Publish Advisories

GHSA-58m3-63qv-6g2g
GHSA-5hgj-5c28-fh2j
GHSA-c662-3p6q-p5c7
GHSA-c8f9-2rww-56v5
GHSA-2xfx-cg6v-cwqv
GHSA-3xgj-vqg4-h895
GHSA-4hmr-39vp-xfrr
GHSA-4w32-c9g7-27qx
GHSA-5r85-6h7f-rg3r
GHSA-cw24-f6fq-7j9v
GHSA-g88w-v4cq-qgcp
GHSA-h697-w4ph-7pcx
GHSA-pxg4-xjp7-w9c5
GHSA-rg56-94j7-hjx9
GHSA-wr88-x8cm-7cgq
This commit is contained in:
advisory-database[bot]
2025-02-24 21:33:10 +00:00
parent fd4e3591e5
commit 2de68f5a70
15 changed files with 436 additions and 8 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-58m3-63qv-6g2g",
"modified": "2023-04-03T18:32:07Z",
"modified": "2025-02-24T21:31:43Z",
"published": "2023-03-28T00:34:28Z",
"aliases": [
"CVE-2022-48349"
@@ -29,7 +29,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-290"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5hgj-5c28-fh2j",
"modified": "2023-04-03T18:32:09Z",
"modified": "2025-02-24T21:31:43Z",
"published": "2023-03-28T00:34:28Z",
"aliases": [
"CVE-2022-48348"
@@ -29,7 +29,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-200"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c662-3p6q-p5c7",
"modified": "2023-04-04T03:30:17Z",
"modified": "2025-02-24T21:31:43Z",
"published": "2023-03-28T00:34:28Z",
"aliases": [
"CVE-2022-3116"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c8f9-2rww-56v5",
"modified": "2023-04-03T18:32:08Z",
"modified": "2025-02-24T21:31:42Z",
"published": "2023-03-27T21:30:26Z",
"aliases": [
"CVE-2021-3923"
@@ -23,13 +23,19 @@
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2019643"
},
{
"type": "WEB",
"url": "https://lore.kernel.org/all/20220204100036.GA12348%40kili"
},
{
"type": "WEB",
"url": "https://lore.kernel.org/all/20220204100036.GA12348@kili"
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-200"
],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -29,7 +29,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-787"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -0,0 +1,56 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3xgj-vqg4-h895",
"modified": "2025-02-24T21:31:44Z",
"published": "2025-02-24T21:31:43Z",
"aliases": [
"CVE-2025-27364"
],
"details": "In MITRE Caldera through 4.2.0 and 5.0.0 before 35bc06e, a Remote Code Execution (RCE) vulnerability was found in the dynamic agent (implant) compilation functionality of the server. This allows remote attackers to execute arbitrary code on the server that Caldera is running on via a crafted web request to the Caldera server API used for compiling and downloading of Caldera's Sandcat or Manx agent (implants). This web request can use the gcc -extldflags linker flag with sub-commands.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27364"
},
{
"type": "WEB",
"url": "https://github.com/mitre/caldera/pull/3129"
},
{
"type": "WEB",
"url": "https://github.com/mitre/caldera/pull/3131/commits/61de40f92a595bed462372a5e676c2e5a32d1050"
},
{
"type": "WEB",
"url": "https://github.com/mitre/caldera/commit/35bc06e42e19fe7efbc008999b9f993b1b7109c0"
},
{
"type": "WEB",
"url": "https://github.com/mitre/caldera/releases"
},
{
"type": "WEB",
"url": "https://github.com/mitre/caldera/security"
},
{
"type": "WEB",
"url": "https://medium.com/@mitrecaldera/mitre-caldera-security-advisory-remote-code-execution-cve-2025-27364-5f679e2e2a0e"
}
],
"database_specific": {
"cwe_ids": [
"CWE-78"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-24T19:15:14Z"
}
}
@@ -0,0 +1,40 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4hmr-39vp-xfrr",
"modified": "2025-02-24T21:31:44Z",
"published": "2025-02-24T21:31:44Z",
"aliases": [
"CVE-2025-26525"
],
"details": "Insufficient sanitizing in the TeX notation filter resulted in an \narbitrary file read risk on sites where pdfTeX is available (such as \nthose with TeX Live installed).",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26525"
},
{
"type": "WEB",
"url": "https://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-84136"
},
{
"type": "WEB",
"url": "https://moodle.org/mod/forum/discuss.php?d=466141"
}
],
"database_specific": {
"cwe_ids": [
"CWE-552"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-24T20:15:33Z"
}
}
@@ -0,0 +1,40 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4w32-c9g7-27qx",
"modified": "2025-02-24T21:31:44Z",
"published": "2025-02-24T21:31:44Z",
"aliases": [
"CVE-2025-26530"
],
"details": "The question bank filter required additional sanitizing to prevent a reflected XSS risk.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26530"
},
{
"type": "WEB",
"url": "https://moodle.org/mod/forum/discuss.php?d=466146"
},
{
"type": "WEB",
"url": "http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-84146"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-24T20:15:33Z"
}
}
@@ -0,0 +1,40 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5r85-6h7f-rg3r",
"modified": "2025-02-24T21:31:44Z",
"published": "2025-02-24T21:31:44Z",
"aliases": [
"CVE-2025-26527"
],
"details": "Tags not expected to be visible to a user could still be discovered by them via the tag search page or in the tags block.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26527"
},
{
"type": "WEB",
"url": "https://moodle.org/mod/forum/discuss.php?d=466143"
},
{
"type": "WEB",
"url": "http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-83941"
}
],
"database_specific": {
"cwe_ids": [
"CWE-1230"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-24T20:15:33Z"
}
}
@@ -0,0 +1,40 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cw24-f6fq-7j9v",
"modified": "2025-02-24T21:31:44Z",
"published": "2025-02-24T21:31:44Z",
"aliases": [
"CVE-2025-26532"
],
"details": "Additional checks were required to ensure trusttext is applied (when enabled) to glossary entries being restored.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26532"
},
{
"type": "WEB",
"url": "https://moodle.org/mod/forum/discuss.php?d=466149"
},
{
"type": "WEB",
"url": "http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-84003"
}
],
"database_specific": {
"cwe_ids": [
"CWE-863"
],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-24T20:15:34Z"
}
}
@@ -0,0 +1,40 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g88w-v4cq-qgcp",
"modified": "2025-02-24T21:31:44Z",
"published": "2025-02-24T21:31:44Z",
"aliases": [
"CVE-2025-26531"
],
"details": "Insufficient capability checks made it possible to disable badges a user does not have permission to access.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26531"
},
{
"type": "WEB",
"url": "https://moodle.org/mod/forum/discuss.php?d=466148"
},
{
"type": "WEB",
"url": "http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-84239"
}
],
"database_specific": {
"cwe_ids": [
"CWE-863"
],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-24T20:15:33Z"
}
}
@@ -0,0 +1,40 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h697-w4ph-7pcx",
"modified": "2025-02-24T21:31:44Z",
"published": "2025-02-24T21:31:44Z",
"aliases": [
"CVE-2025-26528"
],
"details": "The drag-and-drop onto image (ddimageortext) question type required additional sanitizing to prevent a stored XSS risk.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:N/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26528"
},
{
"type": "WEB",
"url": "https://moodle.org/mod/forum/discuss.php?d=466144"
},
{
"type": "WEB",
"url": "http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-82896"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-24T20:15:33Z"
}
}
@@ -0,0 +1,40 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pxg4-xjp7-w9c5",
"modified": "2025-02-24T21:31:44Z",
"published": "2025-02-24T21:31:44Z",
"aliases": [
"CVE-2025-26526"
],
"details": "Separate Groups mode restrictions were not factored into permission \nchecks before allowing viewing or deletion of responses in Feedback \nactivities.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26526"
},
{
"type": "WEB",
"url": "https://moodle.org/mod/forum/discuss.php?d=466142"
},
{
"type": "WEB",
"url": "http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-79976"
}
],
"database_specific": {
"cwe_ids": [
"CWE-863"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-24T20:15:33Z"
}
}
@@ -0,0 +1,40 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rg56-94j7-hjx9",
"modified": "2025-02-24T21:31:44Z",
"published": "2025-02-24T21:31:44Z",
"aliases": [
"CVE-2025-26533"
],
"details": "An SQL injection risk was identified in the module list filter within course search.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26533"
},
{
"type": "WEB",
"url": "https://moodle.org/mod/forum/discuss.php?d=466150"
},
{
"type": "WEB",
"url": "http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-84271"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-24T21:15:11Z"
}
}
@@ -0,0 +1,40 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wr88-x8cm-7cgq",
"modified": "2025-02-24T21:31:44Z",
"published": "2025-02-24T21:31:44Z",
"aliases": [
"CVE-2025-26529"
],
"details": "Description information displayed in the site administration live log \nrequired additional sanitizing to prevent a stored XSS risk.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26529"
},
{
"type": "WEB",
"url": "https://moodle.org/mod/forum/discuss.php?d=466145"
},
{
"type": "WEB",
"url": "http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-84145"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-02-24T20:15:33Z"
}
}