From 1deaa93de2f6964fa9f79e23958bfd02fe7475c2 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 20 Mar 2025 12:34:24 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-9x24-7fgc-x3vc.json | 4 +- .../GHSA-8vf4-q8g2-79g5.json | 11 +++- .../GHSA-hw9j-mg68-r593.json | 4 +- .../GHSA-227r-w5j2-6243.json | 40 +++++++++++++ .../GHSA-22h9-9rvv-q9qg.json | 36 ++++++++++++ .../GHSA-29rg-m5qv-57gx.json | 36 ++++++++++++ .../GHSA-2c36-wq4v-5v3h.json | 36 ++++++++++++ .../GHSA-2mv8-c3hx-xq6v.json | 40 +++++++++++++ .../GHSA-2rr7-xrrm-67cf.json | 36 ++++++++++++ .../GHSA-2w2q-qp7m-7wrh.json | 36 ++++++++++++ .../GHSA-2xcr-p767-f3rv.json | 40 +++++++++++++ .../GHSA-2xf2-gjm6-g2c6.json | 36 ++++++++++++ .../GHSA-3248-f932-c76p.json | 36 ++++++++++++ .../GHSA-32g6-mg92-ghm2.json | 40 +++++++++++++ .../GHSA-332g-rf22-2vcg.json | 36 ++++++++++++ .../GHSA-339r-cjv9-x78g.json | 40 +++++++++++++ .../GHSA-34v4-5664-chqj.json | 36 ++++++++++++ .../GHSA-35p3-6j45-prwm.json | 36 ++++++++++++ .../GHSA-38mg-wm59-g64x.json | 36 ++++++++++++ .../GHSA-38r9-3j52-h92v.json | 36 ++++++++++++ .../GHSA-3c45-rpmq-6gfj.json | 36 ++++++++++++ .../GHSA-3j5r-3852-j63v.json | 36 ++++++++++++ .../GHSA-3p9q-7w63-3f8q.json | 36 ++++++++++++ .../GHSA-3ppw-4jp4-5852.json | 36 ++++++++++++ .../GHSA-3xq5-x4fj-rff7.json | 36 ++++++++++++ .../GHSA-43g4-487m-5q6m.json | 36 ++++++++++++ .../GHSA-43qf-4rqw-9q2g.json | 36 ++++++++++++ .../GHSA-4452-rwq3-2x44.json | 36 ++++++++++++ .../GHSA-44q8-52gx-27g8.json | 40 +++++++++++++ .../GHSA-45p5-8q33-98hw.json | 40 +++++++++++++ .../GHSA-47f6-5p7h-5f3h.json | 36 ++++++++++++ .../GHSA-49m6-vrr9-2cqm.json | 36 ++++++++++++ .../GHSA-49rx-72gp-wfgj.json | 36 ++++++++++++ .../GHSA-4cv3-v7pv-rfhf.json | 40 +++++++++++++ .../GHSA-4cxc-r29p-3327.json | 36 ++++++++++++ .../GHSA-4f3h-89pj-w84f.json | 36 ++++++++++++ .../GHSA-4g3f-9mfg-xxgh.json | 36 ++++++++++++ .../GHSA-4jr8-64gc-wqqx.json | 40 +++++++++++++ .../GHSA-4qcx-jx49-6qrh.json | 36 ++++++++++++ .../GHSA-4rj2-9gcx-5qhx.json | 40 +++++++++++++ .../GHSA-4rqf-8pfm-p36r.json | 40 +++++++++++++ .../GHSA-4v9f-r55g-g6hc.json | 40 +++++++++++++ .../GHSA-4vm5-r6m3-2448.json | 36 ++++++++++++ .../GHSA-4vmg-rw8f-92f9.json | 36 ++++++++++++ .../GHSA-4vqf-pwq6-3wh3.json | 36 ++++++++++++ .../GHSA-4w44-j4vc-r3rp.json | 36 ++++++++++++ .../GHSA-4wfj-v7c8-rwh4.json | 36 ++++++++++++ .../GHSA-53gh-p8jc-7rg8.json | 36 ++++++++++++ .../GHSA-54c7-72v9-gm27.json | 36 ++++++++++++ .../GHSA-54hh-fh2m-4396.json | 40 +++++++++++++ .../GHSA-564p-rx2q-4c8v.json | 36 ++++++++++++ .../GHSA-56p4-cfqw-jx4h.json | 36 ++++++++++++ .../GHSA-5c8j-g96x-cj78.json | 36 ++++++++++++ .../GHSA-5ccf-884p-4jjq.json | 36 ++++++++++++ .../GHSA-5chr-fjjv-38qv.json | 40 +++++++++++++ .../GHSA-5cpq-9538-jm2j.json | 36 ++++++++++++ .../GHSA-5fhx-jcwv-9wjj.json | 36 ++++++++++++ .../GHSA-5jmj-h3c5-682w.json | 40 +++++++++++++ .../GHSA-5mh3-rhm7-jxx3.json | 36 ++++++++++++ .../GHSA-5pfw-4vjf-fvc9.json | 36 ++++++++++++ .../GHSA-5v9m-57mq-qc75.json | 36 ++++++++++++ .../GHSA-5vqr-wprc-cpp7.json | 36 ++++++++++++ .../GHSA-5xg7-5662-8x7j.json | 36 ++++++++++++ .../GHSA-62xp-4pcv-pw3j.json | 40 +++++++++++++ .../GHSA-63gf-x2fr-8r32.json | 36 ++++++++++++ .../GHSA-64c5-jj57-f29g.json | 40 +++++++++++++ .../GHSA-64jp-4xjj-prcw.json | 40 +++++++++++++ .../GHSA-67hg-xcw3-33fm.json | 36 ++++++++++++ .../GHSA-6827-g8xf-36c7.json | 40 +++++++++++++ .../GHSA-69j6-4w2p-2887.json | 40 +++++++++++++ .../GHSA-6ch3-c5vc-j2r6.json | 36 ++++++++++++ .../GHSA-6f6x-f56q-5xgv.json | 36 ++++++++++++ .../GHSA-6fwx-j832-vvw6.json | 36 ++++++++++++ .../GHSA-6gmf-2369-c76c.json | 40 +++++++++++++ .../GHSA-6mf6-7j75-2m6f.json | 36 ++++++++++++ .../GHSA-6pvw-p9fg-rwxj.json | 40 +++++++++++++ .../GHSA-6rvg-6v2m-4j46.json | 40 +++++++++++++ .../GHSA-6v28-q95m-93qr.json | 36 ++++++++++++ .../GHSA-6vmm-pmxf-9784.json | 36 ++++++++++++ .../GHSA-6w2c-f4vg-j9hv.json | 36 ++++++++++++ .../GHSA-6w62-3jvj-mfj6.json | 36 ++++++++++++ .../GHSA-6w7p-xrvp-p7xv.json | 36 ++++++++++++ .../GHSA-6wj5-5pgr-jwq8.json | 36 ++++++++++++ .../GHSA-6xgj-c5fx-5v57.json | 36 ++++++++++++ .../GHSA-726r-vfh2-3vvj.json | 40 +++++++++++++ .../GHSA-73c8-qmph-r39f.json | 40 +++++++++++++ .../GHSA-73p4-hh43-4h48.json | 40 +++++++++++++ .../GHSA-745f-48gc-258q.json | 36 ++++++++++++ .../GHSA-747f-ww56-4q4h.json | 40 +++++++++++++ .../GHSA-749v-xf6w-5wcx.json | 48 ++++++++++++++++ .../GHSA-75px-35p4-qq6h.json | 36 ++++++++++++ .../GHSA-75v5-6885-59f9.json | 36 ++++++++++++ .../GHSA-775f-24cq-qg6p.json | 40 +++++++++++++ .../GHSA-77cj-rv5x-v6r2.json | 36 ++++++++++++ .../GHSA-79rp-v9rm-gxm8.json | 36 ++++++++++++ .../GHSA-7g3f-q846-q9hx.json | 36 ++++++++++++ .../GHSA-7gj6-22m4-qfhx.json | 36 ++++++++++++ .../GHSA-7h46-xxgg-f9q8.json | 36 ++++++++++++ .../GHSA-7hc9-vjg2-vpcr.json | 36 ++++++++++++ .../GHSA-7j9v-mc62-mcm5.json | 36 ++++++++++++ .../GHSA-7qq7-pvm9-x8rf.json | 36 ++++++++++++ .../GHSA-7rxf-gvfg-47g4.json | 36 ++++++++++++ .../GHSA-7v2w-h4gh-w5cv.json | 36 ++++++++++++ .../GHSA-7xmc-vhjp-qv5q.json | 36 ++++++++++++ .../GHSA-823j-2wj6-7jwh.json | 40 +++++++++++++ .../GHSA-82mg-566w-vpxp.json | 36 ++++++++++++ .../GHSA-85ff-r9hw-4grc.json | 40 +++++++++++++ .../GHSA-85jc-8h5p-8vw8.json | 36 ++++++++++++ .../GHSA-873w-8cph-rghj.json | 36 ++++++++++++ .../GHSA-879v-fggm-vxw2.json | 36 ++++++++++++ .../GHSA-89qx-m49c-8crf.json | 36 ++++++++++++ .../GHSA-8f78-f6p2-mjw7.json | 40 +++++++++++++ .../GHSA-8fw3-c8jq-g74q.json | 36 ++++++++++++ .../GHSA-8gfh-hxjj-c33j.json | 40 +++++++++++++ .../GHSA-8jhr-8vq6-2gp8.json | 40 +++++++++++++ .../GHSA-8pwp-phcg-h36g.json | 36 ++++++++++++ .../GHSA-8q24-hc9h-h952.json | 36 ++++++++++++ .../GHSA-8qff-6gwc-wph3.json | 36 ++++++++++++ .../GHSA-8v6j-vg6w-6wwj.json | 36 ++++++++++++ .../GHSA-8vgw-p6qm-5gr7.json | 34 +++++++++++ .../GHSA-8vjh-pxfw-4fqm.json | 36 ++++++++++++ .../GHSA-93qj-49fq-62jp.json | 36 ++++++++++++ .../GHSA-959v-wfjp-7c37.json | 36 ++++++++++++ .../GHSA-969w-gqqr-g6j3.json | 40 +++++++++++++ .../GHSA-96mw-rfcv-484q.json | 36 ++++++++++++ .../GHSA-96w2-hg6w-6xv2.json | 36 ++++++++++++ .../GHSA-97pg-wr4r-53wr.json | 36 ++++++++++++ .../GHSA-98fp-7v67-4v3q.json | 36 ++++++++++++ .../GHSA-9g44-gwvm-hc44.json | 36 ++++++++++++ .../GHSA-9gcr-28rp-cc24.json | 36 ++++++++++++ .../GHSA-9mhf-9hxp-8j3m.json | 36 ++++++++++++ .../GHSA-9vf8-xgwm-97r8.json | 36 ++++++++++++ .../GHSA-9vwq-rwcj-cmcg.json | 36 ++++++++++++ .../GHSA-9w5h-67gf-xvv8.json | 36 ++++++++++++ .../GHSA-9xvx-2953-c58g.json | 40 +++++++++++++ .../GHSA-c2qr-w9p6-cxgr.json | 40 +++++++++++++ .../GHSA-c2xf-763v-3rqh.json | 36 ++++++++++++ .../GHSA-c39q-wr4f-xpw7.json | 48 ++++++++++++++++ .../GHSA-c4cc-w454-4634.json | 36 ++++++++++++ .../GHSA-c7fq-p62p-wvpc.json | 36 ++++++++++++ .../GHSA-c85g-5883-vjj7.json | 36 ++++++++++++ .../GHSA-cfc5-c899-6ww2.json | 36 ++++++++++++ .../GHSA-cfvq-fj53-j2c7.json | 36 ++++++++++++ .../GHSA-cg4p-5qfm-pjjj.json | 36 ++++++++++++ .../GHSA-chf7-q7m5-fq92.json | 36 ++++++++++++ .../GHSA-cj47-qj6g-x7r4.json | 36 ++++++++++++ .../GHSA-cjjc-mf84-xp9f.json | 40 +++++++++++++ .../GHSA-cppx-6f25-3qxc.json | 36 ++++++++++++ .../GHSA-crh6-pj8c-xrhc.json | 36 ++++++++++++ .../GHSA-cvg9-334x-w586.json | 36 ++++++++++++ .../GHSA-cwc2-3f9g-phm3.json | 36 ++++++++++++ .../GHSA-cx66-wgv6-fpfh.json | 36 ++++++++++++ .../GHSA-f2v6-7vxr-j9g8.json | 36 ++++++++++++ .../GHSA-f3v2-jc5f-6328.json | 36 ++++++++++++ .../GHSA-f4hc-q562-cc5r.json | 36 ++++++++++++ .../GHSA-f64v-mwpx-gv6x.json | 36 ++++++++++++ .../GHSA-f6rh-g2v9-v6qp.json | 40 +++++++++++++ .../GHSA-fccc-8m69-8r78.json | 36 ++++++++++++ .../GHSA-ff5c-56m7-vc75.json | 36 ++++++++++++ .../GHSA-ffh5-w482-c7m5.json | 36 ++++++++++++ .../GHSA-fgqc-p7g9-x92w.json | 36 ++++++++++++ .../GHSA-fh2c-86xm-pm2x.json | 36 ++++++++++++ .../GHSA-fhfg-frx8-7458.json | 36 ++++++++++++ .../GHSA-fjcf-3j3r-78rp.json | 40 +++++++++++++ .../GHSA-fm93-g6xp-35xq.json | 36 ++++++++++++ .../GHSA-fqr7-jjqq-hpr6.json | 40 +++++++++++++ .../GHSA-fx47-jpv9-7hxr.json | 36 ++++++++++++ .../GHSA-fxpx-7wrq-8ggp.json | 40 +++++++++++++ .../GHSA-g394-qpx6-x7rr.json | 36 ++++++++++++ .../GHSA-g3mx-83mp-3rwc.json | 36 ++++++++++++ .../GHSA-g3p7-f346-26m6.json | 36 ++++++++++++ .../GHSA-g3v3-r244-mhhm.json | 36 ++++++++++++ .../GHSA-g44m-hpf4-vmrp.json | 36 ++++++++++++ .../GHSA-g48v-3p35-88jr.json | 36 ++++++++++++ .../GHSA-g5pg-73fc-hjwq.json | 40 +++++++++++++ .../GHSA-g9c4-qhpw-x7pw.json | 52 +++++++++++++++++ .../GHSA-gc79-m262-q226.json | 36 ++++++++++++ .../GHSA-gf99-rrrr-wjqh.json | 40 +++++++++++++ .../GHSA-gg5q-w3xv-q3f4.json | 48 ++++++++++++++++ .../GHSA-gggj-77q9-hf6x.json | 36 ++++++++++++ .../GHSA-gh22-g6w4-m562.json | 36 ++++++++++++ .../GHSA-gj27-76gq-5v3p.json | 36 ++++++++++++ .../GHSA-gjxm-x497-4h6h.json | 40 +++++++++++++ .../GHSA-gmqg-7635-v6cj.json | 40 +++++++++++++ .../GHSA-grjq-mg5m-r4jj.json | 36 ++++++++++++ .../GHSA-gv26-qw3h-8qvp.json | 36 ++++++++++++ .../GHSA-gvmg-6fvg-2jp2.json | 40 +++++++++++++ .../GHSA-gw2q-qw9j-rgv7.json | 40 +++++++++++++ .../GHSA-h254-g997-685c.json | 36 ++++++++++++ .../GHSA-h35f-g2pq-8xq7.json | 36 ++++++++++++ .../GHSA-h36j-8vv3-cj52.json | 36 ++++++++++++ .../GHSA-h4p8-798h-26f4.json | 36 ++++++++++++ .../GHSA-h4x7-365q-3rm3.json | 36 ++++++++++++ .../GHSA-h5h7-gc2g-vq79.json | 40 +++++++++++++ .../GHSA-h5jv-6xg2-9cv8.json | 40 +++++++++++++ .../GHSA-h5p2-273c-rxjp.json | 40 +++++++++++++ .../GHSA-h7xg-cmpp-48hf.json | 40 +++++++++++++ .../GHSA-h9jx-rcv4-cgqg.json | 36 ++++++++++++ .../GHSA-h9m7-c24m-gqr9.json | 36 ++++++++++++ .../GHSA-hc5x-x2vx-497g.json | 36 ++++++++++++ .../GHSA-hc9x-f65g-gjqh.json | 36 ++++++++++++ .../GHSA-hh3j-9m59-p8vc.json | 36 ++++++++++++ .../GHSA-hhr6-7642-8pmh.json | 36 ++++++++++++ .../GHSA-hhw5-29f6-hf4x.json | 36 ++++++++++++ .../GHSA-hjcr-w68h-rg2p.json | 36 ++++++++++++ .../GHSA-hm5x-x82r-982c.json | 36 ++++++++++++ .../GHSA-hq38-64gm-3w2c.json | 40 +++++++++++++ .../GHSA-hw3w-6mhf-rh8m.json | 36 ++++++++++++ .../GHSA-hw8j-hw49-752c.json | 36 ++++++++++++ .../GHSA-hx67-j5pj-h8ch.json | 40 +++++++++++++ .../GHSA-j274-m559-cj4j.json | 36 ++++++++++++ .../GHSA-j3jw-5w88-cqxr.json | 40 +++++++++++++ .../GHSA-j3wr-m6xh-64hg.json | 40 +++++++++++++ .../GHSA-j46h-c723-q9rm.json | 56 +++++++++++++++++++ .../GHSA-j4mc-gwfc-jcf5.json | 40 +++++++++++++ .../GHSA-j5fq-p3c6-93jm.json | 40 +++++++++++++ .../GHSA-j5qj-rg5j-j7c2.json | 36 ++++++++++++ .../GHSA-j8gf-4j8g-8mvp.json | 36 ++++++++++++ .../GHSA-j8x9-qc9m-rmhj.json | 40 +++++++++++++ .../GHSA-j9g7-mqhh-9hxf.json | 36 ++++++++++++ .../GHSA-j9rw-qm5f-r8xm.json | 36 ++++++++++++ .../GHSA-jccx-m9v4-9hwh.json | 40 +++++++++++++ .../GHSA-jfm2-hq55-pxgq.json | 40 +++++++++++++ .../GHSA-jg5r-v2h9-wfxx.json | 40 +++++++++++++ .../GHSA-jjcv-gwx7-hcx9.json | 40 +++++++++++++ .../GHSA-jjhp-4v9p-5fv8.json | 36 ++++++++++++ .../GHSA-jjm2-vhrm-92vg.json | 36 ++++++++++++ .../GHSA-jm82-665g-74jp.json | 36 ++++++++++++ .../GHSA-jm87-8wm6-fr27.json | 36 ++++++++++++ .../GHSA-jmgm-gx32-vp4w.json | 40 +++++++++++++ .../GHSA-jqgv-3ch9-c9qv.json | 40 +++++++++++++ .../GHSA-jrhc-9qg9-4qfq.json | 36 ++++++++++++ .../GHSA-jrhv-8gfh-55w6.json | 48 ++++++++++++++++ .../GHSA-jv2r-r6r9-hvhj.json | 36 ++++++++++++ .../GHSA-jvpf-xf32-2w4q.json | 40 +++++++++++++ .../GHSA-jw8w-84x3-c2r9.json | 40 +++++++++++++ .../GHSA-jx9r-x782-9r4m.json | 36 ++++++++++++ .../GHSA-m2g8-2vhm-m4cx.json | 36 ++++++++++++ .../GHSA-m2gm-4vg9-pcc4.json | 36 ++++++++++++ .../GHSA-m2v2-9gxp-2r53.json | 36 ++++++++++++ .../GHSA-m37h-8r48-2cxj.json | 36 ++++++++++++ .../GHSA-m47g-ghr5-3734.json | 36 ++++++++++++ .../GHSA-m62f-m76v-gfwr.json | 36 ++++++++++++ .../GHSA-m724-88wc-fpgh.json | 36 ++++++++++++ .../GHSA-m724-hqmc-ggpx.json | 36 ++++++++++++ .../GHSA-m74w-gj86-32q9.json | 36 ++++++++++++ .../GHSA-m76r-xqqj-mqmv.json | 36 ++++++++++++ .../GHSA-mc9m-5hw4-g3g6.json | 36 ++++++++++++ .../GHSA-mf57-6hg5-mrvm.json | 36 ++++++++++++ .../GHSA-mhmr-w8pp-75w5.json | 40 +++++++++++++ .../GHSA-mj67-2mvx-f778.json | 40 +++++++++++++ .../GHSA-mjvp-pg3h-wh59.json | 40 +++++++++++++ .../GHSA-mq4w-5hp5-6g52.json | 40 +++++++++++++ .../GHSA-mq78-p977-pwgv.json | 36 ++++++++++++ .../GHSA-mq8r-j55w-fv46.json | 40 +++++++++++++ .../GHSA-mqp7-6vh9-99r6.json | 40 +++++++++++++ .../GHSA-mrhh-3ggq-23p2.json | 36 ++++++++++++ .../GHSA-mrvr-7493-pfq3.json | 36 ++++++++++++ .../GHSA-mvp8-9qgw-vf58.json | 36 ++++++++++++ .../GHSA-p2f3-rm9r-rxgj.json | 40 +++++++++++++ .../GHSA-p2vc-m5fv-9w9m.json | 36 ++++++++++++ .../GHSA-p2wh-w96x-w232.json | 36 ++++++++++++ .../GHSA-p5vx-9hj8-cf4h.json | 36 ++++++++++++ .../GHSA-p6h7-hfj2-vmcf.json | 36 ++++++++++++ .../GHSA-p6x3-v6g3-7557.json | 36 ++++++++++++ .../GHSA-p868-p9pj-fvmr.json | 40 +++++++++++++ .../GHSA-p926-8677-385w.json | 36 ++++++++++++ .../GHSA-pgfv-gvc5-prfg.json | 36 ++++++++++++ .../GHSA-pgr7-mhp5-fgjp.json | 36 ++++++++++++ .../GHSA-ph84-8v89-25q8.json | 36 ++++++++++++ .../GHSA-pqwr-phvv-v49f.json | 36 ++++++++++++ .../GHSA-prpg-p95c-32fv.json | 36 ++++++++++++ .../GHSA-prx2-6cc4-7qq5.json | 40 +++++++++++++ .../GHSA-q36w-fgp3-q2gw.json | 36 ++++++++++++ .../GHSA-q3gw-8236-5jw4.json | 36 ++++++++++++ .../GHSA-q5v7-7r3x-m7hg.json | 36 ++++++++++++ .../GHSA-q67c-vgg7-pvrq.json | 36 ++++++++++++ .../GHSA-q6gg-j289-2hm4.json | 36 ++++++++++++ .../GHSA-q73m-3cg7-m23w.json | 36 ++++++++++++ .../GHSA-q88j-ff64-2m3q.json | 36 ++++++++++++ .../GHSA-q8pp-mmm3-9j9w.json | 40 +++++++++++++ .../GHSA-qccg-9m4q-xfm6.json | 36 ++++++++++++ .../GHSA-qg86-f892-m4hj.json | 36 ++++++++++++ .../GHSA-qgm6-wj98-3qh4.json | 40 +++++++++++++ .../GHSA-qhfv-rxrj-6w5f.json | 36 ++++++++++++ .../GHSA-qjq5-7g6p-p3vg.json | 40 +++++++++++++ .../GHSA-qv9p-39px-hfwc.json | 40 +++++++++++++ .../GHSA-qvg9-vp87-h3hr.json | 36 ++++++++++++ .../GHSA-r229-5wgf-f28g.json | 36 ++++++++++++ .../GHSA-r3hj-whx4-hvvj.json | 36 ++++++++++++ .../GHSA-r49j-4jpw-x35c.json | 36 ++++++++++++ .../GHSA-r4hm-vcvh-rm39.json | 36 ++++++++++++ .../GHSA-r9m5-fcw8-68f6.json | 40 +++++++++++++ .../GHSA-rc69-h6h5-3q4x.json | 36 ++++++++++++ .../GHSA-rm69-wvpv-r2w7.json | 36 ++++++++++++ .../GHSA-rqhc-x44r-f23j.json | 40 +++++++++++++ .../GHSA-rqrm-p43g-fpmq.json | 40 +++++++++++++ .../GHSA-rrfw-qqmx-gqwx.json | 40 +++++++++++++ .../GHSA-rv4f-crjq-xjf8.json | 36 ++++++++++++ .../GHSA-rvgh-pr46-x7gg.json | 36 ++++++++++++ .../GHSA-rvmr-crph-7vj2.json | 44 +++++++++++++++ .../GHSA-rxwh-3m8p-2qq5.json | 36 ++++++++++++ .../GHSA-v3f4-7pp9-6f99.json | 36 ++++++++++++ .../GHSA-v464-r2r9-www7.json | 36 ++++++++++++ .../GHSA-v5pj-jrpv-h6g2.json | 36 ++++++++++++ .../GHSA-v67x-89x7-mh47.json | 40 +++++++++++++ .../GHSA-vffc-qpx3-764c.json | 36 ++++++++++++ .../GHSA-vh85-qfmh-23mf.json | 40 +++++++++++++ .../GHSA-vhfq-gpqw-p5cw.json | 36 ++++++++++++ .../GHSA-vpg6-7cch-gq2j.json | 36 ++++++++++++ .../GHSA-vq2g-prvr-rgr4.json | 40 +++++++++++++ .../GHSA-vqqv-6pvc-4m7q.json | 40 +++++++++++++ .../GHSA-vrw3-r7jw-4785.json | 36 ++++++++++++ .../GHSA-vx9q-6hqp-j863.json | 40 +++++++++++++ .../GHSA-w3m9-crxx-972f.json | 36 ++++++++++++ .../GHSA-w466-2wfc-8g58.json | 36 ++++++++++++ .../GHSA-w4cv-4jm4-pg8h.json | 40 +++++++++++++ .../GHSA-w6hh-w36c-vxmw.json | 40 +++++++++++++ .../GHSA-w6r4-j5cm-c7fp.json | 40 +++++++++++++ .../GHSA-wcwp-9rcp-jvfg.json | 36 ++++++++++++ .../GHSA-wjpv-64v2-2qpq.json | 36 ++++++++++++ .../GHSA-wmc2-c6g2-9mf2.json | 36 ++++++++++++ .../GHSA-wr4v-pc76-3q4p.json | 40 +++++++++++++ .../GHSA-wwr9-4gmr-xvq9.json | 36 ++++++++++++ .../GHSA-wxpc-2674-rxvw.json | 36 ++++++++++++ .../GHSA-x2w2-frfv-4f2j.json | 40 +++++++++++++ .../GHSA-x48g-hm9c-ww42.json | 40 +++++++++++++ .../GHSA-x552-5vh8-qccx.json | 40 +++++++++++++ .../GHSA-x5xw-28w4-53j5.json | 36 ++++++++++++ .../GHSA-x757-hv69-jr45.json | 36 ++++++++++++ .../GHSA-x7c5-9r9g-pghj.json | 36 ++++++++++++ .../GHSA-x9hf-jr2h-w47p.json | 36 ++++++++++++ .../GHSA-xcp6-jv5m-jwrm.json | 40 +++++++++++++ .../GHSA-xfjg-gcvp-vw7p.json | 40 +++++++++++++ .../GHSA-xqgj-r6xv-9cw4.json | 36 ++++++++++++ .../GHSA-xv4c-2443-pc28.json | 36 ++++++++++++ .../GHSA-xx7c-j7h3-vjcq.json | 34 +++++++++++ 337 files changed, 12513 insertions(+), 6 deletions(-) create mode 100644 advisories/unreviewed/2025/03/GHSA-227r-w5j2-6243/GHSA-227r-w5j2-6243.json create mode 100644 advisories/unreviewed/2025/03/GHSA-22h9-9rvv-q9qg/GHSA-22h9-9rvv-q9qg.json create mode 100644 advisories/unreviewed/2025/03/GHSA-29rg-m5qv-57gx/GHSA-29rg-m5qv-57gx.json create mode 100644 advisories/unreviewed/2025/03/GHSA-2c36-wq4v-5v3h/GHSA-2c36-wq4v-5v3h.json create mode 100644 advisories/unreviewed/2025/03/GHSA-2mv8-c3hx-xq6v/GHSA-2mv8-c3hx-xq6v.json create mode 100644 advisories/unreviewed/2025/03/GHSA-2rr7-xrrm-67cf/GHSA-2rr7-xrrm-67cf.json create mode 100644 advisories/unreviewed/2025/03/GHSA-2w2q-qp7m-7wrh/GHSA-2w2q-qp7m-7wrh.json create mode 100644 advisories/unreviewed/2025/03/GHSA-2xcr-p767-f3rv/GHSA-2xcr-p767-f3rv.json create mode 100644 advisories/unreviewed/2025/03/GHSA-2xf2-gjm6-g2c6/GHSA-2xf2-gjm6-g2c6.json create mode 100644 advisories/unreviewed/2025/03/GHSA-3248-f932-c76p/GHSA-3248-f932-c76p.json create mode 100644 advisories/unreviewed/2025/03/GHSA-32g6-mg92-ghm2/GHSA-32g6-mg92-ghm2.json create mode 100644 advisories/unreviewed/2025/03/GHSA-332g-rf22-2vcg/GHSA-332g-rf22-2vcg.json create mode 100644 advisories/unreviewed/2025/03/GHSA-339r-cjv9-x78g/GHSA-339r-cjv9-x78g.json create mode 100644 advisories/unreviewed/2025/03/GHSA-34v4-5664-chqj/GHSA-34v4-5664-chqj.json create mode 100644 advisories/unreviewed/2025/03/GHSA-35p3-6j45-prwm/GHSA-35p3-6j45-prwm.json create mode 100644 advisories/unreviewed/2025/03/GHSA-38mg-wm59-g64x/GHSA-38mg-wm59-g64x.json create mode 100644 advisories/unreviewed/2025/03/GHSA-38r9-3j52-h92v/GHSA-38r9-3j52-h92v.json create mode 100644 advisories/unreviewed/2025/03/GHSA-3c45-rpmq-6gfj/GHSA-3c45-rpmq-6gfj.json create mode 100644 advisories/unreviewed/2025/03/GHSA-3j5r-3852-j63v/GHSA-3j5r-3852-j63v.json create mode 100644 advisories/unreviewed/2025/03/GHSA-3p9q-7w63-3f8q/GHSA-3p9q-7w63-3f8q.json create mode 100644 advisories/unreviewed/2025/03/GHSA-3ppw-4jp4-5852/GHSA-3ppw-4jp4-5852.json create mode 100644 advisories/unreviewed/2025/03/GHSA-3xq5-x4fj-rff7/GHSA-3xq5-x4fj-rff7.json create mode 100644 advisories/unreviewed/2025/03/GHSA-43g4-487m-5q6m/GHSA-43g4-487m-5q6m.json create mode 100644 advisories/unreviewed/2025/03/GHSA-43qf-4rqw-9q2g/GHSA-43qf-4rqw-9q2g.json create mode 100644 advisories/unreviewed/2025/03/GHSA-4452-rwq3-2x44/GHSA-4452-rwq3-2x44.json create mode 100644 advisories/unreviewed/2025/03/GHSA-44q8-52gx-27g8/GHSA-44q8-52gx-27g8.json create mode 100644 advisories/unreviewed/2025/03/GHSA-45p5-8q33-98hw/GHSA-45p5-8q33-98hw.json create mode 100644 advisories/unreviewed/2025/03/GHSA-47f6-5p7h-5f3h/GHSA-47f6-5p7h-5f3h.json create mode 100644 advisories/unreviewed/2025/03/GHSA-49m6-vrr9-2cqm/GHSA-49m6-vrr9-2cqm.json create mode 100644 advisories/unreviewed/2025/03/GHSA-49rx-72gp-wfgj/GHSA-49rx-72gp-wfgj.json create mode 100644 advisories/unreviewed/2025/03/GHSA-4cv3-v7pv-rfhf/GHSA-4cv3-v7pv-rfhf.json create mode 100644 advisories/unreviewed/2025/03/GHSA-4cxc-r29p-3327/GHSA-4cxc-r29p-3327.json create mode 100644 advisories/unreviewed/2025/03/GHSA-4f3h-89pj-w84f/GHSA-4f3h-89pj-w84f.json create mode 100644 advisories/unreviewed/2025/03/GHSA-4g3f-9mfg-xxgh/GHSA-4g3f-9mfg-xxgh.json create mode 100644 advisories/unreviewed/2025/03/GHSA-4jr8-64gc-wqqx/GHSA-4jr8-64gc-wqqx.json create mode 100644 advisories/unreviewed/2025/03/GHSA-4qcx-jx49-6qrh/GHSA-4qcx-jx49-6qrh.json create mode 100644 advisories/unreviewed/2025/03/GHSA-4rj2-9gcx-5qhx/GHSA-4rj2-9gcx-5qhx.json create mode 100644 advisories/unreviewed/2025/03/GHSA-4rqf-8pfm-p36r/GHSA-4rqf-8pfm-p36r.json create mode 100644 advisories/unreviewed/2025/03/GHSA-4v9f-r55g-g6hc/GHSA-4v9f-r55g-g6hc.json create mode 100644 advisories/unreviewed/2025/03/GHSA-4vm5-r6m3-2448/GHSA-4vm5-r6m3-2448.json create mode 100644 advisories/unreviewed/2025/03/GHSA-4vmg-rw8f-92f9/GHSA-4vmg-rw8f-92f9.json create mode 100644 advisories/unreviewed/2025/03/GHSA-4vqf-pwq6-3wh3/GHSA-4vqf-pwq6-3wh3.json create mode 100644 advisories/unreviewed/2025/03/GHSA-4w44-j4vc-r3rp/GHSA-4w44-j4vc-r3rp.json create mode 100644 advisories/unreviewed/2025/03/GHSA-4wfj-v7c8-rwh4/GHSA-4wfj-v7c8-rwh4.json create mode 100644 advisories/unreviewed/2025/03/GHSA-53gh-p8jc-7rg8/GHSA-53gh-p8jc-7rg8.json create mode 100644 advisories/unreviewed/2025/03/GHSA-54c7-72v9-gm27/GHSA-54c7-72v9-gm27.json create mode 100644 advisories/unreviewed/2025/03/GHSA-54hh-fh2m-4396/GHSA-54hh-fh2m-4396.json create mode 100644 advisories/unreviewed/2025/03/GHSA-564p-rx2q-4c8v/GHSA-564p-rx2q-4c8v.json create mode 100644 advisories/unreviewed/2025/03/GHSA-56p4-cfqw-jx4h/GHSA-56p4-cfqw-jx4h.json create mode 100644 advisories/unreviewed/2025/03/GHSA-5c8j-g96x-cj78/GHSA-5c8j-g96x-cj78.json create mode 100644 advisories/unreviewed/2025/03/GHSA-5ccf-884p-4jjq/GHSA-5ccf-884p-4jjq.json create mode 100644 advisories/unreviewed/2025/03/GHSA-5chr-fjjv-38qv/GHSA-5chr-fjjv-38qv.json create mode 100644 advisories/unreviewed/2025/03/GHSA-5cpq-9538-jm2j/GHSA-5cpq-9538-jm2j.json create mode 100644 advisories/unreviewed/2025/03/GHSA-5fhx-jcwv-9wjj/GHSA-5fhx-jcwv-9wjj.json create mode 100644 advisories/unreviewed/2025/03/GHSA-5jmj-h3c5-682w/GHSA-5jmj-h3c5-682w.json create mode 100644 advisories/unreviewed/2025/03/GHSA-5mh3-rhm7-jxx3/GHSA-5mh3-rhm7-jxx3.json create mode 100644 advisories/unreviewed/2025/03/GHSA-5pfw-4vjf-fvc9/GHSA-5pfw-4vjf-fvc9.json create mode 100644 advisories/unreviewed/2025/03/GHSA-5v9m-57mq-qc75/GHSA-5v9m-57mq-qc75.json create mode 100644 advisories/unreviewed/2025/03/GHSA-5vqr-wprc-cpp7/GHSA-5vqr-wprc-cpp7.json create mode 100644 advisories/unreviewed/2025/03/GHSA-5xg7-5662-8x7j/GHSA-5xg7-5662-8x7j.json create mode 100644 advisories/unreviewed/2025/03/GHSA-62xp-4pcv-pw3j/GHSA-62xp-4pcv-pw3j.json create mode 100644 advisories/unreviewed/2025/03/GHSA-63gf-x2fr-8r32/GHSA-63gf-x2fr-8r32.json create mode 100644 advisories/unreviewed/2025/03/GHSA-64c5-jj57-f29g/GHSA-64c5-jj57-f29g.json create mode 100644 advisories/unreviewed/2025/03/GHSA-64jp-4xjj-prcw/GHSA-64jp-4xjj-prcw.json create mode 100644 advisories/unreviewed/2025/03/GHSA-67hg-xcw3-33fm/GHSA-67hg-xcw3-33fm.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6827-g8xf-36c7/GHSA-6827-g8xf-36c7.json create mode 100644 advisories/unreviewed/2025/03/GHSA-69j6-4w2p-2887/GHSA-69j6-4w2p-2887.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6ch3-c5vc-j2r6/GHSA-6ch3-c5vc-j2r6.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6f6x-f56q-5xgv/GHSA-6f6x-f56q-5xgv.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6fwx-j832-vvw6/GHSA-6fwx-j832-vvw6.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6gmf-2369-c76c/GHSA-6gmf-2369-c76c.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6mf6-7j75-2m6f/GHSA-6mf6-7j75-2m6f.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6pvw-p9fg-rwxj/GHSA-6pvw-p9fg-rwxj.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6rvg-6v2m-4j46/GHSA-6rvg-6v2m-4j46.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6v28-q95m-93qr/GHSA-6v28-q95m-93qr.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6vmm-pmxf-9784/GHSA-6vmm-pmxf-9784.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6w2c-f4vg-j9hv/GHSA-6w2c-f4vg-j9hv.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6w62-3jvj-mfj6/GHSA-6w62-3jvj-mfj6.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6w7p-xrvp-p7xv/GHSA-6w7p-xrvp-p7xv.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6wj5-5pgr-jwq8/GHSA-6wj5-5pgr-jwq8.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6xgj-c5fx-5v57/GHSA-6xgj-c5fx-5v57.json create mode 100644 advisories/unreviewed/2025/03/GHSA-726r-vfh2-3vvj/GHSA-726r-vfh2-3vvj.json create mode 100644 advisories/unreviewed/2025/03/GHSA-73c8-qmph-r39f/GHSA-73c8-qmph-r39f.json create mode 100644 advisories/unreviewed/2025/03/GHSA-73p4-hh43-4h48/GHSA-73p4-hh43-4h48.json create mode 100644 advisories/unreviewed/2025/03/GHSA-745f-48gc-258q/GHSA-745f-48gc-258q.json create mode 100644 advisories/unreviewed/2025/03/GHSA-747f-ww56-4q4h/GHSA-747f-ww56-4q4h.json create mode 100644 advisories/unreviewed/2025/03/GHSA-749v-xf6w-5wcx/GHSA-749v-xf6w-5wcx.json create mode 100644 advisories/unreviewed/2025/03/GHSA-75px-35p4-qq6h/GHSA-75px-35p4-qq6h.json create mode 100644 advisories/unreviewed/2025/03/GHSA-75v5-6885-59f9/GHSA-75v5-6885-59f9.json create mode 100644 advisories/unreviewed/2025/03/GHSA-775f-24cq-qg6p/GHSA-775f-24cq-qg6p.json create mode 100644 advisories/unreviewed/2025/03/GHSA-77cj-rv5x-v6r2/GHSA-77cj-rv5x-v6r2.json create mode 100644 advisories/unreviewed/2025/03/GHSA-79rp-v9rm-gxm8/GHSA-79rp-v9rm-gxm8.json create mode 100644 advisories/unreviewed/2025/03/GHSA-7g3f-q846-q9hx/GHSA-7g3f-q846-q9hx.json create mode 100644 advisories/unreviewed/2025/03/GHSA-7gj6-22m4-qfhx/GHSA-7gj6-22m4-qfhx.json create mode 100644 advisories/unreviewed/2025/03/GHSA-7h46-xxgg-f9q8/GHSA-7h46-xxgg-f9q8.json create mode 100644 advisories/unreviewed/2025/03/GHSA-7hc9-vjg2-vpcr/GHSA-7hc9-vjg2-vpcr.json create mode 100644 advisories/unreviewed/2025/03/GHSA-7j9v-mc62-mcm5/GHSA-7j9v-mc62-mcm5.json create mode 100644 advisories/unreviewed/2025/03/GHSA-7qq7-pvm9-x8rf/GHSA-7qq7-pvm9-x8rf.json create mode 100644 advisories/unreviewed/2025/03/GHSA-7rxf-gvfg-47g4/GHSA-7rxf-gvfg-47g4.json create mode 100644 advisories/unreviewed/2025/03/GHSA-7v2w-h4gh-w5cv/GHSA-7v2w-h4gh-w5cv.json create mode 100644 advisories/unreviewed/2025/03/GHSA-7xmc-vhjp-qv5q/GHSA-7xmc-vhjp-qv5q.json create mode 100644 advisories/unreviewed/2025/03/GHSA-823j-2wj6-7jwh/GHSA-823j-2wj6-7jwh.json create mode 100644 advisories/unreviewed/2025/03/GHSA-82mg-566w-vpxp/GHSA-82mg-566w-vpxp.json create mode 100644 advisories/unreviewed/2025/03/GHSA-85ff-r9hw-4grc/GHSA-85ff-r9hw-4grc.json create mode 100644 advisories/unreviewed/2025/03/GHSA-85jc-8h5p-8vw8/GHSA-85jc-8h5p-8vw8.json create mode 100644 advisories/unreviewed/2025/03/GHSA-873w-8cph-rghj/GHSA-873w-8cph-rghj.json create mode 100644 advisories/unreviewed/2025/03/GHSA-879v-fggm-vxw2/GHSA-879v-fggm-vxw2.json create mode 100644 advisories/unreviewed/2025/03/GHSA-89qx-m49c-8crf/GHSA-89qx-m49c-8crf.json create mode 100644 advisories/unreviewed/2025/03/GHSA-8f78-f6p2-mjw7/GHSA-8f78-f6p2-mjw7.json create mode 100644 advisories/unreviewed/2025/03/GHSA-8fw3-c8jq-g74q/GHSA-8fw3-c8jq-g74q.json create mode 100644 advisories/unreviewed/2025/03/GHSA-8gfh-hxjj-c33j/GHSA-8gfh-hxjj-c33j.json create mode 100644 advisories/unreviewed/2025/03/GHSA-8jhr-8vq6-2gp8/GHSA-8jhr-8vq6-2gp8.json create mode 100644 advisories/unreviewed/2025/03/GHSA-8pwp-phcg-h36g/GHSA-8pwp-phcg-h36g.json create mode 100644 advisories/unreviewed/2025/03/GHSA-8q24-hc9h-h952/GHSA-8q24-hc9h-h952.json create mode 100644 advisories/unreviewed/2025/03/GHSA-8qff-6gwc-wph3/GHSA-8qff-6gwc-wph3.json create mode 100644 advisories/unreviewed/2025/03/GHSA-8v6j-vg6w-6wwj/GHSA-8v6j-vg6w-6wwj.json create mode 100644 advisories/unreviewed/2025/03/GHSA-8vgw-p6qm-5gr7/GHSA-8vgw-p6qm-5gr7.json create mode 100644 advisories/unreviewed/2025/03/GHSA-8vjh-pxfw-4fqm/GHSA-8vjh-pxfw-4fqm.json create mode 100644 advisories/unreviewed/2025/03/GHSA-93qj-49fq-62jp/GHSA-93qj-49fq-62jp.json create mode 100644 advisories/unreviewed/2025/03/GHSA-959v-wfjp-7c37/GHSA-959v-wfjp-7c37.json create mode 100644 advisories/unreviewed/2025/03/GHSA-969w-gqqr-g6j3/GHSA-969w-gqqr-g6j3.json create mode 100644 advisories/unreviewed/2025/03/GHSA-96mw-rfcv-484q/GHSA-96mw-rfcv-484q.json create mode 100644 advisories/unreviewed/2025/03/GHSA-96w2-hg6w-6xv2/GHSA-96w2-hg6w-6xv2.json create mode 100644 advisories/unreviewed/2025/03/GHSA-97pg-wr4r-53wr/GHSA-97pg-wr4r-53wr.json create mode 100644 advisories/unreviewed/2025/03/GHSA-98fp-7v67-4v3q/GHSA-98fp-7v67-4v3q.json create mode 100644 advisories/unreviewed/2025/03/GHSA-9g44-gwvm-hc44/GHSA-9g44-gwvm-hc44.json create mode 100644 advisories/unreviewed/2025/03/GHSA-9gcr-28rp-cc24/GHSA-9gcr-28rp-cc24.json create mode 100644 advisories/unreviewed/2025/03/GHSA-9mhf-9hxp-8j3m/GHSA-9mhf-9hxp-8j3m.json create mode 100644 advisories/unreviewed/2025/03/GHSA-9vf8-xgwm-97r8/GHSA-9vf8-xgwm-97r8.json create mode 100644 advisories/unreviewed/2025/03/GHSA-9vwq-rwcj-cmcg/GHSA-9vwq-rwcj-cmcg.json create mode 100644 advisories/unreviewed/2025/03/GHSA-9w5h-67gf-xvv8/GHSA-9w5h-67gf-xvv8.json create mode 100644 advisories/unreviewed/2025/03/GHSA-9xvx-2953-c58g/GHSA-9xvx-2953-c58g.json create mode 100644 advisories/unreviewed/2025/03/GHSA-c2qr-w9p6-cxgr/GHSA-c2qr-w9p6-cxgr.json create mode 100644 advisories/unreviewed/2025/03/GHSA-c2xf-763v-3rqh/GHSA-c2xf-763v-3rqh.json create mode 100644 advisories/unreviewed/2025/03/GHSA-c39q-wr4f-xpw7/GHSA-c39q-wr4f-xpw7.json create mode 100644 advisories/unreviewed/2025/03/GHSA-c4cc-w454-4634/GHSA-c4cc-w454-4634.json create mode 100644 advisories/unreviewed/2025/03/GHSA-c7fq-p62p-wvpc/GHSA-c7fq-p62p-wvpc.json create mode 100644 advisories/unreviewed/2025/03/GHSA-c85g-5883-vjj7/GHSA-c85g-5883-vjj7.json create mode 100644 advisories/unreviewed/2025/03/GHSA-cfc5-c899-6ww2/GHSA-cfc5-c899-6ww2.json create mode 100644 advisories/unreviewed/2025/03/GHSA-cfvq-fj53-j2c7/GHSA-cfvq-fj53-j2c7.json create mode 100644 advisories/unreviewed/2025/03/GHSA-cg4p-5qfm-pjjj/GHSA-cg4p-5qfm-pjjj.json create mode 100644 advisories/unreviewed/2025/03/GHSA-chf7-q7m5-fq92/GHSA-chf7-q7m5-fq92.json create mode 100644 advisories/unreviewed/2025/03/GHSA-cj47-qj6g-x7r4/GHSA-cj47-qj6g-x7r4.json create mode 100644 advisories/unreviewed/2025/03/GHSA-cjjc-mf84-xp9f/GHSA-cjjc-mf84-xp9f.json create mode 100644 advisories/unreviewed/2025/03/GHSA-cppx-6f25-3qxc/GHSA-cppx-6f25-3qxc.json create mode 100644 advisories/unreviewed/2025/03/GHSA-crh6-pj8c-xrhc/GHSA-crh6-pj8c-xrhc.json create mode 100644 advisories/unreviewed/2025/03/GHSA-cvg9-334x-w586/GHSA-cvg9-334x-w586.json create mode 100644 advisories/unreviewed/2025/03/GHSA-cwc2-3f9g-phm3/GHSA-cwc2-3f9g-phm3.json create mode 100644 advisories/unreviewed/2025/03/GHSA-cx66-wgv6-fpfh/GHSA-cx66-wgv6-fpfh.json create mode 100644 advisories/unreviewed/2025/03/GHSA-f2v6-7vxr-j9g8/GHSA-f2v6-7vxr-j9g8.json create mode 100644 advisories/unreviewed/2025/03/GHSA-f3v2-jc5f-6328/GHSA-f3v2-jc5f-6328.json create mode 100644 advisories/unreviewed/2025/03/GHSA-f4hc-q562-cc5r/GHSA-f4hc-q562-cc5r.json create mode 100644 advisories/unreviewed/2025/03/GHSA-f64v-mwpx-gv6x/GHSA-f64v-mwpx-gv6x.json create mode 100644 advisories/unreviewed/2025/03/GHSA-f6rh-g2v9-v6qp/GHSA-f6rh-g2v9-v6qp.json create mode 100644 advisories/unreviewed/2025/03/GHSA-fccc-8m69-8r78/GHSA-fccc-8m69-8r78.json create mode 100644 advisories/unreviewed/2025/03/GHSA-ff5c-56m7-vc75/GHSA-ff5c-56m7-vc75.json create mode 100644 advisories/unreviewed/2025/03/GHSA-ffh5-w482-c7m5/GHSA-ffh5-w482-c7m5.json create mode 100644 advisories/unreviewed/2025/03/GHSA-fgqc-p7g9-x92w/GHSA-fgqc-p7g9-x92w.json create mode 100644 advisories/unreviewed/2025/03/GHSA-fh2c-86xm-pm2x/GHSA-fh2c-86xm-pm2x.json create mode 100644 advisories/unreviewed/2025/03/GHSA-fhfg-frx8-7458/GHSA-fhfg-frx8-7458.json create mode 100644 advisories/unreviewed/2025/03/GHSA-fjcf-3j3r-78rp/GHSA-fjcf-3j3r-78rp.json create mode 100644 advisories/unreviewed/2025/03/GHSA-fm93-g6xp-35xq/GHSA-fm93-g6xp-35xq.json create mode 100644 advisories/unreviewed/2025/03/GHSA-fqr7-jjqq-hpr6/GHSA-fqr7-jjqq-hpr6.json create mode 100644 advisories/unreviewed/2025/03/GHSA-fx47-jpv9-7hxr/GHSA-fx47-jpv9-7hxr.json create mode 100644 advisories/unreviewed/2025/03/GHSA-fxpx-7wrq-8ggp/GHSA-fxpx-7wrq-8ggp.json create mode 100644 advisories/unreviewed/2025/03/GHSA-g394-qpx6-x7rr/GHSA-g394-qpx6-x7rr.json create mode 100644 advisories/unreviewed/2025/03/GHSA-g3mx-83mp-3rwc/GHSA-g3mx-83mp-3rwc.json create mode 100644 advisories/unreviewed/2025/03/GHSA-g3p7-f346-26m6/GHSA-g3p7-f346-26m6.json create mode 100644 advisories/unreviewed/2025/03/GHSA-g3v3-r244-mhhm/GHSA-g3v3-r244-mhhm.json create mode 100644 advisories/unreviewed/2025/03/GHSA-g44m-hpf4-vmrp/GHSA-g44m-hpf4-vmrp.json create mode 100644 advisories/unreviewed/2025/03/GHSA-g48v-3p35-88jr/GHSA-g48v-3p35-88jr.json create mode 100644 advisories/unreviewed/2025/03/GHSA-g5pg-73fc-hjwq/GHSA-g5pg-73fc-hjwq.json create mode 100644 advisories/unreviewed/2025/03/GHSA-g9c4-qhpw-x7pw/GHSA-g9c4-qhpw-x7pw.json create mode 100644 advisories/unreviewed/2025/03/GHSA-gc79-m262-q226/GHSA-gc79-m262-q226.json create mode 100644 advisories/unreviewed/2025/03/GHSA-gf99-rrrr-wjqh/GHSA-gf99-rrrr-wjqh.json create mode 100644 advisories/unreviewed/2025/03/GHSA-gg5q-w3xv-q3f4/GHSA-gg5q-w3xv-q3f4.json create mode 100644 advisories/unreviewed/2025/03/GHSA-gggj-77q9-hf6x/GHSA-gggj-77q9-hf6x.json create mode 100644 advisories/unreviewed/2025/03/GHSA-gh22-g6w4-m562/GHSA-gh22-g6w4-m562.json create mode 100644 advisories/unreviewed/2025/03/GHSA-gj27-76gq-5v3p/GHSA-gj27-76gq-5v3p.json create mode 100644 advisories/unreviewed/2025/03/GHSA-gjxm-x497-4h6h/GHSA-gjxm-x497-4h6h.json create mode 100644 advisories/unreviewed/2025/03/GHSA-gmqg-7635-v6cj/GHSA-gmqg-7635-v6cj.json create mode 100644 advisories/unreviewed/2025/03/GHSA-grjq-mg5m-r4jj/GHSA-grjq-mg5m-r4jj.json create mode 100644 advisories/unreviewed/2025/03/GHSA-gv26-qw3h-8qvp/GHSA-gv26-qw3h-8qvp.json create mode 100644 advisories/unreviewed/2025/03/GHSA-gvmg-6fvg-2jp2/GHSA-gvmg-6fvg-2jp2.json create mode 100644 advisories/unreviewed/2025/03/GHSA-gw2q-qw9j-rgv7/GHSA-gw2q-qw9j-rgv7.json create mode 100644 advisories/unreviewed/2025/03/GHSA-h254-g997-685c/GHSA-h254-g997-685c.json create mode 100644 advisories/unreviewed/2025/03/GHSA-h35f-g2pq-8xq7/GHSA-h35f-g2pq-8xq7.json create mode 100644 advisories/unreviewed/2025/03/GHSA-h36j-8vv3-cj52/GHSA-h36j-8vv3-cj52.json create mode 100644 advisories/unreviewed/2025/03/GHSA-h4p8-798h-26f4/GHSA-h4p8-798h-26f4.json create mode 100644 advisories/unreviewed/2025/03/GHSA-h4x7-365q-3rm3/GHSA-h4x7-365q-3rm3.json create mode 100644 advisories/unreviewed/2025/03/GHSA-h5h7-gc2g-vq79/GHSA-h5h7-gc2g-vq79.json create mode 100644 advisories/unreviewed/2025/03/GHSA-h5jv-6xg2-9cv8/GHSA-h5jv-6xg2-9cv8.json create mode 100644 advisories/unreviewed/2025/03/GHSA-h5p2-273c-rxjp/GHSA-h5p2-273c-rxjp.json create mode 100644 advisories/unreviewed/2025/03/GHSA-h7xg-cmpp-48hf/GHSA-h7xg-cmpp-48hf.json create mode 100644 advisories/unreviewed/2025/03/GHSA-h9jx-rcv4-cgqg/GHSA-h9jx-rcv4-cgqg.json create mode 100644 advisories/unreviewed/2025/03/GHSA-h9m7-c24m-gqr9/GHSA-h9m7-c24m-gqr9.json create mode 100644 advisories/unreviewed/2025/03/GHSA-hc5x-x2vx-497g/GHSA-hc5x-x2vx-497g.json create mode 100644 advisories/unreviewed/2025/03/GHSA-hc9x-f65g-gjqh/GHSA-hc9x-f65g-gjqh.json create mode 100644 advisories/unreviewed/2025/03/GHSA-hh3j-9m59-p8vc/GHSA-hh3j-9m59-p8vc.json create mode 100644 advisories/unreviewed/2025/03/GHSA-hhr6-7642-8pmh/GHSA-hhr6-7642-8pmh.json create mode 100644 advisories/unreviewed/2025/03/GHSA-hhw5-29f6-hf4x/GHSA-hhw5-29f6-hf4x.json create mode 100644 advisories/unreviewed/2025/03/GHSA-hjcr-w68h-rg2p/GHSA-hjcr-w68h-rg2p.json create mode 100644 advisories/unreviewed/2025/03/GHSA-hm5x-x82r-982c/GHSA-hm5x-x82r-982c.json create mode 100644 advisories/unreviewed/2025/03/GHSA-hq38-64gm-3w2c/GHSA-hq38-64gm-3w2c.json create mode 100644 advisories/unreviewed/2025/03/GHSA-hw3w-6mhf-rh8m/GHSA-hw3w-6mhf-rh8m.json create mode 100644 advisories/unreviewed/2025/03/GHSA-hw8j-hw49-752c/GHSA-hw8j-hw49-752c.json create mode 100644 advisories/unreviewed/2025/03/GHSA-hx67-j5pj-h8ch/GHSA-hx67-j5pj-h8ch.json create mode 100644 advisories/unreviewed/2025/03/GHSA-j274-m559-cj4j/GHSA-j274-m559-cj4j.json create mode 100644 advisories/unreviewed/2025/03/GHSA-j3jw-5w88-cqxr/GHSA-j3jw-5w88-cqxr.json create mode 100644 advisories/unreviewed/2025/03/GHSA-j3wr-m6xh-64hg/GHSA-j3wr-m6xh-64hg.json create mode 100644 advisories/unreviewed/2025/03/GHSA-j46h-c723-q9rm/GHSA-j46h-c723-q9rm.json create mode 100644 advisories/unreviewed/2025/03/GHSA-j4mc-gwfc-jcf5/GHSA-j4mc-gwfc-jcf5.json create mode 100644 advisories/unreviewed/2025/03/GHSA-j5fq-p3c6-93jm/GHSA-j5fq-p3c6-93jm.json create mode 100644 advisories/unreviewed/2025/03/GHSA-j5qj-rg5j-j7c2/GHSA-j5qj-rg5j-j7c2.json create mode 100644 advisories/unreviewed/2025/03/GHSA-j8gf-4j8g-8mvp/GHSA-j8gf-4j8g-8mvp.json create mode 100644 advisories/unreviewed/2025/03/GHSA-j8x9-qc9m-rmhj/GHSA-j8x9-qc9m-rmhj.json create mode 100644 advisories/unreviewed/2025/03/GHSA-j9g7-mqhh-9hxf/GHSA-j9g7-mqhh-9hxf.json create mode 100644 advisories/unreviewed/2025/03/GHSA-j9rw-qm5f-r8xm/GHSA-j9rw-qm5f-r8xm.json create mode 100644 advisories/unreviewed/2025/03/GHSA-jccx-m9v4-9hwh/GHSA-jccx-m9v4-9hwh.json create mode 100644 advisories/unreviewed/2025/03/GHSA-jfm2-hq55-pxgq/GHSA-jfm2-hq55-pxgq.json create mode 100644 advisories/unreviewed/2025/03/GHSA-jg5r-v2h9-wfxx/GHSA-jg5r-v2h9-wfxx.json create mode 100644 advisories/unreviewed/2025/03/GHSA-jjcv-gwx7-hcx9/GHSA-jjcv-gwx7-hcx9.json create mode 100644 advisories/unreviewed/2025/03/GHSA-jjhp-4v9p-5fv8/GHSA-jjhp-4v9p-5fv8.json create mode 100644 advisories/unreviewed/2025/03/GHSA-jjm2-vhrm-92vg/GHSA-jjm2-vhrm-92vg.json create mode 100644 advisories/unreviewed/2025/03/GHSA-jm82-665g-74jp/GHSA-jm82-665g-74jp.json create mode 100644 advisories/unreviewed/2025/03/GHSA-jm87-8wm6-fr27/GHSA-jm87-8wm6-fr27.json create mode 100644 advisories/unreviewed/2025/03/GHSA-jmgm-gx32-vp4w/GHSA-jmgm-gx32-vp4w.json create mode 100644 advisories/unreviewed/2025/03/GHSA-jqgv-3ch9-c9qv/GHSA-jqgv-3ch9-c9qv.json create mode 100644 advisories/unreviewed/2025/03/GHSA-jrhc-9qg9-4qfq/GHSA-jrhc-9qg9-4qfq.json create mode 100644 advisories/unreviewed/2025/03/GHSA-jrhv-8gfh-55w6/GHSA-jrhv-8gfh-55w6.json create mode 100644 advisories/unreviewed/2025/03/GHSA-jv2r-r6r9-hvhj/GHSA-jv2r-r6r9-hvhj.json create mode 100644 advisories/unreviewed/2025/03/GHSA-jvpf-xf32-2w4q/GHSA-jvpf-xf32-2w4q.json create mode 100644 advisories/unreviewed/2025/03/GHSA-jw8w-84x3-c2r9/GHSA-jw8w-84x3-c2r9.json create mode 100644 advisories/unreviewed/2025/03/GHSA-jx9r-x782-9r4m/GHSA-jx9r-x782-9r4m.json create mode 100644 advisories/unreviewed/2025/03/GHSA-m2g8-2vhm-m4cx/GHSA-m2g8-2vhm-m4cx.json create mode 100644 advisories/unreviewed/2025/03/GHSA-m2gm-4vg9-pcc4/GHSA-m2gm-4vg9-pcc4.json create mode 100644 advisories/unreviewed/2025/03/GHSA-m2v2-9gxp-2r53/GHSA-m2v2-9gxp-2r53.json create mode 100644 advisories/unreviewed/2025/03/GHSA-m37h-8r48-2cxj/GHSA-m37h-8r48-2cxj.json create mode 100644 advisories/unreviewed/2025/03/GHSA-m47g-ghr5-3734/GHSA-m47g-ghr5-3734.json create mode 100644 advisories/unreviewed/2025/03/GHSA-m62f-m76v-gfwr/GHSA-m62f-m76v-gfwr.json create mode 100644 advisories/unreviewed/2025/03/GHSA-m724-88wc-fpgh/GHSA-m724-88wc-fpgh.json create mode 100644 advisories/unreviewed/2025/03/GHSA-m724-hqmc-ggpx/GHSA-m724-hqmc-ggpx.json create mode 100644 advisories/unreviewed/2025/03/GHSA-m74w-gj86-32q9/GHSA-m74w-gj86-32q9.json create mode 100644 advisories/unreviewed/2025/03/GHSA-m76r-xqqj-mqmv/GHSA-m76r-xqqj-mqmv.json create mode 100644 advisories/unreviewed/2025/03/GHSA-mc9m-5hw4-g3g6/GHSA-mc9m-5hw4-g3g6.json create mode 100644 advisories/unreviewed/2025/03/GHSA-mf57-6hg5-mrvm/GHSA-mf57-6hg5-mrvm.json create mode 100644 advisories/unreviewed/2025/03/GHSA-mhmr-w8pp-75w5/GHSA-mhmr-w8pp-75w5.json create mode 100644 advisories/unreviewed/2025/03/GHSA-mj67-2mvx-f778/GHSA-mj67-2mvx-f778.json create mode 100644 advisories/unreviewed/2025/03/GHSA-mjvp-pg3h-wh59/GHSA-mjvp-pg3h-wh59.json create mode 100644 advisories/unreviewed/2025/03/GHSA-mq4w-5hp5-6g52/GHSA-mq4w-5hp5-6g52.json create mode 100644 advisories/unreviewed/2025/03/GHSA-mq78-p977-pwgv/GHSA-mq78-p977-pwgv.json create mode 100644 advisories/unreviewed/2025/03/GHSA-mq8r-j55w-fv46/GHSA-mq8r-j55w-fv46.json create mode 100644 advisories/unreviewed/2025/03/GHSA-mqp7-6vh9-99r6/GHSA-mqp7-6vh9-99r6.json create mode 100644 advisories/unreviewed/2025/03/GHSA-mrhh-3ggq-23p2/GHSA-mrhh-3ggq-23p2.json create mode 100644 advisories/unreviewed/2025/03/GHSA-mrvr-7493-pfq3/GHSA-mrvr-7493-pfq3.json create mode 100644 advisories/unreviewed/2025/03/GHSA-mvp8-9qgw-vf58/GHSA-mvp8-9qgw-vf58.json create mode 100644 advisories/unreviewed/2025/03/GHSA-p2f3-rm9r-rxgj/GHSA-p2f3-rm9r-rxgj.json create mode 100644 advisories/unreviewed/2025/03/GHSA-p2vc-m5fv-9w9m/GHSA-p2vc-m5fv-9w9m.json create mode 100644 advisories/unreviewed/2025/03/GHSA-p2wh-w96x-w232/GHSA-p2wh-w96x-w232.json create mode 100644 advisories/unreviewed/2025/03/GHSA-p5vx-9hj8-cf4h/GHSA-p5vx-9hj8-cf4h.json create mode 100644 advisories/unreviewed/2025/03/GHSA-p6h7-hfj2-vmcf/GHSA-p6h7-hfj2-vmcf.json create mode 100644 advisories/unreviewed/2025/03/GHSA-p6x3-v6g3-7557/GHSA-p6x3-v6g3-7557.json create mode 100644 advisories/unreviewed/2025/03/GHSA-p868-p9pj-fvmr/GHSA-p868-p9pj-fvmr.json create mode 100644 advisories/unreviewed/2025/03/GHSA-p926-8677-385w/GHSA-p926-8677-385w.json create mode 100644 advisories/unreviewed/2025/03/GHSA-pgfv-gvc5-prfg/GHSA-pgfv-gvc5-prfg.json create mode 100644 advisories/unreviewed/2025/03/GHSA-pgr7-mhp5-fgjp/GHSA-pgr7-mhp5-fgjp.json create mode 100644 advisories/unreviewed/2025/03/GHSA-ph84-8v89-25q8/GHSA-ph84-8v89-25q8.json create mode 100644 advisories/unreviewed/2025/03/GHSA-pqwr-phvv-v49f/GHSA-pqwr-phvv-v49f.json create mode 100644 advisories/unreviewed/2025/03/GHSA-prpg-p95c-32fv/GHSA-prpg-p95c-32fv.json create mode 100644 advisories/unreviewed/2025/03/GHSA-prx2-6cc4-7qq5/GHSA-prx2-6cc4-7qq5.json create mode 100644 advisories/unreviewed/2025/03/GHSA-q36w-fgp3-q2gw/GHSA-q36w-fgp3-q2gw.json create mode 100644 advisories/unreviewed/2025/03/GHSA-q3gw-8236-5jw4/GHSA-q3gw-8236-5jw4.json create mode 100644 advisories/unreviewed/2025/03/GHSA-q5v7-7r3x-m7hg/GHSA-q5v7-7r3x-m7hg.json create mode 100644 advisories/unreviewed/2025/03/GHSA-q67c-vgg7-pvrq/GHSA-q67c-vgg7-pvrq.json create mode 100644 advisories/unreviewed/2025/03/GHSA-q6gg-j289-2hm4/GHSA-q6gg-j289-2hm4.json create mode 100644 advisories/unreviewed/2025/03/GHSA-q73m-3cg7-m23w/GHSA-q73m-3cg7-m23w.json create mode 100644 advisories/unreviewed/2025/03/GHSA-q88j-ff64-2m3q/GHSA-q88j-ff64-2m3q.json create mode 100644 advisories/unreviewed/2025/03/GHSA-q8pp-mmm3-9j9w/GHSA-q8pp-mmm3-9j9w.json create mode 100644 advisories/unreviewed/2025/03/GHSA-qccg-9m4q-xfm6/GHSA-qccg-9m4q-xfm6.json create mode 100644 advisories/unreviewed/2025/03/GHSA-qg86-f892-m4hj/GHSA-qg86-f892-m4hj.json create mode 100644 advisories/unreviewed/2025/03/GHSA-qgm6-wj98-3qh4/GHSA-qgm6-wj98-3qh4.json create mode 100644 advisories/unreviewed/2025/03/GHSA-qhfv-rxrj-6w5f/GHSA-qhfv-rxrj-6w5f.json create mode 100644 advisories/unreviewed/2025/03/GHSA-qjq5-7g6p-p3vg/GHSA-qjq5-7g6p-p3vg.json create mode 100644 advisories/unreviewed/2025/03/GHSA-qv9p-39px-hfwc/GHSA-qv9p-39px-hfwc.json create mode 100644 advisories/unreviewed/2025/03/GHSA-qvg9-vp87-h3hr/GHSA-qvg9-vp87-h3hr.json create mode 100644 advisories/unreviewed/2025/03/GHSA-r229-5wgf-f28g/GHSA-r229-5wgf-f28g.json create mode 100644 advisories/unreviewed/2025/03/GHSA-r3hj-whx4-hvvj/GHSA-r3hj-whx4-hvvj.json create mode 100644 advisories/unreviewed/2025/03/GHSA-r49j-4jpw-x35c/GHSA-r49j-4jpw-x35c.json create mode 100644 advisories/unreviewed/2025/03/GHSA-r4hm-vcvh-rm39/GHSA-r4hm-vcvh-rm39.json create mode 100644 advisories/unreviewed/2025/03/GHSA-r9m5-fcw8-68f6/GHSA-r9m5-fcw8-68f6.json create mode 100644 advisories/unreviewed/2025/03/GHSA-rc69-h6h5-3q4x/GHSA-rc69-h6h5-3q4x.json create mode 100644 advisories/unreviewed/2025/03/GHSA-rm69-wvpv-r2w7/GHSA-rm69-wvpv-r2w7.json create mode 100644 advisories/unreviewed/2025/03/GHSA-rqhc-x44r-f23j/GHSA-rqhc-x44r-f23j.json create mode 100644 advisories/unreviewed/2025/03/GHSA-rqrm-p43g-fpmq/GHSA-rqrm-p43g-fpmq.json create mode 100644 advisories/unreviewed/2025/03/GHSA-rrfw-qqmx-gqwx/GHSA-rrfw-qqmx-gqwx.json create mode 100644 advisories/unreviewed/2025/03/GHSA-rv4f-crjq-xjf8/GHSA-rv4f-crjq-xjf8.json create mode 100644 advisories/unreviewed/2025/03/GHSA-rvgh-pr46-x7gg/GHSA-rvgh-pr46-x7gg.json create mode 100644 advisories/unreviewed/2025/03/GHSA-rvmr-crph-7vj2/GHSA-rvmr-crph-7vj2.json create mode 100644 advisories/unreviewed/2025/03/GHSA-rxwh-3m8p-2qq5/GHSA-rxwh-3m8p-2qq5.json create mode 100644 advisories/unreviewed/2025/03/GHSA-v3f4-7pp9-6f99/GHSA-v3f4-7pp9-6f99.json create mode 100644 advisories/unreviewed/2025/03/GHSA-v464-r2r9-www7/GHSA-v464-r2r9-www7.json create mode 100644 advisories/unreviewed/2025/03/GHSA-v5pj-jrpv-h6g2/GHSA-v5pj-jrpv-h6g2.json create mode 100644 advisories/unreviewed/2025/03/GHSA-v67x-89x7-mh47/GHSA-v67x-89x7-mh47.json create mode 100644 advisories/unreviewed/2025/03/GHSA-vffc-qpx3-764c/GHSA-vffc-qpx3-764c.json create mode 100644 advisories/unreviewed/2025/03/GHSA-vh85-qfmh-23mf/GHSA-vh85-qfmh-23mf.json create mode 100644 advisories/unreviewed/2025/03/GHSA-vhfq-gpqw-p5cw/GHSA-vhfq-gpqw-p5cw.json create mode 100644 advisories/unreviewed/2025/03/GHSA-vpg6-7cch-gq2j/GHSA-vpg6-7cch-gq2j.json create mode 100644 advisories/unreviewed/2025/03/GHSA-vq2g-prvr-rgr4/GHSA-vq2g-prvr-rgr4.json create mode 100644 advisories/unreviewed/2025/03/GHSA-vqqv-6pvc-4m7q/GHSA-vqqv-6pvc-4m7q.json create mode 100644 advisories/unreviewed/2025/03/GHSA-vrw3-r7jw-4785/GHSA-vrw3-r7jw-4785.json create mode 100644 advisories/unreviewed/2025/03/GHSA-vx9q-6hqp-j863/GHSA-vx9q-6hqp-j863.json create mode 100644 advisories/unreviewed/2025/03/GHSA-w3m9-crxx-972f/GHSA-w3m9-crxx-972f.json create mode 100644 advisories/unreviewed/2025/03/GHSA-w466-2wfc-8g58/GHSA-w466-2wfc-8g58.json create mode 100644 advisories/unreviewed/2025/03/GHSA-w4cv-4jm4-pg8h/GHSA-w4cv-4jm4-pg8h.json create mode 100644 advisories/unreviewed/2025/03/GHSA-w6hh-w36c-vxmw/GHSA-w6hh-w36c-vxmw.json create mode 100644 advisories/unreviewed/2025/03/GHSA-w6r4-j5cm-c7fp/GHSA-w6r4-j5cm-c7fp.json create mode 100644 advisories/unreviewed/2025/03/GHSA-wcwp-9rcp-jvfg/GHSA-wcwp-9rcp-jvfg.json create mode 100644 advisories/unreviewed/2025/03/GHSA-wjpv-64v2-2qpq/GHSA-wjpv-64v2-2qpq.json create mode 100644 advisories/unreviewed/2025/03/GHSA-wmc2-c6g2-9mf2/GHSA-wmc2-c6g2-9mf2.json create mode 100644 advisories/unreviewed/2025/03/GHSA-wr4v-pc76-3q4p/GHSA-wr4v-pc76-3q4p.json create mode 100644 advisories/unreviewed/2025/03/GHSA-wwr9-4gmr-xvq9/GHSA-wwr9-4gmr-xvq9.json create mode 100644 advisories/unreviewed/2025/03/GHSA-wxpc-2674-rxvw/GHSA-wxpc-2674-rxvw.json create mode 100644 advisories/unreviewed/2025/03/GHSA-x2w2-frfv-4f2j/GHSA-x2w2-frfv-4f2j.json create mode 100644 advisories/unreviewed/2025/03/GHSA-x48g-hm9c-ww42/GHSA-x48g-hm9c-ww42.json create mode 100644 advisories/unreviewed/2025/03/GHSA-x552-5vh8-qccx/GHSA-x552-5vh8-qccx.json create mode 100644 advisories/unreviewed/2025/03/GHSA-x5xw-28w4-53j5/GHSA-x5xw-28w4-53j5.json create mode 100644 advisories/unreviewed/2025/03/GHSA-x757-hv69-jr45/GHSA-x757-hv69-jr45.json create mode 100644 advisories/unreviewed/2025/03/GHSA-x7c5-9r9g-pghj/GHSA-x7c5-9r9g-pghj.json create mode 100644 advisories/unreviewed/2025/03/GHSA-x9hf-jr2h-w47p/GHSA-x9hf-jr2h-w47p.json create mode 100644 advisories/unreviewed/2025/03/GHSA-xcp6-jv5m-jwrm/GHSA-xcp6-jv5m-jwrm.json create mode 100644 advisories/unreviewed/2025/03/GHSA-xfjg-gcvp-vw7p/GHSA-xfjg-gcvp-vw7p.json create mode 100644 advisories/unreviewed/2025/03/GHSA-xqgj-r6xv-9cw4/GHSA-xqgj-r6xv-9cw4.json create mode 100644 advisories/unreviewed/2025/03/GHSA-xv4c-2443-pc28/GHSA-xv4c-2443-pc28.json create mode 100644 advisories/unreviewed/2025/03/GHSA-xx7c-j7h3-vjcq/GHSA-xx7c-j7h3-vjcq.json diff --git a/advisories/unreviewed/2024/03/GHSA-9x24-7fgc-x3vc/GHSA-9x24-7fgc-x3vc.json b/advisories/unreviewed/2024/03/GHSA-9x24-7fgc-x3vc/GHSA-9x24-7fgc-x3vc.json index 0e142a9be9c..9ed222139ba 100644 --- a/advisories/unreviewed/2024/03/GHSA-9x24-7fgc-x3vc/GHSA-9x24-7fgc-x3vc.json +++ b/advisories/unreviewed/2024/03/GHSA-9x24-7fgc-x3vc/GHSA-9x24-7fgc-x3vc.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-8vf4-q8g2-79g5/GHSA-8vf4-q8g2-79g5.json b/advisories/unreviewed/2024/04/GHSA-8vf4-q8g2-79g5/GHSA-8vf4-q8g2-79g5.json index df713b62b19..8b896403e05 100644 --- a/advisories/unreviewed/2024/04/GHSA-8vf4-q8g2-79g5/GHSA-8vf4-q8g2-79g5.json +++ b/advisories/unreviewed/2024/04/GHSA-8vf4-q8g2-79g5/GHSA-8vf4-q8g2-79g5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8vf4-q8g2-79g5", - "modified": "2024-06-26T00:31:36Z", + "modified": "2025-03-20T12:32:37Z", "published": "2024-04-04T09:30:35Z", "aliases": [ "CVE-2024-26787" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmmc: mmci: stm32: fix DMA API overlapping mappings warning\n\nTurning on CONFIG_DMA_API_DEBUG_SG results in the following warning:\n\nDMA-API: mmci-pl18x 48220000.mmc: cacheline tracking EEXIST,\noverlapping mappings aren't supported\nWARNING: CPU: 1 PID: 51 at kernel/dma/debug.c:568\nadd_dma_entry+0x234/0x2f4\nModules linked in:\nCPU: 1 PID: 51 Comm: kworker/1:2 Not tainted 6.1.28 #1\nHardware name: STMicroelectronics STM32MP257F-EV1 Evaluation Board (DT)\nWorkqueue: events_freezable mmc_rescan\nCall trace:\nadd_dma_entry+0x234/0x2f4\ndebug_dma_map_sg+0x198/0x350\n__dma_map_sg_attrs+0xa0/0x110\ndma_map_sg_attrs+0x10/0x2c\nsdmmc_idma_prep_data+0x80/0xc0\nmmci_prep_data+0x38/0x84\nmmci_start_data+0x108/0x2dc\nmmci_request+0xe4/0x190\n__mmc_start_request+0x68/0x140\nmmc_start_request+0x94/0xc0\nmmc_wait_for_req+0x70/0x100\nmmc_send_tuning+0x108/0x1ac\nsdmmc_execute_tuning+0x14c/0x210\nmmc_execute_tuning+0x48/0xec\nmmc_sd_init_uhs_card.part.0+0x208/0x464\nmmc_sd_init_card+0x318/0x89c\nmmc_attach_sd+0xe4/0x180\nmmc_rescan+0x244/0x320\n\nDMA API debug brings to light leaking dma-mappings as dma_map_sg and\ndma_unmap_sg are not correctly balanced.\n\nIf an error occurs in mmci_cmd_irq function, only mmci_dma_error\nfunction is called and as this API is not managed on stm32 variant,\ndma_unmap_sg is never called in this error path.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -45,7 +50,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-04T09:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-hw9j-mg68-r593/GHSA-hw9j-mg68-r593.json b/advisories/unreviewed/2024/04/GHSA-hw9j-mg68-r593/GHSA-hw9j-mg68-r593.json index 777d26e580a..f7e576c8596 100644 --- a/advisories/unreviewed/2024/04/GHSA-hw9j-mg68-r593/GHSA-hw9j-mg68-r593.json +++ b/advisories/unreviewed/2024/04/GHSA-hw9j-mg68-r593/GHSA-hw9j-mg68-r593.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-hw9j-mg68-r593", - "modified": "2024-04-07T18:30:30Z", + "modified": "2025-03-20T12:32:37Z", "published": "2024-04-07T18:30:30Z", "aliases": [ "CVE-2024-31296" ], - "details": "Authorization Bypass Through User-Controlled Key vulnerability in Repute Infosystems BookingPress.This issue affects BookingPress: from n/a through 1.0.81.\n\n", + "details": "Authorization Bypass Through User-Controlled Key vulnerability in Repute Infosystems BookingPress.This issue affects BookingPress: from n/a through 1.0.81.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2025/03/GHSA-227r-w5j2-6243/GHSA-227r-w5j2-6243.json b/advisories/unreviewed/2025/03/GHSA-227r-w5j2-6243/GHSA-227r-w5j2-6243.json new file mode 100644 index 00000000000..57a643f0652 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-227r-w5j2-6243/GHSA-227r-w5j2-6243.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-227r-w5j2-6243", + "modified": "2025-03-20T12:32:41Z", + "published": "2025-03-20T12:32:41Z", + "aliases": [ + "CVE-2024-11042" + ], + "details": "In invoke-ai/invokeai version v5.0.2, the web API `POST /api/v1/images/delete` is vulnerable to Arbitrary File Deletion. This vulnerability allows unauthorized attackers to delete arbitrary files on the server, potentially including critical or sensitive system files such as SSH keys, SQLite databases, and configuration files. This can impact the integrity and availability of applications relying on these files.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11042" + }, + { + "type": "WEB", + "url": "https://github.com/invoke-ai/invokeai/commit/5440c037674882b2ab7acd59087e9bb04b49657a" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/635535a7-c804-4789-ac3a-48d951263987" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-22h9-9rvv-q9qg/GHSA-22h9-9rvv-q9qg.json b/advisories/unreviewed/2025/03/GHSA-22h9-9rvv-q9qg/GHSA-22h9-9rvv-q9qg.json new file mode 100644 index 00000000000..2a95c73a4a0 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-22h9-9rvv-q9qg/GHSA-22h9-9rvv-q9qg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-22h9-9rvv-q9qg", + "modified": "2025-03-20T12:32:42Z", + "published": "2025-03-20T12:32:42Z", + "aliases": [ + "CVE-2024-11449" + ], + "details": "A vulnerability in haotian-liu/llava version 1.2.0 (LLaVA-1.6) allows for Server-Side Request Forgery (SSRF) through the /run/predict endpoint. An attacker can gain unauthorized access to internal networks or the AWS metadata endpoint by sending crafted requests that exploit insufficient validation of the path parameter. This flaw can lead to unauthorized network access, sensitive data exposure, and further exploitation within the network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11449" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/e96aba28-d564-4ecb-ab77-350511d2e1ee" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-29rg-m5qv-57gx/GHSA-29rg-m5qv-57gx.json b/advisories/unreviewed/2025/03/GHSA-29rg-m5qv-57gx/GHSA-29rg-m5qv-57gx.json new file mode 100644 index 00000000000..ea634179fb9 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-29rg-m5qv-57gx/GHSA-29rg-m5qv-57gx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-29rg-m5qv-57gx", + "modified": "2025-03-20T12:32:40Z", + "published": "2025-03-20T12:32:40Z", + "aliases": [ + "CVE-2024-10819" + ], + "details": "A Cross-Site Request Forgery (CSRF) vulnerability in version 3.83 of binary-husky/gpt_academic allows an attacker to trick a user into uploading files without their consent, exploiting their session. This can lead to unauthorized file uploads and potential system compromise. The uploaded file can contain malicious scripts, leading to stored Cross-Site Scripting (XSS) attacks. Through stored XSS, an attacker can steal information about the victim and perform any action on their behalf.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10819" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/45270c4b-a500-4374-a90b-37b604a3ace0" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-2c36-wq4v-5v3h/GHSA-2c36-wq4v-5v3h.json b/advisories/unreviewed/2025/03/GHSA-2c36-wq4v-5v3h/GHSA-2c36-wq4v-5v3h.json new file mode 100644 index 00000000000..20d5c91317a --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-2c36-wq4v-5v3h/GHSA-2c36-wq4v-5v3h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2c36-wq4v-5v3h", + "modified": "2025-03-20T12:32:47Z", + "published": "2025-03-20T12:32:46Z", + "aliases": [ + "CVE-2024-7819" + ], + "details": "A CORS misconfiguration in danswer-ai/danswer v1.4.1 allows attackers to steal sensitive information such as chat contents, API keys, and other data. This vulnerability occurs due to improper validation of the origin header, enabling malicious web pages to make unauthorized requests to the application's API.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7819" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/06a21857-e13f-4cf4-aa67-de11419a98c0" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-346" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-2mv8-c3hx-xq6v/GHSA-2mv8-c3hx-xq6v.json b/advisories/unreviewed/2025/03/GHSA-2mv8-c3hx-xq6v/GHSA-2mv8-c3hx-xq6v.json new file mode 100644 index 00000000000..0df44f27314 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-2mv8-c3hx-xq6v/GHSA-2mv8-c3hx-xq6v.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2mv8-c3hx-xq6v", + "modified": "2025-03-20T12:32:47Z", + "published": "2025-03-20T12:32:47Z", + "aliases": [ + "CVE-2024-8196" + ], + "details": "In mintplex-labs/anything-llm v1.5.11 desktop version for Windows, the application opens server port 3001 on 0.0.0.0 with no authentication by default. This vulnerability allows an attacker to gain full backend access, enabling them to perform actions such as deleting all data from the workspace.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8196" + }, + { + "type": "WEB", + "url": "https://github.com/mintplex-labs/anything-llm/commit/9bfe477f10b188bfe3508ac29105df80d4522ece" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/dbde1c71-7aa5-46f6-847a-d89793cf97a9" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-2rr7-xrrm-67cf/GHSA-2rr7-xrrm-67cf.json b/advisories/unreviewed/2025/03/GHSA-2rr7-xrrm-67cf/GHSA-2rr7-xrrm-67cf.json new file mode 100644 index 00000000000..cf48dc349ec --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-2rr7-xrrm-67cf/GHSA-2rr7-xrrm-67cf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2rr7-xrrm-67cf", + "modified": "2025-03-20T12:32:47Z", + "published": "2025-03-20T12:32:47Z", + "aliases": [ + "CVE-2024-8018" + ], + "details": "A vulnerability in imartinez/privategpt version 0.5.0 allows for a Denial of Service (DOS) attack. When uploading a file, if an attacker appends a large number of characters to the end of a multipart boundary, the system will continuously process these characters, rendering privateGPT inaccessible. This uncontrolled resource consumption can lead to prolonged unavailability of the service, disrupting operations and causing potential data inaccessibility and loss of productivity.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8018" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/0661fa3b-bea4-4156-abed-a65d51958505" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-2w2q-qp7m-7wrh/GHSA-2w2q-qp7m-7wrh.json b/advisories/unreviewed/2025/03/GHSA-2w2q-qp7m-7wrh/GHSA-2w2q-qp7m-7wrh.json new file mode 100644 index 00000000000..ec5848a58ee --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-2w2q-qp7m-7wrh/GHSA-2w2q-qp7m-7wrh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2w2q-qp7m-7wrh", + "modified": "2025-03-20T12:32:51Z", + "published": "2025-03-20T12:32:51Z", + "aliases": [ + "CVE-2024-9617" + ], + "details": "An IDOR vulnerability in danswer-ai/danswer v0.3.94 allows an attacker to view any files. The application does not verify whether the attacker is the creator of the file, allowing the attacker to directly call the GET /api/chat/file/{file_id} interface to view any user's file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9617" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/8f683ff6-3a99-41c6-b763-a8f7b73bd146" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-2xcr-p767-f3rv/GHSA-2xcr-p767-f3rv.json b/advisories/unreviewed/2025/03/GHSA-2xcr-p767-f3rv/GHSA-2xcr-p767-f3rv.json new file mode 100644 index 00000000000..327be64e31c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-2xcr-p767-f3rv/GHSA-2xcr-p767-f3rv.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2xcr-p767-f3rv", + "modified": "2025-03-20T12:32:53Z", + "published": "2025-03-20T12:32:53Z", + "aliases": [ + "CVE-2025-27888" + ], + "details": "Severity: medium (5.8) / important\n\nServer-Side Request Forgery (SSRF), Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache Druid.\n\nThis issue affects all previous Druid versions.\n\n\nWhen using the Druid management proxy, a request that has a specially crafted URL could be used to redirect the request to an arbitrary server instead. This has the potential for XSS or XSRF. The user is required to be authenticated for this exploit. The management proxy is enabled in Druid's out-of-box configuration. It may be disabled to mitigate this vulnerability. If the management proxy is disabled, some web console features will not work properly, but core functionality is unaffected.\n\n\nUsers are recommended to upgrade to Druid 31.0.2 or Druid 32.0.1, which fixes the issue.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27888" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/c0qo989pwtrqkjv6xfr0c30dnjq8vf39" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/03/19/7" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T12:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-2xf2-gjm6-g2c6/GHSA-2xf2-gjm6-g2c6.json b/advisories/unreviewed/2025/03/GHSA-2xf2-gjm6-g2c6/GHSA-2xf2-gjm6-g2c6.json new file mode 100644 index 00000000000..426e5389504 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-2xf2-gjm6-g2c6/GHSA-2xf2-gjm6-g2c6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2xf2-gjm6-g2c6", + "modified": "2025-03-20T12:32:47Z", + "published": "2025-03-20T12:32:47Z", + "aliases": [ + "CVE-2024-8063" + ], + "details": "A divide by zero vulnerability exists in ollama/ollama version v0.3.3. The vulnerability occurs when importing GGUF models with a crafted type for `block_count` in the Modelfile. This can lead to a denial of service (DoS) condition when the server processes the model, causing it to crash.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8063" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/fd8e1ed6-21d2-4c9e-8395-2098f11b7db9" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-369" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3248-f932-c76p/GHSA-3248-f932-c76p.json b/advisories/unreviewed/2025/03/GHSA-3248-f932-c76p/GHSA-3248-f932-c76p.json new file mode 100644 index 00000000000..42423ee1e9e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3248-f932-c76p/GHSA-3248-f932-c76p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3248-f932-c76p", + "modified": "2025-03-20T12:32:41Z", + "published": "2025-03-20T12:32:40Z", + "aliases": [ + "CVE-2024-10906" + ], + "details": "In version 0.6.0 of eosphoros-ai/db-gpt, the `uvicorn` app created by `dbgpt_server` uses an overly permissive instance of `CORSMiddleware` which sets the `Access-Control-Allow-Origin` to `*` for all requests. This configuration makes all endpoints exposed by the server vulnerable to Cross-Site Request Forgery (CSRF). An attacker can exploit this vulnerability to interact with any endpoints of the instance, even if the instance is not publicly exposed to the network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10906" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/8864aca5-a342-4dab-b866-b2882ba6f160" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-32g6-mg92-ghm2/GHSA-32g6-mg92-ghm2.json b/advisories/unreviewed/2025/03/GHSA-32g6-mg92-ghm2/GHSA-32g6-mg92-ghm2.json new file mode 100644 index 00000000000..454bdee8086 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-32g6-mg92-ghm2/GHSA-32g6-mg92-ghm2.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-32g6-mg92-ghm2", + "modified": "2025-03-20T12:32:52Z", + "published": "2025-03-20T12:32:52Z", + "aliases": [ + "CVE-2025-0508" + ], + "details": "A vulnerability in the SageMaker Workflow component of aws/sagemaker-python-sdk allows for the possibility of MD5 hash collisions in all versions. This can lead to workflows being inadvertently replaced due to the reuse of results from different configurations that produce the same MD5 hash. This issue can cause integrity problems within the pipeline, potentially leading to erroneous processing outcomes.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0508" + }, + { + "type": "WEB", + "url": "https://github.com/aws/sagemaker-python-sdk/commit/dcdd99f911e8b1a05d19cf1ad939b0fefae47864" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/eb056818-5b81-466f-81ee-916058d34af2" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-440" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-332g-rf22-2vcg/GHSA-332g-rf22-2vcg.json b/advisories/unreviewed/2025/03/GHSA-332g-rf22-2vcg/GHSA-332g-rf22-2vcg.json new file mode 100644 index 00000000000..aef5660646e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-332g-rf22-2vcg/GHSA-332g-rf22-2vcg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-332g-rf22-2vcg", + "modified": "2025-03-20T12:32:45Z", + "published": "2025-03-20T12:32:44Z", + "aliases": [ + "CVE-2024-6583" + ], + "details": "A path traversal vulnerability exists in the latest version of stangirard/quivr. This vulnerability allows an attacker to upload files to arbitrary paths in an S3 bucket by manipulating the file path in the upload request.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6583" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/c310b500-ec26-4121-8d3a-8e863181346f" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-23" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-339r-cjv9-x78g/GHSA-339r-cjv9-x78g.json b/advisories/unreviewed/2025/03/GHSA-339r-cjv9-x78g/GHSA-339r-cjv9-x78g.json new file mode 100644 index 00000000000..e5331d85d65 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-339r-cjv9-x78g/GHSA-339r-cjv9-x78g.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-339r-cjv9-x78g", + "modified": "2025-03-20T12:32:42Z", + "published": "2025-03-20T12:32:42Z", + "aliases": [ + "CVE-2024-11958" + ], + "details": "A SQL injection vulnerability exists in the `duckdb_retriever` component of the run-llama/llama_index repository, specifically in the latest version. The vulnerability arises from the construction of SQL queries without using prepared statements, allowing an attacker to inject arbitrary SQL code. This can lead to remote code execution (RCE) by installing the shellfs extension and executing malicious commands.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11958" + }, + { + "type": "WEB", + "url": "https://github.com/run-llama/llama_index/commit/35bd221e948e40458052d30c6ef2779bc965b6d0" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/8ddf66e1-f74c-4d53-992b-76bc45cacac1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-34v4-5664-chqj/GHSA-34v4-5664-chqj.json b/advisories/unreviewed/2025/03/GHSA-34v4-5664-chqj/GHSA-34v4-5664-chqj.json new file mode 100644 index 00000000000..b6e31569329 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-34v4-5664-chqj/GHSA-34v4-5664-chqj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-34v4-5664-chqj", + "modified": "2025-03-20T12:32:47Z", + "published": "2025-03-20T12:32:47Z", + "aliases": [ + "CVE-2024-8029" + ], + "details": "An XSS vulnerability was discovered in the upload file(s) process of imartinez/privategpt v0.5.0. Attackers can upload malicious SVG files, which execute JavaScript when victims click on the file link. This can lead to user data theft, session hijacking, malware distribution, and phishing attacks.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8029" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/5941dc63-a4db-4b04-8007-bcaa828106d0" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-35p3-6j45-prwm/GHSA-35p3-6j45-prwm.json b/advisories/unreviewed/2025/03/GHSA-35p3-6j45-prwm/GHSA-35p3-6j45-prwm.json new file mode 100644 index 00000000000..090a9e4b871 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-35p3-6j45-prwm/GHSA-35p3-6j45-prwm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-35p3-6j45-prwm", + "modified": "2025-03-20T12:32:44Z", + "published": "2025-03-20T12:32:44Z", + "aliases": [ + "CVE-2024-12778" + ], + "details": "A vulnerability in aimhubio/aim version 3.25.0 allows for a denial of service (DoS) attack. The issue arises when a large number of tracked metrics are retrieved simultaneously from the Aim web API, causing the web server to become unresponsive. The root cause is the lack of a limit on the number of metrics that can be requested per call, combined with the server's single-threaded nature, leading to excessive resource consumption and blocking of the server.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12778" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/892a9eee-0251-4e57-94a4-dad2e7f32715" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-38mg-wm59-g64x/GHSA-38mg-wm59-g64x.json b/advisories/unreviewed/2025/03/GHSA-38mg-wm59-g64x/GHSA-38mg-wm59-g64x.json new file mode 100644 index 00000000000..40d4900e8dc --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-38mg-wm59-g64x/GHSA-38mg-wm59-g64x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-38mg-wm59-g64x", + "modified": "2025-03-20T12:32:49Z", + "published": "2025-03-20T12:32:49Z", + "aliases": [ + "CVE-2024-8955" + ], + "details": "A Server-Side Request Forgery (SSRF) vulnerability exists in composiohq/composio version v0.4.4. This vulnerability allows an attacker to read the contents of any file in the system by exploiting the BROWSERTOOL_GOTO_PAGE and BROWSERTOOL_GET_PAGE_DETAILS actions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8955" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/13bc0399-2d9b-449e-95f2-6e9a7e39383d" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-643" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-38r9-3j52-h92v/GHSA-38r9-3j52-h92v.json b/advisories/unreviewed/2025/03/GHSA-38r9-3j52-h92v/GHSA-38r9-3j52-h92v.json new file mode 100644 index 00000000000..db200449b9a --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-38r9-3j52-h92v/GHSA-38r9-3j52-h92v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-38r9-3j52-h92v", + "modified": "2025-03-20T12:32:46Z", + "published": "2025-03-20T12:32:46Z", + "aliases": [ + "CVE-2024-7760" + ], + "details": "aimhubio/aim version 3.22.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the tracking server. The vulnerability is due to overly permissive CORS settings, allowing cross-origin requests from all origins. This enables CSRF attacks on all endpoints of the tracking server, which can be chained with other existing vulnerabilities such as remote code execution, denial of service, and arbitrary file read/write.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7760" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/2038df5f-4829-4040-8573-67bf9bb89229" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3c45-rpmq-6gfj/GHSA-3c45-rpmq-6gfj.json b/advisories/unreviewed/2025/03/GHSA-3c45-rpmq-6gfj/GHSA-3c45-rpmq-6gfj.json new file mode 100644 index 00000000000..3fba576b782 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3c45-rpmq-6gfj/GHSA-3c45-rpmq-6gfj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3c45-rpmq-6gfj", + "modified": "2025-03-20T12:32:44Z", + "published": "2025-03-20T12:32:44Z", + "aliases": [ + "CVE-2024-12869" + ], + "details": "In infiniflow/ragflow version v0.12.0, there is an improper authentication vulnerability that allows a user to view another user's invite list. This can lead to a privacy breach where users' personal or private information, such as email addresses or usernames in the invite list, could be exposed without their consent. This data leakage can facilitate further attacks, such as phishing or spam, and result in loss of trust and potential regulatory issues.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12869" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/768b1a56-1e79-416a-8445-65953568b04a" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3j5r-3852-j63v/GHSA-3j5r-3852-j63v.json b/advisories/unreviewed/2025/03/GHSA-3j5r-3852-j63v/GHSA-3j5r-3852-j63v.json new file mode 100644 index 00000000000..d57202e3039 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3j5r-3852-j63v/GHSA-3j5r-3852-j63v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3j5r-3852-j63v", + "modified": "2025-03-20T12:32:42Z", + "published": "2025-03-20T12:32:42Z", + "aliases": [ + "CVE-2024-11302" + ], + "details": "A missing check_access() function in the lollms_binding_infos module of the parisneo/lollms repository, version V14, allows attackers to add, modify, and remove bindings arbitrarily. This vulnerability affects the /install_binding and /reinstall_binding endpoints, among others, enabling unauthorized access and manipulation of binding settings without requiring the client_id value.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11302" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/e341304b-4651-4de9-b7b9-b89aead3b46e" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-304" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3p9q-7w63-3f8q/GHSA-3p9q-7w63-3f8q.json b/advisories/unreviewed/2025/03/GHSA-3p9q-7w63-3f8q/GHSA-3p9q-7w63-3f8q.json new file mode 100644 index 00000000000..4b4ac5adb91 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3p9q-7w63-3f8q/GHSA-3p9q-7w63-3f8q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3p9q-7w63-3f8q", + "modified": "2025-03-20T12:32:45Z", + "published": "2025-03-20T12:32:45Z", + "aliases": [ + "CVE-2024-7033" + ], + "details": "In version 0.3.8 of open-webui/open-webui, an arbitrary file write vulnerability exists in the download_model endpoint. When deployed on Windows, the application improperly handles file paths, allowing an attacker to manipulate the file path to write files to arbitrary locations on the server's filesystem. This can result in overwriting critical system or application files, causing denial of service, or potentially achieving remote code execution (RCE). RCE can allow an attacker to execute malicious code with the privileges of the user running the application, leading to a full system compromise.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7033" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/7078261f-8414-4bb7-9d72-a2a4d8bfd5d1" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-29" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3ppw-4jp4-5852/GHSA-3ppw-4jp4-5852.json b/advisories/unreviewed/2025/03/GHSA-3ppw-4jp4-5852/GHSA-3ppw-4jp4-5852.json new file mode 100644 index 00000000000..f0bef529313 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3ppw-4jp4-5852/GHSA-3ppw-4jp4-5852.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3ppw-4jp4-5852", + "modified": "2025-03-20T12:32:47Z", + "published": "2025-03-20T12:32:47Z", + "aliases": [ + "CVE-2024-8101" + ], + "details": "A stored cross-site scripting (XSS) vulnerability exists in the Text Explorer component of aimhubio/aim version 3.23.0. The vulnerability arises due to the use of `dangerouslySetInnerHTML` without proper sanitization, allowing arbitrary JavaScript execution when rendering tracked texts. This can be exploited by injecting malicious HTML content during the training process, which is then rendered unsanitized in the Text Explorer.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8101" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/60cf2b93-a9a2-435e-a222-3d6abde26adb" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3xq5-x4fj-rff7/GHSA-3xq5-x4fj-rff7.json b/advisories/unreviewed/2025/03/GHSA-3xq5-x4fj-rff7/GHSA-3xq5-x4fj-rff7.json new file mode 100644 index 00000000000..3462c0d0dba --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3xq5-x4fj-rff7/GHSA-3xq5-x4fj-rff7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3xq5-x4fj-rff7", + "modified": "2025-03-20T12:32:40Z", + "published": "2025-03-20T12:32:40Z", + "aliases": [ + "CVE-2024-10902" + ], + "details": "In eosphoros-ai/db-gpt version v0.6.0, the web API `POST /v1/personal/agent/upload` is vulnerable to Arbitrary File Upload with Path Traversal. This vulnerability allows unauthorized attackers to upload arbitrary files to the victim's file system at any location. The impact of this vulnerability includes the potential for remote code execution (RCE) by writing malicious files, such as a malicious `__init__.py` in the Python's `/site-packages/` directory.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10902" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/f7fbf76e-aa1c-4106-b007-e9579f4f7d5f" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-73" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-43g4-487m-5q6m/GHSA-43g4-487m-5q6m.json b/advisories/unreviewed/2025/03/GHSA-43g4-487m-5q6m/GHSA-43g4-487m-5q6m.json new file mode 100644 index 00000000000..0300d9674ca --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-43g4-487m-5q6m/GHSA-43g4-487m-5q6m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-43g4-487m-5q6m", + "modified": "2025-03-20T12:32:46Z", + "published": "2025-03-20T12:32:46Z", + "aliases": [ + "CVE-2024-7053" + ], + "details": "A vulnerability in open-webui/open-webui version 0.3.8 allows an attacker with a user-level account to perform a session fixation attack. The session cookie for all users is set with the default `SameSite=Lax` and does not have the `Secure` flag enabled, allowing the session cookie to be sent over HTTP to a cross-origin domain. An attacker can exploit this by embedding a malicious markdown image in a chat, which, when viewed by an administrator, sends the admin's session cookie to the attacker's server. This can lead to a stealthy administrator account takeover, potentially resulting in remote code execution (RCE) due to the elevated privileges of administrator accounts.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7053" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/947f8191-0abf-4adf-b7c4-d4c19683aba2" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-43qf-4rqw-9q2g/GHSA-43qf-4rqw-9q2g.json b/advisories/unreviewed/2025/03/GHSA-43qf-4rqw-9q2g/GHSA-43qf-4rqw-9q2g.json new file mode 100644 index 00000000000..71055d05636 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-43qf-4rqw-9q2g/GHSA-43qf-4rqw-9q2g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-43qf-4rqw-9q2g", + "modified": "2025-03-20T12:32:45Z", + "published": "2025-03-20T12:32:45Z", + "aliases": [ + "CVE-2024-6866" + ], + "details": "corydolphin/flask-cors version 4.01 contains a vulnerability where the request path matching is case-insensitive due to the use of the `try_match` function, which is originally intended for matching hosts. This results in a mismatch because paths in URLs are case-sensitive, but the regex matching treats them as case-insensitive. This misconfiguration can lead to significant security vulnerabilities, allowing unauthorized origins to access paths meant to be restricted, resulting in data exposure and potential data leaks.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6866" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/808c11af-faee-43a8-824b-b5ab4f62b9e6" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-178" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-4452-rwq3-2x44/GHSA-4452-rwq3-2x44.json b/advisories/unreviewed/2025/03/GHSA-4452-rwq3-2x44/GHSA-4452-rwq3-2x44.json new file mode 100644 index 00000000000..84b4ea4740b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4452-rwq3-2x44/GHSA-4452-rwq3-2x44.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4452-rwq3-2x44", + "modified": "2025-03-20T12:32:41Z", + "published": "2025-03-20T12:32:41Z", + "aliases": [ + "CVE-2024-11031" + ], + "details": "In version 3.83 of binary-husky/gpt_academic, a Server-Side Request Forgery (SSRF) vulnerability exists in the Markdown_Translate.get_files_from_everything() API. This vulnerability is exploited through the HotReload(Markdown翻译中) plugin function, which allows downloading arbitrary web hosts by only checking if the link starts with 'http'. Attackers can exploit this vulnerability to abuse the victim GPT Academic's Gradio Web server's credentials to access unauthorized web resources.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11031" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/d27d89a7-7d54-45b9-a9eb-66c00bc56e02" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-44q8-52gx-27g8/GHSA-44q8-52gx-27g8.json b/advisories/unreviewed/2025/03/GHSA-44q8-52gx-27g8/GHSA-44q8-52gx-27g8.json new file mode 100644 index 00000000000..7c13d2358ac --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-44q8-52gx-27g8/GHSA-44q8-52gx-27g8.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-44q8-52gx-27g8", + "modified": "2025-03-20T12:32:42Z", + "published": "2025-03-20T12:32:42Z", + "aliases": [ + "CVE-2024-11300" + ], + "details": "In lunary-ai/lunary before version 1.6.3, an improper access control vulnerability exists where a user can access prompt data of another user. This issue affects version 1.6.2 and the main branch. The vulnerability allows unauthorized users to view sensitive prompt data by accessing specific URLs, leading to potential exposure of critical information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11300" + }, + { + "type": "WEB", + "url": "https://github.com/lunary-ai/lunary/commit/79dc370596d979b756f6ea0250d97a2d02385ecd" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/8dca7994-0d92-491e-a419-02adfe23ffa4" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-45p5-8q33-98hw/GHSA-45p5-8q33-98hw.json b/advisories/unreviewed/2025/03/GHSA-45p5-8q33-98hw/GHSA-45p5-8q33-98hw.json new file mode 100644 index 00000000000..61206e7dfe0 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-45p5-8q33-98hw/GHSA-45p5-8q33-98hw.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-45p5-8q33-98hw", + "modified": "2025-03-20T12:32:39Z", + "published": "2025-03-20T12:32:39Z", + "aliases": [ + "CVE-2024-10513" + ], + "details": "A path traversal vulnerability exists in the 'document uploads manager' feature of mintplex-labs/anything-llm, affecting the latest version prior to 1.2.2. This vulnerability allows users with the 'manager' role to access and manipulate the 'anythingllm.db' database file. By exploiting the vulnerable endpoint '/api/document/move-files', an attacker can move the database file to a publicly accessible directory, download it, and subsequently delete it. This can lead to unauthorized access to sensitive data, privilege escalation, and potential data loss.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10513" + }, + { + "type": "WEB", + "url": "https://github.com/mintplex-labs/anything-llm/commit/47a5c7126c20e2277ee56e2c7ee11990886a40a7" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/ad11cecf-161a-4fb1-986f-6f88272cbb9e" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-23" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-47f6-5p7h-5f3h/GHSA-47f6-5p7h-5f3h.json b/advisories/unreviewed/2025/03/GHSA-47f6-5p7h-5f3h/GHSA-47f6-5p7h-5f3h.json new file mode 100644 index 00000000000..920940ce8da --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-47f6-5p7h-5f3h/GHSA-47f6-5p7h-5f3h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-47f6-5p7h-5f3h", + "modified": "2025-03-20T12:32:45Z", + "published": "2025-03-20T12:32:45Z", + "aliases": [ + "CVE-2024-6854" + ], + "details": "In h2oai/h2o-3 version 3.46.0, the endpoint for exporting models does not restrict the export location, allowing an attacker to export a model to any file in the server's file structure, thereby overwriting it. This vulnerability can be exploited to overwrite any file on the target server with a trained model file, although the content of the overwrite is not controllable by the attacker.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6854" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/97d013f9-ac51-4c80-8dd7-8dfde11f33b2" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-36" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-49m6-vrr9-2cqm/GHSA-49m6-vrr9-2cqm.json b/advisories/unreviewed/2025/03/GHSA-49m6-vrr9-2cqm/GHSA-49m6-vrr9-2cqm.json new file mode 100644 index 00000000000..2ab12653d7e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-49m6-vrr9-2cqm/GHSA-49m6-vrr9-2cqm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-49m6-vrr9-2cqm", + "modified": "2025-03-20T12:32:52Z", + "published": "2025-03-20T12:32:52Z", + "aliases": [ + "CVE-2025-0453" + ], + "details": "In mlflow/mlflow version 2.17.2, the `/graphql` endpoint is vulnerable to a denial of service attack. An attacker can create large batches of queries that repeatedly request all runs from a given experiment. This can tie up all the workers allocated by MLFlow, rendering the application unable to respond to other requests. This vulnerability is due to uncontrolled resource consumption.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0453" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/788327ec-714a-4d5c-83aa-8df04dd7612b" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-49rx-72gp-wfgj/GHSA-49rx-72gp-wfgj.json b/advisories/unreviewed/2025/03/GHSA-49rx-72gp-wfgj/GHSA-49rx-72gp-wfgj.json new file mode 100644 index 00000000000..f63d3d06862 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-49rx-72gp-wfgj/GHSA-49rx-72gp-wfgj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-49rx-72gp-wfgj", + "modified": "2025-03-20T12:32:48Z", + "published": "2025-03-20T12:32:48Z", + "aliases": [ + "CVE-2024-8489" + ], + "details": "A vulnerability in modelscope/agentscope, specifically in the AgentScope Studio backend server, allows for Cross-Site Request Forgery (CSRF) due to overly permissive CORS headers. This issue affects the latest commit on the main branch (21161fe). The vulnerability permits an attacker to access all backend endpoints, including the `api/file` endpoint, enabling the reading of arbitrary files on the target's local file system through CSRF.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8489" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/93195bf0-9ac2-4476-a2ea-7c9364727e8c" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-4cv3-v7pv-rfhf/GHSA-4cv3-v7pv-rfhf.json b/advisories/unreviewed/2025/03/GHSA-4cv3-v7pv-rfhf/GHSA-4cv3-v7pv-rfhf.json new file mode 100644 index 00000000000..919906574f3 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4cv3-v7pv-rfhf/GHSA-4cv3-v7pv-rfhf.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4cv3-v7pv-rfhf", + "modified": "2025-03-20T12:32:47Z", + "published": "2025-03-20T12:32:46Z", + "aliases": [ + "CVE-2024-8019" + ], + "details": "In lightning-ai/pytorch-lightning version 2.3.2, a vulnerability exists in the `LightningApp` when running on a Windows host. The vulnerability occurs at the `/api/v1/upload_file/` endpoint, allowing an attacker to write or overwrite arbitrary files by providing a crafted filename. This can lead to potential remote code execution (RCE) by overwriting critical files or placing malicious files in sensitive locations.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8019" + }, + { + "type": "WEB", + "url": "https://github.com/lightning-ai/pytorch-lightning/commit/330af381de88cff17515418a341cbc1f9f127f9a" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/2754298b-5af5-48ef-8b38-999093ddf2bd" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-4cxc-r29p-3327/GHSA-4cxc-r29p-3327.json b/advisories/unreviewed/2025/03/GHSA-4cxc-r29p-3327/GHSA-4cxc-r29p-3327.json new file mode 100644 index 00000000000..0b0e6e98f5e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4cxc-r29p-3327/GHSA-4cxc-r29p-3327.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4cxc-r29p-3327", + "modified": "2025-03-20T12:32:43Z", + "published": "2025-03-20T12:32:43Z", + "aliases": [ + "CVE-2024-12387" + ], + "details": "A vulnerability in the binary-husky/gpt_academic repository, as of commit git 3890467, allows an attacker to crash the server by uploading a specially crafted zip bomb. The server decompresses the uploaded file and attempts to load it into memory, which can lead to an out-of-memory crash. This issue arises due to improper input validation when handling compressed file uploads.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12387" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/02b4ab21-d29b-4cd7-ad80-f83081ce82a4" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-4f3h-89pj-w84f/GHSA-4f3h-89pj-w84f.json b/advisories/unreviewed/2025/03/GHSA-4f3h-89pj-w84f/GHSA-4f3h-89pj-w84f.json new file mode 100644 index 00000000000..d7531a60b55 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4f3h-89pj-w84f/GHSA-4f3h-89pj-w84f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4f3h-89pj-w84f", + "modified": "2025-03-20T12:32:46Z", + "published": "2025-03-20T12:32:46Z", + "aliases": [ + "CVE-2024-7779" + ], + "details": "A vulnerability in danswer-ai/danswer version 1 allows an attacker to perform a Regular Expression Denial of Service (ReDoS) by manipulating regular expressions. This can significantly slow down the application's response time and potentially render it completely unusable.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7779" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/829f7d9f-8755-4362-bd40-801e4690dcdc" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-4g3f-9mfg-xxgh/GHSA-4g3f-9mfg-xxgh.json b/advisories/unreviewed/2025/03/GHSA-4g3f-9mfg-xxgh/GHSA-4g3f-9mfg-xxgh.json new file mode 100644 index 00000000000..d5e6a73a7b6 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4g3f-9mfg-xxgh/GHSA-4g3f-9mfg-xxgh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4g3f-9mfg-xxgh", + "modified": "2025-03-20T12:32:45Z", + "published": "2025-03-20T12:32:45Z", + "aliases": [ + "CVE-2024-6986" + ], + "details": "A Cross-site Scripting (XSS) vulnerability exists in the Settings page of parisneo/lollms-webui version 9.8. The vulnerability is due to the improper use of the 'v-html' directive, which inserts the content of the 'full_template' variable directly as HTML. This allows an attacker to execute malicious JavaScript code by injecting a payload into the 'System Template' input field under main configurations.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6986" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/83e9bde1-40b2-49e9-be1c-bc1498eb8ebd" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-4jr8-64gc-wqqx/GHSA-4jr8-64gc-wqqx.json b/advisories/unreviewed/2025/03/GHSA-4jr8-64gc-wqqx/GHSA-4jr8-64gc-wqqx.json new file mode 100644 index 00000000000..0764c850a0e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4jr8-64gc-wqqx/GHSA-4jr8-64gc-wqqx.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4jr8-64gc-wqqx", + "modified": "2025-03-20T12:32:39Z", + "published": "2025-03-20T12:32:39Z", + "aliases": [ + "CVE-2024-10275" + ], + "details": "In version 1.5.5 of lunary-ai/lunary, a vulnerability exists where admins, who do not have direct permissions to access billing resources, can change the permissions of existing users to include billing permissions. This can lead to a privilege escalation scenario where an administrator can manage billing, effectively bypassing the intended role-based access control. Only users with the 'owner' role should be allowed to invite members with billing permissions. This flaw allows admins to circumvent those restrictions, gaining unauthorized access and control over billing information, posing a risk to the organization’s financial resources.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10275" + }, + { + "type": "WEB", + "url": "https://github.com/lunary-ai/lunary/commit/8ba1b8ba2c2c30b1cec30eb5777c1fda670cbbfc" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/863ee34b-c4c6-4325-bf7a-82a7feebf88f" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-4qcx-jx49-6qrh/GHSA-4qcx-jx49-6qrh.json b/advisories/unreviewed/2025/03/GHSA-4qcx-jx49-6qrh/GHSA-4qcx-jx49-6qrh.json new file mode 100644 index 00000000000..94d16aee440 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4qcx-jx49-6qrh/GHSA-4qcx-jx49-6qrh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4qcx-jx49-6qrh", + "modified": "2025-03-20T12:32:49Z", + "published": "2025-03-20T12:32:48Z", + "aliases": [ + "CVE-2024-8769" + ], + "details": "A vulnerability in the `LockManager.release_locks` function in aimhubio/aim (commit bb76afe) allows for arbitrary file deletion through relative path traversal. The `run_hash` parameter, which is user-controllable, is concatenated without normalization as part of a path used to specify file deletion. This vulnerability is exposed through the `Repo._close_run()` method, which is accessible via the tracking server instruction API. As a result, an attacker can exploit this to delete any arbitrary file on the machine running the tracking server.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8769" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/59d3472f-f581-4beb-a090-afd36a00ecf7" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-29" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-4rj2-9gcx-5qhx/GHSA-4rj2-9gcx-5qhx.json b/advisories/unreviewed/2025/03/GHSA-4rj2-9gcx-5qhx/GHSA-4rj2-9gcx-5qhx.json new file mode 100644 index 00000000000..c153c52e8da --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4rj2-9gcx-5qhx/GHSA-4rj2-9gcx-5qhx.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4rj2-9gcx-5qhx", + "modified": "2025-03-20T12:32:53Z", + "published": "2025-03-20T12:32:53Z", + "aliases": [ + "CVE-2025-1474" + ], + "details": "In mlflow/mlflow version 2.18, an admin is able to create a new user account without setting a password. This vulnerability could lead to security risks, as accounts without passwords may be susceptible to unauthorized access. Additionally, this issue violates best practices for secure user account management. The issue is fixed in version 2.19.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1474" + }, + { + "type": "WEB", + "url": "https://github.com/mlflow/mlflow/commit/149c9e18aa219bc47e86b432e130e467a36f4a17" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/e79f7774-10fe-46b2-b522-e73b748e3b2d" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-521" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-4rqf-8pfm-p36r/GHSA-4rqf-8pfm-p36r.json b/advisories/unreviewed/2025/03/GHSA-4rqf-8pfm-p36r/GHSA-4rqf-8pfm-p36r.json new file mode 100644 index 00000000000..b05033c5bb2 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4rqf-8pfm-p36r/GHSA-4rqf-8pfm-p36r.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4rqf-8pfm-p36r", + "modified": "2025-03-20T12:32:49Z", + "published": "2025-03-20T12:32:49Z", + "aliases": [ + "CVE-2024-8859" + ], + "details": "A path traversal vulnerability exists in mlflow/mlflow version 2.15.1. When users configure and use the dbfs service, concatenating the URL directly into the file protocol results in an arbitrary file read vulnerability. This issue occurs because only the path part of the URL is checked, while parts such as query and parameters are not handled. The vulnerability is triggered if the user has configured the dbfs service, and during usage, the service is mounted to a local directory.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8859" + }, + { + "type": "WEB", + "url": "https://github.com/mlflow/mlflow/commit/7791b8cdd595f21b5f179c7b17e4b5eb5cbbe654" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/2259b88b-a0c6-4c7c-b434-6aacf6056dcb" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-29" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-4v9f-r55g-g6hc/GHSA-4v9f-r55g-g6hc.json b/advisories/unreviewed/2025/03/GHSA-4v9f-r55g-g6hc/GHSA-4v9f-r55g-g6hc.json new file mode 100644 index 00000000000..97872da5ba0 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4v9f-r55g-g6hc/GHSA-4v9f-r55g-g6hc.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4v9f-r55g-g6hc", + "modified": "2025-03-20T12:32:47Z", + "published": "2025-03-20T12:32:47Z", + "aliases": [ + "CVE-2024-8183" + ], + "details": "A CORS (Cross-Origin Resource Sharing) misconfiguration in prefecthq/prefect version 2.20.2 allows unauthorized domains to access sensitive data. This vulnerability can lead to unauthorized access to the database, resulting in potential data leaks, loss of confidentiality, service disruption, and data integrity risks.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8183" + }, + { + "type": "WEB", + "url": "https://github.com/prefecthq/prefect/commit/a69266e077169b8a32ad76b1dd3ea63b96d011c2" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/b801de43-ff9f-4db9-b583-4797d4f7d3d2" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-346" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-4vm5-r6m3-2448/GHSA-4vm5-r6m3-2448.json b/advisories/unreviewed/2025/03/GHSA-4vm5-r6m3-2448/GHSA-4vm5-r6m3-2448.json new file mode 100644 index 00000000000..529aab2db9e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4vm5-r6m3-2448/GHSA-4vm5-r6m3-2448.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4vm5-r6m3-2448", + "modified": "2025-03-20T12:32:47Z", + "published": "2025-03-20T12:32:47Z", + "aliases": [ + "CVE-2024-8028" + ], + "details": "A vulnerability in danswer-ai/danswer v0.3.94 allows an attacker to cause a Denial of Service (DoS) by uploading a file with a malformed multipart boundary. By appending a large number of characters to the end of the multipart boundary, the server continuously processes each character, rendering the application inaccessible. This issue can be exploited by sending a single crafted request, affecting all users on the server.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8028" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/55530ecb-0ac2-4dc1-9527-bf24de594a57" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-4vmg-rw8f-92f9/GHSA-4vmg-rw8f-92f9.json b/advisories/unreviewed/2025/03/GHSA-4vmg-rw8f-92f9/GHSA-4vmg-rw8f-92f9.json new file mode 100644 index 00000000000..be2302c793f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4vmg-rw8f-92f9/GHSA-4vmg-rw8f-92f9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4vmg-rw8f-92f9", + "modified": "2025-03-20T12:32:46Z", + "published": "2025-03-20T12:32:46Z", + "aliases": [ + "CVE-2024-7804" + ], + "details": "A deserialization vulnerability exists in the Pytorch RPC framework (torch.distributed.rpc) in pytorch/pytorch versions <=2.3.1. The vulnerability arises from the lack of security verification during the deserialization process of PythonUDF objects in pytorch/torch/distributed/rpc/internal.py. This flaw allows an attacker to execute arbitrary code remotely by sending a malicious serialized PythonUDF object, leading to remote code execution (RCE) on the master node.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7804" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/0e870eeb-f924-4054-8fac-d926b1fb7259" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-4vqf-pwq6-3wh3/GHSA-4vqf-pwq6-3wh3.json b/advisories/unreviewed/2025/03/GHSA-4vqf-pwq6-3wh3/GHSA-4vqf-pwq6-3wh3.json new file mode 100644 index 00000000000..939fed1a42e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4vqf-pwq6-3wh3/GHSA-4vqf-pwq6-3wh3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4vqf-pwq6-3wh3", + "modified": "2025-03-20T12:32:49Z", + "published": "2025-03-20T12:32:49Z", + "aliases": [ + "CVE-2024-8982" + ], + "details": "A Local File Inclusion (LFI) vulnerability in OpenLLM version 0.6.10 allows attackers to include files from the local server through the web application. This flaw could expose internal server files and potentially sensitive information such as configuration files, passwords, and other critical data. Unauthorized access to critical server files, such as configuration files, user credentials (/etc/passwd), and private keys, can lead to a complete compromise of the system's security. Attackers could leverage the exposed information to further penetrate the network, exfiltrate data, or escalate privileges within the environment.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8982" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/b7bdc9a1-51ac-402a-8e6e-0d977699aca6" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-29" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-4w44-j4vc-r3rp/GHSA-4w44-j4vc-r3rp.json b/advisories/unreviewed/2025/03/GHSA-4w44-j4vc-r3rp/GHSA-4w44-j4vc-r3rp.json new file mode 100644 index 00000000000..851eca59efb --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4w44-j4vc-r3rp/GHSA-4w44-j4vc-r3rp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4w44-j4vc-r3rp", + "modified": "2025-03-20T12:32:41Z", + "published": "2025-03-20T12:32:41Z", + "aliases": [ + "CVE-2024-10948" + ], + "details": "A vulnerability in the upload function of binary-husky/gpt_academic allows any user to read arbitrary files on the system, including sensitive files such as `config.py`. This issue affects the latest version of the product. An attacker can exploit this vulnerability by intercepting the websocket request during file upload and replacing the file path with the path of the file they wish to read. The server then copies the file to the `private_upload` folder and provides the path to the copied file, which can be accessed via a GET request. This vulnerability can lead to the exposure of sensitive system files, potentially including credentials, configuration files, or sensitive user data.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10948" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/290a379d-8441-4292-a553-3587e8c5c729" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-4wfj-v7c8-rwh4/GHSA-4wfj-v7c8-rwh4.json b/advisories/unreviewed/2025/03/GHSA-4wfj-v7c8-rwh4/GHSA-4wfj-v7c8-rwh4.json new file mode 100644 index 00000000000..4552470e105 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4wfj-v7c8-rwh4/GHSA-4wfj-v7c8-rwh4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4wfj-v7c8-rwh4", + "modified": "2025-03-20T12:32:51Z", + "published": "2025-03-20T12:32:51Z", + "aliases": [ + "CVE-2024-9311" + ], + "details": "A Cross-Site Request Forgery (CSRF) vulnerability in haotian-liu/llava v1.2.0 (LLaVA-1.6) allows an attacker to upload files with malicious content without authentication or user interaction. The uploaded file is stored in a predictable path, enabling the attacker to execute arbitrary JavaScript code in the context of the victim's browser by visiting the crafted file URL. This can lead to theft of sensitive information, session hijacking, or other actions compromising the security and privacy of the victim.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9311" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/15b18b85-5a6b-43e7-bc65-6b4772871e98" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-53gh-p8jc-7rg8/GHSA-53gh-p8jc-7rg8.json b/advisories/unreviewed/2025/03/GHSA-53gh-p8jc-7rg8/GHSA-53gh-p8jc-7rg8.json new file mode 100644 index 00000000000..79b9f1dddf1 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-53gh-p8jc-7rg8/GHSA-53gh-p8jc-7rg8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-53gh-p8jc-7rg8", + "modified": "2025-03-20T12:32:45Z", + "published": "2025-03-20T12:32:45Z", + "aliases": [ + "CVE-2024-6825" + ], + "details": "BerriAI/litellm version 1.40.12 contains a vulnerability that allows remote code execution. The issue exists in the handling of the 'post_call_rules' configuration, where a callback function can be added. The provided value is split at the final '.' mark, with the last part considered the function name and the remaining part appended with the '.py' extension and imported. This allows an attacker to set a system method, such as 'os.system', as a callback, enabling the execution of arbitrary commands when a chat response is processed.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6825" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/1d98bebb-6cf4-46c9-87c3-d3b1972973b5" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-54c7-72v9-gm27/GHSA-54c7-72v9-gm27.json b/advisories/unreviewed/2025/03/GHSA-54c7-72v9-gm27/GHSA-54c7-72v9-gm27.json new file mode 100644 index 00000000000..b2512b0cad2 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-54c7-72v9-gm27/GHSA-54c7-72v9-gm27.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-54c7-72v9-gm27", + "modified": "2025-03-20T12:32:52Z", + "published": "2025-03-20T12:32:52Z", + "aliases": [ + "CVE-2024-9920" + ], + "details": "In version v12 of parisneo/lollms-webui, the 'Send file to AL' function allows uploading files with various extensions, including potentially dangerous ones like .py, .sh, .bat, and more. Attackers can exploit this by uploading files with malicious content and then using the '/open_file' API endpoint to execute these files. The vulnerability arises from the use of 'subprocess.Popen' to open files without proper validation, leading to potential remote code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9920" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/c70c6732-23b3-4ef8-aec6-0a47467d1ed5" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-54hh-fh2m-4396/GHSA-54hh-fh2m-4396.json b/advisories/unreviewed/2025/03/GHSA-54hh-fh2m-4396/GHSA-54hh-fh2m-4396.json new file mode 100644 index 00000000000..9a27febeaf1 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-54hh-fh2m-4396/GHSA-54hh-fh2m-4396.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-54hh-fh2m-4396", + "modified": "2025-03-20T12:32:51Z", + "published": "2025-03-20T12:32:51Z", + "aliases": [ + "CVE-2024-9901" + ], + "details": "LocalAI version v2.19.4 (af0545834fd565ab56af0b9348550ca9c3cb5349) contains a vulnerability where the delete model API improperly neutralizes input during web page generation, leading to a one-time storage cross-site scripting (XSS) vulnerability. This vulnerability allows an attacker to store a malicious payload that executes when a user accesses the homepage. Additionally, the presence of cross-site request forgery (CSRF) can enable automated malicious requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9901" + }, + { + "type": "WEB", + "url": "https://github.com/mudler/localai/commit/a1634b219a4e52813e70ff07e6376a01449c4515" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/31332c23-ea89-4176-ba57-388cf6008945" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-564p-rx2q-4c8v/GHSA-564p-rx2q-4c8v.json b/advisories/unreviewed/2025/03/GHSA-564p-rx2q-4c8v/GHSA-564p-rx2q-4c8v.json new file mode 100644 index 00000000000..7b57f673199 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-564p-rx2q-4c8v/GHSA-564p-rx2q-4c8v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-564p-rx2q-4c8v", + "modified": "2025-03-20T12:32:43Z", + "published": "2025-03-20T12:32:43Z", + "aliases": [ + "CVE-2024-12760" + ], + "details": "An open redirect vulnerability in bentoml/bentoml v1.3.9 allows a remote unauthenticated attacker to redirect users to arbitrary websites via a specially crafted URL. This can be exploited for phishing attacks, malware distribution, and credential theft.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12760" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/2a284ff6-cc6c-4a10-b72e-1bb31c842bca" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-56p4-cfqw-jx4h/GHSA-56p4-cfqw-jx4h.json b/advisories/unreviewed/2025/03/GHSA-56p4-cfqw-jx4h/GHSA-56p4-cfqw-jx4h.json new file mode 100644 index 00000000000..99900a09663 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-56p4-cfqw-jx4h/GHSA-56p4-cfqw-jx4h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-56p4-cfqw-jx4h", + "modified": "2025-03-20T12:32:45Z", + "published": "2025-03-20T12:32:44Z", + "aliases": [ + "CVE-2024-12882" + ], + "details": "comfyanonymous/comfyui version v0.2.4 suffers from a non-blind Server-Side Request Forgery (SSRF) vulnerability. This vulnerability can be exploited by combining the REST APIs `POST /internal/models/download` and `GET /view`, allowing attackers to abuse the victim server's credentials to access unauthorized web resources.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12882" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/e8768cb1-6a80-40c1-9cdf-bcd21f01f85a" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5c8j-g96x-cj78/GHSA-5c8j-g96x-cj78.json b/advisories/unreviewed/2025/03/GHSA-5c8j-g96x-cj78/GHSA-5c8j-g96x-cj78.json new file mode 100644 index 00000000000..86b69b87f0e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5c8j-g96x-cj78/GHSA-5c8j-g96x-cj78.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5c8j-g96x-cj78", + "modified": "2025-03-20T12:32:47Z", + "published": "2025-03-20T12:32:47Z", + "aliases": [ + "CVE-2024-8062" + ], + "details": "A vulnerability in the typeahead endpoint of h2oai/h2o-3 version 3.46.0 allows for a denial of service. The endpoint performs a `HEAD` request to verify the existence of a specified resource without setting a timeout. An attacker can exploit this by sending multiple requests to an attacker-controlled server that hangs, causing the application to block and become unresponsive to other requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8062" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/a04190d9-4acb-449a-9a7f-f1bf6be1ed23" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1088" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5ccf-884p-4jjq/GHSA-5ccf-884p-4jjq.json b/advisories/unreviewed/2025/03/GHSA-5ccf-884p-4jjq/GHSA-5ccf-884p-4jjq.json new file mode 100644 index 00000000000..30338e1e492 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5ccf-884p-4jjq/GHSA-5ccf-884p-4jjq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5ccf-884p-4jjq", + "modified": "2025-03-20T12:32:51Z", + "published": "2025-03-20T12:32:51Z", + "aliases": [ + "CVE-2024-9840" + ], + "details": "A Denial of Service (DoS) vulnerability exists in open-webui/open-webui version 0.3.21. This vulnerability affects multiple endpoints, including `/ollama/models/upload`, `/audio/api/v1/transcriptions`, and `/rag/api/v1/doc`. The application processes multipart boundaries without authentication, leading to resource exhaustion. By appending additional characters to the multipart boundary, an attacker can cause the server to parse each byte of the boundary, ultimately leading to service unavailability. This vulnerability can be exploited remotely, resulting in high CPU and memory usage, and rendering the service inaccessible to legitimate users.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9840" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/9178f09e-4d4f-4a5b-bc32-cada7445b03c" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5chr-fjjv-38qv/GHSA-5chr-fjjv-38qv.json b/advisories/unreviewed/2025/03/GHSA-5chr-fjjv-38qv/GHSA-5chr-fjjv-38qv.json new file mode 100644 index 00000000000..2841f39c401 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5chr-fjjv-38qv/GHSA-5chr-fjjv-38qv.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5chr-fjjv-38qv", + "modified": "2025-03-20T12:32:41Z", + "published": "2025-03-20T12:32:41Z", + "aliases": [ + "CVE-2024-10940" + ], + "details": "A vulnerability in langchain-core versions >=0.1.17,<0.1.53, >=0.2.0,<0.2.43, and >=0.3.0,<0.3.15 allows unauthorized users to read arbitrary files from the host file system. The issue arises from the ability to create langchain_core.prompts.ImagePromptTemplate's (and by extension langchain_core.prompts.ChatPromptTemplate's) with input variables that can read any user-specified path from the server file system. If the outputs of these prompt templates are exposed to the user, either directly or through downstream model outputs, it can lead to the exposure of sensitive information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10940" + }, + { + "type": "WEB", + "url": "https://github.com/langchain-ai/langchain/commit/c1e742347f9701aadba8920e4d1f79a636e50b68" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/be1ee1cb-2147-4ff4-a57b-b6045271cf27" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-497" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5cpq-9538-jm2j/GHSA-5cpq-9538-jm2j.json b/advisories/unreviewed/2025/03/GHSA-5cpq-9538-jm2j/GHSA-5cpq-9538-jm2j.json new file mode 100644 index 00000000000..401d07cfb2b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5cpq-9538-jm2j/GHSA-5cpq-9538-jm2j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5cpq-9538-jm2j", + "modified": "2025-03-20T12:32:49Z", + "published": "2025-03-20T12:32:49Z", + "aliases": [ + "CVE-2024-8966" + ], + "details": "A vulnerability in the file upload process of gradio-app/gradio version @gradio/video@0.10.2 allows for a Denial of Service (DoS) attack. An attacker can append a large number of characters to the end of a multipart boundary, causing the system to continuously process each character and issue warnings. This can render Gradio inaccessible for extended periods, disrupting services and causing significant downtime.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8966" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/7b5932bb-58d1-4e71-b85c-43dc40522ff2" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5fhx-jcwv-9wjj/GHSA-5fhx-jcwv-9wjj.json b/advisories/unreviewed/2025/03/GHSA-5fhx-jcwv-9wjj/GHSA-5fhx-jcwv-9wjj.json new file mode 100644 index 00000000000..4e2211468b0 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5fhx-jcwv-9wjj/GHSA-5fhx-jcwv-9wjj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5fhx-jcwv-9wjj", + "modified": "2025-03-20T12:32:43Z", + "published": "2025-03-20T12:32:43Z", + "aliases": [ + "CVE-2024-12389" + ], + "details": "A path traversal vulnerability exists in binary-husky/gpt_academic version git 310122f. The application supports the extraction of user-provided 7z files without proper validation. The Python py7zr package used for extraction does not guarantee that files will remain within the intended extraction directory. An attacker can exploit this vulnerability to perform arbitrary file writes, which can lead to remote code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12389" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/37afb1c9-bba9-47ee-8617-a5f715271654" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-29" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5jmj-h3c5-682w/GHSA-5jmj-h3c5-682w.json b/advisories/unreviewed/2025/03/GHSA-5jmj-h3c5-682w/GHSA-5jmj-h3c5-682w.json new file mode 100644 index 00000000000..f39d2629d69 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5jmj-h3c5-682w/GHSA-5jmj-h3c5-682w.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5jmj-h3c5-682w", + "modified": "2025-03-20T12:32:38Z", + "published": "2025-03-20T12:32:38Z", + "aliases": [ + "CVE-2024-10109" + ], + "details": "A vulnerability in the mintplex-labs/anything-llm repository, as of commit 5c40419, allows low privilege users to access the sensitive API endpoint \"/api/system/custom-models\". This access enables them to modify the model's API key and base path, leading to potential API key leakage and denial of service on chats.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10109" + }, + { + "type": "WEB", + "url": "https://github.com/mintplex-labs/anything-llm/commit/8d302c3f670c582b09d47e96132c248101447a11" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/ad3c9e76-679d-4775-b203-96947ff73551" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5mh3-rhm7-jxx3/GHSA-5mh3-rhm7-jxx3.json b/advisories/unreviewed/2025/03/GHSA-5mh3-rhm7-jxx3/GHSA-5mh3-rhm7-jxx3.json new file mode 100644 index 00000000000..87beb64b919 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5mh3-rhm7-jxx3/GHSA-5mh3-rhm7-jxx3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5mh3-rhm7-jxx3", + "modified": "2025-03-20T12:32:43Z", + "published": "2025-03-20T12:32:43Z", + "aliases": [ + "CVE-2024-12392" + ], + "details": "A Server-Side Request Forgery (SSRF) vulnerability exists in binary-husky/gpt_academic version git 310122f. The application has a functionality to download papers from arxiv.org, but the URL validation is incomplete. An attacker can exploit this vulnerability to make the application access any URL, including internal services, and read the response. This can be used to access data that are only accessible from the server, such as AWS metadata credentials, and can escalate local exploits to network-based attacks.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12392" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/858de346-698e-4a72-a9e9-3dbd6c60ac18" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5pfw-4vjf-fvc9/GHSA-5pfw-4vjf-fvc9.json b/advisories/unreviewed/2025/03/GHSA-5pfw-4vjf-fvc9/GHSA-5pfw-4vjf-fvc9.json new file mode 100644 index 00000000000..82472e9fd89 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5pfw-4vjf-fvc9/GHSA-5pfw-4vjf-fvc9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5pfw-4vjf-fvc9", + "modified": "2025-03-20T12:32:39Z", + "published": "2025-03-20T12:32:39Z", + "aliases": [ + "CVE-2024-10714" + ], + "details": "A vulnerability in binary-husky/gpt_academic version 3.83 allows an attacker to cause a Denial of Service (DoS) by adding excessive characters to the end of a multipart boundary during file upload. This results in the server continuously processing each character and displaying warnings, rendering the application inaccessible. The issue occurs when the terminal shows a warning: 'multipart.multipart Consuming a byte '0x2d' in end state'.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10714" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/3e25b76c-714f-4948-8f5a-0ec9a6500068" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5v9m-57mq-qc75/GHSA-5v9m-57mq-qc75.json b/advisories/unreviewed/2025/03/GHSA-5v9m-57mq-qc75/GHSA-5v9m-57mq-qc75.json new file mode 100644 index 00000000000..850f8e30201 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5v9m-57mq-qc75/GHSA-5v9m-57mq-qc75.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5v9m-57mq-qc75", + "modified": "2025-03-20T12:32:47Z", + "published": "2025-03-20T12:32:47Z", + "aliases": [ + "CVE-2024-7983" + ], + "details": "In version 0.3.8 of open-webui, an endpoint for converting markdown to HTML is exposed without authentication. A maliciously crafted markdown payload can cause the server to spend excessive time converting it, leading to a denial of service. The server becomes unresponsive to other requests until the conversion is complete.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7983" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/f8156ca5-1328-480f-a72b-8d3dfdad87dc" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5vqr-wprc-cpp7/GHSA-5vqr-wprc-cpp7.json b/advisories/unreviewed/2025/03/GHSA-5vqr-wprc-cpp7/GHSA-5vqr-wprc-cpp7.json new file mode 100644 index 00000000000..e52894129e6 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5vqr-wprc-cpp7/GHSA-5vqr-wprc-cpp7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5vqr-wprc-cpp7", + "modified": "2025-03-20T12:32:41Z", + "published": "2025-03-20T12:32:41Z", + "aliases": [ + "CVE-2024-11041" + ], + "details": "vllm-project vllm version v0.6.2 contains a vulnerability in the MessageQueue.dequeue() API function. The function uses pickle.loads to parse received sockets directly, leading to a remote code execution vulnerability. An attacker can exploit this by sending a malicious payload to the MessageQueue, causing the victim's machine to execute arbitrary code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11041" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/00136195-11e0-4ad0-98d5-72db066e867f" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5xg7-5662-8x7j/GHSA-5xg7-5662-8x7j.json b/advisories/unreviewed/2025/03/GHSA-5xg7-5662-8x7j/GHSA-5xg7-5662-8x7j.json new file mode 100644 index 00000000000..c0eb8c6621a --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5xg7-5662-8x7j/GHSA-5xg7-5662-8x7j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5xg7-5662-8x7j", + "modified": "2025-03-20T12:32:49Z", + "published": "2025-03-20T12:32:49Z", + "aliases": [ + "CVE-2024-8953" + ], + "details": "In composiohq/composio version 0.4.3, the mathematical_calculator endpoint uses the unsafe eval() function to perform mathematical operations. This can lead to arbitrary code execution if untrusted input is passed to the eval() function.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8953" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/8203d721-e05f-4500-a5bc-c0bec980420c" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-627" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-62xp-4pcv-pw3j/GHSA-62xp-4pcv-pw3j.json b/advisories/unreviewed/2025/03/GHSA-62xp-4pcv-pw3j/GHSA-62xp-4pcv-pw3j.json new file mode 100644 index 00000000000..357b36394eb --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-62xp-4pcv-pw3j/GHSA-62xp-4pcv-pw3j.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-62xp-4pcv-pw3j", + "modified": "2025-03-20T12:32:48Z", + "published": "2025-03-20T12:32:48Z", + "aliases": [ + "CVE-2024-8613" + ], + "details": "A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240802 allows attackers to access, copy, and delete other users' chat histories. This issue arises due to improper handling of session data and lack of access control mechanisms, enabling attackers to view and manipulate chat histories of other users.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8613" + }, + { + "type": "WEB", + "url": "https://github.com/gaizhenbiao/chuanhuchatgpt/commit/526c615c437377ee9c71f866fd0f19011910f705" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/76258774-b011-4044-9c3d-c2609b1cbd29" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-63gf-x2fr-8r32/GHSA-63gf-x2fr-8r32.json b/advisories/unreviewed/2025/03/GHSA-63gf-x2fr-8r32/GHSA-63gf-x2fr-8r32.json new file mode 100644 index 00000000000..f9873bb37ee --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-63gf-x2fr-8r32/GHSA-63gf-x2fr-8r32.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-63gf-x2fr-8r32", + "modified": "2025-03-20T12:32:47Z", + "published": "2025-03-20T12:32:47Z", + "aliases": [ + "CVE-2024-8055" + ], + "details": "Vanna v0.6.3 is vulnerable to SQL injection via Snowflake database in its file staging operations using the `PUT` and `COPY` commands. This vulnerability allows unauthenticated remote users to read arbitrary local files on the victim server, such as `/etc/passwd`, by exploiting the exposed SQL queries through a Python Flask API.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8055" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/7c92a611-6756-4885-8969-01d8b85b6c63" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-20T10:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-64c5-jj57-f29g/GHSA-64c5-jj57-f29g.json b/advisories/unreviewed/2025/03/GHSA-64c5-jj57-f29g/GHSA-64c5-jj57-f29g.json new file mode 100644 index 00000000000..f81ae0ee0a3 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-64c5-jj57-f29g/GHSA-64c5-jj57-f29g.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-64c5-jj57-f29g", + "modified": "2025-03-20T12:32:42Z", + "published": "2025-03-20T12:32:42Z", + "aliases": [ + "CVE-2024-11824" + ], + "details": "A stored cross-site scripting (XSS) vulnerability exists in langgenius/dify version latest, specifically in the chat log functionality. The vulnerability arises because certain HTML tags like and