From 34f655601e8cca8d4b05634172ff178160bc1081 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 19 Mar 2025 15:33:11 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-rp28-mvq3-wf8j.json | 6 ++- .../GHSA-2vqp-59qv-pmrc.json | 10 ++++- .../GHSA-hqw3-7ccf-2jm6.json | 1 + .../GHSA-hxq3-28qm-p5p4.json | 6 ++- .../GHSA-wjmr-m5q4-p45g.json | 2 +- .../GHSA-4ghg-fwhw-h8j9.json | 4 +- .../GHSA-hrh4-w8wr-g4mx.json | 4 +- .../GHSA-q77j-868w-97cc.json | 4 +- .../GHSA-mm6w-vpgv-7hxr.json | 11 ++++-- .../GHSA-mqv8-r98f-v6vp.json | 11 ++++-- .../GHSA-7p4c-c4rq-7g98.json | 8 +++- .../GHSA-6qpq-4383-4c38.json | 3 +- .../GHSA-hx98-qf58-hff9.json | 4 +- .../GHSA-qm78-568c-wg6m.json | 4 +- .../GHSA-c477-fwvr-v9fx.json | 4 +- .../GHSA-f97f-26jc-gffx.json | 4 +- .../GHSA-m8vr-gvfq-cv5f.json | 4 +- .../GHSA-2w2w-c8f9-2jq3.json | 1 + .../GHSA-3723-f7xr-2xgj.json | 4 +- .../GHSA-5h7w-p832-4g53.json | 4 +- .../GHSA-7843-77v9-hw36.json | 4 +- .../GHSA-g5wq-3r27-v2x7.json | 1 + .../GHSA-w57r-3v9h-hq4v.json | 4 +- .../GHSA-j3fj-rfh9-7j99.json | 1 + .../GHSA-6qw8-39x3-j5rj.json | 11 ++++-- .../GHSA-6rg8-wqvx-ghg5.json | 1 + .../GHSA-88mr-9r66-x2c9.json | 36 ++++++++++++++++++ .../GHSA-fqrq-xmxj-v47x.json | 36 ++++++++++++++++++ .../GHSA-j7qq-8hrp-f3j8.json | 37 +++++++++++++++++++ .../GHSA-p487-32h6-758c.json | 15 ++++++-- .../GHSA-v3c6-573j-vx99.json | 15 ++++++-- 31 files changed, 223 insertions(+), 37 deletions(-) create mode 100644 advisories/unreviewed/2025/03/GHSA-88mr-9r66-x2c9/GHSA-88mr-9r66-x2c9.json create mode 100644 advisories/unreviewed/2025/03/GHSA-fqrq-xmxj-v47x/GHSA-fqrq-xmxj-v47x.json create mode 100644 advisories/unreviewed/2025/03/GHSA-j7qq-8hrp-f3j8/GHSA-j7qq-8hrp-f3j8.json diff --git a/advisories/github-reviewed/2025/03/GHSA-rp28-mvq3-wf8j/GHSA-rp28-mvq3-wf8j.json b/advisories/github-reviewed/2025/03/GHSA-rp28-mvq3-wf8j/GHSA-rp28-mvq3-wf8j.json index 2a28a49d4d1..5db9e581366 100644 --- a/advisories/github-reviewed/2025/03/GHSA-rp28-mvq3-wf8j/GHSA-rp28-mvq3-wf8j.json +++ b/advisories/github-reviewed/2025/03/GHSA-rp28-mvq3-wf8j/GHSA-rp28-mvq3-wf8j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rp28-mvq3-wf8j", - "modified": "2025-03-17T14:34:48Z", + "modified": "2025-03-19T15:32:04Z", "published": "2025-03-14T15:32:03Z", "aliases": [ "CVE-2025-2304" @@ -56,6 +56,10 @@ "type": "WEB", "url": "https://github.com/owen2345/camaleon-cms/releases/tag/2.9.1" }, + { + "type": "WEB", + "url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/camaleon_cms/CVE-2025-2304.yml" + }, { "type": "WEB", "url": "https://www.tenable.com/security/research/tra-2025-09" diff --git a/advisories/unreviewed/2023/02/GHSA-2vqp-59qv-pmrc/GHSA-2vqp-59qv-pmrc.json b/advisories/unreviewed/2023/02/GHSA-2vqp-59qv-pmrc/GHSA-2vqp-59qv-pmrc.json index d9613e62c63..2e919847cf6 100644 --- a/advisories/unreviewed/2023/02/GHSA-2vqp-59qv-pmrc/GHSA-2vqp-59qv-pmrc.json +++ b/advisories/unreviewed/2023/02/GHSA-2vqp-59qv-pmrc/GHSA-2vqp-59qv-pmrc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2vqp-59qv-pmrc", - "modified": "2023-02-28T18:30:18Z", + "modified": "2025-03-19T15:31:37Z", "published": "2023-02-17T18:30:24Z", "aliases": [ "CVE-2021-32142" @@ -35,6 +35,14 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2023/05/msg00025.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5ICTVDRGBWGIFBTUWJLGX7QM5GWBWUG7" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E7TEZ7CLRNYYQZJ5NJGZXK6YJU46WH2L" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5ICTVDRGBWGIFBTUWJLGX7QM5GWBWUG7" diff --git a/advisories/unreviewed/2023/02/GHSA-hqw3-7ccf-2jm6/GHSA-hqw3-7ccf-2jm6.json b/advisories/unreviewed/2023/02/GHSA-hqw3-7ccf-2jm6/GHSA-hqw3-7ccf-2jm6.json index 9975e79ef12..924c257786c 100644 --- a/advisories/unreviewed/2023/02/GHSA-hqw3-7ccf-2jm6/GHSA-hqw3-7ccf-2jm6.json +++ b/advisories/unreviewed/2023/02/GHSA-hqw3-7ccf-2jm6/GHSA-hqw3-7ccf-2jm6.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-284", "CWE-863" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/02/GHSA-hxq3-28qm-p5p4/GHSA-hxq3-28qm-p5p4.json b/advisories/unreviewed/2023/02/GHSA-hxq3-28qm-p5p4/GHSA-hxq3-28qm-p5p4.json index b45f7a5c3d4..c716595c9b5 100644 --- a/advisories/unreviewed/2023/02/GHSA-hxq3-28qm-p5p4/GHSA-hxq3-28qm-p5p4.json +++ b/advisories/unreviewed/2023/02/GHSA-hxq3-28qm-p5p4/GHSA-hxq3-28qm-p5p4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hxq3-28qm-p5p4", - "modified": "2023-02-27T15:30:22Z", + "modified": "2025-03-19T15:31:36Z", "published": "2023-02-17T15:30:25Z", "aliases": [ "CVE-2020-29168" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-29168" }, + { + "type": "WEB", + "url": "https://projectworlds.in/free-projects/php-projects/online-doctor-appointment-booking-system-php-and-mysql/%2C" + }, { "type": "WEB", "url": "https://projectworlds.in/free-projects/php-projects/online-doctor-appointment-booking-system-php-and-mysql/," diff --git a/advisories/unreviewed/2023/02/GHSA-wjmr-m5q4-p45g/GHSA-wjmr-m5q4-p45g.json b/advisories/unreviewed/2023/02/GHSA-wjmr-m5q4-p45g/GHSA-wjmr-m5q4-p45g.json index 79fcda9647d..de4083be6a9 100644 --- a/advisories/unreviewed/2023/02/GHSA-wjmr-m5q4-p45g/GHSA-wjmr-m5q4-p45g.json +++ b/advisories/unreviewed/2023/02/GHSA-wjmr-m5q4-p45g/GHSA-wjmr-m5q4-p45g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wjmr-m5q4-p45g", - "modified": "2023-02-24T21:30:18Z", + "modified": "2025-03-19T15:31:36Z", "published": "2023-02-16T21:30:26Z", "aliases": [ "CVE-2022-40080" diff --git a/advisories/unreviewed/2024/02/GHSA-4ghg-fwhw-h8j9/GHSA-4ghg-fwhw-h8j9.json b/advisories/unreviewed/2024/02/GHSA-4ghg-fwhw-h8j9/GHSA-4ghg-fwhw-h8j9.json index c4727e8dec0..b26865f722e 100644 --- a/advisories/unreviewed/2024/02/GHSA-4ghg-fwhw-h8j9/GHSA-4ghg-fwhw-h8j9.json +++ b/advisories/unreviewed/2024/02/GHSA-4ghg-fwhw-h8j9/GHSA-4ghg-fwhw-h8j9.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-hrh4-w8wr-g4mx/GHSA-hrh4-w8wr-g4mx.json b/advisories/unreviewed/2024/02/GHSA-hrh4-w8wr-g4mx/GHSA-hrh4-w8wr-g4mx.json index f8d6098f79b..5f0e159bf92 100644 --- a/advisories/unreviewed/2024/02/GHSA-hrh4-w8wr-g4mx/GHSA-hrh4-w8wr-g4mx.json +++ b/advisories/unreviewed/2024/02/GHSA-hrh4-w8wr-g4mx/GHSA-hrh4-w8wr-g4mx.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-693" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-q77j-868w-97cc/GHSA-q77j-868w-97cc.json b/advisories/unreviewed/2024/03/GHSA-q77j-868w-97cc/GHSA-q77j-868w-97cc.json index 19993acb72c..01080f5e9c5 100644 --- a/advisories/unreviewed/2024/03/GHSA-q77j-868w-97cc/GHSA-q77j-868w-97cc.json +++ b/advisories/unreviewed/2024/03/GHSA-q77j-868w-97cc/GHSA-q77j-868w-97cc.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-q77j-868w-97cc", - "modified": "2024-03-26T21:30:47Z", + "modified": "2025-03-19T15:31:38Z", "published": "2024-03-26T21:30:47Z", "aliases": [ "CVE-2023-38388" ], - "details": "Unrestricted Upload of File with Dangerous Type vulnerability in Artbees JupiterX Core.This issue affects JupiterX Core: from n/a through 3.3.5.\n\n", + "details": "Unrestricted Upload of File with Dangerous Type vulnerability in Artbees JupiterX Core.This issue affects JupiterX Core: from n/a through 3.3.5.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/05/GHSA-mm6w-vpgv-7hxr/GHSA-mm6w-vpgv-7hxr.json b/advisories/unreviewed/2024/05/GHSA-mm6w-vpgv-7hxr/GHSA-mm6w-vpgv-7hxr.json index b700e9a75ff..97f8ac79aa9 100644 --- a/advisories/unreviewed/2024/05/GHSA-mm6w-vpgv-7hxr/GHSA-mm6w-vpgv-7hxr.json +++ b/advisories/unreviewed/2024/05/GHSA-mm6w-vpgv-7hxr/GHSA-mm6w-vpgv-7hxr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mm6w-vpgv-7hxr", - "modified": "2024-05-06T03:30:47Z", + "modified": "2025-03-19T15:31:38Z", "published": "2024-05-06T03:30:47Z", "aliases": [ "CVE-2024-20059" ], "details": "In da, there is a possible escalation of privilege due to an incorrect status check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541749; Issue ID: ALPS08541749.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-1332" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-06T03:15:09Z" diff --git a/advisories/unreviewed/2024/05/GHSA-mqv8-r98f-v6vp/GHSA-mqv8-r98f-v6vp.json b/advisories/unreviewed/2024/05/GHSA-mqv8-r98f-v6vp/GHSA-mqv8-r98f-v6vp.json index 1fee7b7233c..4153be4b919 100644 --- a/advisories/unreviewed/2024/05/GHSA-mqv8-r98f-v6vp/GHSA-mqv8-r98f-v6vp.json +++ b/advisories/unreviewed/2024/05/GHSA-mqv8-r98f-v6vp/GHSA-mqv8-r98f-v6vp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mqv8-r98f-v6vp", - "modified": "2024-05-21T06:30:51Z", + "modified": "2025-03-19T15:31:38Z", "published": "2024-05-21T06:30:51Z", "aliases": [ "CVE-2024-4289" ], "details": "The Sailthru Triggermail WordPress plugin through 1.1 does not sanitise and escape various parameters before outputting them back in pages and attributes, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T06:15:09Z" diff --git a/advisories/unreviewed/2024/06/GHSA-7p4c-c4rq-7g98/GHSA-7p4c-c4rq-7g98.json b/advisories/unreviewed/2024/06/GHSA-7p4c-c4rq-7g98/GHSA-7p4c-c4rq-7g98.json index d47115b5125..d9e541c4cc8 100644 --- a/advisories/unreviewed/2024/06/GHSA-7p4c-c4rq-7g98/GHSA-7p4c-c4rq-7g98.json +++ b/advisories/unreviewed/2024/06/GHSA-7p4c-c4rq-7g98/GHSA-7p4c-c4rq-7g98.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-7p4c-c4rq-7g98", - "modified": "2024-09-19T18:30:49Z", + "modified": "2025-03-19T15:31:38Z", "published": "2024-06-22T09:30:51Z", "aliases": [ "CVE-2024-38379" ], - "details": "Apache Allura's neighborhood settings are vulnerable to a stored XSS attack.  Only neighborhood admins can access these settings, so the scope of risk is limited to configurations where neighborhood admins are not fully trusted.\n\nThis issue affects Apache Allura: from 1.4.0 through 1.17.0.\n\nUsers are recommended to upgrade to version 1.17.1, which fixes the issue.\n\n", + "details": "Apache Allura's neighborhood settings are vulnerable to a stored XSS attack.  Only neighborhood admins can access these settings, so the scope of risk is limited to configurations where neighborhood admins are not fully trusted.\n\nThis issue affects Apache Allura: from 1.4.0 through 1.17.0.\n\nUsers are recommended to upgrade to version 1.17.1, which fixes the issue.", "severity": [ { "type": "CVSS_V3", @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://lists.apache.org/thread/2lb6vp00sj2b2snpmhff5lyortxjsnrp" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/06/21/1" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/08/GHSA-6qpq-4383-4c38/GHSA-6qpq-4383-4c38.json b/advisories/unreviewed/2024/08/GHSA-6qpq-4383-4c38/GHSA-6qpq-4383-4c38.json index 2a944a5c7f3..07495511d78 100644 --- a/advisories/unreviewed/2024/08/GHSA-6qpq-4383-4c38/GHSA-6qpq-4383-4c38.json +++ b/advisories/unreviewed/2024/08/GHSA-6qpq-4383-4c38/GHSA-6qpq-4383-4c38.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-129" + "CWE-129", + "CWE-20" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/09/GHSA-hx98-qf58-hff9/GHSA-hx98-qf58-hff9.json b/advisories/unreviewed/2024/09/GHSA-hx98-qf58-hff9/GHSA-hx98-qf58-hff9.json index 75f2c49f348..b59e8ea0bfd 100644 --- a/advisories/unreviewed/2024/09/GHSA-hx98-qf58-hff9/GHSA-hx98-qf58-hff9.json +++ b/advisories/unreviewed/2024/09/GHSA-hx98-qf58-hff9/GHSA-hx98-qf58-hff9.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/09/GHSA-qm78-568c-wg6m/GHSA-qm78-568c-wg6m.json b/advisories/unreviewed/2024/09/GHSA-qm78-568c-wg6m/GHSA-qm78-568c-wg6m.json index 8d8d28d15a1..b350598970a 100644 --- a/advisories/unreviewed/2024/09/GHSA-qm78-568c-wg6m/GHSA-qm78-568c-wg6m.json +++ b/advisories/unreviewed/2024/09/GHSA-qm78-568c-wg6m/GHSA-qm78-568c-wg6m.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/10/GHSA-c477-fwvr-v9fx/GHSA-c477-fwvr-v9fx.json b/advisories/unreviewed/2024/10/GHSA-c477-fwvr-v9fx/GHSA-c477-fwvr-v9fx.json index e1d7996f736..09f158dcf79 100644 --- a/advisories/unreviewed/2024/10/GHSA-c477-fwvr-v9fx/GHSA-c477-fwvr-v9fx.json +++ b/advisories/unreviewed/2024/10/GHSA-c477-fwvr-v9fx/GHSA-c477-fwvr-v9fx.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-119" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/10/GHSA-f97f-26jc-gffx/GHSA-f97f-26jc-gffx.json b/advisories/unreviewed/2024/10/GHSA-f97f-26jc-gffx/GHSA-f97f-26jc-gffx.json index de1b942d944..65af21c5486 100644 --- a/advisories/unreviewed/2024/10/GHSA-f97f-26jc-gffx/GHSA-f97f-26jc-gffx.json +++ b/advisories/unreviewed/2024/10/GHSA-f97f-26jc-gffx/GHSA-f97f-26jc-gffx.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-125" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/10/GHSA-m8vr-gvfq-cv5f/GHSA-m8vr-gvfq-cv5f.json b/advisories/unreviewed/2024/10/GHSA-m8vr-gvfq-cv5f/GHSA-m8vr-gvfq-cv5f.json index c52e2a5f830..4ebfb943c3b 100644 --- a/advisories/unreviewed/2024/10/GHSA-m8vr-gvfq-cv5f/GHSA-m8vr-gvfq-cv5f.json +++ b/advisories/unreviewed/2024/10/GHSA-m8vr-gvfq-cv5f/GHSA-m8vr-gvfq-cv5f.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-2w2w-c8f9-2jq3/GHSA-2w2w-c8f9-2jq3.json b/advisories/unreviewed/2025/01/GHSA-2w2w-c8f9-2jq3/GHSA-2w2w-c8f9-2jq3.json index 52cd2e4f0a1..819ccb226e8 100644 --- a/advisories/unreviewed/2025/01/GHSA-2w2w-c8f9-2jq3/GHSA-2w2w-c8f9-2jq3.json +++ b/advisories/unreviewed/2025/01/GHSA-2w2w-c8f9-2jq3/GHSA-2w2w-c8f9-2jq3.json @@ -34,6 +34,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-200", "CWE-922" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2025/01/GHSA-3723-f7xr-2xgj/GHSA-3723-f7xr-2xgj.json b/advisories/unreviewed/2025/01/GHSA-3723-f7xr-2xgj/GHSA-3723-f7xr-2xgj.json index edd4b73d278..75fc2394804 100644 --- a/advisories/unreviewed/2025/01/GHSA-3723-f7xr-2xgj/GHSA-3723-f7xr-2xgj.json +++ b/advisories/unreviewed/2025/01/GHSA-3723-f7xr-2xgj/GHSA-3723-f7xr-2xgj.json @@ -30,7 +30,9 @@ ], "database_specific": { "cwe_ids": [ - "CWE-276" + "CWE-276", + "CWE-284", + "CWE-863" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-5h7w-p832-4g53/GHSA-5h7w-p832-4g53.json b/advisories/unreviewed/2025/01/GHSA-5h7w-p832-4g53/GHSA-5h7w-p832-4g53.json index 06f690bbba9..de354a131ce 100644 --- a/advisories/unreviewed/2025/01/GHSA-5h7w-p832-4g53/GHSA-5h7w-p832-4g53.json +++ b/advisories/unreviewed/2025/01/GHSA-5h7w-p832-4g53/GHSA-5h7w-p832-4g53.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-532" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-7843-77v9-hw36/GHSA-7843-77v9-hw36.json b/advisories/unreviewed/2025/01/GHSA-7843-77v9-hw36/GHSA-7843-77v9-hw36.json index 5551af58743..d758fd50c45 100644 --- a/advisories/unreviewed/2025/01/GHSA-7843-77v9-hw36/GHSA-7843-77v9-hw36.json +++ b/advisories/unreviewed/2025/01/GHSA-7843-77v9-hw36/GHSA-7843-77v9-hw36.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-g5wq-3r27-v2x7/GHSA-g5wq-3r27-v2x7.json b/advisories/unreviewed/2025/01/GHSA-g5wq-3r27-v2x7/GHSA-g5wq-3r27-v2x7.json index bda49765f9d..5924b78c26d 100644 --- a/advisories/unreviewed/2025/01/GHSA-g5wq-3r27-v2x7/GHSA-g5wq-3r27-v2x7.json +++ b/advisories/unreviewed/2025/01/GHSA-g5wq-3r27-v2x7/GHSA-g5wq-3r27-v2x7.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-400", "CWE-476" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2025/01/GHSA-w57r-3v9h-hq4v/GHSA-w57r-3v9h-hq4v.json b/advisories/unreviewed/2025/01/GHSA-w57r-3v9h-hq4v/GHSA-w57r-3v9h-hq4v.json index 32480dcc47f..024bf3fa5ba 100644 --- a/advisories/unreviewed/2025/01/GHSA-w57r-3v9h-hq4v/GHSA-w57r-3v9h-hq4v.json +++ b/advisories/unreviewed/2025/01/GHSA-w57r-3v9h-hq4v/GHSA-w57r-3v9h-hq4v.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-j3fj-rfh9-7j99/GHSA-j3fj-rfh9-7j99.json b/advisories/unreviewed/2025/02/GHSA-j3fj-rfh9-7j99/GHSA-j3fj-rfh9-7j99.json index 88873ea2f15..dc51107824f 100644 --- a/advisories/unreviewed/2025/02/GHSA-j3fj-rfh9-7j99/GHSA-j3fj-rfh9-7j99.json +++ b/advisories/unreviewed/2025/02/GHSA-j3fj-rfh9-7j99/GHSA-j3fj-rfh9-7j99.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-667", "CWE-833" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2025/03/GHSA-6qw8-39x3-j5rj/GHSA-6qw8-39x3-j5rj.json b/advisories/unreviewed/2025/03/GHSA-6qw8-39x3-j5rj/GHSA-6qw8-39x3-j5rj.json index 9b3051699a6..439a76435cd 100644 --- a/advisories/unreviewed/2025/03/GHSA-6qw8-39x3-j5rj/GHSA-6qw8-39x3-j5rj.json +++ b/advisories/unreviewed/2025/03/GHSA-6qw8-39x3-j5rj/GHSA-6qw8-39x3-j5rj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6qw8-39x3-j5rj", - "modified": "2025-03-19T06:31:54Z", + "modified": "2025-03-19T15:31:45Z", "published": "2025-03-19T06:31:54Z", "aliases": [ "CVE-2025-1232" ], "details": "The Site Reviews WordPress plugin before 7.2.5 does not properly sanitise and escape some of its Review fields, which could allow unauthenticated users to perform Stored XSS attacks", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-19T06:15:15Z" diff --git a/advisories/unreviewed/2025/03/GHSA-6rg8-wqvx-ghg5/GHSA-6rg8-wqvx-ghg5.json b/advisories/unreviewed/2025/03/GHSA-6rg8-wqvx-ghg5/GHSA-6rg8-wqvx-ghg5.json index 1f498f71d58..0f70a5f4f46 100644 --- a/advisories/unreviewed/2025/03/GHSA-6rg8-wqvx-ghg5/GHSA-6rg8-wqvx-ghg5.json +++ b/advisories/unreviewed/2025/03/GHSA-6rg8-wqvx-ghg5/GHSA-6rg8-wqvx-ghg5.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-312", "CWE-526" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2025/03/GHSA-88mr-9r66-x2c9/GHSA-88mr-9r66-x2c9.json b/advisories/unreviewed/2025/03/GHSA-88mr-9r66-x2c9/GHSA-88mr-9r66-x2c9.json new file mode 100644 index 00000000000..bcb0fce82e7 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-88mr-9r66-x2c9/GHSA-88mr-9r66-x2c9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-88mr-9r66-x2c9", + "modified": "2025-03-19T15:31:45Z", + "published": "2025-03-19T15:31:45Z", + "aliases": [ + "CVE-2024-42176" + ], + "details": "HCL MyXalytics is affected by concurrent login vulnerability. A concurrent login vulnerability occurs when simultaneous active sessions are allowed for a single credential allowing an attacker to potentially obtain access to a user's account or sensitive information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42176" + }, + { + "type": "WEB", + "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0119919" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-307" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-19T15:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-fqrq-xmxj-v47x/GHSA-fqrq-xmxj-v47x.json b/advisories/unreviewed/2025/03/GHSA-fqrq-xmxj-v47x/GHSA-fqrq-xmxj-v47x.json new file mode 100644 index 00000000000..9a7665d9663 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-fqrq-xmxj-v47x/GHSA-fqrq-xmxj-v47x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fqrq-xmxj-v47x", + "modified": "2025-03-19T15:31:45Z", + "published": "2025-03-19T15:31:45Z", + "aliases": [ + "CVE-2025-1472" + ], + "details": "Mattermost versions 9.11.x <= 9.11.8 fail to properly perform authorization of the Viewer role which allows an attacker with the Viewer role configured with No Access to Reporting to still view team and site statistics.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1472" + }, + { + "type": "WEB", + "url": "https://mattermost.com/security-updates" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-19T15:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-j7qq-8hrp-f3j8/GHSA-j7qq-8hrp-f3j8.json b/advisories/unreviewed/2025/03/GHSA-j7qq-8hrp-f3j8/GHSA-j7qq-8hrp-f3j8.json new file mode 100644 index 00000000000..4318d6bf934 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-j7qq-8hrp-f3j8/GHSA-j7qq-8hrp-f3j8.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j7qq-8hrp-f3j8", + "modified": "2025-03-19T15:31:45Z", + "published": "2025-03-19T15:31:45Z", + "aliases": [ + "CVE-2024-55551" + ], + "details": "An issue was discovered in Exasol jdbc driver 24.2.0. Attackers can inject malicious parameters into the JDBC URL, triggering JNDI injection during the process when the JDBC Driver uses this URL to connect to the database. This can further lead to remote code execution vulnerability.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55551" + }, + { + "type": "WEB", + "url": "https://docs.exasol.com/db/latest/connect_exasol/drivers/jdbc.htm" + }, + { + "type": "WEB", + "url": "https://gist.github.com/azraelxuemo/9565ec9219e0c3e9afd5474904c39d0f" + }, + { + "type": "WEB", + "url": "https://www.blackhat.com/eu-24/briefings/schedule/index.html#a-novel-attack-surface-java-authentication-and-authorization-service-jaas-42179" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-19T14:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-p487-32h6-758c/GHSA-p487-32h6-758c.json b/advisories/unreviewed/2025/03/GHSA-p487-32h6-758c/GHSA-p487-32h6-758c.json index f9468250190..95ab7ce5c2a 100644 --- a/advisories/unreviewed/2025/03/GHSA-p487-32h6-758c/GHSA-p487-32h6-758c.json +++ b/advisories/unreviewed/2025/03/GHSA-p487-32h6-758c/GHSA-p487-32h6-758c.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p487-32h6-758c", - "modified": "2025-03-13T15:32:58Z", + "modified": "2025-03-19T15:31:45Z", "published": "2025-03-13T15:32:58Z", "aliases": [ "CVE-2025-29357" ], "details": "Tenda RX3 US_RX3V1.0br_V16.03.13.11_multi_TDE01 is vulnerable to Buffer Overflow via the startIp and endIp parameters at /goform/SetPptpServerCfg. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted packet.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-404" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-13T14:15:36Z" diff --git a/advisories/unreviewed/2025/03/GHSA-v3c6-573j-vx99/GHSA-v3c6-573j-vx99.json b/advisories/unreviewed/2025/03/GHSA-v3c6-573j-vx99/GHSA-v3c6-573j-vx99.json index 48d08cc3733..62edc1f2646 100644 --- a/advisories/unreviewed/2025/03/GHSA-v3c6-573j-vx99/GHSA-v3c6-573j-vx99.json +++ b/advisories/unreviewed/2025/03/GHSA-v3c6-573j-vx99/GHSA-v3c6-573j-vx99.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-v3c6-573j-vx99", - "modified": "2025-03-13T18:32:23Z", + "modified": "2025-03-19T15:31:45Z", "published": "2025-03-13T18:32:23Z", "aliases": [ "CVE-2025-25598" ], "details": "Incorrect access control in the scheduled tasks console of Inova Logic CUSTOMER MONITOR (CM) v3.1.757.1 allows attackers to escalate privileges via placing a crafted executable into a scheduled task.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-13T18:15:50Z"