diff --git a/advisories/unreviewed/2023/03/GHSA-58m3-63qv-6g2g/GHSA-58m3-63qv-6g2g.json b/advisories/unreviewed/2023/03/GHSA-58m3-63qv-6g2g/GHSA-58m3-63qv-6g2g.json index c2c4770f50b..ff6bc42adb1 100644 --- a/advisories/unreviewed/2023/03/GHSA-58m3-63qv-6g2g/GHSA-58m3-63qv-6g2g.json +++ b/advisories/unreviewed/2023/03/GHSA-58m3-63qv-6g2g/GHSA-58m3-63qv-6g2g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-58m3-63qv-6g2g", - "modified": "2023-04-03T18:32:07Z", + "modified": "2025-02-24T21:31:43Z", "published": "2023-03-28T00:34:28Z", "aliases": [ "CVE-2022-48349" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-290" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/03/GHSA-5hgj-5c28-fh2j/GHSA-5hgj-5c28-fh2j.json b/advisories/unreviewed/2023/03/GHSA-5hgj-5c28-fh2j/GHSA-5hgj-5c28-fh2j.json index 29eb7122cc9..1194cefa908 100644 --- a/advisories/unreviewed/2023/03/GHSA-5hgj-5c28-fh2j/GHSA-5hgj-5c28-fh2j.json +++ b/advisories/unreviewed/2023/03/GHSA-5hgj-5c28-fh2j/GHSA-5hgj-5c28-fh2j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5hgj-5c28-fh2j", - "modified": "2023-04-03T18:32:09Z", + "modified": "2025-02-24T21:31:43Z", "published": "2023-03-28T00:34:28Z", "aliases": [ "CVE-2022-48348" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/03/GHSA-c662-3p6q-p5c7/GHSA-c662-3p6q-p5c7.json b/advisories/unreviewed/2023/03/GHSA-c662-3p6q-p5c7/GHSA-c662-3p6q-p5c7.json index 7f0202e3523..1f469eb81a0 100644 --- a/advisories/unreviewed/2023/03/GHSA-c662-3p6q-p5c7/GHSA-c662-3p6q-p5c7.json +++ b/advisories/unreviewed/2023/03/GHSA-c662-3p6q-p5c7/GHSA-c662-3p6q-p5c7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c662-3p6q-p5c7", - "modified": "2023-04-04T03:30:17Z", + "modified": "2025-02-24T21:31:43Z", "published": "2023-03-28T00:34:28Z", "aliases": [ "CVE-2022-3116" diff --git a/advisories/unreviewed/2023/03/GHSA-c8f9-2rww-56v5/GHSA-c8f9-2rww-56v5.json b/advisories/unreviewed/2023/03/GHSA-c8f9-2rww-56v5/GHSA-c8f9-2rww-56v5.json index 1ee044fca06..d6ba25cb7ab 100644 --- a/advisories/unreviewed/2023/03/GHSA-c8f9-2rww-56v5/GHSA-c8f9-2rww-56v5.json +++ b/advisories/unreviewed/2023/03/GHSA-c8f9-2rww-56v5/GHSA-c8f9-2rww-56v5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c8f9-2rww-56v5", - "modified": "2023-04-03T18:32:08Z", + "modified": "2025-02-24T21:31:42Z", "published": "2023-03-27T21:30:26Z", "aliases": [ "CVE-2021-3923" @@ -23,13 +23,19 @@ "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2019643" }, + { + "type": "WEB", + "url": "https://lore.kernel.org/all/20220204100036.GA12348%40kili" + }, { "type": "WEB", "url": "https://lore.kernel.org/all/20220204100036.GA12348@kili" } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-2xfx-cg6v-cwqv/GHSA-2xfx-cg6v-cwqv.json b/advisories/unreviewed/2025/02/GHSA-2xfx-cg6v-cwqv/GHSA-2xfx-cg6v-cwqv.json index 5726800647a..dafa672e59a 100644 --- a/advisories/unreviewed/2025/02/GHSA-2xfx-cg6v-cwqv/GHSA-2xfx-cg6v-cwqv.json +++ b/advisories/unreviewed/2025/02/GHSA-2xfx-cg6v-cwqv/GHSA-2xfx-cg6v-cwqv.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-3xgj-vqg4-h895/GHSA-3xgj-vqg4-h895.json b/advisories/unreviewed/2025/02/GHSA-3xgj-vqg4-h895/GHSA-3xgj-vqg4-h895.json new file mode 100644 index 00000000000..5303a4f356f --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-3xgj-vqg4-h895/GHSA-3xgj-vqg4-h895.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3xgj-vqg4-h895", + "modified": "2025-02-24T21:31:44Z", + "published": "2025-02-24T21:31:43Z", + "aliases": [ + "CVE-2025-27364" + ], + "details": "In MITRE Caldera through 4.2.0 and 5.0.0 before 35bc06e, a Remote Code Execution (RCE) vulnerability was found in the dynamic agent (implant) compilation functionality of the server. This allows remote attackers to execute arbitrary code on the server that Caldera is running on via a crafted web request to the Caldera server API used for compiling and downloading of Caldera's Sandcat or Manx agent (implants). This web request can use the gcc -extldflags linker flag with sub-commands.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27364" + }, + { + "type": "WEB", + "url": "https://github.com/mitre/caldera/pull/3129" + }, + { + "type": "WEB", + "url": "https://github.com/mitre/caldera/pull/3131/commits/61de40f92a595bed462372a5e676c2e5a32d1050" + }, + { + "type": "WEB", + "url": "https://github.com/mitre/caldera/commit/35bc06e42e19fe7efbc008999b9f993b1b7109c0" + }, + { + "type": "WEB", + "url": "https://github.com/mitre/caldera/releases" + }, + { + "type": "WEB", + "url": "https://github.com/mitre/caldera/security" + }, + { + "type": "WEB", + "url": "https://medium.com/@mitrecaldera/mitre-caldera-security-advisory-remote-code-execution-cve-2025-27364-5f679e2e2a0e" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T19:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-4hmr-39vp-xfrr/GHSA-4hmr-39vp-xfrr.json b/advisories/unreviewed/2025/02/GHSA-4hmr-39vp-xfrr/GHSA-4hmr-39vp-xfrr.json new file mode 100644 index 00000000000..bbcca8c6119 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-4hmr-39vp-xfrr/GHSA-4hmr-39vp-xfrr.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4hmr-39vp-xfrr", + "modified": "2025-02-24T21:31:44Z", + "published": "2025-02-24T21:31:44Z", + "aliases": [ + "CVE-2025-26525" + ], + "details": "Insufficient sanitizing in the TeX notation filter resulted in an \narbitrary file read risk on sites where pdfTeX is available (such as \nthose with TeX Live installed).", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26525" + }, + { + "type": "WEB", + "url": "https://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-84136" + }, + { + "type": "WEB", + "url": "https://moodle.org/mod/forum/discuss.php?d=466141" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-552" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T20:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-4w32-c9g7-27qx/GHSA-4w32-c9g7-27qx.json b/advisories/unreviewed/2025/02/GHSA-4w32-c9g7-27qx/GHSA-4w32-c9g7-27qx.json new file mode 100644 index 00000000000..e72cf3425b6 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-4w32-c9g7-27qx/GHSA-4w32-c9g7-27qx.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4w32-c9g7-27qx", + "modified": "2025-02-24T21:31:44Z", + "published": "2025-02-24T21:31:44Z", + "aliases": [ + "CVE-2025-26530" + ], + "details": "The question bank filter required additional sanitizing to prevent a reflected XSS risk.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26530" + }, + { + "type": "WEB", + "url": "https://moodle.org/mod/forum/discuss.php?d=466146" + }, + { + "type": "WEB", + "url": "http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-84146" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T20:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-5r85-6h7f-rg3r/GHSA-5r85-6h7f-rg3r.json b/advisories/unreviewed/2025/02/GHSA-5r85-6h7f-rg3r/GHSA-5r85-6h7f-rg3r.json new file mode 100644 index 00000000000..5d4a66f9e10 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-5r85-6h7f-rg3r/GHSA-5r85-6h7f-rg3r.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5r85-6h7f-rg3r", + "modified": "2025-02-24T21:31:44Z", + "published": "2025-02-24T21:31:44Z", + "aliases": [ + "CVE-2025-26527" + ], + "details": "Tags not expected to be visible to a user could still be discovered by them via the tag search page or in the tags block.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26527" + }, + { + "type": "WEB", + "url": "https://moodle.org/mod/forum/discuss.php?d=466143" + }, + { + "type": "WEB", + "url": "http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-83941" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1230" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T20:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-cw24-f6fq-7j9v/GHSA-cw24-f6fq-7j9v.json b/advisories/unreviewed/2025/02/GHSA-cw24-f6fq-7j9v/GHSA-cw24-f6fq-7j9v.json new file mode 100644 index 00000000000..5f4ea2698fd --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-cw24-f6fq-7j9v/GHSA-cw24-f6fq-7j9v.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cw24-f6fq-7j9v", + "modified": "2025-02-24T21:31:44Z", + "published": "2025-02-24T21:31:44Z", + "aliases": [ + "CVE-2025-26532" + ], + "details": "Additional checks were required to ensure trusttext is applied (when enabled) to glossary entries being restored.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26532" + }, + { + "type": "WEB", + "url": "https://moodle.org/mod/forum/discuss.php?d=466149" + }, + { + "type": "WEB", + "url": "http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-84003" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T20:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-g88w-v4cq-qgcp/GHSA-g88w-v4cq-qgcp.json b/advisories/unreviewed/2025/02/GHSA-g88w-v4cq-qgcp/GHSA-g88w-v4cq-qgcp.json new file mode 100644 index 00000000000..b0ee4a89ad8 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-g88w-v4cq-qgcp/GHSA-g88w-v4cq-qgcp.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g88w-v4cq-qgcp", + "modified": "2025-02-24T21:31:44Z", + "published": "2025-02-24T21:31:44Z", + "aliases": [ + "CVE-2025-26531" + ], + "details": "Insufficient capability checks made it possible to disable badges a user does not have permission to access.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26531" + }, + { + "type": "WEB", + "url": "https://moodle.org/mod/forum/discuss.php?d=466148" + }, + { + "type": "WEB", + "url": "http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-84239" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T20:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-h697-w4ph-7pcx/GHSA-h697-w4ph-7pcx.json b/advisories/unreviewed/2025/02/GHSA-h697-w4ph-7pcx/GHSA-h697-w4ph-7pcx.json new file mode 100644 index 00000000000..dc0a32c40de --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-h697-w4ph-7pcx/GHSA-h697-w4ph-7pcx.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h697-w4ph-7pcx", + "modified": "2025-02-24T21:31:44Z", + "published": "2025-02-24T21:31:44Z", + "aliases": [ + "CVE-2025-26528" + ], + "details": "The drag-and-drop onto image (ddimageortext) question type required additional sanitizing to prevent a stored XSS risk.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26528" + }, + { + "type": "WEB", + "url": "https://moodle.org/mod/forum/discuss.php?d=466144" + }, + { + "type": "WEB", + "url": "http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-82896" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T20:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-pxg4-xjp7-w9c5/GHSA-pxg4-xjp7-w9c5.json b/advisories/unreviewed/2025/02/GHSA-pxg4-xjp7-w9c5/GHSA-pxg4-xjp7-w9c5.json new file mode 100644 index 00000000000..7e198d0852c --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-pxg4-xjp7-w9c5/GHSA-pxg4-xjp7-w9c5.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pxg4-xjp7-w9c5", + "modified": "2025-02-24T21:31:44Z", + "published": "2025-02-24T21:31:44Z", + "aliases": [ + "CVE-2025-26526" + ], + "details": "Separate Groups mode restrictions were not factored into permission \nchecks before allowing viewing or deletion of responses in Feedback \nactivities.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26526" + }, + { + "type": "WEB", + "url": "https://moodle.org/mod/forum/discuss.php?d=466142" + }, + { + "type": "WEB", + "url": "http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-79976" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T20:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-rg56-94j7-hjx9/GHSA-rg56-94j7-hjx9.json b/advisories/unreviewed/2025/02/GHSA-rg56-94j7-hjx9/GHSA-rg56-94j7-hjx9.json new file mode 100644 index 00000000000..cb62f77b23c --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-rg56-94j7-hjx9/GHSA-rg56-94j7-hjx9.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rg56-94j7-hjx9", + "modified": "2025-02-24T21:31:44Z", + "published": "2025-02-24T21:31:44Z", + "aliases": [ + "CVE-2025-26533" + ], + "details": "An SQL injection risk was identified in the module list filter within course search.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26533" + }, + { + "type": "WEB", + "url": "https://moodle.org/mod/forum/discuss.php?d=466150" + }, + { + "type": "WEB", + "url": "http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-84271" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T21:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-wr88-x8cm-7cgq/GHSA-wr88-x8cm-7cgq.json b/advisories/unreviewed/2025/02/GHSA-wr88-x8cm-7cgq/GHSA-wr88-x8cm-7cgq.json new file mode 100644 index 00000000000..a04f35a2641 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-wr88-x8cm-7cgq/GHSA-wr88-x8cm-7cgq.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wr88-x8cm-7cgq", + "modified": "2025-02-24T21:31:44Z", + "published": "2025-02-24T21:31:44Z", + "aliases": [ + "CVE-2025-26529" + ], + "details": "Description information displayed in the site administration live log \nrequired additional sanitizing to prevent a stored XSS risk.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26529" + }, + { + "type": "WEB", + "url": "https://moodle.org/mod/forum/discuss.php?d=466145" + }, + { + "type": "WEB", + "url": "http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-84145" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-24T20:15:33Z" + } +} \ No newline at end of file