Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2025-03-19 15:33:11 +00:00
parent 0bfa4fd94c
commit 34f655601e
31 changed files with 223 additions and 37 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rp28-mvq3-wf8j",
"modified": "2025-03-17T14:34:48Z",
"modified": "2025-03-19T15:32:04Z",
"published": "2025-03-14T15:32:03Z",
"aliases": [
"CVE-2025-2304"
@@ -56,6 +56,10 @@
"type": "WEB",
"url": "https://github.com/owen2345/camaleon-cms/releases/tag/2.9.1"
},
{
"type": "WEB",
"url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/camaleon_cms/CVE-2025-2304.yml"
},
{
"type": "WEB",
"url": "https://www.tenable.com/security/research/tra-2025-09"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2vqp-59qv-pmrc",
"modified": "2023-02-28T18:30:18Z",
"modified": "2025-03-19T15:31:37Z",
"published": "2023-02-17T18:30:24Z",
"aliases": [
"CVE-2021-32142"
@@ -35,6 +35,14 @@
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2023/05/msg00025.html"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5ICTVDRGBWGIFBTUWJLGX7QM5GWBWUG7"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E7TEZ7CLRNYYQZJ5NJGZXK6YJU46WH2L"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5ICTVDRGBWGIFBTUWJLGX7QM5GWBWUG7"
@@ -26,6 +26,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-284",
"CWE-863"
],
"severity": "HIGH",
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hxq3-28qm-p5p4",
"modified": "2023-02-27T15:30:22Z",
"modified": "2025-03-19T15:31:36Z",
"published": "2023-02-17T15:30:25Z",
"aliases": [
"CVE-2020-29168"
@@ -19,6 +19,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2020-29168"
},
{
"type": "WEB",
"url": "https://projectworlds.in/free-projects/php-projects/online-doctor-appointment-booking-system-php-and-mysql/%2C"
},
{
"type": "WEB",
"url": "https://projectworlds.in/free-projects/php-projects/online-doctor-appointment-booking-system-php-and-mysql/,"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wjmr-m5q4-p45g",
"modified": "2023-02-24T21:30:18Z",
"modified": "2025-03-19T15:31:36Z",
"published": "2023-02-16T21:30:26Z",
"aliases": [
"CVE-2022-40080"
@@ -29,7 +29,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-200"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -25,7 +25,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-693"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q77j-868w-97cc",
"modified": "2024-03-26T21:30:47Z",
"modified": "2025-03-19T15:31:38Z",
"published": "2024-03-26T21:30:47Z",
"aliases": [
"CVE-2023-38388"
],
"details": "Unrestricted Upload of File with Dangerous Type vulnerability in Artbees JupiterX Core.This issue affects JupiterX Core: from n/a through 3.3.5.\n\n",
"details": "Unrestricted Upload of File with Dangerous Type vulnerability in Artbees JupiterX Core.This issue affects JupiterX Core: from n/a through 3.3.5.",
"severity": [
{
"type": "CVSS_V3",
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mm6w-vpgv-7hxr",
"modified": "2024-05-06T03:30:47Z",
"modified": "2025-03-19T15:31:38Z",
"published": "2024-05-06T03:30:47Z",
"aliases": [
"CVE-2024-20059"
],
"details": "In da, there is a possible escalation of privilege due to an incorrect status check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541749; Issue ID: ALPS08541749.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -23,7 +28,7 @@
"cwe_ids": [
"CWE-1332"
],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-06T03:15:09Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mqv8-r98f-v6vp",
"modified": "2024-05-21T06:30:51Z",
"modified": "2025-03-19T15:31:38Z",
"published": "2024-05-21T06:30:51Z",
"aliases": [
"CVE-2024-4289"
],
"details": "The Sailthru Triggermail WordPress plugin through 1.1 does not sanitise and escape various parameters before outputting them back in pages and attributes, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
@@ -21,7 +26,7 @@
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-05-21T06:15:09Z"
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7p4c-c4rq-7g98",
"modified": "2024-09-19T18:30:49Z",
"modified": "2025-03-19T15:31:38Z",
"published": "2024-06-22T09:30:51Z",
"aliases": [
"CVE-2024-38379"
],
"details": "Apache Allura's neighborhood settings are vulnerable to a stored XSS attack.  Only neighborhood admins can access these settings, so the scope of risk is limited to configurations where neighborhood admins are not fully trusted.\n\nThis issue affects Apache Allura: from 1.4.0 through 1.17.0.\n\nUsers are recommended to upgrade to version 1.17.1, which fixes the issue.\n\n",
"details": "Apache Allura's neighborhood settings are vulnerable to a stored XSS attack.  Only neighborhood admins can access these settings, so the scope of risk is limited to configurations where neighborhood admins are not fully trusted.\n\nThis issue affects Apache Allura: from 1.4.0 through 1.17.0.\n\nUsers are recommended to upgrade to version 1.17.1, which fixes the issue.",
"severity": [
{
"type": "CVSS_V3",
@@ -22,6 +22,10 @@
{
"type": "WEB",
"url": "https://lists.apache.org/thread/2lb6vp00sj2b2snpmhff5lyortxjsnrp"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2024/06/21/1"
}
],
"database_specific": {
@@ -30,7 +30,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-129"
"CWE-129",
"CWE-20"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -25,7 +25,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-200"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -37,7 +37,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-200"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -37,7 +37,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-119"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -29,7 +29,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-125"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -29,7 +29,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-200"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -34,6 +34,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-200",
"CWE-922"
],
"severity": "CRITICAL",
@@ -30,7 +30,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-276"
"CWE-276",
"CWE-284",
"CWE-863"
],
"severity": "CRITICAL",
"github_reviewed": false,
@@ -29,7 +29,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-532"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,

Some files were not shown because too many files have changed in this diff Show More