diff --git a/advisories/unreviewed/2022/04/GHSA-53gp-9cgv-fj68/GHSA-53gp-9cgv-fj68.json b/advisories/unreviewed/2022/04/GHSA-53gp-9cgv-fj68/GHSA-53gp-9cgv-fj68.json index db1d66b7204..0c960050e58 100644 --- a/advisories/unreviewed/2022/04/GHSA-53gp-9cgv-fj68/GHSA-53gp-9cgv-fj68.json +++ b/advisories/unreviewed/2022/04/GHSA-53gp-9cgv-fj68/GHSA-53gp-9cgv-fj68.json @@ -57,7 +57,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-269" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-27fx-q398-q8vr/GHSA-27fx-q398-q8vr.json b/advisories/unreviewed/2022/05/GHSA-27fx-q398-q8vr/GHSA-27fx-q398-q8vr.json index 4c30c8aea3a..05ab962b38d 100644 --- a/advisories/unreviewed/2022/05/GHSA-27fx-q398-q8vr/GHSA-27fx-q398-q8vr.json +++ b/advisories/unreviewed/2022/05/GHSA-27fx-q398-q8vr/GHSA-27fx-q398-q8vr.json @@ -58,7 +58,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-77" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-5876-f5vv-fv9w/GHSA-5876-f5vv-fv9w.json b/advisories/unreviewed/2022/05/GHSA-5876-f5vv-fv9w/GHSA-5876-f5vv-fv9w.json index 2808edb9c62..f371108475f 100644 --- a/advisories/unreviewed/2022/05/GHSA-5876-f5vv-fv9w/GHSA-5876-f5vv-fv9w.json +++ b/advisories/unreviewed/2022/05/GHSA-5876-f5vv-fv9w/GHSA-5876-f5vv-fv9w.json @@ -45,7 +45,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-20" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-72pp-v9jm-c6xj/GHSA-72pp-v9jm-c6xj.json b/advisories/unreviewed/2022/05/GHSA-72pp-v9jm-c6xj/GHSA-72pp-v9jm-c6xj.json index 49775b36c7a..be2bb2abde5 100644 --- a/advisories/unreviewed/2022/05/GHSA-72pp-v9jm-c6xj/GHSA-72pp-v9jm-c6xj.json +++ b/advisories/unreviewed/2022/05/GHSA-72pp-v9jm-c6xj/GHSA-72pp-v9jm-c6xj.json @@ -97,7 +97,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-749" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-782f-h7v4-m7wc/GHSA-782f-h7v4-m7wc.json b/advisories/unreviewed/2022/05/GHSA-782f-h7v4-m7wc/GHSA-782f-h7v4-m7wc.json index 8eee40d5c58..e89469f4bc6 100644 --- a/advisories/unreviewed/2022/05/GHSA-782f-h7v4-m7wc/GHSA-782f-h7v4-m7wc.json +++ b/advisories/unreviewed/2022/05/GHSA-782f-h7v4-m7wc/GHSA-782f-h7v4-m7wc.json @@ -34,6 +34,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-200", "CWE-22" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/05/GHSA-84wc-9427-hw23/GHSA-84wc-9427-hw23.json b/advisories/unreviewed/2022/05/GHSA-84wc-9427-hw23/GHSA-84wc-9427-hw23.json index 08c5997ebf8..13b7ea54d1f 100644 --- a/advisories/unreviewed/2022/05/GHSA-84wc-9427-hw23/GHSA-84wc-9427-hw23.json +++ b/advisories/unreviewed/2022/05/GHSA-84wc-9427-hw23/GHSA-84wc-9427-hw23.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-84wc-9427-hw23", - "modified": "2022-05-24T17:22:04Z", + "modified": "2025-02-07T15:32:25Z", "published": "2022-05-24T17:22:04Z", "aliases": [ "CVE-2020-2021" ], "details": "When Security Assertion Markup Language (SAML) authentication is enabled and the 'Validate Identity Provider Certificate' option is disabled (unchecked), improper verification of signatures in PAN-OS SAML authentication enables an unauthenticated network-based attacker to access protected resources. The attacker must have network access to the vulnerable server to exploit this vulnerability. This issue affects PAN-OS 9.1 versions earlier than PAN-OS 9.1.3; PAN-OS 9.0 versions earlier than PAN-OS 9.0.9; PAN-OS 8.1 versions earlier than PAN-OS 8.1.15, and all versions of PAN-OS 8.0 (EOL). This issue does not affect PAN-OS 7.1. This issue cannot be exploited if SAML is not used for authentication. This issue cannot be exploited if the 'Validate Identity Provider Certificate' option is enabled (checked) in the SAML Identity Provider Server Profile. Resources that can be protected by SAML-based single sign-on (SSO) authentication are: GlobalProtect Gateway, GlobalProtect Portal, GlobalProtect Clientless VPN, Authentication and Captive Portal, PAN-OS next-generation firewalls (PA-Series, VM-Series) and Panorama web interfaces, Prisma Access In the case of GlobalProtect Gateways, GlobalProtect Portal, Clientless VPN, Captive Portal, and Prisma Access, an unauthenticated attacker with network access to the affected servers can gain access to protected resources if allowed by configured authentication and Security policies. There is no impact on the integrity and availability of the gateway, portal or VPN server. An attacker cannot inspect or tamper with sessions of regular users. In the worst case, this is a critical severity vulnerability with a CVSS Base Score of 10.0 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N). In the case of PAN-OS and Panorama web interfaces, this issue allows an unauthenticated attacker with network access to the PAN-OS or Panorama web interfaces to log in as an administrator and perform administrative actions. In the worst-case scenario, this is a critical severity vulnerability with a CVSS Base Score of 10.0 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). If the web interfaces are only accessible to a restricted management network, then the issue is lowered to a CVSS Base Score of 9.6 (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). Palo Alto Networks is not aware of any malicious attempts to exploit this vulnerability.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-347" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-86cc-wh6w-cw2h/GHSA-86cc-wh6w-cw2h.json b/advisories/unreviewed/2022/05/GHSA-86cc-wh6w-cw2h/GHSA-86cc-wh6w-cw2h.json index 9a1d0e4755e..9d696b84939 100644 --- a/advisories/unreviewed/2022/05/GHSA-86cc-wh6w-cw2h/GHSA-86cc-wh6w-cw2h.json +++ b/advisories/unreviewed/2022/05/GHSA-86cc-wh6w-cw2h/GHSA-86cc-wh6w-cw2h.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-86cc-wh6w-cw2h", - "modified": "2022-05-24T17:17:27Z", + "modified": "2025-02-07T15:32:24Z", "published": "2022-05-24T17:17:27Z", "aliases": [ "CVE-2020-4430" ], "details": "IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote authenticated attacker to traverse directories on the system. An attacker could send a specially-crafted URL request to download arbitrary files from the system. IBM X-Force ID: 180535.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -24,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-22" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-8987-qgc7-79p9/GHSA-8987-qgc7-79p9.json b/advisories/unreviewed/2022/05/GHSA-8987-qgc7-79p9/GHSA-8987-qgc7-79p9.json index 69baecdd1d3..110ea2c52f9 100644 --- a/advisories/unreviewed/2022/05/GHSA-8987-qgc7-79p9/GHSA-8987-qgc7-79p9.json +++ b/advisories/unreviewed/2022/05/GHSA-8987-qgc7-79p9/GHSA-8987-qgc7-79p9.json @@ -58,6 +58,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-502", "CWE-94" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2022/05/GHSA-8ffr-q7j8-h445/GHSA-8ffr-q7j8-h445.json b/advisories/unreviewed/2022/05/GHSA-8ffr-q7j8-h445/GHSA-8ffr-q7j8-h445.json index ad89f184e84..7843c07e6d1 100644 --- a/advisories/unreviewed/2022/05/GHSA-8ffr-q7j8-h445/GHSA-8ffr-q7j8-h445.json +++ b/advisories/unreviewed/2022/05/GHSA-8ffr-q7j8-h445/GHSA-8ffr-q7j8-h445.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8ffr-q7j8-h445", - "modified": "2023-01-31T15:30:32Z", + "modified": "2025-02-07T15:32:18Z", "published": "2022-05-24T16:50:59Z", "aliases": [ "CVE-2019-11707" diff --git a/advisories/unreviewed/2022/05/GHSA-8j2r-c64f-x52g/GHSA-8j2r-c64f-x52g.json b/advisories/unreviewed/2022/05/GHSA-8j2r-c64f-x52g/GHSA-8j2r-c64f-x52g.json index 3909b562a44..2adf96af838 100644 --- a/advisories/unreviewed/2022/05/GHSA-8j2r-c64f-x52g/GHSA-8j2r-c64f-x52g.json +++ b/advisories/unreviewed/2022/05/GHSA-8j2r-c64f-x52g/GHSA-8j2r-c64f-x52g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8j2r-c64f-x52g", - "modified": "2022-05-24T16:44:19Z", + "modified": "2025-02-07T15:32:16Z", "published": "2022-05-24T16:44:19Z", "aliases": [ "CVE-2019-2616" ], "details": "Vulnerability in the BI Publisher (formerly XML Publisher) component of Oracle Fusion Middleware (subcomponent: BI Publisher Security). Supported versions that are affected are 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise BI Publisher (formerly XML Publisher). While the vulnerability is in BI Publisher (formerly XML Publisher), attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of BI Publisher (formerly XML Publisher) accessible data as well as unauthorized read access to a subset of BI Publisher (formerly XML Publisher) accessible data. CVSS 3.0 Base Score 7.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-8mjc-qhq2-3xm8/GHSA-8mjc-qhq2-3xm8.json b/advisories/unreviewed/2022/05/GHSA-8mjc-qhq2-3xm8/GHSA-8mjc-qhq2-3xm8.json index 471993f544e..9eeea05615c 100644 --- a/advisories/unreviewed/2022/05/GHSA-8mjc-qhq2-3xm8/GHSA-8mjc-qhq2-3xm8.json +++ b/advisories/unreviewed/2022/05/GHSA-8mjc-qhq2-3xm8/GHSA-8mjc-qhq2-3xm8.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-425", "CWE-862" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/05/GHSA-8pqx-3rxx-f5pm/GHSA-8pqx-3rxx-f5pm.json b/advisories/unreviewed/2022/05/GHSA-8pqx-3rxx-f5pm/GHSA-8pqx-3rxx-f5pm.json index e7d6ae85b42..1b3939131b3 100644 --- a/advisories/unreviewed/2022/05/GHSA-8pqx-3rxx-f5pm/GHSA-8pqx-3rxx-f5pm.json +++ b/advisories/unreviewed/2022/05/GHSA-8pqx-3rxx-f5pm/GHSA-8pqx-3rxx-f5pm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8pqx-3rxx-f5pm", - "modified": "2022-05-13T01:30:06Z", + "modified": "2025-02-07T15:32:05Z", "published": "2022-05-13T01:30:06Z", "aliases": [ "CVE-2015-5317" ], "details": "The Fingerprints pages in Jenkins before 1.638 and LTS before 1.625.2 might allow remote attackers to obtain sensitive job and build name information via a direct request.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-9m3f-27xq-x4j5/GHSA-9m3f-27xq-x4j5.json b/advisories/unreviewed/2022/05/GHSA-9m3f-27xq-x4j5/GHSA-9m3f-27xq-x4j5.json index 8dd709b6d70..063455eb5a2 100644 --- a/advisories/unreviewed/2022/05/GHSA-9m3f-27xq-x4j5/GHSA-9m3f-27xq-x4j5.json +++ b/advisories/unreviewed/2022/05/GHSA-9m3f-27xq-x4j5/GHSA-9m3f-27xq-x4j5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9m3f-27xq-x4j5", - "modified": "2022-11-16T12:00:20Z", + "modified": "2025-02-07T15:32:23Z", "published": "2022-05-24T17:09:59Z", "aliases": [ "CVE-2019-17026" diff --git a/advisories/unreviewed/2022/05/GHSA-9q4p-22w8-h32x/GHSA-9q4p-22w8-h32x.json b/advisories/unreviewed/2022/05/GHSA-9q4p-22w8-h32x/GHSA-9q4p-22w8-h32x.json index ea29f50b86b..5be185a896f 100644 --- a/advisories/unreviewed/2022/05/GHSA-9q4p-22w8-h32x/GHSA-9q4p-22w8-h32x.json +++ b/advisories/unreviewed/2022/05/GHSA-9q4p-22w8-h32x/GHSA-9q4p-22w8-h32x.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9q4p-22w8-h32x", - "modified": "2022-05-24T16:50:28Z", + "modified": "2025-02-07T15:32:18Z", "published": "2022-05-24T16:50:28Z", "aliases": [ "CVE-2019-12989" ], "details": "Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -32,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-89" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cqg8-w8fp-8gm6/GHSA-cqg8-w8fp-8gm6.json b/advisories/unreviewed/2022/05/GHSA-cqg8-w8fp-8gm6/GHSA-cqg8-w8fp-8gm6.json index 29f0e1dfaeb..83d3be6805f 100644 --- a/advisories/unreviewed/2022/05/GHSA-cqg8-w8fp-8gm6/GHSA-cqg8-w8fp-8gm6.json +++ b/advisories/unreviewed/2022/05/GHSA-cqg8-w8fp-8gm6/GHSA-cqg8-w8fp-8gm6.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-cv8q-mpvf-42h2/GHSA-cv8q-mpvf-42h2.json b/advisories/unreviewed/2022/05/GHSA-cv8q-mpvf-42h2/GHSA-cv8q-mpvf-42h2.json index 32980348747..ceeb07e440e 100644 --- a/advisories/unreviewed/2022/05/GHSA-cv8q-mpvf-42h2/GHSA-cv8q-mpvf-42h2.json +++ b/advisories/unreviewed/2022/05/GHSA-cv8q-mpvf-42h2/GHSA-cv8q-mpvf-42h2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cv8q-mpvf-42h2", - "modified": "2022-07-13T00:00:51Z", + "modified": "2025-02-07T15:32:23Z", "published": "2022-05-24T17:16:27Z", "aliases": [ "CVE-2020-6819" diff --git a/advisories/unreviewed/2022/05/GHSA-f77r-rqc9-53hh/GHSA-f77r-rqc9-53hh.json b/advisories/unreviewed/2022/05/GHSA-f77r-rqc9-53hh/GHSA-f77r-rqc9-53hh.json index d1dd1c68a03..d1ef1c700ab 100644 --- a/advisories/unreviewed/2022/05/GHSA-f77r-rqc9-53hh/GHSA-f77r-rqc9-53hh.json +++ b/advisories/unreviewed/2022/05/GHSA-f77r-rqc9-53hh/GHSA-f77r-rqc9-53hh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f77r-rqc9-53hh", - "modified": "2022-07-13T00:00:51Z", + "modified": "2025-02-07T15:32:23Z", "published": "2022-05-24T17:16:26Z", "aliases": [ "CVE-2020-6820" diff --git a/advisories/unreviewed/2022/05/GHSA-fr34-8fhg-2m6q/GHSA-fr34-8fhg-2m6q.json b/advisories/unreviewed/2022/05/GHSA-fr34-8fhg-2m6q/GHSA-fr34-8fhg-2m6q.json index 8b973ade9b5..d1c60e7ebd1 100644 --- a/advisories/unreviewed/2022/05/GHSA-fr34-8fhg-2m6q/GHSA-fr34-8fhg-2m6q.json +++ b/advisories/unreviewed/2022/05/GHSA-fr34-8fhg-2m6q/GHSA-fr34-8fhg-2m6q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fr34-8fhg-2m6q", - "modified": "2022-05-13T01:04:38Z", + "modified": "2025-02-07T15:32:15Z", "published": "2022-05-13T01:04:38Z", "aliases": [ "CVE-2019-3396" diff --git a/advisories/unreviewed/2022/05/GHSA-gc2g-58xq-cq5h/GHSA-gc2g-58xq-cq5h.json b/advisories/unreviewed/2022/05/GHSA-gc2g-58xq-cq5h/GHSA-gc2g-58xq-cq5h.json index 904987c2c48..a0f4a169fa5 100644 --- a/advisories/unreviewed/2022/05/GHSA-gc2g-58xq-cq5h/GHSA-gc2g-58xq-cq5h.json +++ b/advisories/unreviewed/2022/05/GHSA-gc2g-58xq-cq5h/GHSA-gc2g-58xq-cq5h.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-284", "CWE-287", "CWE-862" ], diff --git a/advisories/unreviewed/2022/05/GHSA-jwfh-687w-6qp5/GHSA-jwfh-687w-6qp5.json b/advisories/unreviewed/2022/05/GHSA-jwfh-687w-6qp5/GHSA-jwfh-687w-6qp5.json index a1eea926121..c1184fa1dc9 100644 --- a/advisories/unreviewed/2022/05/GHSA-jwfh-687w-6qp5/GHSA-jwfh-687w-6qp5.json +++ b/advisories/unreviewed/2022/05/GHSA-jwfh-687w-6qp5/GHSA-jwfh-687w-6qp5.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-20", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/05/GHSA-m437-3crh-7475/GHSA-m437-3crh-7475.json b/advisories/unreviewed/2022/05/GHSA-m437-3crh-7475/GHSA-m437-3crh-7475.json index b32c35ad37b..90bf96b83ed 100644 --- a/advisories/unreviewed/2022/05/GHSA-m437-3crh-7475/GHSA-m437-3crh-7475.json +++ b/advisories/unreviewed/2022/05/GHSA-m437-3crh-7475/GHSA-m437-3crh-7475.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m437-3crh-7475", - "modified": "2022-05-24T16:44:45Z", + "modified": "2025-02-07T15:32:16Z", "published": "2022-05-24T16:44:45Z", "aliases": [ "CVE-2019-2725" diff --git a/advisories/unreviewed/2022/05/GHSA-mc4h-hp66-ccmh/GHSA-mc4h-hp66-ccmh.json b/advisories/unreviewed/2022/05/GHSA-mc4h-hp66-ccmh/GHSA-mc4h-hp66-ccmh.json index c3c911d4877..3be8389d8d8 100644 --- a/advisories/unreviewed/2022/05/GHSA-mc4h-hp66-ccmh/GHSA-mc4h-hp66-ccmh.json +++ b/advisories/unreviewed/2022/05/GHSA-mc4h-hp66-ccmh/GHSA-mc4h-hp66-ccmh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mc4h-hp66-ccmh", - "modified": "2022-05-24T17:32:44Z", + "modified": "2025-02-07T15:32:27Z", "published": "2022-05-24T17:32:44Z", "aliases": [ "CVE-2020-8260" ], "details": "A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary code execution using uncontrolled gzip extraction.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-p833-99r6-7hqr/GHSA-p833-99r6-7hqr.json b/advisories/unreviewed/2022/05/GHSA-p833-99r6-7hqr/GHSA-p833-99r6-7hqr.json index 2881ab96dea..554f2953836 100644 --- a/advisories/unreviewed/2022/05/GHSA-p833-99r6-7hqr/GHSA-p833-99r6-7hqr.json +++ b/advisories/unreviewed/2022/05/GHSA-p833-99r6-7hqr/GHSA-p833-99r6-7hqr.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-22" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qq6c-p3fx-6qcx/GHSA-qq6c-p3fx-6qcx.json b/advisories/unreviewed/2022/05/GHSA-qq6c-p3fx-6qcx/GHSA-qq6c-p3fx-6qcx.json index 0607276ce3f..59eecf186dd 100644 --- a/advisories/unreviewed/2022/05/GHSA-qq6c-p3fx-6qcx/GHSA-qq6c-p3fx-6qcx.json +++ b/advisories/unreviewed/2022/05/GHSA-qq6c-p3fx-6qcx/GHSA-qq6c-p3fx-6qcx.json @@ -141,7 +141,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-77" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-qw37-hh98-8g3j/GHSA-qw37-hh98-8g3j.json b/advisories/unreviewed/2022/05/GHSA-qw37-hh98-8g3j/GHSA-qw37-hh98-8g3j.json index b5fd13bc67b..bb68f8e963a 100644 --- a/advisories/unreviewed/2022/05/GHSA-qw37-hh98-8g3j/GHSA-qw37-hh98-8g3j.json +++ b/advisories/unreviewed/2022/05/GHSA-qw37-hh98-8g3j/GHSA-qw37-hh98-8g3j.json @@ -101,7 +101,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-r3v6-c98w-p4j5/GHSA-r3v6-c98w-p4j5.json b/advisories/unreviewed/2022/05/GHSA-r3v6-c98w-p4j5/GHSA-r3v6-c98w-p4j5.json index b02a056b77f..6cc932930d0 100644 --- a/advisories/unreviewed/2022/05/GHSA-r3v6-c98w-p4j5/GHSA-r3v6-c98w-p4j5.json +++ b/advisories/unreviewed/2022/05/GHSA-r3v6-c98w-p4j5/GHSA-r3v6-c98w-p4j5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-r3v6-c98w-p4j5", - "modified": "2022-05-24T17:17:27Z", + "modified": "2025-02-07T15:32:24Z", "published": "2022-05-24T17:17:27Z", "aliases": [ "CVE-2020-4428" ], "details": "IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, and 2.0.6 could allow a remote authenticated attacker to execute arbitrary commands on the system. IBM X-Force ID: 180533.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-78" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-v6j9-wwcx-4984/GHSA-v6j9-wwcx-4984.json b/advisories/unreviewed/2022/05/GHSA-v6j9-wwcx-4984/GHSA-v6j9-wwcx-4984.json index b56ddf8c7cf..726e83cb875 100644 --- a/advisories/unreviewed/2022/05/GHSA-v6j9-wwcx-4984/GHSA-v6j9-wwcx-4984.json +++ b/advisories/unreviewed/2022/05/GHSA-v6j9-wwcx-4984/GHSA-v6j9-wwcx-4984.json @@ -65,7 +65,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-269" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vcwg-4772-7rvx/GHSA-vcwg-4772-7rvx.json b/advisories/unreviewed/2022/05/GHSA-vcwg-4772-7rvx/GHSA-vcwg-4772-7rvx.json index 59a7d4cb9e6..0b94dc999a5 100644 --- a/advisories/unreviewed/2022/05/GHSA-vcwg-4772-7rvx/GHSA-vcwg-4772-7rvx.json +++ b/advisories/unreviewed/2022/05/GHSA-vcwg-4772-7rvx/GHSA-vcwg-4772-7rvx.json @@ -65,7 +65,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-749" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-vmpp-w9w7-m326/GHSA-vmpp-w9w7-m326.json b/advisories/unreviewed/2022/05/GHSA-vmpp-w9w7-m326/GHSA-vmpp-w9w7-m326.json index c4e61e5bc81..f3dca3210e9 100644 --- a/advisories/unreviewed/2022/05/GHSA-vmpp-w9w7-m326/GHSA-vmpp-w9w7-m326.json +++ b/advisories/unreviewed/2022/05/GHSA-vmpp-w9w7-m326/GHSA-vmpp-w9w7-m326.json @@ -114,7 +114,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-552" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-vph4-5mf4-28v5/GHSA-vph4-5mf4-28v5.json b/advisories/unreviewed/2022/05/GHSA-vph4-5mf4-28v5/GHSA-vph4-5mf4-28v5.json index b8061c3e13e..12274dfcd89 100644 --- a/advisories/unreviewed/2022/05/GHSA-vph4-5mf4-28v5/GHSA-vph4-5mf4-28v5.json +++ b/advisories/unreviewed/2022/05/GHSA-vph4-5mf4-28v5/GHSA-vph4-5mf4-28v5.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-284", "CWE-863" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2022/05/GHSA-w5jq-q2q7-wx7x/GHSA-w5jq-q2q7-wx7x.json b/advisories/unreviewed/2022/05/GHSA-w5jq-q2q7-wx7x/GHSA-w5jq-q2q7-wx7x.json index 135c193bac7..76fd01f0a2e 100644 --- a/advisories/unreviewed/2022/05/GHSA-w5jq-q2q7-wx7x/GHSA-w5jq-q2q7-wx7x.json +++ b/advisories/unreviewed/2022/05/GHSA-w5jq-q2q7-wx7x/GHSA-w5jq-q2q7-wx7x.json @@ -45,7 +45,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-306" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-w6h5-rjp3-hxvc/GHSA-w6h5-rjp3-hxvc.json b/advisories/unreviewed/2022/05/GHSA-w6h5-rjp3-hxvc/GHSA-w6h5-rjp3-hxvc.json index 044fa023682..6cf51c5dc54 100644 --- a/advisories/unreviewed/2022/05/GHSA-w6h5-rjp3-hxvc/GHSA-w6h5-rjp3-hxvc.json +++ b/advisories/unreviewed/2022/05/GHSA-w6h5-rjp3-hxvc/GHSA-w6h5-rjp3-hxvc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w6h5-rjp3-hxvc", - "modified": "2022-05-24T17:10:08Z", + "modified": "2025-02-07T15:32:23Z", "published": "2022-05-24T17:10:08Z", "aliases": [ "CVE-2020-9054" ], "details": "Multiple ZyXEL network-attached storage (NAS) devices running firmware version 5.21 contain a pre-authentication command injection vulnerability, which may allow a remote, unauthenticated attacker to execute arbitrary code on a vulnerable device. ZyXEL NAS devices achieve authentication by using the weblogin.cgi CGI executable. This program fails to properly sanitize the username parameter that is passed to it. If the username parameter contains certain characters, it can allow command injection with the privileges of the web server that runs on the ZyXEL device. Although the web server does not run as the root user, ZyXEL devices include a setuid utility that can be leveraged to run any command with root privileges. As such, it should be assumed that exploitation of this vulnerability can lead to remote code execution with root privileges. By sending a specially-crafted HTTP POST or GET request to a vulnerable ZyXEL device, a remote, unauthenticated attacker may be able to execute arbitrary code on the device. This may happen by directly connecting to a device if it is directly exposed to an attacker. However, there are ways to trigger such crafted requests even if an attacker does not have direct connectivity to a vulnerable devices. For example, simply visiting a website can result in the compromise of any ZyXEL device that is reachable from the client system. Affected products include: NAS326 before firmware V5.21(AAZF.7)C0 NAS520 before firmware V5.21(AASZ.3)C0 NAS540 before firmware V5.21(AATB.4)C0 NAS542 before firmware V5.21(ABAG.4)C0 ZyXEL has made firmware updates available for NAS326, NAS520, NAS540, and NAS542 devices. Affected models that are end-of-support: NSA210, NSA220, NSA220+, NSA221, NSA310, NSA310S, NSA320, NSA320S, NSA325 and NSA325v2", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -36,7 +41,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-78" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-wrxp-682m-vm9p/GHSA-wrxp-682m-vm9p.json b/advisories/unreviewed/2022/05/GHSA-wrxp-682m-vm9p/GHSA-wrxp-682m-vm9p.json index 411c45df81d..dca3b672f32 100644 --- a/advisories/unreviewed/2022/05/GHSA-wrxp-682m-vm9p/GHSA-wrxp-682m-vm9p.json +++ b/advisories/unreviewed/2022/05/GHSA-wrxp-682m-vm9p/GHSA-wrxp-682m-vm9p.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-284", "CWE-287", "CWE-862" ], diff --git a/advisories/unreviewed/2022/05/GHSA-x45p-q5pf-h9jx/GHSA-x45p-q5pf-h9jx.json b/advisories/unreviewed/2022/05/GHSA-x45p-q5pf-h9jx/GHSA-x45p-q5pf-h9jx.json index 69ff9c73388..bc1551403bc 100644 --- a/advisories/unreviewed/2022/05/GHSA-x45p-q5pf-h9jx/GHSA-x45p-q5pf-h9jx.json +++ b/advisories/unreviewed/2022/05/GHSA-x45p-q5pf-h9jx/GHSA-x45p-q5pf-h9jx.json @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-77" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-xqgm-4493-f736/GHSA-xqgm-4493-f736.json b/advisories/unreviewed/2022/05/GHSA-xqgm-4493-f736/GHSA-xqgm-4493-f736.json index c367e074711..2273881096e 100644 --- a/advisories/unreviewed/2022/05/GHSA-xqgm-4493-f736/GHSA-xqgm-4493-f736.json +++ b/advisories/unreviewed/2022/05/GHSA-xqgm-4493-f736/GHSA-xqgm-4493-f736.json @@ -41,7 +41,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-77" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-xwpg-vm43-3qwm/GHSA-xwpg-vm43-3qwm.json b/advisories/unreviewed/2022/05/GHSA-xwpg-vm43-3qwm/GHSA-xwpg-vm43-3qwm.json index f3e1d5553ed..8a22455384e 100644 --- a/advisories/unreviewed/2022/05/GHSA-xwpg-vm43-3qwm/GHSA-xwpg-vm43-3qwm.json +++ b/advisories/unreviewed/2022/05/GHSA-xwpg-vm43-3qwm/GHSA-xwpg-vm43-3qwm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xwpg-vm43-3qwm", - "modified": "2022-05-13T01:23:13Z", + "modified": "2025-02-07T15:32:04Z", "published": "2022-05-13T01:23:13Z", "aliases": [ "CVE-2014-0196" ], "details": "The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the \"LECHO & !OPOST\" case, which allows local users to cause a denial of service (memory corruption and system crash) or gain privileges by triggering a race condition involving read and write operations with long strings.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/08/GHSA-r3j6-h9rm-9q33/GHSA-r3j6-h9rm-9q33.json b/advisories/unreviewed/2022/08/GHSA-r3j6-h9rm-9q33/GHSA-r3j6-h9rm-9q33.json index 1c1eb5598db..1d6311f3751 100644 --- a/advisories/unreviewed/2022/08/GHSA-r3j6-h9rm-9q33/GHSA-r3j6-h9rm-9q33.json +++ b/advisories/unreviewed/2022/08/GHSA-r3j6-h9rm-9q33/GHSA-r3j6-h9rm-9q33.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-400" + "CWE-400", + "CWE-406" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-6h5p-8mvr-f4fg/GHSA-6h5p-8mvr-f4fg.json b/advisories/unreviewed/2024/02/GHSA-6h5p-8mvr-f4fg/GHSA-6h5p-8mvr-f4fg.json index 09a70c39276..a4d9ae78804 100644 --- a/advisories/unreviewed/2024/02/GHSA-6h5p-8mvr-f4fg/GHSA-6h5p-8mvr-f4fg.json +++ b/advisories/unreviewed/2024/02/GHSA-6h5p-8mvr-f4fg/GHSA-6h5p-8mvr-f4fg.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-qgpm-8p88-6c6x/GHSA-qgpm-8p88-6c6x.json b/advisories/unreviewed/2024/06/GHSA-qgpm-8p88-6c6x/GHSA-qgpm-8p88-6c6x.json index 2ead00d5141..ce1748c5612 100644 --- a/advisories/unreviewed/2024/06/GHSA-qgpm-8p88-6c6x/GHSA-qgpm-8p88-6c6x.json +++ b/advisories/unreviewed/2024/06/GHSA-qgpm-8p88-6c6x/GHSA-qgpm-8p88-6c6x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qgpm-8p88-6c6x", - "modified": "2024-06-03T03:31:04Z", + "modified": "2025-02-07T15:32:33Z", "published": "2024-06-03T03:31:04Z", "aliases": [ "CVE-2024-5589" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/06/GHSA-v75w-w4c8-6g57/GHSA-v75w-w4c8-6g57.json b/advisories/unreviewed/2024/06/GHSA-v75w-w4c8-6g57/GHSA-v75w-w4c8-6g57.json index 32a26f4ca8d..46d1b93e357 100644 --- a/advisories/unreviewed/2024/06/GHSA-v75w-w4c8-6g57/GHSA-v75w-w4c8-6g57.json +++ b/advisories/unreviewed/2024/06/GHSA-v75w-w4c8-6g57/GHSA-v75w-w4c8-6g57.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v75w-w4c8-6g57", - "modified": "2024-06-03T03:31:04Z", + "modified": "2025-02-07T15:32:33Z", "published": "2024-06-03T03:31:04Z", "aliases": [ "CVE-2024-5590" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/12/GHSA-x5mp-q3w8-grg7/GHSA-x5mp-q3w8-grg7.json b/advisories/unreviewed/2024/12/GHSA-x5mp-q3w8-grg7/GHSA-x5mp-q3w8-grg7.json index 3cb199b69f7..9b9f724aa9e 100644 --- a/advisories/unreviewed/2024/12/GHSA-x5mp-q3w8-grg7/GHSA-x5mp-q3w8-grg7.json +++ b/advisories/unreviewed/2024/12/GHSA-x5mp-q3w8-grg7/GHSA-x5mp-q3w8-grg7.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-5255-wp7r-mh9x/GHSA-5255-wp7r-mh9x.json b/advisories/unreviewed/2025/01/GHSA-5255-wp7r-mh9x/GHSA-5255-wp7r-mh9x.json index 4eb04864490..a56ca6ef96a 100644 --- a/advisories/unreviewed/2025/01/GHSA-5255-wp7r-mh9x/GHSA-5255-wp7r-mh9x.json +++ b/advisories/unreviewed/2025/01/GHSA-5255-wp7r-mh9x/GHSA-5255-wp7r-mh9x.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-5mfr-hh9v-5vgg/GHSA-5mfr-hh9v-5vgg.json b/advisories/unreviewed/2025/01/GHSA-5mfr-hh9v-5vgg/GHSA-5mfr-hh9v-5vgg.json index 6546e548809..1e3998f43e1 100644 --- a/advisories/unreviewed/2025/01/GHSA-5mfr-hh9v-5vgg/GHSA-5mfr-hh9v-5vgg.json +++ b/advisories/unreviewed/2025/01/GHSA-5mfr-hh9v-5vgg/GHSA-5mfr-hh9v-5vgg.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-434" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-gp5f-6cr8-73qf/GHSA-gp5f-6cr8-73qf.json b/advisories/unreviewed/2025/01/GHSA-gp5f-6cr8-73qf/GHSA-gp5f-6cr8-73qf.json index c48f13d17c4..489cbd0af65 100644 --- a/advisories/unreviewed/2025/01/GHSA-gp5f-6cr8-73qf/GHSA-gp5f-6cr8-73qf.json +++ b/advisories/unreviewed/2025/01/GHSA-gp5f-6cr8-73qf/GHSA-gp5f-6cr8-73qf.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-h384-cwqp-rc8x/GHSA-h384-cwqp-rc8x.json b/advisories/unreviewed/2025/01/GHSA-h384-cwqp-rc8x/GHSA-h384-cwqp-rc8x.json index 55b38a8f4e3..19277bc6757 100644 --- a/advisories/unreviewed/2025/01/GHSA-h384-cwqp-rc8x/GHSA-h384-cwqp-rc8x.json +++ b/advisories/unreviewed/2025/01/GHSA-h384-cwqp-rc8x/GHSA-h384-cwqp-rc8x.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-xm5v-9fv3-x7gp/GHSA-xm5v-9fv3-x7gp.json b/advisories/unreviewed/2025/01/GHSA-xm5v-9fv3-x7gp/GHSA-xm5v-9fv3-x7gp.json index fc56344f1ca..78957aae5b2 100644 --- a/advisories/unreviewed/2025/01/GHSA-xm5v-9fv3-x7gp/GHSA-xm5v-9fv3-x7gp.json +++ b/advisories/unreviewed/2025/01/GHSA-xm5v-9fv3-x7gp/GHSA-xm5v-9fv3-x7gp.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/02/GHSA-244c-33wx-j66j/GHSA-244c-33wx-j66j.json b/advisories/unreviewed/2025/02/GHSA-244c-33wx-j66j/GHSA-244c-33wx-j66j.json new file mode 100644 index 00000000000..eaa0ab7e892 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-244c-33wx-j66j/GHSA-244c-33wx-j66j.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-244c-33wx-j66j", + "modified": "2025-02-07T15:32:38Z", + "published": "2025-02-07T15:32:38Z", + "aliases": [ + "CVE-2025-1103" + ], + "details": "A vulnerability, which was classified as problematic, was found in D-Link DIR-823X 240126/240802. This affects the function set_wifi_blacklists of the file /goform/set_wifi_blacklists of the component HTTP POST Request Handler. The manipulation of the argument macList leads to null pointer dereference. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1103" + }, + { + "type": "WEB", + "url": "https://tasty-foxtrot-3a8.notion.site/D-link-DIR-823X-set_wifi_blacklists-Vulnerability-1870448e619580e5bf09cf628692f7a9?pvs=73" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.294933" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.294933" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.489603" + }, + { + "type": "WEB", + "url": "https://www.dlink.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-404" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-07T15:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-24xj-r6rg-2w25/GHSA-24xj-r6rg-2w25.json b/advisories/unreviewed/2025/02/GHSA-24xj-r6rg-2w25/GHSA-24xj-r6rg-2w25.json new file mode 100644 index 00000000000..abe2167faee --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-24xj-r6rg-2w25/GHSA-24xj-r6rg-2w25.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-24xj-r6rg-2w25", + "modified": "2025-02-07T15:32:38Z", + "published": "2025-02-07T15:32:38Z", + "aliases": [ + "CVE-2025-1107" + ], + "details": "Unverified password change vulnerability in Janto, versions prior to r12. This could allow an unauthenticated attacker to change another user's password without knowing their current password. To exploit the vulnerability, the attacker must create a specific POST request and send it to the endpoint ‘/public/cgi/Gateway.php’.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1107" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-janto" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-620" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-07T14:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-39qw-3w3g-23pr/GHSA-39qw-3w3g-23pr.json b/advisories/unreviewed/2025/02/GHSA-39qw-3w3g-23pr/GHSA-39qw-3w3g-23pr.json index 6a63e0d0f5e..d603ef2488b 100644 --- a/advisories/unreviewed/2025/02/GHSA-39qw-3w3g-23pr/GHSA-39qw-3w3g-23pr.json +++ b/advisories/unreviewed/2025/02/GHSA-39qw-3w3g-23pr/GHSA-39qw-3w3g-23pr.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/02/GHSA-4532-vfvw-gggp/GHSA-4532-vfvw-gggp.json b/advisories/unreviewed/2025/02/GHSA-4532-vfvw-gggp/GHSA-4532-vfvw-gggp.json index a454dcc5455..48469de2965 100644 --- a/advisories/unreviewed/2025/02/GHSA-4532-vfvw-gggp/GHSA-4532-vfvw-gggp.json +++ b/advisories/unreviewed/2025/02/GHSA-4532-vfvw-gggp/GHSA-4532-vfvw-gggp.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/02/GHSA-653f-cqjv-rwfp/GHSA-653f-cqjv-rwfp.json b/advisories/unreviewed/2025/02/GHSA-653f-cqjv-rwfp/GHSA-653f-cqjv-rwfp.json index 2398f8ef8f4..194eb3f9594 100644 --- a/advisories/unreviewed/2025/02/GHSA-653f-cqjv-rwfp/GHSA-653f-cqjv-rwfp.json +++ b/advisories/unreviewed/2025/02/GHSA-653f-cqjv-rwfp/GHSA-653f-cqjv-rwfp.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/02/GHSA-7gpw-jmcm-r9vh/GHSA-7gpw-jmcm-r9vh.json b/advisories/unreviewed/2025/02/GHSA-7gpw-jmcm-r9vh/GHSA-7gpw-jmcm-r9vh.json new file mode 100644 index 00000000000..2e1c2bae40c --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-7gpw-jmcm-r9vh/GHSA-7gpw-jmcm-r9vh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7gpw-jmcm-r9vh", + "modified": "2025-02-07T15:32:38Z", + "published": "2025-02-07T15:32:38Z", + "aliases": [ + "CVE-2025-1108" + ], + "details": "Insufficient data authenticity verification vulnerability in Janto, versions prior to r12. This allows an unauthenticated attacker to modify the content of emails sent to reset the password. To exploit the vulnerability, the attacker must create a POST request by injecting malicious content into the ‘Xml’ parameter on the ‘/public/cgi/Gateway.php’ endpoint.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1108" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-janto" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-345" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-07T14:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-fp9p-7hx8-xfp3/GHSA-fp9p-7hx8-xfp3.json b/advisories/unreviewed/2025/02/GHSA-fp9p-7hx8-xfp3/GHSA-fp9p-7hx8-xfp3.json new file mode 100644 index 00000000000..5d76bdd71a7 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-fp9p-7hx8-xfp3/GHSA-fp9p-7hx8-xfp3.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fp9p-7hx8-xfp3", + "modified": "2025-02-07T15:32:38Z", + "published": "2025-02-07T15:32:38Z", + "aliases": [ + "CVE-2025-25069" + ], + "details": "A Cross-Protocol Scripting vulnerability is found in Apache Kvrocks.\n\nSince Kvrocks didn't detect if \"Host:\" or \"POST\" appears in RESP requests,\na valid HTTP request can also be sent to Kvrocks as a valid RESP request \nand trigger some database operations, which can be dangerous when \nit is chained with SSRF.\n\nIt is similiar to CVE-2016-10517 in Redis.\n\nThis issue affects Apache Kvrocks: from the initial version to the latest version 2.11.0.\n\nUsers are recommended to upgrade to version 2.11.1, which fixes the issue.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25069" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/gbxv9gpsskmdzg6z48zm3tvo8cyo9v3t" + }, + { + "type": "WEB", + "url": "https://www.cve.org/CVERecord?id=CVE-2016-10517" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-115" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-07T13:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-g7f5-75x6-qxhr/GHSA-g7f5-75x6-qxhr.json b/advisories/unreviewed/2025/02/GHSA-g7f5-75x6-qxhr/GHSA-g7f5-75x6-qxhr.json new file mode 100644 index 00000000000..a2b565c7bd6 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-g7f5-75x6-qxhr/GHSA-g7f5-75x6-qxhr.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g7f5-75x6-qxhr", + "modified": "2025-02-07T15:32:38Z", + "published": "2025-02-07T15:32:38Z", + "aliases": [ + "CVE-2024-35106" + ], + "details": "NEXTU FLETA AX1500 WIFI6 v1.0.3 was discovered to contain a buffer overflow at /boafrm/formIpQoS. This vulnerability allows attackers to cause a Denial of Service (DoS) or potentially arbitrary code execution via a crafted POST request.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-35106" + }, + { + "type": "WEB", + "url": "https://ez-net.co.kr/new_2012/customer/download_view.php?cid=&sid=&goods=&cate=&q=&seq=233" + }, + { + "type": "WEB", + "url": "https://ez-net.co.kr/new_2012/product/view.php?cid=461&sid=467&q=%C7%C3%B7%B9%C5%B8&seq=3479&page=" + }, + { + "type": "WEB", + "url": "https://gist.github.com/laskdjlaskdj12/571db73f18be1da1271fa1eb09f488de" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-07T15:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-pf57-w53p-jcw8/GHSA-pf57-w53p-jcw8.json b/advisories/unreviewed/2025/02/GHSA-pf57-w53p-jcw8/GHSA-pf57-w53p-jcw8.json index 99d2a7d823a..79d7048558d 100644 --- a/advisories/unreviewed/2025/02/GHSA-pf57-w53p-jcw8/GHSA-pf57-w53p-jcw8.json +++ b/advisories/unreviewed/2025/02/GHSA-pf57-w53p-jcw8/GHSA-pf57-w53p-jcw8.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/02/GHSA-v575-96v9-gxhw/GHSA-v575-96v9-gxhw.json b/advisories/unreviewed/2025/02/GHSA-v575-96v9-gxhw/GHSA-v575-96v9-gxhw.json new file mode 100644 index 00000000000..0b939494ec5 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-v575-96v9-gxhw/GHSA-v575-96v9-gxhw.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v575-96v9-gxhw", + "modified": "2025-02-07T15:32:38Z", + "published": "2025-02-07T15:32:38Z", + "aliases": [ + "CVE-2024-10383" + ], + "details": "An issue has been discovered in the gitlab-web-ide-vscode-fork component distributed over CDN affecting all versions prior to 1.89.1-1.0.0-dev-20241118094343and used by all versions of GitLab CE/EE starting from 15.11 prior to 17.3 and which also temporarily affected versions 17.4, 17.5 and 17.6, where a XSS attack was possible when loading .ipynb files in the web IDE", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10383" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2765778" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/500785" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-07T15:15:16Z" + } +} \ No newline at end of file