From 280632724b6cab913f9990ea2b87b651fa166561 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 9 Jan 2025 21:33:03 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-c5pj-m2vw-68wh.json | 6 ++- .../GHSA-3cr6-x963-cvm9.json | 4 +- .../GHSA-77mp-cm2p-44gj.json | 4 +- .../GHSA-8fgq-jggm-33jc.json | 4 +- .../GHSA-f5q8-q9fw-rc2j.json | 6 ++- .../GHSA-fvmr-cw8g-v3m9.json | 4 +- .../GHSA-g67q-47ww-68wp.json | 4 +- .../GHSA-h7h9-wg3c-h4wv.json | 4 +- .../GHSA-m8wf-fqcm-6693.json | 1 + .../GHSA-mc5v-8859-pvcf.json | 4 +- .../GHSA-mvj7-x43c-gpcj.json | 4 +- .../GHSA-wpvr-v2cc-f6qx.json | 4 +- .../GHSA-2jvx-42cx-5ggp.json | 6 ++- .../GHSA-7jrw-mp94-7v28.json | 6 ++- .../GHSA-p7jx-m4x8-cghf.json | 6 ++- .../GHSA-69cq-jw85-57p8.json | 11 +++-- .../GHSA-8xhh-j9m8-989c.json | 11 +++-- .../GHSA-5fwg-75w6-7gf9.json | 15 +++++-- .../GHSA-7hmq-6483-qr84.json | 15 +++++-- .../GHSA-8gv8-jqm3-r824.json | 11 +++-- .../GHSA-f2cq-j285-crf8.json | 11 +++-- .../GHSA-qcc7-grh2-48hx.json | 11 +++-- .../GHSA-gxrf-wgpm-vj98.json | 1 + .../GHSA-3chv-hrqx-p726.json | 1 + .../GHSA-49gp-6j88-r9j7.json | 3 +- .../GHSA-76ph-jc9g-v47h.json | 6 ++- .../GHSA-77rq-3336-8w4x.json | 3 +- .../GHSA-pq42-5fqr-w8cx.json | 3 +- .../GHSA-qhv3-2cgf-c955.json | 6 ++- .../GHSA-r6g4-pj3m-jq5m.json | 1 + .../GHSA-w9fw-pjxp-5fgx.json | 3 +- .../GHSA-2h7q-5r55-6wf5.json | 11 +++-- .../GHSA-3868-3wh9-6qr7.json | 11 +++-- .../GHSA-439r-vwp4-cgfr.json | 15 +++++-- .../GHSA-4hrg-cvr4-ff8f.json | 15 +++++-- .../GHSA-4x48-ph6h-wfmf.json | 15 +++++-- .../GHSA-fmfx-vcm3-x4fp.json | 15 +++++-- .../GHSA-hc38-wh54-qgvx.json | 6 ++- .../GHSA-pvx3-2639-67p3.json | 11 +++-- .../GHSA-223j-7cj4-4cw7.json | 31 +++++++++++++ .../GHSA-2479-2frf-9263.json | 31 +++++++++++++ .../GHSA-2gj6-558v-rq2w.json | 36 +++++++++++++++ .../GHSA-2q57-gr73-v7pg.json | 33 ++++++++++++++ .../GHSA-2rx4-vrv5-3mjp.json | 31 +++++++++++++ .../GHSA-2wf3-32wx-c338.json | 29 ++++++++++++ .../GHSA-37wj-v394-2xvc.json | 36 +++++++++++++++ .../GHSA-4g5v-5q43-rwpj.json | 11 +++-- .../GHSA-57r5-pmvw-w26w.json | 31 +++++++++++++ .../GHSA-5c5x-jw5q-2wpw.json | 29 ++++++++++++ .../GHSA-5rcq-gp73-g9jv.json | 31 +++++++++++++ .../GHSA-623r-49cc-q6vj.json | 31 +++++++++++++ .../GHSA-6372-2hcg-2fr4.json | 31 +++++++++++++ .../GHSA-63wg-87qv-rw4r.json | 31 +++++++++++++ .../GHSA-68jp-4r95-v8vr.json | 44 +++++++++++++++++++ .../GHSA-6g5p-29h6-5w4p.json | 29 ++++++++++++ .../GHSA-6h86-6h56-2j4j.json | 31 +++++++++++++ .../GHSA-6hq6-3pp3-9598.json | 31 +++++++++++++ .../GHSA-6j67-4cmx-rgw8.json | 31 +++++++++++++ .../GHSA-6q5c-9hq7-3fc3.json | 36 +++++++++++++++ .../GHSA-7649-pgpq-cpch.json | 31 +++++++++++++ .../GHSA-8244-g8gx-36rj.json | 29 ++++++++++++ .../GHSA-863q-738r-33x7.json | 31 +++++++++++++ .../GHSA-88c8-vf36-8mvr.json | 36 +++++++++++++++ .../GHSA-8hmg-gpg9-2qqw.json | 31 +++++++++++++ .../GHSA-932w-6jv2-mm8q.json | 31 +++++++++++++ .../GHSA-9838-cxcw-r6rf.json | 31 +++++++++++++ .../GHSA-99h6-9pr2-5g94.json | 31 +++++++++++++ .../GHSA-9fxm-qh6m-23f8.json | 15 +++++-- .../GHSA-9j33-5mgw-847x.json | 31 +++++++++++++ .../GHSA-9j66-pm9j-3fvj.json | 31 +++++++++++++ .../GHSA-9m7f-2xgc-3w9v.json | 31 +++++++++++++ .../GHSA-9q24-c9h6-h244.json | 31 +++++++++++++ .../GHSA-9vgr-6gpq-2rj5.json | 15 +++++-- .../GHSA-ch9r-7w7v-gg4p.json | 31 +++++++++++++ .../GHSA-chpw-4vjg-cp92.json | 36 +++++++++++++++ .../GHSA-f4vg-m386-rcvq.json | 15 +++++-- .../GHSA-f56q-8frx-6rwq.json | 31 +++++++++++++ .../GHSA-f6f8-8wvp-pj55.json | 11 +++-- .../GHSA-f6r6-892j-cp9p.json | 31 +++++++++++++ .../GHSA-f8q3-gfv7-h449.json | 36 +++++++++++++++ .../GHSA-fjgg-qw2x-496w.json | 31 +++++++++++++ .../GHSA-fr2h-74vh-mp7c.json | 29 ++++++++++++ .../GHSA-g5hj-6p24-45c3.json | 33 ++++++++++++++ .../GHSA-g5x8-v2ch-gj2g.json | 37 ++++++++++++++++ .../GHSA-g6xh-8j45-qj24.json | 31 +++++++++++++ .../GHSA-g94w-vc32-h449.json | 31 +++++++++++++ .../GHSA-g9m6-gvqr-98xq.json | 33 ++++++++++++++ .../GHSA-g9ph-4g63-c54q.json | 31 +++++++++++++ .../GHSA-gpgg-3g65-72cm.json | 31 +++++++++++++ .../GHSA-gqf5-wjqv-v83c.json | 31 +++++++++++++ .../GHSA-h6w8-m65g-549g.json | 31 +++++++++++++ .../GHSA-h874-6j2r-6vjv.json | 33 ++++++++++++++ .../GHSA-h8j9-776h-g7wr.json | 31 +++++++++++++ .../GHSA-hff4-c3wj-g3xx.json | 31 +++++++++++++ .../GHSA-hqjc-qgf5-4m63.json | 31 +++++++++++++ .../GHSA-hwc6-hhj2-hp24.json | 31 +++++++++++++ .../GHSA-j3fj-gjrj-c97q.json | 15 +++++-- .../GHSA-j6c4-8pwx-h3g3.json | 31 +++++++++++++ .../GHSA-j7cg-x2c3-v6hf.json | 31 +++++++++++++ .../GHSA-jf66-v4fg-qpqx.json | 31 +++++++++++++ .../GHSA-jffw-3h47-42r7.json | 33 ++++++++++++++ .../GHSA-jjvf-4cxj-rqv4.json | 31 +++++++++++++ .../GHSA-jrrh-q8c6-fqg3.json | 31 +++++++++++++ .../GHSA-jv4w-6wrf-3p5g.json | 36 +++++++++++++++ .../GHSA-m39j-xxh8-gc7w.json | 29 ++++++++++++ .../GHSA-m53w-jm38-mh7q.json | 31 +++++++++++++ .../GHSA-m6c8-mv97-5jcm.json | 11 +++-- .../GHSA-m8j3-m4jx-2rhw.json | 31 +++++++++++++ .../GHSA-m8wx-qw6g-2vhr.json | 31 +++++++++++++ .../GHSA-mxgx-9cvp-m653.json | 31 +++++++++++++ .../GHSA-p27g-6xm5-rqrf.json | 31 +++++++++++++ .../GHSA-p3gg-w5rj-m5rv.json | 31 +++++++++++++ .../GHSA-p3jr-34v8-m9x2.json | 31 +++++++++++++ .../GHSA-p4cr-4mjx-v45f.json | 29 ++++++++++++ .../GHSA-p77c-g2ff-r9hf.json | 31 +++++++++++++ .../GHSA-p9jg-5w2m-vgg8.json | 31 +++++++++++++ .../GHSA-phf7-cpqm-749x.json | 15 +++++-- .../GHSA-qf55-97mm-vqcj.json | 33 ++++++++++++++ .../GHSA-qffj-hqp2-qrxm.json | 31 +++++++++++++ .../GHSA-r66p-qgmm-6967.json | 31 +++++++++++++ .../GHSA-rc33-rp5v-32v2.json | 29 ++++++++++++ .../GHSA-rj9h-wxr6-mwg8.json | 31 +++++++++++++ .../GHSA-v6xw-pf6j-mpfg.json | 15 +++++-- .../GHSA-vm82-j6hv-2pfj.json | 36 +++++++++++++++ .../GHSA-vprm-27pv-jp3w.json | 37 ++++++++++++++++ .../GHSA-vw53-vc7r-68m2.json | 31 +++++++++++++ .../GHSA-vxch-vvvr-4v8f.json | 36 +++++++++++++++ .../GHSA-w3q9-jjpq-m527.json | 31 +++++++++++++ .../GHSA-w65p-8m9j-6pm4.json | 31 +++++++++++++ .../GHSA-w993-3vv8-hxp8.json | 15 +++++-- .../GHSA-wjhm-v52r-7x9g.json | 31 +++++++++++++ .../GHSA-wrj5-h97x-2xcg.json | 40 +++++++++++++++++ .../GHSA-x5v3-33m6-c266.json | 31 +++++++++++++ .../GHSA-x7m9-mv49-fv73.json | 37 ++++++++++++++++ .../GHSA-x99c-gp84-c52f.json | 11 +++-- .../GHSA-xff5-h82c-43q2.json | 31 +++++++++++++ .../GHSA-xh2f-mpwc-mhh4.json | 31 +++++++++++++ .../GHSA-xhf8-2ffc-9gh2.json | 31 +++++++++++++ .../GHSA-xw4g-gmmj-5g3m.json | 31 +++++++++++++ 139 files changed, 3158 insertions(+), 109 deletions(-) create mode 100644 advisories/unreviewed/2025/01/GHSA-223j-7cj4-4cw7/GHSA-223j-7cj4-4cw7.json create mode 100644 advisories/unreviewed/2025/01/GHSA-2479-2frf-9263/GHSA-2479-2frf-9263.json create mode 100644 advisories/unreviewed/2025/01/GHSA-2gj6-558v-rq2w/GHSA-2gj6-558v-rq2w.json create mode 100644 advisories/unreviewed/2025/01/GHSA-2q57-gr73-v7pg/GHSA-2q57-gr73-v7pg.json create mode 100644 advisories/unreviewed/2025/01/GHSA-2rx4-vrv5-3mjp/GHSA-2rx4-vrv5-3mjp.json create mode 100644 advisories/unreviewed/2025/01/GHSA-2wf3-32wx-c338/GHSA-2wf3-32wx-c338.json create mode 100644 advisories/unreviewed/2025/01/GHSA-37wj-v394-2xvc/GHSA-37wj-v394-2xvc.json create mode 100644 advisories/unreviewed/2025/01/GHSA-57r5-pmvw-w26w/GHSA-57r5-pmvw-w26w.json create mode 100644 advisories/unreviewed/2025/01/GHSA-5c5x-jw5q-2wpw/GHSA-5c5x-jw5q-2wpw.json create mode 100644 advisories/unreviewed/2025/01/GHSA-5rcq-gp73-g9jv/GHSA-5rcq-gp73-g9jv.json create mode 100644 advisories/unreviewed/2025/01/GHSA-623r-49cc-q6vj/GHSA-623r-49cc-q6vj.json create mode 100644 advisories/unreviewed/2025/01/GHSA-6372-2hcg-2fr4/GHSA-6372-2hcg-2fr4.json create mode 100644 advisories/unreviewed/2025/01/GHSA-63wg-87qv-rw4r/GHSA-63wg-87qv-rw4r.json create mode 100644 advisories/unreviewed/2025/01/GHSA-68jp-4r95-v8vr/GHSA-68jp-4r95-v8vr.json create mode 100644 advisories/unreviewed/2025/01/GHSA-6g5p-29h6-5w4p/GHSA-6g5p-29h6-5w4p.json create mode 100644 advisories/unreviewed/2025/01/GHSA-6h86-6h56-2j4j/GHSA-6h86-6h56-2j4j.json create mode 100644 advisories/unreviewed/2025/01/GHSA-6hq6-3pp3-9598/GHSA-6hq6-3pp3-9598.json create mode 100644 advisories/unreviewed/2025/01/GHSA-6j67-4cmx-rgw8/GHSA-6j67-4cmx-rgw8.json create mode 100644 advisories/unreviewed/2025/01/GHSA-6q5c-9hq7-3fc3/GHSA-6q5c-9hq7-3fc3.json create mode 100644 advisories/unreviewed/2025/01/GHSA-7649-pgpq-cpch/GHSA-7649-pgpq-cpch.json create mode 100644 advisories/unreviewed/2025/01/GHSA-8244-g8gx-36rj/GHSA-8244-g8gx-36rj.json create mode 100644 advisories/unreviewed/2025/01/GHSA-863q-738r-33x7/GHSA-863q-738r-33x7.json create mode 100644 advisories/unreviewed/2025/01/GHSA-88c8-vf36-8mvr/GHSA-88c8-vf36-8mvr.json create mode 100644 advisories/unreviewed/2025/01/GHSA-8hmg-gpg9-2qqw/GHSA-8hmg-gpg9-2qqw.json create mode 100644 advisories/unreviewed/2025/01/GHSA-932w-6jv2-mm8q/GHSA-932w-6jv2-mm8q.json create mode 100644 advisories/unreviewed/2025/01/GHSA-9838-cxcw-r6rf/GHSA-9838-cxcw-r6rf.json create mode 100644 advisories/unreviewed/2025/01/GHSA-99h6-9pr2-5g94/GHSA-99h6-9pr2-5g94.json create mode 100644 advisories/unreviewed/2025/01/GHSA-9j33-5mgw-847x/GHSA-9j33-5mgw-847x.json create mode 100644 advisories/unreviewed/2025/01/GHSA-9j66-pm9j-3fvj/GHSA-9j66-pm9j-3fvj.json create mode 100644 advisories/unreviewed/2025/01/GHSA-9m7f-2xgc-3w9v/GHSA-9m7f-2xgc-3w9v.json create mode 100644 advisories/unreviewed/2025/01/GHSA-9q24-c9h6-h244/GHSA-9q24-c9h6-h244.json create mode 100644 advisories/unreviewed/2025/01/GHSA-ch9r-7w7v-gg4p/GHSA-ch9r-7w7v-gg4p.json create mode 100644 advisories/unreviewed/2025/01/GHSA-chpw-4vjg-cp92/GHSA-chpw-4vjg-cp92.json create mode 100644 advisories/unreviewed/2025/01/GHSA-f56q-8frx-6rwq/GHSA-f56q-8frx-6rwq.json create mode 100644 advisories/unreviewed/2025/01/GHSA-f6r6-892j-cp9p/GHSA-f6r6-892j-cp9p.json create mode 100644 advisories/unreviewed/2025/01/GHSA-f8q3-gfv7-h449/GHSA-f8q3-gfv7-h449.json create mode 100644 advisories/unreviewed/2025/01/GHSA-fjgg-qw2x-496w/GHSA-fjgg-qw2x-496w.json create mode 100644 advisories/unreviewed/2025/01/GHSA-fr2h-74vh-mp7c/GHSA-fr2h-74vh-mp7c.json create mode 100644 advisories/unreviewed/2025/01/GHSA-g5hj-6p24-45c3/GHSA-g5hj-6p24-45c3.json create mode 100644 advisories/unreviewed/2025/01/GHSA-g5x8-v2ch-gj2g/GHSA-g5x8-v2ch-gj2g.json create mode 100644 advisories/unreviewed/2025/01/GHSA-g6xh-8j45-qj24/GHSA-g6xh-8j45-qj24.json create mode 100644 advisories/unreviewed/2025/01/GHSA-g94w-vc32-h449/GHSA-g94w-vc32-h449.json create mode 100644 advisories/unreviewed/2025/01/GHSA-g9m6-gvqr-98xq/GHSA-g9m6-gvqr-98xq.json create mode 100644 advisories/unreviewed/2025/01/GHSA-g9ph-4g63-c54q/GHSA-g9ph-4g63-c54q.json create mode 100644 advisories/unreviewed/2025/01/GHSA-gpgg-3g65-72cm/GHSA-gpgg-3g65-72cm.json create mode 100644 advisories/unreviewed/2025/01/GHSA-gqf5-wjqv-v83c/GHSA-gqf5-wjqv-v83c.json create mode 100644 advisories/unreviewed/2025/01/GHSA-h6w8-m65g-549g/GHSA-h6w8-m65g-549g.json create mode 100644 advisories/unreviewed/2025/01/GHSA-h874-6j2r-6vjv/GHSA-h874-6j2r-6vjv.json create mode 100644 advisories/unreviewed/2025/01/GHSA-h8j9-776h-g7wr/GHSA-h8j9-776h-g7wr.json create mode 100644 advisories/unreviewed/2025/01/GHSA-hff4-c3wj-g3xx/GHSA-hff4-c3wj-g3xx.json create mode 100644 advisories/unreviewed/2025/01/GHSA-hqjc-qgf5-4m63/GHSA-hqjc-qgf5-4m63.json create mode 100644 advisories/unreviewed/2025/01/GHSA-hwc6-hhj2-hp24/GHSA-hwc6-hhj2-hp24.json create mode 100644 advisories/unreviewed/2025/01/GHSA-j6c4-8pwx-h3g3/GHSA-j6c4-8pwx-h3g3.json create mode 100644 advisories/unreviewed/2025/01/GHSA-j7cg-x2c3-v6hf/GHSA-j7cg-x2c3-v6hf.json create mode 100644 advisories/unreviewed/2025/01/GHSA-jf66-v4fg-qpqx/GHSA-jf66-v4fg-qpqx.json create mode 100644 advisories/unreviewed/2025/01/GHSA-jffw-3h47-42r7/GHSA-jffw-3h47-42r7.json create mode 100644 advisories/unreviewed/2025/01/GHSA-jjvf-4cxj-rqv4/GHSA-jjvf-4cxj-rqv4.json create mode 100644 advisories/unreviewed/2025/01/GHSA-jrrh-q8c6-fqg3/GHSA-jrrh-q8c6-fqg3.json create mode 100644 advisories/unreviewed/2025/01/GHSA-jv4w-6wrf-3p5g/GHSA-jv4w-6wrf-3p5g.json create mode 100644 advisories/unreviewed/2025/01/GHSA-m39j-xxh8-gc7w/GHSA-m39j-xxh8-gc7w.json create mode 100644 advisories/unreviewed/2025/01/GHSA-m53w-jm38-mh7q/GHSA-m53w-jm38-mh7q.json create mode 100644 advisories/unreviewed/2025/01/GHSA-m8j3-m4jx-2rhw/GHSA-m8j3-m4jx-2rhw.json create mode 100644 advisories/unreviewed/2025/01/GHSA-m8wx-qw6g-2vhr/GHSA-m8wx-qw6g-2vhr.json create mode 100644 advisories/unreviewed/2025/01/GHSA-mxgx-9cvp-m653/GHSA-mxgx-9cvp-m653.json create mode 100644 advisories/unreviewed/2025/01/GHSA-p27g-6xm5-rqrf/GHSA-p27g-6xm5-rqrf.json create mode 100644 advisories/unreviewed/2025/01/GHSA-p3gg-w5rj-m5rv/GHSA-p3gg-w5rj-m5rv.json create mode 100644 advisories/unreviewed/2025/01/GHSA-p3jr-34v8-m9x2/GHSA-p3jr-34v8-m9x2.json create mode 100644 advisories/unreviewed/2025/01/GHSA-p4cr-4mjx-v45f/GHSA-p4cr-4mjx-v45f.json create mode 100644 advisories/unreviewed/2025/01/GHSA-p77c-g2ff-r9hf/GHSA-p77c-g2ff-r9hf.json create mode 100644 advisories/unreviewed/2025/01/GHSA-p9jg-5w2m-vgg8/GHSA-p9jg-5w2m-vgg8.json create mode 100644 advisories/unreviewed/2025/01/GHSA-qf55-97mm-vqcj/GHSA-qf55-97mm-vqcj.json create mode 100644 advisories/unreviewed/2025/01/GHSA-qffj-hqp2-qrxm/GHSA-qffj-hqp2-qrxm.json create mode 100644 advisories/unreviewed/2025/01/GHSA-r66p-qgmm-6967/GHSA-r66p-qgmm-6967.json create mode 100644 advisories/unreviewed/2025/01/GHSA-rc33-rp5v-32v2/GHSA-rc33-rp5v-32v2.json create mode 100644 advisories/unreviewed/2025/01/GHSA-rj9h-wxr6-mwg8/GHSA-rj9h-wxr6-mwg8.json create mode 100644 advisories/unreviewed/2025/01/GHSA-vm82-j6hv-2pfj/GHSA-vm82-j6hv-2pfj.json create mode 100644 advisories/unreviewed/2025/01/GHSA-vprm-27pv-jp3w/GHSA-vprm-27pv-jp3w.json create mode 100644 advisories/unreviewed/2025/01/GHSA-vw53-vc7r-68m2/GHSA-vw53-vc7r-68m2.json create mode 100644 advisories/unreviewed/2025/01/GHSA-vxch-vvvr-4v8f/GHSA-vxch-vvvr-4v8f.json create mode 100644 advisories/unreviewed/2025/01/GHSA-w3q9-jjpq-m527/GHSA-w3q9-jjpq-m527.json create mode 100644 advisories/unreviewed/2025/01/GHSA-w65p-8m9j-6pm4/GHSA-w65p-8m9j-6pm4.json create mode 100644 advisories/unreviewed/2025/01/GHSA-wjhm-v52r-7x9g/GHSA-wjhm-v52r-7x9g.json create mode 100644 advisories/unreviewed/2025/01/GHSA-wrj5-h97x-2xcg/GHSA-wrj5-h97x-2xcg.json create mode 100644 advisories/unreviewed/2025/01/GHSA-x5v3-33m6-c266/GHSA-x5v3-33m6-c266.json create mode 100644 advisories/unreviewed/2025/01/GHSA-x7m9-mv49-fv73/GHSA-x7m9-mv49-fv73.json create mode 100644 advisories/unreviewed/2025/01/GHSA-xff5-h82c-43q2/GHSA-xff5-h82c-43q2.json create mode 100644 advisories/unreviewed/2025/01/GHSA-xh2f-mpwc-mhh4/GHSA-xh2f-mpwc-mhh4.json create mode 100644 advisories/unreviewed/2025/01/GHSA-xhf8-2ffc-9gh2/GHSA-xhf8-2ffc-9gh2.json create mode 100644 advisories/unreviewed/2025/01/GHSA-xw4g-gmmj-5g3m/GHSA-xw4g-gmmj-5g3m.json diff --git a/advisories/unreviewed/2023/03/GHSA-c5pj-m2vw-68wh/GHSA-c5pj-m2vw-68wh.json b/advisories/unreviewed/2023/03/GHSA-c5pj-m2vw-68wh/GHSA-c5pj-m2vw-68wh.json index a7e4d351cda..a3e5f6e1a0b 100644 --- a/advisories/unreviewed/2023/03/GHSA-c5pj-m2vw-68wh/GHSA-c5pj-m2vw-68wh.json +++ b/advisories/unreviewed/2023/03/GHSA-c5pj-m2vw-68wh/GHSA-c5pj-m2vw-68wh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c5pj-m2vw-68wh", - "modified": "2023-04-03T18:32:09Z", + "modified": "2025-01-09T21:31:24Z", "published": "2023-03-26T21:30:22Z", "aliases": [ "CVE-2023-26801" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://github.com/winmt/my-vuls/tree/main/LB-LINK%20BL-AC1900%2C%20BL-WR9000%2C%20BL-X26%20and%20BL-LTE300%20Wireless%20Routers" + }, + { + "type": "WEB", + "url": "https://www.akamai.com/blog/security-research/cve-2023-26801-exploited-spreading-mirai-botnet" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/06/GHSA-3cr6-x963-cvm9/GHSA-3cr6-x963-cvm9.json b/advisories/unreviewed/2023/06/GHSA-3cr6-x963-cvm9/GHSA-3cr6-x963-cvm9.json index 5adfe75ad3f..95a19963ce9 100644 --- a/advisories/unreviewed/2023/06/GHSA-3cr6-x963-cvm9/GHSA-3cr6-x963-cvm9.json +++ b/advisories/unreviewed/2023/06/GHSA-3cr6-x963-cvm9/GHSA-3cr6-x963-cvm9.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-77mp-cm2p-44gj/GHSA-77mp-cm2p-44gj.json b/advisories/unreviewed/2023/06/GHSA-77mp-cm2p-44gj/GHSA-77mp-cm2p-44gj.json index 3e163bc4933..2431a9592b2 100644 --- a/advisories/unreviewed/2023/06/GHSA-77mp-cm2p-44gj/GHSA-77mp-cm2p-44gj.json +++ b/advisories/unreviewed/2023/06/GHSA-77mp-cm2p-44gj/GHSA-77mp-cm2p-44gj.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-203" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-8fgq-jggm-33jc/GHSA-8fgq-jggm-33jc.json b/advisories/unreviewed/2023/06/GHSA-8fgq-jggm-33jc/GHSA-8fgq-jggm-33jc.json index 53d04d0d81a..2c0219949d9 100644 --- a/advisories/unreviewed/2023/06/GHSA-8fgq-jggm-33jc/GHSA-8fgq-jggm-33jc.json +++ b/advisories/unreviewed/2023/06/GHSA-8fgq-jggm-33jc/GHSA-8fgq-jggm-33jc.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-704" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-f5q8-q9fw-rc2j/GHSA-f5q8-q9fw-rc2j.json b/advisories/unreviewed/2023/06/GHSA-f5q8-q9fw-rc2j/GHSA-f5q8-q9fw-rc2j.json index ad9f9b91540..f94052348f2 100644 --- a/advisories/unreviewed/2023/06/GHSA-f5q8-q9fw-rc2j/GHSA-f5q8-q9fw-rc2j.json +++ b/advisories/unreviewed/2023/06/GHSA-f5q8-q9fw-rc2j/GHSA-f5q8-q9fw-rc2j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f5q8-q9fw-rc2j", - "modified": "2024-04-04T04:30:12Z", + "modified": "2025-01-09T21:31:26Z", "published": "2023-06-02T18:30:18Z", "aliases": [ "CVE-2023-25745" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://bugzilla.mozilla.org/buglist.cgi?bug_id=1688592%2C1797186%2C1804998%2C1806521%2C1813284" }, + { + "type": "WEB", + "url": "https://bugzilla.mozilla.org/show_bug.cgi?id=1804998" + }, { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2023-05" diff --git a/advisories/unreviewed/2023/06/GHSA-fvmr-cw8g-v3m9/GHSA-fvmr-cw8g-v3m9.json b/advisories/unreviewed/2023/06/GHSA-fvmr-cw8g-v3m9/GHSA-fvmr-cw8g-v3m9.json index 4688240111e..d0318f777b9 100644 --- a/advisories/unreviewed/2023/06/GHSA-fvmr-cw8g-v3m9/GHSA-fvmr-cw8g-v3m9.json +++ b/advisories/unreviewed/2023/06/GHSA-fvmr-cw8g-v3m9/GHSA-fvmr-cw8g-v3m9.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-346" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-g67q-47ww-68wp/GHSA-g67q-47ww-68wp.json b/advisories/unreviewed/2023/06/GHSA-g67q-47ww-68wp/GHSA-g67q-47ww-68wp.json index 2b497d9399f..fbe806d79bc 100644 --- a/advisories/unreviewed/2023/06/GHSA-g67q-47ww-68wp/GHSA-g67q-47ww-68wp.json +++ b/advisories/unreviewed/2023/06/GHSA-g67q-47ww-68wp/GHSA-g67q-47ww-68wp.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-522" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-h7h9-wg3c-h4wv/GHSA-h7h9-wg3c-h4wv.json b/advisories/unreviewed/2023/06/GHSA-h7h9-wg3c-h4wv/GHSA-h7h9-wg3c-h4wv.json index 7491c2f6ff8..72747d87f14 100644 --- a/advisories/unreviewed/2023/06/GHSA-h7h9-wg3c-h4wv/GHSA-h7h9-wg3c-h4wv.json +++ b/advisories/unreviewed/2023/06/GHSA-h7h9-wg3c-h4wv/GHSA-h7h9-wg3c-h4wv.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-94" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-m8wf-fqcm-6693/GHSA-m8wf-fqcm-6693.json b/advisories/unreviewed/2023/06/GHSA-m8wf-fqcm-6693/GHSA-m8wf-fqcm-6693.json index c6e1d24d9d8..99938551db1 100644 --- a/advisories/unreviewed/2023/06/GHSA-m8wf-fqcm-6693/GHSA-m8wf-fqcm-6693.json +++ b/advisories/unreviewed/2023/06/GHSA-m8wf-fqcm-6693/GHSA-m8wf-fqcm-6693.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-668" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2023/06/GHSA-mc5v-8859-pvcf/GHSA-mc5v-8859-pvcf.json b/advisories/unreviewed/2023/06/GHSA-mc5v-8859-pvcf/GHSA-mc5v-8859-pvcf.json index d8510b7ba08..a5b70367c7b 100644 --- a/advisories/unreviewed/2023/06/GHSA-mc5v-8859-pvcf/GHSA-mc5v-8859-pvcf.json +++ b/advisories/unreviewed/2023/06/GHSA-mc5v-8859-pvcf/GHSA-mc5v-8859-pvcf.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-1021" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-mvj7-x43c-gpcj/GHSA-mvj7-x43c-gpcj.json b/advisories/unreviewed/2023/06/GHSA-mvj7-x43c-gpcj/GHSA-mvj7-x43c-gpcj.json index cc5cfb86014..f7ab4ce0e40 100644 --- a/advisories/unreviewed/2023/06/GHSA-mvj7-x43c-gpcj/GHSA-mvj7-x43c-gpcj.json +++ b/advisories/unreviewed/2023/06/GHSA-mvj7-x43c-gpcj/GHSA-mvj7-x43c-gpcj.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/06/GHSA-wpvr-v2cc-f6qx/GHSA-wpvr-v2cc-f6qx.json b/advisories/unreviewed/2023/06/GHSA-wpvr-v2cc-f6qx/GHSA-wpvr-v2cc-f6qx.json index 8d211a1274b..efd25f0003d 100644 --- a/advisories/unreviewed/2023/06/GHSA-wpvr-v2cc-f6qx/GHSA-wpvr-v2cc-f6qx.json +++ b/advisories/unreviewed/2023/06/GHSA-wpvr-v2cc-f6qx/GHSA-wpvr-v2cc-f6qx.json @@ -49,7 +49,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-601" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/09/GHSA-2jvx-42cx-5ggp/GHSA-2jvx-42cx-5ggp.json b/advisories/unreviewed/2023/09/GHSA-2jvx-42cx-5ggp/GHSA-2jvx-42cx-5ggp.json index f5ed0a09405..9582a894683 100644 --- a/advisories/unreviewed/2023/09/GHSA-2jvx-42cx-5ggp/GHSA-2jvx-42cx-5ggp.json +++ b/advisories/unreviewed/2023/09/GHSA-2jvx-42cx-5ggp/GHSA-2jvx-42cx-5ggp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2jvx-42cx-5ggp", - "modified": "2024-04-04T07:29:01Z", + "modified": "2025-01-09T21:31:26Z", "published": "2023-09-05T18:30:22Z", "aliases": [ "CVE-2023-36361" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://gist.github.com/Cameleon037/40b3b6f6729d1d0984d6ce5b6837c46b" }, + { + "type": "WEB", + "url": "https://github.com/Henkel-CyberVM/CVEs/tree/main/CVE-2023-36361" + }, { "type": "WEB", "url": "http://audimex.com" diff --git a/advisories/unreviewed/2023/10/GHSA-7jrw-mp94-7v28/GHSA-7jrw-mp94-7v28.json b/advisories/unreviewed/2023/10/GHSA-7jrw-mp94-7v28/GHSA-7jrw-mp94-7v28.json index 8e39c88bcb6..9ace81a4ee7 100644 --- a/advisories/unreviewed/2023/10/GHSA-7jrw-mp94-7v28/GHSA-7jrw-mp94-7v28.json +++ b/advisories/unreviewed/2023/10/GHSA-7jrw-mp94-7v28/GHSA-7jrw-mp94-7v28.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7jrw-mp94-7v28", - "modified": "2024-04-04T08:46:36Z", + "modified": "2025-01-09T21:31:26Z", "published": "2023-10-18T18:31:38Z", "aliases": [ "CVE-2023-45911" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45911" }, + { + "type": "WEB", + "url": "https://github.com/Henkel-CyberVM/CVEs/tree/main/CVE-2023-45911" + }, { "type": "WEB", "url": "https://github.com/PostalBlab/Vulnerabilities/blob/main/ComScale/auth_bypass.txt" diff --git a/advisories/unreviewed/2023/10/GHSA-p7jx-m4x8-cghf/GHSA-p7jx-m4x8-cghf.json b/advisories/unreviewed/2023/10/GHSA-p7jx-m4x8-cghf/GHSA-p7jx-m4x8-cghf.json index d43365b46a5..d393bad02fd 100644 --- a/advisories/unreviewed/2023/10/GHSA-p7jx-m4x8-cghf/GHSA-p7jx-m4x8-cghf.json +++ b/advisories/unreviewed/2023/10/GHSA-p7jx-m4x8-cghf/GHSA-p7jx-m4x8-cghf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p7jx-m4x8-cghf", - "modified": "2024-04-04T08:46:37Z", + "modified": "2025-01-09T21:31:26Z", "published": "2023-10-18T18:31:38Z", "aliases": [ "CVE-2023-45912" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45912" }, + { + "type": "WEB", + "url": "https://github.com/Henkel-CyberVM/CVEs/tree/main/CVE-2023-45912" + }, { "type": "WEB", "url": "https://github.com/PostalBlab/Vulnerabilities/blob/main/ComScale/file_access.txt" diff --git a/advisories/unreviewed/2024/02/GHSA-69cq-jw85-57p8/GHSA-69cq-jw85-57p8.json b/advisories/unreviewed/2024/02/GHSA-69cq-jw85-57p8/GHSA-69cq-jw85-57p8.json index e3d23227243..5f5ff8b6e83 100644 --- a/advisories/unreviewed/2024/02/GHSA-69cq-jw85-57p8/GHSA-69cq-jw85-57p8.json +++ b/advisories/unreviewed/2024/02/GHSA-69cq-jw85-57p8/GHSA-69cq-jw85-57p8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-69cq-jw85-57p8", - "modified": "2024-02-29T15:32:27Z", + "modified": "2025-01-09T21:31:26Z", "published": "2024-02-29T15:32:27Z", "aliases": [ "CVE-2023-52485" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Wake DMCUB before sending a command\n\n[Why]\nWe can hang in place trying to send commands when the DMCUB isn't\npowered on.\n\n[How]\nFor functions that execute within a DC context or DC lock we can\nwrap the direct calls to dm_execute_dmub_cmd/list with code that\nexits idle power optimizations and reallows once we're done with\nthe command submission on success.\n\nFor DM direct submissions the DM will need to manage the enter/exit\nsequencing manually.\n\nWe cannot invoke a DMCUB command directly within the DM execution\nhelper or we can deadlock.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -25,7 +30,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-29T15:15:07Z" diff --git a/advisories/unreviewed/2024/02/GHSA-8xhh-j9m8-989c/GHSA-8xhh-j9m8-989c.json b/advisories/unreviewed/2024/02/GHSA-8xhh-j9m8-989c/GHSA-8xhh-j9m8-989c.json index 067dbf886b1..5362018e91c 100644 --- a/advisories/unreviewed/2024/02/GHSA-8xhh-j9m8-989c/GHSA-8xhh-j9m8-989c.json +++ b/advisories/unreviewed/2024/02/GHSA-8xhh-j9m8-989c/GHSA-8xhh-j9m8-989c.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8xhh-j9m8-989c", - "modified": "2024-02-28T09:30:38Z", + "modified": "2025-01-09T21:31:26Z", "published": "2024-02-28T09:30:38Z", "aliases": [ "CVE-2021-47037" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: q6afe-clocks: fix reprobing of the driver\n\nQ6afe-clocks driver can get reprobed. For example if the APR services\nare restarted after the firmware crash. However currently Q6afe-clocks\ndriver will oops because hw.init will get cleared during first _probe\ncall. Rewrite the driver to fill the clock data at runtime rather than\nusing big static array of clocks.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -29,7 +34,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-28T09:15:39Z" diff --git a/advisories/unreviewed/2024/03/GHSA-5fwg-75w6-7gf9/GHSA-5fwg-75w6-7gf9.json b/advisories/unreviewed/2024/03/GHSA-5fwg-75w6-7gf9/GHSA-5fwg-75w6-7gf9.json index de9c297ce89..a4d8a2f5058 100644 --- a/advisories/unreviewed/2024/03/GHSA-5fwg-75w6-7gf9/GHSA-5fwg-75w6-7gf9.json +++ b/advisories/unreviewed/2024/03/GHSA-5fwg-75w6-7gf9/GHSA-5fwg-75w6-7gf9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5fwg-75w6-7gf9", - "modified": "2024-03-01T00:30:28Z", + "modified": "2025-01-09T21:31:26Z", "published": "2024-03-01T00:30:28Z", "aliases": [ "CVE-2021-47056" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: qat - ADF_STATUS_PF_RUNNING should be set after adf_dev_init\n\nADF_STATUS_PF_RUNNING is (only) used and checked by adf_vf2pf_shutdown()\nbefore calling adf_iov_putmsg()->mutex_lock(vf2pf_lock), however the\nvf2pf_lock is initialized in adf_dev_init(), which can fail and when it\nfail, the vf2pf_lock is either not initialized or destroyed, a subsequent\nuse of vf2pf_lock will cause issue.\nTo fix this issue, only set this flag if adf_dev_init() returns 0.\n\n[ 7.178404] BUG: KASAN: user-memory-access in __mutex_lock.isra.0+0x1ac/0x7c0\n[ 7.180345] Call Trace:\n[ 7.182576] mutex_lock+0xc9/0xd0\n[ 7.183257] adf_iov_putmsg+0x118/0x1a0 [intel_qat]\n[ 7.183541] adf_vf2pf_shutdown+0x4d/0x7b [intel_qat]\n[ 7.183834] adf_dev_shutdown+0x172/0x2b0 [intel_qat]\n[ 7.184127] adf_probe+0x5e9/0x600 [qat_dh895xccvf]", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-908" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-29T23:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-7hmq-6483-qr84/GHSA-7hmq-6483-qr84.json b/advisories/unreviewed/2024/03/GHSA-7hmq-6483-qr84/GHSA-7hmq-6483-qr84.json index 009ddd33819..1848075f8ea 100644 --- a/advisories/unreviewed/2024/03/GHSA-7hmq-6483-qr84/GHSA-7hmq-6483-qr84.json +++ b/advisories/unreviewed/2024/03/GHSA-7hmq-6483-qr84/GHSA-7hmq-6483-qr84.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7hmq-6483-qr84", - "modified": "2024-11-08T18:30:42Z", + "modified": "2025-01-09T21:31:27Z", "published": "2024-03-01T15:31:37Z", "aliases": [ "CVE-2023-52497" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nerofs: fix lz4 inplace decompression\n\nCurrently EROFS can map another compressed buffer for inplace\ndecompression, that was used to handle the cases that some pages of\ncompressed data are actually not in-place I/O.\n\nHowever, like most simple LZ77 algorithms, LZ4 expects the compressed\ndata is arranged at the end of the decompressed buffer and it\nexplicitly uses memmove() to handle overlapping:\n __________________________________________________________\n |_ direction of decompression --> ____ |_ compressed data _|\n\nAlthough EROFS arranges compressed data like this, it typically maps two\nindividual virtual buffers so the relative order is uncertain.\nPreviously, it was hardly observed since LZ4 only uses memmove() for\nshort overlapped literals and x86/arm64 memmove implementations seem to\ncompletely cover it up and they don't have this issue. Juhyung reported\nthat EROFS data corruption can be found on a new Intel x86 processor.\nAfter some analysis, it seems that recent x86 processors with the new\nFSRM feature expose this issue with \"rep movsb\".\n\nLet's strictly use the decompressed buffer for lz4 inplace\ndecompression for now. Later, as an useful improvement, we could try\nto tie up these two buffers together in the correct order.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-01T14:15:53Z" diff --git a/advisories/unreviewed/2024/03/GHSA-8gv8-jqm3-r824/GHSA-8gv8-jqm3-r824.json b/advisories/unreviewed/2024/03/GHSA-8gv8-jqm3-r824/GHSA-8gv8-jqm3-r824.json index fb400cd800e..ce50994782d 100644 --- a/advisories/unreviewed/2024/03/GHSA-8gv8-jqm3-r824/GHSA-8gv8-jqm3-r824.json +++ b/advisories/unreviewed/2024/03/GHSA-8gv8-jqm3-r824/GHSA-8gv8-jqm3-r824.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8gv8-jqm3-r824", - "modified": "2024-03-01T00:30:27Z", + "modified": "2025-01-09T21:31:26Z", "published": "2024-03-01T00:30:27Z", "aliases": [ "CVE-2021-47016" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nm68k: mvme147,mvme16x: Don't wipe PCC timer config bits\n\nDon't clear the timer 1 configuration bits when clearing the interrupt flag\nand counter overflow. As Michael reported, \"This results in no timer\ninterrupts being delivered after the first. Initialization then hangs\nin calibrate_delay as the jiffies counter is not updated.\"\n\nOn mvme16x, enable the timer after requesting the irq, consistent with\nmvme147.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -37,7 +42,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-29T23:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-f2cq-j285-crf8/GHSA-f2cq-j285-crf8.json b/advisories/unreviewed/2024/03/GHSA-f2cq-j285-crf8/GHSA-f2cq-j285-crf8.json index d028f772eaf..4de450a0a85 100644 --- a/advisories/unreviewed/2024/03/GHSA-f2cq-j285-crf8/GHSA-f2cq-j285-crf8.json +++ b/advisories/unreviewed/2024/03/GHSA-f2cq-j285-crf8/GHSA-f2cq-j285-crf8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f2cq-j285-crf8", - "modified": "2024-03-01T00:30:28Z", + "modified": "2025-01-09T21:31:26Z", "published": "2024-03-01T00:30:28Z", "aliases": [ "CVE-2021-47066" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nasync_xor: increase src_offs when dropping destination page\n\nNow we support sharing one page if PAGE_SIZE is not equal stripe size. To\nsupport this, it needs to support calculating xor value with different\noffsets for each r5dev. One offset array is used to record those offsets.\n\nIn RMW mode, parity page is used as a source page. It sets\nASYNC_TX_XOR_DROP_DST before calculating xor value in ops_run_prexor5.\nSo it needs to add src_list and src_offs at the same time. Now it only\nneeds src_list. So the xor value which is calculated is wrong. It can\ncause data corruption problem.\n\nI can reproduce this problem 100% on a POWER8 machine. The steps are:\n\n mdadm -CR /dev/md0 -l5 -n3 /dev/sdb1 /dev/sdc1 /dev/sdd1 --size=3G\n mkfs.xfs /dev/md0\n mount /dev/md0 /mnt/test\n mount: /mnt/test: mount(2) system call failed: Structure needs cleaning.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -33,7 +38,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-29T23:15:08Z" diff --git a/advisories/unreviewed/2024/03/GHSA-qcc7-grh2-48hx/GHSA-qcc7-grh2-48hx.json b/advisories/unreviewed/2024/03/GHSA-qcc7-grh2-48hx/GHSA-qcc7-grh2-48hx.json index 43c66df8a3c..a356a53d4ab 100644 --- a/advisories/unreviewed/2024/03/GHSA-qcc7-grh2-48hx/GHSA-qcc7-grh2-48hx.json +++ b/advisories/unreviewed/2024/03/GHSA-qcc7-grh2-48hx/GHSA-qcc7-grh2-48hx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qcc7-grh2-48hx", - "modified": "2024-03-02T00:31:30Z", + "modified": "2025-01-09T21:31:27Z", "published": "2024-03-02T00:31:30Z", "aliases": [ "CVE-2021-47072" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: fix removed dentries still existing after log is synced\n\nWhen we move one inode from one directory to another and both the inode\nand its previous parent directory were logged before, we are not supposed\nto have the dentry for the old parent if we have a power failure after the\nlog is synced. Only the new dentry is supposed to exist.\n\nGenerally this works correctly, however there is a scenario where this is\nnot currently working, because the old parent of the file/directory that\nwas moved is not authoritative for a range that includes the dir index and\ndir item keys of the old dentry. This case is better explained with the\nfollowing example and reproducer:\n\n # The test requires a very specific layout of keys and items in the\n # fs/subvolume btree to trigger the bug. So we want to make sure that\n # on whatever platform we are, we have the same leaf/node size.\n #\n # Currently in btrfs the node/leaf size can not be smaller than the page\n # size (but it can be greater than the page size). So use the largest\n # supported node/leaf size (64K).\n\n $ mkfs.btrfs -f -n 65536 /dev/sdc\n $ mount /dev/sdc /mnt\n\n # \"testdir\" is inode 257.\n $ mkdir /mnt/testdir\n $ chmod 755 /mnt/testdir\n\n # Create several empty files to have the directory \"testdir\" with its\n # items spread over several leaves (7 in this case).\n $ for ((i = 1; i <= 1200; i++)); do\n echo -n > /mnt/testdir/file$i\n done\n\n # Create our test directory \"dira\", inode number 1458, which gets all\n # its items in leaf 7.\n #\n # The BTRFS_DIR_ITEM_KEY item for inode 257 (\"testdir\") that points to\n # the entry named \"dira\" is in leaf 2, while the BTRFS_DIR_INDEX_KEY\n # item that points to that entry is in leaf 3.\n #\n # For this particular filesystem node size (64K), file count and file\n # names, we endup with the directory entry items from inode 257 in\n # leaves 2 and 3, as previously mentioned - what matters for triggering\n # the bug exercised by this test case is that those items are not placed\n # in leaf 1, they must be placed in a leaf different from the one\n # containing the inode item for inode 257.\n #\n # The corresponding BTRFS_DIR_ITEM_KEY and BTRFS_DIR_INDEX_KEY items for\n # the parent inode (257) are the following:\n #\n # item 460 key (257 DIR_ITEM 3724298081) itemoff 48344 itemsize 34\n # location key (1458 INODE_ITEM 0) type DIR\n # transid 6 data_len 0 name_len 4\n # name: dira\n #\n # and:\n #\n # item 771 key (257 DIR_INDEX 1202) itemoff 36673 itemsize 34\n # location key (1458 INODE_ITEM 0) type DIR\n # transid 6 data_len 0 name_len 4\n # name: dira\n\n $ mkdir /mnt/testdir/dira\n\n # Make sure everything done so far is durably persisted.\n $ sync\n\n # Now do a change to inode 257 (\"testdir\") that does not result in\n # COWing leaves 2 and 3 - the leaves that contain the directory items\n # pointing to inode 1458 (directory \"dira\").\n #\n # Changing permissions, the owner/group, updating or adding a xattr,\n # etc, will not change (COW) leaves 2 and 3. So for the sake of\n # simplicity change the permissions of inode 257, which results in\n # updating its inode item and therefore change (COW) only leaf 1.\n\n $ chmod 700 /mnt/testdir\n\n # Now fsync directory inode 257.\n #\n # Since only the first leaf was changed/COWed, we log the inode item of\n # inode 257 and only the dentries found in the first leaf, all have a\n # key type of BTRFS_DIR_ITEM_KEY, and no keys of type\n # BTRFS_DIR_INDEX_KEY, because they sort after the former type and none\n # exist in the first leaf.\n #\n # We also log 3 items that represent ranges for dir items and dir\n # indexes for which the log is authoritative:\n #\n # 1) a key of type BTRFS_DIR_LOG_ITEM_KEY, which indicates the log is\n # authoritative for all BTRFS_DIR_ITEM_KEY keys that have an offset\n # in the range [0, 2285968570] (the offset here is th\n---truncated---", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -25,7 +30,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-01T22:15:47Z" diff --git a/advisories/unreviewed/2024/06/GHSA-gxrf-wgpm-vj98/GHSA-gxrf-wgpm-vj98.json b/advisories/unreviewed/2024/06/GHSA-gxrf-wgpm-vj98/GHSA-gxrf-wgpm-vj98.json index c18840d40fc..7d6cbe1318c 100644 --- a/advisories/unreviewed/2024/06/GHSA-gxrf-wgpm-vj98/GHSA-gxrf-wgpm-vj98.json +++ b/advisories/unreviewed/2024/06/GHSA-gxrf-wgpm-vj98/GHSA-gxrf-wgpm-vj98.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-126" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/11/GHSA-3chv-hrqx-p726/GHSA-3chv-hrqx-p726.json b/advisories/unreviewed/2024/11/GHSA-3chv-hrqx-p726/GHSA-3chv-hrqx-p726.json index 9559885d268..c0711c08a83 100644 --- a/advisories/unreviewed/2024/11/GHSA-3chv-hrqx-p726/GHSA-3chv-hrqx-p726.json +++ b/advisories/unreviewed/2024/11/GHSA-3chv-hrqx-p726/GHSA-3chv-hrqx-p726.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-119", "CWE-823" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2024/11/GHSA-49gp-6j88-r9j7/GHSA-49gp-6j88-r9j7.json b/advisories/unreviewed/2024/11/GHSA-49gp-6j88-r9j7/GHSA-49gp-6j88-r9j7.json index a845f6aa739..dae44694181 100644 --- a/advisories/unreviewed/2024/11/GHSA-49gp-6j88-r9j7/GHSA-49gp-6j88-r9j7.json +++ b/advisories/unreviewed/2024/11/GHSA-49gp-6j88-r9j7/GHSA-49gp-6j88-r9j7.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-908" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-76ph-jc9g-v47h/GHSA-76ph-jc9g-v47h.json b/advisories/unreviewed/2024/11/GHSA-76ph-jc9g-v47h/GHSA-76ph-jc9g-v47h.json index f21a383dc8d..c20611f4453 100644 --- a/advisories/unreviewed/2024/11/GHSA-76ph-jc9g-v47h/GHSA-76ph-jc9g-v47h.json +++ b/advisories/unreviewed/2024/11/GHSA-76ph-jc9g-v47h/GHSA-76ph-jc9g-v47h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-76ph-jc9g-v47h", - "modified": "2024-11-27T18:34:01Z", + "modified": "2025-01-09T21:31:27Z", "published": "2024-11-20T18:32:17Z", "aliases": [ "CVE-2024-51163" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-51163" }, + { + "type": "WEB", + "url": "https://github.com/Henkel-CyberVM/CVEs/tree/main/CVE-2024-51163" + }, { "type": "WEB", "url": "https://github.com/rahulkadavil/CVEs/tree/main/CVE-2024-51163" diff --git a/advisories/unreviewed/2024/11/GHSA-77rq-3336-8w4x/GHSA-77rq-3336-8w4x.json b/advisories/unreviewed/2024/11/GHSA-77rq-3336-8w4x/GHSA-77rq-3336-8w4x.json index 9e6e0b84eec..80df805dc43 100644 --- a/advisories/unreviewed/2024/11/GHSA-77rq-3336-8w4x/GHSA-77rq-3336-8w4x.json +++ b/advisories/unreviewed/2024/11/GHSA-77rq-3336-8w4x/GHSA-77rq-3336-8w4x.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-126" + "CWE-126", + "CWE-191" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-pq42-5fqr-w8cx/GHSA-pq42-5fqr-w8cx.json b/advisories/unreviewed/2024/11/GHSA-pq42-5fqr-w8cx/GHSA-pq42-5fqr-w8cx.json index 29ee6893725..75e137dc602 100644 --- a/advisories/unreviewed/2024/11/GHSA-pq42-5fqr-w8cx/GHSA-pq42-5fqr-w8cx.json +++ b/advisories/unreviewed/2024/11/GHSA-pq42-5fqr-w8cx/GHSA-pq42-5fqr-w8cx.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-200" + "CWE-200", + "CWE-922" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/11/GHSA-qhv3-2cgf-c955/GHSA-qhv3-2cgf-c955.json b/advisories/unreviewed/2024/11/GHSA-qhv3-2cgf-c955/GHSA-qhv3-2cgf-c955.json index c7bc36f7dd3..bd428d6b9f2 100644 --- a/advisories/unreviewed/2024/11/GHSA-qhv3-2cgf-c955/GHSA-qhv3-2cgf-c955.json +++ b/advisories/unreviewed/2024/11/GHSA-qhv3-2cgf-c955/GHSA-qhv3-2cgf-c955.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qhv3-2cgf-c955", - "modified": "2024-11-22T21:32:13Z", + "modified": "2025-01-09T21:31:27Z", "published": "2024-11-20T18:32:17Z", "aliases": [ "CVE-2024-51162" @@ -26,6 +26,10 @@ { "type": "WEB", "url": "https://github.com/Cameleon037/CVEs/blob/main/CVE-2024-51162/README.md" + }, + { + "type": "WEB", + "url": "https://github.com/Henkel-CyberVM/CVEs/tree/main/CVE-2024-51162" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/11/GHSA-r6g4-pj3m-jq5m/GHSA-r6g4-pj3m-jq5m.json b/advisories/unreviewed/2024/11/GHSA-r6g4-pj3m-jq5m/GHSA-r6g4-pj3m-jq5m.json index a9f25d780f0..289cff0e10c 100644 --- a/advisories/unreviewed/2024/11/GHSA-r6g4-pj3m-jq5m/GHSA-r6g4-pj3m-jq5m.json +++ b/advisories/unreviewed/2024/11/GHSA-r6g4-pj3m-jq5m/GHSA-r6g4-pj3m-jq5m.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-126" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2024/11/GHSA-w9fw-pjxp-5fgx/GHSA-w9fw-pjxp-5fgx.json b/advisories/unreviewed/2024/11/GHSA-w9fw-pjxp-5fgx/GHSA-w9fw-pjxp-5fgx.json index d3eead074e0..cc332778d5f 100644 --- a/advisories/unreviewed/2024/11/GHSA-w9fw-pjxp-5fgx/GHSA-w9fw-pjxp-5fgx.json +++ b/advisories/unreviewed/2024/11/GHSA-w9fw-pjxp-5fgx/GHSA-w9fw-pjxp-5fgx.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-2h7q-5r55-6wf5/GHSA-2h7q-5r55-6wf5.json b/advisories/unreviewed/2024/12/GHSA-2h7q-5r55-6wf5/GHSA-2h7q-5r55-6wf5.json index 8ab7141fd8d..1d73b1649d0 100644 --- a/advisories/unreviewed/2024/12/GHSA-2h7q-5r55-6wf5/GHSA-2h7q-5r55-6wf5.json +++ b/advisories/unreviewed/2024/12/GHSA-2h7q-5r55-6wf5/GHSA-2h7q-5r55-6wf5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2h7q-5r55-6wf5", - "modified": "2024-12-29T12:30:40Z", + "modified": "2025-01-09T21:31:28Z", "published": "2024-12-29T12:30:40Z", "aliases": [ "CVE-2024-56723" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmfd: intel_soc_pmic_bxtwc: Use IRQ domain for PMIC devices\n\nWhile design wise the idea of converting the driver to use\nthe hierarchy of the IRQ chips is correct, the implementation\nhas (inherited) flaws. This was unveiled when platform_get_irq()\nhad started WARN() on IRQ 0 that is supposed to be a Linux\nIRQ number (also known as vIRQ).\n\nRework the driver to respect IRQ domain when creating each MFD\ndevice separately, as the domain is not the same for all of them.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -49,7 +54,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-29T12:15:06Z" diff --git a/advisories/unreviewed/2024/12/GHSA-3868-3wh9-6qr7/GHSA-3868-3wh9-6qr7.json b/advisories/unreviewed/2024/12/GHSA-3868-3wh9-6qr7/GHSA-3868-3wh9-6qr7.json index 74a36cf2da1..b177a4ef8ed 100644 --- a/advisories/unreviewed/2024/12/GHSA-3868-3wh9-6qr7/GHSA-3868-3wh9-6qr7.json +++ b/advisories/unreviewed/2024/12/GHSA-3868-3wh9-6qr7/GHSA-3868-3wh9-6qr7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3868-3wh9-6qr7", - "modified": "2024-12-29T09:30:47Z", + "modified": "2025-01-09T21:31:28Z", "published": "2024-12-29T09:30:47Z", "aliases": [ "CVE-2024-56719" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: stmmac: fix TSO DMA API usage causing oops\n\nCommit 66600fac7a98 (\"net: stmmac: TSO: Fix unbalanced DMA map/unmap\nfor non-paged SKB data\") moved the assignment of tx_skbuff_dma[]'s\nmembers to be later in stmmac_tso_xmit().\n\nThe buf (dma cookie) and len stored in this structure are passed to\ndma_unmap_single() by stmmac_tx_clean(). The DMA API requires that\nthe dma cookie passed to dma_unmap_single() is the same as the value\nreturned from dma_map_single(). However, by moving the assignment\nlater, this is not the case when priv->dma_cap.addr64 > 32 as \"des\"\nis offset by proto_hdr_len.\n\nThis causes problems such as:\n\n dwc-eth-dwmac 2490000.ethernet eth0: Tx DMA map failed\n\nand with DMA_API_DEBUG enabled:\n\n DMA-API: dwc-eth-dwmac 2490000.ethernet: device driver tries to +free DMA memory it has not allocated [device address=0x000000ffffcf65c0] [size=66 bytes]\n\nFix this by maintaining \"des\" as the original DMA cookie, and use\ntso_des to pass the offset DMA cookie to stmmac_tso_allocator().\n\nFull details of the crashes can be found at:\nhttps://lore.kernel.org/all/d8112193-0386-4e14-b516-37c2d838171a@nvidia.com/\nhttps://lore.kernel.org/all/klkzp5yn5kq5efgtrow6wbvnc46bcqfxs65nz3qy77ujr5turc@bwwhelz2l4dw/", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -29,7 +34,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-29T09:15:07Z" diff --git a/advisories/unreviewed/2024/12/GHSA-439r-vwp4-cgfr/GHSA-439r-vwp4-cgfr.json b/advisories/unreviewed/2024/12/GHSA-439r-vwp4-cgfr/GHSA-439r-vwp4-cgfr.json index 4fd2e28ec67..0291ac0f7c9 100644 --- a/advisories/unreviewed/2024/12/GHSA-439r-vwp4-cgfr/GHSA-439r-vwp4-cgfr.json +++ b/advisories/unreviewed/2024/12/GHSA-439r-vwp4-cgfr/GHSA-439r-vwp4-cgfr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-439r-vwp4-cgfr", - "modified": "2024-12-29T12:30:40Z", + "modified": "2025-01-09T21:31:28Z", "published": "2024-12-29T12:30:40Z", "aliases": [ "CVE-2024-56722" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/hns: Fix cpu stuck caused by printings during reset\n\nDuring reset, cmd to destroy resources such as qp, cq, and mr may fail,\nand error logs will be printed. When a large number of resources are\ndestroyed, there will be lots of printings, and it may lead to a cpu\nstuck.\n\nDelete some unnecessary printings and replace other printing functions\nin these paths with the ratelimited version.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-770" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-29T12:15:06Z" diff --git a/advisories/unreviewed/2024/12/GHSA-4hrg-cvr4-ff8f/GHSA-4hrg-cvr4-ff8f.json b/advisories/unreviewed/2024/12/GHSA-4hrg-cvr4-ff8f/GHSA-4hrg-cvr4-ff8f.json index 1e5377e1bde..d143fab3a34 100644 --- a/advisories/unreviewed/2024/12/GHSA-4hrg-cvr4-ff8f/GHSA-4hrg-cvr4-ff8f.json +++ b/advisories/unreviewed/2024/12/GHSA-4hrg-cvr4-ff8f/GHSA-4hrg-cvr4-ff8f.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4hrg-cvr4-ff8f", - "modified": "2024-12-29T12:30:40Z", + "modified": "2025-01-09T21:31:28Z", "published": "2024-12-29T12:30:40Z", "aliases": [ "CVE-2024-56721" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/CPU/AMD: Terminate the erratum_1386_microcode array\n\nThe erratum_1386_microcode array requires an empty entry at the end.\nOtherwise x86_match_cpu_with_stepping() will continue iterate the array after\nit ended.\n\nAdd an empty entry to erratum_1386_microcode to its end.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-29T12:15:06Z" diff --git a/advisories/unreviewed/2024/12/GHSA-4x48-ph6h-wfmf/GHSA-4x48-ph6h-wfmf.json b/advisories/unreviewed/2024/12/GHSA-4x48-ph6h-wfmf/GHSA-4x48-ph6h-wfmf.json index a073a385f37..dbd4f8a2a85 100644 --- a/advisories/unreviewed/2024/12/GHSA-4x48-ph6h-wfmf/GHSA-4x48-ph6h-wfmf.json +++ b/advisories/unreviewed/2024/12/GHSA-4x48-ph6h-wfmf/GHSA-4x48-ph6h-wfmf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4x48-ph6h-wfmf", - "modified": "2024-12-29T12:30:40Z", + "modified": "2025-01-09T21:31:28Z", "published": "2024-12-29T12:30:40Z", "aliases": [ "CVE-2024-56720" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf, sockmap: Several fixes to bpf_msg_pop_data\n\nSeveral fixes to bpf_msg_pop_data,\n1. In sk_msg_shift_left, we should put_page\n2. if (len == 0), return early is better\n3. pop the entire sk_msg (last == msg->sg.size) should be supported\n4. Fix for the value of variable \"a\"\n5. In sk_msg_shift_left, after shifting, i has already pointed to the next\nelement. Addtional sk_msg_iter_var_next may result in BUG.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-193" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-29T12:15:06Z" diff --git a/advisories/unreviewed/2024/12/GHSA-fmfx-vcm3-x4fp/GHSA-fmfx-vcm3-x4fp.json b/advisories/unreviewed/2024/12/GHSA-fmfx-vcm3-x4fp/GHSA-fmfx-vcm3-x4fp.json index 2267413376e..e77071a95de 100644 --- a/advisories/unreviewed/2024/12/GHSA-fmfx-vcm3-x4fp/GHSA-fmfx-vcm3-x4fp.json +++ b/advisories/unreviewed/2024/12/GHSA-fmfx-vcm3-x4fp/GHSA-fmfx-vcm3-x4fp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fmfx-vcm3-x4fp", - "modified": "2024-12-29T12:30:40Z", + "modified": "2025-01-09T21:31:29Z", "published": "2024-12-29T12:30:40Z", "aliases": [ "CVE-2024-56725" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nocteontx2-pf: handle otx2_mbox_get_rsp errors in otx2_dcbnl.c\n\nAdd error pointer check after calling otx2_mbox_get_rsp().", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-754" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-29T12:15:06Z" diff --git a/advisories/unreviewed/2024/12/GHSA-hc38-wh54-qgvx/GHSA-hc38-wh54-qgvx.json b/advisories/unreviewed/2024/12/GHSA-hc38-wh54-qgvx/GHSA-hc38-wh54-qgvx.json index 2e52c6dabe4..1a4681f4404 100644 --- a/advisories/unreviewed/2024/12/GHSA-hc38-wh54-qgvx/GHSA-hc38-wh54-qgvx.json +++ b/advisories/unreviewed/2024/12/GHSA-hc38-wh54-qgvx/GHSA-hc38-wh54-qgvx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hc38-wh54-qgvx", - "modified": "2025-01-09T18:32:13Z", + "modified": "2025-01-09T21:31:28Z", "published": "2024-12-18T09:31:35Z", "aliases": [ "CVE-2024-11614" @@ -31,6 +31,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:0210" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:0211" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:0220" diff --git a/advisories/unreviewed/2024/12/GHSA-pvx3-2639-67p3/GHSA-pvx3-2639-67p3.json b/advisories/unreviewed/2024/12/GHSA-pvx3-2639-67p3/GHSA-pvx3-2639-67p3.json index c541aa6d360..3cadde34f5c 100644 --- a/advisories/unreviewed/2024/12/GHSA-pvx3-2639-67p3/GHSA-pvx3-2639-67p3.json +++ b/advisories/unreviewed/2024/12/GHSA-pvx3-2639-67p3/GHSA-pvx3-2639-67p3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pvx3-2639-67p3", - "modified": "2024-12-29T12:30:40Z", + "modified": "2025-01-09T21:31:28Z", "published": "2024-12-29T12:30:40Z", "aliases": [ "CVE-2024-56724" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmfd: intel_soc_pmic_bxtwc: Use IRQ domain for TMU device\n\nWhile design wise the idea of converting the driver to use\nthe hierarchy of the IRQ chips is correct, the implementation\nhas (inherited) flaws. This was unveiled when platform_get_irq()\nhad started WARN() on IRQ 0 that is supposed to be a Linux\nIRQ number (also known as vIRQ).\n\nRework the driver to respect IRQ domain when creating each MFD\ndevice separately, as the domain is not the same for all of them.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -49,7 +54,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-12-29T12:15:06Z" diff --git a/advisories/unreviewed/2025/01/GHSA-223j-7cj4-4cw7/GHSA-223j-7cj4-4cw7.json b/advisories/unreviewed/2025/01/GHSA-223j-7cj4-4cw7/GHSA-223j-7cj4-4cw7.json new file mode 100644 index 00000000000..6ef8ba8afb2 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-223j-7cj4-4cw7/GHSA-223j-7cj4-4cw7.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-223j-7cj4-4cw7", + "modified": "2025-01-09T21:31:31Z", + "published": "2025-01-09T21:31:31Z", + "aliases": [ + "CVE-2024-13278" + ], + "details": "Incorrect Authorization vulnerability in Drupal Diff allows Functionality Misuse.This issue affects Diff: from 0.0.0 before 1.8.0.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13278" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-042" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T20:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-2479-2frf-9263/GHSA-2479-2frf-9263.json b/advisories/unreviewed/2025/01/GHSA-2479-2frf-9263/GHSA-2479-2frf-9263.json new file mode 100644 index 00000000000..d285c6aded1 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2479-2frf-9263/GHSA-2479-2frf-9263.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2479-2frf-9263", + "modified": "2025-01-09T21:31:30Z", + "published": "2025-01-09T21:31:30Z", + "aliases": [ + "CVE-2024-13248" + ], + "details": "Incorrect Privilege Assignment vulnerability in Drupal Private content allows Target Influence via Framing.This issue affects Private content: from 0.0.0 before 2.1.0.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13248" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-012" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T19:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-2gj6-558v-rq2w/GHSA-2gj6-558v-rq2w.json b/advisories/unreviewed/2025/01/GHSA-2gj6-558v-rq2w/GHSA-2gj6-558v-rq2w.json new file mode 100644 index 00000000000..0ee6e1c8cc9 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2gj6-558v-rq2w/GHSA-2gj6-558v-rq2w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2gj6-558v-rq2w", + "modified": "2025-01-09T21:31:30Z", + "published": "2025-01-09T21:31:30Z", + "aliases": [ + "CVE-2024-13245" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal CKEditor 4 LTS - WYSIWYG HTML editor allows Cross-Site Scripting (XSS).This issue affects CKEditor 4 LTS - WYSIWYG HTML editor: from 1.0.0 before 1.0.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13245" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-009" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T19:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-2q57-gr73-v7pg/GHSA-2q57-gr73-v7pg.json b/advisories/unreviewed/2025/01/GHSA-2q57-gr73-v7pg/GHSA-2q57-gr73-v7pg.json new file mode 100644 index 00000000000..26b7e70f700 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2q57-gr73-v7pg/GHSA-2q57-gr73-v7pg.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2q57-gr73-v7pg", + "modified": "2025-01-09T21:31:31Z", + "published": "2025-01-09T21:31:31Z", + "aliases": [ + "CVE-2024-42898" + ], + "details": "A cross-site scripting (XSS) vulnerability in Nagios XI 2024R1.1.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter in the Account Settings page.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42898" + }, + { + "type": "WEB", + "url": "https://github.com/simalamuel/Research/tree/main/CVE-2024-42898" + }, + { + "type": "WEB", + "url": "https://www.nagios.com/products/security" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T20:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-2rx4-vrv5-3mjp/GHSA-2rx4-vrv5-3mjp.json b/advisories/unreviewed/2025/01/GHSA-2rx4-vrv5-3mjp/GHSA-2rx4-vrv5-3mjp.json new file mode 100644 index 00000000000..8657e8410f1 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2rx4-vrv5-3mjp/GHSA-2rx4-vrv5-3mjp.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2rx4-vrv5-3mjp", + "modified": "2025-01-09T21:31:31Z", + "published": "2025-01-09T21:31:31Z", + "aliases": [ + "CVE-2024-13265" + ], + "details": "Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno Learning path allows PHP Local File Inclusion.This issue affects Opigno Learning path: from 0.0.0 before 3.1.2.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13265" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-029" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-96" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T20:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-2wf3-32wx-c338/GHSA-2wf3-32wx-c338.json b/advisories/unreviewed/2025/01/GHSA-2wf3-32wx-c338/GHSA-2wf3-32wx-c338.json new file mode 100644 index 00000000000..59814b68b1a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-2wf3-32wx-c338/GHSA-2wf3-32wx-c338.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2wf3-32wx-c338", + "modified": "2025-01-09T21:31:31Z", + "published": "2025-01-09T21:31:31Z", + "aliases": [ + "CVE-2024-54761" + ], + "details": "BigAnt Office Messenger 5.6.06 is vulnerable to SQL Injection via the 'dev_code' parameter.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54761" + }, + { + "type": "WEB", + "url": "https://github.com/nscan9/BigAnt-Office-Messenger-5.6.06-RCE-via-SQL-Injection" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T20:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-37wj-v394-2xvc/GHSA-37wj-v394-2xvc.json b/advisories/unreviewed/2025/01/GHSA-37wj-v394-2xvc/GHSA-37wj-v394-2xvc.json new file mode 100644 index 00000000000..44ac717e6b2 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-37wj-v394-2xvc/GHSA-37wj-v394-2xvc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-37wj-v394-2xvc", + "modified": "2025-01-09T21:31:31Z", + "published": "2025-01-09T21:31:31Z", + "aliases": [ + "CVE-2024-13283" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Facets allows Cross-Site Scripting (XSS).This issue affects Facets: from 0.0.0 before 2.0.9.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13283" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-047" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T20:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-4g5v-5q43-rwpj/GHSA-4g5v-5q43-rwpj.json b/advisories/unreviewed/2025/01/GHSA-4g5v-5q43-rwpj/GHSA-4g5v-5q43-rwpj.json index 02a98b76ad6..a9a78a81837 100644 --- a/advisories/unreviewed/2025/01/GHSA-4g5v-5q43-rwpj/GHSA-4g5v-5q43-rwpj.json +++ b/advisories/unreviewed/2025/01/GHSA-4g5v-5q43-rwpj/GHSA-4g5v-5q43-rwpj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4g5v-5q43-rwpj", - "modified": "2025-01-08T18:30:49Z", + "modified": "2025-01-09T21:31:29Z", "published": "2025-01-08T18:30:49Z", "aliases": [ "CVE-2024-56785" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nMIPS: Loongson64: DTS: Really fix PCIe port nodes for ls7a\n\nFix the dtc warnings:\n\n arch/mips/boot/dts/loongson/ls7a-pch.dtsi:68.16-416.5: Warning (interrupt_provider): /bus@10000000/pci@1a000000: '#interrupt-cells' found, but node is not an interrupt provider\n arch/mips/boot/dts/loongson/ls7a-pch.dtsi:68.16-416.5: Warning (interrupt_provider): /bus@10000000/pci@1a000000: '#interrupt-cells' found, but node is not an interrupt provider\n arch/mips/boot/dts/loongson/loongson64g_4core_ls7a.dtb: Warning (interrupt_map): Failed prerequisite 'interrupt_provider'\n\nAnd a runtime warning introduced in commit 045b14ca5c36 (\"of: WARN on\ndeprecated #address-cells/#size-cells handling\"):\n\n WARNING: CPU: 0 PID: 1 at drivers/of/base.c:106 of_bus_n_addr_cells+0x9c/0xe0\n Missing '#address-cells' in /bus@10000000/pci@1a000000/pci_bridge@9,0\n\nThe fix is similar to commit d89a415ff8d5 (\"MIPS: Loongson64: DTS: Fix PCIe\nport nodes for ls7a\"), which has fixed the issue for ls2k (despite its\nsubject mentions ls7a).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -41,7 +46,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-08T18:15:19Z" diff --git a/advisories/unreviewed/2025/01/GHSA-57r5-pmvw-w26w/GHSA-57r5-pmvw-w26w.json b/advisories/unreviewed/2025/01/GHSA-57r5-pmvw-w26w/GHSA-57r5-pmvw-w26w.json new file mode 100644 index 00000000000..f08bf7a5dd4 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-57r5-pmvw-w26w/GHSA-57r5-pmvw-w26w.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-57r5-pmvw-w26w", + "modified": "2025-01-09T21:31:30Z", + "published": "2025-01-09T21:31:30Z", + "aliases": [ + "CVE-2024-13253" + ], + "details": "Incorrect Authorization vulnerability in Drupal Advanced PWA inc Push Notifications allows Forceful Browsing.This issue affects Advanced PWA inc Push Notifications: from 0.0.0 before 1.5.0.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13253" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-017" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T19:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-5c5x-jw5q-2wpw/GHSA-5c5x-jw5q-2wpw.json b/advisories/unreviewed/2025/01/GHSA-5c5x-jw5q-2wpw/GHSA-5c5x-jw5q-2wpw.json new file mode 100644 index 00000000000..c824649c4fc --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-5c5x-jw5q-2wpw/GHSA-5c5x-jw5q-2wpw.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5c5x-jw5q-2wpw", + "modified": "2025-01-09T21:31:32Z", + "published": "2025-01-09T21:31:32Z", + "aliases": [ + "CVE-2024-13300" + ], + "details": "Vulnerability in Drupal Print Anything.This issue affects Print Anything: *.*.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13300" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-066" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T21:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-5rcq-gp73-g9jv/GHSA-5rcq-gp73-g9jv.json b/advisories/unreviewed/2025/01/GHSA-5rcq-gp73-g9jv/GHSA-5rcq-gp73-g9jv.json new file mode 100644 index 00000000000..bfd4d371ba7 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-5rcq-gp73-g9jv/GHSA-5rcq-gp73-g9jv.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5rcq-gp73-g9jv", + "modified": "2025-01-09T21:31:30Z", + "published": "2025-01-09T21:31:30Z", + "aliases": [ + "CVE-2024-13250" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Drupal Drupal Symfony Mailer Lite allows Cross Site Request Forgery.This issue affects Drupal Symfony Mailer Lite: from 0.0.0 before 1.0.6.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13250" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-014" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T19:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-623r-49cc-q6vj/GHSA-623r-49cc-q6vj.json b/advisories/unreviewed/2025/01/GHSA-623r-49cc-q6vj/GHSA-623r-49cc-q6vj.json new file mode 100644 index 00000000000..f64977e3206 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-623r-49cc-q6vj/GHSA-623r-49cc-q6vj.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-623r-49cc-q6vj", + "modified": "2025-01-09T21:31:31Z", + "published": "2025-01-09T21:31:31Z", + "aliases": [ + "CVE-2024-13289" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Cookiebot + GTM allows Cross-Site Scripting (XSS).This issue affects Cookiebot + GTM: from 0.0.0 before 1.0.18.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13289" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-055" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T21:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-6372-2hcg-2fr4/GHSA-6372-2hcg-2fr4.json b/advisories/unreviewed/2025/01/GHSA-6372-2hcg-2fr4/GHSA-6372-2hcg-2fr4.json new file mode 100644 index 00000000000..8cd9fa5cc42 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-6372-2hcg-2fr4/GHSA-6372-2hcg-2fr4.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6372-2hcg-2fr4", + "modified": "2025-01-09T21:31:32Z", + "published": "2025-01-09T21:31:32Z", + "aliases": [ + "CVE-2024-13295" + ], + "details": "Deserialization of Untrusted Data vulnerability in Drupal Node export allows Object Injection.This issue affects Node export: from 7.X-* before 7.X-3.3.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13295" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-061" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T21:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-63wg-87qv-rw4r/GHSA-63wg-87qv-rw4r.json b/advisories/unreviewed/2025/01/GHSA-63wg-87qv-rw4r/GHSA-63wg-87qv-rw4r.json new file mode 100644 index 00000000000..c8cbf9a1ec5 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-63wg-87qv-rw4r/GHSA-63wg-87qv-rw4r.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-63wg-87qv-rw4r", + "modified": "2025-01-09T21:31:31Z", + "published": "2025-01-09T21:31:31Z", + "aliases": [ + "CVE-2024-13274" + ], + "details": "Improper Control of Interaction Frequency vulnerability in Drupal Open Social allows Functionality Misuse.This issue affects Open Social: from 0.0.0 before 12.3.8, from 12.4.0 before 12.4.5.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13274" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-038" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-799" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T20:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-68jp-4r95-v8vr/GHSA-68jp-4r95-v8vr.json b/advisories/unreviewed/2025/01/GHSA-68jp-4r95-v8vr/GHSA-68jp-4r95-v8vr.json new file mode 100644 index 00000000000..79a6fa57b7d --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-68jp-4r95-v8vr/GHSA-68jp-4r95-v8vr.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-68jp-4r95-v8vr", + "modified": "2025-01-09T21:31:30Z", + "published": "2025-01-09T21:31:30Z", + "aliases": [ + "CVE-2025-21598" + ], + "details": "An Out-of-bounds Read vulnerability in Juniper Networks Junos OS and Junos OS Evolved's routing protocol daemon (rpd) allows an unauthenticated, network-based attacker to send malformed BGP packets to a device configured with packet receive trace options enabled to crash rpd.\nThis issue affects:\n\nJunos OS: \n\n\n\n * from 21.2R3-S8 before 21.2R3-S9, \n * from 21.4R3-S7 before 21.4R3-S9, \n * from 22.2R3-S4 before 22.2R3-S5, \n * from 22.3R3-S2 before 22.3R3-S4, \n * from 22.4R3 before 22.4R3-S5, \n * from 23.2R2 before 23.2R2-S2, \n * from 23.4R1 before 23.4R2-S1, \n * from 24.2R1 before 24.2R1-S1, 24.2R2.\n\n\nJunos OS Evolved:\n * from 21.4R3-S7-EVO before 21.4R3-S9-EVO, \n * from 22.2R3-S4-EVO before 22.2R3-S5-EVO, \n * from 22.3R3-S2-EVO before 22.3R3-S4-EVO, \n * from 22.4R3-EVO before 22.4R3-S5-EVO, \n * from 23.2R2-EVO before 23.2R2-S2-EVO, \n * from 23.4R1-EVO before 23.4R2-S1-EVO, \n * from 24.2R1-EVO before 24.2R1-S2-EVO, 24.2R2-EVO.\n\n\nThis issue requires a BGP session to be established.\n\nThis issue can propagate and multiply through multiple ASes until reaching vulnerable devices.\n\nThis issue affects iBGP and eBGP.\n\nThis issue affects IPv4 and IPv6.\n\nAn indicator of compromise may be the presence of malformed update messages in a neighboring AS which is unaffected by this issue:\n\nFor example, by issuing the command on the neighboring device:\n show log messages\n\nReviewing for similar messages from devices within proximity to each other may indicate this malformed packet is propagating:\n  rpd[]: Received malformed update from (External AS )\nand\n  rpd[]: Malformed Attribute", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:A/V:C/RE:M/U:Amber" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21598" + }, + { + "type": "WEB", + "url": "https://supportportal.juniper.net/JSA92867" + }, + { + "type": "WEB", + "url": "https://www.juniper.net/documentation/us/en/software/junos/cli-reference/topics/ref/statement/traceoptions-edit-protocols-bgp.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T19:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-6g5p-29h6-5w4p/GHSA-6g5p-29h6-5w4p.json b/advisories/unreviewed/2025/01/GHSA-6g5p-29h6-5w4p/GHSA-6g5p-29h6-5w4p.json new file mode 100644 index 00000000000..376db1d67e7 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-6g5p-29h6-5w4p/GHSA-6g5p-29h6-5w4p.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6g5p-29h6-5w4p", + "modified": "2025-01-09T21:31:32Z", + "published": "2025-01-09T21:31:32Z", + "aliases": [ + "CVE-2024-13310" + ], + "details": "Vulnerability in Drupal Git Utilities for Drupal.This issue affects Git Utilities for Drupal: *.*.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13310" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-074" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T21:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-6h86-6h56-2j4j/GHSA-6h86-6h56-2j4j.json b/advisories/unreviewed/2025/01/GHSA-6h86-6h56-2j4j/GHSA-6h86-6h56-2j4j.json new file mode 100644 index 00000000000..3b3e1a1532b --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-6h86-6h56-2j4j/GHSA-6h86-6h56-2j4j.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6h86-6h56-2j4j", + "modified": "2025-01-09T21:31:31Z", + "published": "2025-01-09T21:31:31Z", + "aliases": [ + "CVE-2024-13287" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Views SVG Animation allows Cross-Site Scripting (XSS).This issue affects Views SVG Animation: from 0.0.0 before 1.0.1.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13287" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-051" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T20:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-6hq6-3pp3-9598/GHSA-6hq6-3pp3-9598.json b/advisories/unreviewed/2025/01/GHSA-6hq6-3pp3-9598/GHSA-6hq6-3pp3-9598.json new file mode 100644 index 00000000000..00e6cd70f74 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-6hq6-3pp3-9598/GHSA-6hq6-3pp3-9598.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6hq6-3pp3-9598", + "modified": "2025-01-09T21:31:32Z", + "published": "2025-01-09T21:31:32Z", + "aliases": [ + "CVE-2024-13304" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Drupal Minify JS allows Cross Site Request Forgery.This issue affects Minify JS: from 0.0.0 before 3.0.3.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13304" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-070" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T21:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-6j67-4cmx-rgw8/GHSA-6j67-4cmx-rgw8.json b/advisories/unreviewed/2025/01/GHSA-6j67-4cmx-rgw8/GHSA-6j67-4cmx-rgw8.json new file mode 100644 index 00000000000..603f6f68ac0 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-6j67-4cmx-rgw8/GHSA-6j67-4cmx-rgw8.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6j67-4cmx-rgw8", + "modified": "2025-01-09T21:31:31Z", + "published": "2025-01-09T21:31:31Z", + "aliases": [ + "CVE-2024-13263" + ], + "details": "Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno group manager allows PHP Local File Inclusion.This issue affects Opigno group manager: from 0.0.0 before 3.1.1.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13263" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-027" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-96" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T20:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-6q5c-9hq7-3fc3/GHSA-6q5c-9hq7-3fc3.json b/advisories/unreviewed/2025/01/GHSA-6q5c-9hq7-3fc3/GHSA-6q5c-9hq7-3fc3.json new file mode 100644 index 00000000000..af1df4ea640 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-6q5c-9hq7-3fc3/GHSA-6q5c-9hq7-3fc3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6q5c-9hq7-3fc3", + "modified": "2025-01-09T21:31:31Z", + "published": "2025-01-09T21:31:31Z", + "aliases": [ + "CVE-2024-13273" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Open Social allows Cross-Site Scripting (XSS).This issue affects Open Social: from 0.0.0 before 12.3.8, from 12.4.0 before 12.4.5, from 13.0.0 before 13.0.0-alpha11.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13273" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-037" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T20:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-7649-pgpq-cpch/GHSA-7649-pgpq-cpch.json b/advisories/unreviewed/2025/01/GHSA-7649-pgpq-cpch/GHSA-7649-pgpq-cpch.json new file mode 100644 index 00000000000..4c2d4fd2fdb --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-7649-pgpq-cpch/GHSA-7649-pgpq-cpch.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7649-pgpq-cpch", + "modified": "2025-01-09T21:31:30Z", + "published": "2025-01-09T21:31:30Z", + "aliases": [ + "CVE-2024-13258" + ], + "details": "Incorrect Authorization vulnerability in Drupal Drupal REST & JSON API Authentication allows Forceful Browsing.This issue affects Drupal REST & JSON API Authentication: from 0.0.0 before 2.0.13.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13258" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-022" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T19:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-8244-g8gx-36rj/GHSA-8244-g8gx-36rj.json b/advisories/unreviewed/2025/01/GHSA-8244-g8gx-36rj/GHSA-8244-g8gx-36rj.json new file mode 100644 index 00000000000..d31e53b754b --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-8244-g8gx-36rj/GHSA-8244-g8gx-36rj.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8244-g8gx-36rj", + "modified": "2025-01-09T21:31:31Z", + "published": "2025-01-09T21:31:31Z", + "aliases": [ + "CVE-2024-13285" + ], + "details": "Vulnerability in Drupal wkhtmltopdf.This issue affects wkhtmltopdf: *.*.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13285" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-049" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T20:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-863q-738r-33x7/GHSA-863q-738r-33x7.json b/advisories/unreviewed/2025/01/GHSA-863q-738r-33x7/GHSA-863q-738r-33x7.json new file mode 100644 index 00000000000..f33d780db64 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-863q-738r-33x7/GHSA-863q-738r-33x7.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-863q-738r-33x7", + "modified": "2025-01-09T21:31:32Z", + "published": "2025-01-09T21:31:32Z", + "aliases": [ + "CVE-2024-13308" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Browser Back Button allows Cross-Site Scripting (XSS).This issue affects Browser Back Button: from 1.0.0 before 2.0.2.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13308" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-072" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T21:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-88c8-vf36-8mvr/GHSA-88c8-vf36-8mvr.json b/advisories/unreviewed/2025/01/GHSA-88c8-vf36-8mvr/GHSA-88c8-vf36-8mvr.json new file mode 100644 index 00000000000..5efff8bf20c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-88c8-vf36-8mvr/GHSA-88c8-vf36-8mvr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-88c8-vf36-8mvr", + "modified": "2025-01-09T21:31:31Z", + "published": "2025-01-09T21:31:31Z", + "aliases": [ + "CVE-2024-13262" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal View Password allows Cross-Site Scripting (XSS).This issue affects View Password: from 0.0.0 before 6.0.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13262" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-026" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T20:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-8hmg-gpg9-2qqw/GHSA-8hmg-gpg9-2qqw.json b/advisories/unreviewed/2025/01/GHSA-8hmg-gpg9-2qqw/GHSA-8hmg-gpg9-2qqw.json new file mode 100644 index 00000000000..72bfca2d6fb --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-8hmg-gpg9-2qqw/GHSA-8hmg-gpg9-2qqw.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8hmg-gpg9-2qqw", + "modified": "2025-01-09T21:31:31Z", + "published": "2025-01-09T21:31:31Z", + "aliases": [ + "CVE-2024-13271" + ], + "details": "Incorrect Authorization vulnerability in Drupal Content Entity Clone allows Forceful Browsing.This issue affects Content Entity Clone: from 0.0.0 before 1.0.4.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13271" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-035" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T20:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-932w-6jv2-mm8q/GHSA-932w-6jv2-mm8q.json b/advisories/unreviewed/2025/01/GHSA-932w-6jv2-mm8q/GHSA-932w-6jv2-mm8q.json new file mode 100644 index 00000000000..127ee217d1e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-932w-6jv2-mm8q/GHSA-932w-6jv2-mm8q.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-932w-6jv2-mm8q", + "modified": "2025-01-09T21:31:30Z", + "published": "2025-01-09T21:31:30Z", + "aliases": [ + "CVE-2024-13257" + ], + "details": "Incorrect Authorization vulnerability in Drupal Commerce View Receipt allows Forceful Browsing.This issue affects Commerce View Receipt: from 0.0.0 before 1.0.3.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13257" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-021" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T19:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9838-cxcw-r6rf/GHSA-9838-cxcw-r6rf.json b/advisories/unreviewed/2025/01/GHSA-9838-cxcw-r6rf/GHSA-9838-cxcw-r6rf.json new file mode 100644 index 00000000000..36082d2867e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9838-cxcw-r6rf/GHSA-9838-cxcw-r6rf.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9838-cxcw-r6rf", + "modified": "2025-01-09T21:31:32Z", + "published": "2025-01-09T21:31:32Z", + "aliases": [ + "CVE-2024-13294" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal POST File allows Cross-Site Scripting (XSS).This issue affects POST File: from 0.0.0 before 1.0.2.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13294" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-060" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T21:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-99h6-9pr2-5g94/GHSA-99h6-9pr2-5g94.json b/advisories/unreviewed/2025/01/GHSA-99h6-9pr2-5g94/GHSA-99h6-9pr2-5g94.json new file mode 100644 index 00000000000..0ab2b45e260 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-99h6-9pr2-5g94/GHSA-99h6-9pr2-5g94.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-99h6-9pr2-5g94", + "modified": "2025-01-09T21:31:31Z", + "published": "2025-01-09T21:31:31Z", + "aliases": [ + "CVE-2024-13264" + ], + "details": "Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno module allows PHP Local File Inclusion.This issue affects Opigno module: from 0.0.0 before 3.1.2.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13264" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-028" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-96" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T20:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9fxm-qh6m-23f8/GHSA-9fxm-qh6m-23f8.json b/advisories/unreviewed/2025/01/GHSA-9fxm-qh6m-23f8/GHSA-9fxm-qh6m-23f8.json index e9dd86b3a44..c6b903af8fe 100644 --- a/advisories/unreviewed/2025/01/GHSA-9fxm-qh6m-23f8/GHSA-9fxm-qh6m-23f8.json +++ b/advisories/unreviewed/2025/01/GHSA-9fxm-qh6m-23f8/GHSA-9fxm-qh6m-23f8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9fxm-qh6m-23f8", - "modified": "2025-01-02T15:31:59Z", + "modified": "2025-01-09T21:31:29Z", "published": "2025-01-02T15:31:59Z", "aliases": [ "CVE-2022-49035" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: s5p_cec: limit msg.len to CEC_MAX_MSG_SIZE\n\nI expect that the hardware will have limited this to 16, but just in\ncase it hasn't, check for this corner case.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-770" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-02T15:15:18Z" diff --git a/advisories/unreviewed/2025/01/GHSA-9j33-5mgw-847x/GHSA-9j33-5mgw-847x.json b/advisories/unreviewed/2025/01/GHSA-9j33-5mgw-847x/GHSA-9j33-5mgw-847x.json new file mode 100644 index 00000000000..23cdd2a7516 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9j33-5mgw-847x/GHSA-9j33-5mgw-847x.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9j33-5mgw-847x", + "modified": "2025-01-09T21:31:32Z", + "published": "2025-01-09T21:31:32Z", + "aliases": [ + "CVE-2024-13305" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Entity Form Steps allows Cross-Site Scripting (XSS).This issue affects Entity Form Steps: from 0.0.0 before 1.1.4.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13305" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-071" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T21:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9j66-pm9j-3fvj/GHSA-9j66-pm9j-3fvj.json b/advisories/unreviewed/2025/01/GHSA-9j66-pm9j-3fvj/GHSA-9j66-pm9j-3fvj.json new file mode 100644 index 00000000000..28739bbb750 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9j66-pm9j-3fvj/GHSA-9j66-pm9j-3fvj.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9j66-pm9j-3fvj", + "modified": "2025-01-09T21:31:32Z", + "published": "2025-01-09T21:31:32Z", + "aliases": [ + "CVE-2024-13302" + ], + "details": "Incorrect Authorization vulnerability in Drupal Pages Restriction Access allows Forceful Browsing.This issue affects Pages Restriction Access: from 2.0.0 before 2.0.3.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13302" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-068" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T21:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9m7f-2xgc-3w9v/GHSA-9m7f-2xgc-3w9v.json b/advisories/unreviewed/2025/01/GHSA-9m7f-2xgc-3w9v/GHSA-9m7f-2xgc-3w9v.json new file mode 100644 index 00000000000..4468afe1b18 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9m7f-2xgc-3w9v/GHSA-9m7f-2xgc-3w9v.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9m7f-2xgc-3w9v", + "modified": "2025-01-09T21:31:30Z", + "published": "2025-01-09T21:31:30Z", + "aliases": [ + "CVE-2024-13246" + ], + "details": "Improper Ownership Management vulnerability in Drupal Node Access Rebuild Progressive allows Target Influence via Framing.This issue affects Node Access Rebuild Progressive: from 0.0.0 before 2.0.2.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13246" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-010" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-282" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T19:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9q24-c9h6-h244/GHSA-9q24-c9h6-h244.json b/advisories/unreviewed/2025/01/GHSA-9q24-c9h6-h244/GHSA-9q24-c9h6-h244.json new file mode 100644 index 00000000000..08c7456a23b --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9q24-c9h6-h244/GHSA-9q24-c9h6-h244.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9q24-c9h6-h244", + "modified": "2025-01-09T21:31:31Z", + "published": "2025-01-09T21:31:31Z", + "aliases": [ + "CVE-2024-13280" + ], + "details": "Insufficient Session Expiration vulnerability in Drupal Persistent Login allows Forceful Browsing.This issue affects Persistent Login: from 0.0.0 before 1.8.0, from 2.0.* before 2.2.2.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13280" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-044" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-613" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T20:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9vgr-6gpq-2rj5/GHSA-9vgr-6gpq-2rj5.json b/advisories/unreviewed/2025/01/GHSA-9vgr-6gpq-2rj5/GHSA-9vgr-6gpq-2rj5.json index 65f5229a66d..f725dd54063 100644 --- a/advisories/unreviewed/2025/01/GHSA-9vgr-6gpq-2rj5/GHSA-9vgr-6gpq-2rj5.json +++ b/advisories/unreviewed/2025/01/GHSA-9vgr-6gpq-2rj5/GHSA-9vgr-6gpq-2rj5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9vgr-6gpq-2rj5", - "modified": "2025-01-08T18:30:49Z", + "modified": "2025-01-09T21:31:29Z", "published": "2025-01-08T18:30:49Z", "aliases": [ "CVE-2024-56783" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_socket: remove WARN_ON_ONCE on maximum cgroup level\n\ncgroup maximum depth is INT_MAX by default, there is a cgroup toggle to\nrestrict this maximum depth to a more reasonable value not to harm\nperformance. Remove unnecessary WARN_ON_ONCE which is reachable from\nuserspace.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-617" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-08T18:15:19Z" diff --git a/advisories/unreviewed/2025/01/GHSA-ch9r-7w7v-gg4p/GHSA-ch9r-7w7v-gg4p.json b/advisories/unreviewed/2025/01/GHSA-ch9r-7w7v-gg4p/GHSA-ch9r-7w7v-gg4p.json new file mode 100644 index 00000000000..a59e141f03c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-ch9r-7w7v-gg4p/GHSA-ch9r-7w7v-gg4p.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ch9r-7w7v-gg4p", + "modified": "2025-01-09T21:31:32Z", + "published": "2025-01-09T21:31:31Z", + "aliases": [ + "CVE-2024-13292" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Tooltip allows Cross-Site Scripting (XSS).This issue affects Tooltip: from 0.0.0 before 1.1.2.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13292" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-058" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T21:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-chpw-4vjg-cp92/GHSA-chpw-4vjg-cp92.json b/advisories/unreviewed/2025/01/GHSA-chpw-4vjg-cp92/GHSA-chpw-4vjg-cp92.json new file mode 100644 index 00000000000..fc15921215d --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-chpw-4vjg-cp92/GHSA-chpw-4vjg-cp92.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-chpw-4vjg-cp92", + "modified": "2025-01-09T21:31:30Z", + "published": "2025-01-09T21:31:30Z", + "aliases": [ + "CVE-2024-13247" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Coffee allows Cross-Site Scripting (XSS).This issue affects Coffee: from 0.0.0 before 1.4.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13247" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-011" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T19:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-f4vg-m386-rcvq/GHSA-f4vg-m386-rcvq.json b/advisories/unreviewed/2025/01/GHSA-f4vg-m386-rcvq/GHSA-f4vg-m386-rcvq.json index 1bdf9dd3b40..fdb6f192c23 100644 --- a/advisories/unreviewed/2025/01/GHSA-f4vg-m386-rcvq/GHSA-f4vg-m386-rcvq.json +++ b/advisories/unreviewed/2025/01/GHSA-f4vg-m386-rcvq/GHSA-f4vg-m386-rcvq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f4vg-m386-rcvq", - "modified": "2025-01-08T18:30:49Z", + "modified": "2025-01-09T21:31:29Z", "published": "2025-01-08T18:30:49Z", "aliases": [ "CVE-2024-56782" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nACPI: x86: Add adev NULL check to acpi_quirk_skip_serdev_enumeration()\n\nacpi_dev_hid_match() does not check for adev == NULL, dereferencing\nit unconditional.\n\nAdd a check for adev being NULL before calling acpi_dev_hid_match().\n\nAt the moment acpi_quirk_skip_serdev_enumeration() is never called with\na controller_parent without an ACPI companion, but better safe than sorry.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-08T18:15:19Z" diff --git a/advisories/unreviewed/2025/01/GHSA-f56q-8frx-6rwq/GHSA-f56q-8frx-6rwq.json b/advisories/unreviewed/2025/01/GHSA-f56q-8frx-6rwq/GHSA-f56q-8frx-6rwq.json new file mode 100644 index 00000000000..4695cd32737 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-f56q-8frx-6rwq/GHSA-f56q-8frx-6rwq.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f56q-8frx-6rwq", + "modified": "2025-01-09T21:31:32Z", + "published": "2025-01-09T21:31:32Z", + "aliases": [ + "CVE-2024-13303" + ], + "details": "Missing Authorization vulnerability in Drupal Download All Files allows Forceful Browsing.This issue affects Download All Files: from 0.0.0 before 2.0.2.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13303" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-069" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T21:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-f6f8-8wvp-pj55/GHSA-f6f8-8wvp-pj55.json b/advisories/unreviewed/2025/01/GHSA-f6f8-8wvp-pj55/GHSA-f6f8-8wvp-pj55.json index 56fad95e06c..f80f2667cc7 100644 --- a/advisories/unreviewed/2025/01/GHSA-f6f8-8wvp-pj55/GHSA-f6f8-8wvp-pj55.json +++ b/advisories/unreviewed/2025/01/GHSA-f6f8-8wvp-pj55/GHSA-f6f8-8wvp-pj55.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f6f8-8wvp-pj55", - "modified": "2025-01-09T09:31:42Z", + "modified": "2025-01-09T21:31:29Z", "published": "2025-01-09T09:31:42Z", "aliases": [ "CVE-2024-12806" ], "details": "A post-authentication absolute path traversal vulnerability in SonicOS management allows a remote attacker to read an arbitrary file.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-37" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-09T08:15:26Z" diff --git a/advisories/unreviewed/2025/01/GHSA-f6r6-892j-cp9p/GHSA-f6r6-892j-cp9p.json b/advisories/unreviewed/2025/01/GHSA-f6r6-892j-cp9p/GHSA-f6r6-892j-cp9p.json new file mode 100644 index 00000000000..b88bf25c7f9 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-f6r6-892j-cp9p/GHSA-f6r6-892j-cp9p.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f6r6-892j-cp9p", + "modified": "2025-01-09T21:31:32Z", + "published": "2025-01-09T21:31:32Z", + "aliases": [ + "CVE-2024-13301" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal OAuth & OpenID Connect Single Sign On – SSO (OAuth/OIDC Client) allows Cross-Site Scripting (XSS).This issue affects OAuth & OpenID Connect Single Sign On – SSO (OAuth/OIDC Client): from 3.0.0 before 3.44.0, from 4.0.0 before 4.0.19.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13301" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-067" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T21:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-f8q3-gfv7-h449/GHSA-f8q3-gfv7-h449.json b/advisories/unreviewed/2025/01/GHSA-f8q3-gfv7-h449/GHSA-f8q3-gfv7-h449.json new file mode 100644 index 00000000000..e044aea592d --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-f8q3-gfv7-h449/GHSA-f8q3-gfv7-h449.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f8q3-gfv7-h449", + "modified": "2025-01-09T21:31:30Z", + "published": "2025-01-09T21:31:30Z", + "aliases": [ + "CVE-2024-13252" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal TacJS allows Cross-Site Scripting (XSS).This issue affects TacJS: from 0.0.0 before 6.5.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13252" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-016" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T19:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-fjgg-qw2x-496w/GHSA-fjgg-qw2x-496w.json b/advisories/unreviewed/2025/01/GHSA-fjgg-qw2x-496w/GHSA-fjgg-qw2x-496w.json new file mode 100644 index 00000000000..e8f3d530899 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-fjgg-qw2x-496w/GHSA-fjgg-qw2x-496w.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fjgg-qw2x-496w", + "modified": "2025-01-09T21:31:31Z", + "published": "2025-01-09T21:31:31Z", + "aliases": [ + "CVE-2024-13282" + ], + "details": "Incorrect Authorization vulnerability in Drupal Block permissions allows Forceful Browsing.This issue affects Block permissions: from 1.0.0 before 1.2.0.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13282" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-046" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T20:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-fr2h-74vh-mp7c/GHSA-fr2h-74vh-mp7c.json b/advisories/unreviewed/2025/01/GHSA-fr2h-74vh-mp7c/GHSA-fr2h-74vh-mp7c.json new file mode 100644 index 00000000000..4ecbf5b759b --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-fr2h-74vh-mp7c/GHSA-fr2h-74vh-mp7c.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fr2h-74vh-mp7c", + "modified": "2025-01-09T21:31:32Z", + "published": "2025-01-09T21:31:32Z", + "aliases": [ + "CVE-2024-13299" + ], + "details": "Vulnerability in Drupal Megamenu Framework.This issue affects Megamenu Framework: *.*.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13299" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-065" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T21:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-g5hj-6p24-45c3/GHSA-g5hj-6p24-45c3.json b/advisories/unreviewed/2025/01/GHSA-g5hj-6p24-45c3/GHSA-g5hj-6p24-45c3.json new file mode 100644 index 00000000000..a4a7fac997b --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-g5hj-6p24-45c3/GHSA-g5hj-6p24-45c3.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g5hj-6p24-45c3", + "modified": "2025-01-09T21:31:31Z", + "published": "2025-01-09T21:31:31Z", + "aliases": [ + "CVE-2024-56114" + ], + "details": "Canlineapp Online 1.1 is vulnerable to Broken Access Control and allows users with the Auditor role to create an audit template as a result of improper authorization checks. This feature is designated for supervisor role, but auditors have been able to successfully create audit templates from their account.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56114" + }, + { + "type": "WEB", + "url": "https://github.com/Henkel-CyberVM/CVEs/tree/main/CVE-2024-56114" + }, + { + "type": "WEB", + "url": "https://www.e-connectsolutions.com" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T20:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-g5x8-v2ch-gj2g/GHSA-g5x8-v2ch-gj2g.json b/advisories/unreviewed/2025/01/GHSA-g5x8-v2ch-gj2g/GHSA-g5x8-v2ch-gj2g.json new file mode 100644 index 00000000000..f47a04bcdd9 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-g5x8-v2ch-gj2g/GHSA-g5x8-v2ch-gj2g.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g5x8-v2ch-gj2g", + "modified": "2025-01-09T21:31:32Z", + "published": "2025-01-09T21:31:32Z", + "aliases": [ + "CVE-2024-55224" + ], + "details": "An HTML injection vulnerability in Vaultwarden prior to v1.32.5 allows attackers to execute arbitrary code via injecting a crafted payload into the username field of an e-mail message.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55224" + }, + { + "type": "WEB", + "url": "https://github.com/dani-garcia/vaultwarden/releases/tag/1.32.4" + }, + { + "type": "WEB", + "url": "https://github.com/dani-garcia/vaultwarden/releases/tag/1.32.5" + }, + { + "type": "WEB", + "url": "https://insinuator.net/2024/11/vulnerability-disclosure-authentication-bypass-in-vaultwarden-versions-1-32-5" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T21:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-g6xh-8j45-qj24/GHSA-g6xh-8j45-qj24.json b/advisories/unreviewed/2025/01/GHSA-g6xh-8j45-qj24/GHSA-g6xh-8j45-qj24.json new file mode 100644 index 00000000000..53317d68488 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-g6xh-8j45-qj24/GHSA-g6xh-8j45-qj24.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g6xh-8j45-qj24", + "modified": "2025-01-09T21:31:32Z", + "published": "2025-01-09T21:31:32Z", + "aliases": [ + "CVE-2024-13296" + ], + "details": "Deserialization of Untrusted Data vulnerability in Drupal Mailjet allows Object Injection.This issue affects Mailjet: from 0.0.0 before 4.0.1.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13296" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-062" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T21:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-g94w-vc32-h449/GHSA-g94w-vc32-h449.json b/advisories/unreviewed/2025/01/GHSA-g94w-vc32-h449/GHSA-g94w-vc32-h449.json new file mode 100644 index 00000000000..a308f572379 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-g94w-vc32-h449/GHSA-g94w-vc32-h449.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g94w-vc32-h449", + "modified": "2025-01-09T21:31:31Z", + "published": "2025-01-09T21:31:31Z", + "aliases": [ + "CVE-2024-13272" + ], + "details": "Insufficient Granularity of Access Control vulnerability in Drupal Paragraphs table allows Content Spoofing.This issue affects Paragraphs table: from 0.0.0 before 1.23.0, from 2.0.0 before 2.0.2.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13272" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-036" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1220" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T20:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-g9m6-gvqr-98xq/GHSA-g9m6-gvqr-98xq.json b/advisories/unreviewed/2025/01/GHSA-g9m6-gvqr-98xq/GHSA-g9m6-gvqr-98xq.json new file mode 100644 index 00000000000..a5996fe4c93 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-g9m6-gvqr-98xq/GHSA-g9m6-gvqr-98xq.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g9m6-gvqr-98xq", + "modified": "2025-01-09T21:31:31Z", + "published": "2025-01-09T21:31:31Z", + "aliases": [ + "CVE-2024-56113" + ], + "details": "Smart Toilet Lab - Motius 1.3.11 is running with debug mode turned on (DEBUG = True) and exposing sensitive information defined in Django settings file through verbose error page.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56113" + }, + { + "type": "WEB", + "url": "https://github.com/Henkel-CyberVM/CVEs/tree/main/CVE-2024-56113" + }, + { + "type": "WEB", + "url": "https://smarttoilet.pratt.duke.edu" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T20:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-g9ph-4g63-c54q/GHSA-g9ph-4g63-c54q.json b/advisories/unreviewed/2025/01/GHSA-g9ph-4g63-c54q/GHSA-g9ph-4g63-c54q.json new file mode 100644 index 00000000000..bd582cebb35 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-g9ph-4g63-c54q/GHSA-g9ph-4g63-c54q.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g9ph-4g63-c54q", + "modified": "2025-01-09T21:31:31Z", + "published": "2025-01-09T21:31:31Z", + "aliases": [ + "CVE-2024-13268" + ], + "details": "Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno allows PHP Local File Inclusion.This issue affects Opigno: from 7.X-1.0 before 7.X-1.23.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13268" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-032" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-96" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T20:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-gpgg-3g65-72cm/GHSA-gpgg-3g65-72cm.json b/advisories/unreviewed/2025/01/GHSA-gpgg-3g65-72cm/GHSA-gpgg-3g65-72cm.json new file mode 100644 index 00000000000..658c2812b31 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-gpgg-3g65-72cm/GHSA-gpgg-3g65-72cm.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gpgg-3g65-72cm", + "modified": "2025-01-09T21:31:31Z", + "published": "2025-01-09T21:31:31Z", + "aliases": [ + "CVE-2024-13267" + ], + "details": "Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability in Drupal Opigno TinCan Question Type allows PHP Local File Inclusion.This issue affects Opigno TinCan Question Type: from 7.X-1.0 before 7.X-1.3.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13267" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-031" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-96" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T20:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-gqf5-wjqv-v83c/GHSA-gqf5-wjqv-v83c.json b/advisories/unreviewed/2025/01/GHSA-gqf5-wjqv-v83c/GHSA-gqf5-wjqv-v83c.json new file mode 100644 index 00000000000..2909fe7ec30 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-gqf5-wjqv-v83c/GHSA-gqf5-wjqv-v83c.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gqf5-wjqv-v83c", + "modified": "2025-01-09T21:31:29Z", + "published": "2025-01-09T21:31:29Z", + "aliases": [ + "CVE-2024-13239" + ], + "details": "Weak Authentication vulnerability in Drupal Two-factor Authentication (TFA) allows Authentication Abuse.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.5.0.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13239" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-003" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1390" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T19:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-h6w8-m65g-549g/GHSA-h6w8-m65g-549g.json b/advisories/unreviewed/2025/01/GHSA-h6w8-m65g-549g/GHSA-h6w8-m65g-549g.json new file mode 100644 index 00000000000..0a0bf2214d6 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-h6w8-m65g-549g/GHSA-h6w8-m65g-549g.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h6w8-m65g-549g", + "modified": "2025-01-09T21:31:31Z", + "published": "2025-01-09T21:31:31Z", + "aliases": [ + "CVE-2024-13279" + ], + "details": "Session Fixation vulnerability in Drupal Two-factor Authentication (TFA) allows Session Fixation.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.8.0.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13279" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-043" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-384" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T20:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-h874-6j2r-6vjv/GHSA-h874-6j2r-6vjv.json b/advisories/unreviewed/2025/01/GHSA-h874-6j2r-6vjv/GHSA-h874-6j2r-6vjv.json new file mode 100644 index 00000000000..7a2094591ea --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-h874-6j2r-6vjv/GHSA-h874-6j2r-6vjv.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h874-6j2r-6vjv", + "modified": "2025-01-09T21:31:31Z", + "published": "2025-01-09T21:31:31Z", + "aliases": [ + "CVE-2024-54724" + ], + "details": "PHPYun before 7.0.2 is vulnerable to code execution through backdoor-restricted arbitrary file writing and file inclusion.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54724" + }, + { + "type": "WEB", + "url": "https://github.com/la12138la/detail/blob/main/1.md" + }, + { + "type": "WEB", + "url": "http://phpyun.com" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T20:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-h8j9-776h-g7wr/GHSA-h8j9-776h-g7wr.json b/advisories/unreviewed/2025/01/GHSA-h8j9-776h-g7wr/GHSA-h8j9-776h-g7wr.json new file mode 100644 index 00000000000..3c582fa3fc1 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-h8j9-776h-g7wr/GHSA-h8j9-776h-g7wr.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h8j9-776h-g7wr", + "modified": "2025-01-09T21:31:29Z", + "published": "2025-01-09T21:31:29Z", + "aliases": [ + "CVE-2024-13240" + ], + "details": "Improper Access Control vulnerability in Drupal Open Social allows Collect Data from Common Resource Locations.This issue affects Open Social: from 0.0.0 before 12.05.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13240" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-004" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T19:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-hff4-c3wj-g3xx/GHSA-hff4-c3wj-g3xx.json b/advisories/unreviewed/2025/01/GHSA-hff4-c3wj-g3xx/GHSA-hff4-c3wj-g3xx.json new file mode 100644 index 00000000000..13854791b2e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-hff4-c3wj-g3xx/GHSA-hff4-c3wj-g3xx.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hff4-c3wj-g3xx", + "modified": "2025-01-09T21:31:30Z", + "published": "2025-01-09T21:31:30Z", + "aliases": [ + "CVE-2024-13249" + ], + "details": "Improper Ownership Management vulnerability in Drupal Node Access Rebuild Progressive allows Target Influence via Framing.This issue affects Node Access Rebuild Progressive: from 7.X-1.0 before 7.X-1.2.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13249" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-013" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-282" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T19:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-hqjc-qgf5-4m63/GHSA-hqjc-qgf5-4m63.json b/advisories/unreviewed/2025/01/GHSA-hqjc-qgf5-4m63/GHSA-hqjc-qgf5-4m63.json new file mode 100644 index 00000000000..35703475fb8 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-hqjc-qgf5-4m63/GHSA-hqjc-qgf5-4m63.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hqjc-qgf5-4m63", + "modified": "2025-01-09T21:31:29Z", + "published": "2025-01-09T21:31:29Z", + "aliases": [ + "CVE-2024-13242" + ], + "details": "Exposed Dangerous Method or Function vulnerability in Drupal Swift Mailer allows Resource Location Spoofing.This issue affects Swift Mailer: *.*.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13242" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-006" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-749" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T19:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-hwc6-hhj2-hp24/GHSA-hwc6-hhj2-hp24.json b/advisories/unreviewed/2025/01/GHSA-hwc6-hhj2-hp24/GHSA-hwc6-hhj2-hp24.json new file mode 100644 index 00000000000..bf8e1036c41 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-hwc6-hhj2-hp24/GHSA-hwc6-hhj2-hp24.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hwc6-hhj2-hp24", + "modified": "2025-01-09T21:31:31Z", + "published": "2025-01-09T21:31:31Z", + "aliases": [ + "CVE-2024-13286" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal SVG Embed allows Cross-Site Scripting (XSS).This issue affects SVG Embed: from 0.0.0 before 2.1.2.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13286" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-050" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T20:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-j3fj-gjrj-c97q/GHSA-j3fj-gjrj-c97q.json b/advisories/unreviewed/2025/01/GHSA-j3fj-gjrj-c97q/GHSA-j3fj-gjrj-c97q.json index 404c4c5ecd3..a7d021a8eab 100644 --- a/advisories/unreviewed/2025/01/GHSA-j3fj-gjrj-c97q/GHSA-j3fj-gjrj-c97q.json +++ b/advisories/unreviewed/2025/01/GHSA-j3fj-gjrj-c97q/GHSA-j3fj-gjrj-c97q.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-j3fj-gjrj-c97q", - "modified": "2025-01-08T18:30:49Z", + "modified": "2025-01-09T21:31:29Z", "published": "2025-01-08T18:30:49Z", "aliases": [ "CVE-2024-56784" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Adding array index check to prevent memory corruption\n\n[Why & How]\nArray indices out of bound caused memory corruption. Adding checks to\nensure that array index stays in bound.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-08T18:15:19Z" diff --git a/advisories/unreviewed/2025/01/GHSA-j6c4-8pwx-h3g3/GHSA-j6c4-8pwx-h3g3.json b/advisories/unreviewed/2025/01/GHSA-j6c4-8pwx-h3g3/GHSA-j6c4-8pwx-h3g3.json new file mode 100644 index 00000000000..c2c96944db6 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-j6c4-8pwx-h3g3/GHSA-j6c4-8pwx-h3g3.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j6c4-8pwx-h3g3", + "modified": "2025-01-09T21:31:30Z", + "published": "2025-01-09T21:31:30Z", + "aliases": [ + "CVE-2024-13244" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Drupal Migrate Tools allows Cross Site Request Forgery.This issue affects Migrate Tools: from 0.0.0 before 6.0.3.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13244" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-008" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T19:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-j7cg-x2c3-v6hf/GHSA-j7cg-x2c3-v6hf.json b/advisories/unreviewed/2025/01/GHSA-j7cg-x2c3-v6hf/GHSA-j7cg-x2c3-v6hf.json new file mode 100644 index 00000000000..a02fe1f843c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-j7cg-x2c3-v6hf/GHSA-j7cg-x2c3-v6hf.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j7cg-x2c3-v6hf", + "modified": "2025-01-09T21:31:31Z", + "published": "2025-01-09T21:31:31Z", + "aliases": [ + "CVE-2024-13291" + ], + "details": "Incorrect Authorization vulnerability in Drupal Basic HTTP Authentication allows Forceful Browsing.This issue affects Basic HTTP Authentication: from 7.X-1.0 before 7.X-1.4.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13291" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-057" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T21:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-jf66-v4fg-qpqx/GHSA-jf66-v4fg-qpqx.json b/advisories/unreviewed/2025/01/GHSA-jf66-v4fg-qpqx/GHSA-jf66-v4fg-qpqx.json new file mode 100644 index 00000000000..4f816f9deb8 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-jf66-v4fg-qpqx/GHSA-jf66-v4fg-qpqx.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jf66-v4fg-qpqx", + "modified": "2025-01-09T21:31:30Z", + "published": "2025-01-09T21:31:30Z", + "aliases": [ + "CVE-2024-13255" + ], + "details": "Exposure of Sensitive Information Through Data Queries vulnerability in Drupal RESTful Web Services allows Forceful Browsing.This issue affects RESTful Web Services: from 7.X-2.0 before 7.X-2.10.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13255" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-019" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-202" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T19:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-jffw-3h47-42r7/GHSA-jffw-3h47-42r7.json b/advisories/unreviewed/2025/01/GHSA-jffw-3h47-42r7/GHSA-jffw-3h47-42r7.json new file mode 100644 index 00000000000..b53d65609ff --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-jffw-3h47-42r7/GHSA-jffw-3h47-42r7.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jffw-3h47-42r7", + "modified": "2025-01-09T21:31:31Z", + "published": "2025-01-09T21:31:31Z", + "aliases": [ + "CVE-2024-54762" + ], + "details": "Ruoyi v.4.7.9 and before contains an authenticated SQL injection vulnerability. This is because the filterKeyword method does not completely filter SQL injection keywords, resulting in the risk of SQL injection.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54762" + }, + { + "type": "WEB", + "url": "https://github.com/yangzongzhuan/RuoYi" + }, + { + "type": "WEB", + "url": "https://locrian-lightning-dc7.notion.site/CVE-2024-54762-1748e5e2b1a280b4a549dcce2c4823e8" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T20:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-jjvf-4cxj-rqv4/GHSA-jjvf-4cxj-rqv4.json b/advisories/unreviewed/2025/01/GHSA-jjvf-4cxj-rqv4/GHSA-jjvf-4cxj-rqv4.json new file mode 100644 index 00000000000..6df96892366 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-jjvf-4cxj-rqv4/GHSA-jjvf-4cxj-rqv4.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jjvf-4cxj-rqv4", + "modified": "2025-01-09T21:31:31Z", + "published": "2025-01-09T21:31:31Z", + "aliases": [ + "CVE-2024-13275" + ], + "details": "Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Drupal Security Kit allows HTTP DoS.This issue affects Security Kit: from 0.0.0 before 2.0.3.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13275" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-039" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-843" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T20:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-jrrh-q8c6-fqg3/GHSA-jrrh-q8c6-fqg3.json b/advisories/unreviewed/2025/01/GHSA-jrrh-q8c6-fqg3/GHSA-jrrh-q8c6-fqg3.json new file mode 100644 index 00000000000..e359e42b22e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-jrrh-q8c6-fqg3/GHSA-jrrh-q8c6-fqg3.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jrrh-q8c6-fqg3", + "modified": "2025-01-09T21:31:31Z", + "published": "2025-01-09T21:31:31Z", + "aliases": [ + "CVE-2024-13288" + ], + "details": "Deserialization of Untrusted Data vulnerability in Drupal Monster Menus allows Object Injection.This issue affects Monster Menus: from 0.0.0 before 9.3.4, from 9.4.0 before 9.4.2.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13288" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-052" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T21:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-jv4w-6wrf-3p5g/GHSA-jv4w-6wrf-3p5g.json b/advisories/unreviewed/2025/01/GHSA-jv4w-6wrf-3p5g/GHSA-jv4w-6wrf-3p5g.json new file mode 100644 index 00000000000..3e22f29b34a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-jv4w-6wrf-3p5g/GHSA-jv4w-6wrf-3p5g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jv4w-6wrf-3p5g", + "modified": "2025-01-09T21:31:31Z", + "published": "2025-01-09T21:31:31Z", + "aliases": [ + "CVE-2024-55494" + ], + "details": "A cross-site scripting (XSS) vulnerability in Opencode Mobile Collect Call v5.4.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the op_func parameter at /occontrolpanel/index.php.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55494" + }, + { + "type": "WEB", + "url": "https://github.com/hassan-mohammed/security-findings/tree/main/CVEs/CVE-2024-55494" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T20:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-m39j-xxh8-gc7w/GHSA-m39j-xxh8-gc7w.json b/advisories/unreviewed/2025/01/GHSA-m39j-xxh8-gc7w/GHSA-m39j-xxh8-gc7w.json new file mode 100644 index 00000000000..90f2e69b0bf --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-m39j-xxh8-gc7w/GHSA-m39j-xxh8-gc7w.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m39j-xxh8-gc7w", + "modified": "2025-01-09T21:31:32Z", + "published": "2025-01-09T21:31:32Z", + "aliases": [ + "CVE-2024-48806" + ], + "details": "Buffer Overflow vulnerability in Neat Board NFC v.1.20240620.0015 allows a physically proximate attackers to escalate privileges via a crafted payload to the password field", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48806" + }, + { + "type": "WEB", + "url": "https://support.neat.no/article/devices-running-microsoft-teams-allow-for-buffer-overflow-vulnerability" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T21:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-m53w-jm38-mh7q/GHSA-m53w-jm38-mh7q.json b/advisories/unreviewed/2025/01/GHSA-m53w-jm38-mh7q/GHSA-m53w-jm38-mh7q.json new file mode 100644 index 00000000000..b20c5c76661 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-m53w-jm38-mh7q/GHSA-m53w-jm38-mh7q.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m53w-jm38-mh7q", + "modified": "2025-01-09T21:31:30Z", + "published": "2025-01-09T21:31:30Z", + "aliases": [ + "CVE-2024-13243" + ], + "details": "Missing Authorization vulnerability in Drupal Entity Delete Log allows Forceful Browsing.This issue affects Entity Delete Log: from 0.0.0 before 1.1.1.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13243" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-007" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T19:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-m6c8-mv97-5jcm/GHSA-m6c8-mv97-5jcm.json b/advisories/unreviewed/2025/01/GHSA-m6c8-mv97-5jcm/GHSA-m6c8-mv97-5jcm.json index bf40b5800eb..e63ebbe6ac0 100644 --- a/advisories/unreviewed/2025/01/GHSA-m6c8-mv97-5jcm/GHSA-m6c8-mv97-5jcm.json +++ b/advisories/unreviewed/2025/01/GHSA-m6c8-mv97-5jcm/GHSA-m6c8-mv97-5jcm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-m6c8-mv97-5jcm", - "modified": "2025-01-08T18:30:49Z", + "modified": "2025-01-09T21:31:29Z", "published": "2025-01-08T18:30:49Z", "aliases": [ "CVE-2024-56787" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsoc: imx8m: Probe the SoC driver as platform driver\n\nWith driver_async_probe=* on kernel command line, the following trace is\nproduced because on i.MX8M Plus hardware because the soc-imx8m.c driver\ncalls of_clk_get_by_name() which returns -EPROBE_DEFER because the clock\ndriver is not yet probed. This was not detected during regular testing\nwithout driver_async_probe.\n\nConvert the SoC code to platform driver and instantiate a platform device\nin its current device_initcall() to probe the platform driver. Rework\n.soc_revision callback to always return valid error code and return SoC\nrevision via parameter. This way, if anything in the .soc_revision callback\nreturn -EPROBE_DEFER, it gets propagated to .probe and the .probe will get\nretried later.\n\n\"\n------------[ cut here ]------------\nWARNING: CPU: 1 PID: 1 at drivers/soc/imx/soc-imx8m.c:115 imx8mm_soc_revision+0xdc/0x180\nCPU: 1 UID: 0 PID: 1 Comm: swapper/0 Not tainted 6.11.0-next-20240924-00002-g2062bb554dea #603\nHardware name: DH electronics i.MX8M Plus DHCOM Premium Developer Kit (3) (DT)\npstate: 20000005 (nzCv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)\npc : imx8mm_soc_revision+0xdc/0x180\nlr : imx8mm_soc_revision+0xd0/0x180\nsp : ffff8000821fbcc0\nx29: ffff8000821fbce0 x28: 0000000000000000 x27: ffff800081810120\nx26: ffff8000818a9970 x25: 0000000000000006 x24: 0000000000824311\nx23: ffff8000817f42c8 x22: ffff0000df8be210 x21: fffffffffffffdfb\nx20: ffff800082780000 x19: 0000000000000001 x18: ffffffffffffffff\nx17: ffff800081fff418 x16: ffff8000823e1000 x15: ffff0000c03b65e8\nx14: ffff0000c00051b0 x13: ffff800082790000 x12: 0000000000000801\nx11: ffff80008278ffff x10: ffff80008209d3a6 x9 : ffff80008062e95c\nx8 : ffff8000821fb9a0 x7 : 0000000000000000 x6 : 00000000000080e3\nx5 : ffff0000df8c03d8 x4 : 0000000000000000 x3 : 0000000000000000\nx2 : 0000000000000000 x1 : fffffffffffffdfb x0 : fffffffffffffdfb\nCall trace:\n imx8mm_soc_revision+0xdc/0x180\n imx8_soc_init+0xb0/0x1e0\n do_one_initcall+0x94/0x1a8\n kernel_init_freeable+0x240/0x2a8\n kernel_init+0x28/0x140\n ret_from_fork+0x10/0x20\n---[ end trace 0000000000000000 ]---\nSoC: i.MX8MP revision 1.1\n\"", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -37,7 +42,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-08T18:15:19Z" diff --git a/advisories/unreviewed/2025/01/GHSA-m8j3-m4jx-2rhw/GHSA-m8j3-m4jx-2rhw.json b/advisories/unreviewed/2025/01/GHSA-m8j3-m4jx-2rhw/GHSA-m8j3-m4jx-2rhw.json new file mode 100644 index 00000000000..d1c5d2ae831 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-m8j3-m4jx-2rhw/GHSA-m8j3-m4jx-2rhw.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m8j3-m4jx-2rhw", + "modified": "2025-01-09T21:31:31Z", + "published": "2025-01-09T21:31:31Z", + "aliases": [ + "CVE-2024-13266" + ], + "details": "Incorrect Authorization vulnerability in Drupal Responsive and off-canvas menu allows Forceful Browsing.This issue affects Responsive and off-canvas menu: from 0.0.0 before 4.4.4.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13266" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-030" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T20:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-m8wx-qw6g-2vhr/GHSA-m8wx-qw6g-2vhr.json b/advisories/unreviewed/2025/01/GHSA-m8wx-qw6g-2vhr/GHSA-m8wx-qw6g-2vhr.json new file mode 100644 index 00000000000..558eddf0a80 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-m8wx-qw6g-2vhr/GHSA-m8wx-qw6g-2vhr.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m8wx-qw6g-2vhr", + "modified": "2025-01-09T21:31:31Z", + "published": "2025-01-09T21:31:31Z", + "aliases": [ + "CVE-2024-13277" + ], + "details": "Incorrect Authorization vulnerability in Drupal Smart IP Ban allows Forceful Browsing.This issue affects Smart IP Ban: from 7.X-1.0 before 7.X-1.1.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13277" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-041" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T20:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-mxgx-9cvp-m653/GHSA-mxgx-9cvp-m653.json b/advisories/unreviewed/2025/01/GHSA-mxgx-9cvp-m653/GHSA-mxgx-9cvp-m653.json new file mode 100644 index 00000000000..6e374c33575 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-mxgx-9cvp-m653/GHSA-mxgx-9cvp-m653.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mxgx-9cvp-m653", + "modified": "2025-01-09T21:31:31Z", + "published": "2025-01-09T21:31:31Z", + "aliases": [ + "CVE-2024-13290" + ], + "details": "Incorrect Authorization vulnerability in Drupal OhDear Integration allows Forceful Browsing.This issue affects OhDear Integration: from 0.0.0 before 2.0.4.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13290" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-056" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T21:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-p27g-6xm5-rqrf/GHSA-p27g-6xm5-rqrf.json b/advisories/unreviewed/2025/01/GHSA-p27g-6xm5-rqrf/GHSA-p27g-6xm5-rqrf.json new file mode 100644 index 00000000000..a9a3d4011af --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-p27g-6xm5-rqrf/GHSA-p27g-6xm5-rqrf.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p27g-6xm5-rqrf", + "modified": "2025-01-09T21:31:31Z", + "published": "2025-01-09T21:31:31Z", + "aliases": [ + "CVE-2024-13269" + ], + "details": "Insertion of Sensitive Information Into Sent Data vulnerability in Drupal Advanced Varnish allows Forceful Browsing.This issue affects Advanced Varnish: from 0.0.0 before 4.0.11.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13269" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-033" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-201" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T20:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-p3gg-w5rj-m5rv/GHSA-p3gg-w5rj-m5rv.json b/advisories/unreviewed/2025/01/GHSA-p3gg-w5rj-m5rv/GHSA-p3gg-w5rj-m5rv.json new file mode 100644 index 00000000000..fde196a88a7 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-p3gg-w5rj-m5rv/GHSA-p3gg-w5rj-m5rv.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p3gg-w5rj-m5rv", + "modified": "2025-01-09T21:31:32Z", + "published": "2025-01-09T21:31:32Z", + "aliases": [ + "CVE-2024-13312" + ], + "details": "Missing Authorization vulnerability in Drupal Open Social allows Forceful Browsing.This issue affects Open Social: from 11.8.0 before 12.3.10, from 12.4.0 before 12.4.9.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13312" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-076" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T21:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-p3jr-34v8-m9x2/GHSA-p3jr-34v8-m9x2.json b/advisories/unreviewed/2025/01/GHSA-p3jr-34v8-m9x2/GHSA-p3jr-34v8-m9x2.json new file mode 100644 index 00000000000..ad47888effd --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-p3jr-34v8-m9x2/GHSA-p3jr-34v8-m9x2.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p3jr-34v8-m9x2", + "modified": "2025-01-09T21:31:31Z", + "published": "2025-01-09T21:31:31Z", + "aliases": [ + "CVE-2024-13260" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Drupal Migrate queue importer allows Cross Site Request Forgery.This issue affects Migrate queue importer: from 0.0.0 before 2.1.1.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13260" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-024" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T20:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-p4cr-4mjx-v45f/GHSA-p4cr-4mjx-v45f.json b/advisories/unreviewed/2025/01/GHSA-p4cr-4mjx-v45f/GHSA-p4cr-4mjx-v45f.json new file mode 100644 index 00000000000..f7b6f587af6 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-p4cr-4mjx-v45f/GHSA-p4cr-4mjx-v45f.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p4cr-4mjx-v45f", + "modified": "2025-01-09T21:31:31Z", + "published": "2025-01-09T21:31:31Z", + "aliases": [ + "CVE-2024-46505" + ], + "details": "Infoblox BloxOne v2.4 was discovered to contain a business logic flaw due to thick client vulnerabilities.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46505" + }, + { + "type": "WEB", + "url": "https://jayaramyalla.medium.com/bloxone-business-logic-flaw-due-to-thick-client-vulnerabilities-cve-2024-46505-04a4f1966f4b" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T20:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-p77c-g2ff-r9hf/GHSA-p77c-g2ff-r9hf.json b/advisories/unreviewed/2025/01/GHSA-p77c-g2ff-r9hf/GHSA-p77c-g2ff-r9hf.json new file mode 100644 index 00000000000..7a9d103f955 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-p77c-g2ff-r9hf/GHSA-p77c-g2ff-r9hf.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p77c-g2ff-r9hf", + "modified": "2025-01-09T21:31:32Z", + "published": "2025-01-09T21:31:31Z", + "aliases": [ + "CVE-2024-13293" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Drupal POST File allows Cross Site Request Forgery.This issue affects POST File: from 0.0.0 before 1.0.2.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13293" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-059" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T21:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-p9jg-5w2m-vgg8/GHSA-p9jg-5w2m-vgg8.json b/advisories/unreviewed/2025/01/GHSA-p9jg-5w2m-vgg8/GHSA-p9jg-5w2m-vgg8.json new file mode 100644 index 00000000000..e926f006e47 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-p9jg-5w2m-vgg8/GHSA-p9jg-5w2m-vgg8.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p9jg-5w2m-vgg8", + "modified": "2025-01-09T21:31:32Z", + "published": "2025-01-09T21:31:32Z", + "aliases": [ + "CVE-2024-13309" + ], + "details": "Improper Authentication vulnerability in Drupal Login Disable allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Login Disable: from 2.0.0 before 2.1.1.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13309" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-073" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T21:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-phf7-cpqm-749x/GHSA-phf7-cpqm-749x.json b/advisories/unreviewed/2025/01/GHSA-phf7-cpqm-749x/GHSA-phf7-cpqm-749x.json index e983e194582..a2d90e2daa3 100644 --- a/advisories/unreviewed/2025/01/GHSA-phf7-cpqm-749x/GHSA-phf7-cpqm-749x.json +++ b/advisories/unreviewed/2025/01/GHSA-phf7-cpqm-749x/GHSA-phf7-cpqm-749x.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-phf7-cpqm-749x", - "modified": "2025-01-08T18:30:48Z", + "modified": "2025-01-09T21:31:29Z", "published": "2025-01-08T18:30:48Z", "aliases": [ "CVE-2024-56774" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: add a sanity check for btrfs root in btrfs_search_slot()\n\nSyzbot reports a null-ptr-deref in btrfs_search_slot().\n\nThe reproducer is using rescue=ibadroots, and the extent tree root is\ncorrupted thus the extent tree is NULL.\n\nWhen scrub tries to search the extent tree to gather the needed extent\ninfo, btrfs_search_slot() doesn't check if the target root is NULL or\nnot, resulting the null-ptr-deref.\n\nAdd sanity check for btrfs root before using it in btrfs_search_slot().", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-08T18:15:18Z" diff --git a/advisories/unreviewed/2025/01/GHSA-qf55-97mm-vqcj/GHSA-qf55-97mm-vqcj.json b/advisories/unreviewed/2025/01/GHSA-qf55-97mm-vqcj/GHSA-qf55-97mm-vqcj.json new file mode 100644 index 00000000000..ac25d7130c5 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-qf55-97mm-vqcj/GHSA-qf55-97mm-vqcj.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qf55-97mm-vqcj", + "modified": "2025-01-09T21:31:31Z", + "published": "2025-01-09T21:31:31Z", + "aliases": [ + "CVE-2024-54887" + ], + "details": "TP-Link TL-WR940N V3 and V4 with firmware 3.16.9 and earlier contain a buffer overflow via the dnsserver1 and dnsserver2 parameters at /userRpm/Wan6to4TunnelCfgRpm.htm. This vulnerability allows an authenticated attacker to execute arbitrary code on the remote device in the context of the root user.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54887" + }, + { + "type": "WEB", + "url": "https://github.com/JBince/vulnerability-research/tree/main/CVE-2024-54887" + }, + { + "type": "WEB", + "url": "http://tp-link.com" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T20:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-qffj-hqp2-qrxm/GHSA-qffj-hqp2-qrxm.json b/advisories/unreviewed/2025/01/GHSA-qffj-hqp2-qrxm/GHSA-qffj-hqp2-qrxm.json new file mode 100644 index 00000000000..9bae9834b2e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-qffj-hqp2-qrxm/GHSA-qffj-hqp2-qrxm.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qffj-hqp2-qrxm", + "modified": "2025-01-09T21:31:30Z", + "published": "2025-01-09T21:31:30Z", + "aliases": [ + "CVE-2024-13259" + ], + "details": "Insertion of Sensitive Information Into Sent Data vulnerability in Drupal Image Sizes allows Forceful Browsing.This issue affects Image Sizes: from 0.0.0 before 3.0.2.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13259" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-023" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-201" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T19:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-r66p-qgmm-6967/GHSA-r66p-qgmm-6967.json b/advisories/unreviewed/2025/01/GHSA-r66p-qgmm-6967/GHSA-r66p-qgmm-6967.json new file mode 100644 index 00000000000..9133a3e12bd --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-r66p-qgmm-6967/GHSA-r66p-qgmm-6967.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r66p-qgmm-6967", + "modified": "2025-01-09T21:31:31Z", + "published": "2025-01-09T21:31:31Z", + "aliases": [ + "CVE-2024-13261" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Drupal Acquia DAM allows Cross Site Request Forgery.This issue affects Acquia DAM: from 0.0.0 before 1.0.13, from 1.1.0 before 1.1.0-beta3.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13261" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-025" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T20:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-rc33-rp5v-32v2/GHSA-rc33-rp5v-32v2.json b/advisories/unreviewed/2025/01/GHSA-rc33-rp5v-32v2/GHSA-rc33-rp5v-32v2.json new file mode 100644 index 00000000000..c06f1ad63fb --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-rc33-rp5v-32v2/GHSA-rc33-rp5v-32v2.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rc33-rp5v-32v2", + "modified": "2025-01-09T21:31:32Z", + "published": "2025-01-09T21:31:32Z", + "aliases": [ + "CVE-2024-13311" + ], + "details": "Vulnerability in Drupal Allow All File Extensions for file fields.This issue affects Allow All File Extensions for file fields: *.*.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13311" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-075" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T21:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-rj9h-wxr6-mwg8/GHSA-rj9h-wxr6-mwg8.json b/advisories/unreviewed/2025/01/GHSA-rj9h-wxr6-mwg8/GHSA-rj9h-wxr6-mwg8.json new file mode 100644 index 00000000000..396d14c20bb --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-rj9h-wxr6-mwg8/GHSA-rj9h-wxr6-mwg8.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rj9h-wxr6-mwg8", + "modified": "2025-01-09T21:31:32Z", + "published": "2025-01-09T21:31:32Z", + "aliases": [ + "CVE-2024-13297" + ], + "details": "Deserialization of Untrusted Data vulnerability in Drupal Eloqua allows Object Injection.This issue affects Eloqua: from 7.X-* before 7.X-1.15.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13297" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-063" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T21:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-v6xw-pf6j-mpfg/GHSA-v6xw-pf6j-mpfg.json b/advisories/unreviewed/2025/01/GHSA-v6xw-pf6j-mpfg/GHSA-v6xw-pf6j-mpfg.json index 51874c8f596..3051c4c1684 100644 --- a/advisories/unreviewed/2025/01/GHSA-v6xw-pf6j-mpfg/GHSA-v6xw-pf6j-mpfg.json +++ b/advisories/unreviewed/2025/01/GHSA-v6xw-pf6j-mpfg/GHSA-v6xw-pf6j-mpfg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-v6xw-pf6j-mpfg", - "modified": "2025-01-08T18:30:48Z", + "modified": "2025-01-09T21:31:29Z", "published": "2025-01-08T18:30:48Z", "aliases": [ "CVE-2024-56772" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nkunit: string-stream: Fix a UAF bug in kunit_init_suite()\n\nIn kunit_debugfs_create_suite(), if alloc_string_stream() fails in the\nkunit_suite_for_each_test_case() loop, the \"suite->log = stream\"\nhas assigned before, and the error path only free the suite->log's stream\nmemory but not set it to NULL, so the later string_stream_clear() of\nsuite->log in kunit_init_suite() will cause below UAF bug.\n\nSet stream pointer to NULL after free to fix it.\n\n\tUnable to handle kernel paging request at virtual address 006440150000030d\n\tMem abort info:\n\t ESR = 0x0000000096000004\n\t EC = 0x25: DABT (current EL), IL = 32 bits\n\t SET = 0, FnV = 0\n\t EA = 0, S1PTW = 0\n\t FSC = 0x04: level 0 translation fault\n\tData abort info:\n\t ISV = 0, ISS = 0x00000004, ISS2 = 0x00000000\n\t CM = 0, WnR = 0, TnD = 0, TagAccess = 0\n\t GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0\n\t[006440150000030d] address between user and kernel address ranges\n\tInternal error: Oops: 0000000096000004 [#1] PREEMPT SMP\n\tDumping ftrace buffer:\n\t (ftrace buffer empty)\n\tModules linked in: iio_test_gts industrialio_gts_helper cfg80211 rfkill ipv6 [last unloaded: iio_test_gts]\n\tCPU: 5 UID: 0 PID: 6253 Comm: modprobe Tainted: G B W N 6.12.0-rc4+ #458\n\tTainted: [B]=BAD_PAGE, [W]=WARN, [N]=TEST\n\tHardware name: linux,dummy-virt (DT)\n\tpstate: 40000005 (nZcv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n\tpc : string_stream_clear+0x54/0x1ac\n\tlr : string_stream_clear+0x1a8/0x1ac\n\tsp : ffffffc080b47410\n\tx29: ffffffc080b47410 x28: 006440550000030d x27: ffffff80c96b5e98\n\tx26: ffffff80c96b5e80 x25: ffffffe461b3f6c0 x24: 0000000000000003\n\tx23: ffffff80c96b5e88 x22: 1ffffff019cdf4fc x21: dfffffc000000000\n\tx20: ffffff80ce6fa7e0 x19: 032202a80000186d x18: 0000000000001840\n\tx17: 0000000000000000 x16: 0000000000000000 x15: ffffffe45c355cb4\n\tx14: ffffffe45c35589c x13: ffffffe45c03da78 x12: ffffffb810168e75\n\tx11: 1ffffff810168e74 x10: ffffffb810168e74 x9 : dfffffc000000000\n\tx8 : 0000000000000004 x7 : 0000000000000003 x6 : 0000000000000001\n\tx5 : ffffffc080b473a0 x4 : 0000000000000000 x3 : 0000000000000000\n\tx2 : 0000000000000001 x1 : ffffffe462fbf620 x0 : dfffffc000000000\n\tCall trace:\n\t string_stream_clear+0x54/0x1ac\n\t __kunit_test_suites_init+0x108/0x1d8\n\t kunit_exec_run_tests+0xb8/0x100\n\t kunit_module_notify+0x400/0x55c\n\t notifier_call_chain+0xfc/0x3b4\n\t blocking_notifier_call_chain+0x68/0x9c\n\t do_init_module+0x24c/0x5c8\n\t load_module+0x4acc/0x4e90\n\t init_module_from_file+0xd4/0x128\n\t idempotent_init_module+0x2d4/0x57c\n\t __arm64_sys_finit_module+0xac/0x100\n\t invoke_syscall+0x6c/0x258\n\t el0_svc_common.constprop.0+0x160/0x22c\n\t do_el0_svc+0x44/0x5c\n\t el0_svc+0x48/0xb8\n\t el0t_64_sync_handler+0x13c/0x158\n\t el0t_64_sync+0x190/0x194\n\tCode: f9400753 d2dff800 f2fbffe0 d343fe7c (38e06b80)\n\t---[ end trace 0000000000000000 ]---\n\tKernel panic - not syncing: Oops: Fatal exception", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-08T18:15:17Z" diff --git a/advisories/unreviewed/2025/01/GHSA-vm82-j6hv-2pfj/GHSA-vm82-j6hv-2pfj.json b/advisories/unreviewed/2025/01/GHSA-vm82-j6hv-2pfj/GHSA-vm82-j6hv-2pfj.json new file mode 100644 index 00000000000..1e7e08be37d --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-vm82-j6hv-2pfj/GHSA-vm82-j6hv-2pfj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vm82-j6hv-2pfj", + "modified": "2025-01-09T21:31:29Z", + "published": "2025-01-09T21:31:29Z", + "aliases": [ + "CVE-2024-13237" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal File Entity (fieldable files) allows Cross-Site Scripting (XSS).This issue affects File Entity (fieldable files): from 7.X-* before 7.X-2.38.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13237" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-001" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T19:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-vprm-27pv-jp3w/GHSA-vprm-27pv-jp3w.json b/advisories/unreviewed/2025/01/GHSA-vprm-27pv-jp3w/GHSA-vprm-27pv-jp3w.json new file mode 100644 index 00000000000..0f7e9d4f9f3 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-vprm-27pv-jp3w/GHSA-vprm-27pv-jp3w.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vprm-27pv-jp3w", + "modified": "2025-01-09T21:31:32Z", + "published": "2025-01-09T21:31:32Z", + "aliases": [ + "CVE-2024-55226" + ], + "details": "Vaultwarden v1.32.5 was discovered to contain an authenticated reflected cross-site scripting (XSS) vulnerability via the component /api/core/mod.rs.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55226" + }, + { + "type": "WEB", + "url": "https://github.com/dani-garcia/vaultwarden/releases/tag/1.32.4" + }, + { + "type": "WEB", + "url": "https://github.com/dani-garcia/vaultwarden/releases/tag/1.32.5" + }, + { + "type": "WEB", + "url": "https://insinuator.net/2024/11/vulnerability-disclosure-authentication-bypass-in-vaultwarden-versions-1-32-5" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T21:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-vw53-vc7r-68m2/GHSA-vw53-vc7r-68m2.json b/advisories/unreviewed/2025/01/GHSA-vw53-vc7r-68m2/GHSA-vw53-vc7r-68m2.json new file mode 100644 index 00000000000..1ac74c81526 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-vw53-vc7r-68m2/GHSA-vw53-vc7r-68m2.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vw53-vc7r-68m2", + "modified": "2025-01-09T21:31:32Z", + "published": "2025-01-09T21:31:32Z", + "aliases": [ + "CVE-2024-13298" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Tarte au Citron allows Cross-Site Scripting (XSS).This issue affects Tarte au Citron: from 2.0.0 before 2.0.5.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13298" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-064" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T21:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-vxch-vvvr-4v8f/GHSA-vxch-vvvr-4v8f.json b/advisories/unreviewed/2025/01/GHSA-vxch-vvvr-4v8f/GHSA-vxch-vvvr-4v8f.json new file mode 100644 index 00000000000..4296764f981 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-vxch-vvvr-4v8f/GHSA-vxch-vvvr-4v8f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vxch-vvvr-4v8f", + "modified": "2025-01-09T21:31:29Z", + "published": "2025-01-09T21:31:29Z", + "aliases": [ + "CVE-2024-13238" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Typogrify allows Cross-Site Scripting (XSS).This issue affects Typogrify: from 0.0.0 before 1.3.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13238" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-002" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T19:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-w3q9-jjpq-m527/GHSA-w3q9-jjpq-m527.json b/advisories/unreviewed/2025/01/GHSA-w3q9-jjpq-m527/GHSA-w3q9-jjpq-m527.json new file mode 100644 index 00000000000..dc48b4bbb11 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-w3q9-jjpq-m527/GHSA-w3q9-jjpq-m527.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w3q9-jjpq-m527", + "modified": "2025-01-09T21:31:30Z", + "published": "2025-01-09T21:31:30Z", + "aliases": [ + "CVE-2024-13251" + ], + "details": "Incorrect Privilege Assignment vulnerability in Drupal Registration role allows Privilege Escalation.This issue affects Registration role: from 0.0.0 before 2.0.1.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13251" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-015" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T19:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-w65p-8m9j-6pm4/GHSA-w65p-8m9j-6pm4.json b/advisories/unreviewed/2025/01/GHSA-w65p-8m9j-6pm4/GHSA-w65p-8m9j-6pm4.json new file mode 100644 index 00000000000..4dfd73db7f6 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-w65p-8m9j-6pm4/GHSA-w65p-8m9j-6pm4.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w65p-8m9j-6pm4", + "modified": "2025-01-09T21:31:31Z", + "published": "2025-01-09T21:31:31Z", + "aliases": [ + "CVE-2024-13270" + ], + "details": "Incorrect Authorization vulnerability in Drupal Freelinking allows Forceful Browsing.This issue affects Freelinking: from 0.0.0 before 4.0.1.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13270" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-034" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T20:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-w993-3vv8-hxp8/GHSA-w993-3vv8-hxp8.json b/advisories/unreviewed/2025/01/GHSA-w993-3vv8-hxp8/GHSA-w993-3vv8-hxp8.json index 6de59a6e5da..a63d43694a9 100644 --- a/advisories/unreviewed/2025/01/GHSA-w993-3vv8-hxp8/GHSA-w993-3vv8-hxp8.json +++ b/advisories/unreviewed/2025/01/GHSA-w993-3vv8-hxp8/GHSA-w993-3vv8-hxp8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w993-3vv8-hxp8", - "modified": "2025-01-08T18:30:48Z", + "modified": "2025-01-09T21:31:29Z", "published": "2025-01-08T18:30:48Z", "aliases": [ "CVE-2024-56773" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nkunit: Fix potential null dereference in kunit_device_driver_test()\n\nkunit_kzalloc() may return a NULL pointer, dereferencing it without\nNULL check may lead to NULL dereference.\nAdd a NULL check for test_state.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-08T18:15:18Z" diff --git a/advisories/unreviewed/2025/01/GHSA-wjhm-v52r-7x9g/GHSA-wjhm-v52r-7x9g.json b/advisories/unreviewed/2025/01/GHSA-wjhm-v52r-7x9g/GHSA-wjhm-v52r-7x9g.json new file mode 100644 index 00000000000..58e61ed0dc1 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-wjhm-v52r-7x9g/GHSA-wjhm-v52r-7x9g.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wjhm-v52r-7x9g", + "modified": "2025-01-09T21:31:30Z", + "published": "2025-01-09T21:31:30Z", + "aliases": [ + "CVE-2024-13254" + ], + "details": "Insertion of Sensitive Information Into Sent Data vulnerability in Drupal REST Views allows Forceful Browsing.This issue affects REST Views: from 0.0.0 before 3.0.1.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13254" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-018" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-201" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T19:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-wrj5-h97x-2xcg/GHSA-wrj5-h97x-2xcg.json b/advisories/unreviewed/2025/01/GHSA-wrj5-h97x-2xcg/GHSA-wrj5-h97x-2xcg.json new file mode 100644 index 00000000000..6ff20550494 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-wrj5-h97x-2xcg/GHSA-wrj5-h97x-2xcg.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wrj5-h97x-2xcg", + "modified": "2025-01-09T21:31:31Z", + "published": "2025-01-09T21:31:31Z", + "aliases": [ + "CVE-2024-10215" + ], + "details": "The WPBookit plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 1.6.4. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for unauthenticated attackers to change user passwords and potentially take over administrator accounts.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10215" + }, + { + "type": "WEB", + "url": "https://documentation.iqonic.design/wpbookit/versions/change-log" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/2d23a2b9-8476-4564-a5de-5e6cfc38ce68?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T20:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-x5v3-33m6-c266/GHSA-x5v3-33m6-c266.json b/advisories/unreviewed/2025/01/GHSA-x5v3-33m6-c266/GHSA-x5v3-33m6-c266.json new file mode 100644 index 00000000000..aed48da9cae --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-x5v3-33m6-c266/GHSA-x5v3-33m6-c266.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x5v3-33m6-c266", + "modified": "2025-01-09T21:31:31Z", + "published": "2025-01-09T21:31:31Z", + "aliases": [ + "CVE-2024-13281" + ], + "details": "Incorrect Authorization vulnerability in Drupal Monster Menus allows Forceful Browsing.This issue affects Monster Menus: from 0.0.0 before 9.3.2.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13281" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-045" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T20:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-x7m9-mv49-fv73/GHSA-x7m9-mv49-fv73.json b/advisories/unreviewed/2025/01/GHSA-x7m9-mv49-fv73/GHSA-x7m9-mv49-fv73.json new file mode 100644 index 00000000000..b2d48967b90 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-x7m9-mv49-fv73/GHSA-x7m9-mv49-fv73.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x7m9-mv49-fv73", + "modified": "2025-01-09T21:31:32Z", + "published": "2025-01-09T21:31:32Z", + "aliases": [ + "CVE-2024-55225" + ], + "details": "An issue in the component src/api/identity.rs of Vaultwarden prior to v1.32.5 allows attackers to impersonate users, including Administrators, via a crafted authorization request.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55225" + }, + { + "type": "WEB", + "url": "https://github.com/dani-garcia/vaultwarden/releases/tag/1.32.4" + }, + { + "type": "WEB", + "url": "https://github.com/dani-garcia/vaultwarden/releases/tag/1.32.5" + }, + { + "type": "WEB", + "url": "https://insinuator.net/2024/11/vulnerability-disclosure-authentication-bypass-in-vaultwarden-versions-1-32-5" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T21:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-x99c-gp84-c52f/GHSA-x99c-gp84-c52f.json b/advisories/unreviewed/2025/01/GHSA-x99c-gp84-c52f/GHSA-x99c-gp84-c52f.json index d6a50afcdce..3aed9e03a2b 100644 --- a/advisories/unreviewed/2025/01/GHSA-x99c-gp84-c52f/GHSA-x99c-gp84-c52f.json +++ b/advisories/unreviewed/2025/01/GHSA-x99c-gp84-c52f/GHSA-x99c-gp84-c52f.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x99c-gp84-c52f", - "modified": "2025-01-08T18:30:49Z", + "modified": "2025-01-09T21:31:29Z", "published": "2025-01-08T18:30:49Z", "aliases": [ "CVE-2024-56781" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\npowerpc/prom_init: Fixup missing powermac #size-cells\n\nOn some powermacs `escc` nodes are missing `#size-cells` properties,\nwhich is deprecated and now triggers a warning at boot since commit\n045b14ca5c36 (\"of: WARN on deprecated #address-cells/#size-cells\nhandling\").\n\nFor example:\n\n Missing '#size-cells' in /pci@f2000000/mac-io@c/escc@13000\n WARNING: CPU: 0 PID: 0 at drivers/of/base.c:133 of_bus_n_size_cells+0x98/0x108\n Hardware name: PowerMac3,1 7400 0xc0209 PowerMac\n ...\n Call Trace:\n of_bus_n_size_cells+0x98/0x108 (unreliable)\n of_bus_default_count_cells+0x40/0x60\n __of_get_address+0xc8/0x21c\n __of_address_to_resource+0x5c/0x228\n pmz_init_port+0x5c/0x2ec\n pmz_probe.isra.0+0x144/0x1e4\n pmz_console_init+0x10/0x48\n console_init+0xcc/0x138\n start_kernel+0x5c4/0x694\n\nAs powermacs boot via prom_init it's possible to add the missing\nproperties to the device tree during boot, avoiding the warning. Note\nthat `escc-legacy` nodes are also missing `#size-cells` properties, but\nthey are skipped by the macio driver, so leave them alone.\n\nDepends-on: 045b14ca5c36 (\"of: WARN on deprecated #address-cells/#size-cells handling\")", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -45,7 +50,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-08T18:15:19Z" diff --git a/advisories/unreviewed/2025/01/GHSA-xff5-h82c-43q2/GHSA-xff5-h82c-43q2.json b/advisories/unreviewed/2025/01/GHSA-xff5-h82c-43q2/GHSA-xff5-h82c-43q2.json new file mode 100644 index 00000000000..3f646b6030f --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-xff5-h82c-43q2/GHSA-xff5-h82c-43q2.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xff5-h82c-43q2", + "modified": "2025-01-09T21:31:31Z", + "published": "2025-01-09T21:31:31Z", + "aliases": [ + "CVE-2024-13276" + ], + "details": "Insertion of Sensitive Information Into Sent Data vulnerability in Drupal File Entity (fieldable files) allows Forceful Browsing.This issue affects File Entity (fieldable files): from 7.X-* before 7.X-2.39.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13276" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-040" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-201" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T20:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-xh2f-mpwc-mhh4/GHSA-xh2f-mpwc-mhh4.json b/advisories/unreviewed/2025/01/GHSA-xh2f-mpwc-mhh4/GHSA-xh2f-mpwc-mhh4.json new file mode 100644 index 00000000000..cda295a1569 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-xh2f-mpwc-mhh4/GHSA-xh2f-mpwc-mhh4.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xh2f-mpwc-mhh4", + "modified": "2025-01-09T21:31:31Z", + "published": "2025-01-09T21:31:31Z", + "aliases": [ + "CVE-2024-13284" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Drupal Gutenberg allows Cross Site Request Forgery.This issue affects Gutenberg: from 0.0.0 before 2.13.0, from 3.0.0 before 3.0.5.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13284" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-048" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T20:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-xhf8-2ffc-9gh2/GHSA-xhf8-2ffc-9gh2.json b/advisories/unreviewed/2025/01/GHSA-xhf8-2ffc-9gh2/GHSA-xhf8-2ffc-9gh2.json new file mode 100644 index 00000000000..5adae5e5af5 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-xhf8-2ffc-9gh2/GHSA-xhf8-2ffc-9gh2.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xhf8-2ffc-9gh2", + "modified": "2025-01-09T21:31:30Z", + "published": "2025-01-09T21:31:30Z", + "aliases": [ + "CVE-2024-13256" + ], + "details": "Insufficient Granularity of Access Control vulnerability in Drupal Email Contact allows Forceful Browsing.This issue affects Email Contact: from 0.0.0 before 2.0.4.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13256" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-020" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1220" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T19:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-xw4g-gmmj-5g3m/GHSA-xw4g-gmmj-5g3m.json b/advisories/unreviewed/2025/01/GHSA-xw4g-gmmj-5g3m/GHSA-xw4g-gmmj-5g3m.json new file mode 100644 index 00000000000..746564646e3 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-xw4g-gmmj-5g3m/GHSA-xw4g-gmmj-5g3m.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xw4g-gmmj-5g3m", + "modified": "2025-01-09T21:31:29Z", + "published": "2025-01-09T21:31:29Z", + "aliases": [ + "CVE-2024-13241" + ], + "details": "Improper Authorization vulnerability in Drupal Open Social allows Collect Data from Common Resource Locations.This issue affects Open Social: from 0.0.0 before 12.0.5.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13241" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2024-005" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-285" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-09T19:15:17Z" + } +} \ No newline at end of file