Publish Advisories

GHSA-37w5-m4jw-wvfc
GHSA-4jmc-cgpx-wfmf
GHSA-gh3f-64h2-9gjh
GHSA-hc38-wh54-qgvx
GHSA-hmmg-5pjc-xm6h
GHSA-wgq3-vq6c-fvpp
GHSA-573j-p665-w834
GHSA-9279-xrgq-m4hp
GHSA-g9m2-7jc6-pmvf
GHSA-rm74-9v34-j945
GHSA-w7gh-f2fm-9q8r
GHSA-wjm4-hw2r-m766
GHSA-xjjj-rcfc-fp6h
This commit is contained in:
advisory-database[bot]
2025-04-17 03:32:21 +00:00
parent b623dfa8ea
commit 31ce1df65a
13 changed files with 299 additions and 6 deletions
@@ -46,7 +46,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-74"
"CWE-74",
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -46,7 +46,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-74"
"CWE-74",
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -46,7 +46,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-74"
"CWE-74",
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hc38-wh54-qgvx",
"modified": "2025-01-09T21:31:28Z",
"modified": "2025-04-17T03:30:27Z",
"published": "2024-12-18T09:31:35Z",
"aliases": [
"CVE-2024-11614"
@@ -47,6 +47,22 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:0222"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:3963"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:3964"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:3965"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:3970"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-11614"
@@ -46,7 +46,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-74"
"CWE-74",
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wgq3-vq6c-fvpp",
"modified": "2025-01-08T09:30:38Z",
"modified": "2025-04-17T03:30:30Z",
"published": "2025-01-08T09:30:38Z",
"aliases": [
"CVE-2024-12045"
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-573j-p665-w834",
"modified": "2025-04-17T03:30:30Z",
"published": "2025-04-17T03:30:30Z",
"aliases": [
"CVE-2025-31340"
],
"details": "A improper control of filename for include/require statement in PHP program vulnerability in the retrieve course Information function of Wisdom Master Pro versions 5.0 through 5.2 allows remote attackers to perform arbitrary system commands by running a malicious file.",
"severity": [
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31340"
},
{
"type": "WEB",
"url": "https://zuso.ai/advisory/za-2025-03"
}
],
"database_specific": {
"cwe_ids": [
"CWE-98"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-17T03:15:16Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9279-xrgq-m4hp",
"modified": "2025-04-17T03:30:30Z",
"published": "2025-04-17T03:30:30Z",
"aliases": [
"CVE-2025-31339"
],
"details": "An unrestricted upload of file with dangerous type vulnerability in the course management function of Wisdom Master Pro versions 5.0 through 5.2 allows remote authenticated users to craft a malicious file.",
"severity": [
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31339"
},
{
"type": "WEB",
"url": "https://zuso.ai/advisory/za-2025-02"
}
],
"database_specific": {
"cwe_ids": [
"CWE-434"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-17T03:15:16Z"
}
}
@@ -0,0 +1,40 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g9m2-7jc6-pmvf",
"modified": "2025-04-17T03:30:30Z",
"published": "2025-04-17T03:30:30Z",
"aliases": [
"CVE-2025-43715"
],
"details": "Nullsoft Scriptable Install System (NSIS) before 3.11 on Windows allows local users to escalate privileges to SYSTEM during an installation, because the temporary plugins directory is created under %WINDIR%\\temp and unprivileged users can place a crafted executable file by winning a race condition. This occurs because EW_CREATEDIR does not always set the CreateRestrictedDirectory error flag.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43715"
},
{
"type": "WEB",
"url": "https://nsis.sourceforge.io/Docs/AppendixF.html#v3.11-rl"
},
{
"type": "WEB",
"url": "https://sourceforge.net/p/nsis/bugs/1315"
}
],
"database_specific": {
"cwe_ids": [
"CWE-754"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-17T03:15:16Z"
}
}
@@ -0,0 +1,33 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rm74-9v34-j945",
"modified": "2025-04-17T03:30:30Z",
"published": "2025-04-17T03:30:30Z",
"aliases": [
"CVE-2025-1290"
],
"details": "A race condition Use-After-Free vulnerability exists in the virtio_transport_space_update function within the Kernel 5.4 on ChromeOS. Concurrent allocation and freeing of the virtio_vsock_sock structure \nduring an AF_VSOCK connect syscall can occur before a worker thread accesses it resulting in a dangling pointer and potential kernel code execution.",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1290"
},
{
"type": "WEB",
"url": "https://issues.chromium.org/issues/b/301886931"
},
{
"type": "WEB",
"url": "https://issuetracker.google.com/issues/301886931"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-17T01:15:46Z"
}
}
@@ -0,0 +1,48 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w7gh-f2fm-9q8r",
"modified": "2025-04-17T03:30:30Z",
"published": "2025-04-17T03:30:30Z",
"aliases": [
"CVE-2025-43717"
],
"details": "In PEAR HTTP_Request2 before 2.7.0, multiple files in the tests directory, notably tests/_network/getparameters.php and tests/_network/postparameters.php, reflect any GET or POST parameters, leading to XSS.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43717"
},
{
"type": "WEB",
"url": "https://github.com/pear/HTTP_Request2/commit/07925aa77e441dba0ff0fa973a09802729cb838f"
},
{
"type": "WEB",
"url": "https://github.com/pear/HTTP_Request2/commit/265e05f9e08a28a38a57219516a8e4e2dfdbb147"
},
{
"type": "WEB",
"url": "https://github.com/pear/HTTP_Request2/blob/b1c61b71128045734d757c4d3d436457ace80ea7/package.xml#L24"
},
{
"type": "WEB",
"url": "https://github.com/pear/HTTP_Request2/compare/v2.6.0...v2.7.0"
}
],
"database_specific": {
"cwe_ids": [
"CWE-531"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-17T03:15:16Z"
}
}
@@ -0,0 +1,44 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wjm4-hw2r-m766",
"modified": "2025-04-17T03:30:30Z",
"published": "2025-04-17T03:30:30Z",
"aliases": [
"CVE-2025-43708"
],
"details": "VisiCut 2.1 allows stack consumption via an XML document with nested set elements, as demonstrated by a java.util.HashMap StackOverflowError when reference='../../../set/set[2]' is used, aka an \"insecure deserialization\" issue.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43708"
},
{
"type": "WEB",
"url": "https://github.com/Gelcon/PoC-of-VisiCut2_1-Stack-Overflow-Vul"
},
{
"type": "WEB",
"url": "https://github.com/t-oster/VisiCut"
},
{
"type": "WEB",
"url": "https://visicut.org"
}
],
"database_specific": {
"cwe_ids": [
"CWE-674"
],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-17T01:15:46Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xjjj-rcfc-fp6h",
"modified": "2025-04-17T03:30:30Z",
"published": "2025-04-17T03:30:30Z",
"aliases": [
"CVE-2025-31338"
],
"details": "A missing authorization vulnerability in the retrieve teacher Information function of Wisdom Master Pro versions 5.0 through 5.2 allows remote attackers to obtain partial user data by accessing the API functionality.",
"severity": [
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31338"
},
{
"type": "WEB",
"url": "https://zuso.ai/advisory/za-2025-01"
}
],
"database_specific": {
"cwe_ids": [
"CWE-862"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-17T03:15:15Z"
}
}