From 2525c8aeeb46a5a980a790bf79d9da615d94aa13 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 24 Mar 2025 21:31:56 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-88m2-j94x-v4fx.json | 35 +++++++++++-- .../GHSA-3jrv-f6qj-v68p.json | 6 ++- .../GHSA-jxfm-c4r3-w3f8.json | 6 ++- .../GHSA-32cm-387p-hxf5.json | 2 +- .../GHSA-5fmp-xvxf-rqw7.json | 2 +- .../GHSA-5rg3-6jx4-c2qf.json | 2 +- .../GHSA-6f2j-w8wg-p875.json | 6 ++- .../GHSA-6g22-jcp8-98gm.json | 3 +- .../GHSA-9qfw-q6c7-9cmx.json | 3 +- .../GHSA-9x9w-38h4-6344.json | 6 ++- .../GHSA-c3qc-xqj2-mqfj.json | 2 +- .../GHSA-cxm9-p3px-pf2v.json | 2 +- .../GHSA-f52w-ff63-7f4c.json | 1 + .../GHSA-fcgr-87fq-q88m.json | 6 ++- .../GHSA-g4r8-m469-x6vf.json | 2 +- .../GHSA-h27p-fqrc-98gx.json | 2 +- .../GHSA-hfmc-qg6v-fwjv.json | 6 ++- .../GHSA-jh27-8mvh-57qm.json | 2 +- .../GHSA-m48w-94wx-3fq6.json | 2 +- .../GHSA-m5cj-m2cq-qv2p.json | 2 +- .../GHSA-mqvg-7j2h-4xx2.json | 3 +- .../GHSA-mw9x-56vq-m9qf.json | 2 +- .../GHSA-p4g7-64mv-v75q.json | 3 +- .../GHSA-p7q7-p4xf-xrpf.json | 2 +- .../GHSA-pr38-7q66-hqqh.json | 2 +- .../GHSA-v6f5-j8rp-3frr.json | 6 ++- .../GHSA-v9q5-7mjm-c2v2.json | 2 +- .../GHSA-vqcg-f9xc-jc83.json | 6 ++- .../GHSA-whvf-pmrc-vgh4.json | 3 +- .../GHSA-wv67-rh6v-76hv.json | 3 +- .../GHSA-xmjj-rc4w-452x.json | 3 +- .../GHSA-42c4-hvg2-mp96.json | 4 +- .../GHSA-6r4c-h9mj-c94g.json | 4 +- .../GHSA-8c5f-qpcm-fgcv.json | 11 ++-- .../GHSA-27v4-w7r4-68vg.json | 15 ++++-- .../GHSA-5q6q-6936-g555.json | 4 +- .../GHSA-459v-rpwc-w8fx.json | 15 ++++-- .../GHSA-8v44-wj8x-wh72.json | 8 +-- .../GHSA-hvhj-8mqf-w2rh.json | 8 +-- .../GHSA-xf4m-339r-jvfr.json | 4 +- .../GHSA-3g45-cr6q-gf5g.json | 4 +- .../GHSA-6r3g-hmqv-cpgr.json | 4 +- .../GHSA-256g-w77v-wxmx.json | 29 +++++++++++ .../GHSA-3v7w-vw6x-qr3j.json | 52 +++++++++++++++++++ .../GHSA-42rw-qp74-jqxj.json | 3 +- .../GHSA-477c-qcmp-3qmv.json | 11 ++-- .../GHSA-4gqh-r946-jvgc.json | 52 +++++++++++++++++++ .../GHSA-4mm3-765w-vpjr.json | 52 +++++++++++++++++++ .../GHSA-6cpx-55pw-9cxq.json | 29 +++++++++++ .../GHSA-77gx-q4qr-rpgr.json | 15 ++++-- .../GHSA-82ff-q3cr-fjgp.json | 40 ++++++++++++++ .../GHSA-8345-rfq2-7h8q.json | 44 ++++++++++++++++ .../GHSA-8hh4-32mr-38xc.json | 52 +++++++++++++++++++ .../GHSA-9pg2-h843-82vg.json | 2 +- .../GHSA-f6qj-5j3v-gwmm.json | 52 +++++++++++++++++++ .../GHSA-f7h7-c794-m3x5.json | 11 ++-- .../GHSA-fx68-23vp-xpxr.json | 36 +++++++++++++ .../GHSA-g53h-cfhr-24hw.json | 40 ++++++++++++++ .../GHSA-h4vh-mhxh-6rrr.json | 44 ++++++++++++++++ .../GHSA-hp2q-g8c8-4494.json | 52 +++++++++++++++++++ .../GHSA-p2xx-r693-hcg3.json | 29 +++++++++++ .../GHSA-v3vp-fg2v-g7q4.json | 29 +++++++++++ .../GHSA-v767-x36h-4gv8.json | 33 ++++++++++++ .../GHSA-x447-66j7-93px.json | 33 ++++++++++++ .../GHSA-x65v-g96x-c6gw.json | 29 +++++++++++ .../GHSA-xp75-w7vq-5x6j.json | 29 +++++++++++ 66 files changed, 938 insertions(+), 74 deletions(-) rename advisories/{unreviewed => github-reviewed}/2025/03/GHSA-88m2-j94x-v4fx/GHSA-88m2-j94x-v4fx.json (67%) create mode 100644 advisories/unreviewed/2025/03/GHSA-256g-w77v-wxmx/GHSA-256g-w77v-wxmx.json create mode 100644 advisories/unreviewed/2025/03/GHSA-3v7w-vw6x-qr3j/GHSA-3v7w-vw6x-qr3j.json create mode 100644 advisories/unreviewed/2025/03/GHSA-4gqh-r946-jvgc/GHSA-4gqh-r946-jvgc.json create mode 100644 advisories/unreviewed/2025/03/GHSA-4mm3-765w-vpjr/GHSA-4mm3-765w-vpjr.json create mode 100644 advisories/unreviewed/2025/03/GHSA-6cpx-55pw-9cxq/GHSA-6cpx-55pw-9cxq.json create mode 100644 advisories/unreviewed/2025/03/GHSA-82ff-q3cr-fjgp/GHSA-82ff-q3cr-fjgp.json create mode 100644 advisories/unreviewed/2025/03/GHSA-8345-rfq2-7h8q/GHSA-8345-rfq2-7h8q.json create mode 100644 advisories/unreviewed/2025/03/GHSA-8hh4-32mr-38xc/GHSA-8hh4-32mr-38xc.json create mode 100644 advisories/unreviewed/2025/03/GHSA-f6qj-5j3v-gwmm/GHSA-f6qj-5j3v-gwmm.json create mode 100644 advisories/unreviewed/2025/03/GHSA-fx68-23vp-xpxr/GHSA-fx68-23vp-xpxr.json create mode 100644 advisories/unreviewed/2025/03/GHSA-g53h-cfhr-24hw/GHSA-g53h-cfhr-24hw.json create mode 100644 advisories/unreviewed/2025/03/GHSA-h4vh-mhxh-6rrr/GHSA-h4vh-mhxh-6rrr.json create mode 100644 advisories/unreviewed/2025/03/GHSA-hp2q-g8c8-4494/GHSA-hp2q-g8c8-4494.json create mode 100644 advisories/unreviewed/2025/03/GHSA-p2xx-r693-hcg3/GHSA-p2xx-r693-hcg3.json create mode 100644 advisories/unreviewed/2025/03/GHSA-v3vp-fg2v-g7q4/GHSA-v3vp-fg2v-g7q4.json create mode 100644 advisories/unreviewed/2025/03/GHSA-v767-x36h-4gv8/GHSA-v767-x36h-4gv8.json create mode 100644 advisories/unreviewed/2025/03/GHSA-x447-66j7-93px/GHSA-x447-66j7-93px.json create mode 100644 advisories/unreviewed/2025/03/GHSA-x65v-g96x-c6gw/GHSA-x65v-g96x-c6gw.json create mode 100644 advisories/unreviewed/2025/03/GHSA-xp75-w7vq-5x6j/GHSA-xp75-w7vq-5x6j.json diff --git a/advisories/unreviewed/2025/03/GHSA-88m2-j94x-v4fx/GHSA-88m2-j94x-v4fx.json b/advisories/github-reviewed/2025/03/GHSA-88m2-j94x-v4fx/GHSA-88m2-j94x-v4fx.json similarity index 67% rename from advisories/unreviewed/2025/03/GHSA-88m2-j94x-v4fx/GHSA-88m2-j94x-v4fx.json rename to advisories/github-reviewed/2025/03/GHSA-88m2-j94x-v4fx/GHSA-88m2-j94x-v4fx.json index 4d603c82508..827742891de 100644 --- a/advisories/unreviewed/2025/03/GHSA-88m2-j94x-v4fx/GHSA-88m2-j94x-v4fx.json +++ b/advisories/github-reviewed/2025/03/GHSA-88m2-j94x-v4fx/GHSA-88m2-j94x-v4fx.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-88m2-j94x-v4fx", - "modified": "2025-03-24T09:34:03Z", + "modified": "2025-03-24T21:31:19Z", "published": "2025-03-24T09:34:03Z", "aliases": [ "CVE-2025-2689" ], + "summary": "yiisoft Yii2 Deserialization of Untrusted Data", "details": "A vulnerability, which was classified as critical, has been found in yiisoft Yii2 up to 2.0.45. Affected by this issue is the function getIterator of the file symfony\\finder\\Iterator\\SortableIterator.php. The manipulation leads to deserialization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", "severity": [ { @@ -14,10 +15,30 @@ }, { "type": "CVSS_V4", - "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "yiisoft/yii2-dev" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "2.0.45" + } + ] + } + ] } ], - "affected": [], "references": [ { "type": "ADVISORY", @@ -27,6 +48,10 @@ "type": "WEB", "url": "https://github.com/gaorenyusi/gaorenyusi/blob/main/Yii2.md" }, + { + "type": "PACKAGE", + "url": "https://github.com/yiisoft/yii2" + }, { "type": "WEB", "url": "https://vuldb.com/?ctiid.300710" @@ -46,8 +71,8 @@ "CWE-502" ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2025-03-24T21:31:19Z", "nvd_published_at": "2025-03-24T07:15:14Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/05/GHSA-3jrv-f6qj-v68p/GHSA-3jrv-f6qj-v68p.json b/advisories/unreviewed/2022/05/GHSA-3jrv-f6qj-v68p/GHSA-3jrv-f6qj-v68p.json index b0266fe93fd..2f89c5047a7 100644 --- a/advisories/unreviewed/2022/05/GHSA-3jrv-f6qj-v68p/GHSA-3jrv-f6qj-v68p.json +++ b/advisories/unreviewed/2022/05/GHSA-3jrv-f6qj-v68p/GHSA-3jrv-f6qj-v68p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3jrv-f6qj-v68p", - "modified": "2025-03-18T21:31:41Z", + "modified": "2025-03-24T21:30:25Z", "published": "2022-05-24T17:25:33Z", "aliases": [ "CVE-2020-16296" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://bugs.ghostscript.com/show_bug.cgi?id=701792" }, + { + "type": "WEB", + "url": "https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/tree/contrib/lips4/gdevlips.c?h=ghostscript-9.18#n163" + }, { "type": "WEB", "url": "https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=9f39ed4a92578a020ae10459643e1fe72573d134" diff --git a/advisories/unreviewed/2022/05/GHSA-jxfm-c4r3-w3f8/GHSA-jxfm-c4r3-w3f8.json b/advisories/unreviewed/2022/05/GHSA-jxfm-c4r3-w3f8/GHSA-jxfm-c4r3-w3f8.json index c17c6abd43f..38bbd8b6709 100644 --- a/advisories/unreviewed/2022/05/GHSA-jxfm-c4r3-w3f8/GHSA-jxfm-c4r3-w3f8.json +++ b/advisories/unreviewed/2022/05/GHSA-jxfm-c4r3-w3f8/GHSA-jxfm-c4r3-w3f8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jxfm-c4r3-w3f8", - "modified": "2025-03-18T21:31:41Z", + "modified": "2025-03-24T21:30:25Z", "published": "2022-05-24T17:25:35Z", "aliases": [ "CVE-2020-17538" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://bugs.ghostscript.com/show_bug.cgi?id=701792" }, + { + "type": "WEB", + "url": "https://cgit.ghostscript.com/cgi-bin/cgit.cgi/ghostpdl.git/tree/contrib/lips4/gdevlips.c?h=ghostscript-9.18#n148" + }, { "type": "WEB", "url": "https://git.ghostscript.com/?p=ghostpdl.git%3Ba=commit%3Bh=9f39ed4a92578a020ae10459643e1fe72573d134" diff --git a/advisories/unreviewed/2023/02/GHSA-32cm-387p-hxf5/GHSA-32cm-387p-hxf5.json b/advisories/unreviewed/2023/02/GHSA-32cm-387p-hxf5/GHSA-32cm-387p-hxf5.json index d447445e92e..25eb07bd7fc 100644 --- a/advisories/unreviewed/2023/02/GHSA-32cm-387p-hxf5/GHSA-32cm-387p-hxf5.json +++ b/advisories/unreviewed/2023/02/GHSA-32cm-387p-hxf5/GHSA-32cm-387p-hxf5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-32cm-387p-hxf5", - "modified": "2023-02-16T21:30:28Z", + "modified": "2025-03-24T21:30:27Z", "published": "2023-02-10T00:30:19Z", "aliases": [ "CVE-2023-24686" diff --git a/advisories/unreviewed/2023/02/GHSA-5fmp-xvxf-rqw7/GHSA-5fmp-xvxf-rqw7.json b/advisories/unreviewed/2023/02/GHSA-5fmp-xvxf-rqw7/GHSA-5fmp-xvxf-rqw7.json index aa77e0924a6..a532600a857 100644 --- a/advisories/unreviewed/2023/02/GHSA-5fmp-xvxf-rqw7/GHSA-5fmp-xvxf-rqw7.json +++ b/advisories/unreviewed/2023/02/GHSA-5fmp-xvxf-rqw7/GHSA-5fmp-xvxf-rqw7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5fmp-xvxf-rqw7", - "modified": "2023-02-16T21:30:28Z", + "modified": "2025-03-24T21:30:27Z", "published": "2023-02-09T21:30:28Z", "aliases": [ "CVE-2023-24322" diff --git a/advisories/unreviewed/2023/02/GHSA-5rg3-6jx4-c2qf/GHSA-5rg3-6jx4-c2qf.json b/advisories/unreviewed/2023/02/GHSA-5rg3-6jx4-c2qf/GHSA-5rg3-6jx4-c2qf.json index 6250992c46a..6dc8cdf6465 100644 --- a/advisories/unreviewed/2023/02/GHSA-5rg3-6jx4-c2qf/GHSA-5rg3-6jx4-c2qf.json +++ b/advisories/unreviewed/2023/02/GHSA-5rg3-6jx4-c2qf/GHSA-5rg3-6jx4-c2qf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5rg3-6jx4-c2qf", - "modified": "2023-02-16T15:30:29Z", + "modified": "2025-03-24T21:30:26Z", "published": "2023-02-09T18:30:27Z", "aliases": [ "CVE-2022-48289" diff --git a/advisories/unreviewed/2023/02/GHSA-6f2j-w8wg-p875/GHSA-6f2j-w8wg-p875.json b/advisories/unreviewed/2023/02/GHSA-6f2j-w8wg-p875/GHSA-6f2j-w8wg-p875.json index 559e9a94ac4..0af3eeef3d6 100644 --- a/advisories/unreviewed/2023/02/GHSA-6f2j-w8wg-p875/GHSA-6f2j-w8wg-p875.json +++ b/advisories/unreviewed/2023/02/GHSA-6f2j-w8wg-p875/GHSA-6f2j-w8wg-p875.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6f2j-w8wg-p875", - "modified": "2023-02-16T21:30:28Z", + "modified": "2025-03-24T21:30:26Z", "published": "2023-02-09T18:30:27Z", "aliases": [ "CVE-2022-48290" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-693" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-6g22-jcp8-98gm/GHSA-6g22-jcp8-98gm.json b/advisories/unreviewed/2023/02/GHSA-6g22-jcp8-98gm/GHSA-6g22-jcp8-98gm.json index d525ac5ad5f..b1636d4aed1 100644 --- a/advisories/unreviewed/2023/02/GHSA-6g22-jcp8-98gm/GHSA-6g22-jcp8-98gm.json +++ b/advisories/unreviewed/2023/02/GHSA-6g22-jcp8-98gm/GHSA-6g22-jcp8-98gm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6g22-jcp8-98gm", - "modified": "2023-02-17T00:30:29Z", + "modified": "2025-03-24T21:30:27Z", "published": "2023-02-10T15:30:28Z", "aliases": [ "CVE-2023-24347" @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-121", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/02/GHSA-9qfw-q6c7-9cmx/GHSA-9qfw-q6c7-9cmx.json b/advisories/unreviewed/2023/02/GHSA-9qfw-q6c7-9cmx/GHSA-9qfw-q6c7-9cmx.json index 172eeab5474..35378499cef 100644 --- a/advisories/unreviewed/2023/02/GHSA-9qfw-q6c7-9cmx/GHSA-9qfw-q6c7-9cmx.json +++ b/advisories/unreviewed/2023/02/GHSA-9qfw-q6c7-9cmx/GHSA-9qfw-q6c7-9cmx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9qfw-q6c7-9cmx", - "modified": "2023-02-17T00:30:29Z", + "modified": "2025-03-24T21:30:27Z", "published": "2023-02-10T15:30:28Z", "aliases": [ "CVE-2023-24346" @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-121", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/02/GHSA-9x9w-38h4-6344/GHSA-9x9w-38h4-6344.json b/advisories/unreviewed/2023/02/GHSA-9x9w-38h4-6344/GHSA-9x9w-38h4-6344.json index 7f35f66c6b0..393d0e557f8 100644 --- a/advisories/unreviewed/2023/02/GHSA-9x9w-38h4-6344/GHSA-9x9w-38h4-6344.json +++ b/advisories/unreviewed/2023/02/GHSA-9x9w-38h4-6344/GHSA-9x9w-38h4-6344.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9x9w-38h4-6344", - "modified": "2023-02-16T21:30:28Z", + "modified": "2025-03-24T21:30:27Z", "published": "2023-02-09T21:30:27Z", "aliases": [ "CVE-2023-24688" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-c3qc-xqj2-mqfj/GHSA-c3qc-xqj2-mqfj.json b/advisories/unreviewed/2023/02/GHSA-c3qc-xqj2-mqfj/GHSA-c3qc-xqj2-mqfj.json index 7118a3696f2..ddcdf01a828 100644 --- a/advisories/unreviewed/2023/02/GHSA-c3qc-xqj2-mqfj/GHSA-c3qc-xqj2-mqfj.json +++ b/advisories/unreviewed/2023/02/GHSA-c3qc-xqj2-mqfj/GHSA-c3qc-xqj2-mqfj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c3qc-xqj2-mqfj", - "modified": "2023-02-16T21:30:28Z", + "modified": "2025-03-24T21:30:27Z", "published": "2023-02-09T21:30:27Z", "aliases": [ "CVE-2023-24689" diff --git a/advisories/unreviewed/2023/02/GHSA-cxm9-p3px-pf2v/GHSA-cxm9-p3px-pf2v.json b/advisories/unreviewed/2023/02/GHSA-cxm9-p3px-pf2v/GHSA-cxm9-p3px-pf2v.json index 50993dbb46f..f5cf6d25443 100644 --- a/advisories/unreviewed/2023/02/GHSA-cxm9-p3px-pf2v/GHSA-cxm9-p3px-pf2v.json +++ b/advisories/unreviewed/2023/02/GHSA-cxm9-p3px-pf2v/GHSA-cxm9-p3px-pf2v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cxm9-p3px-pf2v", - "modified": "2023-02-16T21:30:28Z", + "modified": "2025-03-24T21:30:27Z", "published": "2023-02-10T00:30:19Z", "aliases": [ "CVE-2023-24690" diff --git a/advisories/unreviewed/2023/02/GHSA-f52w-ff63-7f4c/GHSA-f52w-ff63-7f4c.json b/advisories/unreviewed/2023/02/GHSA-f52w-ff63-7f4c/GHSA-f52w-ff63-7f4c.json index 1b9c68d465c..6c0746c012a 100644 --- a/advisories/unreviewed/2023/02/GHSA-f52w-ff63-7f4c/GHSA-f52w-ff63-7f4c.json +++ b/advisories/unreviewed/2023/02/GHSA-f52w-ff63-7f4c/GHSA-f52w-ff63-7f4c.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-75", "CWE-94" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/02/GHSA-fcgr-87fq-q88m/GHSA-fcgr-87fq-q88m.json b/advisories/unreviewed/2023/02/GHSA-fcgr-87fq-q88m/GHSA-fcgr-87fq-q88m.json index 8132acb598a..32e3c3477c2 100644 --- a/advisories/unreviewed/2023/02/GHSA-fcgr-87fq-q88m/GHSA-fcgr-87fq-q88m.json +++ b/advisories/unreviewed/2023/02/GHSA-fcgr-87fq-q88m/GHSA-fcgr-87fq-q88m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fcgr-87fq-q88m", - "modified": "2023-02-16T21:30:28Z", + "modified": "2025-03-24T21:30:27Z", "published": "2023-02-10T00:30:20Z", "aliases": [ "CVE-2023-24684" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-24684" }, + { + "type": "WEB", + "url": "https://github.com/ChurchCRM/CRM/issues/6440" + }, { "type": "WEB", "url": "https://github.com/ChurchCRM/CRM" diff --git a/advisories/unreviewed/2023/02/GHSA-g4r8-m469-x6vf/GHSA-g4r8-m469-x6vf.json b/advisories/unreviewed/2023/02/GHSA-g4r8-m469-x6vf/GHSA-g4r8-m469-x6vf.json index e96a67c18a5..8137293d725 100644 --- a/advisories/unreviewed/2023/02/GHSA-g4r8-m469-x6vf/GHSA-g4r8-m469-x6vf.json +++ b/advisories/unreviewed/2023/02/GHSA-g4r8-m469-x6vf/GHSA-g4r8-m469-x6vf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g4r8-m469-x6vf", - "modified": "2023-02-16T15:30:30Z", + "modified": "2025-03-24T21:30:26Z", "published": "2023-02-09T18:30:27Z", "aliases": [ "CVE-2022-48288" diff --git a/advisories/unreviewed/2023/02/GHSA-h27p-fqrc-98gx/GHSA-h27p-fqrc-98gx.json b/advisories/unreviewed/2023/02/GHSA-h27p-fqrc-98gx/GHSA-h27p-fqrc-98gx.json index a7f1ed74015..4a0b22b9c7c 100644 --- a/advisories/unreviewed/2023/02/GHSA-h27p-fqrc-98gx/GHSA-h27p-fqrc-98gx.json +++ b/advisories/unreviewed/2023/02/GHSA-h27p-fqrc-98gx/GHSA-h27p-fqrc-98gx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h27p-fqrc-98gx", - "modified": "2023-02-16T21:30:28Z", + "modified": "2025-03-24T21:30:27Z", "published": "2023-02-09T21:30:27Z", "aliases": [ "CVE-2023-24687" diff --git a/advisories/unreviewed/2023/02/GHSA-hfmc-qg6v-fwjv/GHSA-hfmc-qg6v-fwjv.json b/advisories/unreviewed/2023/02/GHSA-hfmc-qg6v-fwjv/GHSA-hfmc-qg6v-fwjv.json index 423c994ea70..c071308e38a 100644 --- a/advisories/unreviewed/2023/02/GHSA-hfmc-qg6v-fwjv/GHSA-hfmc-qg6v-fwjv.json +++ b/advisories/unreviewed/2023/02/GHSA-hfmc-qg6v-fwjv/GHSA-hfmc-qg6v-fwjv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hfmc-qg6v-fwjv", - "modified": "2023-02-17T18:30:24Z", + "modified": "2025-03-24T21:30:27Z", "published": "2023-02-10T00:30:20Z", "aliases": [ "CVE-2023-23592" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-jh27-8mvh-57qm/GHSA-jh27-8mvh-57qm.json b/advisories/unreviewed/2023/02/GHSA-jh27-8mvh-57qm/GHSA-jh27-8mvh-57qm.json index 8a965d2eb07..24b1e584d52 100644 --- a/advisories/unreviewed/2023/02/GHSA-jh27-8mvh-57qm/GHSA-jh27-8mvh-57qm.json +++ b/advisories/unreviewed/2023/02/GHSA-jh27-8mvh-57qm/GHSA-jh27-8mvh-57qm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jh27-8mvh-57qm", - "modified": "2023-02-16T15:30:29Z", + "modified": "2025-03-24T21:30:25Z", "published": "2023-02-09T18:30:28Z", "aliases": [ "CVE-2023-0624" diff --git a/advisories/unreviewed/2023/02/GHSA-m48w-94wx-3fq6/GHSA-m48w-94wx-3fq6.json b/advisories/unreviewed/2023/02/GHSA-m48w-94wx-3fq6/GHSA-m48w-94wx-3fq6.json index 02a66cf30e0..f577532d0df 100644 --- a/advisories/unreviewed/2023/02/GHSA-m48w-94wx-3fq6/GHSA-m48w-94wx-3fq6.json +++ b/advisories/unreviewed/2023/02/GHSA-m48w-94wx-3fq6/GHSA-m48w-94wx-3fq6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m48w-94wx-3fq6", - "modified": "2023-02-16T21:30:28Z", + "modified": "2025-03-24T21:30:27Z", "published": "2023-02-09T18:30:27Z", "aliases": [ "CVE-2022-48293" diff --git a/advisories/unreviewed/2023/02/GHSA-m5cj-m2cq-qv2p/GHSA-m5cj-m2cq-qv2p.json b/advisories/unreviewed/2023/02/GHSA-m5cj-m2cq-qv2p/GHSA-m5cj-m2cq-qv2p.json index 329866b8a36..e502c9d54bf 100644 --- a/advisories/unreviewed/2023/02/GHSA-m5cj-m2cq-qv2p/GHSA-m5cj-m2cq-qv2p.json +++ b/advisories/unreviewed/2023/02/GHSA-m5cj-m2cq-qv2p/GHSA-m5cj-m2cq-qv2p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m5cj-m2cq-qv2p", - "modified": "2023-02-17T15:30:26Z", + "modified": "2025-03-24T21:30:27Z", "published": "2023-02-09T18:30:27Z", "aliases": [ "CVE-2022-48301" diff --git a/advisories/unreviewed/2023/02/GHSA-mqvg-7j2h-4xx2/GHSA-mqvg-7j2h-4xx2.json b/advisories/unreviewed/2023/02/GHSA-mqvg-7j2h-4xx2/GHSA-mqvg-7j2h-4xx2.json index 27de18e85cf..8860bf8ee2e 100644 --- a/advisories/unreviewed/2023/02/GHSA-mqvg-7j2h-4xx2/GHSA-mqvg-7j2h-4xx2.json +++ b/advisories/unreviewed/2023/02/GHSA-mqvg-7j2h-4xx2/GHSA-mqvg-7j2h-4xx2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mqvg-7j2h-4xx2", - "modified": "2023-02-17T00:30:29Z", + "modified": "2025-03-24T21:30:27Z", "published": "2023-02-10T15:30:28Z", "aliases": [ "CVE-2023-24345" @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-121", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/02/GHSA-mw9x-56vq-m9qf/GHSA-mw9x-56vq-m9qf.json b/advisories/unreviewed/2023/02/GHSA-mw9x-56vq-m9qf/GHSA-mw9x-56vq-m9qf.json index ca5fe09b6b3..e1743c4e819 100644 --- a/advisories/unreviewed/2023/02/GHSA-mw9x-56vq-m9qf/GHSA-mw9x-56vq-m9qf.json +++ b/advisories/unreviewed/2023/02/GHSA-mw9x-56vq-m9qf/GHSA-mw9x-56vq-m9qf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mw9x-56vq-m9qf", - "modified": "2023-02-16T21:30:27Z", + "modified": "2025-03-24T21:30:27Z", "published": "2023-02-09T18:30:27Z", "aliases": [ "CVE-2022-48300" diff --git a/advisories/unreviewed/2023/02/GHSA-p4g7-64mv-v75q/GHSA-p4g7-64mv-v75q.json b/advisories/unreviewed/2023/02/GHSA-p4g7-64mv-v75q/GHSA-p4g7-64mv-v75q.json index a2374a95512..f0a64daca25 100644 --- a/advisories/unreviewed/2023/02/GHSA-p4g7-64mv-v75q/GHSA-p4g7-64mv-v75q.json +++ b/advisories/unreviewed/2023/02/GHSA-p4g7-64mv-v75q/GHSA-p4g7-64mv-v75q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p4g7-64mv-v75q", - "modified": "2023-02-17T21:30:40Z", + "modified": "2025-03-24T21:30:27Z", "published": "2023-02-10T15:30:28Z", "aliases": [ "CVE-2023-24348" @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-121", "CWE-787" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2023/02/GHSA-p7q7-p4xf-xrpf/GHSA-p7q7-p4xf-xrpf.json b/advisories/unreviewed/2023/02/GHSA-p7q7-p4xf-xrpf/GHSA-p7q7-p4xf-xrpf.json index d300a68fe41..c2328e49c1a 100644 --- a/advisories/unreviewed/2023/02/GHSA-p7q7-p4xf-xrpf/GHSA-p7q7-p4xf-xrpf.json +++ b/advisories/unreviewed/2023/02/GHSA-p7q7-p4xf-xrpf/GHSA-p7q7-p4xf-xrpf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p7q7-p4xf-xrpf", - "modified": "2023-02-17T15:30:25Z", + "modified": "2025-03-24T21:30:26Z", "published": "2023-02-09T18:30:27Z", "aliases": [ "CVE-2022-48294" diff --git a/advisories/unreviewed/2023/02/GHSA-pr38-7q66-hqqh/GHSA-pr38-7q66-hqqh.json b/advisories/unreviewed/2023/02/GHSA-pr38-7q66-hqqh/GHSA-pr38-7q66-hqqh.json index 2a7cfe6a719..50d0d242bf2 100644 --- a/advisories/unreviewed/2023/02/GHSA-pr38-7q66-hqqh/GHSA-pr38-7q66-hqqh.json +++ b/advisories/unreviewed/2023/02/GHSA-pr38-7q66-hqqh/GHSA-pr38-7q66-hqqh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pr38-7q66-hqqh", - "modified": "2023-02-16T21:30:28Z", + "modified": "2025-03-24T21:30:27Z", "published": "2023-02-09T21:30:27Z", "aliases": [ "CVE-2023-24323" diff --git a/advisories/unreviewed/2023/02/GHSA-v6f5-j8rp-3frr/GHSA-v6f5-j8rp-3frr.json b/advisories/unreviewed/2023/02/GHSA-v6f5-j8rp-3frr/GHSA-v6f5-j8rp-3frr.json index 871f577c3a9..1006225a6d4 100644 --- a/advisories/unreviewed/2023/02/GHSA-v6f5-j8rp-3frr/GHSA-v6f5-j8rp-3frr.json +++ b/advisories/unreviewed/2023/02/GHSA-v6f5-j8rp-3frr/GHSA-v6f5-j8rp-3frr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v6f5-j8rp-3frr", - "modified": "2023-02-16T15:30:29Z", + "modified": "2025-03-24T21:30:26Z", "published": "2023-02-09T18:30:27Z", "aliases": [ "CVE-2022-48287" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-693" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-v9q5-7mjm-c2v2/GHSA-v9q5-7mjm-c2v2.json b/advisories/unreviewed/2023/02/GHSA-v9q5-7mjm-c2v2/GHSA-v9q5-7mjm-c2v2.json index adb010db220..18406d2fbf4 100644 --- a/advisories/unreviewed/2023/02/GHSA-v9q5-7mjm-c2v2/GHSA-v9q5-7mjm-c2v2.json +++ b/advisories/unreviewed/2023/02/GHSA-v9q5-7mjm-c2v2/GHSA-v9q5-7mjm-c2v2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v9q5-7mjm-c2v2", - "modified": "2023-02-16T21:30:28Z", + "modified": "2025-03-24T21:30:26Z", "published": "2023-02-09T18:30:27Z", "aliases": [ "CVE-2022-48292" diff --git a/advisories/unreviewed/2023/02/GHSA-vqcg-f9xc-jc83/GHSA-vqcg-f9xc-jc83.json b/advisories/unreviewed/2023/02/GHSA-vqcg-f9xc-jc83/GHSA-vqcg-f9xc-jc83.json index 4a6483f74d4..7ac4ae9a46a 100644 --- a/advisories/unreviewed/2023/02/GHSA-vqcg-f9xc-jc83/GHSA-vqcg-f9xc-jc83.json +++ b/advisories/unreviewed/2023/02/GHSA-vqcg-f9xc-jc83/GHSA-vqcg-f9xc-jc83.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vqcg-f9xc-jc83", - "modified": "2023-02-16T21:30:28Z", + "modified": "2025-03-24T21:30:27Z", "published": "2023-02-10T00:30:19Z", "aliases": [ "CVE-2023-24685" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-24685" }, + { + "type": "WEB", + "url": "https://github.com/ChurchCRM/CRM/issues/6441" + }, { "type": "WEB", "url": "https://github.com/ChurchCRM/CRM" diff --git a/advisories/unreviewed/2023/02/GHSA-whvf-pmrc-vgh4/GHSA-whvf-pmrc-vgh4.json b/advisories/unreviewed/2023/02/GHSA-whvf-pmrc-vgh4/GHSA-whvf-pmrc-vgh4.json index e70382f208e..5a41c6bdf86 100644 --- a/advisories/unreviewed/2023/02/GHSA-whvf-pmrc-vgh4/GHSA-whvf-pmrc-vgh4.json +++ b/advisories/unreviewed/2023/02/GHSA-whvf-pmrc-vgh4/GHSA-whvf-pmrc-vgh4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-whvf-pmrc-vgh4", - "modified": "2023-02-16T21:30:27Z", + "modified": "2025-03-24T21:30:27Z", "published": "2023-02-09T18:30:27Z", "aliases": [ "CVE-2022-48302" @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-862", "CWE-863" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/02/GHSA-wv67-rh6v-76hv/GHSA-wv67-rh6v-76hv.json b/advisories/unreviewed/2023/02/GHSA-wv67-rh6v-76hv/GHSA-wv67-rh6v-76hv.json index a70c52b2a93..25480fd6ce5 100644 --- a/advisories/unreviewed/2023/02/GHSA-wv67-rh6v-76hv/GHSA-wv67-rh6v-76hv.json +++ b/advisories/unreviewed/2023/02/GHSA-wv67-rh6v-76hv/GHSA-wv67-rh6v-76hv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wv67-rh6v-76hv", - "modified": "2023-02-17T00:30:29Z", + "modified": "2025-03-24T21:30:27Z", "published": "2023-02-10T15:30:28Z", "aliases": [ "CVE-2023-24343" @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-121", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/02/GHSA-xmjj-rc4w-452x/GHSA-xmjj-rc4w-452x.json b/advisories/unreviewed/2023/02/GHSA-xmjj-rc4w-452x/GHSA-xmjj-rc4w-452x.json index 4b4c1f66ea3..ae079eb9d0b 100644 --- a/advisories/unreviewed/2023/02/GHSA-xmjj-rc4w-452x/GHSA-xmjj-rc4w-452x.json +++ b/advisories/unreviewed/2023/02/GHSA-xmjj-rc4w-452x/GHSA-xmjj-rc4w-452x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xmjj-rc4w-452x", - "modified": "2023-02-17T00:30:29Z", + "modified": "2025-03-24T21:30:27Z", "published": "2023-02-10T15:30:28Z", "aliases": [ "CVE-2023-24344" @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-121", "CWE-787" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2024/02/GHSA-42c4-hvg2-mp96/GHSA-42c4-hvg2-mp96.json b/advisories/unreviewed/2024/02/GHSA-42c4-hvg2-mp96/GHSA-42c4-hvg2-mp96.json index 49e44c2f97f..ef7759ccc36 100644 --- a/advisories/unreviewed/2024/02/GHSA-42c4-hvg2-mp96/GHSA-42c4-hvg2-mp96.json +++ b/advisories/unreviewed/2024/02/GHSA-42c4-hvg2-mp96/GHSA-42c4-hvg2-mp96.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-269" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-6r4c-h9mj-c94g/GHSA-6r4c-h9mj-c94g.json b/advisories/unreviewed/2024/02/GHSA-6r4c-h9mj-c94g/GHSA-6r4c-h9mj-c94g.json index 376364bd740..d6981c7148c 100644 --- a/advisories/unreviewed/2024/02/GHSA-6r4c-h9mj-c94g/GHSA-6r4c-h9mj-c94g.json +++ b/advisories/unreviewed/2024/02/GHSA-6r4c-h9mj-c94g/GHSA-6r4c-h9mj-c94g.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-6r4c-h9mj-c94g", - "modified": "2024-03-05T21:30:25Z", + "modified": "2025-03-24T21:30:27Z", "published": "2024-02-13T21:30:29Z", "aliases": [ "CVE-2024-1355" ], - "details": "A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance via the actions-console docker container while setting a service URL. Exploitation of this vulnerability required access to the GitHub Enterprise Server instance and access to the Management Console with the editor role. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.12 and was fixed in versions 3.11.5, 3.10.7, 3.9.10, and 3.8.15. This vulnerability was reported via the GitHub Bug Bounty program.\n", + "details": "A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance via the actions-console docker container while setting a service URL. Exploitation of this vulnerability required access to the GitHub Enterprise Server instance and access to the Management Console with the editor role. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.12 and was fixed in versions 3.11.5, 3.10.7, 3.9.10, and 3.8.15. This vulnerability was reported via the GitHub Bug Bounty program.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/02/GHSA-8c5f-qpcm-fgcv/GHSA-8c5f-qpcm-fgcv.json b/advisories/unreviewed/2024/02/GHSA-8c5f-qpcm-fgcv/GHSA-8c5f-qpcm-fgcv.json index b2cbf9fe40b..73d82c6022d 100644 --- a/advisories/unreviewed/2024/02/GHSA-8c5f-qpcm-fgcv/GHSA-8c5f-qpcm-fgcv.json +++ b/advisories/unreviewed/2024/02/GHSA-8c5f-qpcm-fgcv/GHSA-8c5f-qpcm-fgcv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8c5f-qpcm-fgcv", - "modified": "2024-02-27T09:31:17Z", + "modified": "2025-03-24T21:30:28Z", "published": "2024-02-27T09:31:17Z", "aliases": [ "CVE-2023-7198" ], "details": "The WP Dashboard Notes WordPress plugin before 1.0.11 is vulnerable to Insecure Direct Object References (IDOR) in post_id= parameter. Authenticated users are able to delete private notes associated with different user accounts. This poses a significant security risk as it violates the principle of least privilege and compromises the integrity and privacy of user data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-27T09:15:37Z" diff --git a/advisories/unreviewed/2024/03/GHSA-27v4-w7r4-68vg/GHSA-27v4-w7r4-68vg.json b/advisories/unreviewed/2024/03/GHSA-27v4-w7r4-68vg/GHSA-27v4-w7r4-68vg.json index d9b6132bdc0..e9242897f4f 100644 --- a/advisories/unreviewed/2024/03/GHSA-27v4-w7r4-68vg/GHSA-27v4-w7r4-68vg.json +++ b/advisories/unreviewed/2024/03/GHSA-27v4-w7r4-68vg/GHSA-27v4-w7r4-68vg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-27v4-w7r4-68vg", - "modified": "2024-03-18T03:30:32Z", + "modified": "2025-03-24T21:30:28Z", "published": "2024-03-18T03:30:32Z", "aliases": [ "CVE-2023-40160" ], "details": "Directory traversal vulnerability exists in Mailing List Search CGI (pmmls.exe) included in A.K.I Software's PMailServer/PMailServer2 products. If this vulnerability is exploited, a remote attacker may obtain arbitrary files on the server.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-22" + ], + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-18T01:15:48Z" diff --git a/advisories/unreviewed/2024/03/GHSA-5q6q-6936-g555/GHSA-5q6q-6936-g555.json b/advisories/unreviewed/2024/03/GHSA-5q6q-6936-g555/GHSA-5q6q-6936-g555.json index 944415bcff3..13b49abdb3b 100644 --- a/advisories/unreviewed/2024/03/GHSA-5q6q-6936-g555/GHSA-5q6q-6936-g555.json +++ b/advisories/unreviewed/2024/03/GHSA-5q6q-6936-g555/GHSA-5q6q-6936-g555.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-20" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-459v-rpwc-w8fx/GHSA-459v-rpwc-w8fx.json b/advisories/unreviewed/2024/04/GHSA-459v-rpwc-w8fx/GHSA-459v-rpwc-w8fx.json index 780cc148390..fa32446d279 100644 --- a/advisories/unreviewed/2024/04/GHSA-459v-rpwc-w8fx/GHSA-459v-rpwc-w8fx.json +++ b/advisories/unreviewed/2024/04/GHSA-459v-rpwc-w8fx/GHSA-459v-rpwc-w8fx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-459v-rpwc-w8fx", - "modified": "2024-04-05T21:32:43Z", + "modified": "2025-03-24T21:30:28Z", "published": "2024-04-05T21:32:43Z", "aliases": [ "CVE-2024-29743" ], "details": "In tmu_set_temp_lut of tmu.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-05T20:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-8v44-wj8x-wh72/GHSA-8v44-wj8x-wh72.json b/advisories/unreviewed/2024/04/GHSA-8v44-wj8x-wh72/GHSA-8v44-wj8x-wh72.json index fde2bbc7109..ccbd364b7ab 100644 --- a/advisories/unreviewed/2024/04/GHSA-8v44-wj8x-wh72/GHSA-8v44-wj8x-wh72.json +++ b/advisories/unreviewed/2024/04/GHSA-8v44-wj8x-wh72/GHSA-8v44-wj8x-wh72.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-8v44-wj8x-wh72", - "modified": "2024-04-25T06:30:35Z", + "modified": "2025-03-24T21:30:28Z", "published": "2024-04-25T06:30:35Z", "aliases": [ "CVE-2024-23527" ], - "details": "An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an unauthenticated remote attacker to read sensitive information in memory. ", + "details": "An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an unauthenticated remote attacker to read sensitive information in memory.", "severity": [ { "type": "CVSS_V3", @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-125" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-hvhj-8mqf-w2rh/GHSA-hvhj-8mqf-w2rh.json b/advisories/unreviewed/2024/04/GHSA-hvhj-8mqf-w2rh/GHSA-hvhj-8mqf-w2rh.json index c0967275c0a..6866ce932b5 100644 --- a/advisories/unreviewed/2024/04/GHSA-hvhj-8mqf-w2rh/GHSA-hvhj-8mqf-w2rh.json +++ b/advisories/unreviewed/2024/04/GHSA-hvhj-8mqf-w2rh/GHSA-hvhj-8mqf-w2rh.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-hvhj-8mqf-w2rh", - "modified": "2024-04-19T03:31:03Z", + "modified": "2025-03-24T21:30:28Z", "published": "2024-04-19T03:31:03Z", "aliases": [ "CVE-2024-24996" ], - "details": "A Heap overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3 allows an unauthenticated remote attacker to execute arbitrary commands. ", + "details": "A Heap overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3 allows an unauthenticated remote attacker to execute arbitrary commands.", "severity": [ { "type": "CVSS_V3", @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-122" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-xf4m-339r-jvfr/GHSA-xf4m-339r-jvfr.json b/advisories/unreviewed/2024/06/GHSA-xf4m-339r-jvfr/GHSA-xf4m-339r-jvfr.json index e1520eb778f..ce4f9e58768 100644 --- a/advisories/unreviewed/2024/06/GHSA-xf4m-339r-jvfr/GHSA-xf4m-339r-jvfr.json +++ b/advisories/unreviewed/2024/06/GHSA-xf4m-339r-jvfr/GHSA-xf4m-339r-jvfr.json @@ -41,7 +41,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-359" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-3g45-cr6q-gf5g/GHSA-3g45-cr6q-gf5g.json b/advisories/unreviewed/2024/07/GHSA-3g45-cr6q-gf5g/GHSA-3g45-cr6q-gf5g.json index 6cb549f7a32..6dc965e87e3 100644 --- a/advisories/unreviewed/2024/07/GHSA-3g45-cr6q-gf5g/GHSA-3g45-cr6q-gf5g.json +++ b/advisories/unreviewed/2024/07/GHSA-3g45-cr6q-gf5g/GHSA-3g45-cr6q-gf5g.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/08/GHSA-6r3g-hmqv-cpgr/GHSA-6r3g-hmqv-cpgr.json b/advisories/unreviewed/2024/08/GHSA-6r3g-hmqv-cpgr/GHSA-6r3g-hmqv-cpgr.json index 123c0be5a93..a39e4d1daae 100644 --- a/advisories/unreviewed/2024/08/GHSA-6r3g-hmqv-cpgr/GHSA-6r3g-hmqv-cpgr.json +++ b/advisories/unreviewed/2024/08/GHSA-6r3g-hmqv-cpgr/GHSA-6r3g-hmqv-cpgr.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-256g-w77v-wxmx/GHSA-256g-w77v-wxmx.json b/advisories/unreviewed/2025/03/GHSA-256g-w77v-wxmx/GHSA-256g-w77v-wxmx.json new file mode 100644 index 00000000000..850d6230cac --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-256g-w77v-wxmx/GHSA-256g-w77v-wxmx.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-256g-w77v-wxmx", + "modified": "2025-03-24T21:30:34Z", + "published": "2025-03-24T21:30:33Z", + "aliases": [ + "CVE-2025-29312" + ], + "details": "An issue in onos v2.7.0 allows attackers to trigger unexpected behavior within a device connected to a legacy switch via changing the link type from indirect to direct.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29312" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Saber-Berserker/4e54c2aa70abab2b133ce2c2b7e91249" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-24T21:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-3v7w-vw6x-qr3j/GHSA-3v7w-vw6x-qr3j.json b/advisories/unreviewed/2025/03/GHSA-3v7w-vw6x-qr3j/GHSA-3v7w-vw6x-qr3j.json new file mode 100644 index 00000000000..8138cccc2c3 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3v7w-vw6x-qr3j/GHSA-3v7w-vw6x-qr3j.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3v7w-vw6x-qr3j", + "modified": "2025-03-24T21:30:34Z", + "published": "2025-03-24T21:30:34Z", + "aliases": [ + "CVE-2025-2711" + ], + "details": "A vulnerability was found in Yonyou UFIDA ERP-NC 5.0. It has been classified as problematic. Affected is an unknown function of the file /help/systop.jsp. The manipulation of the argument langcode leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2711" + }, + { + "type": "WEB", + "url": "https://github.com/Hebing123/cve/issues/86" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.300732" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.300732" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.517309" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-24T21:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-42rw-qp74-jqxj/GHSA-42rw-qp74-jqxj.json b/advisories/unreviewed/2025/03/GHSA-42rw-qp74-jqxj/GHSA-42rw-qp74-jqxj.json index 4cc02597485..62db45de678 100644 --- a/advisories/unreviewed/2025/03/GHSA-42rw-qp74-jqxj/GHSA-42rw-qp74-jqxj.json +++ b/advisories/unreviewed/2025/03/GHSA-42rw-qp74-jqxj/GHSA-42rw-qp74-jqxj.json @@ -34,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-1262" + "CWE-1262", + "CWE-190" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-477c-qcmp-3qmv/GHSA-477c-qcmp-3qmv.json b/advisories/unreviewed/2025/03/GHSA-477c-qcmp-3qmv/GHSA-477c-qcmp-3qmv.json index 746d8cc9771..cc489c24183 100644 --- a/advisories/unreviewed/2025/03/GHSA-477c-qcmp-3qmv/GHSA-477c-qcmp-3qmv.json +++ b/advisories/unreviewed/2025/03/GHSA-477c-qcmp-3qmv/GHSA-477c-qcmp-3qmv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-477c-qcmp-3qmv", - "modified": "2025-03-23T06:30:26Z", + "modified": "2025-03-24T21:30:33Z", "published": "2025-03-23T06:30:26Z", "aliases": [ "CVE-2025-1446" ], "details": "The Pods WordPress plugin before 3.2.8.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-23T06:15:12Z" diff --git a/advisories/unreviewed/2025/03/GHSA-4gqh-r946-jvgc/GHSA-4gqh-r946-jvgc.json b/advisories/unreviewed/2025/03/GHSA-4gqh-r946-jvgc/GHSA-4gqh-r946-jvgc.json new file mode 100644 index 00000000000..7d6eb4a5d10 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4gqh-r946-jvgc/GHSA-4gqh-r946-jvgc.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4gqh-r946-jvgc", + "modified": "2025-03-24T21:30:33Z", + "published": "2025-03-24T21:30:33Z", + "aliases": [ + "CVE-2025-2707" + ], + "details": "A vulnerability, which was classified as critical, has been found in zhijiantianya ruoyi-vue-pro 2.4.1. Affected by this issue is some unknown functionality of the file /app-api/infra/file/upload of the component Front-End Store Interface. The manipulation of the argument path leads to path traversal. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2707" + }, + { + "type": "WEB", + "url": "https://github.com/uglory-gll/javasec/blob/main/ruoyi-vue-pro.md#3file-path-traversal-front-end" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.300728" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.300728" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.517029" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-24T19:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-4mm3-765w-vpjr/GHSA-4mm3-765w-vpjr.json b/advisories/unreviewed/2025/03/GHSA-4mm3-765w-vpjr/GHSA-4mm3-765w-vpjr.json new file mode 100644 index 00000000000..549a76a76d5 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4mm3-765w-vpjr/GHSA-4mm3-765w-vpjr.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4mm3-765w-vpjr", + "modified": "2025-03-24T21:30:34Z", + "published": "2025-03-24T21:30:34Z", + "aliases": [ + "CVE-2025-2710" + ], + "details": "A vulnerability was found in Yonyou UFIDA ERP-NC 5.0 and classified as problematic. This issue affects some unknown processing of the file /menu.jsp. The manipulation of the argument flag leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2710" + }, + { + "type": "WEB", + "url": "https://github.com/Hebing123/cve/issues/85" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.300731" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.300731" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.517306" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-24T21:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6cpx-55pw-9cxq/GHSA-6cpx-55pw-9cxq.json b/advisories/unreviewed/2025/03/GHSA-6cpx-55pw-9cxq/GHSA-6cpx-55pw-9cxq.json new file mode 100644 index 00000000000..9d4e87105d0 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-6cpx-55pw-9cxq/GHSA-6cpx-55pw-9cxq.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6cpx-55pw-9cxq", + "modified": "2025-03-24T21:30:33Z", + "published": "2025-03-24T21:30:33Z", + "aliases": [ + "CVE-2025-29311" + ], + "details": "Limited secret space in LLDP packets used in onos v2.7.0 allows attackers to obtain the private key via a bruteforce attack. Attackers are able to leverage this vulnerability into creating crafted LLDP packets.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29311" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Saber-Berserker/790f2a75ae482df3fd0fce569f30504a;" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-24T21:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-77gx-q4qr-rpgr/GHSA-77gx-q4qr-rpgr.json b/advisories/unreviewed/2025/03/GHSA-77gx-q4qr-rpgr/GHSA-77gx-q4qr-rpgr.json index c7200f2d6f6..089204f9d18 100644 --- a/advisories/unreviewed/2025/03/GHSA-77gx-q4qr-rpgr/GHSA-77gx-q4qr-rpgr.json +++ b/advisories/unreviewed/2025/03/GHSA-77gx-q4qr-rpgr/GHSA-77gx-q4qr-rpgr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-77gx-q4qr-rpgr", - "modified": "2025-03-24T18:31:03Z", + "modified": "2025-03-24T21:30:33Z", "published": "2025-03-24T18:31:03Z", "aliases": [ "CVE-2025-30112" ], "details": "On 70mai Dash Cam 1S devices, by connecting directly to the dashcam's network and accessing the API on port 80 and RTSP on port 554, an attacker can bypass the device authorization mechanism from the official mobile app that requires a user to physically press on the power button during a connection.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-288" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-24T17:15:21Z" diff --git a/advisories/unreviewed/2025/03/GHSA-82ff-q3cr-fjgp/GHSA-82ff-q3cr-fjgp.json b/advisories/unreviewed/2025/03/GHSA-82ff-q3cr-fjgp/GHSA-82ff-q3cr-fjgp.json new file mode 100644 index 00000000000..cb67777d1a3 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-82ff-q3cr-fjgp/GHSA-82ff-q3cr-fjgp.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-82ff-q3cr-fjgp", + "modified": "2025-03-24T21:30:33Z", + "published": "2025-03-24T21:30:33Z", + "aliases": [ + "CVE-2025-2231" + ], + "details": "PDF-XChange Editor RTF File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.\n\nThe specific flaw exists within the parsing of RTF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-25473.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2231" + }, + { + "type": "WEB", + "url": "https://www.pdf-xchange.com/support/security-bulletins.html" + }, + { + "type": "WEB", + "url": "https://www.zerodayinitiative.com/advisories/ZDI-25-129" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-24T20:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-8345-rfq2-7h8q/GHSA-8345-rfq2-7h8q.json b/advisories/unreviewed/2025/03/GHSA-8345-rfq2-7h8q/GHSA-8345-rfq2-7h8q.json new file mode 100644 index 00000000000..8a1d43508c8 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-8345-rfq2-7h8q/GHSA-8345-rfq2-7h8q.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8345-rfq2-7h8q", + "modified": "2025-03-24T21:30:33Z", + "published": "2025-03-24T21:30:33Z", + "aliases": [ + "CVE-2025-2747" + ], + "details": "An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server component password handling for the server defined None type. Authentication bypass allows an attacker to control administrative objects.This issue affects Xperience through 13.0.178.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2747" + }, + { + "type": "WEB", + "url": "https://devnet.kentico.com/download/hotfixes" + }, + { + "type": "WEB", + "url": "https://github.com/watchtowrlabs/kentico-xperience13-AuthBypass-wt-2025-0011" + }, + { + "type": "WEB", + "url": "https://labs.watchtowr.com/bypassing-authentication-like-its-the-90s-pre-auth-rce-chain-s-in-kentico-xperience-cms" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-24T19:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-8hh4-32mr-38xc/GHSA-8hh4-32mr-38xc.json b/advisories/unreviewed/2025/03/GHSA-8hh4-32mr-38xc/GHSA-8hh4-32mr-38xc.json new file mode 100644 index 00000000000..a1a7be2c5aa --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-8hh4-32mr-38xc/GHSA-8hh4-32mr-38xc.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8hh4-32mr-38xc", + "modified": "2025-03-24T21:30:33Z", + "published": "2025-03-24T21:30:33Z", + "aliases": [ + "CVE-2025-2706" + ], + "details": "A vulnerability classified as critical was found in Digiwin ERP 5.0.1. Affected by this vulnerability is an unknown functionality of the file /Api/TinyMce/UploadAjaxAPI.ashx. The manipulation of the argument File leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2706" + }, + { + "type": "WEB", + "url": "https://github.com/Rain1er/report/blob/main/THNlcnBf/RCE_5.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.300727" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.300727" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.516293" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-24T19:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9pg2-h843-82vg/GHSA-9pg2-h843-82vg.json b/advisories/unreviewed/2025/03/GHSA-9pg2-h843-82vg/GHSA-9pg2-h843-82vg.json index 65027d0255a..be2ef0ddfb5 100644 --- a/advisories/unreviewed/2025/03/GHSA-9pg2-h843-82vg/GHSA-9pg2-h843-82vg.json +++ b/advisories/unreviewed/2025/03/GHSA-9pg2-h843-82vg/GHSA-9pg2-h843-82vg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9pg2-h843-82vg", - "modified": "2025-03-08T03:30:49Z", + "modified": "2025-03-24T21:30:33Z", "published": "2025-03-08T03:30:49Z", "aliases": [ "CVE-2025-1261" diff --git a/advisories/unreviewed/2025/03/GHSA-f6qj-5j3v-gwmm/GHSA-f6qj-5j3v-gwmm.json b/advisories/unreviewed/2025/03/GHSA-f6qj-5j3v-gwmm/GHSA-f6qj-5j3v-gwmm.json new file mode 100644 index 00000000000..56db71da988 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-f6qj-5j3v-gwmm/GHSA-f6qj-5j3v-gwmm.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f6qj-5j3v-gwmm", + "modified": "2025-03-24T21:30:33Z", + "published": "2025-03-24T21:30:33Z", + "aliases": [ + "CVE-2025-2708" + ], + "details": "A vulnerability, which was classified as critical, was found in zhijiantianya ruoyi-vue-pro 2.4.1. This affects an unknown part of the file /admin-api/infra/file/upload of the component Backend File Upload Interface. The manipulation of the argument path leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2708" + }, + { + "type": "WEB", + "url": "https://github.com/uglory-gll/javasec/blob/main/ruoyi-vue-pro.md#4file-path-traversal-back-end" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.300729" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.300729" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.517030" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-24T20:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-f7h7-c794-m3x5/GHSA-f7h7-c794-m3x5.json b/advisories/unreviewed/2025/03/GHSA-f7h7-c794-m3x5/GHSA-f7h7-c794-m3x5.json index fbad85bedb6..351e663db41 100644 --- a/advisories/unreviewed/2025/03/GHSA-f7h7-c794-m3x5/GHSA-f7h7-c794-m3x5.json +++ b/advisories/unreviewed/2025/03/GHSA-f7h7-c794-m3x5/GHSA-f7h7-c794-m3x5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f7h7-c794-m3x5", - "modified": "2025-03-23T06:30:26Z", + "modified": "2025-03-24T21:30:33Z", "published": "2025-03-23T06:30:26Z", "aliases": [ "CVE-2025-0718" ], "details": "The Nested Pages WordPress plugin before 3.2.13 does not sanitise and escape some of its settings, which could allow high privilege users such as contributors to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-23T06:15:11Z" diff --git a/advisories/unreviewed/2025/03/GHSA-fx68-23vp-xpxr/GHSA-fx68-23vp-xpxr.json b/advisories/unreviewed/2025/03/GHSA-fx68-23vp-xpxr/GHSA-fx68-23vp-xpxr.json new file mode 100644 index 00000000000..b259f61c617 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-fx68-23vp-xpxr/GHSA-fx68-23vp-xpxr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fx68-23vp-xpxr", + "modified": "2025-03-24T21:30:33Z", + "published": "2025-03-24T21:30:33Z", + "aliases": [ + "CVE-2025-2748" + ], + "details": "The Kentico Xperience application does not fully validate or filter files uploaded via the multiple-file upload functionality, which allows for stored XSS.This issue affects Kentico Xperience through 13.0.178.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2748" + }, + { + "type": "WEB", + "url": "https://devnet.kentico.com/download/hotfixes" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-24T19:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-g53h-cfhr-24hw/GHSA-g53h-cfhr-24hw.json b/advisories/unreviewed/2025/03/GHSA-g53h-cfhr-24hw/GHSA-g53h-cfhr-24hw.json new file mode 100644 index 00000000000..6f0e2056e17 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-g53h-cfhr-24hw/GHSA-g53h-cfhr-24hw.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g53h-cfhr-24hw", + "modified": "2025-03-24T21:30:33Z", + "published": "2025-03-24T21:30:33Z", + "aliases": [ + "CVE-2025-2749" + ], + "details": "An authenticated remote code execution in Kentico Xperience allows authenticated users Staging Sync Server to upload arbitrary data to path relative locations. This results in path traversal and arbitrary file upload, including content that can be executed server side leading to remote code execution.This issue affects Kentico Xperience through 13.0.178.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2749" + }, + { + "type": "WEB", + "url": "https://devnet.kentico.com/download/hotfixes" + }, + { + "type": "WEB", + "url": "https://labs.watchtowr.com/bypassing-authentication-like-its-the-90s-pre-auth-rce-chain-s-in-kentico-xperience-cms" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-24T19:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-h4vh-mhxh-6rrr/GHSA-h4vh-mhxh-6rrr.json b/advisories/unreviewed/2025/03/GHSA-h4vh-mhxh-6rrr/GHSA-h4vh-mhxh-6rrr.json new file mode 100644 index 00000000000..04c0614bfd2 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-h4vh-mhxh-6rrr/GHSA-h4vh-mhxh-6rrr.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h4vh-mhxh-6rrr", + "modified": "2025-03-24T21:30:33Z", + "published": "2025-03-24T21:30:33Z", + "aliases": [ + "CVE-2025-2746" + ], + "details": "An authentication bypass vulnerability in Kentico Xperience allows authentication bypass via the Staging Sync Server password handling of empty SHA1 usernames in digest authentication. Authentication bypass allows an attacker to control administrative objects.This issue affects Xperience through 13.0.172.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2746" + }, + { + "type": "WEB", + "url": "https://devnet.kentico.com/download/hotfixes" + }, + { + "type": "WEB", + "url": "https://github.com/watchtowrlabs/kentico-xperience13-AuthBypass-wt-2025-0011" + }, + { + "type": "WEB", + "url": "https://labs.watchtowr.com/bypassing-authentication-like-its-the-90s-pre-auth-rce-chain-s-in-kentico-xperience-cms" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-24T19:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-hp2q-g8c8-4494/GHSA-hp2q-g8c8-4494.json b/advisories/unreviewed/2025/03/GHSA-hp2q-g8c8-4494/GHSA-hp2q-g8c8-4494.json new file mode 100644 index 00000000000..4473ad753f2 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-hp2q-g8c8-4494/GHSA-hp2q-g8c8-4494.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hp2q-g8c8-4494", + "modified": "2025-03-24T21:30:34Z", + "published": "2025-03-24T21:30:33Z", + "aliases": [ + "CVE-2025-2709" + ], + "details": "A vulnerability has been found in Yonyou UFIDA ERP-NC 5.0 and classified as problematic. This vulnerability affects unknown code of the file /login.jsp. The manipulation of the argument key/redirect leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2709" + }, + { + "type": "WEB", + "url": "https://github.com/Hebing123/cve/issues/84" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.300730" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.300730" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.517305" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-24T20:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-p2xx-r693-hcg3/GHSA-p2xx-r693-hcg3.json b/advisories/unreviewed/2025/03/GHSA-p2xx-r693-hcg3/GHSA-p2xx-r693-hcg3.json new file mode 100644 index 00000000000..fa188bfe108 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-p2xx-r693-hcg3/GHSA-p2xx-r693-hcg3.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p2xx-r693-hcg3", + "modified": "2025-03-24T21:30:34Z", + "published": "2025-03-24T21:30:33Z", + "aliases": [ + "CVE-2025-29310" + ], + "details": "An issue in onos v2.7.0 allows attackers to trigger a packet deserialization problem when supplying a crafted LLDP packet. This vulnerability allows attackers to execute arbitrary commands or access network information.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29310" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Saber-Berserker/10c9d548b38fa988310d90b8314e3129." + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-24T21:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-v3vp-fg2v-g7q4/GHSA-v3vp-fg2v-g7q4.json b/advisories/unreviewed/2025/03/GHSA-v3vp-fg2v-g7q4/GHSA-v3vp-fg2v-g7q4.json new file mode 100644 index 00000000000..98d2809b276 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-v3vp-fg2v-g7q4/GHSA-v3vp-fg2v-g7q4.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v3vp-fg2v-g7q4", + "modified": "2025-03-24T21:30:34Z", + "published": "2025-03-24T21:30:34Z", + "aliases": [ + "CVE-2025-29313" + ], + "details": "Use of incorrectly resolved name or reference in OpenDaylight Service Function Chaining (SFC) Subproject SFC Sodium-SR4 and below allows attackers to cause a Denial of Service (DoS).", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29313" + }, + { + "type": "WEB", + "url": "https://blog.csdn.net/weixin_43959580/article/details/146018191" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-24T21:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-v767-x36h-4gv8/GHSA-v767-x36h-4gv8.json b/advisories/unreviewed/2025/03/GHSA-v767-x36h-4gv8/GHSA-v767-x36h-4gv8.json new file mode 100644 index 00000000000..17c974638bf --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-v767-x36h-4gv8/GHSA-v767-x36h-4gv8.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v767-x36h-4gv8", + "modified": "2025-03-24T21:30:33Z", + "published": "2025-03-24T21:30:33Z", + "aliases": [ + "CVE-2025-29135" + ], + "details": "A stack-based buffer overflow vulnerability in Tenda AC7 V15.03.06.44 allows a remote attacker to execute arbitrary code through a stack overflow attack using the security parameter of the formWifiBasicSet function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29135" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Raining-101/1651dd3901efdbb38d94a156a54bbc62" + }, + { + "type": "WEB", + "url": "https://github.com/Raining-101/IOT_cve/blob/main/a7_formWifiBasic_Setsecurity_stackoverflow.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-24T21:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-x447-66j7-93px/GHSA-x447-66j7-93px.json b/advisories/unreviewed/2025/03/GHSA-x447-66j7-93px/GHSA-x447-66j7-93px.json new file mode 100644 index 00000000000..cdcd14a5fbe --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-x447-66j7-93px/GHSA-x447-66j7-93px.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x447-66j7-93px", + "modified": "2025-03-24T21:30:33Z", + "published": "2025-03-24T21:30:33Z", + "aliases": [ + "CVE-2025-29100" + ], + "details": "Tenda AC8 V16.03.34.06 is vulnerable to Buffer Overflow in the fromSetRouteStatic function via the parameter list.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29100" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Raining-101/b2bd27d16cdca94d330150a8ead9caa8" + }, + { + "type": "WEB", + "url": "https://github.com/Raining-101/IOT_cve/blob/main/Tenda%20a8%20V16.03.34.06%20fromSetRouteStatic_stack_overflow.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-24T21:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-x65v-g96x-c6gw/GHSA-x65v-g96x-c6gw.json b/advisories/unreviewed/2025/03/GHSA-x65v-g96x-c6gw/GHSA-x65v-g96x-c6gw.json new file mode 100644 index 00000000000..7c5217b2b45 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-x65v-g96x-c6gw/GHSA-x65v-g96x-c6gw.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x65v-g96x-c6gw", + "modified": "2025-03-24T21:30:34Z", + "published": "2025-03-24T21:30:34Z", + "aliases": [ + "CVE-2025-29315" + ], + "details": "An issue in the Shiro-based RBAC (Role-based Access Control) mechanism of OpenDaylight Service Function Chaining (SFC) Subproject SFC Sodium-SR4 and below allows attackers to execute privileged operations via a crafted request.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29315" + }, + { + "type": "WEB", + "url": "https://blog.csdn.net/weixin_43959580/article/details/144794289" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-24T21:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-xp75-w7vq-5x6j/GHSA-xp75-w7vq-5x6j.json b/advisories/unreviewed/2025/03/GHSA-xp75-w7vq-5x6j/GHSA-xp75-w7vq-5x6j.json new file mode 100644 index 00000000000..bd67f871cb8 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-xp75-w7vq-5x6j/GHSA-xp75-w7vq-5x6j.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xp75-w7vq-5x6j", + "modified": "2025-03-24T21:30:34Z", + "published": "2025-03-24T21:30:34Z", + "aliases": [ + "CVE-2025-29314" + ], + "details": "Insecure Shiro cookie configurations in OpenDaylight Service Function Chaining (SFC) Subproject SFC Sodium-SR4 and below allow attackers to access sensitive information via a man-in-the-middle attack.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29314" + }, + { + "type": "WEB", + "url": "https://blog.csdn.net/weixin_43959580/article/details/146018166" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-24T21:15:18Z" + } +} \ No newline at end of file