From 28ceb290f07212d013b4980b72acf5a7b52e32c7 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 21 Jan 2025 18:34:21 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-hrw6-wg82-cm62.json | 6 ++- .../GHSA-88g2-r9rw-g55h.json | 8 ++-- .../GHSA-c9p4-xwr9-rfhx.json | 16 +++++-- .../GHSA-36qv-62j7-22cf.json | 29 ++++++++++++ .../GHSA-3723-f7xr-2xgj.json | 15 +++++-- .../GHSA-3w84-2h42-qpcw.json | 15 +++++-- .../GHSA-3wjr-3jc2-hr84.json | 15 +++++-- .../GHSA-45wg-59j7-h44g.json | 3 +- .../GHSA-4mfx-6h3r-r7mp.json | 15 +++++-- .../GHSA-53qp-hx3p-8597.json | 36 +++++++++++++++ .../GHSA-5c2x-vx3w-4336.json | 29 ++++++++++++ .../GHSA-5j5x-6785-5fjj.json | 36 +++++++++++++++ .../GHSA-5jhr-4x98-9wjx.json | 36 +++++++++++++++ .../GHSA-79w5-r7g9-r55c.json | 25 +++++++++++ .../GHSA-7q6q-ppp8-9gr5.json | 15 +++++-- .../GHSA-7xfj-4r7x-3733.json | 4 +- .../GHSA-97x5-rp6h-94f8.json | 15 +++++-- .../GHSA-9hqq-vgv6-6grq.json | 36 +++++++++++++++ .../GHSA-9m9x-x6r9-j7rq.json | 15 +++++-- .../GHSA-c5gc-hxmh-64hw.json | 15 +++++-- .../GHSA-c96m-hgv3-chpf.json | 15 +++++-- .../GHSA-c9qq-2xc2-vwcc.json | 36 +++++++++++++++ .../GHSA-cj3x-jjvf-5f5m.json | 15 +++++-- .../GHSA-cp68-4943-vr56.json | 36 +++++++++++++++ .../GHSA-cpff-m354-g6jw.json | 15 +++++-- .../GHSA-cpjm-qvw2-3w53.json | 36 +++++++++++++++ .../GHSA-crr7-2r98-gqm3.json | 15 +++++-- .../GHSA-fc9m-wjm7-wj8r.json | 36 +++++++++++++++ .../GHSA-fpv2-wmww-mxc8.json | 15 +++++-- .../GHSA-fv6j-x52x-7r32.json | 15 +++++-- .../GHSA-g244-x9gp-5m7r.json | 15 +++++-- .../GHSA-g5wq-3r27-v2x7.json | 15 +++++-- .../GHSA-gvh3-4cff-qfpj.json | 11 +++-- .../GHSA-h3c4-5g8f-wf66.json | 15 +++++-- .../GHSA-h874-6j2r-6vjv.json | 15 +++++-- .../GHSA-h8r3-h3c2-pp25.json | 15 +++++-- .../GHSA-h9xv-3v8q-frmv.json | 36 +++++++++++++++ .../GHSA-hfvx-6m6q-5rc7.json | 36 +++++++++++++++ .../GHSA-jhgr-2wpg-7p64.json | 15 +++++-- .../GHSA-jvqm-w56m-w3j7.json | 15 +++++-- .../GHSA-m2vc-489v-fqrc.json | 36 +++++++++++++++ .../GHSA-m4r5-mmhc-jr9f.json | 15 +++++-- .../GHSA-m643-p29m-frx3.json | 36 +++++++++++++++ .../GHSA-mqh5-c2wx-v3pq.json | 44 +++++++++++++++++++ .../GHSA-p92f-q723-jhvq.json | 15 +++++-- .../GHSA-p9jm-mj56-jwpj.json | 36 +++++++++++++++ .../GHSA-q4cc-rq78-hxf8.json | 15 +++++-- .../GHSA-qpr8-gfg5-hxvp.json | 29 ++++++++++++ .../GHSA-qw9x-8r88-2mfq.json | 36 +++++++++++++++ .../GHSA-qxf9-65gj-mxj8.json | 15 +++++-- .../GHSA-r5c9-3mr5-pgp3.json | 3 +- .../GHSA-r5f2-868j-cr9c.json | 36 +++++++++++++++ .../GHSA-v298-p3h5-pc6r.json | 15 +++++-- .../GHSA-v33x-q5jf-g6v4.json | 36 +++++++++++++++ .../GHSA-v5rq-wfmw-7555.json | 15 +++++-- .../GHSA-vc2j-xx32-6w44.json | 29 ++++++++++++ .../GHSA-vmrg-cw8w-fp9r.json | 36 +++++++++++++++ .../GHSA-vww6-44f5-r4h4.json | 15 +++++-- .../GHSA-w287-9q69-3hx9.json | 22 +++++++++- .../GHSA-w28c-hqg3-44gm.json | 15 +++++-- .../GHSA-w373-phfp-m2jq.json | 15 +++++-- .../GHSA-w38q-r3wf-fqwx.json | 36 +++++++++++++++ .../GHSA-w7pq-rmwm-c759.json | 15 +++++-- .../GHSA-wpfp-cm49-9m9q.json | 36 +++++++++++++++ .../GHSA-wqqf-h2wr-4487.json | 36 +++++++++++++++ .../GHSA-xgj7-v3ff-h29v.json | 29 ++++++++++++ .../GHSA-xm36-ph36-7r35.json | 15 +++++-- .../GHSA-xmg9-vq9f-g4cr.json | 15 +++++-- .../GHSA-xmr9-3j8w-v8gw.json | 15 +++++-- 69 files changed, 1366 insertions(+), 151 deletions(-) create mode 100644 advisories/unreviewed/2025/01/GHSA-36qv-62j7-22cf/GHSA-36qv-62j7-22cf.json create mode 100644 advisories/unreviewed/2025/01/GHSA-53qp-hx3p-8597/GHSA-53qp-hx3p-8597.json create mode 100644 advisories/unreviewed/2025/01/GHSA-5c2x-vx3w-4336/GHSA-5c2x-vx3w-4336.json create mode 100644 advisories/unreviewed/2025/01/GHSA-5j5x-6785-5fjj/GHSA-5j5x-6785-5fjj.json create mode 100644 advisories/unreviewed/2025/01/GHSA-5jhr-4x98-9wjx/GHSA-5jhr-4x98-9wjx.json create mode 100644 advisories/unreviewed/2025/01/GHSA-79w5-r7g9-r55c/GHSA-79w5-r7g9-r55c.json create mode 100644 advisories/unreviewed/2025/01/GHSA-9hqq-vgv6-6grq/GHSA-9hqq-vgv6-6grq.json create mode 100644 advisories/unreviewed/2025/01/GHSA-c9qq-2xc2-vwcc/GHSA-c9qq-2xc2-vwcc.json create mode 100644 advisories/unreviewed/2025/01/GHSA-cp68-4943-vr56/GHSA-cp68-4943-vr56.json create mode 100644 advisories/unreviewed/2025/01/GHSA-cpjm-qvw2-3w53/GHSA-cpjm-qvw2-3w53.json create mode 100644 advisories/unreviewed/2025/01/GHSA-fc9m-wjm7-wj8r/GHSA-fc9m-wjm7-wj8r.json create mode 100644 advisories/unreviewed/2025/01/GHSA-h9xv-3v8q-frmv/GHSA-h9xv-3v8q-frmv.json create mode 100644 advisories/unreviewed/2025/01/GHSA-hfvx-6m6q-5rc7/GHSA-hfvx-6m6q-5rc7.json create mode 100644 advisories/unreviewed/2025/01/GHSA-m2vc-489v-fqrc/GHSA-m2vc-489v-fqrc.json create mode 100644 advisories/unreviewed/2025/01/GHSA-m643-p29m-frx3/GHSA-m643-p29m-frx3.json create mode 100644 advisories/unreviewed/2025/01/GHSA-mqh5-c2wx-v3pq/GHSA-mqh5-c2wx-v3pq.json create mode 100644 advisories/unreviewed/2025/01/GHSA-p9jm-mj56-jwpj/GHSA-p9jm-mj56-jwpj.json create mode 100644 advisories/unreviewed/2025/01/GHSA-qpr8-gfg5-hxvp/GHSA-qpr8-gfg5-hxvp.json create mode 100644 advisories/unreviewed/2025/01/GHSA-qw9x-8r88-2mfq/GHSA-qw9x-8r88-2mfq.json create mode 100644 advisories/unreviewed/2025/01/GHSA-r5f2-868j-cr9c/GHSA-r5f2-868j-cr9c.json create mode 100644 advisories/unreviewed/2025/01/GHSA-v33x-q5jf-g6v4/GHSA-v33x-q5jf-g6v4.json create mode 100644 advisories/unreviewed/2025/01/GHSA-vc2j-xx32-6w44/GHSA-vc2j-xx32-6w44.json create mode 100644 advisories/unreviewed/2025/01/GHSA-vmrg-cw8w-fp9r/GHSA-vmrg-cw8w-fp9r.json create mode 100644 advisories/unreviewed/2025/01/GHSA-w38q-r3wf-fqwx/GHSA-w38q-r3wf-fqwx.json create mode 100644 advisories/unreviewed/2025/01/GHSA-wpfp-cm49-9m9q/GHSA-wpfp-cm49-9m9q.json create mode 100644 advisories/unreviewed/2025/01/GHSA-wqqf-h2wr-4487/GHSA-wqqf-h2wr-4487.json create mode 100644 advisories/unreviewed/2025/01/GHSA-xgj7-v3ff-h29v/GHSA-xgj7-v3ff-h29v.json diff --git a/advisories/github-reviewed/2024/06/GHSA-hrw6-wg82-cm62/GHSA-hrw6-wg82-cm62.json b/advisories/github-reviewed/2024/06/GHSA-hrw6-wg82-cm62/GHSA-hrw6-wg82-cm62.json index 9f148a8781f..af34eb79056 100644 --- a/advisories/github-reviewed/2024/06/GHSA-hrw6-wg82-cm62/GHSA-hrw6-wg82-cm62.json +++ b/advisories/github-reviewed/2024/06/GHSA-hrw6-wg82-cm62/GHSA-hrw6-wg82-cm62.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hrw6-wg82-cm62", - "modified": "2024-06-06T21:26:53Z", + "modified": "2025-01-21T18:32:05Z", "published": "2024-06-06T21:26:53Z", "aliases": [ "CVE-2024-35178" @@ -54,6 +54,10 @@ { "type": "PACKAGE", "url": "https://github.com/jupyter-server/jupyter_server" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/jupyter-server/PYSEC-2024-165.yaml" } ], "database_specific": { diff --git a/advisories/github-reviewed/2024/08/GHSA-88g2-r9rw-g55h/GHSA-88g2-r9rw-g55h.json b/advisories/github-reviewed/2024/08/GHSA-88g2-r9rw-g55h/GHSA-88g2-r9rw-g55h.json index 2a77c4e2430..53dfefd9144 100644 --- a/advisories/github-reviewed/2024/08/GHSA-88g2-r9rw-g55h/GHSA-88g2-r9rw-g55h.json +++ b/advisories/github-reviewed/2024/08/GHSA-88g2-r9rw-g55h/GHSA-88g2-r9rw-g55h.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-88g2-r9rw-g55h", - "modified": "2024-11-25T13:49:13Z", + "modified": "2025-01-21T18:31:55Z", "published": "2024-08-22T16:41:28Z", "aliases": [ "CVE-2024-43785" ], "summary": "gitoxide-core does not neutralize special characters for terminals", - "details": "### Summary\n\nThe `gix` and `ein` commands write pathnames and other metadata literally to terminals, even if they contain characters terminals treat specially, including ANSI escape sequences. This sometimes allows an untrusted repository to misrepresent its contents and to alter or concoct error messages.\n\n### Details\n\n`gitoxide-core`, which provides most underlying functionality of the `gix` and `ein` commands, does not neutralize newlines, backspaces, or control characters—including those that form ANSI escape sequences—that appear in a repository's paths, author and committer names, commit messages, or other metadata. Such text may be written as part of the output of a command, as well as appearing in error messages when an operation fails.\n\nANSI escape sequences are of particular concern because, when printed to a terminal, they can change colors, including to render subsequent text unreadable; reposition the cursor to write text in a different location, including where text has already been written; clear the terminal; set the terminal title-bar text to arbitrary values; render the terminal temporarily unusable; and other such operations.\n\nThe effect is mostly an annoyance. But the author of a malicious repository who can predict how information from the repository may be accessed can cause files in the repository to be concealed or otherwise misrepresented, as well as rewrite all or part of error messages, or mimic error messages convincingly by repositioning the cursor and writing colored text.\n\n### PoC\n\nOn a Unix-like system in a POSIX-compatible shell, run:\n\n```sh\ngit init misleading-path\ncd misleading-path\ntouch \"$(printf '\\033]0;Boo!\\007\\033[2K\\r\\033[91mError: Repository is corrupted. Run \\033[96mEVIL_COMMAND\\033[91m to attempt recovery.\\033[0m')\"\ngit add .\ngit commit -m 'Initial commit'\n```\n\nIn the repository—or, if desired, in a clone of it, to show that this is exploitable by getting a user to clone an untrusted repository—run this command, which outputs entries in a three-column form showing type, hash, and filename:\n\n```sh\ngix tree entries\n```\n\nAlthough the output is of that form, it does not appear to be. Instead, the output in a terminal looks like this, colorized to appear to be an error message, with `EVIL_COMMAND` in another color, and with no other text:\n\n```text\nError: Repository is corrupted. Run EVIL_COMMAND to attempt recovery.\n```\n\nIn some terminals, a beep or other sound will be made. In most terminals, the title bar text will be changed to `Boo!`, though in some shells this may be immediately undone when printing the prompt. These elements are included to showcase the abilities of ANSI escape sequences, but they are not usually themselves threats.\n\nTo see what is actually produced, `gix tree entries` can be piped to a command that displays special characters symbolically, such as `less` or `cat -v` if available.\n\n```text\nBLOB e69de29bb2d1d6434b8b29ae775ad8c2e48c5391 ESC]0;Boo!^GESC[2K^MESC[91mError: Repository is corrupted. Run ESC[96mEVIL_COMMANDESC[91m to attempt recovery.ESC[0m\n```\n\nThat shows the effect on `gix tree entries`, but various other commands are also affected, and the escape sequences and other special characters can also appear in non-path metadata, such as in the `user.name` used to create a commit.\n\n### Impact\n\nFor users who do not clone or operate in clones of untrusted repositories, there is no impact.\n\nWindows is much less affected than Unix-like systems due to limitations on what characters can appear in filenames, and because traditionally Windows terminals do not support as many ANSI escape sequences.\n\nBecause different `gix` and `ein` commands display different data in different formats, the author of a malicious repository must guess how it will be used, which complicates crafting truly convincing output, though it may be possible to craft a repository where `gix clone` fails to clone it but produces a misleading message.\n\nAlthough this is mainly exploitable on systems *other* than Windows, in the ability to produce misleading output this superficially resembles CVE-2024-35197. But this is much more limited, because:\n\n- The misleading output can only be made to go where the application is already sending output. Redirection is not defeated, and devices to access cannot be chosen by the attacker.\n- The misleading output can only be take place *when* the application is already producing output. This limitation complicates the production of believable messages.\n- Only terminals are affected. Even if a standard stream is redirected to another file or device, these special characters would not have a special effect, unless echoed later without sanitization.\n- Reading and blocking cannot be performed.\n- Applications other than the gitoxide `gix` and `ein` executables are unaffected. The exception is if another application uses `gitoxide-core`. But this is explicitly discouraged in the `gitoxide-core` documentation and is believed to be rare.", + "details": "### Summary\n\nThe `gix` and `ein` commands write pathnames and other metadata literally to terminals, even if they contain characters terminals treat specially, including ANSI escape sequences. This sometimes allows an untrusted repository to misrepresent its contents and to alter or concoct error messages.\n\n### Details\n\n`gitoxide-core`, which provides most underlying functionality of the `gix` and `ein` commands, does not neutralize newlines, backspaces, or control characters—including those that form ANSI escape sequences—that appear in a repository's paths, author and committer names, commit messages, or other metadata. Such text may be written as part of the output of a command, as well as appearing in error messages when an operation fails.\n\nANSI escape sequences are of particular concern because, when printed to a terminal, they can change colors, including to render subsequent text unreadable; reposition the cursor to write text in a different location, including where text has already been written; clear the terminal; set the terminal title-bar text to arbitrary values; render the terminal temporarily unusable; and other such operations.\n\nThe effect is mostly an annoyance. But the author of a malicious repository who can predict how information from the repository may be accessed can cause files in the repository to be concealed or otherwise misrepresented, as well as rewrite all or part of error messages, or mimic error messages convincingly by repositioning the cursor and writing colored text.\n\n### PoC\n\nOn a Unix-like system in a POSIX-compatible shell, run:\n\n```sh\ngit init misleading-path\ncd misleading-path\ntouch \"$(printf '\\033]0;Boo!\\007\\033[2K\\r\\033[91mError: Repository is corrupted. Run \\033[96mEVIL_COMMAND\\033[91m to attempt recovery.\\033[0m')\"\ngit add .\ngit commit -m 'Initial commit'\n```\n\nIn the repository—or, if desired, in a clone of it, to show that this is exploitable by getting a user to clone an untrusted repository—run this command, which outputs entries in a three-column form showing type, hash, and filename:\n\n```sh\ngix tree entries\n```\n\nAlthough the output is of that form, it does not appear to be. Instead, the output in a terminal looks like this, colorized to appear to be an error message, with `EVIL_COMMAND` in another color, and with no other text:\n\n```text\nError: Repository is corrupted. Run EVIL_COMMAND to attempt recovery.\n```\n\nIn some terminals, a beep or other sound will be made. In most terminals, the title bar text will be changed to `Boo!`, though in some shells this may be immediately undone when printing the prompt. These elements are included to showcase the abilities of ANSI escape sequences, but they are not usually themselves threats.\n\nTo see what is actually produced, `gix tree entries` can be piped to a command that displays special characters symbolically, such as `less` or `cat -v` if available.\n\n```text\nBLOB e69de29bb2d1d6434b8b29ae775ad8c2e48c5391 ESC]0;Boo!^GESC[2K^MESC[91mError: Repository is corrupted. Run ESC[96mEVIL_COMMANDESC[91m to attempt recovery.ESC[0m\n```\n\nThat shows the effect on `gix tree entries`, but various other commands are also affected, and the escape sequences and other special characters can also appear in non-path metadata, such as in the `user.name` used to create a commit.\n\n### Impact\n\nFor users who do not clone or operate in clones of untrusted repositories, there is no impact.\nWindows is much less affected than Unix-like systems due to limitations on what characters can appear in filenames, and because traditionally Windows terminals do not support as many ANSI escape sequences.\n\nBecause different `gix` and `ein` commands display different data in different formats, the author of a malicious repository must guess how it will be used, which complicates crafting truly convincing output, though it may be possible to craft a repository where `gix clone` fails to clone it but produces a misleading message.\n\nAlthough this is mainly exploitable on systems *other* than Windows, in the ability to produce misleading output this superficially resembles CVE-2024-35197. But this is much more limited, because:\n\n- The misleading output can only be made to go where the application is already sending output. Redirection is not defeated, and devices to access cannot be chosen by the attacker.\n- The misleading output can only be take place *when* the application is already producing output. This limitation complicates the production of believable messages.\n- Only terminals are affected. Even if a standard stream is redirected to another file or device, these special characters would not have a special effect, unless echoed later without sanitization.\n- Reading and blocking cannot be performed.\n- Applications other than the gitoxide `gix` and `ein` executables are unaffected. The exception is if another application uses `gitoxide-core`. But this is explicitly discouraged in the `gitoxide-core` documentation and is believed to be rare.", "severity": [ { "type": "CVSS_V3", @@ -32,7 +32,7 @@ "introduced": "0" }, { - "last_affected": "0.43.0" + "last_affected": "0.45.0" } ] } @@ -51,7 +51,7 @@ "introduced": "0" }, { - "last_affected": "0.39.0" + "last_affected": "0.41.0" } ] } diff --git a/advisories/github-reviewed/2025/01/GHSA-c9p4-xwr9-rfhx/GHSA-c9p4-xwr9-rfhx.json b/advisories/github-reviewed/2025/01/GHSA-c9p4-xwr9-rfhx/GHSA-c9p4-xwr9-rfhx.json index bd4f05fd12f..faee0e84aea 100644 --- a/advisories/github-reviewed/2025/01/GHSA-c9p4-xwr9-rfhx/GHSA-c9p4-xwr9-rfhx.json +++ b/advisories/github-reviewed/2025/01/GHSA-c9p4-xwr9-rfhx/GHSA-c9p4-xwr9-rfhx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c9p4-xwr9-rfhx", - "modified": "2025-01-17T22:16:46Z", + "modified": "2025-01-21T18:31:05Z", "published": "2025-01-17T22:02:26Z", "aliases": [ "CVE-2025-23208" @@ -43,6 +43,10 @@ "type": "WEB", "url": "https://github.com/project-zot/zot/security/advisories/GHSA-c9p4-xwr9-rfhx" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23208" + }, { "type": "WEB", "url": "https://github.com/project-zot/zot/commit/002ac62d8a15bf0cba010b3ba7bde86f9837b613" @@ -50,13 +54,19 @@ { "type": "PACKAGE", "url": "https://github.com/project-zot/zot" + }, + { + "type": "WEB", + "url": "https://github.com/project-zot/zot/blob/5e30fec65c49e3139907e2819ccb39b2e3bd784e/pkg/meta/boltdb/boltdb.go#L1665" } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-269" + ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2025-01-17T22:02:26Z", - "nvd_published_at": null + "nvd_published_at": "2025-01-17T23:15:13Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-36qv-62j7-22cf/GHSA-36qv-62j7-22cf.json b/advisories/unreviewed/2025/01/GHSA-36qv-62j7-22cf/GHSA-36qv-62j7-22cf.json new file mode 100644 index 00000000000..a4d41f8ac79 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-36qv-62j7-22cf/GHSA-36qv-62j7-22cf.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-36qv-62j7-22cf", + "modified": "2025-01-21T18:31:07Z", + "published": "2025-01-21T18:31:07Z", + "aliases": [ + "CVE-2024-54794" + ], + "details": "The script input feature of SpagoBI 3.5.1 allows arbitrary code execution.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54794" + }, + { + "type": "WEB", + "url": "https://github.com/MarioTesoro/CVE-2024-54794" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T18:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-3723-f7xr-2xgj/GHSA-3723-f7xr-2xgj.json b/advisories/unreviewed/2025/01/GHSA-3723-f7xr-2xgj/GHSA-3723-f7xr-2xgj.json index b36b9fa6fce..edd4b73d278 100644 --- a/advisories/unreviewed/2025/01/GHSA-3723-f7xr-2xgj/GHSA-3723-f7xr-2xgj.json +++ b/advisories/unreviewed/2025/01/GHSA-3723-f7xr-2xgj/GHSA-3723-f7xr-2xgj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3723-f7xr-2xgj", - "modified": "2025-01-17T21:31:39Z", + "modified": "2025-01-21T18:31:06Z", "published": "2025-01-17T21:31:39Z", "aliases": [ "CVE-2024-57032" ], "details": "WeGIA < 3.2.0 is vulnerable to Incorrect Access Control in controle/control.php. The application does not validate the value of the old password, so it is possible to change the password by placing any value in the senha_antiga field.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-276" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-17T20:15:28Z" diff --git a/advisories/unreviewed/2025/01/GHSA-3w84-2h42-qpcw/GHSA-3w84-2h42-qpcw.json b/advisories/unreviewed/2025/01/GHSA-3w84-2h42-qpcw/GHSA-3w84-2h42-qpcw.json index 8d903b440b8..ae1bce078e8 100644 --- a/advisories/unreviewed/2025/01/GHSA-3w84-2h42-qpcw/GHSA-3w84-2h42-qpcw.json +++ b/advisories/unreviewed/2025/01/GHSA-3w84-2h42-qpcw/GHSA-3w84-2h42-qpcw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3w84-2h42-qpcw", - "modified": "2025-01-18T00:30:48Z", + "modified": "2025-01-21T18:31:07Z", "published": "2025-01-18T00:30:48Z", "aliases": [ "CVE-2018-9384" ], "details": "In multiple locations, there is a possible way to bypass KASLR due to an unusual root cause. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-17T23:15:12Z" diff --git a/advisories/unreviewed/2025/01/GHSA-3wjr-3jc2-hr84/GHSA-3wjr-3jc2-hr84.json b/advisories/unreviewed/2025/01/GHSA-3wjr-3jc2-hr84/GHSA-3wjr-3jc2-hr84.json index 4d92928df46..ff944d36e1d 100644 --- a/advisories/unreviewed/2025/01/GHSA-3wjr-3jc2-hr84/GHSA-3wjr-3jc2-hr84.json +++ b/advisories/unreviewed/2025/01/GHSA-3wjr-3jc2-hr84/GHSA-3wjr-3jc2-hr84.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3wjr-3jc2-hr84", - "modified": "2025-01-16T18:31:00Z", + "modified": "2025-01-21T18:31:06Z", "published": "2025-01-16T18:31:00Z", "aliases": [ "CVE-2024-57772" ], "details": "A cross-site scripting (XSS) vulnerability in the /bumph/getDraftListPage?type interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-16T18:15:26Z" diff --git a/advisories/unreviewed/2025/01/GHSA-45wg-59j7-h44g/GHSA-45wg-59j7-h44g.json b/advisories/unreviewed/2025/01/GHSA-45wg-59j7-h44g/GHSA-45wg-59j7-h44g.json index dd63e359e93..495c029bcc8 100644 --- a/advisories/unreviewed/2025/01/GHSA-45wg-59j7-h44g/GHSA-45wg-59j7-h44g.json +++ b/advisories/unreviewed/2025/01/GHSA-45wg-59j7-h44g/GHSA-45wg-59j7-h44g.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-4mfx-6h3r-r7mp/GHSA-4mfx-6h3r-r7mp.json b/advisories/unreviewed/2025/01/GHSA-4mfx-6h3r-r7mp/GHSA-4mfx-6h3r-r7mp.json index 821c85d3e1c..53d4e4c61cf 100644 --- a/advisories/unreviewed/2025/01/GHSA-4mfx-6h3r-r7mp/GHSA-4mfx-6h3r-r7mp.json +++ b/advisories/unreviewed/2025/01/GHSA-4mfx-6h3r-r7mp/GHSA-4mfx-6h3r-r7mp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4mfx-6h3r-r7mp", - "modified": "2025-01-16T18:31:00Z", + "modified": "2025-01-21T18:31:06Z", "published": "2025-01-16T18:31:00Z", "aliases": [ "CVE-2024-57773" ], "details": "A cross-site scripting (XSS) vulnerability in the openSelectManyUserPage?orgid interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-16T18:15:27Z" diff --git a/advisories/unreviewed/2025/01/GHSA-53qp-hx3p-8597/GHSA-53qp-hx3p-8597.json b/advisories/unreviewed/2025/01/GHSA-53qp-hx3p-8597/GHSA-53qp-hx3p-8597.json new file mode 100644 index 00000000000..8de2d0757d9 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-53qp-hx3p-8597/GHSA-53qp-hx3p-8597.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-53qp-hx3p-8597", + "modified": "2025-01-21T18:31:07Z", + "published": "2025-01-21T18:31:07Z", + "aliases": [ + "CVE-2025-22722" + ], + "details": "Missing Authorization vulnerability in Widget Options Team Widget Options allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Widget Options: from n/a through 4.0.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22722" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/widget-options/vulnerability/wordpress-widget-options-plugin-4-0-8-broken-access-control-to-notice-dimissal-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T18:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-5c2x-vx3w-4336/GHSA-5c2x-vx3w-4336.json b/advisories/unreviewed/2025/01/GHSA-5c2x-vx3w-4336/GHSA-5c2x-vx3w-4336.json new file mode 100644 index 00000000000..4eb5ee916ef --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-5c2x-vx3w-4336/GHSA-5c2x-vx3w-4336.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5c2x-vx3w-4336", + "modified": "2025-01-21T18:31:07Z", + "published": "2025-01-21T18:31:07Z", + "aliases": [ + "CVE-2024-54792" + ], + "details": "A Cross-Site Request Forgery (CSRF) vulnerability has been found in SpagoBI v3.5.1 in the user administration panel. An authenticated user can lead another user into executing unwanted actions inside the application they are logged in, like adding, editing or deleting users.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54792" + }, + { + "type": "WEB", + "url": "https://github.com/MarioTesoro/CVE-2024-54792" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T18:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-5j5x-6785-5fjj/GHSA-5j5x-6785-5fjj.json b/advisories/unreviewed/2025/01/GHSA-5j5x-6785-5fjj/GHSA-5j5x-6785-5fjj.json new file mode 100644 index 00000000000..0d9da2b2982 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-5j5x-6785-5fjj/GHSA-5j5x-6785-5fjj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5j5x-6785-5fjj", + "modified": "2025-01-21T18:31:08Z", + "published": "2025-01-21T18:31:08Z", + "aliases": [ + "CVE-2025-24457" + ], + "details": "In JetBrains YouTrack before 2024.3.55417 permanent tokens could be exposed in logs", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24457" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T18:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-5jhr-4x98-9wjx/GHSA-5jhr-4x98-9wjx.json b/advisories/unreviewed/2025/01/GHSA-5jhr-4x98-9wjx/GHSA-5jhr-4x98-9wjx.json new file mode 100644 index 00000000000..fd2d8302627 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-5jhr-4x98-9wjx/GHSA-5jhr-4x98-9wjx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5jhr-4x98-9wjx", + "modified": "2025-01-21T18:31:07Z", + "published": "2025-01-21T18:31:07Z", + "aliases": [ + "CVE-2025-23580" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Matthew Garvin BizLibrary allows Reflected XSS. This issue affects BizLibrary: from n/a through 1.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23580" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/bizlibrary/vulnerability/wordpress-bizlibrary-plugin-1-1-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T18:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-79w5-r7g9-r55c/GHSA-79w5-r7g9-r55c.json b/advisories/unreviewed/2025/01/GHSA-79w5-r7g9-r55c/GHSA-79w5-r7g9-r55c.json new file mode 100644 index 00000000000..1470ade2adc --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-79w5-r7g9-r55c/GHSA-79w5-r7g9-r55c.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-79w5-r7g9-r55c", + "modified": "2025-01-21T18:31:07Z", + "published": "2025-01-21T18:31:07Z", + "aliases": [ + "CVE-2025-0623" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0623" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T17:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-7q6q-ppp8-9gr5/GHSA-7q6q-ppp8-9gr5.json b/advisories/unreviewed/2025/01/GHSA-7q6q-ppp8-9gr5/GHSA-7q6q-ppp8-9gr5.json index ea9250c4c73..f073ff05b75 100644 --- a/advisories/unreviewed/2025/01/GHSA-7q6q-ppp8-9gr5/GHSA-7q6q-ppp8-9gr5.json +++ b/advisories/unreviewed/2025/01/GHSA-7q6q-ppp8-9gr5/GHSA-7q6q-ppp8-9gr5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7q6q-ppp8-9gr5", - "modified": "2025-01-15T15:31:24Z", + "modified": "2025-01-21T18:31:05Z", "published": "2025-01-15T15:31:24Z", "aliases": [ "CVE-2024-57801" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: Skip restore TC rules for vport rep without loaded flag\n\nDuring driver unload, unregister_netdev is called after unloading\nvport rep. So, the mlx5e_rep_priv is already freed while trying to get\nrpriv->netdev, or walk rpriv->tc_ht, which results in use-after-free.\nSo add the checking to make sure access the data of vport rep which is\nstill loaded.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-15T13:15:11Z" diff --git a/advisories/unreviewed/2025/01/GHSA-7xfj-4r7x-3733/GHSA-7xfj-4r7x-3733.json b/advisories/unreviewed/2025/01/GHSA-7xfj-4r7x-3733/GHSA-7xfj-4r7x-3733.json index b8154297e19..5016dc52530 100644 --- a/advisories/unreviewed/2025/01/GHSA-7xfj-4r7x-3733/GHSA-7xfj-4r7x-3733.json +++ b/advisories/unreviewed/2025/01/GHSA-7xfj-4r7x-3733/GHSA-7xfj-4r7x-3733.json @@ -41,7 +41,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-347" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-97x5-rp6h-94f8/GHSA-97x5-rp6h-94f8.json b/advisories/unreviewed/2025/01/GHSA-97x5-rp6h-94f8/GHSA-97x5-rp6h-94f8.json index 86abd3dbbd7..3d245ccc1f4 100644 --- a/advisories/unreviewed/2025/01/GHSA-97x5-rp6h-94f8/GHSA-97x5-rp6h-94f8.json +++ b/advisories/unreviewed/2025/01/GHSA-97x5-rp6h-94f8/GHSA-97x5-rp6h-94f8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-97x5-rp6h-94f8", - "modified": "2025-01-18T00:30:48Z", + "modified": "2025-01-21T18:31:06Z", "published": "2025-01-18T00:30:48Z", "aliases": [ "CVE-2018-9382" ], "details": "In multiple functions of WifiServiceImpl.java, there is a possible way to activate Wi-Fi hotspot from a non-owner profile due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-17T23:15:11Z" diff --git a/advisories/unreviewed/2025/01/GHSA-9hqq-vgv6-6grq/GHSA-9hqq-vgv6-6grq.json b/advisories/unreviewed/2025/01/GHSA-9hqq-vgv6-6grq/GHSA-9hqq-vgv6-6grq.json new file mode 100644 index 00000000000..02000c171e7 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9hqq-vgv6-6grq/GHSA-9hqq-vgv6-6grq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9hqq-vgv6-6grq", + "modified": "2025-01-21T18:31:07Z", + "published": "2025-01-21T18:31:07Z", + "aliases": [ + "CVE-2025-23489" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brian Messenlehner of WebDevStudios WP-Announcements allows Reflected XSS. This issue affects WP-Announcements: from n/a through 1.8.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23489" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-announcements/vulnerability/wordpress-wp-announcements-plugin-1-8-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T18:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-9m9x-x6r9-j7rq/GHSA-9m9x-x6r9-j7rq.json b/advisories/unreviewed/2025/01/GHSA-9m9x-x6r9-j7rq/GHSA-9m9x-x6r9-j7rq.json index 679fac10ebf..95bd33def8d 100644 --- a/advisories/unreviewed/2025/01/GHSA-9m9x-x6r9-j7rq/GHSA-9m9x-x6r9-j7rq.json +++ b/advisories/unreviewed/2025/01/GHSA-9m9x-x6r9-j7rq/GHSA-9m9x-x6r9-j7rq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9m9x-x6r9-j7rq", - "modified": "2025-01-18T00:30:48Z", + "modified": "2025-01-21T18:31:07Z", "published": "2025-01-18T00:30:48Z", "aliases": [ "CVE-2018-9405" ], "details": "In BnDmAgent::onTransact of dm_agent.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-18T00:15:24Z" diff --git a/advisories/unreviewed/2025/01/GHSA-c5gc-hxmh-64hw/GHSA-c5gc-hxmh-64hw.json b/advisories/unreviewed/2025/01/GHSA-c5gc-hxmh-64hw/GHSA-c5gc-hxmh-64hw.json index 2405e9728cc..4dd8bd68ce6 100644 --- a/advisories/unreviewed/2025/01/GHSA-c5gc-hxmh-64hw/GHSA-c5gc-hxmh-64hw.json +++ b/advisories/unreviewed/2025/01/GHSA-c5gc-hxmh-64hw/GHSA-c5gc-hxmh-64hw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c5gc-hxmh-64hw", - "modified": "2025-01-15T18:30:58Z", + "modified": "2025-01-21T18:31:06Z", "published": "2025-01-15T18:30:58Z", "aliases": [ "CVE-2024-57025" ], "details": "TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the \"desc\" parameter in setWiFiScheduleCfg.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-78" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-15T17:15:18Z" diff --git a/advisories/unreviewed/2025/01/GHSA-c96m-hgv3-chpf/GHSA-c96m-hgv3-chpf.json b/advisories/unreviewed/2025/01/GHSA-c96m-hgv3-chpf/GHSA-c96m-hgv3-chpf.json index 885fe9ffb2d..f145a6586eb 100644 --- a/advisories/unreviewed/2025/01/GHSA-c96m-hgv3-chpf/GHSA-c96m-hgv3-chpf.json +++ b/advisories/unreviewed/2025/01/GHSA-c96m-hgv3-chpf/GHSA-c96m-hgv3-chpf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c96m-hgv3-chpf", - "modified": "2025-01-15T18:30:58Z", + "modified": "2025-01-21T18:31:06Z", "published": "2025-01-15T18:30:58Z", "aliases": [ "CVE-2024-57023" ], "details": "TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the \"week\" parameter in setWiFiScheduleCfg.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-78" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-15T17:15:18Z" diff --git a/advisories/unreviewed/2025/01/GHSA-c9qq-2xc2-vwcc/GHSA-c9qq-2xc2-vwcc.json b/advisories/unreviewed/2025/01/GHSA-c9qq-2xc2-vwcc/GHSA-c9qq-2xc2-vwcc.json new file mode 100644 index 00000000000..b261697cb5e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-c9qq-2xc2-vwcc/GHSA-c9qq-2xc2-vwcc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c9qq-2xc2-vwcc", + "modified": "2025-01-21T18:31:08Z", + "published": "2025-01-21T18:31:08Z", + "aliases": [ + "CVE-2025-24460" + ], + "details": "In JetBrains TeamCity before 2024.12.1 improper access control allowed to see Projects’ names in the agent pool", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24460" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T18:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-cj3x-jjvf-5f5m/GHSA-cj3x-jjvf-5f5m.json b/advisories/unreviewed/2025/01/GHSA-cj3x-jjvf-5f5m/GHSA-cj3x-jjvf-5f5m.json index 7fe9da231b5..d659d5283c9 100644 --- a/advisories/unreviewed/2025/01/GHSA-cj3x-jjvf-5f5m/GHSA-cj3x-jjvf-5f5m.json +++ b/advisories/unreviewed/2025/01/GHSA-cj3x-jjvf-5f5m/GHSA-cj3x-jjvf-5f5m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cj3x-jjvf-5f5m", - "modified": "2025-01-18T00:30:48Z", + "modified": "2025-01-21T18:31:07Z", "published": "2025-01-18T00:30:48Z", "aliases": [ "CVE-2018-9401" ], "details": "In many locations, there is a possible way to access kernel memory in user space due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-18T00:15:24Z" diff --git a/advisories/unreviewed/2025/01/GHSA-cp68-4943-vr56/GHSA-cp68-4943-vr56.json b/advisories/unreviewed/2025/01/GHSA-cp68-4943-vr56/GHSA-cp68-4943-vr56.json new file mode 100644 index 00000000000..c21c41bb1f7 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-cp68-4943-vr56/GHSA-cp68-4943-vr56.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cp68-4943-vr56", + "modified": "2025-01-21T18:31:07Z", + "published": "2025-01-21T18:31:07Z", + "aliases": [ + "CVE-2025-23477" + ], + "details": "Missing Authorization vulnerability in Realty Workstation Realty Workstation allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Realty Workstation: from n/a through 1.0.45.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23477" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/realty-workstation/vulnerability/wordpress-realty-workstation-plugin-1-0-45-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T18:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-cpff-m354-g6jw/GHSA-cpff-m354-g6jw.json b/advisories/unreviewed/2025/01/GHSA-cpff-m354-g6jw/GHSA-cpff-m354-g6jw.json index cf8f9b47a4e..536c1035d8b 100644 --- a/advisories/unreviewed/2025/01/GHSA-cpff-m354-g6jw/GHSA-cpff-m354-g6jw.json +++ b/advisories/unreviewed/2025/01/GHSA-cpff-m354-g6jw/GHSA-cpff-m354-g6jw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cpff-m354-g6jw", - "modified": "2025-01-18T00:30:48Z", + "modified": "2025-01-21T18:31:06Z", "published": "2025-01-18T00:30:48Z", "aliases": [ "CVE-2018-9375" ], "details": "In multiple functions of UserDictionaryProvider.java, there is a possible way to add and delete words in the user dictionary due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-611" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-17T23:15:11Z" diff --git a/advisories/unreviewed/2025/01/GHSA-cpjm-qvw2-3w53/GHSA-cpjm-qvw2-3w53.json b/advisories/unreviewed/2025/01/GHSA-cpjm-qvw2-3w53/GHSA-cpjm-qvw2-3w53.json new file mode 100644 index 00000000000..039c5954918 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-cpjm-qvw2-3w53/GHSA-cpjm-qvw2-3w53.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cpjm-qvw2-3w53", + "modified": "2025-01-21T18:31:07Z", + "published": "2025-01-21T18:31:07Z", + "aliases": [ + "CVE-2025-23461" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Andrea Dotta, Jacopo Campani, di xkoll.com Social2Blog allows Reflected XSS. This issue affects Social2Blog: from n/a through 0.2.990.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23461" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/social2blog/vulnerability/wordpress-social2blog-plugin-0-2-990-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T18:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-crr7-2r98-gqm3/GHSA-crr7-2r98-gqm3.json b/advisories/unreviewed/2025/01/GHSA-crr7-2r98-gqm3/GHSA-crr7-2r98-gqm3.json index 5dd46c50b28..8bc59e1fca9 100644 --- a/advisories/unreviewed/2025/01/GHSA-crr7-2r98-gqm3/GHSA-crr7-2r98-gqm3.json +++ b/advisories/unreviewed/2025/01/GHSA-crr7-2r98-gqm3/GHSA-crr7-2r98-gqm3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-crr7-2r98-gqm3", - "modified": "2025-01-18T00:30:48Z", + "modified": "2025-01-21T18:31:06Z", "published": "2025-01-18T00:30:48Z", "aliases": [ "CVE-2018-9383" ], "details": "In asn1_ber_decoder of asn1_decoder.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-17T23:15:12Z" diff --git a/advisories/unreviewed/2025/01/GHSA-fc9m-wjm7-wj8r/GHSA-fc9m-wjm7-wj8r.json b/advisories/unreviewed/2025/01/GHSA-fc9m-wjm7-wj8r/GHSA-fc9m-wjm7-wj8r.json new file mode 100644 index 00000000000..481d327d2a7 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-fc9m-wjm7-wj8r/GHSA-fc9m-wjm7-wj8r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fc9m-wjm7-wj8r", + "modified": "2025-01-21T18:31:08Z", + "published": "2025-01-21T18:31:08Z", + "aliases": [ + "CVE-2025-24458" + ], + "details": "In JetBrains YouTrack before 2024.3.55417 account takeover was possible via spoofed email and Helpdesk integration", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24458" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-290" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T18:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-fpv2-wmww-mxc8/GHSA-fpv2-wmww-mxc8.json b/advisories/unreviewed/2025/01/GHSA-fpv2-wmww-mxc8/GHSA-fpv2-wmww-mxc8.json index 41074cd5ce9..eb960b3f4a1 100644 --- a/advisories/unreviewed/2025/01/GHSA-fpv2-wmww-mxc8/GHSA-fpv2-wmww-mxc8.json +++ b/advisories/unreviewed/2025/01/GHSA-fpv2-wmww-mxc8/GHSA-fpv2-wmww-mxc8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fpv2-wmww-mxc8", - "modified": "2025-01-17T21:31:39Z", + "modified": "2025-01-21T18:31:06Z", "published": "2025-01-17T21:31:39Z", "aliases": [ "CVE-2024-57031" ], "details": "WeGIA < 3.2.0 is vulnerable to SQL Injection in /funcionario/remuneracao.php via the id_funcionario parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-17T20:15:28Z" diff --git a/advisories/unreviewed/2025/01/GHSA-fv6j-x52x-7r32/GHSA-fv6j-x52x-7r32.json b/advisories/unreviewed/2025/01/GHSA-fv6j-x52x-7r32/GHSA-fv6j-x52x-7r32.json index 2d250c798e3..d6b7b0a30c6 100644 --- a/advisories/unreviewed/2025/01/GHSA-fv6j-x52x-7r32/GHSA-fv6j-x52x-7r32.json +++ b/advisories/unreviewed/2025/01/GHSA-fv6j-x52x-7r32/GHSA-fv6j-x52x-7r32.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fv6j-x52x-7r32", - "modified": "2025-01-17T21:31:39Z", + "modified": "2025-01-21T18:31:06Z", "published": "2025-01-17T21:31:39Z", "aliases": [ "CVE-2024-57035" ], "details": "WeGIA v3.2.0 is vulnerable to SQL Injection viathe nextPage parameter in /controle/control.php.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-17T21:15:10Z" diff --git a/advisories/unreviewed/2025/01/GHSA-g244-x9gp-5m7r/GHSA-g244-x9gp-5m7r.json b/advisories/unreviewed/2025/01/GHSA-g244-x9gp-5m7r/GHSA-g244-x9gp-5m7r.json index 04afb713a20..6d015ffed1e 100644 --- a/advisories/unreviewed/2025/01/GHSA-g244-x9gp-5m7r/GHSA-g244-x9gp-5m7r.json +++ b/advisories/unreviewed/2025/01/GHSA-g244-x9gp-5m7r/GHSA-g244-x9gp-5m7r.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-g244-x9gp-5m7r", - "modified": "2025-01-16T18:31:00Z", + "modified": "2025-01-21T18:31:06Z", "published": "2025-01-16T18:31:00Z", "aliases": [ "CVE-2024-57774" ], "details": "A cross-site scripting (XSS) vulnerability in the getBusinessUploadListPage?busid interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-16T18:15:27Z" diff --git a/advisories/unreviewed/2025/01/GHSA-g5wq-3r27-v2x7/GHSA-g5wq-3r27-v2x7.json b/advisories/unreviewed/2025/01/GHSA-g5wq-3r27-v2x7/GHSA-g5wq-3r27-v2x7.json index 00aa0cb223f..bda49765f9d 100644 --- a/advisories/unreviewed/2025/01/GHSA-g5wq-3r27-v2x7/GHSA-g5wq-3r27-v2x7.json +++ b/advisories/unreviewed/2025/01/GHSA-g5wq-3r27-v2x7/GHSA-g5wq-3r27-v2x7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-g5wq-3r27-v2x7", - "modified": "2025-01-18T00:30:48Z", + "modified": "2025-01-21T18:31:07Z", "published": "2025-01-18T00:30:48Z", "aliases": [ "CVE-2018-9447" ], "details": "In onCreate of EmergencyCallbackModeExitDialog.java, there is a possible way to crash the emergency callback mode due to a missing null check. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-17T23:15:12Z" diff --git a/advisories/unreviewed/2025/01/GHSA-gvh3-4cff-qfpj/GHSA-gvh3-4cff-qfpj.json b/advisories/unreviewed/2025/01/GHSA-gvh3-4cff-qfpj/GHSA-gvh3-4cff-qfpj.json index 0bb26a1e810..a416ec1d921 100644 --- a/advisories/unreviewed/2025/01/GHSA-gvh3-4cff-qfpj/GHSA-gvh3-4cff-qfpj.json +++ b/advisories/unreviewed/2025/01/GHSA-gvh3-4cff-qfpj/GHSA-gvh3-4cff-qfpj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gvh3-4cff-qfpj", - "modified": "2025-01-15T15:31:25Z", + "modified": "2025-01-21T18:31:05Z", "published": "2025-01-15T15:31:25Z", "aliases": [ "CVE-2024-57895" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: set ATTR_CTIME flags when setting mtime\n\nDavid reported that the new warning from setattr_copy_mgtime is coming\nlike the following.\n\n[ 113.215316] ------------[ cut here ]------------\n[ 113.215974] WARNING: CPU: 1 PID: 31 at fs/attr.c:300 setattr_copy+0x1ee/0x200\n[ 113.219192] CPU: 1 UID: 0 PID: 31 Comm: kworker/1:1 Not tainted 6.13.0-rc1+ #234\n[ 113.220127] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.2-3-gd478f380-rebuilt.opensuse.org 04/01/2014\n[ 113.221530] Workqueue: ksmbd-io handle_ksmbd_work [ksmbd]\n[ 113.222220] RIP: 0010:setattr_copy+0x1ee/0x200\n[ 113.222833] Code: 24 28 49 8b 44 24 30 48 89 53 58 89 43 6c 5b 41 5c 41 5d 41 5e 41 5f 5d c3 cc cc cc cc 48 89 df e8 77 d6 ff ff e9 cd fe ff ff <0f> 0b e9 be fe ff ff 66 0\n[ 113.225110] RSP: 0018:ffffaf218010fb68 EFLAGS: 00010202\n[ 113.225765] RAX: 0000000000000120 RBX: ffffa446815f8568 RCX: 0000000000000003\n[ 113.226667] RDX: ffffaf218010fd38 RSI: ffffa446815f8568 RDI: ffffffff94eb03a0\n[ 113.227531] RBP: ffffaf218010fb90 R08: 0000001a251e217d R09: 00000000675259fa\n[ 113.228426] R10: 0000000002ba8a6d R11: ffffa4468196c7a8 R12: ffffaf218010fd38\n[ 113.229304] R13: 0000000000000120 R14: ffffffff94eb03a0 R15: 0000000000000000\n[ 113.230210] FS: 0000000000000000(0000) GS:ffffa44739d00000(0000) knlGS:0000000000000000\n[ 113.231215] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 113.232055] CR2: 00007efe0053d27e CR3: 000000000331a000 CR4: 00000000000006b0\n[ 113.232926] DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n[ 113.233812] DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n[ 113.234797] Call Trace:\n[ 113.235116] \n[ 113.235393] ? __warn+0x73/0xd0\n[ 113.235802] ? setattr_copy+0x1ee/0x200\n[ 113.236299] ? report_bug+0xf3/0x1e0\n[ 113.236757] ? handle_bug+0x4d/0x90\n[ 113.237202] ? exc_invalid_op+0x13/0x60\n[ 113.237689] ? asm_exc_invalid_op+0x16/0x20\n[ 113.238185] ? setattr_copy+0x1ee/0x200\n[ 113.238692] btrfs_setattr+0x80/0x820 [btrfs]\n[ 113.239285] ? get_stack_info_noinstr+0x12/0xf0\n[ 113.239857] ? __module_address+0x22/0xa0\n[ 113.240368] ? handle_ksmbd_work+0x6e/0x460 [ksmbd]\n[ 113.240993] ? __module_text_address+0x9/0x50\n[ 113.241545] ? __module_address+0x22/0xa0\n[ 113.242033] ? unwind_next_frame+0x10e/0x920\n[ 113.242600] ? __pfx_stack_trace_consume_entry+0x10/0x10\n[ 113.243268] notify_change+0x2c2/0x4e0\n[ 113.243746] ? stack_depot_save_flags+0x27/0x730\n[ 113.244339] ? set_file_basic_info+0x130/0x2b0 [ksmbd]\n[ 113.244993] set_file_basic_info+0x130/0x2b0 [ksmbd]\n[ 113.245613] ? process_scheduled_works+0xbe/0x310\n[ 113.246181] ? worker_thread+0x100/0x240\n[ 113.246696] ? kthread+0xc8/0x100\n[ 113.247126] ? ret_from_fork+0x2b/0x40\n[ 113.247606] ? ret_from_fork_asm+0x1a/0x30\n[ 113.248132] smb2_set_info+0x63f/0xa70 [ksmbd]\n\nksmbd is trying to set the atime and mtime via notify_change without also\nsetting the ctime. so This patch add ATTR_CTIME flags when setting mtime\nto avoid a warning.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -29,7 +34,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-15T13:15:14Z" diff --git a/advisories/unreviewed/2025/01/GHSA-h3c4-5g8f-wf66/GHSA-h3c4-5g8f-wf66.json b/advisories/unreviewed/2025/01/GHSA-h3c4-5g8f-wf66/GHSA-h3c4-5g8f-wf66.json index 5712c5c96ca..dfde400afd1 100644 --- a/advisories/unreviewed/2025/01/GHSA-h3c4-5g8f-wf66/GHSA-h3c4-5g8f-wf66.json +++ b/advisories/unreviewed/2025/01/GHSA-h3c4-5g8f-wf66/GHSA-h3c4-5g8f-wf66.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h3c4-5g8f-wf66", - "modified": "2025-01-15T15:31:25Z", + "modified": "2025-01-21T18:31:05Z", "published": "2025-01-15T15:31:24Z", "aliases": [ "CVE-2024-57890" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/uverbs: Prevent integer overflow issue\n\nIn the expression \"cmd.wqe_size * cmd.wr_count\", both variables are u32\nvalues that come from the user so the multiplication can lead to integer\nwrapping. Then we pass the result to uverbs_request_next_ptr() which also\ncould potentially wrap. The \"cmd.sge_count * sizeof(struct ib_uverbs_sge)\"\nmultiplication can also overflow on 32bit systems although it's fine on\n64bit systems.\n\nThis patch does two things. First, I've re-arranged the condition in\nuverbs_request_next_ptr() so that the use controlled variable \"len\" is on\none side of the comparison by itself without any math. Then I've modified\nall the callers to use size_mul() for the multiplications.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-190" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-15T13:15:13Z" diff --git a/advisories/unreviewed/2025/01/GHSA-h874-6j2r-6vjv/GHSA-h874-6j2r-6vjv.json b/advisories/unreviewed/2025/01/GHSA-h874-6j2r-6vjv/GHSA-h874-6j2r-6vjv.json index 7a2094591ea..61e833d9fbf 100644 --- a/advisories/unreviewed/2025/01/GHSA-h874-6j2r-6vjv/GHSA-h874-6j2r-6vjv.json +++ b/advisories/unreviewed/2025/01/GHSA-h874-6j2r-6vjv/GHSA-h874-6j2r-6vjv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h874-6j2r-6vjv", - "modified": "2025-01-09T21:31:31Z", + "modified": "2025-01-21T18:31:04Z", "published": "2025-01-09T21:31:31Z", "aliases": [ "CVE-2024-54724" ], "details": "PHPYun before 7.0.2 is vulnerable to code execution through backdoor-restricted arbitrary file writing and file inclusion.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-09T20:15:38Z" diff --git a/advisories/unreviewed/2025/01/GHSA-h8r3-h3c2-pp25/GHSA-h8r3-h3c2-pp25.json b/advisories/unreviewed/2025/01/GHSA-h8r3-h3c2-pp25/GHSA-h8r3-h3c2-pp25.json index a3a179a2f7b..133b2a09b29 100644 --- a/advisories/unreviewed/2025/01/GHSA-h8r3-h3c2-pp25/GHSA-h8r3-h3c2-pp25.json +++ b/advisories/unreviewed/2025/01/GHSA-h8r3-h3c2-pp25/GHSA-h8r3-h3c2-pp25.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h8r3-h3c2-pp25", - "modified": "2025-01-15T18:30:58Z", + "modified": "2025-01-21T18:31:06Z", "published": "2025-01-15T18:30:58Z", "aliases": [ "CVE-2024-57024" ], "details": "TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the \"eMinute\" parameter in setWiFiScheduleCfg.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-78" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-15T17:15:18Z" diff --git a/advisories/unreviewed/2025/01/GHSA-h9xv-3v8q-frmv/GHSA-h9xv-3v8q-frmv.json b/advisories/unreviewed/2025/01/GHSA-h9xv-3v8q-frmv/GHSA-h9xv-3v8q-frmv.json new file mode 100644 index 00000000000..f5b6683db9a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-h9xv-3v8q-frmv/GHSA-h9xv-3v8q-frmv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h9xv-3v8q-frmv", + "modified": "2025-01-21T18:31:08Z", + "published": "2025-01-21T18:31:08Z", + "aliases": [ + "CVE-2025-24461" + ], + "details": "In JetBrains TeamCity before 2024.12.1 decryption of connection secrets without proper permissions was possible via Test Connection endpoint", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24461" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T18:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-hfvx-6m6q-5rc7/GHSA-hfvx-6m6q-5rc7.json b/advisories/unreviewed/2025/01/GHSA-hfvx-6m6q-5rc7/GHSA-hfvx-6m6q-5rc7.json new file mode 100644 index 00000000000..57c57bde806 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-hfvx-6m6q-5rc7/GHSA-hfvx-6m6q-5rc7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hfvx-6m6q-5rc7", + "modified": "2025-01-21T18:31:08Z", + "published": "2025-01-21T18:31:07Z", + "aliases": [ + "CVE-2025-23551" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in P. Razvan SexBundle allows Reflected XSS. This issue affects SexBundle: from n/a through 1.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23551" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/sexbundle/vulnerability/wordpress-sexbundle-plugin-1-4-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T18:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-jhgr-2wpg-7p64/GHSA-jhgr-2wpg-7p64.json b/advisories/unreviewed/2025/01/GHSA-jhgr-2wpg-7p64/GHSA-jhgr-2wpg-7p64.json index c3a9c222b5e..4a76a3020d5 100644 --- a/advisories/unreviewed/2025/01/GHSA-jhgr-2wpg-7p64/GHSA-jhgr-2wpg-7p64.json +++ b/advisories/unreviewed/2025/01/GHSA-jhgr-2wpg-7p64/GHSA-jhgr-2wpg-7p64.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jhgr-2wpg-7p64", - "modified": "2025-01-15T15:31:24Z", + "modified": "2025-01-21T18:31:05Z", "published": "2025-01-15T15:31:24Z", "aliases": [ "CVE-2024-36476" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/rtrs: Ensure 'ib_sge list' is accessible\n\nMove the declaration of the 'ib_sge list' variable outside the\n'always_invalidate' block to ensure it remains accessible for use\nthroughout the function.\n\nPreviously, 'ib_sge list' was declared within the 'always_invalidate'\nblock, limiting its accessibility, then caused a\n'BUG: kernel NULL pointer dereference'[1].\n ? __die_body.cold+0x19/0x27\n ? page_fault_oops+0x15a/0x2d0\n ? search_module_extables+0x19/0x60\n ? search_bpf_extables+0x5f/0x80\n ? exc_page_fault+0x7e/0x180\n ? asm_exc_page_fault+0x26/0x30\n ? memcpy_orig+0xd5/0x140\n rxe_mr_copy+0x1c3/0x200 [rdma_rxe]\n ? rxe_pool_get_index+0x4b/0x80 [rdma_rxe]\n copy_data+0xa5/0x230 [rdma_rxe]\n rxe_requester+0xd9b/0xf70 [rdma_rxe]\n ? finish_task_switch.isra.0+0x99/0x2e0\n rxe_sender+0x13/0x40 [rdma_rxe]\n do_task+0x68/0x1e0 [rdma_rxe]\n process_one_work+0x177/0x330\n worker_thread+0x252/0x390\n ? __pfx_worker_thread+0x10/0x10\n\nThis change ensures the variable is available for subsequent operations\nthat require it.\n\n[1] https://lore.kernel.org/linux-rdma/6a1f3e8f-deb0-49f9-bc69-a9b03ecfcda7@fujitsu.com/", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-15T13:15:09Z" diff --git a/advisories/unreviewed/2025/01/GHSA-jvqm-w56m-w3j7/GHSA-jvqm-w56m-w3j7.json b/advisories/unreviewed/2025/01/GHSA-jvqm-w56m-w3j7/GHSA-jvqm-w56m-w3j7.json index 932baaf9f8e..3369f7e4900 100644 --- a/advisories/unreviewed/2025/01/GHSA-jvqm-w56m-w3j7/GHSA-jvqm-w56m-w3j7.json +++ b/advisories/unreviewed/2025/01/GHSA-jvqm-w56m-w3j7/GHSA-jvqm-w56m-w3j7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jvqm-w56m-w3j7", - "modified": "2025-01-18T00:30:48Z", + "modified": "2025-01-21T18:31:06Z", "published": "2025-01-18T00:30:48Z", "aliases": [ "CVE-2018-9379" ], "details": "In multiple functions of MiniThumbFile.java, there is a possible way to view the thumbnails of deleted photos due to a confused deputy. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-611" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-17T23:15:11Z" diff --git a/advisories/unreviewed/2025/01/GHSA-m2vc-489v-fqrc/GHSA-m2vc-489v-fqrc.json b/advisories/unreviewed/2025/01/GHSA-m2vc-489v-fqrc/GHSA-m2vc-489v-fqrc.json new file mode 100644 index 00000000000..f2ed83f79c7 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-m2vc-489v-fqrc/GHSA-m2vc-489v-fqrc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m2vc-489v-fqrc", + "modified": "2025-01-21T18:31:08Z", + "published": "2025-01-21T18:31:07Z", + "aliases": [ + "CVE-2025-23996" + ], + "details": "Cross-Site Request Forgery (CSRF) vulnerability in anyroad.com AnyRoad allows Cross Site Request Forgery. This issue affects AnyRoad: from n/a through 1.3.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23996" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/anyguide/vulnerability/wordpress-anyroad-plugin-1-3-2-cross-site-request-forgery-csrf-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T18:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-m4r5-mmhc-jr9f/GHSA-m4r5-mmhc-jr9f.json b/advisories/unreviewed/2025/01/GHSA-m4r5-mmhc-jr9f/GHSA-m4r5-mmhc-jr9f.json index 8b76173f7ee..9b772d6e556 100644 --- a/advisories/unreviewed/2025/01/GHSA-m4r5-mmhc-jr9f/GHSA-m4r5-mmhc-jr9f.json +++ b/advisories/unreviewed/2025/01/GHSA-m4r5-mmhc-jr9f/GHSA-m4r5-mmhc-jr9f.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-m4r5-mmhc-jr9f", - "modified": "2025-01-18T00:30:48Z", + "modified": "2025-01-21T18:31:07Z", "published": "2025-01-18T00:30:48Z", "aliases": [ "CVE-2018-9464" ], "details": "In multiple locations, there is a possible way to read protected files due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-18T00:15:25Z" diff --git a/advisories/unreviewed/2025/01/GHSA-m643-p29m-frx3/GHSA-m643-p29m-frx3.json b/advisories/unreviewed/2025/01/GHSA-m643-p29m-frx3/GHSA-m643-p29m-frx3.json new file mode 100644 index 00000000000..d13ee77ef11 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-m643-p29m-frx3/GHSA-m643-p29m-frx3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m643-p29m-frx3", + "modified": "2025-01-21T18:31:08Z", + "published": "2025-01-21T18:31:08Z", + "aliases": [ + "CVE-2025-24456" + ], + "details": "In JetBrains Hub before 2024.3.55417 privilege escalation was possible via LDAP authentication mapping", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24456" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-288" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T18:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-mqh5-c2wx-v3pq/GHSA-mqh5-c2wx-v3pq.json b/advisories/unreviewed/2025/01/GHSA-mqh5-c2wx-v3pq/GHSA-mqh5-c2wx-v3pq.json new file mode 100644 index 00000000000..f3cc61de980 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-mqh5-c2wx-v3pq/GHSA-mqh5-c2wx-v3pq.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mqh5-c2wx-v3pq", + "modified": "2025-01-21T18:31:07Z", + "published": "2025-01-21T18:31:07Z", + "aliases": [ + "CVE-2024-45687" + ], + "details": "Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') vulnerability in Payara Platform Payara Server (Grizzly, REST Management Interface modules), Payara Platform Payara Micro (Grizzly modules) allows Manipulating State, Identity Spoofing.This issue affects Payara Server: from 4.1.151 through 4.1.2.191.51, from 5.20.0 through 5.70.0, from 5.2020.2 through 5.2022.5, from 6.2022.1 through 6.2024.12, from 6.0.0 through 6.21.0; Payara Micro: from 4.1.152 through 4.1.2.191.51, from 5.20.0 through 5.70.0, from 5.2020.2 through 5.2022.5, from 6.2022.1 through 6.2024.12, from 6.0.0 through 6.21.0.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45687" + }, + { + "type": "WEB", + "url": "https://docs.payara.fish/community/docs/6.2025.1/Release%20Notes/Release%20Notes%206.2025.1.html" + }, + { + "type": "WEB", + "url": "https://docs.payara.fish/enterprise/docs/5.71.0/Release%20Notes/Release%20Notes%205.71.0.html" + }, + { + "type": "WEB", + "url": "https://docs.payara.fish/enterprise/docs/Release%20Notes/Release%20Notes%206.22.0.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-113" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T17:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-p92f-q723-jhvq/GHSA-p92f-q723-jhvq.json b/advisories/unreviewed/2025/01/GHSA-p92f-q723-jhvq/GHSA-p92f-q723-jhvq.json index 872a45efe23..c376d469825 100644 --- a/advisories/unreviewed/2025/01/GHSA-p92f-q723-jhvq/GHSA-p92f-q723-jhvq.json +++ b/advisories/unreviewed/2025/01/GHSA-p92f-q723-jhvq/GHSA-p92f-q723-jhvq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p92f-q723-jhvq", - "modified": "2025-01-18T00:30:48Z", + "modified": "2025-01-21T18:31:07Z", "published": "2025-01-18T00:30:48Z", "aliases": [ "CVE-2018-9461" ], "details": "In onAttachFragment of ShareIntentActivity.java, there is a possible way for an app to read files in the messages app due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-18T00:15:25Z" diff --git a/advisories/unreviewed/2025/01/GHSA-p9jm-mj56-jwpj/GHSA-p9jm-mj56-jwpj.json b/advisories/unreviewed/2025/01/GHSA-p9jm-mj56-jwpj/GHSA-p9jm-mj56-jwpj.json new file mode 100644 index 00000000000..3946eb95cc5 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-p9jm-mj56-jwpj/GHSA-p9jm-mj56-jwpj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p9jm-mj56-jwpj", + "modified": "2025-01-21T18:31:07Z", + "published": "2025-01-21T18:31:07Z", + "aliases": [ + "CVE-2025-22276" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Enguerran Weiss Related Post Shortcode allows Stored XSS. This issue affects Related Post Shortcode: from n/a through 1.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22276" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/related-post-shortcode/vulnerability/wordpress-related-post-shortcode-plugin-1-2-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T18:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-q4cc-rq78-hxf8/GHSA-q4cc-rq78-hxf8.json b/advisories/unreviewed/2025/01/GHSA-q4cc-rq78-hxf8/GHSA-q4cc-rq78-hxf8.json index 89adf62de28..45bc447884c 100644 --- a/advisories/unreviewed/2025/01/GHSA-q4cc-rq78-hxf8/GHSA-q4cc-rq78-hxf8.json +++ b/advisories/unreviewed/2025/01/GHSA-q4cc-rq78-hxf8/GHSA-q4cc-rq78-hxf8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-q4cc-rq78-hxf8", - "modified": "2025-01-17T21:31:39Z", + "modified": "2025-01-21T18:31:06Z", "published": "2025-01-17T21:31:39Z", "aliases": [ "CVE-2024-57034" ], "details": "WeGIA < 3.2.0 is vulnerable to SQL Injection in query_geracao_auto.php via the query parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-17T20:15:29Z" diff --git a/advisories/unreviewed/2025/01/GHSA-qpr8-gfg5-hxvp/GHSA-qpr8-gfg5-hxvp.json b/advisories/unreviewed/2025/01/GHSA-qpr8-gfg5-hxvp/GHSA-qpr8-gfg5-hxvp.json new file mode 100644 index 00000000000..1ab6f4b271a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-qpr8-gfg5-hxvp/GHSA-qpr8-gfg5-hxvp.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qpr8-gfg5-hxvp", + "modified": "2025-01-21T18:31:07Z", + "published": "2025-01-21T18:31:07Z", + "aliases": [ + "CVE-2024-56990" + ], + "details": "PHPGurukul Hospital Management System 4.0 is vulnerable to Cross Site Scripting (XSS) in /view-medhistory.php and /admin/view-patient.php.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56990" + }, + { + "type": "WEB", + "url": "https://github.com/kirito999/HMS_stored_XSS/blob/main/stored%20XSS1%20%20in%20HMS4.0/stored%20XSS%20%20in%20HMS.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T16:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-qw9x-8r88-2mfq/GHSA-qw9x-8r88-2mfq.json b/advisories/unreviewed/2025/01/GHSA-qw9x-8r88-2mfq/GHSA-qw9x-8r88-2mfq.json new file mode 100644 index 00000000000..9d7fe35f41a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-qw9x-8r88-2mfq/GHSA-qw9x-8r88-2mfq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qw9x-8r88-2mfq", + "modified": "2025-01-21T18:31:07Z", + "published": "2025-01-21T18:31:07Z", + "aliases": [ + "CVE-2025-22721" + ], + "details": "Missing Authorization vulnerability in Farhan Noor ApplyOnline – Application Form Builder and Manager allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ApplyOnline – Application Form Builder and Manager: from n/a through 2.6.7.1.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22721" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/apply-online/vulnerability/wordpress-applyonline-plugin-2-6-7-1-broken-access-control-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T18:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-qxf9-65gj-mxj8/GHSA-qxf9-65gj-mxj8.json b/advisories/unreviewed/2025/01/GHSA-qxf9-65gj-mxj8/GHSA-qxf9-65gj-mxj8.json index 9a75fc3391b..d664def4a8f 100644 --- a/advisories/unreviewed/2025/01/GHSA-qxf9-65gj-mxj8/GHSA-qxf9-65gj-mxj8.json +++ b/advisories/unreviewed/2025/01/GHSA-qxf9-65gj-mxj8/GHSA-qxf9-65gj-mxj8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qxf9-65gj-mxj8", - "modified": "2025-01-15T15:31:24Z", + "modified": "2025-01-21T18:31:05Z", "published": "2025-01-15T15:31:24Z", "aliases": [ "CVE-2024-57841" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: fix memory leak in tcp_conn_request()\n\nIf inet_csk_reqsk_queue_hash_add() return false, tcp_conn_request() will\nreturn without free the dst memory, which allocated in af_ops->route_req.\n\nHere is the kmemleak stack:\n\nunreferenced object 0xffff8881198631c0 (size 240):\n comm \"softirq\", pid 0, jiffies 4299266571 (age 1802.392s)\n hex dump (first 32 bytes):\n 00 10 9b 03 81 88 ff ff 80 98 da bc ff ff ff ff ................\n 81 55 18 bb ff ff ff ff 00 00 00 00 00 00 00 00 .U..............\n backtrace:\n [] kmem_cache_alloc+0x60c/0xa80\n [] dst_alloc+0x55/0x250\n [] rt_dst_alloc+0x46/0x1d0\n [] __mkroute_output+0x29a/0xa50\n [] ip_route_output_key_hash+0x10b/0x240\n [] ip_route_output_flow+0x1d/0x90\n [] inet_csk_route_req+0x2c5/0x500\n [] tcp_conn_request+0x691/0x12c0\n [] tcp_rcv_state_process+0x3c8/0x11b0\n [] tcp_v4_do_rcv+0x156/0x3b0\n [] tcp_v4_rcv+0x1cf8/0x1d80\n [] ip_protocol_deliver_rcu+0xf6/0x360\n [] ip_local_deliver_finish+0xe6/0x1e0\n [] ip_local_deliver+0xee/0x360\n [] ip_rcv+0xad/0x2f0\n [] __netif_receive_skb_one_core+0x123/0x140\n\nCall dst_release() to free the dst memory when\ninet_csk_reqsk_queue_hash_add() return false in tcp_conn_request().", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-15T13:15:12Z" diff --git a/advisories/unreviewed/2025/01/GHSA-r5c9-3mr5-pgp3/GHSA-r5c9-3mr5-pgp3.json b/advisories/unreviewed/2025/01/GHSA-r5c9-3mr5-pgp3/GHSA-r5c9-3mr5-pgp3.json index 54f993ee926..4c6e939381a 100644 --- a/advisories/unreviewed/2025/01/GHSA-r5c9-3mr5-pgp3/GHSA-r5c9-3mr5-pgp3.json +++ b/advisories/unreviewed/2025/01/GHSA-r5c9-3mr5-pgp3/GHSA-r5c9-3mr5-pgp3.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-r5f2-868j-cr9c/GHSA-r5f2-868j-cr9c.json b/advisories/unreviewed/2025/01/GHSA-r5f2-868j-cr9c/GHSA-r5f2-868j-cr9c.json new file mode 100644 index 00000000000..4c72e806e49 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-r5f2-868j-cr9c/GHSA-r5f2-868j-cr9c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r5f2-868j-cr9c", + "modified": "2025-01-21T18:31:08Z", + "published": "2025-01-21T18:31:07Z", + "aliases": [ + "CVE-2025-23994" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Estatebud Estatebud – Properties & Listings allows Stored XSS. This issue affects Estatebud – Properties & Listings: from n/a through 5.5.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23994" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/estatebud-properties-listings/vulnerability/wordpress-estatebud-properties-listings-plugin-5-5-0-csrf-to-stored-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T18:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-v298-p3h5-pc6r/GHSA-v298-p3h5-pc6r.json b/advisories/unreviewed/2025/01/GHSA-v298-p3h5-pc6r/GHSA-v298-p3h5-pc6r.json index 39fc8b146b7..edce1296e65 100644 --- a/advisories/unreviewed/2025/01/GHSA-v298-p3h5-pc6r/GHSA-v298-p3h5-pc6r.json +++ b/advisories/unreviewed/2025/01/GHSA-v298-p3h5-pc6r/GHSA-v298-p3h5-pc6r.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-v298-p3h5-pc6r", - "modified": "2025-01-15T15:31:25Z", + "modified": "2025-01-21T18:31:05Z", "published": "2025-01-15T15:31:25Z", "aliases": [ "CVE-2024-57900" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nila: serialize calls to nf_register_net_hooks()\n\nsyzbot found a race in ila_add_mapping() [1]\n\ncommit 031ae72825ce (\"ila: call nf_unregister_net_hooks() sooner\")\nattempted to fix a similar issue.\n\nLooking at the syzbot repro, we have concurrent ILA_CMD_ADD commands.\n\nAdd a mutex to make sure at most one thread is calling nf_register_net_hooks().\n\n[1]\n BUG: KASAN: slab-use-after-free in rht_key_hashfn include/linux/rhashtable.h:159 [inline]\n BUG: KASAN: slab-use-after-free in __rhashtable_lookup.constprop.0+0x426/0x550 include/linux/rhashtable.h:604\nRead of size 4 at addr ffff888028f40008 by task dhcpcd/5501\n\nCPU: 1 UID: 0 PID: 5501 Comm: dhcpcd Not tainted 6.13.0-rc4-syzkaller-00054-gd6ef8b40d075 #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024\nCall Trace:\n \n __dump_stack lib/dump_stack.c:94 [inline]\n dump_stack_lvl+0x116/0x1f0 lib/dump_stack.c:120\n print_address_description mm/kasan/report.c:378 [inline]\n print_report+0xc3/0x620 mm/kasan/report.c:489\n kasan_report+0xd9/0x110 mm/kasan/report.c:602\n rht_key_hashfn include/linux/rhashtable.h:159 [inline]\n __rhashtable_lookup.constprop.0+0x426/0x550 include/linux/rhashtable.h:604\n rhashtable_lookup include/linux/rhashtable.h:646 [inline]\n rhashtable_lookup_fast include/linux/rhashtable.h:672 [inline]\n ila_lookup_wildcards net/ipv6/ila/ila_xlat.c:127 [inline]\n ila_xlat_addr net/ipv6/ila/ila_xlat.c:652 [inline]\n ila_nf_input+0x1ee/0x620 net/ipv6/ila/ila_xlat.c:185\n nf_hook_entry_hookfn include/linux/netfilter.h:154 [inline]\n nf_hook_slow+0xbb/0x200 net/netfilter/core.c:626\n nf_hook.constprop.0+0x42e/0x750 include/linux/netfilter.h:269\n NF_HOOK include/linux/netfilter.h:312 [inline]\n ipv6_rcv+0xa4/0x680 net/ipv6/ip6_input.c:309\n __netif_receive_skb_one_core+0x12e/0x1e0 net/core/dev.c:5672\n __netif_receive_skb+0x1d/0x160 net/core/dev.c:5785\n process_backlog+0x443/0x15f0 net/core/dev.c:6117\n __napi_poll.constprop.0+0xb7/0x550 net/core/dev.c:6883\n napi_poll net/core/dev.c:6952 [inline]\n net_rx_action+0xa94/0x1010 net/core/dev.c:7074\n handle_softirqs+0x213/0x8f0 kernel/softirq.c:561\n __do_softirq kernel/softirq.c:595 [inline]\n invoke_softirq kernel/softirq.c:435 [inline]\n __irq_exit_rcu+0x109/0x170 kernel/softirq.c:662\n irq_exit_rcu+0x9/0x30 kernel/softirq.c:678\n instr_sysvec_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1049 [inline]\n sysvec_apic_timer_interrupt+0xa4/0xc0 arch/x86/kernel/apic/apic.c:1049", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-15T13:15:14Z" diff --git a/advisories/unreviewed/2025/01/GHSA-v33x-q5jf-g6v4/GHSA-v33x-q5jf-g6v4.json b/advisories/unreviewed/2025/01/GHSA-v33x-q5jf-g6v4/GHSA-v33x-q5jf-g6v4.json new file mode 100644 index 00000000000..4b15b760426 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-v33x-q5jf-g6v4/GHSA-v33x-q5jf-g6v4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v33x-q5jf-g6v4", + "modified": "2025-01-21T18:31:08Z", + "published": "2025-01-21T18:31:08Z", + "aliases": [ + "CVE-2025-24459" + ], + "details": "In JetBrains TeamCity before 2024.12.1 reflected XSS was possible on the Vault Connection page", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24459" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T18:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-v5rq-wfmw-7555/GHSA-v5rq-wfmw-7555.json b/advisories/unreviewed/2025/01/GHSA-v5rq-wfmw-7555/GHSA-v5rq-wfmw-7555.json index 218ba31bff7..6caa86ba312 100644 --- a/advisories/unreviewed/2025/01/GHSA-v5rq-wfmw-7555/GHSA-v5rq-wfmw-7555.json +++ b/advisories/unreviewed/2025/01/GHSA-v5rq-wfmw-7555/GHSA-v5rq-wfmw-7555.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-v5rq-wfmw-7555", - "modified": "2025-01-18T00:30:48Z", + "modified": "2025-01-21T18:31:07Z", "published": "2025-01-18T00:30:48Z", "aliases": [ "CVE-2018-9387" ], "details": "In multiple functions of mnh-sm.c, there is a possible way to trigger a heap overflow due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-18T00:15:23Z" diff --git a/advisories/unreviewed/2025/01/GHSA-vc2j-xx32-6w44/GHSA-vc2j-xx32-6w44.json b/advisories/unreviewed/2025/01/GHSA-vc2j-xx32-6w44/GHSA-vc2j-xx32-6w44.json new file mode 100644 index 00000000000..43977400503 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-vc2j-xx32-6w44/GHSA-vc2j-xx32-6w44.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vc2j-xx32-6w44", + "modified": "2025-01-21T18:31:07Z", + "published": "2025-01-21T18:31:07Z", + "aliases": [ + "CVE-2024-54795" + ], + "details": "SpagoBI v3.5.1 contains multiple Stored Cross-Site Scripting (XSS) vulnerabilities in the create/edit forms of the worksheet designer function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54795" + }, + { + "type": "WEB", + "url": "https://github.com/MarioTesoro/CVE-2024-54795" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T18:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-vmrg-cw8w-fp9r/GHSA-vmrg-cw8w-fp9r.json b/advisories/unreviewed/2025/01/GHSA-vmrg-cw8w-fp9r/GHSA-vmrg-cw8w-fp9r.json new file mode 100644 index 00000000000..4384dc287e4 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-vmrg-cw8w-fp9r/GHSA-vmrg-cw8w-fp9r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vmrg-cw8w-fp9r", + "modified": "2025-01-21T18:31:07Z", + "published": "2025-01-21T18:31:07Z", + "aliases": [ + "CVE-2025-23454" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in flashmaniac Nature FlipBook allows Reflected XSS. This issue affects Nature FlipBook: from n/a through 1.7.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23454" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/vertical-diamond-flipbook-flash/vulnerability/wordpress-nature-flipbook-wordpress-plugin-plugin-1-7-reflected-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T18:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-vww6-44f5-r4h4/GHSA-vww6-44f5-r4h4.json b/advisories/unreviewed/2025/01/GHSA-vww6-44f5-r4h4/GHSA-vww6-44f5-r4h4.json index c2adb2273b2..07e52e4a8f3 100644 --- a/advisories/unreviewed/2025/01/GHSA-vww6-44f5-r4h4/GHSA-vww6-44f5-r4h4.json +++ b/advisories/unreviewed/2025/01/GHSA-vww6-44f5-r4h4/GHSA-vww6-44f5-r4h4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vww6-44f5-r4h4", - "modified": "2025-01-18T00:30:48Z", + "modified": "2025-01-21T18:31:07Z", "published": "2025-01-18T00:30:48Z", "aliases": [ "CVE-2018-9434" ], "details": "In multiple functions of Parcel.cpp, there is a possible way to bypass address space layout randomization. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-129" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-17T23:15:12Z" diff --git a/advisories/unreviewed/2025/01/GHSA-w287-9q69-3hx9/GHSA-w287-9q69-3hx9.json b/advisories/unreviewed/2025/01/GHSA-w287-9q69-3hx9/GHSA-w287-9q69-3hx9.json index 57f1af744c6..d68070bc0fa 100644 --- a/advisories/unreviewed/2025/01/GHSA-w287-9q69-3hx9/GHSA-w287-9q69-3hx9.json +++ b/advisories/unreviewed/2025/01/GHSA-w287-9q69-3hx9/GHSA-w287-9q69-3hx9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w287-9q69-3hx9", - "modified": "2025-01-11T00:32:04Z", + "modified": "2025-01-21T18:31:04Z", "published": "2025-01-04T00:33:40Z", "aliases": [ "CVE-2025-22376" @@ -19,6 +19,18 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22376" }, + { + "type": "WEB", + "url": "https://github.com/keeth/Net-OAuth/commit/2aa25e04aadab247ae4063363fcee177161e1f42" + }, + { + "type": "WEB", + "url": "https://datatracker.ietf.org/doc/html/rfc5849#section-3.3" + }, + { + "type": "WEB", + "url": "https://datatracker.ietf.org/doc/html/rfc5849#section-4.10" + }, { "type": "WEB", "url": "https://metacpan.org/release/KGRENNAN/Net-OAuth-0.28/source/lib/Net/OAuth/Client.pm#L260" @@ -26,6 +38,14 @@ { "type": "WEB", "url": "https://metacpan.org/release/RRWO/Net-OAuth-0.29/changes" + }, + { + "type": "WEB", + "url": "https://metacpan.org/release/RRWO/Net-OAuth-0.29/diff/KGRENNAN/Net-OAuth-0.28#lib/Net/OAuth/Client.pm" + }, + { + "type": "WEB", + "url": "https://www.vulnarium.com/blogpost-2025-01-05" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/01/GHSA-w28c-hqg3-44gm/GHSA-w28c-hqg3-44gm.json b/advisories/unreviewed/2025/01/GHSA-w28c-hqg3-44gm/GHSA-w28c-hqg3-44gm.json index fb7a709421b..5afe5555e43 100644 --- a/advisories/unreviewed/2025/01/GHSA-w28c-hqg3-44gm/GHSA-w28c-hqg3-44gm.json +++ b/advisories/unreviewed/2025/01/GHSA-w28c-hqg3-44gm/GHSA-w28c-hqg3-44gm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w28c-hqg3-44gm", - "modified": "2025-01-15T15:31:25Z", + "modified": "2025-01-21T18:31:05Z", "published": "2025-01-15T15:31:25Z", "aliases": [ "CVE-2024-57896" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: flush delalloc workers queue before stopping cleaner kthread during unmount\n\nDuring the unmount path, at close_ctree(), we first stop the cleaner\nkthread, using kthread_stop() which frees the associated task_struct, and\nthen stop and destroy all the work queues. However after we stopped the\ncleaner we may still have a worker from the delalloc_workers queue running\ninode.c:submit_compressed_extents(), which calls btrfs_add_delayed_iput(),\nwhich in turn tries to wake up the cleaner kthread - which was already\ndestroyed before, resulting in a use-after-free on the task_struct.\n\nSyzbot reported this with the following stack traces:\n\n BUG: KASAN: slab-use-after-free in __lock_acquire+0x78/0x2100 kernel/locking/lockdep.c:5089\n Read of size 8 at addr ffff8880259d2818 by task kworker/u8:3/52\n\n CPU: 1 UID: 0 PID: 52 Comm: kworker/u8:3 Not tainted 6.13.0-rc1-syzkaller-00002-gcdd30ebb1b9f #0\n Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024\n Workqueue: btrfs-delalloc btrfs_work_helper\n Call Trace:\n \n __dump_stack lib/dump_stack.c:94 [inline]\n dump_stack_lvl+0x241/0x360 lib/dump_stack.c:120\n print_address_description mm/kasan/report.c:378 [inline]\n print_report+0x169/0x550 mm/kasan/report.c:489\n kasan_report+0x143/0x180 mm/kasan/report.c:602\n __lock_acquire+0x78/0x2100 kernel/locking/lockdep.c:5089\n lock_acquire+0x1ed/0x550 kernel/locking/lockdep.c:5849\n __raw_spin_lock_irqsave include/linux/spinlock_api_smp.h:110 [inline]\n _raw_spin_lock_irqsave+0xd5/0x120 kernel/locking/spinlock.c:162\n class_raw_spinlock_irqsave_constructor include/linux/spinlock.h:551 [inline]\n try_to_wake_up+0xc2/0x1470 kernel/sched/core.c:4205\n submit_compressed_extents+0xdf/0x16e0 fs/btrfs/inode.c:1615\n run_ordered_work fs/btrfs/async-thread.c:288 [inline]\n btrfs_work_helper+0x96f/0xc40 fs/btrfs/async-thread.c:324\n process_one_work kernel/workqueue.c:3229 [inline]\n process_scheduled_works+0xa66/0x1840 kernel/workqueue.c:3310\n worker_thread+0x870/0xd30 kernel/workqueue.c:3391\n kthread+0x2f0/0x390 kernel/kthread.c:389\n ret_from_fork+0x4b/0x80 arch/x86/kernel/process.c:147\n ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:244\n \n\n Allocated by task 2:\n kasan_save_stack mm/kasan/common.c:47 [inline]\n kasan_save_track+0x3f/0x80 mm/kasan/common.c:68\n unpoison_slab_object mm/kasan/common.c:319 [inline]\n __kasan_slab_alloc+0x66/0x80 mm/kasan/common.c:345\n kasan_slab_alloc include/linux/kasan.h:250 [inline]\n slab_post_alloc_hook mm/slub.c:4104 [inline]\n slab_alloc_node mm/slub.c:4153 [inline]\n kmem_cache_alloc_node_noprof+0x1d9/0x380 mm/slub.c:4205\n alloc_task_struct_node kernel/fork.c:180 [inline]\n dup_task_struct+0x57/0x8c0 kernel/fork.c:1113\n copy_process+0x5d1/0x3d50 kernel/fork.c:2225\n kernel_clone+0x223/0x870 kernel/fork.c:2807\n kernel_thread+0x1bc/0x240 kernel/fork.c:2869\n create_kthread kernel/kthread.c:412 [inline]\n kthreadd+0x60d/0x810 kernel/kthread.c:767\n ret_from_fork+0x4b/0x80 arch/x86/kernel/process.c:147\n ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:244\n\n Freed by task 24:\n kasan_save_stack mm/kasan/common.c:47 [inline]\n kasan_save_track+0x3f/0x80 mm/kasan/common.c:68\n kasan_save_free_info+0x40/0x50 mm/kasan/generic.c:582\n poison_slab_object mm/kasan/common.c:247 [inline]\n __kasan_slab_free+0x59/0x70 mm/kasan/common.c:264\n kasan_slab_free include/linux/kasan.h:233 [inline]\n slab_free_hook mm/slub.c:2338 [inline]\n slab_free mm/slub.c:4598 [inline]\n kmem_cache_free+0x195/0x410 mm/slub.c:4700\n put_task_struct include/linux/sched/task.h:144 [inline]\n delayed_put_task_struct+0x125/0x300 kernel/exit.c:227\n rcu_do_batch kernel/rcu/tree.c:2567 [inline]\n rcu_core+0xaaa/0x17a0 kernel/rcu/tree.c:2823\n handle_softirqs+0x2d4/0x9b0 kernel/softirq.c:554\n run_ksoftirqd+0xca/0x130 kernel/softirq.c:943\n \n---truncated---", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-15T13:15:14Z" diff --git a/advisories/unreviewed/2025/01/GHSA-w373-phfp-m2jq/GHSA-w373-phfp-m2jq.json b/advisories/unreviewed/2025/01/GHSA-w373-phfp-m2jq/GHSA-w373-phfp-m2jq.json index ac1229382ce..7f2534daac8 100644 --- a/advisories/unreviewed/2025/01/GHSA-w373-phfp-m2jq/GHSA-w373-phfp-m2jq.json +++ b/advisories/unreviewed/2025/01/GHSA-w373-phfp-m2jq/GHSA-w373-phfp-m2jq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w373-phfp-m2jq", - "modified": "2025-01-15T15:31:24Z", + "modified": "2025-01-21T18:31:05Z", "published": "2025-01-15T15:31:24Z", "aliases": [ "CVE-2024-57882" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: fix TCP options overflow.\n\nSyzbot reported the following splat:\n\nOops: general protection fault, probably for non-canonical address 0xdffffc0000000001: 0000 [#1] PREEMPT SMP KASAN PTI\nKASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f]\nCPU: 1 UID: 0 PID: 5836 Comm: sshd Not tainted 6.13.0-rc3-syzkaller #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 11/25/2024\nRIP: 0010:_compound_head include/linux/page-flags.h:242 [inline]\nRIP: 0010:put_page+0x23/0x260 include/linux/mm.h:1552\nCode: 90 90 90 90 90 90 90 55 41 57 41 56 53 49 89 fe 48 bd 00 00 00 00 00 fc ff df e8 f8 5e 12 f8 49 8d 5e 08 48 89 d8 48 c1 e8 03 <80> 3c 28 00 74 08 48 89 df e8 8f c7 78 f8 48 8b 1b 48 89 de 48 83\nRSP: 0000:ffffc90003916c90 EFLAGS: 00010202\nRAX: 0000000000000001 RBX: 0000000000000008 RCX: ffff888030458000\nRDX: 0000000000000100 RSI: 0000000000000000 RDI: 0000000000000000\nRBP: dffffc0000000000 R08: ffffffff898ca81d R09: 1ffff110054414ac\nR10: dffffc0000000000 R11: ffffed10054414ad R12: 0000000000000007\nR13: ffff88802a20a542 R14: 0000000000000000 R15: 0000000000000000\nFS: 00007f34f496e800(0000) GS:ffff8880b8700000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007f9d6ec9ec28 CR3: 000000004d260000 CR4: 00000000003526f0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\nCall Trace:\n \n skb_page_unref include/linux/skbuff_ref.h:43 [inline]\n __skb_frag_unref include/linux/skbuff_ref.h:56 [inline]\n skb_release_data+0x483/0x8a0 net/core/skbuff.c:1119\n skb_release_all net/core/skbuff.c:1190 [inline]\n __kfree_skb+0x55/0x70 net/core/skbuff.c:1204\n tcp_clean_rtx_queue net/ipv4/tcp_input.c:3436 [inline]\n tcp_ack+0x2442/0x6bc0 net/ipv4/tcp_input.c:4032\n tcp_rcv_state_process+0x8eb/0x44e0 net/ipv4/tcp_input.c:6805\n tcp_v4_do_rcv+0x77d/0xc70 net/ipv4/tcp_ipv4.c:1939\n tcp_v4_rcv+0x2dc0/0x37f0 net/ipv4/tcp_ipv4.c:2351\n ip_protocol_deliver_rcu+0x22e/0x440 net/ipv4/ip_input.c:205\n ip_local_deliver_finish+0x341/0x5f0 net/ipv4/ip_input.c:233\n NF_HOOK+0x3a4/0x450 include/linux/netfilter.h:314\n NF_HOOK+0x3a4/0x450 include/linux/netfilter.h:314\n __netif_receive_skb_one_core net/core/dev.c:5672 [inline]\n __netif_receive_skb+0x2bf/0x650 net/core/dev.c:5785\n process_backlog+0x662/0x15b0 net/core/dev.c:6117\n __napi_poll+0xcb/0x490 net/core/dev.c:6883\n napi_poll net/core/dev.c:6952 [inline]\n net_rx_action+0x89b/0x1240 net/core/dev.c:7074\n handle_softirqs+0x2d4/0x9b0 kernel/softirq.c:561\n __do_softirq kernel/softirq.c:595 [inline]\n invoke_softirq kernel/softirq.c:435 [inline]\n __irq_exit_rcu+0xf7/0x220 kernel/softirq.c:662\n irq_exit_rcu+0x9/0x30 kernel/softirq.c:678\n instr_sysvec_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1049 [inline]\n sysvec_apic_timer_interrupt+0x57/0xc0 arch/x86/kernel/apic/apic.c:1049\n asm_sysvec_apic_timer_interrupt+0x1a/0x20 arch/x86/include/asm/idtentry.h:702\nRIP: 0033:0x7f34f4519ad5\nCode: 85 d2 74 0d 0f 10 02 48 8d 54 24 20 0f 11 44 24 20 64 8b 04 25 18 00 00 00 85 c0 75 27 41 b8 08 00 00 00 b8 0f 01 00 00 0f 05 <48> 3d 00 f0 ff ff 76 75 48 8b 15 24 73 0d 00 f7 d8 64 89 02 48 83\nRSP: 002b:00007ffec5b32ce0 EFLAGS: 00000246\nRAX: 0000000000000001 RBX: 00000000000668a0 RCX: 00007f34f4519ad5\nRDX: 00007ffec5b32d00 RSI: 0000000000000004 RDI: 0000564f4bc6cae0\nRBP: 0000564f4bc6b5a0 R08: 0000000000000008 R09: 0000000000000000\nR10: 00007ffec5b32de8 R11: 0000000000000246 R12: 0000564f48ea8aa4\nR13: 0000000000000001 R14: 0000564f48ea93e8 R15: 00007ffec5b32d68\n \n\nEric noted a probable shinfo->nr_frags corruption, which indeed\noccurs.\n\nThe root cause is a buggy MPTCP option len computation in some\ncircumstances: the ADD_ADDR option should be mutually exclusive\nwith DSS since the blamed commit.\n\nStill, mptcp_established_options_add_addr() tries to set the\nrelevant info in mptcp_out_options, if \n---truncated---", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-15T13:15:12Z" diff --git a/advisories/unreviewed/2025/01/GHSA-w38q-r3wf-fqwx/GHSA-w38q-r3wf-fqwx.json b/advisories/unreviewed/2025/01/GHSA-w38q-r3wf-fqwx/GHSA-w38q-r3wf-fqwx.json new file mode 100644 index 00000000000..f5da6887aa0 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-w38q-r3wf-fqwx/GHSA-w38q-r3wf-fqwx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w38q-r3wf-fqwx", + "modified": "2025-01-21T18:31:07Z", + "published": "2025-01-21T18:31:07Z", + "aliases": [ + "CVE-2025-22661" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vcita.com Online Payments – Get Paid with PayPal, Square & Stripe allows Stored XSS. This issue affects Online Payments – Get Paid with PayPal, Square & Stripe: from n/a through 3.20.0.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22661" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/paypal-payment-button-by-vcita/vulnerability/wordpress-online-payments-plugin-3-20-0-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T18:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-w7pq-rmwm-c759/GHSA-w7pq-rmwm-c759.json b/advisories/unreviewed/2025/01/GHSA-w7pq-rmwm-c759/GHSA-w7pq-rmwm-c759.json index 3055f06c4ed..ac2418b7682 100644 --- a/advisories/unreviewed/2025/01/GHSA-w7pq-rmwm-c759/GHSA-w7pq-rmwm-c759.json +++ b/advisories/unreviewed/2025/01/GHSA-w7pq-rmwm-c759/GHSA-w7pq-rmwm-c759.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w7pq-rmwm-c759", - "modified": "2025-01-17T15:32:32Z", + "modified": "2025-01-21T18:31:05Z", "published": "2025-01-15T15:31:24Z", "aliases": [ "CVE-2024-57887" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm: adv7511: Fix use-after-free in adv7533_attach_dsi()\n\nThe host_node pointer was assigned and freed in adv7533_parse_dt(), and\nlater, adv7533_attach_dsi() uses the same. Fix this use-after-free issue\nby dropping of_node_put() in adv7533_parse_dt() and calling of_node_put()\nin error path of probe() and also in the remove().", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-15T13:15:13Z" diff --git a/advisories/unreviewed/2025/01/GHSA-wpfp-cm49-9m9q/GHSA-wpfp-cm49-9m9q.json b/advisories/unreviewed/2025/01/GHSA-wpfp-cm49-9m9q/GHSA-wpfp-cm49-9m9q.json new file mode 100644 index 00000000000..1c7eaf5033c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-wpfp-cm49-9m9q/GHSA-wpfp-cm49-9m9q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wpfp-cm49-9m9q", + "modified": "2025-01-21T18:31:07Z", + "published": "2025-01-21T18:31:07Z", + "aliases": [ + "CVE-2025-0377" + ], + "details": "HashiCorp’s go-slug library is vulnerable to a zip-slip style attack when a non-existing user-provided path is extracted from the tar entry.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0377" + }, + { + "type": "WEB", + "url": "https://discuss.hashicorp.com/t/hcsec-2025-01-hashicorp-go-slug-vulnerable-to-zip-slip-attack" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-59" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T16:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-wqqf-h2wr-4487/GHSA-wqqf-h2wr-4487.json b/advisories/unreviewed/2025/01/GHSA-wqqf-h2wr-4487/GHSA-wqqf-h2wr-4487.json new file mode 100644 index 00000000000..77b8d0697cf --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-wqqf-h2wr-4487/GHSA-wqqf-h2wr-4487.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wqqf-h2wr-4487", + "modified": "2025-01-21T18:31:07Z", + "published": "2025-01-21T18:31:07Z", + "aliases": [ + "CVE-2025-22267" + ], + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bruce Wampler Weaver Themes Shortcode Compatibility allows Stored XSS. This issue affects Weaver Themes Shortcode Compatibility: from n/a through 1.0.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22267" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/weaver-themes-shortcode-compatibility/vulnerability/wordpress-weaver-themes-shortcode-compatibility-plugin-1-0-4-cross-site-scripting-xss-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T18:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-xgj7-v3ff-h29v/GHSA-xgj7-v3ff-h29v.json b/advisories/unreviewed/2025/01/GHSA-xgj7-v3ff-h29v/GHSA-xgj7-v3ff-h29v.json new file mode 100644 index 00000000000..2c387cdeb56 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-xgj7-v3ff-h29v/GHSA-xgj7-v3ff-h29v.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xgj7-v3ff-h29v", + "modified": "2025-01-21T18:31:07Z", + "published": "2025-01-21T18:31:07Z", + "aliases": [ + "CVE-2024-57036" + ], + "details": "TOTOLINK A810R V4.1.2cu.5032_B20200407 was found to contain a command insertion vulnerability in downloadFile.cgi main function. This vulnerability allows an attacker to execute arbitrary commands by sending HTTP request.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57036" + }, + { + "type": "WEB", + "url": "https://github.com/luckysmallbird/Totolink-A810R-Vulnerability-1/blob/main/3.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-21T16:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-xm36-ph36-7r35/GHSA-xm36-ph36-7r35.json b/advisories/unreviewed/2025/01/GHSA-xm36-ph36-7r35/GHSA-xm36-ph36-7r35.json index 4845bf5e4ca..39078c29555 100644 --- a/advisories/unreviewed/2025/01/GHSA-xm36-ph36-7r35/GHSA-xm36-ph36-7r35.json +++ b/advisories/unreviewed/2025/01/GHSA-xm36-ph36-7r35/GHSA-xm36-ph36-7r35.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xm36-ph36-7r35", - "modified": "2025-01-15T15:31:24Z", + "modified": "2025-01-21T18:31:05Z", "published": "2025-01-15T15:31:24Z", "aliases": [ "CVE-2024-57802" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetrom: check buffer length before accessing it\n\nSyzkaller reports an uninit value read from ax25cmp when sending raw message\nthrough ieee802154 implementation.\n\n=====================================================\nBUG: KMSAN: uninit-value in ax25cmp+0x3a5/0x460 net/ax25/ax25_addr.c:119\n ax25cmp+0x3a5/0x460 net/ax25/ax25_addr.c:119\n nr_dev_get+0x20e/0x450 net/netrom/nr_route.c:601\n nr_route_frame+0x1a2/0xfc0 net/netrom/nr_route.c:774\n nr_xmit+0x5a/0x1c0 net/netrom/nr_dev.c:144\n __netdev_start_xmit include/linux/netdevice.h:4940 [inline]\n netdev_start_xmit include/linux/netdevice.h:4954 [inline]\n xmit_one net/core/dev.c:3548 [inline]\n dev_hard_start_xmit+0x247/0xa10 net/core/dev.c:3564\n __dev_queue_xmit+0x33b8/0x5130 net/core/dev.c:4349\n dev_queue_xmit include/linux/netdevice.h:3134 [inline]\n raw_sendmsg+0x654/0xc10 net/ieee802154/socket.c:299\n ieee802154_sock_sendmsg+0x91/0xc0 net/ieee802154/socket.c:96\n sock_sendmsg_nosec net/socket.c:730 [inline]\n __sock_sendmsg net/socket.c:745 [inline]\n ____sys_sendmsg+0x9c2/0xd60 net/socket.c:2584\n ___sys_sendmsg+0x28d/0x3c0 net/socket.c:2638\n __sys_sendmsg net/socket.c:2667 [inline]\n __do_sys_sendmsg net/socket.c:2676 [inline]\n __se_sys_sendmsg net/socket.c:2674 [inline]\n __x64_sys_sendmsg+0x307/0x490 net/socket.c:2674\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0x44/0x110 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x63/0x6b\n\nUninit was created at:\n slab_post_alloc_hook+0x129/0xa70 mm/slab.h:768\n slab_alloc_node mm/slub.c:3478 [inline]\n kmem_cache_alloc_node+0x5e9/0xb10 mm/slub.c:3523\n kmalloc_reserve+0x13d/0x4a0 net/core/skbuff.c:560\n __alloc_skb+0x318/0x740 net/core/skbuff.c:651\n alloc_skb include/linux/skbuff.h:1286 [inline]\n alloc_skb_with_frags+0xc8/0xbd0 net/core/skbuff.c:6334\n sock_alloc_send_pskb+0xa80/0xbf0 net/core/sock.c:2780\n sock_alloc_send_skb include/net/sock.h:1884 [inline]\n raw_sendmsg+0x36d/0xc10 net/ieee802154/socket.c:282\n ieee802154_sock_sendmsg+0x91/0xc0 net/ieee802154/socket.c:96\n sock_sendmsg_nosec net/socket.c:730 [inline]\n __sock_sendmsg net/socket.c:745 [inline]\n ____sys_sendmsg+0x9c2/0xd60 net/socket.c:2584\n ___sys_sendmsg+0x28d/0x3c0 net/socket.c:2638\n __sys_sendmsg net/socket.c:2667 [inline]\n __do_sys_sendmsg net/socket.c:2676 [inline]\n __se_sys_sendmsg net/socket.c:2674 [inline]\n __x64_sys_sendmsg+0x307/0x490 net/socket.c:2674\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0x44/0x110 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x63/0x6b\n\nCPU: 0 PID: 5037 Comm: syz-executor166 Not tainted 6.7.0-rc7-syzkaller-00003-gfbafc3e621c3 #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 11/17/2023\n=====================================================\n\nThis issue occurs because the skb buffer is too small, and it's actual\nallocation is aligned. This hides an actual issue, which is that nr_route_frame\ndoes not validate the buffer size before using it.\n\nFix this issue by checking skb->len before accessing any fields in skb->data.\n\nFound by Linux Verification Center (linuxtesting.org) with Syzkaller.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-908" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-15T13:15:11Z" diff --git a/advisories/unreviewed/2025/01/GHSA-xmg9-vq9f-g4cr/GHSA-xmg9-vq9f-g4cr.json b/advisories/unreviewed/2025/01/GHSA-xmg9-vq9f-g4cr/GHSA-xmg9-vq9f-g4cr.json index c36bd086bf2..299e2ea0346 100644 --- a/advisories/unreviewed/2025/01/GHSA-xmg9-vq9f-g4cr/GHSA-xmg9-vq9f-g4cr.json +++ b/advisories/unreviewed/2025/01/GHSA-xmg9-vq9f-g4cr/GHSA-xmg9-vq9f-g4cr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xmg9-vq9f-g4cr", - "modified": "2025-01-17T15:32:32Z", + "modified": "2025-01-21T18:31:05Z", "published": "2025-01-15T15:31:24Z", "aliases": [ "CVE-2024-57892" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nocfs2: fix slab-use-after-free due to dangling pointer dqi_priv\n\nWhen mounting ocfs2 and then remounting it as read-only, a\nslab-use-after-free occurs after the user uses a syscall to\nquota_getnextquota. Specifically, sb_dqinfo(sb, type)->dqi_priv is the\ndangling pointer.\n\nDuring the remounting process, the pointer dqi_priv is freed but is never\nset as null leaving it to be accessed. Additionally, the read-only option\nfor remounting sets the DQUOT_SUSPENDED flag instead of setting the\nDQUOT_USAGE_ENABLED flags. Moreover, later in the process of getting the\nnext quota, the function ocfs2_get_next_id is called and only checks the\nquota usage flags and not the quota suspended flags.\n\nTo fix this, I set dqi_priv to null when it is freed after remounting with\nread-only and put a check for DQUOT_SUSPENDED in ocfs2_get_next_id.\n\n[akpm@linux-foundation.org: coding-style cleanups]", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-15T13:15:13Z" diff --git a/advisories/unreviewed/2025/01/GHSA-xmr9-3j8w-v8gw/GHSA-xmr9-3j8w-v8gw.json b/advisories/unreviewed/2025/01/GHSA-xmr9-3j8w-v8gw/GHSA-xmr9-3j8w-v8gw.json index b705e8ae13b..7ba1eea89e8 100644 --- a/advisories/unreviewed/2025/01/GHSA-xmr9-3j8w-v8gw/GHSA-xmr9-3j8w-v8gw.json +++ b/advisories/unreviewed/2025/01/GHSA-xmr9-3j8w-v8gw/GHSA-xmr9-3j8w-v8gw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xmr9-3j8w-v8gw", - "modified": "2025-01-16T18:31:00Z", + "modified": "2025-01-21T18:31:06Z", "published": "2025-01-16T18:31:00Z", "aliases": [ "CVE-2024-57771" ], "details": "A cross-site scripting (XSS) vulnerability in the common/getEditPage?view interface of JFinalOA before v2025.01.01 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-16T18:15:26Z"