ec-714a-4d5c-83aa-8df04dd7612b" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-49rx-72gp-wfgj/GHSA-49rx-72gp-wfgj.json b/advisories/unreviewed/2025/03/GHSA-49rx-72gp-wfgj/GHSA-49rx-72gp-wfgj.json new file mode 100644 index 00000000000..f63d3d06862 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-49rx-72gp-wfgj/GHSA-49rx-72gp-wfgj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-49rx-72gp-wfgj", + "modified": "2025-03-20T12:32:48Z", + "published": "2025-03-20T12:32:48Z", + "aliases": [ + "CVE-2024-8489" + ], + "details": "A vulnerability in modelscope/agentscope, specifically in the AgentScope Studio backend server, allows for Cross-Site Request Forgery (CSRF) due to overly permissive CORS headers. This issue affects the latest commit on the main branch (21161fe). The vulnerability permits an attacker to access all backend endpoints, including the `api/file` endpoint, enabling the reading of arbitrary files on the target's local file system through CSRF.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8489" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/93195bf0-9ac2-4476-a2ea-7c9364727e8c" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-4cv3-v7pv-rfhf/GHSA-4cv3-v7pv-rfhf.json b/advisories/unreviewed/2025/03/GHSA-4cv3-v7pv-rfhf/GHSA-4cv3-v7pv-rfhf.json new file mode 100644 index 00000000000..919906574f3 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4cv3-v7pv-rfhf/GHSA-4cv3-v7pv-rfhf.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4cv3-v7pv-rfhf", + "modified": "2025-03-20T12:32:47Z", + "published": "2025-03-20T12:32:46Z", + "aliases": [ + "CVE-2024-8019" + ], + "details": "In lightning-ai/pytorch-lightning version 2.3.2, a vulnerability exists in the `LightningApp` when running on a Windows host. The vulnerability occurs at the `/api/v1/upload_file/` endpoint, allowing an attacker to write or overwrite arbitrary files by providing a crafted filename. This can lead to potential remote code execution (RCE) by overwriting critical files or placing malicious files in sensitive locations.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8019" + }, + { + "type": "WEB", + "url": "https://github.com/lightning-ai/pytorch-lightning/commit/330af381de88cff17515418a341cbc1f9f127f9a" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/2754298b-5af5-48ef-8b38-999093ddf2bd" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-4cxc-r29p-3327/GHSA-4cxc-r29p-3327.json b/advisories/unreviewed/2025/03/GHSA-4cxc-r29p-3327/GHSA-4cxc-r29p-3327.json new file mode 100644 index 00000000000..0b0e6e98f5e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4cxc-r29p-3327/GHSA-4cxc-r29p-3327.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4cxc-r29p-3327", + "modified": "2025-03-20T12:32:43Z", + "published": "2025-03-20T12:32:43Z", + "aliases": [ + "CVE-2024-12387" + ], + "details": "A vulnerability in the binary-husky/gpt_academic repository, as of commit git 3890467, allows an attacker to crash the server by uploading a specially crafted zip bomb. The server decompresses the uploaded file and attempts to load it into memory, which can lead to an out-of-memory crash. This issue arises due to improper input validation when handling compressed file uploads.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12387" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/02b4ab21-d29b-4cd7-ad80-f83081ce82a4" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-4f3h-89pj-w84f/GHSA-4f3h-89pj-w84f.json b/advisories/unreviewed/2025/03/GHSA-4f3h-89pj-w84f/GHSA-4f3h-89pj-w84f.json new file mode 100644 index 00000000000..d7531a60b55 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4f3h-89pj-w84f/GHSA-4f3h-89pj-w84f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4f3h-89pj-w84f", + "modified": "2025-03-20T12:32:46Z", + "published": "2025-03-20T12:32:46Z", + "aliases": [ + "CVE-2024-7779" + ], + "details": "A vulnerability in danswer-ai/danswer version 1 allows an attacker to perform a Regular Expression Denial of Service (ReDoS) by manipulating regular expressions. This can significantly slow down the application's response time and potentially render it completely unusable.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7779" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/829f7d9f-8755-4362-bd40-801e4690dcdc" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-4g3f-9mfg-xxgh/GHSA-4g3f-9mfg-xxgh.json b/advisories/unreviewed/2025/03/GHSA-4g3f-9mfg-xxgh/GHSA-4g3f-9mfg-xxgh.json new file mode 100644 index 00000000000..d5e6a73a7b6 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4g3f-9mfg-xxgh/GHSA-4g3f-9mfg-xxgh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4g3f-9mfg-xxgh", + "modified": "2025-03-20T12:32:45Z", + "published": "2025-03-20T12:32:45Z", + "aliases": [ + "CVE-2024-6986" + ], + "details": "A Cross-site Scripting (XSS) vulnerability exists in the Settings page of parisneo/lollms-webui version 9.8. The vulnerability is due to the improper use of the 'v-html' directive, which inserts the content of the 'full_template' variable directly as HTML. This allows an attacker to execute malicious JavaScript code by injecting a payload into the 'System Template' input field under main configurations.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6986" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/83e9bde1-40b2-49e9-be1c-bc1498eb8ebd" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-4jr8-64gc-wqqx/GHSA-4jr8-64gc-wqqx.json b/advisories/unreviewed/2025/03/GHSA-4jr8-64gc-wqqx/GHSA-4jr8-64gc-wqqx.json new file mode 100644 index 00000000000..0764c850a0e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4jr8-64gc-wqqx/GHSA-4jr8-64gc-wqqx.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4jr8-64gc-wqqx", + "modified": "2025-03-20T12:32:39Z", + "published": "2025-03-20T12:32:39Z", + "aliases": [ + "CVE-2024-10275" + ], + "details": "In version 1.5.5 of lunary-ai/lunary, a vulnerability exists where admins, who do not have direct permissions to access billing resources, can change the permissions of existing users to include billing permissions. This can lead to a privilege escalation scenario where an administrator can manage billing, effectively bypassing the intended role-based access control. Only users with the 'owner' role should be allowed to invite members with billing permissions. This flaw allows admins to circumvent those restrictions, gaining unauthorized access and control over billing information, posing a risk to the organization’s financial resources.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10275" + }, + { + "type": "WEB", + "url": "https://github.com/lunary-ai/lunary/commit/8ba1b8ba2c2c30b1cec30eb5777c1fda670cbbfc" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/863ee34b-c4c6-4325-bf7a-82a7feebf88f" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-4qcx-jx49-6qrh/GHSA-4qcx-jx49-6qrh.json b/advisories/unreviewed/2025/03/GHSA-4qcx-jx49-6qrh/GHSA-4qcx-jx49-6qrh.json new file mode 100644 index 00000000000..94d16aee440 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4qcx-jx49-6qrh/GHSA-4qcx-jx49-6qrh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4qcx-jx49-6qrh", + "modified": "2025-03-20T12:32:49Z", + "published": "2025-03-20T12:32:48Z", + "aliases": [ + "CVE-2024-8769" + ], + "details": "A vulnerability in the `LockManager.release_locks` function in aimhubio/aim (commit bb76afe) allows for arbitrary file deletion through relative path traversal. The `run_hash` parameter, which is user-controllable, is concatenated without normalization as part of a path used to specify file deletion. This vulnerability is exposed through the `Repo._close_run()` method, which is accessible via the tracking server instruction API. As a result, an attacker can exploit this to delete any arbitrary file on the machine running the tracking server.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8769" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/59d3472f-f581-4beb-a090-afd36a00ecf7" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-29" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-4rj2-9gcx-5qhx/GHSA-4rj2-9gcx-5qhx.json b/advisories/unreviewed/2025/03/GHSA-4rj2-9gcx-5qhx/GHSA-4rj2-9gcx-5qhx.json new file mode 100644 index 00000000000..c153c52e8da --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4rj2-9gcx-5qhx/GHSA-4rj2-9gcx-5qhx.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4rj2-9gcx-5qhx", + "modified": "2025-03-20T12:32:53Z", + "published": "2025-03-20T12:32:53Z", + "aliases": [ + "CVE-2025-1474" + ], + "details": "In mlflow/mlflow version 2.18, an admin is able to create a new user account without setting a password. This vulnerability could lead to security risks, as accounts without passwords may be susceptible to unauthorized access. Additionally, this issue violates best practices for secure user account management. The issue is fixed in version 2.19.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1474" + }, + { + "type": "WEB", + "url": "https://github.com/mlflow/mlflow/commit/149c9e18aa219bc47e86b432e130e467a36f4a17" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/e79f7774-10fe-46b2-b522-e73b748e3b2d" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-521" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-4rqf-8pfm-p36r/GHSA-4rqf-8pfm-p36r.json b/advisories/unreviewed/2025/03/GHSA-4rqf-8pfm-p36r/GHSA-4rqf-8pfm-p36r.json new file mode 100644 index 00000000000..b05033c5bb2 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4rqf-8pfm-p36r/GHSA-4rqf-8pfm-p36r.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4rqf-8pfm-p36r", + "modified": "2025-03-20T12:32:49Z", + "published": "2025-03-20T12:32:49Z", + "aliases": [ + "CVE-2024-8859" + ], + "details": "A path traversal vulnerability exists in mlflow/mlflow version 2.15.1. When users configure and use the dbfs service, concatenating the URL directly into the file protocol results in an arbitrary file read vulnerability. This issue occurs because only the path part of the URL is checked, while parts such as query and parameters are not handled. The vulnerability is triggered if the user has configured the dbfs service, and during usage, the service is mounted to a local directory.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8859" + }, + { + "type": "WEB", + "url": "https://github.com/mlflow/mlflow/commit/7791b8cdd595f21b5f179c7b17e4b5eb5cbbe654" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/2259b88b-a0c6-4c7c-b434-6aacf6056dcb" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-29" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-4v9f-r55g-g6hc/GHSA-4v9f-r55g-g6hc.json b/advisories/unreviewed/2025/03/GHSA-4v9f-r55g-g6hc/GHSA-4v9f-r55g-g6hc.json new file mode 100644 index 00000000000..97872da5ba0 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4v9f-r55g-g6hc/GHSA-4v9f-r55g-g6hc.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4v9f-r55g-g6hc", + "modified": "2025-03-20T12:32:47Z", + "published": "2025-03-20T12:32:47Z", + "aliases": [ + "CVE-2024-8183" + ], + "details": "A CORS (Cross-Origin Resource Sharing) misconfiguration in prefecthq/prefect version 2.20.2 allows unauthorized domains to access sensitive data. This vulnerability can lead to unauthorized access to the database, resulting in potential data leaks, loss of confidentiality, service disruption, and data integrity risks.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8183" + }, + { + "type": "WEB", + "url": "https://github.com/prefecthq/prefect/commit/a69266e077169b8a32ad76b1dd3ea63b96d011c2" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/b801de43-ff9f-4db9-b583-4797d4f7d3d2" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-346" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-4vm5-r6m3-2448/GHSA-4vm5-r6m3-2448.json b/advisories/unreviewed/2025/03/GHSA-4vm5-r6m3-2448/GHSA-4vm5-r6m3-2448.json new file mode 100644 index 00000000000..529aab2db9e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4vm5-r6m3-2448/GHSA-4vm5-r6m3-2448.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4vm5-r6m3-2448", + "modified": "2025-03-20T12:32:47Z", + "published": "2025-03-20T12:32:47Z", + "aliases": [ + "CVE-2024-8028" + ], + "details": "A vulnerability in danswer-ai/danswer v0.3.94 allows an attacker to cause a Denial of Service (DoS) by uploading a file with a malformed multipart boundary. By appending a large number of characters to the end of the multipart boundary, the server continuously processes each character, rendering the application inaccessible. This issue can be exploited by sending a single crafted request, affecting all users on the server.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8028" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/55530ecb-0ac2-4dc1-9527-bf24de594a57" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-4vmg-rw8f-92f9/GHSA-4vmg-rw8f-92f9.json b/advisories/unreviewed/2025/03/GHSA-4vmg-rw8f-92f9/GHSA-4vmg-rw8f-92f9.json new file mode 100644 index 00000000000..be2302c793f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4vmg-rw8f-92f9/GHSA-4vmg-rw8f-92f9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4vmg-rw8f-92f9", + "modified": "2025-03-20T12:32:46Z", + "published": "2025-03-20T12:32:46Z", + "aliases": [ + "CVE-2024-7804" + ], + "details": "A deserialization vulnerability exists in the Pytorch RPC framework (torch.distributed.rpc) in pytorch/pytorch versions <=2.3.1. The vulnerability arises from the lack of security verification during the deserialization process of PythonUDF objects in pytorch/torch/distributed/rpc/internal.py. This flaw allows an attacker to execute arbitrary code remotely by sending a malicious serialized PythonUDF object, leading to remote code execution (RCE) on the master node.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7804" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/0e870eeb-f924-4054-8fac-d926b1fb7259" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-4vqf-pwq6-3wh3/GHSA-4vqf-pwq6-3wh3.json b/advisories/unreviewed/2025/03/GHSA-4vqf-pwq6-3wh3/GHSA-4vqf-pwq6-3wh3.json new file mode 100644 index 00000000000..939fed1a42e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4vqf-pwq6-3wh3/GHSA-4vqf-pwq6-3wh3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4vqf-pwq6-3wh3", + "modified": "2025-03-20T12:32:49Z", + "published": "2025-03-20T12:32:49Z", + "aliases": [ + "CVE-2024-8982" + ], + "details": "A Local File Inclusion (LFI) vulnerability in OpenLLM version 0.6.10 allows attackers to include files from the local server through the web application. This flaw could expose internal server files and potentially sensitive information such as configuration files, passwords, and other critical data. Unauthorized access to critical server files, such as configuration files, user credentials (/etc/passwd), and private keys, can lead to a complete compromise of the system's security. Attackers could leverage the exposed information to further penetrate the network, exfiltrate data, or escalate privileges within the environment.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8982" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/b7bdc9a1-51ac-402a-8e6e-0d977699aca6" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-29" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-4w44-j4vc-r3rp/GHSA-4w44-j4vc-r3rp.json b/advisories/unreviewed/2025/03/GHSA-4w44-j4vc-r3rp/GHSA-4w44-j4vc-r3rp.json new file mode 100644 index 00000000000..851eca59efb --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4w44-j4vc-r3rp/GHSA-4w44-j4vc-r3rp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4w44-j4vc-r3rp", + "modified": "2025-03-20T12:32:41Z", + "published": "2025-03-20T12:32:41Z", + "aliases": [ + "CVE-2024-10948" + ], + "details": "A vulnerability in the upload function of binary-husky/gpt_academic allows any user to read arbitrary files on the system, including sensitive files such as `config.py`. This issue affects the latest version of the product. An attacker can exploit this vulnerability by intercepting the websocket request during file upload and replacing the file path with the path of the file they wish to read. The server then copies the file to the `private_upload` folder and provides the path to the copied file, which can be accessed via a GET request. This vulnerability can lead to the exposure of sensitive system files, potentially including credentials, configuration files, or sensitive user data.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10948" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/290a379d-8441-4292-a553-3587e8c5c729" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-4wfj-v7c8-rwh4/GHSA-4wfj-v7c8-rwh4.json b/advisories/unreviewed/2025/03/GHSA-4wfj-v7c8-rwh4/GHSA-4wfj-v7c8-rwh4.json new file mode 100644 index 00000000000..4552470e105 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4wfj-v7c8-rwh4/GHSA-4wfj-v7c8-rwh4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4wfj-v7c8-rwh4", + "modified": "2025-03-20T12:32:51Z", + "published": "2025-03-20T12:32:51Z", + "aliases": [ + "CVE-2024-9311" + ], + "details": "A Cross-Site Request Forgery (CSRF) vulnerability in haotian-liu/llava v1.2.0 (LLaVA-1.6) allows an attacker to upload files with malicious content without authentication or user interaction. The uploaded file is stored in a predictable path, enabling the attacker to execute arbitrary JavaScript code in the context of the victim's browser by visiting the crafted file URL. This can lead to theft of sensitive information, session hijacking, or other actions compromising the security and privacy of the victim.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9311" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/15b18b85-5a6b-43e7-bc65-6b4772871e98" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-53gh-p8jc-7rg8/GHSA-53gh-p8jc-7rg8.json b/advisories/unreviewed/2025/03/GHSA-53gh-p8jc-7rg8/GHSA-53gh-p8jc-7rg8.json new file mode 100644 index 00000000000..79b9f1dddf1 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-53gh-p8jc-7rg8/GHSA-53gh-p8jc-7rg8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-53gh-p8jc-7rg8", + "modified": "2025-03-20T12:32:45Z", + "published": "2025-03-20T12:32:45Z", + "aliases": [ + "CVE-2024-6825" + ], + "details": "BerriAI/litellm version 1.40.12 contains a vulnerability that allows remote code execution. The issue exists in the handling of the 'post_call_rules' configuration, where a callback function can be added. The provided value is split at the final '.' mark, with the last part considered the function name and the remaining part appended with the '.py' extension and imported. This allows an attacker to set a system method, such as 'os.system', as a callback, enabling the execution of arbitrary commands when a chat response is processed.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6825" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/1d98bebb-6cf4-46c9-87c3-d3b1972973b5" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-54c7-72v9-gm27/GHSA-54c7-72v9-gm27.json b/advisories/unreviewed/2025/03/GHSA-54c7-72v9-gm27/GHSA-54c7-72v9-gm27.json new file mode 100644 index 00000000000..b2512b0cad2 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-54c7-72v9-gm27/GHSA-54c7-72v9-gm27.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-54c7-72v9-gm27", + "modified": "2025-03-20T12:32:52Z", + "published": "2025-03-20T12:32:52Z", + "aliases": [ + "CVE-2024-9920" + ], + "details": "In version v12 of parisneo/lollms-webui, the 'Send file to AL' function allows uploading files with various extensions, including potentially dangerous ones like .py, .sh, .bat, and more. Attackers can exploit this by uploading files with malicious content and then using the '/open_file' API endpoint to execute these files. The vulnerability arises from the use of 'subprocess.Popen' to open files without proper validation, leading to potential remote code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9920" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/c70c6732-23b3-4ef8-aec6-0a47467d1ed5" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-54hh-fh2m-4396/GHSA-54hh-fh2m-4396.json b/advisories/unreviewed/2025/03/GHSA-54hh-fh2m-4396/GHSA-54hh-fh2m-4396.json new file mode 100644 index 00000000000..9a27febeaf1 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-54hh-fh2m-4396/GHSA-54hh-fh2m-4396.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-54hh-fh2m-4396", + "modified": "2025-03-20T12:32:51Z", + "published": "2025-03-20T12:32:51Z", + "aliases": [ + "CVE-2024-9901" + ], + "details": "LocalAI version v2.19.4 (af0545834fd565ab56af0b9348550ca9c3cb5349) contains a vulnerability where the delete model API improperly neutralizes input during web page generation, leading to a one-time storage cross-site scripting (XSS) vulnerability. This vulnerability allows an attacker to store a malicious payload that executes when a user accesses the homepage. Additionally, the presence of cross-site request forgery (CSRF) can enable automated malicious requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9901" + }, + { + "type": "WEB", + "url": "https://github.com/mudler/localai/commit/a1634b219a4e52813e70ff07e6376a01449c4515" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/31332c23-ea89-4176-ba57-388cf6008945" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-564p-rx2q-4c8v/GHSA-564p-rx2q-4c8v.json b/advisories/unreviewed/2025/03/GHSA-564p-rx2q-4c8v/GHSA-564p-rx2q-4c8v.json new file mode 100644 index 00000000000..7b57f673199 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-564p-rx2q-4c8v/GHSA-564p-rx2q-4c8v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-564p-rx2q-4c8v", + "modified": "2025-03-20T12:32:43Z", + "published": "2025-03-20T12:32:43Z", + "aliases": [ + "CVE-2024-12760" + ], + "details": "An open redirect vulnerability in bentoml/bentoml v1.3.9 allows a remote unauthenticated attacker to redirect users to arbitrary websites via a specially crafted URL. This can be exploited for phishing attacks, malware distribution, and credential theft.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12760" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/2a284ff6-cc6c-4a10-b72e-1bb31c842bca" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-56p4-cfqw-jx4h/GHSA-56p4-cfqw-jx4h.json b/advisories/unreviewed/2025/03/GHSA-56p4-cfqw-jx4h/GHSA-56p4-cfqw-jx4h.json new file mode 100644 index 00000000000..99900a09663 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-56p4-cfqw-jx4h/GHSA-56p4-cfqw-jx4h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-56p4-cfqw-jx4h", + "modified": "2025-03-20T12:32:45Z", + "published": "2025-03-20T12:32:44Z", + "aliases": [ + "CVE-2024-12882" + ], + "details": "comfyanonymous/comfyui version v0.2.4 suffers from a non-blind Server-Side Request Forgery (SSRF) vulnerability. This vulnerability can be exploited by combining the REST APIs `POST /internal/models/download` and `GET /view`, allowing attackers to abuse the victim server's credentials to access unauthorized web resources.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12882" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/e8768cb1-6a80-40c1-9cdf-bcd21f01f85a" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5c8j-g96x-cj78/GHSA-5c8j-g96x-cj78.json b/advisories/unreviewed/2025/03/GHSA-5c8j-g96x-cj78/GHSA-5c8j-g96x-cj78.json new file mode 100644 index 00000000000..86b69b87f0e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5c8j-g96x-cj78/GHSA-5c8j-g96x-cj78.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5c8j-g96x-cj78", + "modified": "2025-03-20T12:32:47Z", + "published": "2025-03-20T12:32:47Z", + "aliases": [ + "CVE-2024-8062" + ], + "details": "A vulnerability in the typeahead endpoint of h2oai/h2o-3 version 3.46.0 allows for a denial of service. The endpoint performs a `HEAD` request to verify the existence of a specified resource without setting a timeout. An attacker can exploit this by sending multiple requests to an attacker-controlled server that hangs, causing the application to block and become unresponsive to other requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8062" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/a04190d9-4acb-449a-9a7f-f1bf6be1ed23" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1088" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5ccf-884p-4jjq/GHSA-5ccf-884p-4jjq.json b/advisories/unreviewed/2025/03/GHSA-5ccf-884p-4jjq/GHSA-5ccf-884p-4jjq.json new file mode 100644 index 00000000000..30338e1e492 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5ccf-884p-4jjq/GHSA-5ccf-884p-4jjq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5ccf-884p-4jjq", + "modified": "2025-03-20T12:32:51Z", + "published": "2025-03-20T12:32:51Z", + "aliases": [ + "CVE-2024-9840" + ], + "details": "A Denial of Service (DoS) vulnerability exists in open-webui/open-webui version 0.3.21. This vulnerability affects multiple endpoints, including `/ollama/models/upload`, `/audio/api/v1/transcriptions`, and `/rag/api/v1/doc`. The application processes multipart boundaries without authentication, leading to resource exhaustion. By appending additional characters to the multipart boundary, an attacker can cause the server to parse each byte of the boundary, ultimately leading to service unavailability. This vulnerability can be exploited remotely, resulting in high CPU and memory usage, and rendering the service inaccessible to legitimate users.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9840" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/9178f09e-4d4f-4a5b-bc32-cada7445b03c" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5chr-fjjv-38qv/GHSA-5chr-fjjv-38qv.json b/advisories/unreviewed/2025/03/GHSA-5chr-fjjv-38qv/GHSA-5chr-fjjv-38qv.json new file mode 100644 index 00000000000..2841f39c401 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5chr-fjjv-38qv/GHSA-5chr-fjjv-38qv.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5chr-fjjv-38qv", + "modified": "2025-03-20T12:32:41Z", + "published": "2025-03-20T12:32:41Z", + "aliases": [ + "CVE-2024-10940" + ], + "details": "A vulnerability in langchain-core versions >=0.1.17,<0.1.53, >=0.2.0,<0.2.43, and >=0.3.0,<0.3.15 allows unauthorized users to read arbitrary files from the host file system. The issue arises from the ability to create langchain_core.prompts.ImagePromptTemplate's (and by extension langchain_core.prompts.ChatPromptTemplate's) with input variables that can read any user-specified path from the server file system. If the outputs of these prompt templates are exposed to the user, either directly or through downstream model outputs, it can lead to the exposure of sensitive information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10940" + }, + { + "type": "WEB", + "url": "https://github.com/langchain-ai/langchain/commit/c1e742347f9701aadba8920e4d1f79a636e50b68" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/be1ee1cb-2147-4ff4-a57b-b6045271cf27" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-497" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5cpq-9538-jm2j/GHSA-5cpq-9538-jm2j.json b/advisories/unreviewed/2025/03/GHSA-5cpq-9538-jm2j/GHSA-5cpq-9538-jm2j.json new file mode 100644 index 00000000000..401d07cfb2b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5cpq-9538-jm2j/GHSA-5cpq-9538-jm2j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5cpq-9538-jm2j", + "modified": "2025-03-20T12:32:49Z", + "published": "2025-03-20T12:32:49Z", + "aliases": [ + "CVE-2024-8966" + ], + "details": "A vulnerability in the file upload process of gradio-app/gradio version @gradio/video@0.10.2 allows for a Denial of Service (DoS) attack. An attacker can append a large number of characters to the end of a multipart boundary, causing the system to continuously process each character and issue warnings. This can render Gradio inaccessible for extended periods, disrupting services and causing significant downtime.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8966" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/7b5932bb-58d1-4e71-b85c-43dc40522ff2" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5fhx-jcwv-9wjj/GHSA-5fhx-jcwv-9wjj.json b/advisories/unreviewed/2025/03/GHSA-5fhx-jcwv-9wjj/GHSA-5fhx-jcwv-9wjj.json new file mode 100644 index 00000000000..4e2211468b0 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5fhx-jcwv-9wjj/GHSA-5fhx-jcwv-9wjj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5fhx-jcwv-9wjj", + "modified": "2025-03-20T12:32:43Z", + "published": "2025-03-20T12:32:43Z", + "aliases": [ + "CVE-2024-12389" + ], + "details": "A path traversal vulnerability exists in binary-husky/gpt_academic version git 310122f. The application supports the extraction of user-provided 7z files without proper validation. The Python py7zr package used for extraction does not guarantee that files will remain within the intended extraction directory. An attacker can exploit this vulnerability to perform arbitrary file writes, which can lead to remote code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12389" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/37afb1c9-bba9-47ee-8617-a5f715271654" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-29" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5jmj-h3c5-682w/GHSA-5jmj-h3c5-682w.json b/advisories/unreviewed/2025/03/GHSA-5jmj-h3c5-682w/GHSA-5jmj-h3c5-682w.json new file mode 100644 index 00000000000..f39d2629d69 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5jmj-h3c5-682w/GHSA-5jmj-h3c5-682w.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5jmj-h3c5-682w", + "modified": "2025-03-20T12:32:38Z", + "published": "2025-03-20T12:32:38Z", + "aliases": [ + "CVE-2024-10109" + ], + "details": "A vulnerability in the mintplex-labs/anything-llm repository, as of commit 5c40419, allows low privilege users to access the sensitive API endpoint \"/api/system/custom-models\". This access enables them to modify the model's API key and base path, leading to potential API key leakage and denial of service on chats.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10109" + }, + { + "type": "WEB", + "url": "https://github.com/mintplex-labs/anything-llm/commit/8d302c3f670c582b09d47e96132c248101447a11" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/ad3c9e76-679d-4775-b203-96947ff73551" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5mh3-rhm7-jxx3/GHSA-5mh3-rhm7-jxx3.json b/advisories/unreviewed/2025/03/GHSA-5mh3-rhm7-jxx3/GHSA-5mh3-rhm7-jxx3.json new file mode 100644 index 00000000000..87beb64b919 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5mh3-rhm7-jxx3/GHSA-5mh3-rhm7-jxx3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5mh3-rhm7-jxx3", + "modified": "2025-03-20T12:32:43Z", + "published": "2025-03-20T12:32:43Z", + "aliases": [ + "CVE-2024-12392" + ], + "details": "A Server-Side Request Forgery (SSRF) vulnerability exists in binary-husky/gpt_academic version git 310122f. The application has a functionality to download papers from arxiv.org, but the URL validation is incomplete. An attacker can exploit this vulnerability to make the application access any URL, including internal services, and read the response. This can be used to access data that are only accessible from the server, such as AWS metadata credentials, and can escalate local exploits to network-based attacks.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12392" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/858de346-698e-4a72-a9e9-3dbd6c60ac18" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5pfw-4vjf-fvc9/GHSA-5pfw-4vjf-fvc9.json b/advisories/unreviewed/2025/03/GHSA-5pfw-4vjf-fvc9/GHSA-5pfw-4vjf-fvc9.json new file mode 100644 index 00000000000..82472e9fd89 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5pfw-4vjf-fvc9/GHSA-5pfw-4vjf-fvc9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5pfw-4vjf-fvc9", + "modified": "2025-03-20T12:32:39Z", + "published": "2025-03-20T12:32:39Z", + "aliases": [ + "CVE-2024-10714" + ], + "details": "A vulnerability in binary-husky/gpt_academic version 3.83 allows an attacker to cause a Denial of Service (DoS) by adding excessive characters to the end of a multipart boundary during file upload. This results in the server continuously processing each character and displaying warnings, rendering the application inaccessible. The issue occurs when the terminal shows a warning: 'multipart.multipart Consuming a byte '0x2d' in end state'.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10714" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/3e25b76c-714f-4948-8f5a-0ec9a6500068" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5v9m-57mq-qc75/GHSA-5v9m-57mq-qc75.json b/advisories/unreviewed/2025/03/GHSA-5v9m-57mq-qc75/GHSA-5v9m-57mq-qc75.json new file mode 100644 index 00000000000..850f8e30201 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5v9m-57mq-qc75/GHSA-5v9m-57mq-qc75.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5v9m-57mq-qc75", + "modified": "2025-03-20T12:32:47Z", + "published": "2025-03-20T12:32:47Z", + "aliases": [ + "CVE-2024-7983" + ], + "details": "In version 0.3.8 of open-webui, an endpoint for converting markdown to HTML is exposed without authentication. A maliciously crafted markdown payload can cause the server to spend excessive time converting it, leading to a denial of service. The server becomes unresponsive to other requests until the conversion is complete.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7983" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/f8156ca5-1328-480f-a72b-8d3dfdad87dc" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5vqr-wprc-cpp7/GHSA-5vqr-wprc-cpp7.json b/advisories/unreviewed/2025/03/GHSA-5vqr-wprc-cpp7/GHSA-5vqr-wprc-cpp7.json new file mode 100644 index 00000000000..e52894129e6 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5vqr-wprc-cpp7/GHSA-5vqr-wprc-cpp7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5vqr-wprc-cpp7", + "modified": "2025-03-20T12:32:41Z", + "published": "2025-03-20T12:32:41Z", + "aliases": [ + "CVE-2024-11041" + ], + "details": "vllm-project vllm version v0.6.2 contains a vulnerability in the MessageQueue.dequeue() API function. The function uses pickle.loads to parse received sockets directly, leading to a remote code execution vulnerability. An attacker can exploit this by sending a malicious payload to the MessageQueue, causing the victim's machine to execute arbitrary code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11041" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/00136195-11e0-4ad0-98d5-72db066e867f" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5xg7-5662-8x7j/GHSA-5xg7-5662-8x7j.json b/advisories/unreviewed/2025/03/GHSA-5xg7-5662-8x7j/GHSA-5xg7-5662-8x7j.json new file mode 100644 index 00000000000..c0eb8c6621a --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5xg7-5662-8x7j/GHSA-5xg7-5662-8x7j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5xg7-5662-8x7j", + "modified": "2025-03-20T12:32:49Z", + "published": "2025-03-20T12:32:49Z", + "aliases": [ + "CVE-2024-8953" + ], + "details": "In composiohq/composio version 0.4.3, the mathematical_calculator endpoint uses the unsafe eval() function to perform mathematical operations. This can lead to arbitrary code execution if untrusted input is passed to the eval() function.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8953" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/8203d721-e05f-4500-a5bc-c0bec980420c" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-627" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-62xp-4pcv-pw3j/GHSA-62xp-4pcv-pw3j.json b/advisories/unreviewed/2025/03/GHSA-62xp-4pcv-pw3j/GHSA-62xp-4pcv-pw3j.json new file mode 100644 index 00000000000..357b36394eb --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-62xp-4pcv-pw3j/GHSA-62xp-4pcv-pw3j.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-62xp-4pcv-pw3j", + "modified": "2025-03-20T12:32:48Z", + "published": "2025-03-20T12:32:48Z", + "aliases": [ + "CVE-2024-8613" + ], + "details": "A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240802 allows attackers to access, copy, and delete other users' chat histories. This issue arises due to improper handling of session data and lack of access control mechanisms, enabling attackers to view and manipulate chat histories of other users.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8613" + }, + { + "type": "WEB", + "url": "https://github.com/gaizhenbiao/chuanhuchatgpt/commit/526c615c437377ee9c71f866fd0f19011910f705" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/76258774-b011-4044-9c3d-c2609b1cbd29" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-63gf-x2fr-8r32/GHSA-63gf-x2fr-8r32.json b/advisories/unreviewed/2025/03/GHSA-63gf-x2fr-8r32/GHSA-63gf-x2fr-8r32.json new file mode 100644 index 00000000000..f9873bb37ee --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-63gf-x2fr-8r32/GHSA-63gf-x2fr-8r32.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-63gf-x2fr-8r32", + "modified": "2025-03-20T12:32:47Z", + "published": "2025-03-20T12:32:47Z", + "aliases": [ + "CVE-2024-8055" + ], + "details": "Vanna v0.6.3 is vulnerable to SQL injection via Snowflake database in its file staging operations using the `PUT` and `COPY` commands. This vulnerability allows unauthenticated remote users to read arbitrary local files on the victim server, such as `/etc/passwd`, by exploiting the exposed SQL queries through a Python Flask API.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8055" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/7c92a611-6756-4885-8969-01d8b85b6c63" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-64c5-jj57-f29g/GHSA-64c5-jj57-f29g.json b/advisories/unreviewed/2025/03/GHSA-64c5-jj57-f29g/GHSA-64c5-jj57-f29g.json new file mode 100644 index 00000000000..f81ae0ee0a3 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-64c5-jj57-f29g/GHSA-64c5-jj57-f29g.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-64c5-jj57-f29g", + "modified": "2025-03-20T12:32:42Z", + "published": "2025-03-20T12:32:42Z", + "aliases": [ + "CVE-2024-11824" + ], + "details": "A stored cross-site scripting (XSS) vulnerability exists in langgenius/dify version latest, specifically in the chat log functionality. The vulnerability arises because certain HTML tags like and
are not disallowed, allowing an attacker to inject malicious HTML into the log via prompts. When an admin views the log containing the malicious HTML, the attacker could steal the admin's credentials or sensitive information. This issue is fixed in version 0.12.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11824" + }, + { + "type": "WEB", + "url": "https://github.com/langgenius/dify/commit/55edd5047e6fcbc9bb56a4ea055fcce090f3eb5d" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/72387deb-6e64-48ed-a8c3-b50d22a0970f" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-64jp-4xjj-prcw/GHSA-64jp-4xjj-prcw.json b/advisories/unreviewed/2025/03/GHSA-64jp-4xjj-prcw/GHSA-64jp-4xjj-prcw.json new file mode 100644 index 00000000000..aba933031b4 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-64jp-4xjj-prcw/GHSA-64jp-4xjj-prcw.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-64jp-4xjj-prcw", + "modified": "2025-03-20T12:32:39Z", + "published": "2025-03-20T12:32:39Z", + "aliases": [ + "CVE-2024-10457" + ], + "details": "Multiple Server-Side Request Forgery (SSRF) vulnerabilities were identified in the significant-gravitas/autogpt repository, specifically in the GitHub Integration and Web Search blocks. These vulnerabilities affect version agpt-platform-beta-v0.1.1. The issues arise when block inputs are controlled by untrusted sources, leading to potential credential leakage, internal network scanning, and unauthorized access to internal services, APIs, or data stores. The affected blocks include GithubListPullRequestsBlock, GithubReadPullRequestBlock, GithubAssignPRReviewerBlock, GithubListPRReviewersBlock, GithubUnassignPRReviewerBlock, GithubCommentBlock, GithubMakeIssueBlock, GithubReadIssueBlock, GithubListIssuesBlock, GithubAddLabelBlock, GithubRemoveLabelBlock, GithubListBranchesBlock, and ExtractWebsiteContentBlock.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10457" + }, + { + "type": "WEB", + "url": "https://github.com/significant-gravitas/autogpt/commit/bcaf3241dadfc1fca024e91fb8f2e3004105a172" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/1d91e1e1-7d45-4bda-bc27-bfe9052fd975" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-67hg-xcw3-33fm/GHSA-67hg-xcw3-33fm.json b/advisories/unreviewed/2025/03/GHSA-67hg-xcw3-33fm/GHSA-67hg-xcw3-33fm.json new file mode 100644 index 00000000000..bca2674c549 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-67hg-xcw3-33fm/GHSA-67hg-xcw3-33fm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-67hg-xcw3-33fm", + "modified": "2025-03-20T12:32:51Z", + "published": "2025-03-20T12:32:51Z", + "aliases": [ + "CVE-2024-9597" + ], + "details": "A Path Traversal vulnerability exists in the `/wipe_database` endpoint of parisneo/lollms version v12, allowing an attacker to delete any directory on the system. The vulnerability arises from improper validation of the `key` parameter, which is used to construct file paths. An attacker can exploit this by sending a specially crafted HTTP request to delete arbitrary directories.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9597" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/1f6c8908-d486-4141-be55-25bd29933d8b" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6827-g8xf-36c7/GHSA-6827-g8xf-36c7.json b/advisories/unreviewed/2025/03/GHSA-6827-g8xf-36c7/GHSA-6827-g8xf-36c7.json new file mode 100644 index 00000000000..2b906b35eec --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6827-g8xf-36c7/GHSA-6827-g8xf-36c7.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6827-g8xf-36c7", + "modified": "2025-03-20T12:32:41Z", + "published": "2025-03-20T12:32:41Z", + "aliases": [ + "CVE-2024-11172" + ], + "details": "A vulnerability in danny-avila/librechat version git a1647d7 allows an unauthenticated attacker to cause a denial of service by sending a crafted payload to the server. The middleware `checkBan` is not surrounded by a try-catch block, and an unhandled exception will cause the server to crash. This issue is fixed in version 0.7.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11172" + }, + { + "type": "WEB", + "url": "https://github.com/danny-avila/librechat/commit/976784c01fa4cce00d4c2941801d56aed375c21b" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/c76a7ee3-2e26-45a0-8940-21c749592105" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-69j6-4w2p-2887/GHSA-69j6-4w2p-2887.json b/advisories/unreviewed/2025/03/GHSA-69j6-4w2p-2887/GHSA-69j6-4w2p-2887.json new file mode 100644 index 00000000000..d9bb76b8305 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-69j6-4w2p-2887/GHSA-69j6-4w2p-2887.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-69j6-4w2p-2887", + "modified": "2025-03-20T12:32:39Z", + "published": "2025-03-20T12:32:38Z", + "aliases": [ + "CVE-2024-10272" + ], + "details": "lunary-ai/lunary is vulnerable to broken access control in the latest version. An attacker can view the content of any dataset without any kind of authorization by sending a GET request to the /v1/datasets endpoint without a valid authorization token.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10272" + }, + { + "type": "WEB", + "url": "https://github.com/lunary-ai/lunary/commit/35dd4af0001a54ccb14276a1546eb977f82c0c5e" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/3de48a54-b5c9-40a1-b794-d59c36d58fb6" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6ch3-c5vc-j2r6/GHSA-6ch3-c5vc-j2r6.json b/advisories/unreviewed/2025/03/GHSA-6ch3-c5vc-j2r6/GHSA-6ch3-c5vc-j2r6.json new file mode 100644 index 00000000000..a3e44f34f37 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6ch3-c5vc-j2r6/GHSA-6ch3-c5vc-j2r6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6ch3-c5vc-j2r6", + "modified": "2025-03-20T12:32:44Z", + "published": "2025-03-20T12:32:44Z", + "aliases": [ + "CVE-2024-12866" + ], + "details": "A local file inclusion vulnerability exists in netease-youdao/qanything version v2.0.0. This vulnerability allows an attacker to read arbitrary files on the file system, which can lead to remote code execution by retrieving private SSH keys, reading private files, source code, and configuration files.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12866" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/c23da7c7-a226-40a2-83db-6a8ab1b2ef64" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6f6x-f56q-5xgv/GHSA-6f6x-f56q-5xgv.json b/advisories/unreviewed/2025/03/GHSA-6f6x-f56q-5xgv/GHSA-6f6x-f56q-5xgv.json new file mode 100644 index 00000000000..e462d11e5f4 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6f6x-f56q-5xgv/GHSA-6f6x-f56q-5xgv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6f6x-f56q-5xgv", + "modified": "2025-03-20T12:32:40Z", + "published": "2025-03-20T12:32:40Z", + "aliases": [ + "CVE-2024-10821" + ], + "details": "A Denial of Service (DoS) vulnerability in the multipart request boundary processing mechanism of the Invoke-AI server (version v5.0.1) allows unauthenticated attackers to cause excessive resource consumption. The server fails to handle excessive characters appended to the end of multipart boundaries, leading to an infinite loop and a complete denial of service for all users. The affected endpoint is `/api/v1/images/upload`.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10821" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/0ac24835-c4c0-4f11-938a-d5641dfb80b2" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6fwx-j832-vvw6/GHSA-6fwx-j832-vvw6.json b/advisories/unreviewed/2025/03/GHSA-6fwx-j832-vvw6/GHSA-6fwx-j832-vvw6.json new file mode 100644 index 00000000000..c275097b377 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6fwx-j832-vvw6/GHSA-6fwx-j832-vvw6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6fwx-j832-vvw6", + "modified": "2025-03-20T12:32:41Z", + "published": "2025-03-20T12:32:41Z", + "aliases": [ + "CVE-2024-10956" + ], + "details": "GPT Academy version 3.83 in the binary-husky/gpt_academic repository is vulnerable to Cross-Site WebSocket Hijacking (CSWSH). This vulnerability allows an attacker to hijack an existing WebSocket connection between the victim's browser and the server, enabling unauthorized actions such as deleting conversation history without the victim's consent. The issue arises due to insufficient WebSocket authentication and lack of origin validation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10956" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/0f8403ad-5f60-4eb9-9f51-8fbd2e41eda4" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6gmf-2369-c76c/GHSA-6gmf-2369-c76c.json b/advisories/unreviewed/2025/03/GHSA-6gmf-2369-c76c/GHSA-6gmf-2369-c76c.json new file mode 100644 index 00000000000..14107d0ac39 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6gmf-2369-c76c/GHSA-6gmf-2369-c76c.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6gmf-2369-c76c", + "modified": "2025-03-20T12:32:51Z", + "published": "2025-03-20T12:32:51Z", + "aliases": [ + "CVE-2024-9340" + ], + "details": "A Denial of Service (DoS) vulnerability in zenml-io/zenml version 0.66.0 allows unauthenticated attackers to cause excessive resource consumption by sending malformed multipart requests with arbitrary characters appended to the end of multipart boundaries. This flaw in the multipart request boundary processing mechanism leads to an infinite loop, resulting in a complete denial of service for all users. Affected endpoints include `/api/v1/login` and `/api/v1/device_authorization`.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9340" + }, + { + "type": "WEB", + "url": "https://github.com/zenml-io/zenml/commit/cba152eb9ca3071c8372b0b91c02d9d3351de48d" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/c9200654-7dc0-4c1d-8573-ab79a87fb4f6" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6mf6-7j75-2m6f/GHSA-6mf6-7j75-2m6f.json b/advisories/unreviewed/2025/03/GHSA-6mf6-7j75-2m6f/GHSA-6mf6-7j75-2m6f.json new file mode 100644 index 00000000000..650d215f042 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6mf6-7j75-2m6f/GHSA-6mf6-7j75-2m6f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6mf6-7j75-2m6f", + "modified": "2025-03-20T12:32:48Z", + "published": "2025-03-20T12:32:48Z", + "aliases": [ + "CVE-2024-8556" + ], + "details": "A stored cross-site scripting (XSS) vulnerability exists in modelscope/agentscope, as of the latest commit 21161fe on the main branch. The vulnerability occurs in the view for inspecting detailed run information, where a user-controllable string (run ID) is appended and rendered as HTML. This allows an attacker to execute arbitrary JavaScript code in the context of the user's browser.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8556" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/8439f16b-5256-4466-bb7d-371572572a4b" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6pvw-p9fg-rwxj/GHSA-6pvw-p9fg-rwxj.json b/advisories/unreviewed/2025/03/GHSA-6pvw-p9fg-rwxj/GHSA-6pvw-p9fg-rwxj.json new file mode 100644 index 00000000000..723b24f2a77 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6pvw-p9fg-rwxj/GHSA-6pvw-p9fg-rwxj.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6pvw-p9fg-rwxj", + "modified": "2025-03-20T12:32:40Z", + "published": "2025-03-20T12:32:40Z", + "aliases": [ + "CVE-2024-10727" + ], + "details": "A reflected cross-site scripting (XSS) vulnerability exists in phpipam/phpipam versions 1.5.0 through 1.6.0. The vulnerability arises when the application receives data in an HTTP request and includes that data within the immediate response in an unsafe manner. This allows an attacker to execute arbitrary JavaScript in the context of the user's browser, potentially leading to full compromise of the user.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10727" + }, + { + "type": "WEB", + "url": "https://github.com/phpipam/phpipam/commit/c1697bb6c4e4a6403d69c0868e1eb1040f98b731" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/259eed22-4d6f-4229-92e5-04674f302d5d" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6rvg-6v2m-4j46/GHSA-6rvg-6v2m-4j46.json b/advisories/unreviewed/2025/03/GHSA-6rvg-6v2m-4j46/GHSA-6rvg-6v2m-4j46.json new file mode 100644 index 00000000000..7b94f2d41f6 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6rvg-6v2m-4j46/GHSA-6rvg-6v2m-4j46.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6rvg-6v2m-4j46", + "modified": "2025-03-20T12:32:43Z", + "published": "2025-03-20T12:32:43Z", + "aliases": [ + "CVE-2024-12720" + ], + "details": "A Regular Expression Denial of Service (ReDoS) vulnerability was identified in the huggingface/transformers library, specifically in the file tokenization_nougat_fast.py. The vulnerability occurs in the post_process_single() function, where a regular expression processes specially crafted input. The issue stems from the regex exhibiting exponential time complexity under certain conditions, leading to excessive backtracking. This can result in significantly high CPU usage and potential application downtime, effectively creating a Denial of Service (DoS) scenario. The affected version is v4.46.3 (latest).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12720" + }, + { + "type": "WEB", + "url": "https://github.com/huggingface/transformers/commit/deac971c469bcbb182c2e52da0b82fb3bf54cccf" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/4bed1214-7835-4252-a853-22bbad891f98" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1333" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6v28-q95m-93qr/GHSA-6v28-q95m-93qr.json b/advisories/unreviewed/2025/03/GHSA-6v28-q95m-93qr/GHSA-6v28-q95m-93qr.json new file mode 100644 index 00000000000..1b4329e35d6 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6v28-q95m-93qr/GHSA-6v28-q95m-93qr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6v28-q95m-93qr", + "modified": "2025-03-20T12:32:48Z", + "published": "2025-03-20T12:32:48Z", + "aliases": [ + "CVE-2024-8524" + ], + "details": "A directory traversal vulnerability exists in modelscope/agentscope version 0.0.4. An attacker can exploit this vulnerability to read any local JSON file by sending a crafted POST request to the /read-examples endpoint.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8524" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/cc4acf33-700d-4220-8a8a-db28f5c4cc8f" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-73" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6vmm-pmxf-9784/GHSA-6vmm-pmxf-9784.json b/advisories/unreviewed/2025/03/GHSA-6vmm-pmxf-9784/GHSA-6vmm-pmxf-9784.json new file mode 100644 index 00000000000..756c2cdd7d8 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6vmm-pmxf-9784/GHSA-6vmm-pmxf-9784.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6vmm-pmxf-9784", + "modified": "2025-03-20T12:32:41Z", + "published": "2025-03-20T12:32:41Z", + "aliases": [ + "CVE-2024-11045" + ], + "details": "A Cross-Site WebSocket Hijacking (CSWSH) vulnerability in automatic1111/stable-diffusion-webui version 1.10.0 allows an attacker to clone a malicious server extension from a GitHub repository. The vulnerability arises from the lack of proper validation on WebSocket connections at ws://127.0.0.1:7860/queue/join, enabling unauthorized actions on the server. This can lead to unauthorized cloning of server extensions, execution of malicious scripts, data exfiltration, and potential denial of service (DoS).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11045" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/b7ed0d87-0be5-4526-9b21-ffe0d39c283e" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6w2c-f4vg-j9hv/GHSA-6w2c-f4vg-j9hv.json b/advisories/unreviewed/2025/03/GHSA-6w2c-f4vg-j9hv/GHSA-6w2c-f4vg-j9hv.json new file mode 100644 index 00000000000..ab85b558315 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6w2c-f4vg-j9hv/GHSA-6w2c-f4vg-j9hv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6w2c-f4vg-j9hv", + "modified": "2025-03-20T12:32:51Z", + "published": "2025-03-20T12:32:51Z", + "aliases": [ + "CVE-2024-9919" + ], + "details": "A missing authentication check in the uninstall endpoint of parisneo/lollms-webui V13 allows attackers to perform unauthorized directory deletions. The /uninstall/{app_name} API endpoint does not call the check_access() function to verify the client_id, enabling attackers to delete directories without proper authentication.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9919" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/5c00f56b-32a8-4e26-a4e3-de64f139da6b" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-304" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6w62-3jvj-mfj6/GHSA-6w62-3jvj-mfj6.json b/advisories/unreviewed/2025/03/GHSA-6w62-3jvj-mfj6/GHSA-6w62-3jvj-mfj6.json new file mode 100644 index 00000000000..518be7c0ddf --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6w62-3jvj-mfj6/GHSA-6w62-3jvj-mfj6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6w62-3jvj-mfj6", + "modified": "2025-03-20T12:32:46Z", + "published": "2025-03-20T12:32:46Z", + "aliases": [ + "CVE-2024-7765" + ], + "details": "In h2oai/h2o-3 version 3.46.0.2, a vulnerability exists where uploading and repeatedly parsing a large GZIP file can cause a denial of service. The server becomes unresponsive due to memory exhaustion and a large number of concurrent slow-running jobs. This issue arises from the improper handling of highly compressed data, leading to significant data amplification.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7765" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/0e58b1a5-bdca-4e60-af92-09de9c76a9ff" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-409" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6w7p-xrvp-p7xv/GHSA-6w7p-xrvp-p7xv.json b/advisories/unreviewed/2025/03/GHSA-6w7p-xrvp-p7xv/GHSA-6w7p-xrvp-p7xv.json new file mode 100644 index 00000000000..65bc80c424b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6w7p-xrvp-p7xv/GHSA-6w7p-xrvp-p7xv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6w7p-xrvp-p7xv", + "modified": "2025-03-20T12:32:47Z", + "published": "2025-03-20T12:32:47Z", + "aliases": [ + "CVE-2024-8061" + ], + "details": "In version 3.23.0 of aimhubio/aim, certain methods that request data from external servers do not have set timeouts, causing the server to wait indefinitely for a response. This can lead to a denial of service, as the tracking server does not respond to other requests while waiting. The issue arises in the client used by the `aim` tracking server to communicate with external resources, specifically in the `_run_read_instructions` method and similar calls without timeouts.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8061" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/c85d005c-b354-4c51-a88f-adda2f09622b" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6wj5-5pgr-jwq8/GHSA-6wj5-5pgr-jwq8.json b/advisories/unreviewed/2025/03/GHSA-6wj5-5pgr-jwq8/GHSA-6wj5-5pgr-jwq8.json new file mode 100644 index 00000000000..2ba6ceb3309 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6wj5-5pgr-jwq8/GHSA-6wj5-5pgr-jwq8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6wj5-5pgr-jwq8", + "modified": "2025-03-20T12:32:46Z", + "published": "2025-03-20T12:32:46Z", + "aliases": [ + "CVE-2024-7999" + ], + "details": "A vulnerability in open-webui/open-webui version 79778fa allows an attacker to cause a Denial of Service (DoS) by uploading a file with a malformed multipart boundary. By appending a large number of characters to the end of the multipart boundary, the server continuously processes each character, rendering the application inaccessible. This issue can prevent all users from accessing the application until the server recovers.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7999" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/15eb4fbe-70d4-420e-806a-ec6f4ecb7202" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6xgj-c5fx-5v57/GHSA-6xgj-c5fx-5v57.json b/advisories/unreviewed/2025/03/GHSA-6xgj-c5fx-5v57/GHSA-6xgj-c5fx-5v57.json new file mode 100644 index 00000000000..db91c23a918 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6xgj-c5fx-5v57/GHSA-6xgj-c5fx-5v57.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6xgj-c5fx-5v57", + "modified": "2025-03-20T12:32:40Z", + "published": "2025-03-20T12:32:40Z", + "aliases": [ + "CVE-2024-10829" + ], + "details": "A Denial of Service (DoS) vulnerability in the multipart request boundary processing mechanism of eosphoros-ai/db-gpt v0.6.0 allows unauthenticated attackers to cause excessive resource consumption. The server fails to handle excessive characters appended to the end of multipart boundaries, leading to an infinite loop and complete denial of service for all users. This vulnerability affects all endpoints processing multipart/form-data requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10829" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/e3a4a0ad-a2e0-497f-a2e0-e3c0ec7c4de4" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-726r-vfh2-3vvj/GHSA-726r-vfh2-3vvj.json b/advisories/unreviewed/2025/03/GHSA-726r-vfh2-3vvj/GHSA-726r-vfh2-3vvj.json new file mode 100644 index 00000000000..fcb3e87271f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-726r-vfh2-3vvj/GHSA-726r-vfh2-3vvj.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-726r-vfh2-3vvj", + "modified": "2025-03-20T12:32:40Z", + "published": "2025-03-20T12:32:39Z", + "aliases": [ + "CVE-2024-10719" + ], + "details": "A stored cross-site scripting (XSS) vulnerability exists in phpipam version 1.5.2, specifically in the circuits options functionality. This vulnerability allows an attacker to inject malicious scripts via the 'option' parameter in the POST request to /phpipam/app/admin/circuits/edit-options-submit.php. The injected script can be executed in the context of the user's browser, leading to potential cookie theft and end-user file disclosure. The issue is fixed in version 1.7.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10719" + }, + { + "type": "WEB", + "url": "https://github.com/phpipam/phpipam/commit/c1697bb6c4e4a6403d69c0868e1eb1040f98b731" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/56aba8cb-4da1-44b4-8c4d-c5ba00ea3670" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-73c8-qmph-r39f/GHSA-73c8-qmph-r39f.json b/advisories/unreviewed/2025/03/GHSA-73c8-qmph-r39f/GHSA-73c8-qmph-r39f.json new file mode 100644 index 00000000000..399c666a5ec --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-73c8-qmph-r39f/GHSA-73c8-qmph-r39f.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-73c8-qmph-r39f", + "modified": "2025-03-20T12:32:41Z", + "published": "2025-03-20T12:32:41Z", + "aliases": [ + "CVE-2024-11137" + ], + "details": "An Insecure Direct Object Reference (IDOR) vulnerability exists in the `PATCH /v1/runs/:id/score` endpoint of lunary-ai/lunary version 1.6.0. This vulnerability allows an attacker to update the score data of any run by manipulating the id parameter in the request URL, which corresponds to the `runId_score` in the database. The endpoint does not sufficiently validate whether the authenticated user has permission to modify the specified runId, enabling an attacker with a valid account to modify other users' runId scores by specifying different id values. This issue was fixed in version 1.6.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11137" + }, + { + "type": "WEB", + "url": "https://github.com/lunary-ai/lunary/commit/ded72a95c220904a151d27daf3c67e8644e386c6" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/0a399d86-0105-4f48-a77b-9fa7d7054be8" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-73p4-hh43-4h48/GHSA-73p4-hh43-4h48.json b/advisories/unreviewed/2025/03/GHSA-73p4-hh43-4h48/GHSA-73p4-hh43-4h48.json new file mode 100644 index 00000000000..28e16f3cd8b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-73p4-hh43-4h48/GHSA-73p4-hh43-4h48.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-73p4-hh43-4h48", + "modified": "2025-03-20T12:32:42Z", + "published": "2025-03-20T12:32:42Z", + "aliases": [ + "CVE-2024-11301" + ], + "details": "In lunary-ai/lunary before version 1.6.3, the application allows the creation of evaluators without enforcing a unique constraint on the combination of projectId and slug. This allows an attacker to overwrite existing data by submitting a POST request with the same slug as an existing evaluator. The lack of database constraints or application-layer validation to prevent duplicates exposes the application to data integrity issues. This vulnerability can result in corrupted data and potentially malicious actions, impairing the system's functionality.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11301" + }, + { + "type": "WEB", + "url": "https://github.com/lunary-ai/lunary/commit/79dc370596d979b756f6ea0250d97a2d02385ecd" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/3d99aca5-b135-4833-b48b-7806bc4bf861" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-837" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-745f-48gc-258q/GHSA-745f-48gc-258q.json b/advisories/unreviewed/2025/03/GHSA-745f-48gc-258q/GHSA-745f-48gc-258q.json new file mode 100644 index 00000000000..86d40c72a92 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-745f-48gc-258q/GHSA-745f-48gc-258q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-745f-48gc-258q", + "modified": "2025-03-20T12:32:38Z", + "published": "2025-03-20T12:32:38Z", + "aliases": [ + "CVE-2024-10225" + ], + "details": "A vulnerability in haotian-liu/llava v1.2.0 allows an attacker to cause a Denial of Service (DoS) by appending a large number of characters to the end of a multipart boundary in a file upload request. This causes the server to continuously process each character, rendering the application inaccessible.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10225" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/cd793f83-f122-432b-83e7-1cc8c78817b7" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-747f-ww56-4q4h/GHSA-747f-ww56-4q4h.json b/advisories/unreviewed/2025/03/GHSA-747f-ww56-4q4h/GHSA-747f-ww56-4q4h.json new file mode 100644 index 00000000000..59a4853387a --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-747f-ww56-4q4h/GHSA-747f-ww56-4q4h.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-747f-ww56-4q4h", + "modified": "2025-03-20T12:32:51Z", + "published": "2025-03-20T12:32:51Z", + "aliases": [ + "CVE-2024-9701" + ], + "details": "A Remote Code Execution (RCE) vulnerability has been identified in the Kedro ShelveStore class (version 0.19.8). This vulnerability allows an attacker to execute arbitrary Python code via deserialization of malicious payloads, potentially leading to a full system compromise. The ShelveStore class uses Python's shelve module to manage session data, which relies on pickle for serialization. Crafting a malicious payload and storing it in the shelve file can lead to RCE when the payload is deserialized.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9701" + }, + { + "type": "WEB", + "url": "https://github.com/kedro-org/kedro/commit/d79fa51de55ac0ccb58cce1a482df1b445f0fe7c" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/96c77fef-93b2-4d4d-8cbe-57a718d8eea5" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-749v-xf6w-5wcx/GHSA-749v-xf6w-5wcx.json b/advisories/unreviewed/2025/03/GHSA-749v-xf6w-5wcx/GHSA-749v-xf6w-5wcx.json new file mode 100644 index 00000000000..c794ca5e2fe --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-749v-xf6w-5wcx/GHSA-749v-xf6w-5wcx.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-749v-xf6w-5wcx", + "modified": "2025-03-20T12:32:53Z", + "published": "2025-03-20T12:32:53Z", + "aliases": [ + "CVE-2024-13920" + ], + "details": "The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.6.0 via the download_file() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to read the contents of arbitrary log files on the server, which can contain sensitive information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13920" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/order-import-export-for-woocommerce/trunk/admin/modules/history/history.php#L751" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3258567" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/users-customers-import-export-for-wp-woocommerce/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/dba84eb3-f48a-4175-a652-7c11b12c9afc?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T12:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-75px-35p4-qq6h/GHSA-75px-35p4-qq6h.json b/advisories/unreviewed/2025/03/GHSA-75px-35p4-qq6h/GHSA-75px-35p4-qq6h.json new file mode 100644 index 00000000000..b38b1661c67 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-75px-35p4-qq6h/GHSA-75px-35p4-qq6h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-75px-35p4-qq6h", + "modified": "2025-03-20T12:32:45Z", + "published": "2025-03-20T12:32:45Z", + "aliases": [ + "CVE-2024-6829" + ], + "details": "A vulnerability in aimhubio/aim version 3.19.3 allows an attacker to exploit the `tarfile.extractall()` function to extract the contents of a maliciously crafted tarfile to arbitrary locations on the host server. The attacker can control `repo.path` and `run_hash` to bypass directory existence checks and extract files to unintended locations, potentially overwriting critical files. This can lead to arbitrary data being written to arbitrary locations on the remote tracking server, which could be used for further attacks such as writing a new SSH key to the target server.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6829" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/7c97065c-1b63-4982-82c1-8038be0ed570" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-73" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-75v5-6885-59f9/GHSA-75v5-6885-59f9.json b/advisories/unreviewed/2025/03/GHSA-75v5-6885-59f9/GHSA-75v5-6885-59f9.json new file mode 100644 index 00000000000..a750c4a04d6 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-75v5-6885-59f9/GHSA-75v5-6885-59f9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-75v5-6885-59f9", + "modified": "2025-03-20T12:32:48Z", + "published": "2025-03-20T12:32:48Z", + "aliases": [ + "CVE-2024-8487" + ], + "details": "A Cross-Origin Resource Sharing (CORS) vulnerability exists in modelscope/agentscope version v0.0.4. The CORS configuration on the agentscope server does not properly restrict access to only trusted origins, allowing any external domain to make requests to the API. This can lead to unauthorized data access, information disclosure, and potential further exploitation, thereby compromising the integrity and confidentiality of the system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8487" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/7aca7507-a94e-4e63-83a2-15648e5c4067" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-346" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-775f-24cq-qg6p/GHSA-775f-24cq-qg6p.json b/advisories/unreviewed/2025/03/GHSA-775f-24cq-qg6p/GHSA-775f-24cq-qg6p.json new file mode 100644 index 00000000000..f8bb4dcaed6 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-775f-24cq-qg6p/GHSA-775f-24cq-qg6p.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-775f-24cq-qg6p", + "modified": "2025-03-20T12:32:43Z", + "published": "2025-03-20T12:32:43Z", + "aliases": [ + "CVE-2024-12450" + ], + "details": "In infiniflow/ragflow versions 0.12.0, the `web_crawl` function in `document_app.py` contains multiple vulnerabilities. The function does not filter URL parameters, allowing attackers to exploit Full Read SSRF by accessing internal network addresses and viewing their content through the generated PDF files. Additionally, the lack of restrictions on the file protocol enables Arbitrary File Read, allowing attackers to read server files. Furthermore, the use of an outdated Chromium headless version with --no-sandbox mode enabled makes the application susceptible to Remote Code Execution (RCE) via known Chromium v8 vulnerabilities. These issues are resolved in version 0.14.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12450" + }, + { + "type": "WEB", + "url": "https://github.com/infiniflow/ragflow/commit/3faae0b2c2f8a26233ee1442ba04874b3406f6e9" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/da06360c-87c3-4ba9-be67-29f6eff9d44a" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-77cj-rv5x-v6r2/GHSA-77cj-rv5x-v6r2.json b/advisories/unreviewed/2025/03/GHSA-77cj-rv5x-v6r2/GHSA-77cj-rv5x-v6r2.json new file mode 100644 index 00000000000..aba1a8f9821 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-77cj-rv5x-v6r2/GHSA-77cj-rv5x-v6r2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-77cj-rv5x-v6r2", + "modified": "2025-03-20T12:32:41Z", + "published": "2025-03-20T12:32:41Z", + "aliases": [ + "CVE-2024-10908" + ], + "details": "An open redirect vulnerability in lm-sys/fastchat Release v0.2.36 allows a remote unauthenticated attacker to redirect users to arbitrary websites via a specially crafted URL. This can be exploited for phishing attacks, malware distribution, and credential theft.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10908" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/61f5e725-5579-4d08-8a88-e4ba04e6d1f2" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-79rp-v9rm-gxm8/GHSA-79rp-v9rm-gxm8.json b/advisories/unreviewed/2025/03/GHSA-79rp-v9rm-gxm8/GHSA-79rp-v9rm-gxm8.json new file mode 100644 index 00000000000..68adabc4f54 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-79rp-v9rm-gxm8/GHSA-79rp-v9rm-gxm8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-79rp-v9rm-gxm8", + "modified": "2025-03-20T12:32:41Z", + "published": "2025-03-20T12:32:41Z", + "aliases": [ + "CVE-2024-10912" + ], + "details": "A Denial of Service (DoS) vulnerability exists in the file upload feature of lm-sys/fastchat version 0.2.36. The vulnerability is due to improper handling of form-data with a large filename in the file upload request. An attacker can exploit this by sending a payload with an excessively large filename, causing the server to become overwhelmed and unavailable to legitimate users.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10912" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/52f335b8-1134-4d0f-acb4-efef516de414" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-7g3f-q846-q9hx/GHSA-7g3f-q846-q9hx.json b/advisories/unreviewed/2025/03/GHSA-7g3f-q846-q9hx/GHSA-7g3f-q846-q9hx.json new file mode 100644 index 00000000000..77015b1cfe4 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-7g3f-q846-q9hx/GHSA-7g3f-q846-q9hx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7g3f-q846-q9hx", + "modified": "2025-03-20T12:32:46Z", + "published": "2025-03-20T12:32:46Z", + "aliases": [ + "CVE-2024-7764" + ], + "details": "Vanna-ai v0.6.2 is vulnerable to SQL Injection due to insufficient protection against injecting additional SQL commands from user requests. The vulnerability occurs when the `generate_sql` function calls `extract_sql` with the LLM response. An attacker can include a semi-colon between a search data field and their own command, causing the `extract_sql` function to remove all LLM generated SQL and execute the attacker's command if it passes the `is_sql_valid` function. This allows the execution of user-defined SQL beyond the expected boundaries, notably the trained schema.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7764" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/85d403b1-fbed-42e9-9ec1-2f79abf6eb0f" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-7gj6-22m4-qfhx/GHSA-7gj6-22m4-qfhx.json b/advisories/unreviewed/2025/03/GHSA-7gj6-22m4-qfhx/GHSA-7gj6-22m4-qfhx.json new file mode 100644 index 00000000000..8a419f03c6f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-7gj6-22m4-qfhx/GHSA-7gj6-22m4-qfhx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7gj6-22m4-qfhx", + "modified": "2025-03-20T12:32:40Z", + "published": "2025-03-20T12:32:40Z", + "aliases": [ + "CVE-2024-10901" + ], + "details": "In eosphoros-ai/db-gpt version v0.6.0, the web API `POST /api/v1/editor/chart/run` allows execution of arbitrary SQL queries without any access control. This vulnerability can be exploited by attackers to perform Arbitrary File Write, enabling them to write arbitrary files to the victim's file system. This can potentially lead to Remote Code Execution (RCE) by writing malicious files such as `__init__.py` in the Python's `/site-packages/` directory.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10901" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/db2c1d59-6e3a-4553-a1f6-94c8df162a18" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-7h46-xxgg-f9q8/GHSA-7h46-xxgg-f9q8.json b/advisories/unreviewed/2025/03/GHSA-7h46-xxgg-f9q8/GHSA-7h46-xxgg-f9q8.json new file mode 100644 index 00000000000..2f23ca22945 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-7h46-xxgg-f9q8/GHSA-7h46-xxgg-f9q8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7h46-xxgg-f9q8", + "modified": "2025-03-20T12:32:40Z", + "published": "2025-03-20T12:32:40Z", + "aliases": [ + "CVE-2024-10834" + ], + "details": "eosphoros-ai/db-gpt version 0.6.0 contains a vulnerability in the RAG-knowledge endpoint that allows for arbitrary file write. The issue arises from the ability to pass an absolute path to a call to `os.path.join`, enabling an attacker to write files to arbitrary locations on the target server. This vulnerability can be exploited by setting the `doc_file.filename` to an absolute path, which can lead to overwriting system files or creating new SSH-key entries.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10834" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/0d598508-151a-4050-9ccd-31bb82955e7a" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-73" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-7hc9-vjg2-vpcr/GHSA-7hc9-vjg2-vpcr.json b/advisories/unreviewed/2025/03/GHSA-7hc9-vjg2-vpcr/GHSA-7hc9-vjg2-vpcr.json new file mode 100644 index 00000000000..d4583b9b746 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-7hc9-vjg2-vpcr/GHSA-7hc9-vjg2-vpcr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7hc9-vjg2-vpcr", + "modified": "2025-03-20T12:32:42Z", + "published": "2025-03-20T12:32:42Z", + "aliases": [ + "CVE-2024-12068" + ], + "details": "A Server-Side Request Forgery (SSRF) vulnerability was discovered in haotian-liu/llava, affecting version git c121f04. This vulnerability allows an attacker to make the server perform HTTP requests to arbitrary URLs, potentially accessing sensitive data that is only accessible from the server, such as AWS metadata credentials.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12068" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/9d0b908d-63cd-4d62-91ff-6ceef3183752" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-7j9v-mc62-mcm5/GHSA-7j9v-mc62-mcm5.json b/advisories/unreviewed/2025/03/GHSA-7j9v-mc62-mcm5/GHSA-7j9v-mc62-mcm5.json new file mode 100644 index 00000000000..df003b910b5 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-7j9v-mc62-mcm5/GHSA-7j9v-mc62-mcm5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7j9v-mc62-mcm5", + "modified": "2025-03-20T12:32:42Z", + "published": "2025-03-20T12:32:42Z", + "aliases": [ + "CVE-2024-11850" + ], + "details": "A stored cross-site scripting (XSS) vulnerability exists in the latest version of langgenius/dify. The vulnerability is due to improper validation and sanitization of user input in SVG markdown support within the chatbot feature. An attacker can exploit this vulnerability by injecting malicious SVG content, which can execute arbitrary JavaScript code when viewed by an admin, potentially leading to credential theft.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11850" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/893da115-028d-4718-b586-a2b77897a470" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-7qq7-pvm9-x8rf/GHSA-7qq7-pvm9-x8rf.json b/advisories/unreviewed/2025/03/GHSA-7qq7-pvm9-x8rf/GHSA-7qq7-pvm9-x8rf.json new file mode 100644 index 00000000000..388247a4404 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-7qq7-pvm9-x8rf/GHSA-7qq7-pvm9-x8rf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7qq7-pvm9-x8rf", + "modified": "2025-03-20T12:32:39Z", + "published": "2025-03-20T12:32:39Z", + "aliases": [ + "CVE-2024-10550" + ], + "details": "A vulnerability in the `/3/ParseSetup` endpoint of h2oai/h2o-3 version 3.46.0.1 allows for a denial of service (DoS) attack. The endpoint applies a user-specified regular expression to a user-controllable string. This can be exploited by an attacker to cause inefficient regular expression complexity, leading to the exhaustion of server resources and making the server unresponsive.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10550" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/ef3f4d89-3b8b-4618-b134-cb93c1664ec6" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1333" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-7rxf-gvfg-47g4/GHSA-7rxf-gvfg-47g4.json b/advisories/unreviewed/2025/03/GHSA-7rxf-gvfg-47g4/GHSA-7rxf-gvfg-47g4.json new file mode 100644 index 00000000000..f776d630d2c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-7rxf-gvfg-47g4/GHSA-7rxf-gvfg-47g4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7rxf-gvfg-47g4", + "modified": "2025-03-20T12:32:45Z", + "published": "2025-03-20T12:32:45Z", + "aliases": [ + "CVE-2024-6839" + ], + "details": "corydolphin/flask-cors version 4.0.1 contains an improper regex path matching vulnerability. The plugin prioritizes longer regex patterns over more specific ones when matching paths, which can lead to less restrictive CORS policies being applied to sensitive endpoints. This mismatch in regex pattern priority allows unauthorized cross-origin access to sensitive data or functionality, potentially exposing confidential information and increasing the risk of unauthorized actions by malicious actors.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6839" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/403eb1fc-86f4-4820-8eba-0f3dfae9f2b4" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-41" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-7v2w-h4gh-w5cv/GHSA-7v2w-h4gh-w5cv.json b/advisories/unreviewed/2025/03/GHSA-7v2w-h4gh-w5cv/GHSA-7v2w-h4gh-w5cv.json new file mode 100644 index 00000000000..af07a789679 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-7v2w-h4gh-w5cv/GHSA-7v2w-h4gh-w5cv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7v2w-h4gh-w5cv", + "modified": "2025-03-20T12:32:47Z", + "published": "2025-03-20T12:32:47Z", + "aliases": [ + "CVE-2024-8021" + ], + "details": "An open redirect vulnerability exists in the latest version of gradio-app/gradio. The vulnerability allows an attacker to redirect users to a malicious website by URL encoding. This can be exploited by sending a crafted request to the application, which results in a 302 redirect to an attacker-controlled site.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8021" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/adc23067-ec04-47ef-9265-afd452071888" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-7xmc-vhjp-qv5q/GHSA-7xmc-vhjp-qv5q.json b/advisories/unreviewed/2025/03/GHSA-7xmc-vhjp-qv5q/GHSA-7xmc-vhjp-qv5q.json new file mode 100644 index 00000000000..fdb49064890 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-7xmc-vhjp-qv5q/GHSA-7xmc-vhjp-qv5q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7xmc-vhjp-qv5q", + "modified": "2025-03-20T12:32:39Z", + "published": "2025-03-20T12:32:39Z", + "aliases": [ + "CVE-2024-10569" + ], + "details": "A vulnerability in the dataframe component of gradio-app/gradio (version git 98cbcae) allows for a zip bomb attack. The component uses pd.read_csv to process input values, which can accept compressed files. An attacker can exploit this by uploading a maliciously crafted zip bomb, leading to a server crash and causing a denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10569" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/7192bcbb-08a3-4d22-a321-9c6d19dbfc74" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-475" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-823j-2wj6-7jwh/GHSA-823j-2wj6-7jwh.json b/advisories/unreviewed/2025/03/GHSA-823j-2wj6-7jwh/GHSA-823j-2wj6-7jwh.json new file mode 100644 index 00000000000..9f2db216651 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-823j-2wj6-7jwh/GHSA-823j-2wj6-7jwh.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-823j-2wj6-7jwh", + "modified": "2025-03-20T12:32:52Z", + "published": "2025-03-20T12:32:52Z", + "aliases": [ + "CVE-2025-0184" + ], + "details": "A Server-Side Request Forgery (SSRF) vulnerability was identified in langgenius/dify version 0.10.2. The vulnerability occurs in the 'Create Knowledge' section when uploading DOCX files. If an external relationship exists in the DOCX file, the reltype value is requested as a URL using the 'requests' module instead of the 'ssrf_proxy', leading to an SSRF vulnerability. This issue was fixed in version 0.11.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0184" + }, + { + "type": "WEB", + "url": "https://github.com/langgenius/dify/commit/c135ec4b08d946a1a1d3a198a1d72c1ccf47250f" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/a7eac4ae-5d5e-4ac1-894b-7a8cce5cba9b" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-82mg-566w-vpxp/GHSA-82mg-566w-vpxp.json b/advisories/unreviewed/2025/03/GHSA-82mg-566w-vpxp/GHSA-82mg-566w-vpxp.json new file mode 100644 index 00000000000..710f0cee1b8 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-82mg-566w-vpxp/GHSA-82mg-566w-vpxp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-82mg-566w-vpxp", + "modified": "2025-03-20T12:32:47Z", + "published": "2025-03-20T12:32:47Z", + "aliases": [ + "CVE-2024-8017" + ], + "details": "An XSS vulnerability exists in open-webui/open-webui versions <= 0.3.8, specifically in the function that constructs the HTML for tooltips. This vulnerability allows attackers to perform operations with the victim's privileges, such as stealing chat history, deleting chats, and escalating their own account to an admin if the victim is an admin.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8017" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/ef06c7c8-1cb2-42a7-a6e6-17b2e1c744f7" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-85ff-r9hw-4grc/GHSA-85ff-r9hw-4grc.json b/advisories/unreviewed/2025/03/GHSA-85ff-r9hw-4grc/GHSA-85ff-r9hw-4grc.json new file mode 100644 index 00000000000..6d61b773262 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-85ff-r9hw-4grc/GHSA-85ff-r9hw-4grc.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-85ff-r9hw-4grc", + "modified": "2025-03-20T12:32:40Z", + "published": "2025-03-20T12:32:40Z", + "aliases": [ + "CVE-2024-10721" + ], + "details": "A stored cross-site scripting (XSS) vulnerability was discovered in phpipam/phpipam version 1.5.2. This vulnerability allows an attacker to inject malicious scripts into the application, which can be executed in the context of other users who view the affected page. The issue occurs in the circuits options page (https://demo.phpipam.net/tools/circuits/options/). An attacker can exploit this vulnerability to steal cookies, gain unauthorized access to user accounts, or redirect users to malicious websites. The vulnerability has been fixed in version 1.7.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10721" + }, + { + "type": "WEB", + "url": "https://github.com/phpipam/phpipam/commit/c1697bb6c4e4a6403d69c0868e1eb1040f98b731" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/a440a003-84c9-47b5-bfbd-675564abe3d8" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-85jc-8h5p-8vw8/GHSA-85jc-8h5p-8vw8.json b/advisories/unreviewed/2025/03/GHSA-85jc-8h5p-8vw8/GHSA-85jc-8h5p-8vw8.json new file mode 100644 index 00000000000..2dabe7f90c0 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-85jc-8h5p-8vw8/GHSA-85jc-8h5p-8vw8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-85jc-8h5p-8vw8", + "modified": "2025-03-20T12:32:47Z", + "published": "2025-03-20T12:32:46Z", + "aliases": [ + "CVE-2024-7806" + ], + "details": "A vulnerability in open-webui/open-webui versions <= 0.3.8 allows remote code execution by non-admin users via Cross-Site Request Forgery (CSRF). The application uses cookies with the SameSite attribute set to lax for authentication and lacks CSRF tokens. This allows an attacker to craft a malicious HTML that, when accessed by a victim, can modify the Python code of an existing pipeline and execute arbitrary code with the victim's privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7806" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/9350a68d-5f33-4b3d-988b-81e778160ab8" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-873w-8cph-rghj/GHSA-873w-8cph-rghj.json b/advisories/unreviewed/2025/03/GHSA-873w-8cph-rghj/GHSA-873w-8cph-rghj.json new file mode 100644 index 00000000000..538e23dbf40 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-873w-8cph-rghj/GHSA-873w-8cph-rghj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-873w-8cph-rghj", + "modified": "2025-03-20T12:32:40Z", + "published": "2025-03-20T12:32:40Z", + "aliases": [ + "CVE-2024-10812" + ], + "details": "An open redirect vulnerability exists in binary-husky/gpt_academic version 3.83. The vulnerability occurs when a user is redirected to a URL specified by user-controlled input in the 'file' parameter without proper validation or sanitization. This can be exploited by attackers to conduct phishing attacks, distribute malware, and steal user credentials.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10812" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/51408ebd-e0be-489d-8088-f210087dbd6a" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-879v-fggm-vxw2/GHSA-879v-fggm-vxw2.json b/advisories/unreviewed/2025/03/GHSA-879v-fggm-vxw2/GHSA-879v-fggm-vxw2.json new file mode 100644 index 00000000000..c9afc969ad7 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-879v-fggm-vxw2/GHSA-879v-fggm-vxw2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-879v-fggm-vxw2", + "modified": "2025-03-20T12:32:52Z", + "published": "2025-03-20T12:32:52Z", + "aliases": [ + "CVE-2025-0330" + ], + "details": "In berriai/litellm version v1.52.1, an issue in proxy_server.py causes the leakage of Langfuse API keys when an error occurs while parsing team settings. This vulnerability exposes sensitive information, including langfuse_secret and langfuse_public_key, which can provide full access to the Langfuse project storing all requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0330" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/661b388a-44d8-4ad5-862b-4dc5b80be30a" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1230" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-89qx-m49c-8crf/GHSA-89qx-m49c-8crf.json b/advisories/unreviewed/2025/03/GHSA-89qx-m49c-8crf/GHSA-89qx-m49c-8crf.json new file mode 100644 index 00000000000..c479731060e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-89qx-m49c-8crf/GHSA-89qx-m49c-8crf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-89qx-m49c-8crf", + "modified": "2025-03-20T12:32:42Z", + "published": "2025-03-20T12:32:42Z", + "aliases": [ + "CVE-2024-12055" + ], + "details": "A vulnerability in Ollama versions <=0.3.14 allows a malicious user to create a customized gguf model file that can be uploaded to the public Ollama server. When the server processes this malicious model, it crashes, leading to a Denial of Service (DoS) attack. The root cause of the issue is an out-of-bounds read in the gguf.go file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12055" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/7b111d55-8215-4727-8807-c5ed4cf1bfbe" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-8f78-f6p2-mjw7/GHSA-8f78-f6p2-mjw7.json b/advisories/unreviewed/2025/03/GHSA-8f78-f6p2-mjw7/GHSA-8f78-f6p2-mjw7.json new file mode 100644 index 00000000000..e6fb8579cb5 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-8f78-f6p2-mjw7/GHSA-8f78-f6p2-mjw7.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8f78-f6p2-mjw7", + "modified": "2025-03-20T12:32:40Z", + "published": "2025-03-20T12:32:40Z", + "aliases": [ + "CVE-2024-10725" + ], + "details": "A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2. This vulnerability allows an attacker to inject malicious scripts into the application, which are then executed in the context of other users who view the affected pages. The issue occurs when editing the NAT destination address, where user input is not properly sanitized. This can lead to data theft, account compromise, and other malicious activities. The vulnerability is fixed in version 1.7.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10725" + }, + { + "type": "WEB", + "url": "https://github.com/phpipam/phpipam/commit/c1697bb6c4e4a6403d69c0868e1eb1040f98b731" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/343465fa-6dec-40af-a012-7b118e91a771" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-8fw3-c8jq-g74q/GHSA-8fw3-c8jq-g74q.json b/advisories/unreviewed/2025/03/GHSA-8fw3-c8jq-g74q/GHSA-8fw3-c8jq-g74q.json new file mode 100644 index 00000000000..e84a8ca82c0 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-8fw3-c8jq-g74q/GHSA-8fw3-c8jq-g74q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8fw3-c8jq-g74q", + "modified": "2025-03-20T12:32:49Z", + "published": "2025-03-20T12:32:49Z", + "aliases": [ + "CVE-2024-8958" + ], + "details": "In composiohq/composio version 0.4.3, there is an unrestricted file write and read vulnerability in the filetools actions. Due to improper validation of file paths, an attacker can read and write files anywhere on the server, potentially leading to privilege escalation or remote code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8958" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/e152b094-0593-428e-b813-068d2390ce68" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-8gfh-hxjj-c33j/GHSA-8gfh-hxjj-c33j.json b/advisories/unreviewed/2025/03/GHSA-8gfh-hxjj-c33j/GHSA-8gfh-hxjj-c33j.json new file mode 100644 index 00000000000..a2fe40d69f8 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-8gfh-hxjj-c33j/GHSA-8gfh-hxjj-c33j.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8gfh-hxjj-c33j", + "modified": "2025-03-20T12:32:38Z", + "published": "2025-03-20T12:32:38Z", + "aliases": [ + "CVE-2024-0640" + ], + "details": "A stored cross-site scripting (XSS) vulnerability exists in chatwoot/chatwoot versions 3.0.0 to 3.5.1. This vulnerability allows an admin user to inject malicious JavaScript code via the dashboard app settings, which can then be executed by another admin user when they access the affected dashboard app. The issue is fixed in version 3.5.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0640" + }, + { + "type": "WEB", + "url": "https://github.com/chatwoot/chatwoot/commit/e39c14460b860d5e3d23d989dd6af48404ad1bb4" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/08b3bebf-ce3c-4416-b75e-1927ba61de85" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-8jhr-8vq6-2gp8/GHSA-8jhr-8vq6-2gp8.json b/advisories/unreviewed/2025/03/GHSA-8jhr-8vq6-2gp8/GHSA-8jhr-8vq6-2gp8.json new file mode 100644 index 00000000000..377b756ecae --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-8jhr-8vq6-2gp8/GHSA-8jhr-8vq6-2gp8.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8jhr-8vq6-2gp8", + "modified": "2025-03-20T12:32:44Z", + "published": "2025-03-20T12:32:44Z", + "aliases": [ + "CVE-2024-5752" + ], + "details": "A path traversal vulnerability exists in stitionai/devika, specifically in the project creation functionality. In the affected version beacf6edaa205a5a5370525407a6db45137873b3, the project name is not validated, allowing an attacker to create a project with a crafted name that traverses directories. This can lead to arbitrary file overwrite when the application generates code and saves it to the specified project directory, potentially resulting in remote code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5752" + }, + { + "type": "WEB", + "url": "https://github.com/stitionai/devika/commit/6acce21fb08c3d1123ef05df6a33912bf0ee77c2" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/865b5f44-ef75-4243-a5f1-2f0d895353b1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-8pwp-phcg-h36g/GHSA-8pwp-phcg-h36g.json b/advisories/unreviewed/2025/03/GHSA-8pwp-phcg-h36g/GHSA-8pwp-phcg-h36g.json new file mode 100644 index 00000000000..57fbf684791 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-8pwp-phcg-h36g/GHSA-8pwp-phcg-h36g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8pwp-phcg-h36g", + "modified": "2025-03-20T12:32:40Z", + "published": "2025-03-20T12:32:40Z", + "aliases": [ + "CVE-2024-10830" + ], + "details": "A Path Traversal vulnerability exists in the eosphoros-ai/db-gpt version 0.6.0 at the API endpoint `/v1/resource/file/delete`. This vulnerability allows an attacker to delete any file on the server by manipulating the `file_key` parameter. The `file_key` parameter is not properly sanitized, enabling an attacker to specify arbitrary file paths. If the specified file exists, the application will delete it.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10830" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/26adf08a-9262-4d5a-a2ee-ce12ed919620" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-8q24-hc9h-h952/GHSA-8q24-hc9h-h952.json b/advisories/unreviewed/2025/03/GHSA-8q24-hc9h-h952/GHSA-8q24-hc9h-h952.json new file mode 100644 index 00000000000..2876edea7eb --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-8q24-hc9h-h952/GHSA-8q24-hc9h-h952.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8q24-hc9h-h952", + "modified": "2025-03-20T12:32:41Z", + "published": "2025-03-20T12:32:41Z", + "aliases": [ + "CVE-2024-10986" + ], + "details": "GPT Academic version 3.83 is vulnerable to a Local File Read (LFI) vulnerability through its HotReload function. This function can download and extract tar.gz files from arxiv.org. Despite implementing protections against path traversal, the application overlooks the Tarslip triggered by symlinks. This oversight allows attackers to read arbitrary local files from the victim server.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10986" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/db2167f5-f17f-491d-aeec-69ba55bf6427" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-8qff-6gwc-wph3/GHSA-8qff-6gwc-wph3.json b/advisories/unreviewed/2025/03/GHSA-8qff-6gwc-wph3/GHSA-8qff-6gwc-wph3.json new file mode 100644 index 00000000000..23b631ee4b5 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-8qff-6gwc-wph3/GHSA-8qff-6gwc-wph3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8qff-6gwc-wph3", + "modified": "2025-03-20T12:32:39Z", + "published": "2025-03-20T12:32:38Z", + "aliases": [ + "CVE-2024-10267" + ], + "details": "An information disclosure vulnerability exists in the latest version of transformeroptimus/superagi. An attacker can leak sensitive user information, including names, emails, and passwords, by attempting to register a new account with an email that is already in use. The server returns all information associated with the existing account. The vulnerable endpoint is located in the user registration functionality.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10267" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/13da8366-4670-4d46-9f5a-ba3f642b692e" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-359" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-8v6j-vg6w-6wwj/GHSA-8v6j-vg6w-6wwj.json b/advisories/unreviewed/2025/03/GHSA-8v6j-vg6w-6wwj/GHSA-8v6j-vg6w-6wwj.json new file mode 100644 index 00000000000..70a4c9397c1 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-8v6j-vg6w-6wwj/GHSA-8v6j-vg6w-6wwj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8v6j-vg6w-6wwj", + "modified": "2025-03-20T12:32:42Z", + "published": "2025-03-20T12:32:42Z", + "aliases": [ + "CVE-2024-11822" + ], + "details": "langgenius/dify version 0.9.1 contains a Server-Side Request Forgery (SSRF) vulnerability. The vulnerability exists due to improper handling of the api_endpoint parameter, allowing an attacker to make direct requests to internal network services. This can lead to unauthorized access to internal servers and potentially expose sensitive information, including access to the AWS metadata endpoint.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11822" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/f3042029-5d4e-41c6-850d-bbe02fae6592" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-8vgw-p6qm-5gr7/GHSA-8vgw-p6qm-5gr7.json b/advisories/unreviewed/2025/03/GHSA-8vgw-p6qm-5gr7/GHSA-8vgw-p6qm-5gr7.json new file mode 100644 index 00000000000..ae11660c8c8 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-8vgw-p6qm-5gr7/GHSA-8vgw-p6qm-5gr7.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8vgw-p6qm-5gr7", + "modified": "2025-03-20T12:32:45Z", + "published": "2025-03-20T12:32:45Z", + "aliases": [ + "CVE-2024-6844" + ], + "details": "A vulnerability in corydolphin/flask-cors version 4.0.1 allows for inconsistent CORS matching due to the handling of the '+' character in URL paths. The request.path is passed through the unquote_plus function, which converts the '+' character to a space ' '. This behavior leads to incorrect path normalization, causing potential mismatches in CORS configuration. As a result, endpoints may not be matched correctly to their CORS settings, leading to unexpected CORS policy application. This can cause unauthorized cross-origin access or block valid requests, creating security vulnerabilities and usability issues.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6844" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/731a6cd4-d05f-4fe6-8f5b-fe088d7b34e0" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-8vjh-pxfw-4fqm/GHSA-8vjh-pxfw-4fqm.json b/advisories/unreviewed/2025/03/GHSA-8vjh-pxfw-4fqm/GHSA-8vjh-pxfw-4fqm.json new file mode 100644 index 00000000000..d92a3184421 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-8vjh-pxfw-4fqm/GHSA-8vjh-pxfw-4fqm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8vjh-pxfw-4fqm", + "modified": "2025-03-20T12:32:43Z", + "published": "2025-03-20T12:32:43Z", + "aliases": [ + "CVE-2024-12391" + ], + "details": "A vulnerability in binary-husky/gpt_academic, as of commit 310122f, allows for a Regular Expression Denial of Service (ReDoS) attack. The function '解析项目源码(手动指定和筛选源码文件类型)' permits the execution of user-provided regular expressions. Certain regular expressions can cause the Python RE engine to take exponential time to execute, leading to a Denial of Service (DoS) condition. An attacker who controls both the regular expression and the search string can exploit this vulnerability to hang the server for an arbitrary amount of time.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12391" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/70b3f4f0-6b1b-4563-a18c-fe46502e6ba0" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-183" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-93qj-49fq-62jp/GHSA-93qj-49fq-62jp.json b/advisories/unreviewed/2025/03/GHSA-93qj-49fq-62jp/GHSA-93qj-49fq-62jp.json new file mode 100644 index 00000000000..7d9432d3264 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-93qj-49fq-62jp/GHSA-93qj-49fq-62jp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-93qj-49fq-62jp", + "modified": "2025-03-20T12:32:44Z", + "published": "2025-03-20T12:32:44Z", + "aliases": [ + "CVE-2024-12870" + ], + "details": "A stored cross-site scripting (XSS) vulnerability exists in infiniflow/ragflow, affecting the latest commit on the main branch (cec2080). The vulnerability allows an attacker to upload HTML/XML files that can host arbitrary JavaScript payloads. These files are served with the 'application/xml' content type, which is automatically rendered by browsers. This can lead to the execution of arbitrary JavaScript in the context of the user's browser, potentially allowing attackers to steal cookies and gain unauthorized access to user files and resources. The vulnerability does not require authentication, making it accessible to anyone with network access to the instance.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12870" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/d6b497d2-5c95-4abc-8033-04b8068fed65" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-959v-wfjp-7c37/GHSA-959v-wfjp-7c37.json b/advisories/unreviewed/2025/03/GHSA-959v-wfjp-7c37/GHSA-959v-wfjp-7c37.json new file mode 100644 index 00000000000..08e10b7264c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-959v-wfjp-7c37/GHSA-959v-wfjp-7c37.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-959v-wfjp-7c37", + "modified": "2025-03-20T12:32:51Z", + "published": "2025-03-20T12:32:51Z", + "aliases": [ + "CVE-2024-9415" + ], + "details": "A Path Traversal vulnerability exists in the file upload functionality of transformeroptimus/superagi version 0.0.14. This vulnerability allows an attacker to upload an arbitrary file to the server, potentially leading to remote code execution or overwriting any file on the server.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9415" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/31bdf98c-5205-4c48-9bc7-9e780ba63398" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-969w-gqqr-g6j3/GHSA-969w-gqqr-g6j3.json b/advisories/unreviewed/2025/03/GHSA-969w-gqqr-g6j3/GHSA-969w-gqqr-g6j3.json new file mode 100644 index 00000000000..181be0a442e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-969w-gqqr-g6j3/GHSA-969w-gqqr-g6j3.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-969w-gqqr-g6j3", + "modified": "2025-03-20T12:32:53Z", + "published": "2025-03-20T12:32:53Z", + "aliases": [ + "CVE-2025-1473" + ], + "details": "A Cross-Site Request Forgery (CSRF) vulnerability exists in the Signup feature of mlflow/mlflow versions 2.17.0 to 2.20.1. This vulnerability allows an attacker to create a new account, which may be used to perform unauthorized actions on behalf of the malicious user.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1473" + }, + { + "type": "WEB", + "url": "https://github.com/mlflow/mlflow/commit/ecfa61cb43d3303589f3b5834fd95991c9706628" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/43dc50b6-7d1e-41b9-9f97-f28809df1d45" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-96mw-rfcv-484q/GHSA-96mw-rfcv-484q.json b/advisories/unreviewed/2025/03/GHSA-96mw-rfcv-484q/GHSA-96mw-rfcv-484q.json new file mode 100644 index 00000000000..31161f21571 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-96mw-rfcv-484q/GHSA-96mw-rfcv-484q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-96mw-rfcv-484q", + "modified": "2025-03-20T12:32:43Z", + "published": "2025-03-20T12:32:43Z", + "aliases": [ + "CVE-2024-12779" + ], + "details": "A Server-Side Request Forgery (SSRF) vulnerability exists in infiniflow/ragflow version 0.12.0. The vulnerability is present in the `POST /v1/llm/add_llm` and `POST /v1/conversation/tts` endpoints. Attackers can specify an arbitrary URL as the `api_base` when adding an `OPENAITTS` model, and subsequently access the `tts` REST API endpoint to read contents from the specified URL. This can lead to unauthorized access to internal web resources.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12779" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/3cc748ba-2afb-4bfe-8553-10eb6d6dd4f0" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-96w2-hg6w-6xv2/GHSA-96w2-hg6w-6xv2.json b/advisories/unreviewed/2025/03/GHSA-96w2-hg6w-6xv2/GHSA-96w2-hg6w-6xv2.json new file mode 100644 index 00000000000..b0287bfadb4 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-96w2-hg6w-6xv2/GHSA-96w2-hg6w-6xv2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-96w2-hg6w-6xv2", + "modified": "2025-03-20T12:32:41Z", + "published": "2025-03-20T12:32:41Z", + "aliases": [ + "CVE-2024-11044" + ], + "details": "An open redirect vulnerability in automatic1111/stable-diffusion-webui version 1.10.0 allows a remote unauthenticated attacker to redirect users to arbitrary websites via a specially crafted URL. This vulnerability can be exploited to conduct phishing attacks, distribute malware, and steal user credentials.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11044" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/ee942e5e-4987-4f81-ba83-014fec6b33b3" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-97pg-wr4r-53wr/GHSA-97pg-wr4r-53wr.json b/advisories/unreviewed/2025/03/GHSA-97pg-wr4r-53wr/GHSA-97pg-wr4r-53wr.json new file mode 100644 index 00000000000..0450c1ef5b0 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-97pg-wr4r-53wr/GHSA-97pg-wr4r-53wr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-97pg-wr4r-53wr", + "modified": "2025-03-20T12:32:42Z", + "published": "2025-03-20T12:32:42Z", + "aliases": [ + "CVE-2024-11821" + ], + "details": "A privilege escalation vulnerability exists in langgenius/dify version 0.9.1. This vulnerability allows a normal user to modify Orchestrate instructions for a chatbot created by an admin user. The issue arises because the application does not properly enforce access controls on the endpoint /console/api/apps/{chatbot-id}/model-config, allowing unauthorized users to alter chatbot configurations.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11821" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/76d5986d-3882-4ea7-81cb-f00400e5c6b6" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-250" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-98fp-7v67-4v3q/GHSA-98fp-7v67-4v3q.json b/advisories/unreviewed/2025/03/GHSA-98fp-7v67-4v3q/GHSA-98fp-7v67-4v3q.json new file mode 100644 index 00000000000..9e50e57bad3 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-98fp-7v67-4v3q/GHSA-98fp-7v67-4v3q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-98fp-7v67-4v3q", + "modified": "2025-03-20T12:32:47Z", + "published": "2025-03-20T12:32:47Z", + "aliases": [ + "CVE-2024-8020" + ], + "details": "A vulnerability in lightning-ai/pytorch-lightning version 2.3.2 allows an attacker to cause a denial of service by sending an unexpected POST request to the `/api/v1/state` endpoint of `LightningApp`. This issue occurs due to improper handling of unexpected state values, which results in the server shutting down.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8020" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/8b642a78-2b80-4fb0-9b2f-8ba0ff37db6a" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9g44-gwvm-hc44/GHSA-9g44-gwvm-hc44.json b/advisories/unreviewed/2025/03/GHSA-9g44-gwvm-hc44/GHSA-9g44-gwvm-hc44.json new file mode 100644 index 00000000000..f76d5cee63b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-9g44-gwvm-hc44/GHSA-9g44-gwvm-hc44.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9g44-gwvm-hc44", + "modified": "2025-03-20T12:32:50Z", + "published": "2025-03-20T12:32:50Z", + "aliases": [ + "CVE-2024-9070" + ], + "details": "A deserialization vulnerability exists in BentoML's runner server in bentoml/bentoml versions <=1.3.4.post1. By setting specific parameters, an attacker can execute unauthorized arbitrary code on the server, causing severe harm. The vulnerability is triggered when the args-number parameter is greater than 1, leading to automatic deserialization and arbitrary code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9070" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/7be6fc22-be18-44ee-a001-ac7158d5e1a5" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9gcr-28rp-cc24/GHSA-9gcr-28rp-cc24.json b/advisories/unreviewed/2025/03/GHSA-9gcr-28rp-cc24/GHSA-9gcr-28rp-cc24.json new file mode 100644 index 00000000000..b33109a490d --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-9gcr-28rp-cc24/GHSA-9gcr-28rp-cc24.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9gcr-28rp-cc24", + "modified": "2025-03-20T12:32:52Z", + "published": "2025-03-20T12:32:52Z", + "aliases": [ + "CVE-2025-0317" + ], + "details": "A vulnerability in ollama/ollama versions <=0.3.14 allows a malicious user to upload and create a customized GGUF model file on the Ollama server. This can lead to a division by zero error in the ggufPadding function, causing the server to crash and resulting in a Denial of Service (DoS) attack.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0317" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/a9951bca-9bd8-49b2-b143-4cd4219f9fa0" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-369" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9mhf-9hxp-8j3m/GHSA-9mhf-9hxp-8j3m.json b/advisories/unreviewed/2025/03/GHSA-9mhf-9hxp-8j3m/GHSA-9mhf-9hxp-8j3m.json new file mode 100644 index 00000000000..c4762d3de26 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-9mhf-9hxp-8j3m/GHSA-9mhf-9hxp-8j3m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9mhf-9hxp-8j3m", + "modified": "2025-03-20T12:32:52Z", + "published": "2025-03-20T12:32:52Z", + "aliases": [ + "CVE-2025-0192" + ], + "details": "A stored Cross-site Scripting (XSS) vulnerability exists in the latest version of wandb/openui. The vulnerability is present in the edit HTML functionality, where an attacker can inject malicious scripts. When the modified HTML is shared with another user, the XSS payload executes, potentially leading to the theft of user prompt history and other sensitive information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0192" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/5f82c722-b674-456a-8691-a6565bf90e39" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9vf8-xgwm-97r8/GHSA-9vf8-xgwm-97r8.json b/advisories/unreviewed/2025/03/GHSA-9vf8-xgwm-97r8/GHSA-9vf8-xgwm-97r8.json new file mode 100644 index 00000000000..3467461dd38 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-9vf8-xgwm-97r8/GHSA-9vf8-xgwm-97r8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9vf8-xgwm-97r8", + "modified": "2025-03-20T12:32:47Z", + "published": "2025-03-20T12:32:47Z", + "aliases": [ + "CVE-2024-8053" + ], + "details": "In version v0.3.10 of open-webui/open-webui, the `api/v1/utils/pdf` endpoint lacks authentication mechanisms, allowing unauthenticated attackers to access the PDF generation service. This vulnerability can be exploited by sending a POST request with an excessively large payload, potentially leading to server resource exhaustion and denial of service (DoS). Additionally, unauthorized users can misuse the endpoint to generate PDFs without verification, resulting in service misuse and potential operational and financial impacts.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8053" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/ebe8c1fa-113b-4df9-be03-a406b9adb9f4" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9vwq-rwcj-cmcg/GHSA-9vwq-rwcj-cmcg.json b/advisories/unreviewed/2025/03/GHSA-9vwq-rwcj-cmcg/GHSA-9vwq-rwcj-cmcg.json new file mode 100644 index 00000000000..346e1d27a5c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-9vwq-rwcj-cmcg/GHSA-9vwq-rwcj-cmcg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9vwq-rwcj-cmcg", + "modified": "2025-03-20T12:32:45Z", + "published": "2025-03-20T12:32:45Z", + "aliases": [ + "CVE-2024-6841" + ], + "details": "A Cross-Site Request Forgery (CSRF) vulnerability exists in the latest commit (56b782bcefd2e59b19cd7ba7878b95f54884f502) of the vanna-ai/vanna repository. Two endpoints in the built-in web app that provide SQL functionality are implemented as simple GET requests, making them susceptible to CSRF attacks. This vulnerability allows an attacker to run arbitrary SQL commands via CSRF without the target intending to expose the web app to the network or other users. The impact is limited to data alteration or deletion, as the attacker cannot read the results of the query.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6841" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/7c6cf388-6399-4e37-99f6-3f052eb1136e" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9w5h-67gf-xvv8/GHSA-9w5h-67gf-xvv8.json b/advisories/unreviewed/2025/03/GHSA-9w5h-67gf-xvv8/GHSA-9w5h-67gf-xvv8.json new file mode 100644 index 00000000000..a9affadc065 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-9w5h-67gf-xvv8/GHSA-9w5h-67gf-xvv8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9w5h-67gf-xvv8", + "modified": "2025-03-20T12:32:48Z", + "published": "2025-03-20T12:32:48Z", + "aliases": [ + "CVE-2024-8502" + ], + "details": "A vulnerability in the RpcAgentServerLauncher class of modelscope/agentscope v0.0.6a3 allows for remote code execution (RCE) via deserialization of untrusted data using the dill library. The issue occurs in the AgentServerServicer.create_agent method, where serialized input is deserialized using dill.loads, enabling an attacker to execute arbitrary commands on the server.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8502" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/7a42da2a-2ae5-442d-aff9-c9a3b47870eb" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9xvx-2953-c58g/GHSA-9xvx-2953-c58g.json b/advisories/unreviewed/2025/03/GHSA-9xvx-2953-c58g/GHSA-9xvx-2953-c58g.json new file mode 100644 index 00000000000..77cfb4e27a6 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-9xvx-2953-c58g/GHSA-9xvx-2953-c58g.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9xvx-2953-c58g", + "modified": "2025-03-20T12:32:46Z", + "published": "2025-03-20T12:32:46Z", + "aliases": [ + "CVE-2024-7476" + ], + "details": "A broken access control vulnerability exists in lunary-ai/lunary versions 1.2.7 through 1.4.2. The vulnerability allows an authenticated attacker to modify any user's templates by sending a crafted HTTP POST request to the /v1/templates/{id}/versions endpoint. This issue is resolved in version 1.4.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7476" + }, + { + "type": "WEB", + "url": "https://github.com/lunary-ai/lunary/commit/8f563c77d8614a72980113f530c7a9ec15a5f8d5" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/183761f7-d411-4332-af86-2ccfbcc5bd9f" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-c2qr-w9p6-cxgr/GHSA-c2qr-w9p6-cxgr.json b/advisories/unreviewed/2025/03/GHSA-c2qr-w9p6-cxgr/GHSA-c2qr-w9p6-cxgr.json new file mode 100644 index 00000000000..80343b760aa --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-c2qr-w9p6-cxgr/GHSA-c2qr-w9p6-cxgr.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c2qr-w9p6-cxgr", + "modified": "2025-03-20T12:32:41Z", + "published": "2025-03-20T12:32:41Z", + "aliases": [ + "CVE-2024-11171" + ], + "details": "In danny-avila/librechat version git 0c2a583, there is an improper input validation vulnerability. The application uses multer middleware for handling multipart file uploads. When using in-memory storage (the default setting for multer), there is no limit on the upload file size. This can lead to a server crash due to out-of-memory errors when handling large files. An attacker without any privileges can exploit this vulnerability to cause a complete denial of service. The issue is fixed in version 0.7.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11171" + }, + { + "type": "WEB", + "url": "https://github.com/danny-avila/librechat/commit/bb58a2d0662ef86dc75a9d2f6560125c018e3836" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/91717a5a-d653-4e35-b186-9e8d00aa4285" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-c2xf-763v-3rqh/GHSA-c2xf-763v-3rqh.json b/advisories/unreviewed/2025/03/GHSA-c2xf-763v-3rqh/GHSA-c2xf-763v-3rqh.json new file mode 100644 index 00000000000..ff709151ef8 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-c2xf-763v-3rqh/GHSA-c2xf-763v-3rqh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c2xf-763v-3rqh", + "modified": "2025-03-20T12:32:52Z", + "published": "2025-03-20T12:32:52Z", + "aliases": [ + "CVE-2025-0183" + ], + "details": "A stored cross-site scripting (XSS) vulnerability exists in the Latex Proof-Reading Module of binary-husky/gpt_academic version 3.9.0. This vulnerability allows an attacker to inject malicious scripts into the `debug_log.html` file generated by the module. When an admin visits this debug report, the injected scripts can execute, potentially leading to unauthorized actions and data access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0183" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/53bced90-64a9-4ca2-8f2f-282c4ce84d1f" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-c39q-wr4f-xpw7/GHSA-c39q-wr4f-xpw7.json b/advisories/unreviewed/2025/03/GHSA-c39q-wr4f-xpw7/GHSA-c39q-wr4f-xpw7.json new file mode 100644 index 00000000000..a82289f0e1e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-c39q-wr4f-xpw7/GHSA-c39q-wr4f-xpw7.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c39q-wr4f-xpw7", + "modified": "2025-03-20T12:32:53Z", + "published": "2025-03-20T12:32:53Z", + "aliases": [ + "CVE-2025-2539" + ], + "details": "The File Away plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ajax() function in all versions up to, and including, 3.9.9.0.1. This makes it possible for unauthenticated attackers, leveraging the use of a reversible weak algorithm, to read the contents of arbitrary files on the server, which can contain sensitive information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2539" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/file-away/trunk/lib/cls/class.fileaway_encrypted.php" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/file-away/trunk/lib/cls/class.fileaway_stats.php" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/file-away/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/5b23bd5c-db27-4d63-8461-1f36958a2ff6?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-327" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T12:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-c4cc-w454-4634/GHSA-c4cc-w454-4634.json b/advisories/unreviewed/2025/03/GHSA-c4cc-w454-4634/GHSA-c4cc-w454-4634.json new file mode 100644 index 00000000000..eaa649dd9a4 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-c4cc-w454-4634/GHSA-c4cc-w454-4634.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c4cc-w454-4634", + "modified": "2025-03-20T12:32:48Z", + "published": "2025-03-20T12:32:48Z", + "aliases": [ + "CVE-2024-8537" + ], + "details": "A path traversal vulnerability exists in the modelscope/agentscope application, affecting all versions. The vulnerability is present in the /delete-workflow endpoint, allowing an attacker to delete arbitrary files from the filesystem. This issue arises due to improper input validation, enabling the attacker to manipulate file paths and delete sensitive files outside of the intended directory.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8537" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/eeb8aa4b-e6e5-465c-b0dd-aa97e3b7dc09" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-29" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-c7fq-p62p-wvpc/GHSA-c7fq-p62p-wvpc.json b/advisories/unreviewed/2025/03/GHSA-c7fq-p62p-wvpc/GHSA-c7fq-p62p-wvpc.json new file mode 100644 index 00000000000..c2dcb4a8de6 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-c7fq-p62p-wvpc/GHSA-c7fq-p62p-wvpc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c7fq-p62p-wvpc", + "modified": "2025-03-20T12:32:46Z", + "published": "2025-03-20T12:32:46Z", + "aliases": [ + "CVE-2024-7045" + ], + "details": "In version v0.3.8 of open-webui/open-webui, improper access control vulnerabilities allow an attacker to view any prompts. The application does not verify whether the attacker is an administrator, allowing the attacker to directly call the /api/v1/prompts/ interface to retrieve all prompt information created by the admin, which includes the ID values. Subsequently, the attacker can exploit the /api/v1/prompts/command/{command_id} interface to obtain arbitrary prompt information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7045" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/03ea0826-af7b-4717-b63e-90fd19675ab2" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1100" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-c85g-5883-vjj7/GHSA-c85g-5883-vjj7.json b/advisories/unreviewed/2025/03/GHSA-c85g-5883-vjj7/GHSA-c85g-5883-vjj7.json new file mode 100644 index 00000000000..9f12aadd2ef --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-c85g-5883-vjj7/GHSA-c85g-5883-vjj7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c85g-5883-vjj7", + "modified": "2025-03-20T12:32:41Z", + "published": "2025-03-20T12:32:41Z", + "aliases": [ + "CVE-2024-10950" + ], + "details": "In binary-husky/gpt_academic version <= 3.83, the plugin `CodeInterpreter` is vulnerable to code injection caused by prompt injection. The root cause is the execution of user-provided prompts that generate untrusted code without a sandbox, allowing the execution of parts of the LLM-generated code. This vulnerability can be exploited by an attacker to achieve remote code execution (RCE) on the application backend server, potentially gaining full control of the server.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10950" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/9abb1617-0c1d-42c7-a647-d9d2b39c6866" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-cfc5-c899-6ww2/GHSA-cfc5-c899-6ww2.json b/advisories/unreviewed/2025/03/GHSA-cfc5-c899-6ww2/GHSA-cfc5-c899-6ww2.json new file mode 100644 index 00000000000..1e257e975c7 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-cfc5-c899-6ww2/GHSA-cfc5-c899-6ww2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cfc5-c899-6ww2", + "modified": "2025-03-20T12:32:53Z", + "published": "2025-03-20T12:32:53Z", + "aliases": [ + "CVE-2025-2311" + ], + "details": "Incorrect Use of Privileged APIs, Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials vulnerability in Nebula Informatics SecHard allows Authentication Bypass, Interface Manipulation, Authentication Abuse, Harvesting Information via API Event Monitoring.This issue affects SecHard: before 3.3.0.20220411.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2311" + }, + { + "type": "WEB", + "url": "https://www.usom.gov.tr/bildirim/tr-25-0074" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-319" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T12:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-cfvq-fj53-j2c7/GHSA-cfvq-fj53-j2c7.json b/advisories/unreviewed/2025/03/GHSA-cfvq-fj53-j2c7/GHSA-cfvq-fj53-j2c7.json new file mode 100644 index 00000000000..1b2e7425d72 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-cfvq-fj53-j2c7/GHSA-cfvq-fj53-j2c7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cfvq-fj53-j2c7", + "modified": "2025-03-20T12:32:46Z", + "published": "2025-03-20T12:32:45Z", + "aliases": [ + "CVE-2024-7040" + ], + "details": "In version v0.3.8 of open-webui/open-webui, there is an improper access control vulnerability. On the frontend admin page, administrators are intended to view only the chats of non-admin members. However, by modifying the user_id parameter, it is possible to view the chats of any administrator, including those of other admin (owner) accounts.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7040" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/bd182309-4aa4-4747-941e-bbc1741955c1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-cg4p-5qfm-pjjj/GHSA-cg4p-5qfm-pjjj.json b/advisories/unreviewed/2025/03/GHSA-cg4p-5qfm-pjjj/GHSA-cg4p-5qfm-pjjj.json new file mode 100644 index 00000000000..cc5a4e09df1 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-cg4p-5qfm-pjjj/GHSA-cg4p-5qfm-pjjj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cg4p-5qfm-pjjj", + "modified": "2025-03-20T12:32:40Z", + "published": "2025-03-20T12:32:40Z", + "aliases": [ + "CVE-2024-10713" + ], + "details": "A vulnerability in szad670401/hyperlpr v3.0 allows for a Denial of Service (DoS) attack. The server fails to handle excessive characters appended to the end of multipart boundaries, regardless of the character used. This flaw can be exploited by sending malformed multipart requests with arbitrary characters at the end of the boundary, leading to excessive resource consumption and a complete denial of service for all users. The vulnerability is unauthenticated, meaning no user login or interaction is required for an attacker to exploit this issue.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10713" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/d5404069-95b3-40e0-a7a4-c3a183d861b0" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-chf7-q7m5-fq92/GHSA-chf7-q7m5-fq92.json b/advisories/unreviewed/2025/03/GHSA-chf7-q7m5-fq92/GHSA-chf7-q7m5-fq92.json new file mode 100644 index 00000000000..04ef6019f2a --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-chf7-q7m5-fq92/GHSA-chf7-q7m5-fq92.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-chf7-q7m5-fq92", + "modified": "2025-03-20T12:32:43Z", + "published": "2025-03-20T12:32:43Z", + "aliases": [ + "CVE-2024-12537" + ], + "details": "In version 0.3.32 of open-webui/open-webui, the absence of authentication mechanisms allows any unauthenticated attacker to access the `api/v1/utils/code/format` endpoint. If a malicious actor sends a POST request with an excessively high volume of content, the server could become completely unresponsive. This could lead to severe performance issues, causing the server to become unresponsive or experience significant degradation, ultimately resulting in service interruptions for legitimate users.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12537" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/edabd06c-acc0-428c-a481-271f333755bc" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-cj47-qj6g-x7r4/GHSA-cj47-qj6g-x7r4.json b/advisories/unreviewed/2025/03/GHSA-cj47-qj6g-x7r4/GHSA-cj47-qj6g-x7r4.json new file mode 100644 index 00000000000..654afb615bf --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-cj47-qj6g-x7r4/GHSA-cj47-qj6g-x7r4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cj47-qj6g-x7r4", + "modified": "2025-03-20T12:32:50Z", + "published": "2025-03-20T12:32:50Z", + "aliases": [ + "CVE-2024-9053" + ], + "details": "vllm-project vllm version 0.6.0 contains a vulnerability in the AsyncEngineRPCServer() RPC server entrypoints. The core functionality run_server_loop() calls the function _make_handler_coro(), which directly uses cloudpickle.loads() on received messages without any sanitization. This can result in remote code execution by deserializing malicious pickle data.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9053" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/75a544f3-34a3-4da0-b5a3-1495cb031e09" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-cjjc-mf84-xp9f/GHSA-cjjc-mf84-xp9f.json b/advisories/unreviewed/2025/03/GHSA-cjjc-mf84-xp9f/GHSA-cjjc-mf84-xp9f.json new file mode 100644 index 00000000000..43a6998745b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-cjjc-mf84-xp9f/GHSA-cjjc-mf84-xp9f.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cjjc-mf84-xp9f", + "modified": "2025-03-20T12:32:52Z", + "published": "2025-03-20T12:32:52Z", + "aliases": [ + "CVE-2025-1040" + ], + "details": "AutoGPT versions 0.3.4 and earlier are vulnerable to a Server-Side Template Injection (SSTI) that could lead to Remote Code Execution (RCE). The vulnerability arises from the improper handling of user-supplied format strings in the `AgentOutputBlock` implementation, where malicious input is passed to the Jinja2 templating engine without adequate security measures. Attackers can exploit this flaw to execute arbitrary commands on the host system. The issue is fixed in version 0.4.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1040" + }, + { + "type": "WEB", + "url": "https://github.com/significant-gravitas/autogpt/commit/6dba31e0215549604bdcc1aed24e3a1714e75ee2" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/b74ef75f-61d5-4422-ab15-9550c8b4f185" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-cppx-6f25-3qxc/GHSA-cppx-6f25-3qxc.json b/advisories/unreviewed/2025/03/GHSA-cppx-6f25-3qxc/GHSA-cppx-6f25-3qxc.json new file mode 100644 index 00000000000..4e93864ae2c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-cppx-6f25-3qxc/GHSA-cppx-6f25-3qxc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cppx-6f25-3qxc", + "modified": "2025-03-20T12:32:47Z", + "published": "2025-03-20T12:32:47Z", + "aliases": [ + "CVE-2024-8099" + ], + "details": "A Server-Side Request Forgery (SSRF) vulnerability exists in the latest version of vanna-ai/vanna when using DuckDB as the database. An attacker can exploit this vulnerability by submitting crafted SQL queries that leverage DuckDB's default features, such as `read_csv`, `read_csv_auto`, `read_text`, and `read_blob`, to make unauthorized requests to internal or external resources. This can lead to unauthorized access to sensitive data, internal systems, and potentially further attacks.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8099" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/19b96694-ed52-4ee4-8d2c-6cc7bd09c0ad" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-crh6-pj8c-xrhc/GHSA-crh6-pj8c-xrhc.json b/advisories/unreviewed/2025/03/GHSA-crh6-pj8c-xrhc/GHSA-crh6-pj8c-xrhc.json new file mode 100644 index 00000000000..58ca1d34cc2 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-crh6-pj8c-xrhc/GHSA-crh6-pj8c-xrhc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-crh6-pj8c-xrhc", + "modified": "2025-03-20T12:32:45Z", + "published": "2025-03-20T12:32:45Z", + "aliases": [ + "CVE-2024-7034" + ], + "details": "In open-webui version 0.3.8, the endpoint `/models/upload` is vulnerable to arbitrary file write due to improper handling of user-supplied filenames. The vulnerability arises from the usage of `file_path = f\"{UPLOAD_DIR}/{file.filename}\"` without proper input validation or sanitization. An attacker can exploit this by manipulating the `file.filename` parameter to include directory traversal sequences, causing the resulting `file_path` to escape the intended `UPLOAD_DIR` and potentially overwrite arbitrary files on the system. This can lead to unauthorized modifications of system binaries, configuration files, or sensitive data, potentially enabling remote command execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7034" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/711beada-10fe-4567-9278-80a689da8613" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-cvg9-334x-w586/GHSA-cvg9-334x-w586.json b/advisories/unreviewed/2025/03/GHSA-cvg9-334x-w586/GHSA-cvg9-334x-w586.json new file mode 100644 index 00000000000..caa483a3672 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-cvg9-334x-w586/GHSA-cvg9-334x-w586.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cvg9-334x-w586", + "modified": "2025-03-20T12:32:53Z", + "published": "2025-03-20T12:32:53Z", + "aliases": [ + "CVE-2025-1796" + ], + "details": "A vulnerability in langgenius/dify v0.10.1 allows an attacker to take over any account, including administrator accounts, by exploiting a weak pseudo-random number generator (PRNG) used for generating password reset codes. The application uses `random.randint` for this purpose, which is not suitable for cryptographic use and can be cracked. An attacker with access to workflow tools can extract the PRNG output and predict future password reset codes, leading to a complete compromise of the application.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1796" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/a60f3039-5394-4e22-8de7-a7da9c6a6e00" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-338" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-cwc2-3f9g-phm3/GHSA-cwc2-3f9g-phm3.json b/advisories/unreviewed/2025/03/GHSA-cwc2-3f9g-phm3/GHSA-cwc2-3f9g-phm3.json new file mode 100644 index 00000000000..405f348fc4c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-cwc2-3f9g-phm3/GHSA-cwc2-3f9g-phm3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cwc2-3f9g-phm3", + "modified": "2025-03-20T12:32:44Z", + "published": "2025-03-20T12:32:44Z", + "aliases": [ + "CVE-2024-12880" + ], + "details": "A vulnerability in infiniflow/ragflow version RAGFlow-0.13.0 allows for partial account takeover via insecure data querying. The issue arises from the way tenant IDs are handled in the application. If a user has access to multiple tenants, they can manipulate their tenant access to query and access API tokens of other tenants. This vulnerability affects the following endpoints: /v1/system/token_list, /v1/system/new_token, /v1/api/token_list, /v1/api/new_token, and /v1/api/rm. An attacker can exploit this to access other tenants' API tokens, perform actions on behalf of other tenants, and access their data.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12880" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/c41c7eaa-554a-408c-96be-9dba56113970" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-285" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-cx66-wgv6-fpfh/GHSA-cx66-wgv6-fpfh.json b/advisories/unreviewed/2025/03/GHSA-cx66-wgv6-fpfh/GHSA-cx66-wgv6-fpfh.json new file mode 100644 index 00000000000..37ab44cb02c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-cx66-wgv6-fpfh/GHSA-cx66-wgv6-fpfh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cx66-wgv6-fpfh", + "modified": "2025-03-20T12:32:51Z", + "published": "2025-03-20T12:32:51Z", + "aliases": [ + "CVE-2024-9437" + ], + "details": "SuperAGI version v0.0.14 is vulnerable to an unauthenticated Denial of Service (DoS) attack. The vulnerability exists in the resource upload request, where appending characters, such as dashes (-), to the end of a multipart boundary in an HTTP request causes the server to continuously process each character. This leads to excessive resource consumption and renders the service unavailable. The issue is unauthenticated and does not require any user interaction, impacting all users of the service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9437" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/27404e9c-eb3d-4626-a9d9-8dc1b3295ce0" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-f2v6-7vxr-j9g8/GHSA-f2v6-7vxr-j9g8.json b/advisories/unreviewed/2025/03/GHSA-f2v6-7vxr-j9g8/GHSA-f2v6-7vxr-j9g8.json new file mode 100644 index 00000000000..34439aff46f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-f2v6-7vxr-j9g8/GHSA-f2v6-7vxr-j9g8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f2v6-7vxr-j9g8", + "modified": "2025-03-20T12:32:51Z", + "published": "2025-03-20T12:32:51Z", + "aliases": [ + "CVE-2024-9447" + ], + "details": "An information disclosure vulnerability exists in the latest version of transformeroptimus/superagi. The `/get/organisation/` endpoint does not verify the user's organization, allowing any authenticated user to retrieve sensitive configuration details, including API keys, of any organization. This could lead to unauthorized access to services and significant data breaches or financial loss.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9447" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/c952ea32-3047-42d3-8a3e-e67899e35dfd" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1230" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-f3v2-jc5f-6328/GHSA-f3v2-jc5f-6328.json b/advisories/unreviewed/2025/03/GHSA-f3v2-jc5f-6328/GHSA-f3v2-jc5f-6328.json new file mode 100644 index 00000000000..ed9d83169ae --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-f3v2-jc5f-6328/GHSA-f3v2-jc5f-6328.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f3v2-jc5f-6328", + "modified": "2025-03-20T12:32:43Z", + "published": "2025-03-20T12:32:43Z", + "aliases": [ + "CVE-2024-12374" + ], + "details": "A stored cross-site scripting (XSS) vulnerability exists in automatic1111/stable-diffusion-webui version git 82a973c. An attacker can upload an HTML file, which the application interprets as content-type application/html. If a victim accesses the malicious link, it will execute arbitrary JavaScript in the victim's browser.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12374" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/3dae386a-f442-4be6-87ef-956606c8a6ac" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-f4hc-q562-cc5r/GHSA-f4hc-q562-cc5r.json b/advisories/unreviewed/2025/03/GHSA-f4hc-q562-cc5r/GHSA-f4hc-q562-cc5r.json new file mode 100644 index 00000000000..9457df5acb7 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-f4hc-q562-cc5r/GHSA-f4hc-q562-cc5r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f4hc-q562-cc5r", + "modified": "2025-03-20T12:32:48Z", + "published": "2025-03-20T12:32:48Z", + "aliases": [ + "CVE-2024-8438" + ], + "details": "A path traversal vulnerability exists in modelscope/agentscope version v.0.0.4. The API endpoint `/api/file` does not properly sanitize the `path` parameter, allowing an attacker to read arbitrary files on the server.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8438" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/3f170c58-42ee-422d-ab6f-32c7aa05b974" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-f64v-mwpx-gv6x/GHSA-f64v-mwpx-gv6x.json b/advisories/unreviewed/2025/03/GHSA-f64v-mwpx-gv6x/GHSA-f64v-mwpx-gv6x.json new file mode 100644 index 00000000000..643c26c1706 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-f64v-mwpx-gv6x/GHSA-f64v-mwpx-gv6x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f64v-mwpx-gv6x", + "modified": "2025-03-20T12:32:47Z", + "published": "2025-03-20T12:32:47Z", + "aliases": [ + "CVE-2024-8065" + ], + "details": "A Cross-Site Request Forgery (CSRF) vulnerability in version v1.4.1 of danswer-ai/danswer allows attackers to perform unauthorized actions in the context of the victim's browser. This includes connecting the victim's application with a malicious Slack Bot, inviting users, and deleting chats, among other actions. The application does not implement any CSRF protection, making it susceptible to these attacks.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8065" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/61b58753-af36-43fd-b1b9-f3019532dd08" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-f6rh-g2v9-v6qp/GHSA-f6rh-g2v9-v6qp.json b/advisories/unreviewed/2025/03/GHSA-f6rh-g2v9-v6qp/GHSA-f6rh-g2v9-v6qp.json new file mode 100644 index 00000000000..8a30e8134f0 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-f6rh-g2v9-v6qp/GHSA-f6rh-g2v9-v6qp.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f6rh-g2v9-v6qp", + "modified": "2025-03-20T12:32:48Z", + "published": "2025-03-20T12:32:48Z", + "aliases": [ + "CVE-2024-8251" + ], + "details": "A vulnerability in mintplex-labs/anything-llm prior to version 1.2.2 allows for Prisma injection. The issue exists in the API endpoint \"/embed/:embedId/stream-chat\" where user-provided JSON is directly taken to the Prisma library's where clause. An attacker can exploit this by providing a specially crafted JSON object, such as {\"sessionId\":{\"not\":\"a\"}}, causing Prisma to return all data from the table. This can lead to unauthorized access to all user queries in embedded chat mode.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8251" + }, + { + "type": "WEB", + "url": "https://github.com/mintplex-labs/anything-llm/commit/334fd9cdd02ad4aa6a3c9bdfc95e7764651c13f4" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/7c263ef1-7d50-475a-9425-b15df4e0403c" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-fccc-8m69-8r78/GHSA-fccc-8m69-8r78.json b/advisories/unreviewed/2025/03/GHSA-fccc-8m69-8r78/GHSA-fccc-8m69-8r78.json new file mode 100644 index 00000000000..bb0e8513e51 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-fccc-8m69-8r78/GHSA-fccc-8m69-8r78.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fccc-8m69-8r78", + "modified": "2025-03-20T12:32:52Z", + "published": "2025-03-20T12:32:52Z", + "aliases": [ + "CVE-2025-0315" + ], + "details": "A vulnerability in ollama/ollama <=0.3.14 allows a malicious user to create a customized GGUF model file, upload it to the Ollama server, and create it. This can cause the server to allocate unlimited memory, leading to a Denial of Service (DoS) attack.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0315" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/da414d29-b55a-496f-b135-17e0fcec67bc" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-770" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-ff5c-56m7-vc75/GHSA-ff5c-56m7-vc75.json b/advisories/unreviewed/2025/03/GHSA-ff5c-56m7-vc75/GHSA-ff5c-56m7-vc75.json new file mode 100644 index 00000000000..f7f711d0ae1 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-ff5c-56m7-vc75/GHSA-ff5c-56m7-vc75.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ff5c-56m7-vc75", + "modified": "2025-03-20T12:32:47Z", + "published": "2025-03-20T12:32:47Z", + "aliases": [ + "CVE-2024-8060" + ], + "details": "OpenWebUI version 0.3.0 contains a vulnerability in the audio API endpoint `/audio/api/v1/transcriptions` that allows for arbitrary file upload. The application performs insufficient validation on the `file.content_type` and allows user-controlled filenames, leading to a path traversal vulnerability. This can be exploited by an authenticated user to overwrite critical files within the Docker container, potentially leading to remote code execution as the root user.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8060" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/a3b1a4b7-c723-496d-842c-844cc0988fe9" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-ffh5-w482-c7m5/GHSA-ffh5-w482-c7m5.json b/advisories/unreviewed/2025/03/GHSA-ffh5-w482-c7m5/GHSA-ffh5-w482-c7m5.json new file mode 100644 index 00000000000..7a4c1c1ea91 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-ffh5-w482-c7m5/GHSA-ffh5-w482-c7m5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ffh5-w482-c7m5", + "modified": "2025-03-20T12:32:41Z", + "published": "2025-03-20T12:32:41Z", + "aliases": [ + "CVE-2024-11043" + ], + "details": "A Denial of Service (DoS) vulnerability was discovered in the /api/v1/boards/{board_id} endpoint of invoke-ai/invokeai version v5.0.2. This vulnerability occurs when an excessively large payload is sent in the board_name field during a PATCH request. By sending a large payload, the UI becomes unresponsive, rendering it impossible for users to interact with or manage the affected board. Additionally, the option to delete the board becomes inaccessible, amplifying the severity of the issue.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11043" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/9270900a-b8b7-402f-aee5-432d891e5648" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-fgqc-p7g9-x92w/GHSA-fgqc-p7g9-x92w.json b/advisories/unreviewed/2025/03/GHSA-fgqc-p7g9-x92w/GHSA-fgqc-p7g9-x92w.json new file mode 100644 index 00000000000..4adad4be1f3 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-fgqc-p7g9-x92w/GHSA-fgqc-p7g9-x92w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fgqc-p7g9-x92w", + "modified": "2025-03-20T12:32:47Z", + "published": "2025-03-20T12:32:47Z", + "aliases": [ + "CVE-2024-8057" + ], + "details": "In version 0.4.1 of danswer-ai/danswer, a vulnerability exists where a basic user can create credentials and link them to an existing connector. This issue arises because the system allows an unauthenticated attacker to sign up with a basic account and perform actions that should be restricted to admin users. This can lead to excessive resource consumption, potentially resulting in a Denial of Service (DoS) and other significant issues, impacting the system's stability and security.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8057" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/b5991b98-a721-4acd-8ef2-980e15682913" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-fh2c-86xm-pm2x/GHSA-fh2c-86xm-pm2x.json b/advisories/unreviewed/2025/03/GHSA-fh2c-86xm-pm2x/GHSA-fh2c-86xm-pm2x.json new file mode 100644 index 00000000000..c50fa616eec --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-fh2c-86xm-pm2x/GHSA-fh2c-86xm-pm2x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fh2c-86xm-pm2x", + "modified": "2025-03-20T12:32:49Z", + "published": "2025-03-20T12:32:49Z", + "aliases": [ + "CVE-2024-8984" + ], + "details": "A Denial of Service (DoS) vulnerability exists in berriai/litellm version v1.44.5. This vulnerability can be exploited by appending characters, such as dashes (-), to the end of a multipart boundary in an HTTP request. The server continuously processes each character, leading to excessive resource consumption and rendering the service unavailable. The issue is unauthenticated and does not require any user interaction, impacting all users of the service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8984" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/554fc76b-3097-4223-b4cf-110b853e9355" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-fhfg-frx8-7458/GHSA-fhfg-frx8-7458.json b/advisories/unreviewed/2025/03/GHSA-fhfg-frx8-7458/GHSA-fhfg-frx8-7458.json new file mode 100644 index 00000000000..045467b0953 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-fhfg-frx8-7458/GHSA-fhfg-frx8-7458.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fhfg-frx8-7458", + "modified": "2025-03-20T12:32:49Z", + "published": "2025-03-20T12:32:49Z", + "aliases": [ + "CVE-2024-8954" + ], + "details": "In composiohq/composio version 0.5.10, the API does not validate the `x-api-key` header's value during the authentication step. This vulnerability allows an attacker to bypass authentication by providing any random value in the `x-api-key` header, thereby gaining unauthorized access to the server.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8954" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/f1e0fdce-00d7-4261-a466-923062800b12" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-304" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-fjcf-3j3r-78rp/GHSA-fjcf-3j3r-78rp.json b/advisories/unreviewed/2025/03/GHSA-fjcf-3j3r-78rp/GHSA-fjcf-3j3r-78rp.json new file mode 100644 index 00000000000..84a430787b9 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-fjcf-3j3r-78rp/GHSA-fjcf-3j3r-78rp.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fjcf-3j3r-78rp", + "modified": "2025-03-20T12:32:52Z", + "published": "2025-03-20T12:32:52Z", + "aliases": [ + "CVE-2025-0628" + ], + "details": "An improper authorization vulnerability exists in the main-latest version of BerriAI/litellm. When a user with the role 'internal_user_viewer' logs into the application, they are provided with an overly privileged API key. This key can be used to access all the admin functionality of the application, including endpoints such as '/users/list' and '/users/get_users'. This vulnerability allows for privilege escalation within the application, enabling any account to become a PROXY ADMIN.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0628" + }, + { + "type": "WEB", + "url": "https://github.com/berriai/litellm/commit/566d9354aab4215091b2e51ad0333e948125fa1b" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/6c0e2f75-2d03-42f9-9530-e16a973317fc" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-285" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-fm93-g6xp-35xq/GHSA-fm93-g6xp-35xq.json b/advisories/unreviewed/2025/03/GHSA-fm93-g6xp-35xq/GHSA-fm93-g6xp-35xq.json new file mode 100644 index 00000000000..6f30ef2f9b6 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-fm93-g6xp-35xq/GHSA-fm93-g6xp-35xq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fm93-g6xp-35xq", + "modified": "2025-03-20T12:32:52Z", + "published": "2025-03-20T12:32:52Z", + "aliases": [ + "CVE-2025-0190" + ], + "details": "In version 3.25.0 of aimhubio/aim, a denial of service vulnerability exists. By tracking a large number of `Text` objects and then querying them simultaneously through the web API, the Aim web server becomes unresponsive to other requests for an extended period while processing and returning these objects. This vulnerability can be exploited repeatedly, leading to a complete denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0190" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/38d151f1-abb4-443a-86b0-6c26f0c6cb70" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1049" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-fqr7-jjqq-hpr6/GHSA-fqr7-jjqq-hpr6.json b/advisories/unreviewed/2025/03/GHSA-fqr7-jjqq-hpr6/GHSA-fqr7-jjqq-hpr6.json new file mode 100644 index 00000000000..af08835a890 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-fqr7-jjqq-hpr6/GHSA-fqr7-jjqq-hpr6.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fqr7-jjqq-hpr6", + "modified": "2025-03-20T12:32:39Z", + "published": "2025-03-20T12:32:39Z", + "aliases": [ + "CVE-2024-10330" + ], + "details": "In lunary-ai/lunary version 1.5.6, the `/v1/evaluators/` endpoint lacks proper access control, allowing any user associated with a project to fetch all evaluator data regardless of their role. This vulnerability permits low-privilege users to access potentially sensitive evaluation data.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10330" + }, + { + "type": "WEB", + "url": "https://github.com/lunary-ai/lunary/commit/8ba1b8ba2c2c30b1cec30eb5777c1fda670cbbfc" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/598ecd65-1723-4fb7-a9aa-9c4f56a5a2aa" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-fx47-jpv9-7hxr/GHSA-fx47-jpv9-7hxr.json b/advisories/unreviewed/2025/03/GHSA-fx47-jpv9-7hxr/GHSA-fx47-jpv9-7hxr.json new file mode 100644 index 00000000000..882373674c2 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-fx47-jpv9-7hxr/GHSA-fx47-jpv9-7hxr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fx47-jpv9-7hxr", + "modified": "2025-03-20T12:32:38Z", + "published": "2025-03-20T12:32:38Z", + "aliases": [ + "CVE-2024-10110" + ], + "details": "In version 3.23.0 of aimhubio/aim, the ScheduledStatusReporter object can be instantiated to run on the main thread of the tracking server, leading to the main thread being blocked indefinitely. This results in a denial of service as the tracking server becomes unable to respond to other requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10110" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/5ea6cf56-7b4c-4dce-9b6c-3e910fbb1ae4" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-fxpx-7wrq-8ggp/GHSA-fxpx-7wrq-8ggp.json b/advisories/unreviewed/2025/03/GHSA-fxpx-7wrq-8ggp/GHSA-fxpx-7wrq-8ggp.json new file mode 100644 index 00000000000..431b4402cb8 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-fxpx-7wrq-8ggp/GHSA-fxpx-7wrq-8ggp.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fxpx-7wrq-8ggp", + "modified": "2025-03-20T12:32:50Z", + "published": "2025-03-20T12:32:50Z", + "aliases": [ + "CVE-2024-9098" + ], + "details": "In lunary-ai/lunary before version 1.4.30, a privilege escalation vulnerability exists where admins can invite new members with billing permissions, thereby gaining unauthorized access to billing resources. This issue arises because the user creation endpoint does not restrict admins from inviting users with billing roles. As a result, admins can circumvent the intended access control, posing a risk to the organization's financial resources.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9098" + }, + { + "type": "WEB", + "url": "https://github.com/lunary-ai/lunary/commit/a8d7b2959e87c30fbafdb12af7ffa093385dcc60" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/75d466ae-8591-44d5-9160-eea7cad0c4fc" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-g394-qpx6-x7rr/GHSA-g394-qpx6-x7rr.json b/advisories/unreviewed/2025/03/GHSA-g394-qpx6-x7rr/GHSA-g394-qpx6-x7rr.json new file mode 100644 index 00000000000..e7ae5e5fba1 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-g394-qpx6-x7rr/GHSA-g394-qpx6-x7rr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g394-qpx6-x7rr", + "modified": "2025-03-20T12:32:43Z", + "published": "2025-03-20T12:32:43Z", + "aliases": [ + "CVE-2024-12776" + ], + "details": "In langgenius/dify v0.10.1, the `/forgot-password/resets` endpoint does not verify the password reset code, allowing an attacker to reset the password of any user, including administrators. This vulnerability can lead to a complete compromise of the application.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12776" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/00a8b403-7da5-431e-afa3-40339cf734bf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-305" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-g3mx-83mp-3rwc/GHSA-g3mx-83mp-3rwc.json b/advisories/unreviewed/2025/03/GHSA-g3mx-83mp-3rwc/GHSA-g3mx-83mp-3rwc.json new file mode 100644 index 00000000000..ae1f61cd619 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-g3mx-83mp-3rwc/GHSA-g3mx-83mp-3rwc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g3mx-83mp-3rwc", + "modified": "2025-03-20T12:32:43Z", + "published": "2025-03-20T12:32:43Z", + "aliases": [ + "CVE-2024-12534" + ], + "details": "In version v0.3.32 of open-webui/open-webui, the application allows users to submit large payloads in the email and password fields during the sign-in process due to the lack of character length validation on these inputs. This vulnerability can lead to a Denial of Service (DoS) condition when a user submits excessively large strings, exhausting server resources such as CPU, memory, and disk space, and rendering the service unavailable for legitimate users. This makes the server susceptible to resource exhaustion attacks without requiring authentication.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12534" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/c7c0a4e6-acd3-49b4-8684-2c2c27014b76" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-g3p7-f346-26m6/GHSA-g3p7-f346-26m6.json b/advisories/unreviewed/2025/03/GHSA-g3p7-f346-26m6/GHSA-g3p7-f346-26m6.json new file mode 100644 index 00000000000..de79436d38a --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-g3p7-f346-26m6/GHSA-g3p7-f346-26m6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g3p7-f346-26m6", + "modified": "2025-03-20T12:32:50Z", + "published": "2025-03-20T12:32:50Z", + "aliases": [ + "CVE-2024-9216" + ], + "details": "An authentication bypass vulnerability exists in gaizhenbiao/ChuanhuChatGPT, as of commit 3856d4f, allowing any user to read and delete other users' chat history. The vulnerability arises because the username is provided via an HTTP request from the client side, rather than being read from a secure source like a cookie. This allows an attacker to pass another user's username to the get_model function, thereby gaining unauthorized access to that user's chat history.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9216" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/21e54c3f-e2d7-423b-9890-1f0cb99af4dd" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-304" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-g3v3-r244-mhhm/GHSA-g3v3-r244-mhhm.json b/advisories/unreviewed/2025/03/GHSA-g3v3-r244-mhhm/GHSA-g3v3-r244-mhhm.json new file mode 100644 index 00000000000..07c87faa215 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-g3v3-r244-mhhm/GHSA-g3v3-r244-mhhm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g3v3-r244-mhhm", + "modified": "2025-03-20T12:32:51Z", + "published": "2025-03-20T12:32:51Z", + "aliases": [ + "CVE-2024-9880" + ], + "details": "A command injection vulnerability exists in the `pandas.DataFrame.query` function of pandas-dev/pandas versions up to and including v2.2.2. This vulnerability allows an attacker to execute arbitrary commands on the server by crafting a malicious query. The issue arises from the improper validation of user-supplied input in the `query` function when using the 'python' engine, leading to potential remote command execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9880" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/a49baae1-4652-4d6c-a179-313c21c41a8d" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-g44m-hpf4-vmrp/GHSA-g44m-hpf4-vmrp.json b/advisories/unreviewed/2025/03/GHSA-g44m-hpf4-vmrp/GHSA-g44m-hpf4-vmrp.json new file mode 100644 index 00000000000..61cd41a6c54 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-g44m-hpf4-vmrp/GHSA-g44m-hpf4-vmrp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g44m-hpf4-vmrp", + "modified": "2025-03-20T12:32:43Z", + "published": "2025-03-20T12:32:43Z", + "aliases": [ + "CVE-2024-12376" + ], + "details": "A Server-Side Request Forgery (SSRF) vulnerability was identified in the lm-sys/fastchat web server, specifically in the affected version git 2c68a13. This vulnerability allows an attacker to access internal server resources and data that are otherwise inaccessible, such as AWS metadata credentials.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12376" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/c9cc3f28-ee9f-4d2d-9ee5-8c6455a11892" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-g48v-3p35-88jr/GHSA-g48v-3p35-88jr.json b/advisories/unreviewed/2025/03/GHSA-g48v-3p35-88jr/GHSA-g48v-3p35-88jr.json new file mode 100644 index 00000000000..eb6459ee920 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-g48v-3p35-88jr/GHSA-g48v-3p35-88jr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g48v-3p35-88jr", + "modified": "2025-03-20T12:32:48Z", + "published": "2025-03-20T12:32:48Z", + "aliases": [ + "CVE-2024-8616" + ], + "details": "In h2oai/h2o-3 version 3.46.0, the `/99/Models/{name}/json` endpoint allows for arbitrary file overwrite on the target server. The vulnerability arises from the `exportModelDetails` function in `ModelsHandler.java`, where the user-controllable `mexport.dir` parameter is used to specify the file path for writing model details. This can lead to overwriting files at arbitrary locations on the host system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8616" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/aebf69a5-b9b1-4d2f-a8ff-902c11a8c97a" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-73" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-g5pg-73fc-hjwq/GHSA-g5pg-73fc-hjwq.json b/advisories/unreviewed/2025/03/GHSA-g5pg-73fc-hjwq/GHSA-g5pg-73fc-hjwq.json new file mode 100644 index 00000000000..3b9acf96ae8 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-g5pg-73fc-hjwq/GHSA-g5pg-73fc-hjwq.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g5pg-73fc-hjwq", + "modified": "2025-03-20T12:32:51Z", + "published": "2025-03-20T12:32:51Z", + "aliases": [ + "CVE-2024-9606" + ], + "details": "In berriai/litellm before version 1.44.12, the `litellm/litellm_core_utils/litellm_logging.py` file contains a vulnerability where the API key masking code only masks the first 5 characters of the key. This results in the leakage of almost the entire API key in the logs, exposing a significant amount of the secret key. The issue affects version v1.44.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9606" + }, + { + "type": "WEB", + "url": "https://github.com/berriai/litellm/commit/9094071c4782183e84f10630e2450be3db55509a" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/4a03796f-a8d4-4293-84ef-d3959456223a" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-117" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-g9c4-qhpw-x7pw/GHSA-g9c4-qhpw-x7pw.json b/advisories/unreviewed/2025/03/GHSA-g9c4-qhpw-x7pw/GHSA-g9c4-qhpw-x7pw.json new file mode 100644 index 00000000000..214ea363496 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-g9c4-qhpw-x7pw/GHSA-g9c4-qhpw-x7pw.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g9c4-qhpw-x7pw", + "modified": "2025-03-20T12:32:53Z", + "published": "2025-03-20T12:32:53Z", + "aliases": [ + "CVE-2024-13921" + ], + "details": "The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.6.0 via deserialization of untrusted input from the 'form_data' parameter. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13921" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/order-import-export-for-woocommerce/trunk/admin/modules/export/classes/class-export-ajax.php" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/order-import-export-for-woocommerce/trunk/admin/modules/import/classes/class-import-ajax.php" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3258567" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/users-customers-import-export-for-wp-woocommerce/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/c5fcfa21-b3f7-4241-a931-9708ced4f811?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T12:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-gc79-m262-q226/GHSA-gc79-m262-q226.json b/advisories/unreviewed/2025/03/GHSA-gc79-m262-q226/GHSA-gc79-m262-q226.json new file mode 100644 index 00000000000..32545afe5cf --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-gc79-m262-q226/GHSA-gc79-m262-q226.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gc79-m262-q226", + "modified": "2025-03-20T12:32:38Z", + "published": "2025-03-20T12:32:38Z", + "aliases": [ + "CVE-2024-10019" + ], + "details": "A vulnerability in the `start_app_server` function of parisneo/lollms-webui V12 (Strawberry) allows for path traversal and OS command injection. The function does not properly sanitize the `app_name` parameter, enabling an attacker to upload a malicious `server.py` file and execute arbitrary code by exploiting the path traversal vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10019" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/3cf80890-2d8a-4fc7-8e0e-6d4bf648b3ea" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-23" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-gf99-rrrr-wjqh/GHSA-gf99-rrrr-wjqh.json b/advisories/unreviewed/2025/03/GHSA-gf99-rrrr-wjqh/GHSA-gf99-rrrr-wjqh.json new file mode 100644 index 00000000000..4ddedaf1609 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-gf99-rrrr-wjqh/GHSA-gf99-rrrr-wjqh.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gf99-rrrr-wjqh", + "modified": "2025-03-20T12:32:41Z", + "published": "2025-03-20T12:32:41Z", + "aliases": [ + "CVE-2024-11039" + ], + "details": "A pickle deserialization vulnerability exists in the Latex English error correction plug-in function of binary-husky/gpt_academic versions up to and including 3.83. This vulnerability allows attackers to achieve remote command execution by deserializing untrusted data. The issue arises from the inclusion of numpy in the deserialization whitelist, which can be exploited by constructing a malicious compressed package containing a merge_result.pkl file and a merge_proofread_en.tex file. The vulnerability is fixed in commit 91f5e6b.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11039" + }, + { + "type": "WEB", + "url": "https://github.com/binary-husky/gpt_academic/commit/91f5e6b8f754beb47b02f7c1893804c1c9543ccb" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/f233a365-522c-44f6-876f-db492fb58ad5" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-gg5q-w3xv-q3f4/GHSA-gg5q-w3xv-q3f4.json b/advisories/unreviewed/2025/03/GHSA-gg5q-w3xv-q3f4/GHSA-gg5q-w3xv-q3f4.json new file mode 100644 index 00000000000..5b709f6db56 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-gg5q-w3xv-q3f4/GHSA-gg5q-w3xv-q3f4.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gg5q-w3xv-q3f4", + "modified": "2025-03-20T12:32:53Z", + "published": "2025-03-20T12:32:53Z", + "aliases": [ + "CVE-2024-13923" + ], + "details": "The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.6.0 via the validate_file() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13923" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/order-import-export-for-woocommerce/trunk/admin/modules/import/classes/class-import-ajax.php#L175" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3258567" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/order-import-export-for-woocommerce/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/3283b3ff-1787-466b-9517-84bd715e4165?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T12:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-gggj-77q9-hf6x/GHSA-gggj-77q9-hf6x.json b/advisories/unreviewed/2025/03/GHSA-gggj-77q9-hf6x/GHSA-gggj-77q9-hf6x.json new file mode 100644 index 00000000000..c67202bde07 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-gggj-77q9-hf6x/GHSA-gggj-77q9-hf6x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gggj-77q9-hf6x", + "modified": "2025-03-20T12:32:50Z", + "published": "2025-03-20T12:32:50Z", + "aliases": [ + "CVE-2024-9309" + ], + "details": "A Server-Side Request Forgery (SSRF) vulnerability exists in the POST /worker_generate_stream API endpoint of the Controller API Server in haotian-liu/llava version v1.2.0 (LLaVA-1.6). This vulnerability allows attackers to exploit the victim Controller API Server's credentials to perform unauthorized web actions or access unauthorized web resources.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9309" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/2ba6be79-5c90-48fa-99cb-82503ea49a12" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-gh22-g6w4-m562/GHSA-gh22-g6w4-m562.json b/advisories/unreviewed/2025/03/GHSA-gh22-g6w4-m562/GHSA-gh22-g6w4-m562.json new file mode 100644 index 00000000000..8fddbf279bf --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-gh22-g6w4-m562/GHSA-gh22-g6w4-m562.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gh22-g6w4-m562", + "modified": "2025-03-20T12:32:41Z", + "published": "2025-03-20T12:32:41Z", + "aliases": [ + "CVE-2024-11030" + ], + "details": "GPT Academic version 3.83 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability through its HotReload plugin function, which calls the crazy_utils.get_files_from_everything() API without proper sanitization. This allows attackers to exploit the vulnerability to abuse the victim GPT Academic's Gradio Web server's credentials to access unauthorized web resources.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11030" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/729d9928-c28a-40fd-8a86-bb4ca2984bba" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-gj27-76gq-5v3p/GHSA-gj27-76gq-5v3p.json b/advisories/unreviewed/2025/03/GHSA-gj27-76gq-5v3p/GHSA-gj27-76gq-5v3p.json new file mode 100644 index 00000000000..ba3f2038dc9 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-gj27-76gq-5v3p/GHSA-gj27-76gq-5v3p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gj27-76gq-5v3p", + "modified": "2025-03-20T12:32:47Z", + "published": "2025-03-20T12:32:47Z", + "aliases": [ + "CVE-2024-7990" + ], + "details": "A stored cross-site scripting (XSS) vulnerability exists in open-webui/open-webui version 0.3.8. The vulnerability is present in the `/api/v1/models/add` endpoint, where the model description field is improperly sanitized before being rendered in chat. This allows an attacker to inject malicious scripts that can be executed by any user, including administrators, potentially leading to arbitrary code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7990" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/2256e336-0f67-449e-a82d-7fc57081a21c" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-gjxm-x497-4h6h/GHSA-gjxm-x497-4h6h.json b/advisories/unreviewed/2025/03/GHSA-gjxm-x497-4h6h/GHSA-gjxm-x497-4h6h.json new file mode 100644 index 00000000000..89c43efacba --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-gjxm-x497-4h6h/GHSA-gjxm-x497-4h6h.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gjxm-x497-4h6h", + "modified": "2025-03-20T12:32:52Z", + "published": "2025-03-20T12:32:52Z", + "aliases": [ + "CVE-2025-0655" + ], + "details": "A vulnerability in man-group/dtale versions 3.15.1 allows an attacker to override global state settings to enable the `enable_custom_filters` feature, which is typically restricted to trusted environments. Once enabled, the attacker can exploit the /test-filter endpoint to execute arbitrary system commands, leading to remote code execution (RCE). This issue is addressed in version 3.16.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0655" + }, + { + "type": "WEB", + "url": "https://github.com/man-group/dtale/commit/1e26ed3ca12fe83812b90f12a2b3e5fb0b740f7a" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/f63af7bd-5438-4b36-a39b-4c90466cff13" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-gmqg-7635-v6cj/GHSA-gmqg-7635-v6cj.json b/advisories/unreviewed/2025/03/GHSA-gmqg-7635-v6cj/GHSA-gmqg-7635-v6cj.json new file mode 100644 index 00000000000..41e41105d5b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-gmqg-7635-v6cj/GHSA-gmqg-7635-v6cj.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gmqg-7635-v6cj", + "modified": "2025-03-20T12:32:41Z", + "published": "2025-03-20T12:32:41Z", + "aliases": [ + "CVE-2024-11169" + ], + "details": "An unhandled exception in danny-avila/librechat version 3c94ff2 can lead to a server crash. The issue occurs when the fs module throws an exception while handling file uploads. An unauthenticated user can trigger this exception by sending a specially crafted request, causing the server to crash. The vulnerability is fixed in version 0.7.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11169" + }, + { + "type": "WEB", + "url": "https://github.com/danny-avila/librechat/commit/629be5c0ca2b332178524b4e3f6fac715aea8cc4" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/754e1649-5612-4ba9-a533-06b46de5c4b5" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-115" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-grjq-mg5m-r4jj/GHSA-grjq-mg5m-r4jj.json b/advisories/unreviewed/2025/03/GHSA-grjq-mg5m-r4jj/GHSA-grjq-mg5m-r4jj.json new file mode 100644 index 00000000000..5ff08a7a98e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-grjq-mg5m-r4jj/GHSA-grjq-mg5m-r4jj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-grjq-mg5m-r4jj", + "modified": "2025-03-20T12:32:39Z", + "published": "2025-03-20T12:32:39Z", + "aliases": [ + "CVE-2024-10707" + ], + "details": "gaizhenbiao/chuanhuchatgpt version git d4ec6a3 is affected by a local file inclusion vulnerability due to the use of the gradio component gr.JSON, which has a known issue (CVE-2024-4941). This vulnerability allows unauthenticated users to access arbitrary files on the server by uploading a specially crafted JSON file and exploiting the improper input validation in the handle_dataset_selection function.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10707" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/98fdedea-6ad0-4157-b7d2-ae71c9786ee8" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-gv26-qw3h-8qvp/GHSA-gv26-qw3h-8qvp.json b/advisories/unreviewed/2025/03/GHSA-gv26-qw3h-8qvp/GHSA-gv26-qw3h-8qvp.json new file mode 100644 index 00000000000..948c27c38d7 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-gv26-qw3h-8qvp/GHSA-gv26-qw3h-8qvp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gv26-qw3h-8qvp", + "modified": "2025-03-20T12:32:46Z", + "published": "2025-03-20T12:32:46Z", + "aliases": [ + "CVE-2024-7046" + ], + "details": "An improper access control vulnerability in open-webui/open-webui v0.3.8 allows an attacker to view admin details. The application does not verify whether the attacker is an administrator, allowing the attacker to directly call the /api/v1/auths/admin/details interface to retrieve the first admin (owner) details.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7046" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/684185e4-6766-4638-b08a-0de9c2820aee" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-475" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-gvmg-6fvg-2jp2/GHSA-gvmg-6fvg-2jp2.json b/advisories/unreviewed/2025/03/GHSA-gvmg-6fvg-2jp2/GHSA-gvmg-6fvg-2jp2.json new file mode 100644 index 00000000000..9cb26259fd1 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-gvmg-6fvg-2jp2/GHSA-gvmg-6fvg-2jp2.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gvmg-6fvg-2jp2", + "modified": "2025-03-20T12:32:38Z", + "published": "2025-03-20T12:32:38Z", + "aliases": [ + "CVE-2024-10252" + ], + "details": "A vulnerability in langgenius/dify versions <=v0.9.1 allows for code injection via internal SSRF requests in the Dify sandbox service. This vulnerability enables an attacker to execute arbitrary Python code with root privileges within the sandbox environment, potentially leading to the deletion of the entire sandbox service and causing irreversible damage.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10252" + }, + { + "type": "WEB", + "url": "https://github.com/langgenius/dify/commit/4ac99ffe0e1c9f4d7c523908e91bbc7739e0a8d4" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/62c6c958-96cb-426c-aebc-c41f06b9d7b0" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-gw2q-qw9j-rgv7/GHSA-gw2q-qw9j-rgv7.json b/advisories/unreviewed/2025/03/GHSA-gw2q-qw9j-rgv7/GHSA-gw2q-qw9j-rgv7.json new file mode 100644 index 00000000000..b606feb29b4 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-gw2q-qw9j-rgv7/GHSA-gw2q-qw9j-rgv7.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gw2q-qw9j-rgv7", + "modified": "2025-03-20T12:32:38Z", + "published": "2025-03-20T12:32:38Z", + "aliases": [ + "CVE-2024-10188" + ], + "details": "A vulnerability in BerriAI/litellm, as of commit 26c03c9, allows unauthenticated users to cause a Denial of Service (DoS) by exploiting the use of ast.literal_eval to parse user input. This function is not safe and is prone to DoS attacks, which can crash the litellm Python server.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10188" + }, + { + "type": "WEB", + "url": "https://github.com/berriai/litellm/commit/21156ff5d0d84a7dd93f951ca033275c77e4f73c" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/96a32812-213c-4819-ba4e-36143d35e95b" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-h254-g997-685c/GHSA-h254-g997-685c.json b/advisories/unreviewed/2025/03/GHSA-h254-g997-685c/GHSA-h254-g997-685c.json new file mode 100644 index 00000000000..09d556f5337 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-h254-g997-685c/GHSA-h254-g997-685c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h254-g997-685c", + "modified": "2025-03-20T12:32:42Z", + "published": "2025-03-20T12:32:42Z", + "aliases": [ + "CVE-2024-11603" + ], + "details": "A Server-Side Request Forgery (SSRF) vulnerability exists in lm-sys/fastchat version 0.2.36. The vulnerability is present in the `/queue/join?` endpoint, where insufficient validation of the path parameter allows an attacker to send crafted requests. This can lead to unauthorized access to internal networks or the AWS metadata endpoint, potentially exposing sensitive data and compromising internal servers.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11603" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/89f1158d-4a75-4000-a1bd-f82dd1a62bff" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-h35f-g2pq-8xq7/GHSA-h35f-g2pq-8xq7.json b/advisories/unreviewed/2025/03/GHSA-h35f-g2pq-8xq7/GHSA-h35f-g2pq-8xq7.json new file mode 100644 index 00000000000..139c8cd522c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-h35f-g2pq-8xq7/GHSA-h35f-g2pq-8xq7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h35f-g2pq-8xq7", + "modified": "2025-03-20T12:32:47Z", + "published": "2025-03-20T12:32:47Z", + "aliases": [ + "CVE-2024-8024" + ], + "details": "A CORS misconfiguration vulnerability exists in netease-youdao/qanything version 1.4.1. This vulnerability allows an attacker to bypass the Same-Origin Policy, potentially leading to sensitive information exposure. Properly implementing a restrictive CORS policy is crucial to prevent such security issues.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8024" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/bda53fab-88aa-4e03-8d9d-4cf50a98ffc7" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-346" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-h36j-8vv3-cj52/GHSA-h36j-8vv3-cj52.json b/advisories/unreviewed/2025/03/GHSA-h36j-8vv3-cj52/GHSA-h36j-8vv3-cj52.json new file mode 100644 index 00000000000..ae2bb06124c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-h36j-8vv3-cj52/GHSA-h36j-8vv3-cj52.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h36j-8vv3-cj52", + "modified": "2025-03-20T12:32:46Z", + "published": "2025-03-20T12:32:46Z", + "aliases": [ + "CVE-2024-7776" + ], + "details": "A vulnerability in the `download_model` function of the onnx/onnx framework, before and including version 1.16.1, allows for arbitrary file overwrite due to inadequate prevention of path traversal attacks in malicious tar files. This vulnerability can be exploited by an attacker to overwrite files in the user's directory, potentially leading to remote command execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7776" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/a7a46cf6-1fa0-454b-988c-62d222e83f63" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-h4p8-798h-26f4/GHSA-h4p8-798h-26f4.json b/advisories/unreviewed/2025/03/GHSA-h4p8-798h-26f4/GHSA-h4p8-798h-26f4.json new file mode 100644 index 00000000000..09097ec0dc5 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-h4p8-798h-26f4/GHSA-h4p8-798h-26f4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h4p8-798h-26f4", + "modified": "2025-03-20T12:32:52Z", + "published": "2025-03-20T12:32:52Z", + "aliases": [ + "CVE-2025-0452" + ], + "details": "eosphoros-ai/DB-GPT version latest is vulnerable to arbitrary file deletion on Windows systems via the '/v1/agent/hub/update' endpoint. The application fails to properly filter the '\\' character, which is commonly used as a separator in Windows paths. This vulnerability allows attackers to delete any files on the host system by manipulating the 'plugin_repo_name' variable.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0452" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/7e854343-3d61-47d4-ad41-c4d2f356a54a" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-73" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-h4x7-365q-3rm3/GHSA-h4x7-365q-3rm3.json b/advisories/unreviewed/2025/03/GHSA-h4x7-365q-3rm3/GHSA-h4x7-365q-3rm3.json new file mode 100644 index 00000000000..06f7340efe7 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-h4x7-365q-3rm3/GHSA-h4x7-365q-3rm3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h4x7-365q-3rm3", + "modified": "2025-03-20T12:32:51Z", + "published": "2025-03-20T12:32:51Z", + "aliases": [ + "CVE-2024-9418" + ], + "details": "In version 0.0.14 of transformeroptimus/superagi, the API endpoint `/api/users/get/{id}` returns the user's password in plaintext. This vulnerability allows an attacker to retrieve the password of another user, leading to potential account takeover.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9418" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/9a8118a2-ea32-41f5-b501-fef4f31d8213" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-522" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-h5h7-gc2g-vq79/GHSA-h5h7-gc2g-vq79.json b/advisories/unreviewed/2025/03/GHSA-h5h7-gc2g-vq79/GHSA-h5h7-gc2g-vq79.json new file mode 100644 index 00000000000..c6c68b5f8ba --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-h5h7-gc2g-vq79/GHSA-h5h7-gc2g-vq79.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h5h7-gc2g-vq79", + "modified": "2025-03-20T12:32:40Z", + "published": "2025-03-20T12:32:40Z", + "aliases": [ + "CVE-2024-10724" + ], + "details": "A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2, specifically in the Subnet NAT translations section when editing the Destination address. This vulnerability allows an attacker to execute malicious code. The issue is fixed in version 1.7.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10724" + }, + { + "type": "WEB", + "url": "https://github.com/phpipam/phpipam/commit/c1697bb6c4e4a6403d69c0868e1eb1040f98b731" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/0746e357-fcc7-44db-b8e7-857875c54999" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-h5jv-6xg2-9cv8/GHSA-h5jv-6xg2-9cv8.json b/advisories/unreviewed/2025/03/GHSA-h5jv-6xg2-9cv8/GHSA-h5jv-6xg2-9cv8.json new file mode 100644 index 00000000000..82961c5bcb4 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-h5jv-6xg2-9cv8/GHSA-h5jv-6xg2-9cv8.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h5jv-6xg2-9cv8", + "modified": "2025-03-20T12:32:48Z", + "published": "2025-03-20T12:32:48Z", + "aliases": [ + "CVE-2024-8249" + ], + "details": "mintplex-labs/anything-llm version git 6dc3642 contains an unauthenticated Denial of Service (DoS) vulnerability in the API for the embeddable chat functionality. An attacker can exploit this vulnerability by sending a malformed JSON payload to the API endpoint, causing a server crash due to an uncaught exception. This issue is fixed in version 1.2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8249" + }, + { + "type": "WEB", + "url": "https://github.com/mintplex-labs/anything-llm/commit/548da9ade30368289c5beaf0a8ee2ed2b5c1d81c" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/2fb0c93f-5bc1-4212-bdca-292db7c6951f" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-248" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-h5p2-273c-rxjp/GHSA-h5p2-273c-rxjp.json b/advisories/unreviewed/2025/03/GHSA-h5p2-273c-rxjp/GHSA-h5p2-273c-rxjp.json new file mode 100644 index 00000000000..630417b2336 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-h5p2-273c-rxjp/GHSA-h5p2-273c-rxjp.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h5p2-273c-rxjp", + "modified": "2025-03-20T12:32:39Z", + "published": "2025-03-20T12:32:39Z", + "aliases": [ + "CVE-2024-10366" + ], + "details": "An improper access control vulnerability (IDOR) exists in the delete attachments functionality of danny-avila/librechat version v0.7.5-rc2. The endpoint does not verify whether the provided attachment ID belongs to the current user, allowing any authenticated user to delete attachments of other users.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10366" + }, + { + "type": "WEB", + "url": "https://github.com/danny-avila/librechat/commit/a350443661d001ac55787741969a75d94ca14116" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/cde47cf8-dc81-46ab-b472-f7e44a981a7e" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-h7xg-cmpp-48hf/GHSA-h7xg-cmpp-48hf.json b/advisories/unreviewed/2025/03/GHSA-h7xg-cmpp-48hf/GHSA-h7xg-cmpp-48hf.json new file mode 100644 index 00000000000..d2b15fffacb --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-h7xg-cmpp-48hf/GHSA-h7xg-cmpp-48hf.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h7xg-cmpp-48hf", + "modified": "2025-03-20T12:32:39Z", + "published": "2025-03-20T12:32:39Z", + "aliases": [ + "CVE-2024-10553" + ], + "details": "A vulnerability in the h2oai/h2o-3 REST API versions 3.46.0.4 allows unauthenticated remote attackers to execute arbitrary code via deserialization of untrusted data. The vulnerability exists in the endpoints POST /99/ImportSQLTable and POST /3/SaveToHiveTable, where user-controlled JDBC URLs are passed to DriverManager.getConnection, leading to deserialization if a MySQL or PostgreSQL driver is available in the classpath. This issue is fixed in version 3.47.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10553" + }, + { + "type": "WEB", + "url": "https://github.com/h2oai/h2o-3/commit/ac1d642b4d86f10a02d75974055baf2a4b2025ac" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/e6f550dd-eda2-428c-a740-ed8f893a084b" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-h9jx-rcv4-cgqg/GHSA-h9jx-rcv4-cgqg.json b/advisories/unreviewed/2025/03/GHSA-h9jx-rcv4-cgqg/GHSA-h9jx-rcv4-cgqg.json new file mode 100644 index 00000000000..9c8eaeb02c0 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-h9jx-rcv4-cgqg/GHSA-h9jx-rcv4-cgqg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h9jx-rcv4-cgqg", + "modified": "2025-03-20T12:32:39Z", + "published": "2025-03-20T12:32:39Z", + "aliases": [ + "CVE-2024-10481" + ], + "details": "A CSRF vulnerability exists in comfyanonymous/comfyui versions up to v0.2.2. This vulnerability allows attackers to host malicious websites that, when visited by authenticated ComfyUI users, can perform arbitrary API requests on behalf of the user. This can be exploited to perform actions such as uploading arbitrary files via the `/upload/image` endpoint. The lack of CSRF protections on API endpoints like `/upload/image`, `/prompt`, and `/history` leaves users vulnerable to unauthorized actions, which could be combined with other vulnerabilities such as stored-XSS to further compromise user sessions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10481" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/f4d5bfb5-6ff1-4356-b81f-f8c01d2e6ded" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-h9m7-c24m-gqr9/GHSA-h9m7-c24m-gqr9.json b/advisories/unreviewed/2025/03/GHSA-h9m7-c24m-gqr9/GHSA-h9m7-c24m-gqr9.json new file mode 100644 index 00000000000..197f9177ea7 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-h9m7-c24m-gqr9/GHSA-h9m7-c24m-gqr9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h9m7-c24m-gqr9", + "modified": "2025-03-20T12:32:38Z", + "published": "2025-03-20T12:32:38Z", + "aliases": [ + "CVE-2024-10047" + ], + "details": "parisneo/lollms-webui versions v9.9 to the latest are vulnerable to a directory listing vulnerability. An attacker can list arbitrary directories on a Windows system by sending a specially crafted HTTP request to the /open_file endpoint.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10047" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/69c3a27c-bd93-4aff-a46b-56798f28a3ce" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-36" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hc5x-x2vx-497g/GHSA-hc5x-x2vx-497g.json b/advisories/unreviewed/2025/03/GHSA-hc5x-x2vx-497g/GHSA-hc5x-x2vx-497g.json new file mode 100644 index 00000000000..15074ae2497 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hc5x-x2vx-497g/GHSA-hc5x-x2vx-497g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hc5x-x2vx-497g", + "modified": "2025-03-20T12:32:45Z", + "published": "2025-03-20T12:32:45Z", + "aliases": [ + "CVE-2024-6827" + ], + "details": "Gunicorn version 21.2.0 does not properly validate the value of the 'Transfer-Encoding' header as specified in the RFC standards, which leads to the default fallback method of 'Content-Length,' making it vulnerable to TE.CL request smuggling. This vulnerability can lead to cache poisoning, data exposure, session manipulation, SSRF, XSS, DoS, data integrity compromise, security bypass, information leakage, and business logic abuse.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6827" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/1b4f8f38-39da-44b6-9f98-f618639d0dd7" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-444" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hc9x-f65g-gjqh/GHSA-hc9x-f65g-gjqh.json b/advisories/unreviewed/2025/03/GHSA-hc9x-f65g-gjqh/GHSA-hc9x-f65g-gjqh.json new file mode 100644 index 00000000000..d2648ec5857 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hc9x-f65g-gjqh/GHSA-hc9x-f65g-gjqh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hc9x-f65g-gjqh", + "modified": "2025-03-20T12:32:52Z", + "published": "2025-03-20T12:32:52Z", + "aliases": [ + "CVE-2025-0191" + ], + "details": "A Denial of Service (DoS) vulnerability exists in the file upload feature of gaizhenbiao/chuanhuchatgpt version 20240914. The vulnerability is due to improper handling of form-data with a large filename in the file upload request. By sending a payload with an excessively large filename, the server becomes overwhelmed and unresponsive, leading to unavailability for legitimate users.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0191" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/c89a1dfd-a733-41b3-af20-6ef6024361eb" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hh3j-9m59-p8vc/GHSA-hh3j-9m59-p8vc.json b/advisories/unreviewed/2025/03/GHSA-hh3j-9m59-p8vc/GHSA-hh3j-9m59-p8vc.json new file mode 100644 index 00000000000..12434794392 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hh3j-9m59-p8vc/GHSA-hh3j-9m59-p8vc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hh3j-9m59-p8vc", + "modified": "2025-03-20T12:32:43Z", + "published": "2025-03-20T12:32:43Z", + "aliases": [ + "CVE-2024-12759" + ], + "details": "In bentoml/bentoml version 1.3.9, the `/login` endpoint of the newly integrated Gradio app is vulnerable to a Denial of Service (DoS) attack. This vulnerability can be exploited by appending characters, such as dashes (-), to the end of a multipart boundary in an HTTP request. The server continuously processes each character, leading to excessive resource consumption and rendering the service unavailable. The issue is unauthenticated and does not require any user interaction.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12759" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/e467ec92-0ad1-4461-8468-1beabf701b9f" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hhr6-7642-8pmh/GHSA-hhr6-7642-8pmh.json b/advisories/unreviewed/2025/03/GHSA-hhr6-7642-8pmh/GHSA-hhr6-7642-8pmh.json new file mode 100644 index 00000000000..fe3e4dba485 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hhr6-7642-8pmh/GHSA-hhr6-7642-8pmh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hhr6-7642-8pmh", + "modified": "2025-03-20T12:32:41Z", + "published": "2025-03-20T12:32:41Z", + "aliases": [ + "CVE-2024-11040" + ], + "details": "vllm-project vllm version 0.5.2.2 is vulnerable to Denial of Service attacks. The issue occurs in the 'POST /v1/completions' and 'POST /v1/embeddings' endpoints. For 'POST /v1/completions', enabling 'use_beam_search' and setting 'best_of' to a high value causes the HTTP connection to time out, with vllm ceasing effective work and the request remaining in a 'pending' state, blocking new completion requests. For 'POST /v1/embeddings', supplying invalid inputs to the JSON object causes an issue in the background loop, resulting in all further completion requests returning a 500 HTTP error code ('Internal Server Error') until vllm is restarted.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11040" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/8ce20bbe-3c96-4cd1-97e5-25a5630925be" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hhw5-29f6-hf4x/GHSA-hhw5-29f6-hf4x.json b/advisories/unreviewed/2025/03/GHSA-hhw5-29f6-hf4x/GHSA-hhw5-29f6-hf4x.json new file mode 100644 index 00000000000..928dd57401c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hhw5-29f6-hf4x/GHSA-hhw5-29f6-hf4x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hhw5-29f6-hf4x", + "modified": "2025-03-20T12:32:40Z", + "published": "2025-03-20T12:32:40Z", + "aliases": [ + "CVE-2024-10831" + ], + "details": "In eosphoros-ai/db-gpt version 0.6.0, the endpoint for uploading files is vulnerable to absolute path traversal. This vulnerability allows an attacker to upload arbitrary files to arbitrary locations on the target server. The issue arises because the `file_key` and `doc_file.filename` parameters are user-controllable, enabling the construction of paths outside the intended directory. This can lead to overwriting essential system files, such as SSH keys, for further exploitation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10831" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/5c34c39f-66d4-414c-ab6a-f7888a5d882a" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-36" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hjcr-w68h-rg2p/GHSA-hjcr-w68h-rg2p.json b/advisories/unreviewed/2025/03/GHSA-hjcr-w68h-rg2p/GHSA-hjcr-w68h-rg2p.json new file mode 100644 index 00000000000..8553fe4800b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hjcr-w68h-rg2p/GHSA-hjcr-w68h-rg2p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hjcr-w68h-rg2p", + "modified": "2025-03-20T12:32:50Z", + "published": "2025-03-20T12:32:50Z", + "aliases": [ + "CVE-2024-9308" + ], + "details": "An open redirect vulnerability in haotian-liu/llava version v1.2.0 (LLaVA-1.6) allows a remote unauthenticated attacker to redirect users to arbitrary websites via a specially crafted URL. This can be exploited for phishing attacks, malware distribution, and credential theft.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9308" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/6233a165-a435-464d-915c-4c7510ffbf82" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hm5x-x82r-982c/GHSA-hm5x-x82r-982c.json b/advisories/unreviewed/2025/03/GHSA-hm5x-x82r-982c/GHSA-hm5x-x82r-982c.json new file mode 100644 index 00000000000..d83c930b9d8 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hm5x-x82r-982c/GHSA-hm5x-x82r-982c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hm5x-x82r-982c", + "modified": "2025-03-20T12:32:50Z", + "published": "2025-03-20T12:32:50Z", + "aliases": [ + "CVE-2024-9107" + ], + "details": "A stored cross-site scripting (XSS) vulnerability exists in the gaizhenbiao/chuanhuchatgpt repository, affecting version git 20b2e02. The vulnerability arises from improper sanitization of HTML tags in chat history uploads. Specifically, the sanitization logic fails to handle HTML tags within code blocks correctly, allowing an attacker to inject malicious scripts. This can lead to the execution of arbitrary JavaScript code in the context of the user's browser, potentially leading to identity theft or other malicious actions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9107" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/a2972c51-4780-4f60-afbf-a7a8ee4066ea" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hq38-64gm-3w2c/GHSA-hq38-64gm-3w2c.json b/advisories/unreviewed/2025/03/GHSA-hq38-64gm-3w2c/GHSA-hq38-64gm-3w2c.json new file mode 100644 index 00000000000..3232e8f61af --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hq38-64gm-3w2c/GHSA-hq38-64gm-3w2c.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hq38-64gm-3w2c", + "modified": "2025-03-20T12:32:49Z", + "published": "2025-03-20T12:32:49Z", + "aliases": [ + "CVE-2024-8898" + ], + "details": "A path traversal vulnerability exists in the `install` and `uninstall` API endpoints of parisneo/lollms-webui version V12 (Strawberry). This vulnerability allows attackers to create or delete directories with arbitrary paths on the system. The issue arises due to insufficient sanitization of user-supplied input, which can be exploited to traverse directories outside the intended path.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8898" + }, + { + "type": "WEB", + "url": "https://github.com/parisneo/lollms-webui/commit/6d07c8a0dd0a15cc060becc73fda9fe8e788eb23" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/6072371f-0ddc-42e3-9207-1c6d6b18d32f" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hw3w-6mhf-rh8m/GHSA-hw3w-6mhf-rh8m.json b/advisories/unreviewed/2025/03/GHSA-hw3w-6mhf-rh8m/GHSA-hw3w-6mhf-rh8m.json new file mode 100644 index 00000000000..184d405adc7 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hw3w-6mhf-rh8m/GHSA-hw3w-6mhf-rh8m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hw3w-6mhf-rh8m", + "modified": "2025-03-20T12:32:44Z", + "published": "2025-03-20T12:32:44Z", + "aliases": [ + "CVE-2024-12871" + ], + "details": "An XSS vulnerability in infiniflow/ragflow version 0.12.0 allows an attacker to upload a malicious PDF file to the knowledge base. When the file is viewed within Ragflow, the payload is executed in the context of the user's browser. This can lead to session hijacking, data exfiltration, or unauthorized actions performed on behalf of the victim, compromising sensitive user data and affecting the integrity of the entire application.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12871" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/7903945c-2839-4dd5-9d40-9ef47fe53118" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hw8j-hw49-752c/GHSA-hw8j-hw49-752c.json b/advisories/unreviewed/2025/03/GHSA-hw8j-hw49-752c/GHSA-hw8j-hw49-752c.json new file mode 100644 index 00000000000..dae070c294d --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hw8j-hw49-752c/GHSA-hw8j-hw49-752c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hw8j-hw49-752c", + "modified": "2025-03-20T12:32:50Z", + "published": "2025-03-20T12:32:50Z", + "aliases": [ + "CVE-2024-9056" + ], + "details": "BentoML version v1.3.4post1 is vulnerable to a Denial of Service (DoS) attack. The vulnerability can be exploited by appending characters, such as dashes (-), to the end of a multipart boundary in an HTTP request. This causes the server to continuously process each character, leading to excessive resource consumption and rendering the service unavailable. The issue is unauthenticated and does not require any user interaction, impacting all users of the service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9056" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/a24a13c2-0300-4a95-b26a-ac7fe8f6521b" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hx67-j5pj-h8ch/GHSA-hx67-j5pj-h8ch.json b/advisories/unreviewed/2025/03/GHSA-hx67-j5pj-h8ch/GHSA-hx67-j5pj-h8ch.json new file mode 100644 index 00000000000..320685f468f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hx67-j5pj-h8ch/GHSA-hx67-j5pj-h8ch.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hx67-j5pj-h8ch", + "modified": "2025-03-20T12:32:49Z", + "published": "2025-03-20T12:32:49Z", + "aliases": [ + "CVE-2024-8998" + ], + "details": "A Regular Expression Denial of Service (ReDoS) vulnerability exists in lunary-ai/lunary version git f07a845. The server uses the regex /{.*?}/ to match user-controlled strings. In the default JavaScript regex engine, this regex can take polynomial time to match certain crafted user inputs. As a result, an attacker can cause the server to hang for an arbitrary amount of time by submitting a specially crafted payload. This issue is fixed in version 1.4.26.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8998" + }, + { + "type": "WEB", + "url": "https://github.com/lunary-ai/lunary/commit/f2bfa036caf2c48686474f4560a9c5abcf5f43b7" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/4dbd8648-1dca-4f95-b74f-978ef030e97e" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-j274-m559-cj4j/GHSA-j274-m559-cj4j.json b/advisories/unreviewed/2025/03/GHSA-j274-m559-cj4j/GHSA-j274-m559-cj4j.json new file mode 100644 index 00000000000..ae5b23ce4eb --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-j274-m559-cj4j/GHSA-j274-m559-cj4j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j274-m559-cj4j", + "modified": "2025-03-20T12:32:45Z", + "published": "2025-03-20T12:32:45Z", + "aliases": [ + "CVE-2024-7044" + ], + "details": "A Stored Cross-Site Scripting (XSS) vulnerability exists in the chat file upload functionality of open-webui/open-webui version 0.3.8. An attacker can inject malicious content into a file, which, when accessed by a victim through a URL or shared chat, executes JavaScript in the victim's browser. This can lead to user data theft, session hijacking, malware distribution, and phishing attacks.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7044" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/c25a885c-d6e2-4169-9ee8-4d33bcbb5ef6" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-j3jw-5w88-cqxr/GHSA-j3jw-5w88-cqxr.json b/advisories/unreviewed/2025/03/GHSA-j3jw-5w88-cqxr/GHSA-j3jw-5w88-cqxr.json new file mode 100644 index 00000000000..4070d80ee86 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-j3jw-5w88-cqxr/GHSA-j3jw-5w88-cqxr.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j3jw-5w88-cqxr", + "modified": "2025-03-20T12:32:39Z", + "published": "2025-03-20T12:32:39Z", + "aliases": [ + "CVE-2024-10273" + ], + "details": "In lunary-ai/lunary v1.5.0, improper privilege management in the models.ts file allows users with viewer roles to modify models owned by others. The PATCH endpoint for models does not have appropriate privilege checks, enabling low-privilege users to update models they should not have access to modify. This vulnerability could lead to unauthorized changes in critical resources, affecting the integrity and reliability of the system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10273" + }, + { + "type": "WEB", + "url": "https://github.com/lunary-ai/lunary/commit/8ba1b8ba2c2c30b1cec30eb5777c1fda670cbbfc" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/883d9fe2-5730-41e1-a5c2-59972489876e" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-j3wr-m6xh-64hg/GHSA-j3wr-m6xh-64hg.json b/advisories/unreviewed/2025/03/GHSA-j3wr-m6xh-64hg/GHSA-j3wr-m6xh-64hg.json new file mode 100644 index 00000000000..924a01acc78 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-j3wr-m6xh-64hg/GHSA-j3wr-m6xh-64hg.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j3wr-m6xh-64hg", + "modified": "2025-03-20T12:32:43Z", + "published": "2025-03-20T12:32:43Z", + "aliases": [ + "CVE-2024-12704" + ], + "details": "A vulnerability in the LangChainLLM class of the run-llama/llama_index repository, version v0.12.5, allows for a Denial of Service (DoS) attack. The stream_complete method executes the llm using a thread and retrieves the result via the get_response_gen method of the StreamingGeneratorCallbackHandler class. If the thread terminates abnormally before the _llm.predict is executed, there is no exception handling for this case, leading to an infinite loop in the get_response_gen function. This can be triggered by providing an input of an incorrect type, causing the thread to terminate and the process to continue running indefinitely.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12704" + }, + { + "type": "WEB", + "url": "https://github.com/run-llama/llama_index/commit/d1ecfb77578d089cbe66728f18f635c09aa32a05" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/a0b638fd-21c6-4ba7-b381-6ab98472a02a" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-755" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-j46h-c723-q9rm/GHSA-j46h-c723-q9rm.json b/advisories/unreviewed/2025/03/GHSA-j46h-c723-q9rm/GHSA-j46h-c723-q9rm.json new file mode 100644 index 00000000000..f5fc7196d80 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-j46h-c723-q9rm/GHSA-j46h-c723-q9rm.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j46h-c723-q9rm", + "modified": "2025-03-20T12:32:53Z", + "published": "2025-03-20T12:32:53Z", + "aliases": [ + "CVE-2025-1802" + ], + "details": "The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘marker_title’, 'notification_content', and 'stt_button_text' parameters in all versions up to, and including, 2.8.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability was partially patched in version 2.8.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1802" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/ht-mega-for-elementor/trunk/extensions/scroll-to-top/assets/js/htmega-scroll-to-top.js" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/ht-mega-for-elementor/trunk/includes/widgets/htmega_googlemap.php" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/ht-mega-for-elementor/trunk/includes/widgets/htmega_notify.php" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3249106" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3257530" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/68530904-22d2-4228-b9f2-76f5ee1fd541?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T12:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-j4mc-gwfc-jcf5/GHSA-j4mc-gwfc-jcf5.json b/advisories/unreviewed/2025/03/GHSA-j4mc-gwfc-jcf5/GHSA-j4mc-gwfc-jcf5.json new file mode 100644 index 00000000000..b35502b49be --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-j4mc-gwfc-jcf5/GHSA-j4mc-gwfc-jcf5.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j4mc-gwfc-jcf5", + "modified": "2025-03-20T12:32:50Z", + "published": "2025-03-20T12:32:50Z", + "aliases": [ + "CVE-2024-9095" + ], + "details": "In lunary-ai/lunary version v1.4.28, the /bigquery API route lacks proper access control, allowing any logged-in user to create a Datastream to Google BigQuery and export the entire database. This includes sensitive data such as password hashes and secret API keys. The route is protected by a config check (`config.DATA_WAREHOUSE_EXPORTS_ALLOWED`), but it does not verify the user's access level or implement any access control middleware. This vulnerability can lead to the extraction of sensitive data, disruption of services, credential compromise, and service integrity breaches.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9095" + }, + { + "type": "WEB", + "url": "https://github.com/lunary-ai/lunary/commit/a8d7b2959e87c30fbafdb12af7ffa093385dcc60" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/e242a92e-da41-440d-b718-3de91e4b4eac" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-285" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-j5fq-p3c6-93jm/GHSA-j5fq-p3c6-93jm.json b/advisories/unreviewed/2025/03/GHSA-j5fq-p3c6-93jm/GHSA-j5fq-p3c6-93jm.json new file mode 100644 index 00000000000..9a9762d97b6 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-j5fq-p3c6-93jm/GHSA-j5fq-p3c6-93jm.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j5fq-p3c6-93jm", + "modified": "2025-03-20T12:32:43Z", + "published": "2025-03-20T12:32:43Z", + "aliases": [ + "CVE-2024-12580" + ], + "details": "A vulnerability in danny-avila/librechat prior to version 0.7.6 allows for logs debug injection. The parameters sessionId, fileId, userId, and file_id in the /code/download/:sessionId/:fileId and /download/:userId/:file_id APIs are not validated or filtered, leading to potential log injection attacks. This can cause distortion of monitoring and investigation information, evade detection from security systems, and create difficulties in maintenance and operation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12580" + }, + { + "type": "WEB", + "url": "https://github.com/danny-avila/librechat/commit/95d6bd2c2db4a09b308be2b96e3d5fd522c7b72a" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/6e477667-dcd4-42c2-b342-a6ce09ffdeeb" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-117" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-j5qj-rg5j-j7c2/GHSA-j5qj-rg5j-j7c2.json b/advisories/unreviewed/2025/03/GHSA-j5qj-rg5j-j7c2/GHSA-j5qj-rg5j-j7c2.json new file mode 100644 index 00000000000..9b579ca57a0 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-j5qj-rg5j-j7c2/GHSA-j5qj-rg5j-j7c2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j5qj-rg5j-j7c2", + "modified": "2025-03-20T12:32:52Z", + "published": "2025-03-20T12:32:52Z", + "aliases": [ + "CVE-2025-0189" + ], + "details": "In version 3.25.0 of aimhubio/aim, the tracking server is vulnerable to a denial of service attack. The server overrides the maximum size for websocket messages, allowing very large images to be tracked. This causes the server to become unresponsive to other requests while processing the large image, leading to a denial of service condition.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0189" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/e4c9bf41-72cf-4d04-baaf-8f12b5b7926e" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-j8gf-4j8g-8mvp/GHSA-j8gf-4j8g-8mvp.json b/advisories/unreviewed/2025/03/GHSA-j8gf-4j8g-8mvp/GHSA-j8gf-4j8g-8mvp.json new file mode 100644 index 00000000000..d61a2530360 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-j8gf-4j8g-8mvp/GHSA-j8gf-4j8g-8mvp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j8gf-4j8g-8mvp", + "modified": "2025-03-20T12:32:50Z", + "published": "2025-03-20T12:32:50Z", + "aliases": [ + "CVE-2024-9016" + ], + "details": "man-group dtale version <= 3.13.1 contains a vulnerability where the query parameters from the request are directly passed into the run_query function without proper sanitization. This allows for unauthenticated remote command execution via the df.query method when the query engine is set to 'python'.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9016" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/8b84de4f-e4c6-44f7-b985-d548b07ccf89" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-j8x9-qc9m-rmhj/GHSA-j8x9-qc9m-rmhj.json b/advisories/unreviewed/2025/03/GHSA-j8x9-qc9m-rmhj/GHSA-j8x9-qc9m-rmhj.json new file mode 100644 index 00000000000..e789921fd3b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-j8x9-qc9m-rmhj/GHSA-j8x9-qc9m-rmhj.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j8x9-qc9m-rmhj", + "modified": "2025-03-20T12:32:48Z", + "published": "2025-03-20T12:32:48Z", + "aliases": [ + "CVE-2024-8764" + ], + "details": "A vulnerability in lunary-ai/lunary, as of commit be54057, allows users to upload and execute arbitrary regular expressions on the server side. This can lead to a Denial of Service (DoS) condition, as certain regular expressions can cause excessive resource consumption, blocking the server from processing other requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8764" + }, + { + "type": "WEB", + "url": "https://github.com/lunary-ai/lunary/commit/7ff89b0304d191534b924cf063f3648206d497fa" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/088c04a1-d23a-47f2-9d7c-b84d7332868d" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-285" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-j9g7-mqhh-9hxf/GHSA-j9g7-mqhh-9hxf.json b/advisories/unreviewed/2025/03/GHSA-j9g7-mqhh-9hxf/GHSA-j9g7-mqhh-9hxf.json new file mode 100644 index 00000000000..4348fade74b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-j9g7-mqhh-9hxf/GHSA-j9g7-mqhh-9hxf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j9g7-mqhh-9hxf", + "modified": "2025-03-20T12:32:40Z", + "published": "2025-03-20T12:32:40Z", + "aliases": [ + "CVE-2024-10833" + ], + "details": "eosphoros-ai/db-gpt version 0.6.0 is vulnerable to an arbitrary file write through the knowledge API. The endpoint for uploading files as 'knowledge' is susceptible to absolute path traversal, allowing attackers to write files to arbitrary locations on the target server. This vulnerability arises because the 'doc_file.filename' parameter is user-controllable, enabling the construction of absolute paths.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10833" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/dc58e981-e325-4c11-b4e1-1095890fd15a" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-j9rw-qm5f-r8xm/GHSA-j9rw-qm5f-r8xm.json b/advisories/unreviewed/2025/03/GHSA-j9rw-qm5f-r8xm/GHSA-j9rw-qm5f-r8xm.json new file mode 100644 index 00000000000..f8bcc0b0d40 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-j9rw-qm5f-r8xm/GHSA-j9rw-qm5f-r8xm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j9rw-qm5f-r8xm", + "modified": "2025-03-20T12:32:48Z", + "published": "2025-03-20T12:32:48Z", + "aliases": [ + "CVE-2024-8551" + ], + "details": "A path traversal vulnerability exists in the save-workflow and load-workflow functionality of modelscope/agentscope versions prior to the fix. This vulnerability allows an attacker to read and write arbitrary JSON files on the filesystem, potentially leading to the exposure or modification of sensitive information such as configuration files, API keys, and hardcoded passwords.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8551" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/e0c0c294-f1e2-4f2c-a632-a9be9fd06989" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-23" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jccx-m9v4-9hwh/GHSA-jccx-m9v4-9hwh.json b/advisories/unreviewed/2025/03/GHSA-jccx-m9v4-9hwh/GHSA-jccx-m9v4-9hwh.json new file mode 100644 index 00000000000..f50c9988857 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jccx-m9v4-9hwh/GHSA-jccx-m9v4-9hwh.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jccx-m9v4-9hwh", + "modified": "2025-03-20T12:32:45Z", + "published": "2025-03-20T12:32:45Z", + "aliases": [ + "CVE-2024-6982" + ], + "details": "A remote code execution vulnerability exists in the Calculate function of parisneo/lollms version 9.8. The vulnerability arises from the use of Python's `eval()` function to evaluate mathematical expressions within a Python sandbox that disables `__builtins__` and only allows functions from the `math` module. This sandbox can be bypassed by loading the `os` module using the `_frozen_importlib.BuiltinImporter` class, allowing an attacker to execute arbitrary commands on the server. The issue is fixed in version 9.10.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6982" + }, + { + "type": "WEB", + "url": "https://github.com/parisneo/lollms/commit/30e7eaba2ccfb751a81e7cb29fdef2ae8ffa6832" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/4f8e73ac-aaaf-4d5c-a6dd-58215b5a7fea" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jfm2-hq55-pxgq/GHSA-jfm2-hq55-pxgq.json b/advisories/unreviewed/2025/03/GHSA-jfm2-hq55-pxgq/GHSA-jfm2-hq55-pxgq.json new file mode 100644 index 00000000000..ca03c1dd1ee --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jfm2-hq55-pxgq/GHSA-jfm2-hq55-pxgq.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jfm2-hq55-pxgq", + "modified": "2025-03-20T12:32:49Z", + "published": "2025-03-20T12:32:48Z", + "aliases": [ + "CVE-2024-8789" + ], + "details": "Lunary-ai/lunary version git 105a3f6 is vulnerable to a Regular Expression Denial of Service (ReDoS) attack. The application allows users to upload their own regular expressions, which are then executed on the server side. Certain regular expressions can have exponential runtime complexity relative to the input size, leading to potential denial of service. An attacker can exploit this by submitting a specially crafted regular expression, causing the server to become unresponsive for an arbitrary length of time.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8789" + }, + { + "type": "WEB", + "url": "https://github.com/lunary-ai/lunary/commit/7ff89b0304d191534b924cf063f3648206d497fa" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/e32f5f0d-bd46-4268-b6b1-619e07c6fda3" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jg5r-v2h9-wfxx/GHSA-jg5r-v2h9-wfxx.json b/advisories/unreviewed/2025/03/GHSA-jg5r-v2h9-wfxx/GHSA-jg5r-v2h9-wfxx.json new file mode 100644 index 00000000000..0ce54cf3b7e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jg5r-v2h9-wfxx/GHSA-jg5r-v2h9-wfxx.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jg5r-v2h9-wfxx", + "modified": "2025-03-20T12:32:52Z", + "published": "2025-03-20T12:32:52Z", + "aliases": [ + "CVE-2025-0454" + ], + "details": "A Server-Side Request Forgery (SSRF) vulnerability was identified in the Requests utility of significant-gravitas/autogpt versions prior to v0.4.0. The vulnerability arises due to a hostname confusion between the `urlparse` function from the `urllib.parse` library and the `requests` library. A malicious user can exploit this by submitting a specially crafted URL, such as `http://localhost:\\@google.com/../`, to bypass the SSRF check and perform an SSRF attack.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0454" + }, + { + "type": "WEB", + "url": "https://github.com/significant-gravitas/autogpt/commit/ff065cd24c2289878c0abdb9adbf91c305f0d70a" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/0664fdee-bdc2-4650-8075-74d7b8d3e308" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jjcv-gwx7-hcx9/GHSA-jjcv-gwx7-hcx9.json b/advisories/unreviewed/2025/03/GHSA-jjcv-gwx7-hcx9/GHSA-jjcv-gwx7-hcx9.json new file mode 100644 index 00000000000..cec1a7b5196 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jjcv-gwx7-hcx9/GHSA-jjcv-gwx7-hcx9.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jjcv-gwx7-hcx9", + "modified": "2025-03-20T12:32:48Z", + "published": "2025-03-20T12:32:48Z", + "aliases": [ + "CVE-2024-8400" + ], + "details": "A stored cross-site scripting (XSS) vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. The vulnerability allows an attacker to upload a malicious HTML file containing JavaScript code, which is then executed when the file is accessed. This can lead to the execution of arbitrary JavaScript in the context of the user's browser.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8400" + }, + { + "type": "WEB", + "url": "https://github.com/gaizhenbiao/chuanhuchatgpt/commit/2cca68e34f029babbe4eaa5a77d220dad68fdd49" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/405f16b8-848e-427d-a61a-ea7d3fd6f0e3" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jjhp-4v9p-5fv8/GHSA-jjhp-4v9p-5fv8.json b/advisories/unreviewed/2025/03/GHSA-jjhp-4v9p-5fv8/GHSA-jjhp-4v9p-5fv8.json new file mode 100644 index 00000000000..9f632fbfd7c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jjhp-4v9p-5fv8/GHSA-jjhp-4v9p-5fv8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jjhp-4v9p-5fv8", + "modified": "2025-03-20T12:32:51Z", + "published": "2025-03-20T12:32:51Z", + "aliases": [ + "CVE-2024-9612" + ], + "details": "In danswer-ai/danswer v0.3.94, administrators can set the visibility of pages within a workspace, including the search page. When the search page is set to be invisible, regular users cannot view the search page or access its functionalities from the front-end interface. However, the back-end does not verify the visibility status of the search page. Consequently, attackers can directly call the API to access the functionalities provided by the search page, bypassing the visibility restriction set by the administrator.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9612" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/c1046fa0-a719-475e-ba62-2b97873fbac4" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1100" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jjm2-vhrm-92vg/GHSA-jjm2-vhrm-92vg.json b/advisories/unreviewed/2025/03/GHSA-jjm2-vhrm-92vg/GHSA-jjm2-vhrm-92vg.json new file mode 100644 index 00000000000..a7de73be3f5 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jjm2-vhrm-92vg/GHSA-jjm2-vhrm-92vg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jjm2-vhrm-92vg", + "modified": "2025-03-20T12:32:42Z", + "published": "2025-03-20T12:32:42Z", + "aliases": [ + "CVE-2024-12039" + ], + "details": "langgenius/dify version v0.10.1 contains a vulnerability where there are no limits applied to the number of code guess attempts for password reset. This allows an unauthenticated attacker to reset owner, admin, or other user passwords within a few hours by guessing the six-digit code, resulting in a complete compromise of the application.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12039" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/61af30d5-6055-4c6c-8a55-3fa43dada512" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-307" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jm82-665g-74jp/GHSA-jm82-665g-74jp.json b/advisories/unreviewed/2025/03/GHSA-jm82-665g-74jp/GHSA-jm82-665g-74jp.json new file mode 100644 index 00000000000..6263ee084f2 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jm82-665g-74jp/GHSA-jm82-665g-74jp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jm82-665g-74jp", + "modified": "2025-03-20T12:32:52Z", + "published": "2025-03-20T12:32:52Z", + "aliases": [ + "CVE-2025-0187" + ], + "details": "A Denial of Service (DoS) vulnerability was discovered in the file upload feature of gradio-app/gradio version 0.39.1. The vulnerability is due to improper handling of form-data with a large filename in the file upload request. By sending a payload with an excessively large filename, the server becomes overwhelmed and unresponsive, leading to unavailability for legitimate users.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0187" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/77f3ed54-9e1c-4d9f-948f-ee6f82e2fe24" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jm87-8wm6-fr27/GHSA-jm87-8wm6-fr27.json b/advisories/unreviewed/2025/03/GHSA-jm87-8wm6-fr27/GHSA-jm87-8wm6-fr27.json new file mode 100644 index 00000000000..f8f4b27b9ba --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jm87-8wm6-fr27/GHSA-jm87-8wm6-fr27.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jm87-8wm6-fr27", + "modified": "2025-03-20T12:32:52Z", + "published": "2025-03-20T12:32:52Z", + "aliases": [ + "CVE-2025-0313" + ], + "details": "A vulnerability in ollama/ollama versions <=0.3.14 allows a malicious user to create a GGUF model that can cause a denial of service (DoS) attack. The vulnerability is due to improper validation of array index bounds in the GGUF model handling code, which can be exploited via a remote network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0313" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/450c90f9-bc02-4560-afd4-d0aa057ac82c" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-129" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jmgm-gx32-vp4w/GHSA-jmgm-gx32-vp4w.json b/advisories/unreviewed/2025/03/GHSA-jmgm-gx32-vp4w/GHSA-jmgm-gx32-vp4w.json new file mode 100644 index 00000000000..b2e483a9643 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jmgm-gx32-vp4w/GHSA-jmgm-gx32-vp4w.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jmgm-gx32-vp4w", + "modified": "2025-03-20T12:32:44Z", + "published": "2025-03-20T12:32:44Z", + "aliases": [ + "CVE-2024-12911" + ], + "details": "A vulnerability in the `default_jsonalyzer` function of the `JSONalyzeQueryEngine` in the run-llama/llama_index repository allows for SQL injection via prompt injection. This can lead to arbitrary file creation and Denial-of-Service (DoS) attacks. The vulnerability affects the latest version and is fixed in version 0.5.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12911" + }, + { + "type": "WEB", + "url": "https://github.com/run-llama/llama_index/commit/bf282074e20e7dafd5e2066137dcd4cd17c3fb9e" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/095f9e67-311d-494c-99c5-5e61a0adb8f3" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-379" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jqgv-3ch9-c9qv/GHSA-jqgv-3ch9-c9qv.json b/advisories/unreviewed/2025/03/GHSA-jqgv-3ch9-c9qv/GHSA-jqgv-3ch9-c9qv.json new file mode 100644 index 00000000000..db706f27ee7 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jqgv-3ch9-c9qv/GHSA-jqgv-3ch9-c9qv.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jqgv-3ch9-c9qv", + "modified": "2025-03-20T12:32:48Z", + "published": "2025-03-20T12:32:48Z", + "aliases": [ + "CVE-2024-8763" + ], + "details": "A Regular Expression Denial of Service (ReDoS) vulnerability exists in the lunary-ai/lunary repository, specifically in the compileTextTemplate function. The affected version is git be54057. An attacker can exploit this vulnerability by manipulating the regular expression /{{(.*?)}}/g, causing the server to hang indefinitely and become unresponsive to any requests. This is due to the regular expression's susceptibility to second-degree polynomial time complexity, which can be triggered by a large number of braces in the input.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8763" + }, + { + "type": "WEB", + "url": "https://github.com/lunary-ai/lunary/commit/7ff89b0304d191534b924cf063f3648206d497fa" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/4fb63a6e-0056-4550-a34d-e161de1c13b8" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jrhc-9qg9-4qfq/GHSA-jrhc-9qg9-4qfq.json b/advisories/unreviewed/2025/03/GHSA-jrhc-9qg9-4qfq/GHSA-jrhc-9qg9-4qfq.json new file mode 100644 index 00000000000..2fd86cdbe84 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jrhc-9qg9-4qfq/GHSA-jrhc-9qg9-4qfq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jrhc-9qg9-4qfq", + "modified": "2025-03-20T12:32:45Z", + "published": "2025-03-20T12:32:45Z", + "aliases": [ + "CVE-2024-7043" + ], + "details": "An improper access control vulnerability in open-webui/open-webui v0.3.8 allows attackers to view and delete any files. The application does not verify whether the attacker is an administrator, allowing the attacker to directly call the GET /api/v1/files/ interface to retrieve information on all files uploaded by users, which includes the ID values. The attacker can then use the GET /api/v1/files/{file_id} interface to obtain information on any file and the DELETE /api/v1/files/{file_id} interface to delete any file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7043" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/c01e0c7f-68d8-45cf-91d2-521c97f33b00" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-821" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jrhv-8gfh-55w6/GHSA-jrhv-8gfh-55w6.json b/advisories/unreviewed/2025/03/GHSA-jrhv-8gfh-55w6/GHSA-jrhv-8gfh-55w6.json new file mode 100644 index 00000000000..26aea562998 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jrhv-8gfh-55w6/GHSA-jrhv-8gfh-55w6.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jrhv-8gfh-55w6", + "modified": "2025-03-20T12:32:53Z", + "published": "2025-03-20T12:32:53Z", + "aliases": [ + "CVE-2024-13922" + ], + "details": "The Order Export & Order Import for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the admin_log_page() function in all versions up to, and including, 2.6.0. This makes it possible for authenticated attackers, with Administrator-level access and above, to delete arbitrary log files on the server.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13922" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/order-import-export-for-woocommerce/trunk/admin/modules/history/history.php#L248" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3258567" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/product-import-export-for-woo/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/4eb8f85f-656a-4e5a-a57d-7289da2cd951?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-73" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T12:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jv2r-r6r9-hvhj/GHSA-jv2r-r6r9-hvhj.json b/advisories/unreviewed/2025/03/GHSA-jv2r-r6r9-hvhj/GHSA-jv2r-r6r9-hvhj.json new file mode 100644 index 00000000000..61c2fcb9b4b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jv2r-r6r9-hvhj/GHSA-jv2r-r6r9-hvhj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jv2r-r6r9-hvhj", + "modified": "2025-03-20T12:32:46Z", + "published": "2025-03-20T12:32:46Z", + "aliases": [ + "CVE-2024-7767" + ], + "details": "An improper access control vulnerability exists in danswer-ai/danswer version v0.3.94. This vulnerability allows the first user created in the system to view, modify, and delete chats created by an Admin. This can lead to unauthorized access to sensitive information, loss of data integrity, and potential compliance violations.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7767" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/1425dada-72d8-4bd9-a3e7-2863bb3e1a6c" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jvpf-xf32-2w4q/GHSA-jvpf-xf32-2w4q.json b/advisories/unreviewed/2025/03/GHSA-jvpf-xf32-2w4q/GHSA-jvpf-xf32-2w4q.json new file mode 100644 index 00000000000..b921c9a08d0 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jvpf-xf32-2w4q/GHSA-jvpf-xf32-2w4q.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jvpf-xf32-2w4q", + "modified": "2025-03-20T12:32:45Z", + "published": "2025-03-20T12:32:44Z", + "aliases": [ + "CVE-2024-12910" + ], + "details": "A vulnerability in the `KnowledgeBaseWebReader` class of the run-llama/llama_index repository, version latest, allows an attacker to cause a Denial of Service (DoS) by controlling a URL variable to contain the root URL. This leads to infinite recursive calls to the `get_article_urls` method, exhausting system resources and potentially crashing the application.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12910" + }, + { + "type": "WEB", + "url": "https://github.com/run-llama/llama_index/commit/159ce485a1168100bb219dc1b93133f1121579d9" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/27883f22-35ff-49df-aaa5-05031c7d6ad8" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jw8w-84x3-c2r9/GHSA-jw8w-84x3-c2r9.json b/advisories/unreviewed/2025/03/GHSA-jw8w-84x3-c2r9/GHSA-jw8w-84x3-c2r9.json new file mode 100644 index 00000000000..ba134758e36 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jw8w-84x3-c2r9/GHSA-jw8w-84x3-c2r9.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jw8w-84x3-c2r9", + "modified": "2025-03-20T12:32:41Z", + "published": "2025-03-20T12:32:41Z", + "aliases": [ + "CVE-2024-11167" + ], + "details": "An improper access control vulnerability in danny-avila/librechat versions prior to 0.7.6 allows authenticated users to delete other users' prompts via the groupid parameter. This issue occurs because the endpoint does not verify whether the provided prompt ID belongs to the current user.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11167" + }, + { + "type": "WEB", + "url": "https://github.com/danny-avila/librechat/commit/5071bdbf9ac621165f0e8d009818851f3951eee7" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/298f5760-5797-4432-8b9e-544609d612c0" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jx9r-x782-9r4m/GHSA-jx9r-x782-9r4m.json b/advisories/unreviewed/2025/03/GHSA-jx9r-x782-9r4m/GHSA-jx9r-x782-9r4m.json new file mode 100644 index 00000000000..b58cb9de03b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jx9r-x782-9r4m/GHSA-jx9r-x782-9r4m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jx9r-x782-9r4m", + "modified": "2025-03-20T12:32:38Z", + "published": "2025-03-20T12:32:38Z", + "aliases": [ + "CVE-2024-10264" + ], + "details": "HTTP Request Smuggling vulnerability in netease-youdao/qanything version 1.4.1 allows attackers to exploit inconsistencies in the interpretation of HTTP requests between a proxy and a server. This can lead to unauthorized access, bypassing security controls, session hijacking, data leakage, and potentially arbitrary code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10264" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/988247d5-fd60-4d85-845a-e867d62c0d02" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-444" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-m2g8-2vhm-m4cx/GHSA-m2g8-2vhm-m4cx.json b/advisories/unreviewed/2025/03/GHSA-m2g8-2vhm-m4cx/GHSA-m2g8-2vhm-m4cx.json new file mode 100644 index 00000000000..3476ad9aec1 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-m2g8-2vhm-m4cx/GHSA-m2g8-2vhm-m4cx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m2g8-2vhm-m4cx", + "modified": "2025-03-20T12:32:43Z", + "published": "2025-03-20T12:32:43Z", + "aliases": [ + "CVE-2024-12390" + ], + "details": "A vulnerability in binary-husky/gpt_academic version git 310122f allows for remote code execution. The application supports the extraction of user-provided RAR files without proper validation. The Python rarfile module, which supports symlinks, can be exploited to perform arbitrary file writes. This can lead to remote code execution by writing to sensitive files such as SSH keys, crontab files, or the application's own code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12390" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/1add2b26-460d-4aa5-8fda-ab045d153177" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-475" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-m2gm-4vg9-pcc4/GHSA-m2gm-4vg9-pcc4.json b/advisories/unreviewed/2025/03/GHSA-m2gm-4vg9-pcc4/GHSA-m2gm-4vg9-pcc4.json new file mode 100644 index 00000000000..bec828829dd --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-m2gm-4vg9-pcc4/GHSA-m2gm-4vg9-pcc4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m2gm-4vg9-pcc4", + "modified": "2025-03-20T12:32:41Z", + "published": "2025-03-20T12:32:41Z", + "aliases": [ + "CVE-2024-10954" + ], + "details": "In the `manim` plugin of binary-husky/gpt_academic, versions prior to the fix, a vulnerability exists due to improper handling of user-provided prompts. The root cause is the execution of untrusted code generated by the LLM without a proper sandbox. This allows an attacker to perform remote code execution (RCE) on the app backend server by injecting malicious code through the prompt.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10954" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/72d034e3-6ca2-495d-98a7-ac9565588c09" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-m2v2-9gxp-2r53/GHSA-m2v2-9gxp-2r53.json b/advisories/unreviewed/2025/03/GHSA-m2v2-9gxp-2r53/GHSA-m2v2-9gxp-2r53.json new file mode 100644 index 00000000000..f9693bb6d0a --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-m2v2-9gxp-2r53/GHSA-m2v2-9gxp-2r53.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m2v2-9gxp-2r53", + "modified": "2025-03-20T12:32:43Z", + "published": "2025-03-20T12:32:43Z", + "aliases": [ + "CVE-2024-12766" + ], + "details": "parisneo/lollms-webui version V13 (feather) suffers from a Server-Side Request Forgery (SSRF) vulnerability in the `POST /api/proxy` REST API. Attackers can exploit this vulnerability to abuse the victim server's credentials to access unauthorized web resources by specifying the JSON parameter `{\"url\":\"http://steal.target\"}`. Existing security mechanisms such as `forbid_remote_access(lollmsElfServer)`, `lollmsElfServer.config.headless_server_mode`, and `check_access(lollmsElfServer, request.client_id)` do not protect against this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12766" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/a143a2e2-1293-4dec-b875-3312584bd2b1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-m37h-8r48-2cxj/GHSA-m37h-8r48-2cxj.json b/advisories/unreviewed/2025/03/GHSA-m37h-8r48-2cxj/GHSA-m37h-8r48-2cxj.json new file mode 100644 index 00000000000..b66fc6867fd --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-m37h-8r48-2cxj/GHSA-m37h-8r48-2cxj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m37h-8r48-2cxj", + "modified": "2025-03-20T12:32:45Z", + "published": "2025-03-20T12:32:45Z", + "aliases": [ + "CVE-2024-6863" + ], + "details": "In h2oai/h2o-3 version 3.46.0, an endpoint exposing a custom EncryptionTool allows an attacker to encrypt any files on the target server with a key of their choosing. The chosen key can also be overwritten, resulting in ransomware-like behavior. This vulnerability makes it possible for an attacker to encrypt arbitrary files with keys of their choice, making it exceedingly difficult for the target to recover the keys needed for decryption.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6863" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/10f55937-0cba-4530-897f-2abf30ed5270" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-749" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-m47g-ghr5-3734/GHSA-m47g-ghr5-3734.json b/advisories/unreviewed/2025/03/GHSA-m47g-ghr5-3734/GHSA-m47g-ghr5-3734.json new file mode 100644 index 00000000000..7dedf374587 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-m47g-ghr5-3734/GHSA-m47g-ghr5-3734.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m47g-ghr5-3734", + "modified": "2025-03-20T12:32:51Z", + "published": "2025-03-20T12:32:51Z", + "aliases": [ + "CVE-2024-9363" + ], + "details": "An unauthorized file deletion vulnerability exists in the latest version of the Polyaxon platform, which can lead to denial of service by terminating critical containers. An attacker can delete important files within the containers, such as `polyaxon.sock`, causing the API container to exit unexpectedly. This disrupts related services and prevents the system from functioning normally, without requiring authentication or UUID parameters.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9363" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/ec7b7e1d-795d-4414-93d5-9df35d2fd391" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-23" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-m62f-m76v-gfwr/GHSA-m62f-m76v-gfwr.json b/advisories/unreviewed/2025/03/GHSA-m62f-m76v-gfwr/GHSA-m62f-m76v-gfwr.json new file mode 100644 index 00000000000..709968427ad --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-m62f-m76v-gfwr/GHSA-m62f-m76v-gfwr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m62f-m76v-gfwr", + "modified": "2025-03-20T12:32:47Z", + "published": "2025-03-20T12:32:47Z", + "aliases": [ + "CVE-2024-8026" + ], + "details": "A Cross-Site Request Forgery (CSRF) vulnerability exists in the backend API of netease-youdao/qanything, as of commit d9ab8bc. The backend server has overly permissive CORS headers, allowing all cross-origin calls. This vulnerability affects all backend endpoints, enabling actions such as creating, uploading, listing, deleting files, and managing knowledge bases.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8026" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/e57f1e32-0fe5-4997-926c-587461aa6274" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-m724-88wc-fpgh/GHSA-m724-88wc-fpgh.json b/advisories/unreviewed/2025/03/GHSA-m724-88wc-fpgh/GHSA-m724-88wc-fpgh.json new file mode 100644 index 00000000000..15802056348 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-m724-88wc-fpgh/GHSA-m724-88wc-fpgh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m724-88wc-fpgh", + "modified": "2025-03-20T12:32:51Z", + "published": "2025-03-20T12:32:51Z", + "aliases": [ + "CVE-2024-9431" + ], + "details": "In version v0.0.14 of transformeroptimus/superagi, there is an improper privilege management vulnerability. After logging into the system, users can change the passwords of other users, leading to potential account takeover.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9431" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/9b33d7c1-ed0a-4f5b-a378-694570fd990b" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-m724-hqmc-ggpx/GHSA-m724-hqmc-ggpx.json b/advisories/unreviewed/2025/03/GHSA-m724-hqmc-ggpx/GHSA-m724-hqmc-ggpx.json new file mode 100644 index 00000000000..1eff84662ad --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-m724-hqmc-ggpx/GHSA-m724-hqmc-ggpx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m724-hqmc-ggpx", + "modified": "2025-03-20T12:32:42Z", + "published": "2025-03-20T12:32:42Z", + "aliases": [ + "CVE-2024-12216" + ], + "details": "A vulnerability in the `ImageClassificationDataset.from_csv()` API of the `dmlc/gluon-cv` repository, version 0.10.0, allows for arbitrary file write. The function downloads and extracts `tar.gz` files from URLs without proper sanitization, making it susceptible to a TarSlip vulnerability. Attackers can exploit this by crafting malicious tar files that, when extracted, can overwrite files on the victim's system via path traversal or faked symlinks.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12216" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/46081fdc-2951-4deb-a2c9-2627007bdce0" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-m74w-gj86-32q9/GHSA-m74w-gj86-32q9.json b/advisories/unreviewed/2025/03/GHSA-m74w-gj86-32q9/GHSA-m74w-gj86-32q9.json new file mode 100644 index 00000000000..43654f25682 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-m74w-gj86-32q9/GHSA-m74w-gj86-32q9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m74w-gj86-32q9", + "modified": "2025-03-20T12:32:42Z", + "published": "2025-03-20T12:32:42Z", + "aliases": [ + "CVE-2024-12048" + ], + "details": "An IDOR (Insecure Direct Object Reference) vulnerability exists in transformeroptimus/superagi version v0.0.14. The application fails to properly check authorization for multiple API endpoints, allowing attackers to view, edit, and delete other users' information without proper authorization. Affected endpoints include but are not limited to /get/project/{project_id}, /get/schedule_data/{agent_id}, /delete/{agent_id}, /get/organisation/{organisation_id}, and /get/user/{user_id}.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12048" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/6def3e3a-c443-44bb-b20e-3e69b48f37dc" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-304" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-m76r-xqqj-mqmv/GHSA-m76r-xqqj-mqmv.json b/advisories/unreviewed/2025/03/GHSA-m76r-xqqj-mqmv/GHSA-m76r-xqqj-mqmv.json new file mode 100644 index 00000000000..31605daa967 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-m76r-xqqj-mqmv/GHSA-m76r-xqqj-mqmv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m76r-xqqj-mqmv", + "modified": "2025-03-20T12:32:50Z", + "published": "2025-03-20T12:32:50Z", + "aliases": [ + "CVE-2024-9229" + ], + "details": "A Denial of Service (DoS) vulnerability in the file upload feature of stangirard/quivr v0.0.298 allows unauthenticated attackers to cause excessive resource consumption by appending characters to the end of a multipart boundary in an HTTP request. This leads to the server continuously processing each character, rendering the service unavailable and impacting all users.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9229" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/946a412d-422f-4623-bb1d-d2646ad23dfd" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-mc9m-5hw4-g3g6/GHSA-mc9m-5hw4-g3g6.json b/advisories/unreviewed/2025/03/GHSA-mc9m-5hw4-g3g6/GHSA-mc9m-5hw4-g3g6.json new file mode 100644 index 00000000000..da4993a71fa --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-mc9m-5hw4-g3g6/GHSA-mc9m-5hw4-g3g6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mc9m-5hw4-g3g6", + "modified": "2025-03-20T12:32:52Z", + "published": "2025-03-20T12:32:52Z", + "aliases": [ + "CVE-2025-0188" + ], + "details": "A Server-Side Request Forgery (SSRF) vulnerability was discovered in gaizhenbiao/chuanhuchatgpt version 20240914. The vulnerability allows an attacker to construct a response link by saving the response in a folder named after the SHA-1 hash of the target URL. This enables the attacker to access the response directly, potentially leading to unauthorized access to internal systems, data theft, service disruption, or further attacks such as port scanning and accessing metadata endpoints.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0188" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/879d2470-eca5-49c0-b3d1-57469cfff412" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-mf57-6hg5-mrvm/GHSA-mf57-6hg5-mrvm.json b/advisories/unreviewed/2025/03/GHSA-mf57-6hg5-mrvm/GHSA-mf57-6hg5-mrvm.json new file mode 100644 index 00000000000..01129c2efb4 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-mf57-6hg5-mrvm/GHSA-mf57-6hg5-mrvm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mf57-6hg5-mrvm", + "modified": "2025-03-20T12:32:52Z", + "published": "2025-03-20T12:32:52Z", + "aliases": [ + "CVE-2025-0185" + ], + "details": "A vulnerability in the Dify Tools' Vanna module of the langgenius/dify repository allows for a Pandas Query Injection in the latest version. The vulnerability occurs in the function `vn.get_training_plan_generic(df_information_schema)`, which does not properly sanitize user inputs before executing queries using the Pandas library. This can potentially lead to Remote Code Execution (RCE) if exploited.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0185" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/7d9eb9b2-7b86-45ed-89bd-276c1350db7e" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-mhmr-w8pp-75w5/GHSA-mhmr-w8pp-75w5.json b/advisories/unreviewed/2025/03/GHSA-mhmr-w8pp-75w5/GHSA-mhmr-w8pp-75w5.json new file mode 100644 index 00000000000..eeeeed5f764 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-mhmr-w8pp-75w5/GHSA-mhmr-w8pp-75w5.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mhmr-w8pp-75w5", + "modified": "2025-03-20T12:32:39Z", + "published": "2025-03-20T12:32:39Z", + "aliases": [ + "CVE-2024-10363" + ], + "details": "In version 0.7.5 of danny-avila/LibreChat, there is an improper access control vulnerability. Users can share, use, and create prompts without being granted permission by the admin. This can break application logic and permissions, allowing unauthorized actions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10363" + }, + { + "type": "WEB", + "url": "https://github.com/danny-avila/librechat/commit/42a4d02c62e2a6cf677d1cb6cfcb36d136aaa599" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/41a1137d-e725-4fec-b04c-58555cb16b6b" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-mj67-2mvx-f778/GHSA-mj67-2mvx-f778.json b/advisories/unreviewed/2025/03/GHSA-mj67-2mvx-f778/GHSA-mj67-2mvx-f778.json new file mode 100644 index 00000000000..e2e77154726 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-mj67-2mvx-f778/GHSA-mj67-2mvx-f778.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mj67-2mvx-f778", + "modified": "2025-03-20T12:32:40Z", + "published": "2025-03-20T12:32:40Z", + "aliases": [ + "CVE-2024-10718" + ], + "details": "In phpipam/phpipam version 1.5.1, the Secure attribute for sensitive cookies in HTTPS sessions is not set. This could cause the user agent to send those cookies in plaintext over an HTTP session, potentially exposing sensitive information. The issue is fixed in version 1.7.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10718" + }, + { + "type": "WEB", + "url": "https://github.com/phpipam/phpipam/commit/ddf70ef6801442eb8b0be5eea829e470e653c70e" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/725bce8f-328f-4fbc-acf5-46ea920cd3c1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-614" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-mjvp-pg3h-wh59/GHSA-mjvp-pg3h-wh59.json b/advisories/unreviewed/2025/03/GHSA-mjvp-pg3h-wh59/GHSA-mjvp-pg3h-wh59.json new file mode 100644 index 00000000000..0bf2d01264a --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-mjvp-pg3h-wh59/GHSA-mjvp-pg3h-wh59.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mjvp-pg3h-wh59", + "modified": "2025-03-20T12:32:44Z", + "published": "2025-03-20T12:32:44Z", + "aliases": [ + "CVE-2024-13060" + ], + "details": "A vulnerability in AnythingLLM Docker version 1.3.1 allows users with 'Default' permission to access other users' profile pictures by changing the 'id' parameter in the user cookie. This issue is present in versions prior to 1.3.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13060" + }, + { + "type": "WEB", + "url": "https://github.com/mintplex-labs/anything-llm/commit/696af19c45473172ad4d3ca749281800a4d1a45a" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/98a49c90-e095-441f-900c-59d463dc8e8f" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-285" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-mq4w-5hp5-6g52/GHSA-mq4w-5hp5-6g52.json b/advisories/unreviewed/2025/03/GHSA-mq4w-5hp5-6g52/GHSA-mq4w-5hp5-6g52.json new file mode 100644 index 00000000000..6e4249faed3 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-mq4w-5hp5-6g52/GHSA-mq4w-5hp5-6g52.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mq4w-5hp5-6g52", + "modified": "2025-03-20T12:32:41Z", + "published": "2025-03-20T12:32:41Z", + "aliases": [ + "CVE-2024-11170" + ], + "details": "A vulnerability in danny-avila/librechat version git 81f2936 allows for path traversal due to improper sanitization of file paths by the multer middleware. This can lead to arbitrary file write and potentially remote code execution. The issue is fixed in version 0.7.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11170" + }, + { + "type": "WEB", + "url": "https://github.com/danny-avila/librechat/commit/629be5c0ca2b332178524b4e3f6fac715aea8cc4" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/b64156c2-5380-4d4d-af30-b2938dcdd46e" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-29" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-mq78-p977-pwgv/GHSA-mq78-p977-pwgv.json b/advisories/unreviewed/2025/03/GHSA-mq78-p977-pwgv/GHSA-mq78-p977-pwgv.json new file mode 100644 index 00000000000..61227005fb1 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-mq78-p977-pwgv/GHSA-mq78-p977-pwgv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mq78-p977-pwgv", + "modified": "2025-03-20T12:32:51Z", + "published": "2025-03-20T12:32:51Z", + "aliases": [ + "CVE-2024-9439" + ], + "details": "SuperAGI is vulnerable to remote code execution in the latest version. The `agent template update` API allows attackers to control certain parameters, which are then fed to the eval function without any sanitization or checks in place. This vulnerability can lead to full system compromise.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9439" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/d710884f-b5ab-4b31-a2e6-e4b38488def1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-mq8r-j55w-fv46/GHSA-mq8r-j55w-fv46.json b/advisories/unreviewed/2025/03/GHSA-mq8r-j55w-fv46/GHSA-mq8r-j55w-fv46.json new file mode 100644 index 00000000000..265eb739b50 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-mq8r-j55w-fv46/GHSA-mq8r-j55w-fv46.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mq8r-j55w-fv46", + "modified": "2025-03-20T12:32:40Z", + "published": "2025-03-20T12:32:40Z", + "aliases": [ + "CVE-2024-10762" + ], + "details": "In lunary-ai/lunary before version 1.5.9, the /v1/evaluators/ endpoint allows users to delete evaluators of a project by sending a DELETE request. However, the route lacks proper access control, such as middleware to ensure that only users with appropriate roles can delete evaluator data. This vulnerability allows low-privilege users to delete evaluators data, causing permanent data loss and potentially hindering operations.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10762" + }, + { + "type": "WEB", + "url": "https://github.com/lunary-ai/lunary/commit/91587496673da24cb7ddedfbbd6e602592b20ef6" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/23ab508e-d956-4861-b28f-0569d3b404a6" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-mqp7-6vh9-99r6/GHSA-mqp7-6vh9-99r6.json b/advisories/unreviewed/2025/03/GHSA-mqp7-6vh9-99r6/GHSA-mqp7-6vh9-99r6.json new file mode 100644 index 00000000000..5b45db0963d --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-mqp7-6vh9-99r6/GHSA-mqp7-6vh9-99r6.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mqp7-6vh9-99r6", + "modified": "2025-03-20T12:32:48Z", + "published": "2025-03-20T12:32:48Z", + "aliases": [ + "CVE-2024-8248" + ], + "details": "A vulnerability in the normalizePath function in mintplex-labs/anything-llm version git 296f041 allows for path traversal, leading to arbitrary file read and write in the storage directory. This can result in privilege escalation from manager to admin. The issue is fixed in version 1.2.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8248" + }, + { + "type": "WEB", + "url": "https://github.com/mintplex-labs/anything-llm/commit/47a5c7126c20e2277ee56e2c7ee11990886a40a7" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/7d6c3b7a-1116-450d-b539-9c911a97537e" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-29" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-mrhh-3ggq-23p2/GHSA-mrhh-3ggq-23p2.json b/advisories/unreviewed/2025/03/GHSA-mrhh-3ggq-23p2/GHSA-mrhh-3ggq-23p2.json new file mode 100644 index 00000000000..e8809a2bc3c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-mrhh-3ggq-23p2/GHSA-mrhh-3ggq-23p2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mrhh-3ggq-23p2", + "modified": "2025-03-20T12:32:38Z", + "published": "2025-03-20T12:32:38Z", + "aliases": [ + "CVE-2024-10190" + ], + "details": "Horovod versions up to and including v0.28.1 are vulnerable to unauthenticated remote code execution. The vulnerability is due to improper handling of base64-encoded data in the `ElasticRendezvousHandler`, a subclass of `KVStoreHandler`. Specifically, the `_put_value` method in `ElasticRendezvousHandler` calls `codec.loads_base64(value)`, which eventually invokes `cloudpickle.loads(decoded)`. This allows an attacker to send a malicious pickle object via a PUT request, leading to arbitrary code execution on the server.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10190" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/3e398d1f-70c2-4e05-ae22-f5d66b19a754" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-mrvr-7493-pfq3/GHSA-mrvr-7493-pfq3.json b/advisories/unreviewed/2025/03/GHSA-mrvr-7493-pfq3/GHSA-mrvr-7493-pfq3.json new file mode 100644 index 00000000000..5af67eb18e8 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-mrvr-7493-pfq3/GHSA-mrvr-7493-pfq3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mrvr-7493-pfq3", + "modified": "2025-03-20T12:32:45Z", + "published": "2025-03-20T12:32:45Z", + "aliases": [ + "CVE-2024-6851" + ], + "details": "In version 3.22.0 of aimhubio/aim, the LocalFileManager._cleanup function in the aim tracking server accepts a user-specified glob-pattern for deleting files. The function does not verify that the matched files are within the directory managed by LocalFileManager, allowing a maliciously crafted glob-pattern to lead to arbitrary file deletion.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6851" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/839703fb-23b7-4dc4-ae81-44cd4740d3f3" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-mvp8-9qgw-vf58/GHSA-mvp8-9qgw-vf58.json b/advisories/unreviewed/2025/03/GHSA-mvp8-9qgw-vf58/GHSA-mvp8-9qgw-vf58.json new file mode 100644 index 00000000000..1ac9dd26bdd --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-mvp8-9qgw-vf58/GHSA-mvp8-9qgw-vf58.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mvp8-9qgw-vf58", + "modified": "2025-03-20T12:32:42Z", + "published": "2025-03-20T12:32:42Z", + "aliases": [ + "CVE-2024-12044" + ], + "details": "A remote code execution vulnerability exists in open-mmlab/mmdetection version v3.3.0. The vulnerability is due to the use of the `pickle.loads()` function in the `all_reduce_dict()` distributed training API without proper sanitization. This allows an attacker to execute arbitrary code by broadcasting a malicious payload to the distributed training network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12044" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/f7e4fc32-e167-49fb-9fc7-f092b9c27e8a" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-p2f3-rm9r-rxgj/GHSA-p2f3-rm9r-rxgj.json b/advisories/unreviewed/2025/03/GHSA-p2f3-rm9r-rxgj/GHSA-p2f3-rm9r-rxgj.json new file mode 100644 index 00000000000..85fe17f41c1 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-p2f3-rm9r-rxgj/GHSA-p2f3-rm9r-rxgj.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p2f3-rm9r-rxgj", + "modified": "2025-03-20T12:32:48Z", + "published": "2025-03-20T12:32:48Z", + "aliases": [ + "CVE-2024-8765" + ], + "details": "In lunary-ai/lunary, the privilege check mechanism is flawed in version git afc5df4. The system incorrectly identifies certain endpoints as public if the path contains '/auth/' anywhere within it. This allows unauthenticated attackers to access sensitive endpoints by including '/auth/' in the path. As a result, attackers can obtain and modify sensitive data and utilize other organizations' resources without proper authentication.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8765" + }, + { + "type": "WEB", + "url": "https://github.com/lunary-ai/lunary/commit/7ff89b0304d191534b924cf063f3648206d497fa" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/4908cfcf-607a-412a-9635-966cbb08bb49" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-41" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-p2vc-m5fv-9w9m/GHSA-p2vc-m5fv-9w9m.json b/advisories/unreviewed/2025/03/GHSA-p2vc-m5fv-9w9m/GHSA-p2vc-m5fv-9w9m.json new file mode 100644 index 00000000000..c6bc14be3fb --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-p2vc-m5fv-9w9m/GHSA-p2vc-m5fv-9w9m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p2vc-m5fv-9w9m", + "modified": "2025-03-20T12:32:46Z", + "published": "2025-03-20T12:32:46Z", + "aliases": [ + "CVE-2024-7768" + ], + "details": "A vulnerability in the `/3/ImportFiles` endpoint of h2oai/h2o-3 version 3.46.1 allows an attacker to cause a denial of service. The endpoint takes a single GET parameter, `path`, which can be recursively set to reference itself. This leads the server to repeatedly call its own endpoint, eventually filling up the request queue and leaving the server unable to handle other requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7768" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/3fe640df-bef4-4072-8890-0d12bc2818f6" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-p2wh-w96x-w232/GHSA-p2wh-w96x-w232.json b/advisories/unreviewed/2025/03/GHSA-p2wh-w96x-w232/GHSA-p2wh-w96x-w232.json new file mode 100644 index 00000000000..2a55fc6478a --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-p2wh-w96x-w232/GHSA-p2wh-w96x-w232.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p2wh-w96x-w232", + "modified": "2025-03-20T12:32:52Z", + "published": "2025-03-20T12:32:52Z", + "aliases": [ + "CVE-2025-0312" + ], + "details": "A vulnerability in ollama/ollama versions <=0.3.14 allows a malicious user to create a customized GGUF model file that, when uploaded and created on the Ollama server, can cause a crash due to an unchecked null pointer dereference. This can lead to a Denial of Service (DoS) attack via remote network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0312" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/522c87b6-a7ac-41b2-84f3-62fd58921f21" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-p5vx-9hj8-cf4h/GHSA-p5vx-9hj8-cf4h.json b/advisories/unreviewed/2025/03/GHSA-p5vx-9hj8-cf4h/GHSA-p5vx-9hj8-cf4h.json new file mode 100644 index 00000000000..c5ee7673120 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-p5vx-9hj8-cf4h/GHSA-p5vx-9hj8-cf4h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p5vx-9hj8-cf4h", + "modified": "2025-03-20T12:32:46Z", + "published": "2025-03-20T12:32:46Z", + "aliases": [ + "CVE-2024-7035" + ], + "details": "In version v0.3.8 of open-webui/open-webui, sensitive actions such as deleting and resetting are performed using the GET method. This vulnerability allows an attacker to perform Cross-Site Request Forgery (CSRF) attacks, where an unaware user can unintentionally perform sensitive actions by simply visiting a malicious site or through top-level navigation. The affected endpoints include /rag/api/v1/reset, /rag/api/v1/reset/db, /api/v1/memories/reset, and /rag/api/v1/reset/uploads. This impacts both the availability and integrity of the application.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:H/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7035" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/2ac81740-410b-467a-9244-75d82a6f9e11" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-p6h7-hfj2-vmcf/GHSA-p6h7-hfj2-vmcf.json b/advisories/unreviewed/2025/03/GHSA-p6h7-hfj2-vmcf/GHSA-p6h7-hfj2-vmcf.json new file mode 100644 index 00000000000..87aa7059da1 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-p6h7-hfj2-vmcf/GHSA-p6h7-hfj2-vmcf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p6h7-hfj2-vmcf", + "modified": "2025-03-20T12:32:48Z", + "published": "2025-03-20T12:32:48Z", + "aliases": [ + "CVE-2024-8501" + ], + "details": "An arbitrary file download vulnerability exists in the rpc_agent_client component of modelscope/agentscope version v0.0.4. This vulnerability allows any user to download any file from the rpc_agent's host by exploiting the download_file method. This can lead to unauthorized access to sensitive information, including configuration files, credentials, and potentially system files, which may facilitate further exploitation such as privilege escalation or lateral movement within the network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8501" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/83e433c0-ed2d-4b10-8358-d3c1eee0a47c" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-36" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-p6x3-v6g3-7557/GHSA-p6x3-v6g3-7557.json b/advisories/unreviewed/2025/03/GHSA-p6x3-v6g3-7557/GHSA-p6x3-v6g3-7557.json new file mode 100644 index 00000000000..600ac78143f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-p6x3-v6g3-7557/GHSA-p6x3-v6g3-7557.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p6x3-v6g3-7557", + "modified": "2025-03-20T12:32:44Z", + "published": "2025-03-20T12:32:44Z", + "aliases": [ + "CVE-2024-6483" + ], + "details": "A vulnerability in the `runs/delete-batch` endpoint of aimhubio/aim version 3.19.3 allows for arbitrary file or directory deletion through path traversal. The endpoint does not mitigate path traversal when handling user-specified run-names, which are used to specify log/metadata files for deletion. This can be exploited to delete arbitrary files or directories, potentially causing denial of service or data loss.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6483" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/dc45d480-e579-4af4-8603-c52ecfd5e363" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-23" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-p868-p9pj-fvmr/GHSA-p868-p9pj-fvmr.json b/advisories/unreviewed/2025/03/GHSA-p868-p9pj-fvmr/GHSA-p868-p9pj-fvmr.json new file mode 100644 index 00000000000..cdb57ab0cde --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-p868-p9pj-fvmr/GHSA-p868-p9pj-fvmr.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p868-p9pj-fvmr", + "modified": "2025-03-20T12:32:45Z", + "published": "2025-03-20T12:32:45Z", + "aliases": [ + "CVE-2024-6842" + ], + "details": "In version 1.5.5 of mintplex-labs/anything-llm, the `/setup-complete` API endpoint allows unauthorized users to access sensitive system settings. The data returned by the `currentSettings` function includes sensitive information such as API keys for search engines, which can be exploited by attackers to steal these keys and cause loss of user assets.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6842" + }, + { + "type": "WEB", + "url": "https://github.com/mintplex-labs/anything-llm/commit/8b1ceb30c159cf3a10efa16275bc6849d84e4ea8" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/cd911fc7-ac6b-4974-acd0-9cc926fa8d9e" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-p926-8677-385w/GHSA-p926-8677-385w.json b/advisories/unreviewed/2025/03/GHSA-p926-8677-385w/GHSA-p926-8677-385w.json new file mode 100644 index 00000000000..aa9cd91fd7a --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-p926-8677-385w/GHSA-p926-8677-385w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p926-8677-385w", + "modified": "2025-03-20T12:32:43Z", + "published": "2025-03-20T12:32:43Z", + "aliases": [ + "CVE-2024-12775" + ], + "details": "langgenius/dify version 0.10.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the test functionality for the Create Custom Tool option via the REST API `POST /console/api/workspaces/current/tool-provider/api/test/pre`. Attackers can set the `url` in the `servers` dictionary in OpenAI's schema with arbitrary URL targets, allowing them to abuse the victim server's credentials to access unauthorized web resources.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12775" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/e90e929a-9bc9-46ad-a5e5-1f6f124d0f12" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-pgfv-gvc5-prfg/GHSA-pgfv-gvc5-prfg.json b/advisories/unreviewed/2025/03/GHSA-pgfv-gvc5-prfg/GHSA-pgfv-gvc5-prfg.json new file mode 100644 index 00000000000..4a8774eafd7 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-pgfv-gvc5-prfg/GHSA-pgfv-gvc5-prfg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pgfv-gvc5-prfg", + "modified": "2025-03-20T12:32:39Z", + "published": "2025-03-20T12:32:39Z", + "aliases": [ + "CVE-2024-10648" + ], + "details": "A path traversal vulnerability exists in the Gradio Audio component of gradio-app/gradio, as of version git 98cbcae. This vulnerability allows an attacker to control the format of the audio file, leading to arbitrary file content deletion. By manipulating the output format, an attacker can reset any file to an empty file, causing a denial of service (DOS) on the server.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10648" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/667d664d-8189-458c-8ed7-483fe8f33c76" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-29" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-pgr7-mhp5-fgjp/GHSA-pgr7-mhp5-fgjp.json b/advisories/unreviewed/2025/03/GHSA-pgr7-mhp5-fgjp/GHSA-pgr7-mhp5-fgjp.json new file mode 100644 index 00000000000..c879d90c80c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-pgr7-mhp5-fgjp/GHSA-pgr7-mhp5-fgjp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pgr7-mhp5-fgjp", + "modified": "2025-03-20T12:32:50Z", + "published": "2025-03-20T12:32:50Z", + "aliases": [ + "CVE-2024-9052" + ], + "details": "vllm-project vllm version 0.6.0 contains a vulnerability in the distributed training API. The function vllm.distributed.GroupCoordinator.recv_object() deserializes received object bytes using pickle.loads() without sanitization, leading to a remote code execution vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9052" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/ea75728f-4efe-4a3d-9f53-33f2c908e9f8" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-ph84-8v89-25q8/GHSA-ph84-8v89-25q8.json b/advisories/unreviewed/2025/03/GHSA-ph84-8v89-25q8/GHSA-ph84-8v89-25q8.json new file mode 100644 index 00000000000..7411c46b570 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-ph84-8v89-25q8/GHSA-ph84-8v89-25q8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ph84-8v89-25q8", + "modified": "2025-03-20T12:32:39Z", + "published": "2025-03-20T12:32:39Z", + "aliases": [ + "CVE-2024-10650" + ], + "details": "An unauthenticated Denial of Service (DoS) vulnerability was identified in ChuanhuChatGPT version 20240918, which could be exploited by sending large data payloads using a multipart boundary. Although a patch was applied for CVE-2024-7807, the issue can still be exploited by sending data in groups with 10 characters in a line, with multiple lines. This can cause the system to continuously process these characters, resulting in prolonged unavailability of the service. The exploitation now requires low privilege if authentication is enabled due to a version upgrade in Gradio.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10650" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/f820371d-a878-44bf-b1fd-2d837dd58eb4" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-pqwr-phvv-v49f/GHSA-pqwr-phvv-v49f.json b/advisories/unreviewed/2025/03/GHSA-pqwr-phvv-v49f/GHSA-pqwr-phvv-v49f.json new file mode 100644 index 00000000000..0665874ef10 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-pqwr-phvv-v49f/GHSA-pqwr-phvv-v49f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pqwr-phvv-v49f", + "modified": "2025-03-20T12:32:45Z", + "published": "2025-03-20T12:32:45Z", + "aliases": [ + "CVE-2024-7039" + ], + "details": "In open-webui/open-webui version v0.3.8, there is an improper privilege management vulnerability. The application allows an attacker, acting as an admin, to delete other administrators via the API endpoint `http://0.0.0.0:8080/api/v1/users/{uuid_administrator}`. This action is restricted by the user interface but can be performed through direct API calls.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7039" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/27fc8a5a-546e-4cf2-8edb-df42e36518fc" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-prpg-p95c-32fv/GHSA-prpg-p95c-32fv.json b/advisories/unreviewed/2025/03/GHSA-prpg-p95c-32fv/GHSA-prpg-p95c-32fv.json new file mode 100644 index 00000000000..ed51baa89e5 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-prpg-p95c-32fv/GHSA-prpg-p95c-32fv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-prpg-p95c-32fv", + "modified": "2025-03-20T12:32:42Z", + "published": "2025-03-20T12:32:42Z", + "aliases": [ + "CVE-2024-12217" + ], + "details": "A vulnerability in the gradio-app/gradio repository, version git 67e4044, allows for path traversal on Windows OS. The implementation of the blocked_path functionality, which is intended to disallow users from reading certain files, is flawed. Specifically, while the application correctly blocks access to paths like 'C:/tmp/secret.txt', it fails to block access when using NTFS Alternate Data Streams (ADS) syntax, such as 'C:/tmp/secret.txt::$DATA'. This flaw can lead to unauthorized reading of blocked file paths.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12217" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/0439bf3d-cb38-43a5-8314-0fadf85cc5a0" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-prx2-6cc4-7qq5/GHSA-prx2-6cc4-7qq5.json b/advisories/unreviewed/2025/03/GHSA-prx2-6cc4-7qq5/GHSA-prx2-6cc4-7qq5.json new file mode 100644 index 00000000000..8fcc0cc91b7 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-prx2-6cc4-7qq5/GHSA-prx2-6cc4-7qq5.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-prx2-6cc4-7qq5", + "modified": "2025-03-20T12:32:40Z", + "published": "2025-03-20T12:32:40Z", + "aliases": [ + "CVE-2024-10723" + ], + "details": "A stored cross-site scripting (XSS) vulnerability was discovered in phpipam/phpipam version 1.5.2. This vulnerability allows an attacker to inject malicious scripts into the destination address field of the NAT tool, which can be executed when a user interacts with the field. The impact of this vulnerability includes the potential theft of user cookies, unauthorized access to user accounts, and redirection to malicious websites. The issue has been fixed in version 1.7.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10723" + }, + { + "type": "WEB", + "url": "https://github.com/phpipam/phpipam/commit/c1697bb6c4e4a6403d69c0868e1eb1040f98b731" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/9af99057-e4f6-4d07-b3bb-3213b977801d" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-q36w-fgp3-q2gw/GHSA-q36w-fgp3-q2gw.json b/advisories/unreviewed/2025/03/GHSA-q36w-fgp3-q2gw/GHSA-q36w-fgp3-q2gw.json new file mode 100644 index 00000000000..31b43a0e93f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-q36w-fgp3-q2gw/GHSA-q36w-fgp3-q2gw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q36w-fgp3-q2gw", + "modified": "2025-03-20T12:32:42Z", + "published": "2025-03-20T12:32:42Z", + "aliases": [ + "CVE-2024-12065" + ], + "details": "A local file inclusion vulnerability exists in haotian-liu/llava at commit c121f04. This vulnerability allows an attacker to access any file on the system by sending multiple crafted requests to the server. The issue is due to improper input validation in the gradio web UI component.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12065" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/0594503c-038f-401c-9127-08be32bfd682" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-q3gw-8236-5jw4/GHSA-q3gw-8236-5jw4.json b/advisories/unreviewed/2025/03/GHSA-q3gw-8236-5jw4/GHSA-q3gw-8236-5jw4.json new file mode 100644 index 00000000000..4aafcf80bfc --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-q3gw-8236-5jw4/GHSA-q3gw-8236-5jw4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q3gw-8236-5jw4", + "modified": "2025-03-20T12:32:45Z", + "published": "2025-03-20T12:32:45Z", + "aliases": [ + "CVE-2024-6838" + ], + "details": "In mlflow/mlflow version v2.13.2, a vulnerability exists that allows the creation or renaming of an experiment with a large number of integers in its name due to the lack of a limit on the experiment name. This can cause the MLflow UI panel to become unresponsive, leading to a potential denial of service. Additionally, there is no character limit in the `artifact_location` parameter while creating the experiment.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6838" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/8ad52cb2-2cda-4eb0-aec9-586060ee43e0" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-q5v7-7r3x-m7hg/GHSA-q5v7-7r3x-m7hg.json b/advisories/unreviewed/2025/03/GHSA-q5v7-7r3x-m7hg/GHSA-q5v7-7r3x-m7hg.json new file mode 100644 index 00000000000..b61edc125bb --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-q5v7-7r3x-m7hg/GHSA-q5v7-7r3x-m7hg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q5v7-7r3x-m7hg", + "modified": "2025-03-20T12:32:42Z", + "published": "2025-03-20T12:32:42Z", + "aliases": [ + "CVE-2024-12063" + ], + "details": "A Denial of Service (DoS) vulnerability exists in the file upload feature of imartinez/privategpt version v0.6.2. The vulnerability is due to improper handling of form-data with a large filename in the file upload request. An attacker can exploit this by sending a payload with an excessively large filename, causing the server to become overwhelmed and unavailable to legitimate users.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12063" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/7db0091f-cb53-4cde-aad7-7ce491dfd8d9" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-q67c-vgg7-pvrq/GHSA-q67c-vgg7-pvrq.json b/advisories/unreviewed/2025/03/GHSA-q67c-vgg7-pvrq/GHSA-q67c-vgg7-pvrq.json new file mode 100644 index 00000000000..e927997d6f5 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-q67c-vgg7-pvrq/GHSA-q67c-vgg7-pvrq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q67c-vgg7-pvrq", + "modified": "2025-03-20T12:32:42Z", + "published": "2025-03-20T12:32:42Z", + "aliases": [ + "CVE-2024-11441" + ], + "details": "A stored cross-site scripting (XSS) vulnerability exists in Serge version 0.9.0. The vulnerability is due to improper neutralization of input during web page generation in the chat prompt. An attacker can exploit this vulnerability by sending a crafted message containing malicious HTML/JavaScript code, which will be stored and executed whenever the chat is accessed, leading to unintended content being shown to the user and potential phishing attacks.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11441" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/ae76d1ea-21a4-456d-bef2-331aef3ea376" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-q6gg-j289-2hm4/GHSA-q6gg-j289-2hm4.json b/advisories/unreviewed/2025/03/GHSA-q6gg-j289-2hm4/GHSA-q6gg-j289-2hm4.json new file mode 100644 index 00000000000..a9c278a15f1 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-q6gg-j289-2hm4/GHSA-q6gg-j289-2hm4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q6gg-j289-2hm4", + "modified": "2025-03-20T12:32:47Z", + "published": "2025-03-20T12:32:47Z", + "aliases": [ + "CVE-2024-7957" + ], + "details": "An arbitrary file overwrite vulnerability exists in the ZulipConnector of danswer-ai/danswer, affecting the latest version. The vulnerability arises from the load_credentials method, where user-controlled input for realm_name and zuliprc_content is used to construct file paths and write file contents. This allows attackers to overwrite or create arbitrary files if a zuliprc- directory already exists in the temporary directory.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7957" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/21e9b909-036c-4544-ad35-6a5117836275" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-29" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-q73m-3cg7-m23w/GHSA-q73m-3cg7-m23w.json b/advisories/unreviewed/2025/03/GHSA-q73m-3cg7-m23w/GHSA-q73m-3cg7-m23w.json new file mode 100644 index 00000000000..42a7597a288 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-q73m-3cg7-m23w/GHSA-q73m-3cg7-m23w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q73m-3cg7-m23w", + "modified": "2025-03-20T12:32:43Z", + "published": "2025-03-20T12:32:43Z", + "aliases": [ + "CVE-2024-12375" + ], + "details": "A local file inclusion vulnerability was identified in automatic1111/stable-diffusion-webui, affecting version git 82a973c. This vulnerability allows an attacker to read arbitrary files on the system by sending a specially crafted request to the application.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12375" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/21952043-395f-4cd3-9374-b73ab9612f27" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-36" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-q88j-ff64-2m3q/GHSA-q88j-ff64-2m3q.json b/advisories/unreviewed/2025/03/GHSA-q88j-ff64-2m3q/GHSA-q88j-ff64-2m3q.json new file mode 100644 index 00000000000..4cb34e7f8fd --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-q88j-ff64-2m3q/GHSA-q88j-ff64-2m3q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q88j-ff64-2m3q", + "modified": "2025-03-20T12:32:51Z", + "published": "2025-03-20T12:32:51Z", + "aliases": [ + "CVE-2024-9362" + ], + "details": "An unauthenticated directory traversal vulnerability exists in Polyaxon, affecting the latest version. This vulnerability allows an attacker to retrieve directory information and file contents from the server without proper authorization, leading to sensitive information disclosure. The issue enables access to system directories such as `/etc`, potentially resulting in significant security risks.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9362" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/d8dcb40f-ce76-4524-8d06-e0f12a07809d" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-q8pp-mmm3-9j9w/GHSA-q8pp-mmm3-9j9w.json b/advisories/unreviewed/2025/03/GHSA-q8pp-mmm3-9j9w/GHSA-q8pp-mmm3-9j9w.json new file mode 100644 index 00000000000..7f10891bdaa --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-q8pp-mmm3-9j9w/GHSA-q8pp-mmm3-9j9w.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q8pp-mmm3-9j9w", + "modified": "2025-03-20T12:32:46Z", + "published": "2025-03-20T12:32:46Z", + "aliases": [ + "CVE-2024-7771" + ], + "details": "A vulnerability in the Dockerized version of mintplex-labs/anything-llm (latest, digest 1d9452da2b92) allows for a denial of service. Uploading an audio file with a very low sample rate causes the functionality responsible for transcribing it to crash the entire site instance. The issue arises from the localWhisper implementation, where resampling the audio file from 1 Hz to 16000 Hz quickly exceeds available memory, leading to the Docker instance being killed by the instance manager.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7771" + }, + { + "type": "WEB", + "url": "https://github.com/mintplex-labs/anything-llm/commit/dd017c6cbbf42abdef7861a66558c53b66424d07" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/a31a9834-e9c4-4b50-a1ec-ecb69f2a6142" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-qccg-9m4q-xfm6/GHSA-qccg-9m4q-xfm6.json b/advisories/unreviewed/2025/03/GHSA-qccg-9m4q-xfm6/GHSA-qccg-9m4q-xfm6.json new file mode 100644 index 00000000000..a57afd69f8d --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-qccg-9m4q-xfm6/GHSA-qccg-9m4q-xfm6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qccg-9m4q-xfm6", + "modified": "2025-03-20T12:32:40Z", + "published": "2025-03-20T12:32:40Z", + "aliases": [ + "CVE-2024-10835" + ], + "details": "In eosphoros-ai/db-gpt version v0.6.0, the web API `POST /api/v1/editor/sql/run` allows execution of arbitrary SQL queries without any access control. This vulnerability can be exploited by attackers to perform Arbitrary File Write using DuckDB SQL, enabling them to write arbitrary files to the victim's file system. This can potentially lead to Remote Code Execution (RCE).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10835" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/e32fda74-ca83-431c-8de8-08274ba686c9" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-qg86-f892-m4hj/GHSA-qg86-f892-m4hj.json b/advisories/unreviewed/2025/03/GHSA-qg86-f892-m4hj/GHSA-qg86-f892-m4hj.json new file mode 100644 index 00000000000..422a623a28e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-qg86-f892-m4hj/GHSA-qg86-f892-m4hj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qg86-f892-m4hj", + "modified": "2025-03-20T12:32:41Z", + "published": "2025-03-20T12:32:41Z", + "aliases": [ + "CVE-2024-10907" + ], + "details": "In lm-sys/fastchat Release v0.2.36, the server fails to handle excessive characters appended to the end of multipart boundaries. This flaw can be exploited by sending malformed multipart requests with arbitrary characters at the end of the boundary. Each extra character is processed in an infinite loop, leading to excessive resource consumption and a complete denial of service (DoS) for all users. The vulnerability is unauthenticated, meaning no user login or interaction is required for an attacker to exploit this issue.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10907" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/bf3ca81d-3508-4455-95d9-0b653e46d6e4" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-qgm6-wj98-3qh4/GHSA-qgm6-wj98-3qh4.json b/advisories/unreviewed/2025/03/GHSA-qgm6-wj98-3qh4/GHSA-qgm6-wj98-3qh4.json new file mode 100644 index 00000000000..5b273b5cacb --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-qgm6-wj98-3qh4/GHSA-qgm6-wj98-3qh4.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qgm6-wj98-3qh4", + "modified": "2025-03-20T12:32:40Z", + "published": "2025-03-20T12:32:40Z", + "aliases": [ + "CVE-2024-10720" + ], + "details": "A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2. The vulnerability occurs in the 'Device Management' section under 'Administration' where an attacker can inject malicious scripts into the 'Name' and 'Description' fields when adding a new device type. This can lead to data theft, account compromise, distribution of malware, website defacement, and phishing attacks. The issue is fixed in version 1.7.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10720" + }, + { + "type": "WEB", + "url": "https://github.com/phpipam/phpipam/commit/c1697bb6c4e4a6403d69c0868e1eb1040f98b731" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/75e06e05-7f69-4938-a83c-1dcc98922188" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-qhfv-rxrj-6w5f/GHSA-qhfv-rxrj-6w5f.json b/advisories/unreviewed/2025/03/GHSA-qhfv-rxrj-6w5f/GHSA-qhfv-rxrj-6w5f.json new file mode 100644 index 00000000000..0f49b1758e7 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-qhfv-rxrj-6w5f/GHSA-qhfv-rxrj-6w5f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qhfv-rxrj-6w5f", + "modified": "2025-03-20T12:32:41Z", + "published": "2025-03-20T12:32:41Z", + "aliases": [ + "CVE-2024-11037" + ], + "details": "A path traversal vulnerability exists in binary-husky/gpt_academic at commit 679352d, which allows an attacker to bypass the blocked_paths protection and read the config.py file containing sensitive information such as the OpenAI API key. This vulnerability is exploitable on Windows operating systems by accessing a specific URL that includes the absolute path of the project.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11037" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/91243fc1-f287-4f4b-8aa6-dfe3efff23e5" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-qjq5-7g6p-p3vg/GHSA-qjq5-7g6p-p3vg.json b/advisories/unreviewed/2025/03/GHSA-qjq5-7g6p-p3vg/GHSA-qjq5-7g6p-p3vg.json new file mode 100644 index 00000000000..ddad1e85225 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-qjq5-7g6p-p3vg/GHSA-qjq5-7g6p-p3vg.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qjq5-7g6p-p3vg", + "modified": "2025-03-20T12:32:50Z", + "published": "2025-03-20T12:32:50Z", + "aliases": [ + "CVE-2024-9099" + ], + "details": "In lunary-ai/lunary version v1.4.29, the GET /projects API endpoint exposes both public and private API keys for all projects to users with minimal permissions, such as Viewers or Prompt Editors. This vulnerability allows unauthorized users to retrieve sensitive credentials, which can be used to perform actions on behalf of the project, access private data, and delete resources. The private API keys are exposed in the developer tools when the endpoint is called from the frontend.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9099" + }, + { + "type": "WEB", + "url": "https://github.com/lunary-ai/lunary/commit/8ba1b8ba2c2c30b1cec30eb5777c1fda670cbbfc" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/ffb84fe8-3e60-4200-ac2d-1fd1e1c93e91" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1230" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-qv9p-39px-hfwc/GHSA-qv9p-39px-hfwc.json b/advisories/unreviewed/2025/03/GHSA-qv9p-39px-hfwc/GHSA-qv9p-39px-hfwc.json new file mode 100644 index 00000000000..835ef4ee668 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-qv9p-39px-hfwc/GHSA-qv9p-39px-hfwc.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qv9p-39px-hfwc", + "modified": "2025-03-20T12:32:45Z", + "published": "2025-03-20T12:32:44Z", + "aliases": [ + "CVE-2024-4023" + ], + "details": "A stored cross-site scripting (XSS) vulnerability exists in flatpressblog/flatpress version 1.3. When a user uploads a file with a `.xsig` extension and directly accesses this file, the server responds with a Content-type of application/octet-stream, leading to the file being processed as an HTML file. This allows an attacker to execute arbitrary JavaScript code, which can be used to steal user cookies, perform HTTP requests, and access content of the same origin.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4023" + }, + { + "type": "WEB", + "url": "https://github.com/flatpressblog/flatpress/commit/3c9cc69364a45fd3f92d4bd606344b5dd1205d6a" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/ed803c13-0858-4c22-93ba-bf2384ab1e9d" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-qvg9-vp87-h3hr/GHSA-qvg9-vp87-h3hr.json b/advisories/unreviewed/2025/03/GHSA-qvg9-vp87-h3hr/GHSA-qvg9-vp87-h3hr.json new file mode 100644 index 00000000000..5c30449a2d2 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-qvg9-vp87-h3hr/GHSA-qvg9-vp87-h3hr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qvg9-vp87-h3hr", + "modified": "2025-03-20T12:32:49Z", + "published": "2025-03-20T12:32:49Z", + "aliases": [ + "CVE-2024-8952" + ], + "details": "A Server-Side Request Forgery (SSRF) vulnerability exists in composiohq/composio version v0.4.2, specifically in the /api/actions/execute/WEBTOOL_SCRAPE_WEBSITE_CONTENT endpoint. This vulnerability allows an attacker to read files, access AWS metadata, and interact with local services on the system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8952" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/d1acdd38-10d7-45df-9df0-9fc71f0e1c2a" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-r229-5wgf-f28g/GHSA-r229-5wgf-f28g.json b/advisories/unreviewed/2025/03/GHSA-r229-5wgf-f28g/GHSA-r229-5wgf-f28g.json new file mode 100644 index 00000000000..a6f1ac0d6a7 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-r229-5wgf-f28g/GHSA-r229-5wgf-f28g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r229-5wgf-f28g", + "modified": "2025-03-20T12:32:48Z", + "published": "2025-03-20T12:32:47Z", + "aliases": [ + "CVE-2024-8238" + ], + "details": "In version 3.22.0 of aimhubio/aim, the AimQL query language uses an outdated version of the safer_getattr() function from RestrictedPython. This version does not protect against the str.format_map() method, allowing an attacker to leak server-side secrets or potentially gain unrestricted code execution. The vulnerability arises because str.format_map() can read arbitrary attributes of Python objects, enabling attackers to access sensitive variables such as os.environ. If an attacker can write files to a known location on the Aim server, they can use str.format_map() to load a malicious .dll/.so file into the Python interpreter, leading to unrestricted code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8238" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/4e140ef9-f6d1-4e68-a44c-3b9e856924d3" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-r3hj-whx4-hvvj/GHSA-r3hj-whx4-hvvj.json b/advisories/unreviewed/2025/03/GHSA-r3hj-whx4-hvvj/GHSA-r3hj-whx4-hvvj.json new file mode 100644 index 00000000000..840c2477079 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-r3hj-whx4-hvvj/GHSA-r3hj-whx4-hvvj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r3hj-whx4-hvvj", + "modified": "2025-03-20T12:32:52Z", + "published": "2025-03-20T12:32:52Z", + "aliases": [ + "CVE-2025-1451" + ], + "details": "A vulnerability in parisneo/lollms-webui v13 arises from the server's handling of multipart boundaries in file uploads. The server does not limit or validate the length of the boundary or the characters appended to it, allowing an attacker to craft requests with excessively long boundaries, leading to resource exhaustion and eventual denial of service (DoS). Despite an attempted patch in commit 483431bb, which blocked hyphen characters from being appended to the multipart boundary, the fix is insufficient. The server remains vulnerable if other characters (e.g., '4', 'a') are used instead of hyphens. This allows attackers to exploit the vulnerability using different characters, causing resource exhaustion and service unavailability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1451" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/63f5aea4-953b-4b38-9f10-3afe425be1d4" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-r49j-4jpw-x35c/GHSA-r49j-4jpw-x35c.json b/advisories/unreviewed/2025/03/GHSA-r49j-4jpw-x35c/GHSA-r49j-4jpw-x35c.json new file mode 100644 index 00000000000..6627740e6d0 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-r49j-4jpw-x35c/GHSA-r49j-4jpw-x35c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r49j-4jpw-x35c", + "modified": "2025-03-20T12:32:42Z", + "published": "2025-03-20T12:32:42Z", + "aliases": [ + "CVE-2024-12074" + ], + "details": "A Denial of Service (DoS) vulnerability was discovered in the file upload feature of automatic1111/stable-diffusion-webui version 1.10.0. The vulnerability is due to improper handling of form-data with a large filename in the file upload request. By sending a payload with an excessively large filename, the server becomes overwhelmed and unresponsive, leading to unavailability for legitimate users. This issue can be exploited without authentication, making it highly scalable and increasing the risk of exploitation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12074" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/6b44bfc2-31a7-4fe9-86fb-072c90a23642" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-r4hm-vcvh-rm39/GHSA-r4hm-vcvh-rm39.json b/advisories/unreviewed/2025/03/GHSA-r4hm-vcvh-rm39/GHSA-r4hm-vcvh-rm39.json new file mode 100644 index 00000000000..eb5b93e09bb --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-r4hm-vcvh-rm39/GHSA-r4hm-vcvh-rm39.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r4hm-vcvh-rm39", + "modified": "2025-03-20T12:32:42Z", + "published": "2025-03-20T12:32:42Z", + "aliases": [ + "CVE-2024-12070" + ], + "details": "A Denial of Service (DoS) vulnerability exists in the file upload feature of haotian-liu/llava, specifically in Release v1.2.0 (LLaVA-1.6). The vulnerability is due to improper handling of form-data with a large filename in the file upload request. By sending a payload with an excessively large filename, the server becomes overwhelmed and unresponsive, leading to unavailability for legitimate users. This issue can be exploited without authentication, making it highly scalable and increasing the risk of exploitation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12070" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/8adac028-21c5-41ba-b785-b03066c0b2a6" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-r9m5-fcw8-68f6/GHSA-r9m5-fcw8-68f6.json b/advisories/unreviewed/2025/03/GHSA-r9m5-fcw8-68f6/GHSA-r9m5-fcw8-68f6.json new file mode 100644 index 00000000000..3f8d0a6aa69 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-r9m5-fcw8-68f6/GHSA-r9m5-fcw8-68f6.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r9m5-fcw8-68f6", + "modified": "2025-03-20T12:32:50Z", + "published": "2025-03-20T12:32:50Z", + "aliases": [ + "CVE-2024-9096" + ], + "details": "In lunary-ai/lunary version 1.4.28, the /checklists/:id route allows low-privilege users to modify checklists by sending a PATCH request. The route lacks proper access control, such as middleware to ensure that only authorized users (e.g., project owners or admins) can modify checklist data. This vulnerability allows any user associated with the project, regardless of their role, to modify checklists, including changing the slug or data fields, which can lead to tampering with essential project workflows, altering business logic, and introducing errors that undermine integrity.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9096" + }, + { + "type": "WEB", + "url": "https://github.com/lunary-ai/lunary/commit/a8d7b2959e87c30fbafdb12af7ffa093385dcc60" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/653e7109-4c21-4e33-b636-7598d3202b9a" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-285" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-rc69-h6h5-3q4x/GHSA-rc69-h6h5-3q4x.json b/advisories/unreviewed/2025/03/GHSA-rc69-h6h5-3q4x/GHSA-rc69-h6h5-3q4x.json new file mode 100644 index 00000000000..3aabe6b20a3 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-rc69-h6h5-3q4x/GHSA-rc69-h6h5-3q4x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rc69-h6h5-3q4x", + "modified": "2025-03-20T12:32:38Z", + "published": "2025-03-20T12:32:38Z", + "aliases": [ + "CVE-2024-10051" + ], + "details": "Realchar version v0.0.4 is vulnerable to an unauthenticated denial of service (DoS) attack. The vulnerability exists in the file upload request handling, where appending characters, such as dashes (-), to the end of a multipart boundary in an HTTP request causes the server to continuously process each character. This leads to excessive resource consumption and renders the service unavailable. The issue is unauthenticated and does not require any user interaction, impacting all users of the service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10051" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/6db72368-e7bc-43ee-a4ae-6092f710c263" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-rm69-wvpv-r2w7/GHSA-rm69-wvpv-r2w7.json b/advisories/unreviewed/2025/03/GHSA-rm69-wvpv-r2w7/GHSA-rm69-wvpv-r2w7.json new file mode 100644 index 00000000000..6ef4d1489cd --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-rm69-wvpv-r2w7/GHSA-rm69-wvpv-r2w7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rm69-wvpv-r2w7", + "modified": "2025-03-20T12:32:43Z", + "published": "2025-03-20T12:32:42Z", + "aliases": [ + "CVE-2024-12215" + ], + "details": "In kedro-org/kedro version 0.19.8, the `pull_package()` API function allows users to download and extract micro packages from the Internet. However, the function `project_wheel_metadata()` within the code path can execute the `setup.py` file inside the tar file, leading to remote code execution (RCE) by running arbitrary commands on the victim's machine.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12215" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/fad27503-97a4-4933-91d4-96223b8c54d8" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-rqhc-x44r-f23j/GHSA-rqhc-x44r-f23j.json b/advisories/unreviewed/2025/03/GHSA-rqhc-x44r-f23j/GHSA-rqhc-x44r-f23j.json new file mode 100644 index 00000000000..3a4a68a81e8 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-rqhc-x44r-f23j/GHSA-rqhc-x44r-f23j.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rqhc-x44r-f23j", + "modified": "2025-03-20T12:32:51Z", + "published": "2025-03-20T12:32:51Z", + "aliases": [ + "CVE-2024-9699" + ], + "details": "A vulnerability in the file upload functionality of the FlatPress CMS admin panel (version latest) allows an attacker to upload a file with a JavaScript payload disguised as a filename. This can lead to a Cross-Site Scripting (XSS) attack if the uploaded file is accessed by other users. The issue is fixed in version 1.4.dev.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9699" + }, + { + "type": "WEB", + "url": "https://github.com/flatpressblog/flatpress/commit/f364391085334a7eae02aa2320edd6de7466ec85" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/a993a05f-be50-4983-a44a-3bbff1ec00db" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-rqrm-p43g-fpmq/GHSA-rqrm-p43g-fpmq.json b/advisories/unreviewed/2025/03/GHSA-rqrm-p43g-fpmq/GHSA-rqrm-p43g-fpmq.json new file mode 100644 index 00000000000..041966c1fef --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-rqrm-p43g-fpmq/GHSA-rqrm-p43g-fpmq.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rqrm-p43g-fpmq", + "modified": "2025-03-20T12:32:49Z", + "published": "2025-03-20T12:32:49Z", + "aliases": [ + "CVE-2024-8999" + ], + "details": "lunary-ai/lunary version v1.4.25 contains an improper access control vulnerability in the POST /api/v1/data-warehouse/bigquery endpoint. This vulnerability allows any user to export the entire database data by creating a stream to Google BigQuery without proper authentication or authorization. The issue is fixed in version 1.4.26.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8999" + }, + { + "type": "WEB", + "url": "https://github.com/lunary-ai/lunary/commit/aa0fd22952d1d84a717ae563eb1ab564d94a9e2b" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/d42b7a44-0dcb-4ef0-b15c-d0e558da65c6" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-rrfw-qqmx-gqwx/GHSA-rrfw-qqmx-gqwx.json b/advisories/unreviewed/2025/03/GHSA-rrfw-qqmx-gqwx/GHSA-rrfw-qqmx-gqwx.json new file mode 100644 index 00000000000..14312b60225 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-rrfw-qqmx-gqwx/GHSA-rrfw-qqmx-gqwx.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rrfw-qqmx-gqwx", + "modified": "2025-03-20T12:32:48Z", + "published": "2025-03-20T12:32:47Z", + "aliases": [ + "CVE-2024-8156" + ], + "details": "A command injection vulnerability exists in the workflow-checker.yml workflow of significant-gravitas/autogpt. The untrusted user input `github.head.ref` is used insecurely, allowing an attacker to inject arbitrary commands. This vulnerability affects versions up to and including the latest version. An attacker can exploit this by creating a branch name with a malicious payload and opening a pull request, potentially leading to reverse shell access or theft of sensitive tokens and keys.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8156" + }, + { + "type": "WEB", + "url": "https://github.com/significant-gravitas/autogpt/commit/1df7d527dd37dff8363dc162fb58d300f072e302" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/959efe87-f109-4cef-94d8-90ff2c7aef51" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-rv4f-crjq-xjf8/GHSA-rv4f-crjq-xjf8.json b/advisories/unreviewed/2025/03/GHSA-rv4f-crjq-xjf8/GHSA-rv4f-crjq-xjf8.json new file mode 100644 index 00000000000..7ce78ac44e3 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-rv4f-crjq-xjf8/GHSA-rv4f-crjq-xjf8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rv4f-crjq-xjf8", + "modified": "2025-03-20T12:32:47Z", + "published": "2025-03-20T12:32:47Z", + "aliases": [ + "CVE-2024-8027" + ], + "details": "A stored Cross-Site Scripting (XSS) vulnerability exists in netease-youdao/QAnything. Attackers can upload malicious knowledge files to the knowledge base, which can trigger XSS attacks during user chats. This vulnerability affects all versions prior to the fix.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8027" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/cf75f024-3d64-416d-adfe-c4255d7c3f34" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-rvgh-pr46-x7gg/GHSA-rvgh-pr46-x7gg.json b/advisories/unreviewed/2025/03/GHSA-rvgh-pr46-x7gg/GHSA-rvgh-pr46-x7gg.json new file mode 100644 index 00000000000..31cfbddffb3 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-rvgh-pr46-x7gg/GHSA-rvgh-pr46-x7gg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rvgh-pr46-x7gg", + "modified": "2025-03-20T12:32:39Z", + "published": "2025-03-20T12:32:39Z", + "aliases": [ + "CVE-2024-10624" + ], + "details": "A Regular Expression Denial of Service (ReDoS) vulnerability exists in the gradio-app/gradio repository, affecting the gr.Datetime component. The affected version is git commit 98cbcae. The vulnerability arises from the use of a regular expression `^(?:\\s*now\\s*(?:-\\s*(\\d+)\\s*([dmhs]))?)?\\s*$` to process user input. In Python's default regex engine, this regular expression can take polynomial time to match certain crafted inputs. An attacker can exploit this by sending a crafted HTTP request, causing the gradio process to consume 100% CPU and potentially leading to a Denial of Service (DoS) condition on the server.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10624" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/e8d0b248-8feb-4c23-9ef9-be4d1e868374" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-rvmr-crph-7vj2/GHSA-rvmr-crph-7vj2.json b/advisories/unreviewed/2025/03/GHSA-rvmr-crph-7vj2/GHSA-rvmr-crph-7vj2.json new file mode 100644 index 00000000000..036f90838c7 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-rvmr-crph-7vj2/GHSA-rvmr-crph-7vj2.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rvmr-crph-7vj2", + "modified": "2025-03-20T12:32:53Z", + "published": "2025-03-20T12:32:53Z", + "aliases": [ + "CVE-2024-13558" + ], + "details": "The NP Quote Request for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.9.179 due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to read the content of quote requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13558" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3256816" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/woo-rfq-for-woocommerce/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/5991c86b-6785-41a6-a5df-c65e8a28201c?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T12:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-rxwh-3m8p-2qq5/GHSA-rxwh-3m8p-2qq5.json b/advisories/unreviewed/2025/03/GHSA-rxwh-3m8p-2qq5/GHSA-rxwh-3m8p-2qq5.json new file mode 100644 index 00000000000..3bed76cffaf --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-rxwh-3m8p-2qq5/GHSA-rxwh-3m8p-2qq5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rxwh-3m8p-2qq5", + "modified": "2025-03-20T12:32:50Z", + "published": "2025-03-20T12:32:50Z", + "aliases": [ + "CVE-2024-9159" + ], + "details": "An incorrect authorization vulnerability exists in gaizhenbiao/chuanhuchatgpt version git c91dbfc. The vulnerability allows any user to restart the server at will, leading to a complete loss of availability. The issue arises because the function responsible for restarting the server is not properly guarded by an admin check.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9159" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/ab0f8fbb-c17a-45a7-8dab-7d4c8b90490a" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-v3f4-7pp9-6f99/GHSA-v3f4-7pp9-6f99.json b/advisories/unreviewed/2025/03/GHSA-v3f4-7pp9-6f99/GHSA-v3f4-7pp9-6f99.json new file mode 100644 index 00000000000..2cc2686c326 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-v3f4-7pp9-6f99/GHSA-v3f4-7pp9-6f99.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v3f4-7pp9-6f99", + "modified": "2025-03-20T12:32:46Z", + "published": "2025-03-20T12:32:46Z", + "aliases": [ + "CVE-2024-7058" + ], + "details": "A vulnerability in the sanitize_path function in parisneo/lollms-webui v10 - latest allows an attacker to bypass path sanitization by using relative paths such as './'. This can lead to unauthorized access to directories within the personality_folder on the victim's computer.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7058" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/148fce03-0f5a-4939-b636-b7f9848765e4" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-23" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-v464-r2r9-www7/GHSA-v464-r2r9-www7.json b/advisories/unreviewed/2025/03/GHSA-v464-r2r9-www7/GHSA-v464-r2r9-www7.json new file mode 100644 index 00000000000..d6c9251d9ab --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-v464-r2r9-www7/GHSA-v464-r2r9-www7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v464-r2r9-www7", + "modified": "2025-03-20T12:32:44Z", + "published": "2025-03-20T12:32:44Z", + "aliases": [ + "CVE-2024-12886" + ], + "details": "An Out-Of-Memory (OOM) vulnerability exists in the `ollama` server version 0.3.14. This vulnerability can be triggered when a malicious API server responds with a gzip bomb HTTP response, leading to the `ollama` server crashing. The vulnerability is present in the `makeRequestWithRetry` and `getAuthorizationToken` functions, which use `io.ReadAll` to read the response body. This can result in excessive memory usage and a Denial of Service (DoS) condition.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12886" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/f115fe52-58af-4844-ad29-b1c25f7245df" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-v5pj-jrpv-h6g2/GHSA-v5pj-jrpv-h6g2.json b/advisories/unreviewed/2025/03/GHSA-v5pj-jrpv-h6g2/GHSA-v5pj-jrpv-h6g2.json new file mode 100644 index 00000000000..1d3125e4928 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-v5pj-jrpv-h6g2/GHSA-v5pj-jrpv-h6g2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v5pj-jrpv-h6g2", + "modified": "2025-03-20T12:32:43Z", + "published": "2025-03-20T12:32:43Z", + "aliases": [ + "CVE-2024-12777" + ], + "details": "A vulnerability in aimhubio/aim version 3.25.0 allows for a denial of service through the misuse of the sshfs-client. The tracking server, which is single-threaded, can be made unresponsive by requesting it to connect to an unresponsive socket via sshfs. The lack of an additional timeout setting in the sshfs-client causes the server to hang for a significant amount of time, preventing it from responding to other requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12777" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/cdf8db79-c290-4fe5-9383-4c518bfba4a8" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1088" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-v67x-89x7-mh47/GHSA-v67x-89x7-mh47.json b/advisories/unreviewed/2025/03/GHSA-v67x-89x7-mh47/GHSA-v67x-89x7-mh47.json new file mode 100644 index 00000000000..7cf9d613dc1 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-v67x-89x7-mh47/GHSA-v67x-89x7-mh47.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v67x-89x7-mh47", + "modified": "2025-03-20T12:32:38Z", + "published": "2025-03-20T12:32:38Z", + "aliases": [ + "CVE-2024-0245" + ], + "details": "A misconfiguration in the AndroidManifest.xml file in hamza417/inure before build97 allows for task hijacking. This vulnerability permits malicious applications to inherit permissions of the vulnerable app, potentially leading to the exposure of sensitive information. An attacker can create a malicious app that hijacks the legitimate Inure app, intercepting and stealing sensitive information when installed on the victim's device. This issue affects all Android versions before Android 11.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0245" + }, + { + "type": "WEB", + "url": "https://github.com/hamza417/inure/commit/a0c3e68b0542bcd7007c93618e0d50a5331de061" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/2108644e-9e54-4236-932d-f204fc68b607" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-vffc-qpx3-764c/GHSA-vffc-qpx3-764c.json b/advisories/unreviewed/2025/03/GHSA-vffc-qpx3-764c/GHSA-vffc-qpx3-764c.json new file mode 100644 index 00000000000..db1d5669918 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-vffc-qpx3-764c/GHSA-vffc-qpx3-764c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vffc-qpx3-764c", + "modified": "2025-03-20T12:32:43Z", + "published": "2025-03-20T12:32:43Z", + "aliases": [ + "CVE-2024-12388" + ], + "details": "A vulnerability in binary-husky/gpt_academic version 310122f allows for a Regular Expression Denial of Service (ReDoS) attack. The application uses a regular expression to parse user input, which can take polynomial time to match certain crafted inputs. This allows an attacker to send a small malicious payload to the server, causing it to become unresponsive and unable to handle any requests from other users.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12388" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/b1c01c94-e477-41db-9d17-601aa25e351c" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-115" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-vh85-qfmh-23mf/GHSA-vh85-qfmh-23mf.json b/advisories/unreviewed/2025/03/GHSA-vh85-qfmh-23mf/GHSA-vh85-qfmh-23mf.json new file mode 100644 index 00000000000..9fbdfe6f65c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-vh85-qfmh-23mf/GHSA-vh85-qfmh-23mf.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vh85-qfmh-23mf", + "modified": "2025-03-20T12:32:40Z", + "published": "2025-03-20T12:32:40Z", + "aliases": [ + "CVE-2024-10722" + ], + "details": "A stored cross-site scripting (XSS) vulnerability exists in phpipam/phpipam version 1.5.2. The vulnerability allows attackers to inject malicious scripts into the 'Description' field of custom fields in the 'IP RELATED MANAGEMENT' section. This can lead to data theft, account compromise, distribution of malware, website defacement, content manipulation, and phishing attacks. The issue is fixed in version 1.7.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10722" + }, + { + "type": "WEB", + "url": "https://github.com/phpipam/phpipam/commit/c1697bb6c4e4a6403d69c0868e1eb1040f98b731" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/f0bc97b2-33a9-4b15-aa05-ff7c57624847" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-vhfq-gpqw-p5cw/GHSA-vhfq-gpqw-p5cw.json b/advisories/unreviewed/2025/03/GHSA-vhfq-gpqw-p5cw/GHSA-vhfq-gpqw-p5cw.json new file mode 100644 index 00000000000..5c026132b5a --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-vhfq-gpqw-p5cw/GHSA-vhfq-gpqw-p5cw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vhfq-gpqw-p5cw", + "modified": "2025-03-20T12:32:41Z", + "published": "2025-03-20T12:32:41Z", + "aliases": [ + "CVE-2024-10955" + ], + "details": "A Regular Expression Denial of Service (ReDoS) vulnerability exists in gaizhenbiao/chuanhuchatgpt, as of commit 20b2e02. The server uses the regex pattern `r'<[^>]+>'` to parse user input. In Python's default regex engine, this pattern can take polynomial time to match certain crafted inputs. An attacker can exploit this by uploading a malicious JSON payload, causing the server to consume 100% CPU for an extended period. This can lead to a Denial of Service (DoS) condition, potentially affecting the entire server.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10955" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/8291f8d0-5060-47e7-9986-1f411310fb7b" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-vpg6-7cch-gq2j/GHSA-vpg6-7cch-gq2j.json b/advisories/unreviewed/2025/03/GHSA-vpg6-7cch-gq2j/GHSA-vpg6-7cch-gq2j.json new file mode 100644 index 00000000000..a9ad8451506 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-vpg6-7cch-gq2j/GHSA-vpg6-7cch-gq2j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vpg6-7cch-gq2j", + "modified": "2025-03-20T12:32:48Z", + "published": "2025-03-20T12:32:48Z", + "aliases": [ + "CVE-2024-8736" + ], + "details": "A Denial of Service (DoS) vulnerability exists in multiple file upload endpoints of parisneo/lollms-webui version V12 (Strawberry). The vulnerability can be exploited remotely via Cross-Site Request Forgery (CSRF). Despite CSRF protection preventing file uploads, the application still processes multipart boundaries, leading to resource exhaustion. By appending additional characters to the multipart boundary, an attacker can cause the server to parse each byte of the boundary, ultimately leading to service unavailability. This vulnerability is present in the `/upload_avatar`, `/upload_app`, and `/upload_logo` endpoints.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8736" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/935dbc03-1b43-4dbb-b6cd-1aa95a789d4f" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-vq2g-prvr-rgr4/GHSA-vq2g-prvr-rgr4.json b/advisories/unreviewed/2025/03/GHSA-vq2g-prvr-rgr4/GHSA-vq2g-prvr-rgr4.json new file mode 100644 index 00000000000..e52aa368cf7 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-vq2g-prvr-rgr4/GHSA-vq2g-prvr-rgr4.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vq2g-prvr-rgr4", + "modified": "2025-03-20T12:32:46Z", + "published": "2025-03-20T12:32:46Z", + "aliases": [ + "CVE-2024-7773" + ], + "details": "A vulnerability in ollama/ollama version 0.1.37 allows for remote code execution (RCE) due to improper input validation in the handling of zip files. The vulnerability, known as ZipSlip, occurs in the parseFromZipFile function in server/model.go. The code does not check for directory traversal sequences (../) in file names within the zip archive, allowing an attacker to write arbitrary files to the file system. This can be exploited to create files such as /etc/ld.so.preload and a malicious shared library, leading to RCE.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7773" + }, + { + "type": "WEB", + "url": "https://github.com/ollama/ollama/commit/123a722a6f541e300bc8e34297ac378ebe23f527" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/aeb82e05-484f-4431-9ede-25a3478d8dbb" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-vqqv-6pvc-4m7q/GHSA-vqqv-6pvc-4m7q.json b/advisories/unreviewed/2025/03/GHSA-vqqv-6pvc-4m7q/GHSA-vqqv-6pvc-4m7q.json new file mode 100644 index 00000000000..b094d49e105 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-vqqv-6pvc-4m7q/GHSA-vqqv-6pvc-4m7q.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vqqv-6pvc-4m7q", + "modified": "2025-03-20T12:32:52Z", + "published": "2025-03-20T12:32:52Z", + "aliases": [ + "CVE-2025-0281" + ], + "details": "A stored cross-site scripting (XSS) vulnerability exists in lunary-ai/lunary versions 1.6.7 and earlier. An attacker can inject malicious JavaScript into the SAML IdP XML metadata, which is used to generate the SAML login redirect URL. This URL is then set as the value of `window.location.href` without proper validation or sanitization. This vulnerability allows the attacker to execute arbitrary JavaScript in the context of the user's browser, potentially leading to session hijacking, data theft, or other malicious actions. The issue is fixed in version 1.7.10.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0281" + }, + { + "type": "WEB", + "url": "https://github.com/lunary-ai/lunary/commit/fa0fd7742ae029ed934690d282519263f5d838de" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/b3f4a655-5b08-4fef-be2c-aac8703ad5d0" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-vrw3-r7jw-4785/GHSA-vrw3-r7jw-4785.json b/advisories/unreviewed/2025/03/GHSA-vrw3-r7jw-4785/GHSA-vrw3-r7jw-4785.json new file mode 100644 index 00000000000..48793ad1cc3 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-vrw3-r7jw-4785/GHSA-vrw3-r7jw-4785.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vrw3-r7jw-4785", + "modified": "2025-03-20T12:32:52Z", + "published": "2025-03-20T12:32:52Z", + "aliases": [ + "CVE-2025-0182" + ], + "details": "A vulnerability in danswer-ai/danswer version 0.9.0 allows for denial of service through memory exhaustion. The issue arises from the use of a vulnerable version of the starlette package (<=0.49) via fastapi, which was patched in fastapi version 0.115.3. The vulnerability can be exploited by sending multiple requests to the /auth/saml/callback endpoint, leading to uncontrolled memory consumption and eventual denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0182" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/969b8056-b66c-4d70-8f77-04c1cbdc1d1a" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-vx9q-6hqp-j863/GHSA-vx9q-6hqp-j863.json b/advisories/unreviewed/2025/03/GHSA-vx9q-6hqp-j863/GHSA-vx9q-6hqp-j863.json new file mode 100644 index 00000000000..8720b95c220 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-vx9q-6hqp-j863/GHSA-vx9q-6hqp-j863.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vx9q-6hqp-j863", + "modified": "2025-03-20T12:32:39Z", + "published": "2025-03-20T12:32:39Z", + "aliases": [ + "CVE-2024-10274" + ], + "details": "An improper authorization vulnerability exists in lunary-ai/lunary version 1.5.5. The /users/me/org endpoint lacks adequate access control mechanisms, allowing unauthorized users to access sensitive information about all team members in the current organization. This vulnerability can lead to the disclosure of sensitive information such as names, roles, or emails to users without sufficient privileges, resulting in privacy violations and potential reconnaissance for targeted attacks.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10274" + }, + { + "type": "WEB", + "url": "https://github.com/lunary-ai/lunary/commit/8ba1b8ba2c2c30b1cec30eb5777c1fda670cbbfc" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/506459c1-da60-45c5-a10d-8bd540a4b4c1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-285" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-w3m9-crxx-972f/GHSA-w3m9-crxx-972f.json b/advisories/unreviewed/2025/03/GHSA-w3m9-crxx-972f/GHSA-w3m9-crxx-972f.json new file mode 100644 index 00000000000..154c5194cde --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-w3m9-crxx-972f/GHSA-w3m9-crxx-972f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w3m9-crxx-972f", + "modified": "2025-03-20T12:32:44Z", + "published": "2025-03-20T12:32:43Z", + "aliases": [ + "CVE-2024-12864" + ], + "details": "A Denial of Service (DoS) vulnerability was discovered in the file upload feature of netease-youdao/qanything version v2.0.0. The vulnerability is due to improper handling of form-data with a large filename in the file upload request. An attacker can exploit this vulnerability by sending a large filename, causing the server to become overwhelmed and unavailable for legitimate users. This attack does not require authentication, making it highly scalable and increasing the risk of exploitation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12864" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/365c3b9a-180c-4bb5-98d8-dbd78d93fcb7" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-w466-2wfc-8g58/GHSA-w466-2wfc-8g58.json b/advisories/unreviewed/2025/03/GHSA-w466-2wfc-8g58/GHSA-w466-2wfc-8g58.json new file mode 100644 index 00000000000..83390cd9170 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-w466-2wfc-8g58/GHSA-w466-2wfc-8g58.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w466-2wfc-8g58", + "modified": "2025-03-20T12:32:44Z", + "published": "2025-03-20T12:32:44Z", + "aliases": [ + "CVE-2024-12868" + ], + "details": "In version 0.3.32 of open-webui, the application uses a vulnerable version of the starlette package through its dependency on fastapi. The starlette package versions <=0.49 are susceptible to uncontrolled resource consumption, which can be exploited to cause a denial of service through memory exhaustion. This issue is addressed in fastapi version 0.115.3.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12868" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/56175583-70e3-4d53-94de-3f3a8e2423ec" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-w4cv-4jm4-pg8h/GHSA-w4cv-4jm4-pg8h.json b/advisories/unreviewed/2025/03/GHSA-w4cv-4jm4-pg8h/GHSA-w4cv-4jm4-pg8h.json new file mode 100644 index 00000000000..60105088c4c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-w4cv-4jm4-pg8h/GHSA-w4cv-4jm4-pg8h.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w4cv-4jm4-pg8h", + "modified": "2025-03-20T12:32:39Z", + "published": "2025-03-20T12:32:39Z", + "aliases": [ + "CVE-2024-10359" + ], + "details": "In danny-avila/librechat version v0.7.5-rc2, a vulnerability exists in the preset creation functionality where a user can manipulate the user ID field through mass assignment. This allows an attacker to inject a different user ID into the preset object, causing the preset to appear in the UI of another user. The vulnerability arises because the backend saves the entire object received without validating the attributes and their values, impacting both integrity and confidentiality.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10359" + }, + { + "type": "WEB", + "url": "https://github.com/danny-avila/librechat/commit/e3e52402f69accc35c6d0acd9c3266ae1cb6333f" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/bba65eb4-4c83-4f33-83c1-ede5ed0d5656" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-915" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-w6hh-w36c-vxmw/GHSA-w6hh-w36c-vxmw.json b/advisories/unreviewed/2025/03/GHSA-w6hh-w36c-vxmw/GHSA-w6hh-w36c-vxmw.json new file mode 100644 index 00000000000..8d4f748a4c3 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-w6hh-w36c-vxmw/GHSA-w6hh-w36c-vxmw.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w6hh-w36c-vxmw", + "modified": "2025-03-20T12:32:51Z", + "published": "2025-03-20T12:32:51Z", + "aliases": [ + "CVE-2024-9900" + ], + "details": "mudler/localai version v2.21.1 contains a Cross-Site Scripting (XSS) vulnerability in its search functionality. The vulnerability arises due to improper sanitization of user input, allowing the injection and execution of arbitrary JavaScript code. This can lead to the execution of malicious scripts in the context of the victim's browser, potentially compromising user sessions, stealing session cookies, redirecting users to malicious websites, or manipulating the DOM.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9900" + }, + { + "type": "WEB", + "url": "https://github.com/mudler/localai/commit/a1634b219a4e52813e70ff07e6376a01449c4515" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/b39cd230-db66-471b-89b9-24afaa078e68" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-115" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-w6r4-j5cm-c7fp/GHSA-w6r4-j5cm-c7fp.json b/advisories/unreviewed/2025/03/GHSA-w6r4-j5cm-c7fp/GHSA-w6r4-j5cm-c7fp.json new file mode 100644 index 00000000000..35facd32b3f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-w6r4-j5cm-c7fp/GHSA-w6r4-j5cm-c7fp.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w6r4-j5cm-c7fp", + "modified": "2025-03-20T12:32:48Z", + "published": "2025-03-20T12:32:48Z", + "aliases": [ + "CVE-2024-8581" + ], + "details": "A vulnerability in the `upload_app` function of parisneo/lollms-webui V12 (Strawberry) allows an attacker to delete any file or directory on the system. The function does not implement user input filtering with the `filename` value, causing a Path Traversal error.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8581" + }, + { + "type": "WEB", + "url": "https://github.com/parisneo/lollms-webui/commit/dcc078cbe20d2a9640b0942a622134b0e3fa6e48" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/67ead5b9-8149-4001-a1cd-ac648cb7b414" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-wcwp-9rcp-jvfg/GHSA-wcwp-9rcp-jvfg.json b/advisories/unreviewed/2025/03/GHSA-wcwp-9rcp-jvfg/GHSA-wcwp-9rcp-jvfg.json new file mode 100644 index 00000000000..ac930e8fbab --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-wcwp-9rcp-jvfg/GHSA-wcwp-9rcp-jvfg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wcwp-9rcp-jvfg", + "modified": "2025-03-20T12:32:45Z", + "published": "2025-03-20T12:32:45Z", + "aliases": [ + "CVE-2024-7036" + ], + "details": "A vulnerability in open-webui/open-webui v0.3.8 allows an unauthenticated attacker to sign up with excessively large text in the 'name' field, causing the Admin panel to become unresponsive. This prevents administrators from performing essential user management actions such as deleting, editing, or adding users. The vulnerability can also be exploited by authenticated users with low privileges, leading to the same unresponsive state in the Admin panel.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7036" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/ba62d093-ab27-48fa-9c53-0602c8cdc48a" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-wjpv-64v2-2qpq/GHSA-wjpv-64v2-2qpq.json b/advisories/unreviewed/2025/03/GHSA-wjpv-64v2-2qpq/GHSA-wjpv-64v2-2qpq.json new file mode 100644 index 00000000000..87211e36ab0 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-wjpv-64v2-2qpq/GHSA-wjpv-64v2-2qpq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wjpv-64v2-2qpq", + "modified": "2025-03-20T12:32:39Z", + "published": "2025-03-20T12:32:39Z", + "aliases": [ + "CVE-2024-10572" + ], + "details": "In h2oai/h2o-3 version 3.46.0.1, the `run_tool` command exposes classes in the `water.tools` package through the `ast` parser. This includes the `XGBoostLibExtractTool` class, which can be exploited to shut down the server and write large files to arbitrary directories, leading to a denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10572" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/db8939a0-9be8-4d0f-a8b0-1bd181666da2" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-wmc2-c6g2-9mf2/GHSA-wmc2-c6g2-9mf2.json b/advisories/unreviewed/2025/03/GHSA-wmc2-c6g2-9mf2/GHSA-wmc2-c6g2-9mf2.json new file mode 100644 index 00000000000..c2dbf0bafb7 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-wmc2-c6g2-9mf2/GHSA-wmc2-c6g2-9mf2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wmc2-c6g2-9mf2", + "modified": "2025-03-20T12:32:51Z", + "published": "2025-03-20T12:32:51Z", + "aliases": [ + "CVE-2024-9365" + ], + "details": "A Cross-Site Request Forgery (CSRF) vulnerability in polyaxon/polyaxon v2.4.0 allows attackers to perform unauthorized actions in the context of the victim's browser. This includes creating projects, model versions, and artifact versions, or changing settings. The impact of this vulnerability includes potential data loss and service disruption.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9365" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/cdfa012b-a694-4beb-9a9a-12a9dde07ef9" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-wr4v-pc76-3q4p/GHSA-wr4v-pc76-3q4p.json b/advisories/unreviewed/2025/03/GHSA-wr4v-pc76-3q4p/GHSA-wr4v-pc76-3q4p.json new file mode 100644 index 00000000000..d442c8a8db7 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-wr4v-pc76-3q4p/GHSA-wr4v-pc76-3q4p.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wr4v-pc76-3q4p", + "modified": "2025-03-20T12:32:43Z", + "published": "2025-03-20T12:32:43Z", + "aliases": [ + "CVE-2024-12433" + ], + "details": "A vulnerability in infiniflow/ragflow versions v0.12.0 allows for remote code execution. The RPC server in RagFlow uses a hard-coded AuthKey 'authkey=b'infiniflow-token4kevinhu'' which can be easily fetched by attackers to join the group communication without restrictions. Additionally, the server processes incoming data using pickle deserialization via `pickle.loads()` on `connection.recv()`, making it vulnerable to remote code execution. This issue is fixed in version 0.14.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12433" + }, + { + "type": "WEB", + "url": "https://github.com/infiniflow/ragflow/commit/49494d4e3c8f06a5e52cf1f7cce9fa03cadcfbf6" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/8a1465af-09e4-42af-9e54-0b70e7c87499" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-wwr9-4gmr-xvq9/GHSA-wwr9-4gmr-xvq9.json b/advisories/unreviewed/2025/03/GHSA-wwr9-4gmr-xvq9/GHSA-wwr9-4gmr-xvq9.json new file mode 100644 index 00000000000..708ebdc3ca8 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-wwr9-4gmr-xvq9/GHSA-wwr9-4gmr-xvq9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wwr9-4gmr-xvq9", + "modified": "2025-03-20T12:32:39Z", + "published": "2025-03-20T12:32:39Z", + "aliases": [ + "CVE-2024-10549" + ], + "details": "A vulnerability in the `/3/Parse` endpoint of h2oai/h2o-3 version 3.46.0.1 allows for a denial of service (DoS) attack. The endpoint uses a user-specified string to construct a regular expression, which is then applied to another user-specified string. By sending multiple simultaneous requests, an attacker can exhaust all available threads, leading to a complete denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10549" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/ce7bd2d6-fd38-440d-a91a-dd8f3fc06bc2" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-wxpc-2674-rxvw/GHSA-wxpc-2674-rxvw.json b/advisories/unreviewed/2025/03/GHSA-wxpc-2674-rxvw/GHSA-wxpc-2674-rxvw.json new file mode 100644 index 00000000000..66ab17b24a2 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-wxpc-2674-rxvw/GHSA-wxpc-2674-rxvw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wxpc-2674-rxvw", + "modified": "2025-03-20T12:32:42Z", + "published": "2025-03-20T12:32:42Z", + "aliases": [ + "CVE-2024-11602" + ], + "details": "A Cross-Origin Resource Sharing (CORS) vulnerability exists in feast-dev/feast version 0.40.0. The CORS configuration on the agentscope server does not properly restrict access to only trusted origins, allowing any external domain to make requests to the API. This can bypass intended security controls and potentially expose sensitive information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11602" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/7b24ecbe-0af7-4125-ab56-bce09786042e" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-346" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-x2w2-frfv-4f2j/GHSA-x2w2-frfv-4f2j.json b/advisories/unreviewed/2025/03/GHSA-x2w2-frfv-4f2j/GHSA-x2w2-frfv-4f2j.json new file mode 100644 index 00000000000..ab6e74d38e6 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-x2w2-frfv-4f2j/GHSA-x2w2-frfv-4f2j.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x2w2-frfv-4f2j", + "modified": "2025-03-20T12:32:52Z", + "published": "2025-03-20T12:32:51Z", + "aliases": [ + "CVE-2024-9847" + ], + "details": "FlatPress CMS version latest is vulnerable to Cross-Site Request Forgery (CSRF) attacks that allow an attacker to enable or disable plugins on behalf of a victim user. The attacker can craft a malicious link or script that, when clicked by an authenticated user, will send a request to the FlatPress CMS server to perform the desired action on behalf of the victim user. Since the request is authenticated, the server will process it as if it were initiated by the legitimate user, effectively allowing the attacker to perform unauthorized actions. This vulnerability is fixed in version 1.4.dev.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9847" + }, + { + "type": "WEB", + "url": "https://github.com/flatpressblog/flatpress/commit/a81c968f51f134b5e5f9bbe208aa12f4fbc329df" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/b30ef7b0-74ea-4cac-adc4-1cc8a5cb559e" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-x48g-hm9c-ww42/GHSA-x48g-hm9c-ww42.json b/advisories/unreviewed/2025/03/GHSA-x48g-hm9c-ww42/GHSA-x48g-hm9c-ww42.json new file mode 100644 index 00000000000..2c6005e436d --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-x48g-hm9c-ww42/GHSA-x48g-hm9c-ww42.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x48g-hm9c-ww42", + "modified": "2025-03-20T12:32:44Z", + "published": "2025-03-20T12:32:44Z", + "aliases": [ + "CVE-2024-12909" + ], + "details": "A vulnerability in the FinanceChatLlamaPack of the run-llama/llama_index repository, versions up to v0.12.3, allows for SQL injection in the `run_sql_query` function of the `database_agent`. This vulnerability can be exploited by an attacker to inject arbitrary SQL queries, leading to remote code execution (RCE) through the use of PostgreSQL's large object functionality. The issue is fixed in version 0.3.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12909" + }, + { + "type": "WEB", + "url": "https://github.com/run-llama/llama_index/commit/5d03c175476452db9b8abcdb7d5767dd7b310a75" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/44e8177f-200a-4ba3-a12c-8bc21e313a3f" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-x552-5vh8-qccx/GHSA-x552-5vh8-qccx.json b/advisories/unreviewed/2025/03/GHSA-x552-5vh8-qccx/GHSA-x552-5vh8-qccx.json new file mode 100644 index 00000000000..8f2554187e1 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-x552-5vh8-qccx/GHSA-x552-5vh8-qccx.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x552-5vh8-qccx", + "modified": "2025-03-20T12:32:50Z", + "published": "2025-03-20T12:32:50Z", + "aliases": [ + "CVE-2024-9000" + ], + "details": "In lunary-ai/lunary before version 1.4.26, the checklists.post() endpoint allows users to create or modify checklists without validating whether the user has proper permissions. This missing access control permits unauthorized users to create checklists, bypassing intended permission checks. Additionally, the endpoint does not validate the uniqueness of the slug field when creating a new checklist, allowing an attacker to spoof existing checklists by reusing the slug of an already-existing checklist. This can lead to significant data integrity issues, as legitimate checklists can be replaced with malicious or altered data.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9000" + }, + { + "type": "WEB", + "url": "https://github.com/lunary-ai/lunary/commit/a02861ef9bb6ce860a35f7b8f178d58859cd85f0" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/f5fca549-0a4a-4f64-8ccf-d4e108856da4" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-285" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-x5xw-28w4-53j5/GHSA-x5xw-28w4-53j5.json b/advisories/unreviewed/2025/03/GHSA-x5xw-28w4-53j5/GHSA-x5xw-28w4-53j5.json new file mode 100644 index 00000000000..daaac342b94 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-x5xw-28w4-53j5/GHSA-x5xw-28w4-53j5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x5xw-28w4-53j5", + "modified": "2025-03-20T12:32:43Z", + "published": "2025-03-20T12:32:43Z", + "aliases": [ + "CVE-2024-12761" + ], + "details": "A Denial of Service (DoS) vulnerability exists in the brycedrennan/imaginairy repository, version 15.0.0. The vulnerability is present in the `/api/stablestudio/generate` endpoint, which can be exploited by sending an invalid request. This causes the server process to terminate abruptly, outputting `KILLED` in the terminal, and results in the unavailability of the server. This issue disrupts the server's functionality, affecting all users.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12761" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/282900f4-2498-42c4-8ce7-ba5368aaf035" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-x757-hv69-jr45/GHSA-x757-hv69-jr45.json b/advisories/unreviewed/2025/03/GHSA-x757-hv69-jr45/GHSA-x757-hv69-jr45.json new file mode 100644 index 00000000000..a29fe9e289c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-x757-hv69-jr45/GHSA-x757-hv69-jr45.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x757-hv69-jr45", + "modified": "2025-03-20T12:32:46Z", + "published": "2025-03-20T12:32:46Z", + "aliases": [ + "CVE-2024-7959" + ], + "details": "The `/openai/models` endpoint in open-webui/open-webui version 0.3.8 is vulnerable to Server-Side Request Forgery (SSRF). An attacker can change the OpenAI URL to any URL without checks, causing the endpoint to send a request to the specified URL and return the output. This vulnerability allows the attacker to access internal services and potentially gain command execution by accessing instance secrets.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7959" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/3c8bea0a-d678-4d67-bb9c-2b5b610a2193" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-x7c5-9r9g-pghj/GHSA-x7c5-9r9g-pghj.json b/advisories/unreviewed/2025/03/GHSA-x7c5-9r9g-pghj/GHSA-x7c5-9r9g-pghj.json new file mode 100644 index 00000000000..e3f350cca46 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-x7c5-9r9g-pghj/GHSA-x7c5-9r9g-pghj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x7c5-9r9g-pghj", + "modified": "2025-03-20T12:32:41Z", + "published": "2025-03-20T12:32:41Z", + "aliases": [ + "CVE-2024-11033" + ], + "details": "A Denial of Service (DoS) vulnerability exists in the file upload feature of binary-husky/gpt_academic version 3.83. The vulnerability is due to improper handling of form-data with a large filename in the file upload request. An attacker can exploit this vulnerability by sending a payload with an excessively large filename, causing the server to become overwhelmed and unavailable for legitimate users.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11033" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/78afc15c-7db7-42fe-90f5-a0480a2ec222" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-x9hf-jr2h-w47p/GHSA-x9hf-jr2h-w47p.json b/advisories/unreviewed/2025/03/GHSA-x9hf-jr2h-w47p/GHSA-x9hf-jr2h-w47p.json new file mode 100644 index 00000000000..6b9d83aba17 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-x9hf-jr2h-w47p/GHSA-x9hf-jr2h-w47p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x9hf-jr2h-w47p", + "modified": "2025-03-20T12:32:41Z", + "published": "2025-03-20T12:32:41Z", + "aliases": [ + "CVE-2024-10935" + ], + "details": "automatic1111/stable-diffusion-webui version 1.10.0 contains a vulnerability where the server fails to handle excessive characters appended to the end of multipart boundaries. This flaw can be exploited by sending malformed multipart requests with arbitrary characters at the end of the boundary, leading to excessive resource consumption and a complete denial of service (DoS) for all users. The vulnerability is unauthenticated, meaning no user login or interaction is required for an attacker to exploit this issue.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10935" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/e6fdc6ed-f38d-4798-b60a-0e47893a81a6" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-xcp6-jv5m-jwrm/GHSA-xcp6-jv5m-jwrm.json b/advisories/unreviewed/2025/03/GHSA-xcp6-jv5m-jwrm/GHSA-xcp6-jv5m-jwrm.json new file mode 100644 index 00000000000..edc577ed52d --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-xcp6-jv5m-jwrm/GHSA-xcp6-jv5m-jwrm.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xcp6-jv5m-jwrm", + "modified": "2025-03-20T12:32:39Z", + "published": "2025-03-20T12:32:39Z", + "aliases": [ + "CVE-2024-10361" + ], + "details": "An arbitrary file deletion vulnerability exists in danny-avila/librechat version v0.7.5-rc2, specifically within the /api/files endpoint. This vulnerability arises from improper input validation, allowing path traversal techniques to delete arbitrary files on the server. Attackers can exploit this to bypass security mechanisms and delete files outside the intended directory, including critical system files, user data, or application resources. This vulnerability impacts the integrity and availability of the system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10361" + }, + { + "type": "WEB", + "url": "https://github.com/danny-avila/librechat/commit/0b744db1e2af31a531ffb761584d85540430639c" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/e811f7f7-9556-4564-82e2-5b3d17599b2d" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-73" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-xfjg-gcvp-vw7p/GHSA-xfjg-gcvp-vw7p.json b/advisories/unreviewed/2025/03/GHSA-xfjg-gcvp-vw7p/GHSA-xfjg-gcvp-vw7p.json new file mode 100644 index 00000000000..31ecd648468 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-xfjg-gcvp-vw7p/GHSA-xfjg-gcvp-vw7p.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xfjg-gcvp-vw7p", + "modified": "2025-03-20T12:32:42Z", + "published": "2025-03-20T12:32:42Z", + "aliases": [ + "CVE-2024-11173" + ], + "details": "An unhandled exception in the danny-avila/librechat repository, version git 600d217, can cause the server to crash, leading to a full denial of service. This issue occurs when certain API endpoints receive malformed input, resulting in an uncaught exception. Although a valid JWT is required to exploit this vulnerability, LibreChat allows open registration, enabling unauthenticated attackers to create an account and perform the attack. The issue is fixed in version 0.7.6.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11173" + }, + { + "type": "WEB", + "url": "https://github.com/danny-avila/librechat/commit/95a212534f1c5991bd1231a34ac3668b4b592cc3" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/4cebf926-c17f-4836-868b-e1de86221cec" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-248" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-xqgj-r6xv-9cw4/GHSA-xqgj-r6xv-9cw4.json b/advisories/unreviewed/2025/03/GHSA-xqgj-r6xv-9cw4/GHSA-xqgj-r6xv-9cw4.json new file mode 100644 index 00000000000..ead6863b09c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-xqgj-r6xv-9cw4/GHSA-xqgj-r6xv-9cw4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xqgj-r6xv-9cw4", + "modified": "2025-03-20T12:32:38Z", + "published": "2025-03-20T12:32:38Z", + "aliases": [ + "CVE-2024-10096" + ], + "details": "Dask versions <=2024.8.2 contain a vulnerability in the Dask Distributed Server where the use of pickle serialization allows attackers to craft malicious objects. These objects can be serialized on the client side and sent to the server for deserialization, leading to remote command execution and potentially granting full control over the Dask server.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10096" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/a4be847b-a52d-42cc-9e78-3299e2d30ab2" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-xv4c-2443-pc28/GHSA-xv4c-2443-pc28.json b/advisories/unreviewed/2025/03/GHSA-xv4c-2443-pc28/GHSA-xv4c-2443-pc28.json new file mode 100644 index 00000000000..06e420aa663 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-xv4c-2443-pc28/GHSA-xv4c-2443-pc28.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xv4c-2443-pc28", + "modified": "2025-03-20T12:32:44Z", + "published": "2025-03-20T12:32:44Z", + "aliases": [ + "CVE-2024-2292" + ], + "details": "Due to a lack of access control, unauthorized users are able to view and modify information pertaining to other users.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-2292" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/90a7299e-9233-43fd-b666-7375c4fdbb3c" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-xx7c-j7h3-vjcq/GHSA-xx7c-j7h3-vjcq.json b/advisories/unreviewed/2025/03/GHSA-xx7c-j7h3-vjcq/GHSA-xx7c-j7h3-vjcq.json new file mode 100644 index 00000000000..1ee62a4849d --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-xx7c-j7h3-vjcq/GHSA-xx7c-j7h3-vjcq.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xx7c-j7h3-vjcq", + "modified": "2025-03-20T12:32:45Z", + "published": "2025-03-20T12:32:45Z", + "aliases": [ + "CVE-2024-6577" + ], + "details": "In the latest version of pytorch/serve, the script 'upload_results_to_s3.sh' references the S3 bucket 'benchmarkai-metrics-prod' without ensuring its ownership or confirming its accessibility. This could lead to potential security vulnerabilities or unauthorized access to the bucket if it is not properly secured or claimed by the appropriate entity. The issue may result in data breaches, exposure of proprietary information, or unauthorized modifications to stored data.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6577" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/20917570-8328-428f-bd1d-4fcd71fb2359" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:32Z" + } +} \ No newline at end of file