From 29c2dac907c70f1a53e222f1ddd97256f813a76a Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 14 May 2025 12:33:08 +0000 Subject: [PATCH] Publish Advisories GHSA-5fc3-pqf2-57cx GHSA-6p47-2pgh-wj76 GHSA-8mxf-4389-q8j9 GHSA-8qhh-qg7r-qg2v GHSA-c3pr-284f-8x9f GHSA-f4rq-f4j9-f6rm GHSA-gp98-hfvm-2r4x GHSA-r263-h39v-v2j9 GHSA-rpg2-jvhp-h354 GHSA-xq7c-hjvw-rh5f --- .../GHSA-5fc3-pqf2-57cx.json | 35 +++++++++++++++ .../GHSA-6p47-2pgh-wj76.json | 6 ++- .../GHSA-8mxf-4389-q8j9.json | 40 +++++++++++++++++ .../GHSA-8qhh-qg7r-qg2v.json | 36 +++++++++++++++ .../GHSA-c3pr-284f-8x9f.json | 36 +++++++++++++++ .../GHSA-f4rq-f4j9-f6rm.json | 33 ++++++++++++++ .../GHSA-gp98-hfvm-2r4x.json | 35 +++++++++++++++ .../GHSA-r263-h39v-v2j9.json | 36 +++++++++++++++ .../GHSA-rpg2-jvhp-h354.json | 44 +++++++++++++++++++ .../GHSA-xq7c-hjvw-rh5f.json | 44 +++++++++++++++++++ 10 files changed, 344 insertions(+), 1 deletion(-) create mode 100644 advisories/unreviewed/2025/05/GHSA-5fc3-pqf2-57cx/GHSA-5fc3-pqf2-57cx.json create mode 100644 advisories/unreviewed/2025/05/GHSA-8mxf-4389-q8j9/GHSA-8mxf-4389-q8j9.json create mode 100644 advisories/unreviewed/2025/05/GHSA-8qhh-qg7r-qg2v/GHSA-8qhh-qg7r-qg2v.json create mode 100644 advisories/unreviewed/2025/05/GHSA-c3pr-284f-8x9f/GHSA-c3pr-284f-8x9f.json create mode 100644 advisories/unreviewed/2025/05/GHSA-f4rq-f4j9-f6rm/GHSA-f4rq-f4j9-f6rm.json create mode 100644 advisories/unreviewed/2025/05/GHSA-gp98-hfvm-2r4x/GHSA-gp98-hfvm-2r4x.json create mode 100644 advisories/unreviewed/2025/05/GHSA-r263-h39v-v2j9/GHSA-r263-h39v-v2j9.json create mode 100644 advisories/unreviewed/2025/05/GHSA-rpg2-jvhp-h354/GHSA-rpg2-jvhp-h354.json create mode 100644 advisories/unreviewed/2025/05/GHSA-xq7c-hjvw-rh5f/GHSA-xq7c-hjvw-rh5f.json diff --git a/advisories/unreviewed/2025/05/GHSA-5fc3-pqf2-57cx/GHSA-5fc3-pqf2-57cx.json b/advisories/unreviewed/2025/05/GHSA-5fc3-pqf2-57cx/GHSA-5fc3-pqf2-57cx.json new file mode 100644 index 00000000000..f109e164633 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5fc3-pqf2-57cx/GHSA-5fc3-pqf2-57cx.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5fc3-pqf2-57cx", + "modified": "2025-05-14T12:31:11Z", + "published": "2025-05-14T12:31:11Z", + "aliases": [ + "CVE-2025-26864" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in the OpenIdAuthorizer of Apache IoTDB.\n\nThis issue affects Apache IoTDB: from 0.10.0 through 1.3.3, from 2.0.1-beta before 2.0.2.\n\nUsers are recommended to upgrade to version 1.3.4 and 2.0.2, which fix the issue.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26864" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/2kcjnlypppk8qjh17dpz0jvkcpn6l162" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/05/14/4" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T11:16:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-6p47-2pgh-wj76/GHSA-6p47-2pgh-wj76.json b/advisories/unreviewed/2025/05/GHSA-6p47-2pgh-wj76/GHSA-6p47-2pgh-wj76.json index 5d289bb8746..1f1c8d61bc0 100644 --- a/advisories/unreviewed/2025/05/GHSA-6p47-2pgh-wj76/GHSA-6p47-2pgh-wj76.json +++ b/advisories/unreviewed/2025/05/GHSA-6p47-2pgh-wj76/GHSA-6p47-2pgh-wj76.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6p47-2pgh-wj76", - "modified": "2025-05-08T12:34:29Z", + "modified": "2025-05-14T12:31:11Z", "published": "2025-05-08T12:34:29Z", "aliases": [ "CVE-2025-41450" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://sm800a.danfoss.com/sw_shared/SM800A-4.2.4.spk" + }, + { + "type": "WEB", + "url": "https://www.danfoss.com/en/service-and-support/coordinated-vulnerability-disclosure/danfoss-security-advisories/dsa-2025-03-01" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/05/GHSA-8mxf-4389-q8j9/GHSA-8mxf-4389-q8j9.json b/advisories/unreviewed/2025/05/GHSA-8mxf-4389-q8j9/GHSA-8mxf-4389-q8j9.json new file mode 100644 index 00000000000..6ef8646992a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8mxf-4389-q8j9/GHSA-8mxf-4389-q8j9.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8mxf-4389-q8j9", + "modified": "2025-05-14T12:31:12Z", + "published": "2025-05-14T12:31:12Z", + "aliases": [ + "CVE-2025-4430" + ], + "details": "Unauthorized access to \"/api/Token/gettoken\" endpoint in EZD RP allows file manipulation.This issue affects EZD RP in versions before 20.19 (published on 22nd August 2024).", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4430" + }, + { + "type": "WEB", + "url": "https://cert.pl/en/posts/2025/05/CVE-2025-4430" + }, + { + "type": "WEB", + "url": "https://www.gov.pl/web/ezd-rp" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T11:16:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8qhh-qg7r-qg2v/GHSA-8qhh-qg7r-qg2v.json b/advisories/unreviewed/2025/05/GHSA-8qhh-qg7r-qg2v/GHSA-8qhh-qg7r-qg2v.json new file mode 100644 index 00000000000..c67905bd3c5 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8qhh-qg7r-qg2v/GHSA-8qhh-qg7r-qg2v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8qhh-qg7r-qg2v", + "modified": "2025-05-14T12:31:11Z", + "published": "2025-05-14T12:31:11Z", + "aliases": [ + "CVE-2025-3834" + ], + "details": "Zohocorp ManageEngine ADAudit Plus versions 8510 and prior are vulnerable to authenticated SQL injection in the OU History report.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3834" + }, + { + "type": "WEB", + "url": "https://www.manageengine.com/products/active-directory-audit/cve-2025-3834.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T11:16:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-c3pr-284f-8x9f/GHSA-c3pr-284f-8x9f.json b/advisories/unreviewed/2025/05/GHSA-c3pr-284f-8x9f/GHSA-c3pr-284f-8x9f.json new file mode 100644 index 00000000000..8aa85ebbe56 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-c3pr-284f-8x9f/GHSA-c3pr-284f-8x9f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c3pr-284f-8x9f", + "modified": "2025-05-14T12:31:12Z", + "published": "2025-05-14T12:31:12Z", + "aliases": [ + "CVE-2025-47445" + ], + "details": "Relative Path Traversal vulnerability in Themewinter Eventin allows Path Traversal.This issue affects Eventin: from n/a through 4.0.26.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47445" + }, + { + "type": "WEB", + "url": "https://patchstack.com/database/wordpress/plugin/wp-event-solution/vulnerability/wordpress-eventin-4-0-26-arbitrary-file-download-vulnerability?_s_id=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-23" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T12:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-f4rq-f4j9-f6rm/GHSA-f4rq-f4j9-f6rm.json b/advisories/unreviewed/2025/05/GHSA-f4rq-f4j9-f6rm/GHSA-f4rq-f4j9-f6rm.json new file mode 100644 index 00000000000..a3925c0bbe3 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-f4rq-f4j9-f6rm/GHSA-f4rq-f4j9-f6rm.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f4rq-f4j9-f6rm", + "modified": "2025-05-14T12:31:11Z", + "published": "2025-05-14T12:31:11Z", + "aliases": [ + "CVE-2024-24780" + ], + "details": "Remote Code Execution with untrusted URI of UDF vulnerability in Apache IoTDB. The attacker who has privilege to create UDF can register malicious function from untrusted URI.\n\nThis issue affects Apache IoTDB: from 1.0.0 before 1.3.4.\n\nUsers are recommended to upgrade to version 1.3.4, which fixes the issue.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24780" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/xphtm98v3zsk9vlpfh481m1ry2ctxvmj" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/05/14/2" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T11:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-gp98-hfvm-2r4x/GHSA-gp98-hfvm-2r4x.json b/advisories/unreviewed/2025/05/GHSA-gp98-hfvm-2r4x/GHSA-gp98-hfvm-2r4x.json new file mode 100644 index 00000000000..bc375dc17d2 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-gp98-hfvm-2r4x/GHSA-gp98-hfvm-2r4x.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gp98-hfvm-2r4x", + "modified": "2025-05-14T12:31:11Z", + "published": "2025-05-14T12:31:11Z", + "aliases": [ + "CVE-2025-26795" + ], + "details": "Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in Apache IoTDB JDBC driver.\n\nThis issue affects iotdb-jdbc: from 0.10.0 through 1.3.3, from 2.0.1-beta before 2.0.2.\n\nUsers are recommended to upgrade to version 2.0.2 and 1.3.4, which fix the issue.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26795" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/bj0ytxr5wg0c4jw8xm7rhfd8ogho0r91" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/05/14/3" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T11:16:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-r263-h39v-v2j9/GHSA-r263-h39v-v2j9.json b/advisories/unreviewed/2025/05/GHSA-r263-h39v-v2j9/GHSA-r263-h39v-v2j9.json new file mode 100644 index 00000000000..1d9620f0ea6 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-r263-h39v-v2j9/GHSA-r263-h39v-v2j9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r263-h39v-v2j9", + "modified": "2025-05-14T12:31:11Z", + "published": "2025-05-14T12:31:11Z", + "aliases": [ + "CVE-2025-3833" + ], + "details": "Zohocorp ManageEngine ADSelfService Plus versions 6513 and prior are vulnerable to authenticated SQL injection in the MFA reports.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3833" + }, + { + "type": "WEB", + "url": "https://www.manageengine.com/products/self-service-password/advisory/CVE-2025-3833.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T11:16:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rpg2-jvhp-h354/GHSA-rpg2-jvhp-h354.json b/advisories/unreviewed/2025/05/GHSA-rpg2-jvhp-h354/GHSA-rpg2-jvhp-h354.json new file mode 100644 index 00000000000..f75a8d9691d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-rpg2-jvhp-h354/GHSA-rpg2-jvhp-h354.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rpg2-jvhp-h354", + "modified": "2025-05-14T12:31:12Z", + "published": "2025-05-14T12:31:12Z", + "aliases": [ + "CVE-2025-3931" + ], + "details": "A flaw was found in Yggdrasil, which acts as a system broker, allowing the processes to communicate to other children's \"worker\" processes through the DBus component. Yggdrasil creates a DBus method to dispatch messages to workers. However, it misses authentication and authorization checks, allowing every system user to call it. One available Yggdrasil worker acts as a package manager with capabilities to create and enable new repositories and install or remove packages. \n\nThis flaw allows an attacker with access to the system to leverage the lack of authentication on the dispatch message to force the Yggdrasil worker to install arbitrary RPM packages. This issue results in local privilege escalation, enabling the attacker to access and modify sensitive system data.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3931" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:7592" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2025-3931" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2362345" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-280" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T12:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-xq7c-hjvw-rh5f/GHSA-xq7c-hjvw-rh5f.json b/advisories/unreviewed/2025/05/GHSA-xq7c-hjvw-rh5f/GHSA-xq7c-hjvw-rh5f.json new file mode 100644 index 00000000000..e9de3782039 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-xq7c-hjvw-rh5f/GHSA-xq7c-hjvw-rh5f.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xq7c-hjvw-rh5f", + "modified": "2025-05-14T12:31:12Z", + "published": "2025-05-14T12:31:12Z", + "aliases": [ + "CVE-2025-3769" + ], + "details": "The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.92 via the 'view_booking_summary_in_lightbox' due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to retrieve appointment details such as customer names and email addresses.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3769" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/latepoint/trunk/lib/controllers/customer_cabinet_controller.php" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3291162" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/7e9acd26-c341-4ece-bcf1-102f953a4b4f?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-14T12:15:18Z" + } +} \ No newline at end of file