From 363dda016d9f55791176674a9a1c7cfd5065d2d1 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 8 Apr 2025 21:33:23 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-4hpx-4mpp-gqwv.json | 6 +- .../GHSA-5863-jg7w-jf64.json | 22 +++++++- .../GHSA-6q39-qvw3-75jq.json | 10 +++- .../GHSA-7wwm-8prx-hpg2.json | 2 +- .../GHSA-cfcv-rgx7-fw5j.json | 4 +- .../GHSA-cxfq-cc8j-j2pp.json | 3 +- .../GHSA-pxhp-jr2p-7hw7.json | 2 +- .../GHSA-wvcg-5hx9-98xw.json | 4 +- .../GHSA-g63x-ch35-x5p5.json | 4 +- .../GHSA-q6fw-pgc6-r84c.json | 4 +- .../GHSA-4jwm-p35r-q67q.json | 4 +- .../GHSA-8j2w-2cpm-xpmr.json | 4 +- .../GHSA-989p-25jr-248m.json | 4 +- .../GHSA-fpf4-cfch-367m.json | 4 +- .../GHSA-hwgv-8256-p54x.json | 4 +- .../GHSA-p29c-5vv5-vh3p.json | 4 +- .../GHSA-q43w-g673-m6f4.json | 4 +- .../GHSA-r32p-gh6m-33hq.json | 4 +- .../GHSA-8r78-c2f2-82qm.json | 4 +- .../GHSA-973h-x7w2-jgpx.json | 4 +- .../GHSA-cx5c-hrvr-85gj.json | 4 +- .../GHSA-fx68-rvxh-32hf.json | 4 +- .../GHSA-g77r-j94w-3wm3.json | 4 +- .../GHSA-gghh-gpx3-pmx6.json | 11 +++- .../GHSA-j4gv-c6jh-pvhm.json | 4 +- .../GHSA-j9g6-83mp-8mvr.json | 4 +- .../GHSA-p437-j6g9-3f2f.json | 6 +- .../GHSA-p565-x5fx-43j3.json | 4 +- .../GHSA-p672-9qr7-4cmf.json | 4 +- .../GHSA-rmx7-cw76-79w4.json | 4 +- .../GHSA-rr8j-q4x4-g24r.json | 4 +- .../GHSA-7w4w-ph42-vrfq.json | 4 +- .../GHSA-fpm3-qrmh-vx5x.json | 4 +- .../GHSA-h42g-49qq-h3x6.json | 15 +++-- .../GHSA-qccg-v3f9-84pm.json | 4 +- .../GHSA-2qhj-xvhg-5rmf.json | 36 ++++++++++++ .../GHSA-2r94-wm5v-4prx.json | 36 ++++++++++++ .../GHSA-2wf7-238m-g5qh.json | 3 +- .../GHSA-33qf-6xj8-p2pq.json | 3 +- .../GHSA-3cg4-jf33-6fwh.json | 36 ++++++++++++ .../GHSA-3gxj-2579-vrcc.json | 36 ++++++++++++ .../GHSA-3qpv-2q49-9qj8.json | 15 +++-- .../GHSA-527p-356f-cgq4.json | 4 +- .../GHSA-5x84-fgc9-6qq4.json | 5 +- .../GHSA-633m-895c-3f9g.json | 11 +++- .../GHSA-6423-85cc-8gf6.json | 11 +++- .../GHSA-64wf-mpw9-cw5v.json | 36 ++++++++++++ .../GHSA-658h-wc48-rw6r.json | 36 ++++++++++++ .../GHSA-65g2-h96w-cwp4.json | 36 ++++++++++++ .../GHSA-6j75-9vmv-439p.json | 3 +- .../GHSA-6wq7-cg9h-mj6q.json | 36 ++++++++++++ .../GHSA-73gg-qjfg-4g7x.json | 36 ++++++++++++ .../GHSA-796g-c5p5-hfrr.json | 15 +++-- .../GHSA-7c4q-68g6-pmr5.json | 36 ++++++++++++ .../GHSA-7frx-2jch-mmcm.json | 15 +++-- .../GHSA-7r4x-ff5h-ghvg.json | 5 +- .../GHSA-86h2-47xr-3w77.json | 36 ++++++++++++ .../GHSA-8843-g665-5rpj.json | 15 +++-- .../GHSA-8w94-ggwf-26rw.json | 15 +++-- .../GHSA-8xhv-fwf3-q27f.json | 3 +- .../GHSA-96jf-mvrm-934f.json | 36 ++++++++++++ .../GHSA-98gx-7m8x-x64f.json | 36 ++++++++++++ .../GHSA-9f8p-m62j-44x8.json | 36 ++++++++++++ .../GHSA-cp9f-7jr4-m2mj.json | 36 ++++++++++++ .../GHSA-cqwm-8779-r274.json | 36 ++++++++++++ .../GHSA-f29x-f897-g8f9.json | 36 ++++++++++++ .../GHSA-f2ff-9j2m-p32f.json | 3 +- .../GHSA-fhq8-pvx2-r42x.json | 36 ++++++++++++ .../GHSA-fpf8-39f6-cgrc.json | 36 ++++++++++++ .../GHSA-fv2f-q5hc-738w.json | 2 +- .../GHSA-g2qq-97wv-38qx.json | 15 +++-- .../GHSA-g9pc-8g42-g6vq.json | 45 +++++++++++++++ .../GHSA-gx9w-r4j8-6p7h.json | 36 ++++++++++++ .../GHSA-h78g-f5x3-jrm2.json | 4 +- .../GHSA-hpc9-p79m-q8wm.json | 36 ++++++++++++ .../GHSA-j46p-wfvm-g6pg.json | 15 +++-- .../GHSA-j72q-qc2x-rq8g.json | 36 ++++++++++++ .../GHSA-jhqq-vcx8-rp7q.json | 36 ++++++++++++ .../GHSA-mgh2-hf68-73c8.json | 56 +++++++++++++++++++ .../GHSA-mrv4-mqvc-q66g.json | 15 +++-- .../GHSA-mw45-m2cr-q9jj.json | 36 ++++++++++++ .../GHSA-pc39-7549-89wv.json | 36 ++++++++++++ .../GHSA-ppxr-f836-phpf.json | 15 +++-- .../GHSA-q969-vh79-2qg8.json | 36 ++++++++++++ .../GHSA-qj34-w7fp-qg2w.json | 36 ++++++++++++ .../GHSA-r3m2-p27f-8635.json | 36 ++++++++++++ .../GHSA-r4wm-j267-rq33.json | 36 ++++++++++++ .../GHSA-rqjr-gvph-vqwr.json | 15 +++-- .../GHSA-rr2g-rrjj-xw86.json | 36 ++++++++++++ .../GHSA-rv7x-66xx-8rvv.json | 36 ++++++++++++ .../GHSA-rvvc-m8pv-rj9r.json | 15 +++-- .../GHSA-v236-qrg8-r7vx.json | 36 ++++++++++++ .../GHSA-vc28-9jgm-3qpx.json | 1 + .../GHSA-vcfm-2r3w-vjx5.json | 36 ++++++++++++ .../GHSA-vhcq-4xrm-2cr2.json | 36 ++++++++++++ .../GHSA-wgxm-3jgj-5pwf.json | 36 ++++++++++++ .../GHSA-ww98-mrx2-m82h.json | 36 ++++++++++++ 97 files changed, 1698 insertions(+), 103 deletions(-) create mode 100644 advisories/unreviewed/2025/04/GHSA-2qhj-xvhg-5rmf/GHSA-2qhj-xvhg-5rmf.json create mode 100644 advisories/unreviewed/2025/04/GHSA-2r94-wm5v-4prx/GHSA-2r94-wm5v-4prx.json create mode 100644 advisories/unreviewed/2025/04/GHSA-3cg4-jf33-6fwh/GHSA-3cg4-jf33-6fwh.json create mode 100644 advisories/unreviewed/2025/04/GHSA-3gxj-2579-vrcc/GHSA-3gxj-2579-vrcc.json create mode 100644 advisories/unreviewed/2025/04/GHSA-64wf-mpw9-cw5v/GHSA-64wf-mpw9-cw5v.json create mode 100644 advisories/unreviewed/2025/04/GHSA-658h-wc48-rw6r/GHSA-658h-wc48-rw6r.json create mode 100644 advisories/unreviewed/2025/04/GHSA-65g2-h96w-cwp4/GHSA-65g2-h96w-cwp4.json create mode 100644 advisories/unreviewed/2025/04/GHSA-6wq7-cg9h-mj6q/GHSA-6wq7-cg9h-mj6q.json create mode 100644 advisories/unreviewed/2025/04/GHSA-73gg-qjfg-4g7x/GHSA-73gg-qjfg-4g7x.json create mode 100644 advisories/unreviewed/2025/04/GHSA-7c4q-68g6-pmr5/GHSA-7c4q-68g6-pmr5.json create mode 100644 advisories/unreviewed/2025/04/GHSA-86h2-47xr-3w77/GHSA-86h2-47xr-3w77.json create mode 100644 advisories/unreviewed/2025/04/GHSA-96jf-mvrm-934f/GHSA-96jf-mvrm-934f.json create mode 100644 advisories/unreviewed/2025/04/GHSA-98gx-7m8x-x64f/GHSA-98gx-7m8x-x64f.json create mode 100644 advisories/unreviewed/2025/04/GHSA-9f8p-m62j-44x8/GHSA-9f8p-m62j-44x8.json create mode 100644 advisories/unreviewed/2025/04/GHSA-cp9f-7jr4-m2mj/GHSA-cp9f-7jr4-m2mj.json create mode 100644 advisories/unreviewed/2025/04/GHSA-cqwm-8779-r274/GHSA-cqwm-8779-r274.json create mode 100644 advisories/unreviewed/2025/04/GHSA-f29x-f897-g8f9/GHSA-f29x-f897-g8f9.json create mode 100644 advisories/unreviewed/2025/04/GHSA-fhq8-pvx2-r42x/GHSA-fhq8-pvx2-r42x.json create mode 100644 advisories/unreviewed/2025/04/GHSA-fpf8-39f6-cgrc/GHSA-fpf8-39f6-cgrc.json create mode 100644 advisories/unreviewed/2025/04/GHSA-g9pc-8g42-g6vq/GHSA-g9pc-8g42-g6vq.json create mode 100644 advisories/unreviewed/2025/04/GHSA-gx9w-r4j8-6p7h/GHSA-gx9w-r4j8-6p7h.json create mode 100644 advisories/unreviewed/2025/04/GHSA-hpc9-p79m-q8wm/GHSA-hpc9-p79m-q8wm.json create mode 100644 advisories/unreviewed/2025/04/GHSA-j72q-qc2x-rq8g/GHSA-j72q-qc2x-rq8g.json create mode 100644 advisories/unreviewed/2025/04/GHSA-jhqq-vcx8-rp7q/GHSA-jhqq-vcx8-rp7q.json create mode 100644 advisories/unreviewed/2025/04/GHSA-mgh2-hf68-73c8/GHSA-mgh2-hf68-73c8.json create mode 100644 advisories/unreviewed/2025/04/GHSA-mw45-m2cr-q9jj/GHSA-mw45-m2cr-q9jj.json create mode 100644 advisories/unreviewed/2025/04/GHSA-pc39-7549-89wv/GHSA-pc39-7549-89wv.json create mode 100644 advisories/unreviewed/2025/04/GHSA-q969-vh79-2qg8/GHSA-q969-vh79-2qg8.json create mode 100644 advisories/unreviewed/2025/04/GHSA-qj34-w7fp-qg2w/GHSA-qj34-w7fp-qg2w.json create mode 100644 advisories/unreviewed/2025/04/GHSA-r3m2-p27f-8635/GHSA-r3m2-p27f-8635.json create mode 100644 advisories/unreviewed/2025/04/GHSA-r4wm-j267-rq33/GHSA-r4wm-j267-rq33.json create mode 100644 advisories/unreviewed/2025/04/GHSA-rr2g-rrjj-xw86/GHSA-rr2g-rrjj-xw86.json create mode 100644 advisories/unreviewed/2025/04/GHSA-rv7x-66xx-8rvv/GHSA-rv7x-66xx-8rvv.json create mode 100644 advisories/unreviewed/2025/04/GHSA-v236-qrg8-r7vx/GHSA-v236-qrg8-r7vx.json create mode 100644 advisories/unreviewed/2025/04/GHSA-vcfm-2r3w-vjx5/GHSA-vcfm-2r3w-vjx5.json create mode 100644 advisories/unreviewed/2025/04/GHSA-vhcq-4xrm-2cr2/GHSA-vhcq-4xrm-2cr2.json create mode 100644 advisories/unreviewed/2025/04/GHSA-wgxm-3jgj-5pwf/GHSA-wgxm-3jgj-5pwf.json create mode 100644 advisories/unreviewed/2025/04/GHSA-ww98-mrx2-m82h/GHSA-ww98-mrx2-m82h.json diff --git a/advisories/unreviewed/2023/01/GHSA-4hpx-4mpp-gqwv/GHSA-4hpx-4mpp-gqwv.json b/advisories/unreviewed/2023/01/GHSA-4hpx-4mpp-gqwv/GHSA-4hpx-4mpp-gqwv.json index 5d0525eb8c0..b05d08bd837 100644 --- a/advisories/unreviewed/2023/01/GHSA-4hpx-4mpp-gqwv/GHSA-4hpx-4mpp-gqwv.json +++ b/advisories/unreviewed/2023/01/GHSA-4hpx-4mpp-gqwv/GHSA-4hpx-4mpp-gqwv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4hpx-4mpp-gqwv", - "modified": "2023-01-14T06:30:28Z", + "modified": "2025-04-08T21:31:27Z", "published": "2023-01-11T00:30:48Z", "aliases": [ "CVE-2022-4379" @@ -50,6 +50,10 @@ { "type": "WEB", "url": "https://seclists.org/oss-sec/2022/q4/185" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20230223-0004" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/01/GHSA-5863-jg7w-jf64/GHSA-5863-jg7w-jf64.json b/advisories/unreviewed/2023/01/GHSA-5863-jg7w-jf64/GHSA-5863-jg7w-jf64.json index abf38d2bbfb..f7e769b2013 100644 --- a/advisories/unreviewed/2023/01/GHSA-5863-jg7w-jf64/GHSA-5863-jg7w-jf64.json +++ b/advisories/unreviewed/2023/01/GHSA-5863-jg7w-jf64/GHSA-5863-jg7w-jf64.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5863-jg7w-jf64", - "modified": "2023-01-25T03:30:30Z", + "modified": "2025-04-08T21:31:29Z", "published": "2023-01-17T21:30:22Z", "aliases": [ "CVE-2022-23739" @@ -19,6 +19,26 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-23739" }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server%403.3/admin/release-notes#3.3.16" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server%403.4/admin/release-notes#3.4.11" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server%403.5/admin/release-notes#3.5.8" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server%403.6/admin/release-notes#3.6.4" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server%403.7/admin/release-notes#3.7.1" + }, { "type": "WEB", "url": "https://docs.github.com/en/enterprise-server@3.3/admin/release-notes#3.3.16" diff --git a/advisories/unreviewed/2023/01/GHSA-6q39-qvw3-75jq/GHSA-6q39-qvw3-75jq.json b/advisories/unreviewed/2023/01/GHSA-6q39-qvw3-75jq/GHSA-6q39-qvw3-75jq.json index 0ce02842f4c..5169758c57b 100644 --- a/advisories/unreviewed/2023/01/GHSA-6q39-qvw3-75jq/GHSA-6q39-qvw3-75jq.json +++ b/advisories/unreviewed/2023/01/GHSA-6q39-qvw3-75jq/GHSA-6q39-qvw3-75jq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6q39-qvw3-75jq", - "modified": "2023-01-20T00:30:28Z", + "modified": "2025-04-08T21:31:28Z", "published": "2023-01-12T00:30:16Z", "aliases": [ "CVE-2022-4344" @@ -23,6 +23,14 @@ "type": "WEB", "url": "https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-4344.json" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RDZMWIKH3L5JQZC6GSVOJ3N5UXNQPJGQ" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SGWIW6K64PKC375YAONYXKIVT2FDEDV3" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RDZMWIKH3L5JQZC6GSVOJ3N5UXNQPJGQ" diff --git a/advisories/unreviewed/2023/01/GHSA-7wwm-8prx-hpg2/GHSA-7wwm-8prx-hpg2.json b/advisories/unreviewed/2023/01/GHSA-7wwm-8prx-hpg2/GHSA-7wwm-8prx-hpg2.json index 461eff85a75..41e5553715c 100644 --- a/advisories/unreviewed/2023/01/GHSA-7wwm-8prx-hpg2/GHSA-7wwm-8prx-hpg2.json +++ b/advisories/unreviewed/2023/01/GHSA-7wwm-8prx-hpg2/GHSA-7wwm-8prx-hpg2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7wwm-8prx-hpg2", - "modified": "2023-01-27T18:30:31Z", + "modified": "2025-04-08T21:31:29Z", "published": "2023-01-17T21:30:21Z", "aliases": [ "CVE-2021-36647" diff --git a/advisories/unreviewed/2023/01/GHSA-cfcv-rgx7-fw5j/GHSA-cfcv-rgx7-fw5j.json b/advisories/unreviewed/2023/01/GHSA-cfcv-rgx7-fw5j/GHSA-cfcv-rgx7-fw5j.json index 3b4778b0724..066f0729fca 100644 --- a/advisories/unreviewed/2023/01/GHSA-cfcv-rgx7-fw5j/GHSA-cfcv-rgx7-fw5j.json +++ b/advisories/unreviewed/2023/01/GHSA-cfcv-rgx7-fw5j/GHSA-cfcv-rgx7-fw5j.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-345" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/01/GHSA-cxfq-cc8j-j2pp/GHSA-cxfq-cc8j-j2pp.json b/advisories/unreviewed/2023/01/GHSA-cxfq-cc8j-j2pp/GHSA-cxfq-cc8j-j2pp.json index 4efa39c012c..a562eacf76c 100644 --- a/advisories/unreviewed/2023/01/GHSA-cxfq-cc8j-j2pp/GHSA-cxfq-cc8j-j2pp.json +++ b/advisories/unreviewed/2023/01/GHSA-cxfq-cc8j-j2pp/GHSA-cxfq-cc8j-j2pp.json @@ -34,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/01/GHSA-pxhp-jr2p-7hw7/GHSA-pxhp-jr2p-7hw7.json b/advisories/unreviewed/2023/01/GHSA-pxhp-jr2p-7hw7/GHSA-pxhp-jr2p-7hw7.json index 405ad50abd4..609070f2cad 100644 --- a/advisories/unreviewed/2023/01/GHSA-pxhp-jr2p-7hw7/GHSA-pxhp-jr2p-7hw7.json +++ b/advisories/unreviewed/2023/01/GHSA-pxhp-jr2p-7hw7/GHSA-pxhp-jr2p-7hw7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pxhp-jr2p-7hw7", - "modified": "2023-01-24T18:30:32Z", + "modified": "2025-04-08T21:31:28Z", "published": "2023-01-15T09:30:15Z", "aliases": [ "CVE-2023-23595" diff --git a/advisories/unreviewed/2023/01/GHSA-wvcg-5hx9-98xw/GHSA-wvcg-5hx9-98xw.json b/advisories/unreviewed/2023/01/GHSA-wvcg-5hx9-98xw/GHSA-wvcg-5hx9-98xw.json index a912fa3ba12..03cb51ac257 100644 --- a/advisories/unreviewed/2023/01/GHSA-wvcg-5hx9-98xw/GHSA-wvcg-5hx9-98xw.json +++ b/advisories/unreviewed/2023/01/GHSA-wvcg-5hx9-98xw/GHSA-wvcg-5hx9-98xw.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-330" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-g63x-ch35-x5p5/GHSA-g63x-ch35-x5p5.json b/advisories/unreviewed/2024/03/GHSA-g63x-ch35-x5p5/GHSA-g63x-ch35-x5p5.json index ef2fe9a01a0..3fdbccdf35c 100644 --- a/advisories/unreviewed/2024/03/GHSA-g63x-ch35-x5p5/GHSA-g63x-ch35-x5p5.json +++ b/advisories/unreviewed/2024/03/GHSA-g63x-ch35-x5p5/GHSA-g63x-ch35-x5p5.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-476" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-q6fw-pgc6-r84c/GHSA-q6fw-pgc6-r84c.json b/advisories/unreviewed/2024/03/GHSA-q6fw-pgc6-r84c/GHSA-q6fw-pgc6-r84c.json index 87383e9bec3..dd5c52299ee 100644 --- a/advisories/unreviewed/2024/03/GHSA-q6fw-pgc6-r84c/GHSA-q6fw-pgc6-r84c.json +++ b/advisories/unreviewed/2024/03/GHSA-q6fw-pgc6-r84c/GHSA-q6fw-pgc6-r84c.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-415" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-4jwm-p35r-q67q/GHSA-4jwm-p35r-q67q.json b/advisories/unreviewed/2024/04/GHSA-4jwm-p35r-q67q/GHSA-4jwm-p35r-q67q.json index 8a1491c76aa..1d9578a8b83 100644 --- a/advisories/unreviewed/2024/04/GHSA-4jwm-p35r-q67q/GHSA-4jwm-p35r-q67q.json +++ b/advisories/unreviewed/2024/04/GHSA-4jwm-p35r-q67q/GHSA-4jwm-p35r-q67q.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-8j2w-2cpm-xpmr/GHSA-8j2w-2cpm-xpmr.json b/advisories/unreviewed/2024/04/GHSA-8j2w-2cpm-xpmr/GHSA-8j2w-2cpm-xpmr.json index 2451544b70b..deb4ed7db52 100644 --- a/advisories/unreviewed/2024/04/GHSA-8j2w-2cpm-xpmr/GHSA-8j2w-2cpm-xpmr.json +++ b/advisories/unreviewed/2024/04/GHSA-8j2w-2cpm-xpmr/GHSA-8j2w-2cpm-xpmr.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-989p-25jr-248m/GHSA-989p-25jr-248m.json b/advisories/unreviewed/2024/04/GHSA-989p-25jr-248m/GHSA-989p-25jr-248m.json index d179e9b055f..644314971f3 100644 --- a/advisories/unreviewed/2024/04/GHSA-989p-25jr-248m/GHSA-989p-25jr-248m.json +++ b/advisories/unreviewed/2024/04/GHSA-989p-25jr-248m/GHSA-989p-25jr-248m.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-476" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-fpf4-cfch-367m/GHSA-fpf4-cfch-367m.json b/advisories/unreviewed/2024/04/GHSA-fpf4-cfch-367m/GHSA-fpf4-cfch-367m.json index 6f8f73f492a..7b4f81f30c7 100644 --- a/advisories/unreviewed/2024/04/GHSA-fpf4-cfch-367m/GHSA-fpf4-cfch-367m.json +++ b/advisories/unreviewed/2024/04/GHSA-fpf4-cfch-367m/GHSA-fpf4-cfch-367m.json @@ -57,7 +57,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-362" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-hwgv-8256-p54x/GHSA-hwgv-8256-p54x.json b/advisories/unreviewed/2024/04/GHSA-hwgv-8256-p54x/GHSA-hwgv-8256-p54x.json index 4524dd96f9d..8655f000334 100644 --- a/advisories/unreviewed/2024/04/GHSA-hwgv-8256-p54x/GHSA-hwgv-8256-p54x.json +++ b/advisories/unreviewed/2024/04/GHSA-hwgv-8256-p54x/GHSA-hwgv-8256-p54x.json @@ -41,7 +41,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-120" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-p29c-5vv5-vh3p/GHSA-p29c-5vv5-vh3p.json b/advisories/unreviewed/2024/04/GHSA-p29c-5vv5-vh3p/GHSA-p29c-5vv5-vh3p.json index a48e0270110..047e1cf392b 100644 --- a/advisories/unreviewed/2024/04/GHSA-p29c-5vv5-vh3p/GHSA-p29c-5vv5-vh3p.json +++ b/advisories/unreviewed/2024/04/GHSA-p29c-5vv5-vh3p/GHSA-p29c-5vv5-vh3p.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-q43w-g673-m6f4/GHSA-q43w-g673-m6f4.json b/advisories/unreviewed/2024/04/GHSA-q43w-g673-m6f4/GHSA-q43w-g673-m6f4.json index f2de757e522..7873edffbe9 100644 --- a/advisories/unreviewed/2024/04/GHSA-q43w-g673-m6f4/GHSA-q43w-g673-m6f4.json +++ b/advisories/unreviewed/2024/04/GHSA-q43w-g673-m6f4/GHSA-q43w-g673-m6f4.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-191" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-r32p-gh6m-33hq/GHSA-r32p-gh6m-33hq.json b/advisories/unreviewed/2024/04/GHSA-r32p-gh6m-33hq/GHSA-r32p-gh6m-33hq.json index 9b89a26d9df..45cf15d554b 100644 --- a/advisories/unreviewed/2024/04/GHSA-r32p-gh6m-33hq/GHSA-r32p-gh6m-33hq.json +++ b/advisories/unreviewed/2024/04/GHSA-r32p-gh6m-33hq/GHSA-r32p-gh6m-33hq.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-476" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-8r78-c2f2-82qm/GHSA-8r78-c2f2-82qm.json b/advisories/unreviewed/2024/05/GHSA-8r78-c2f2-82qm/GHSA-8r78-c2f2-82qm.json index 2ea797eef56..5f4f7a62d96 100644 --- a/advisories/unreviewed/2024/05/GHSA-8r78-c2f2-82qm/GHSA-8r78-c2f2-82qm.json +++ b/advisories/unreviewed/2024/05/GHSA-8r78-c2f2-82qm/GHSA-8r78-c2f2-82qm.json @@ -49,7 +49,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-401" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-973h-x7w2-jgpx/GHSA-973h-x7w2-jgpx.json b/advisories/unreviewed/2024/05/GHSA-973h-x7w2-jgpx/GHSA-973h-x7w2-jgpx.json index 7fbd517a0ee..13fffc870ae 100644 --- a/advisories/unreviewed/2024/05/GHSA-973h-x7w2-jgpx/GHSA-973h-x7w2-jgpx.json +++ b/advisories/unreviewed/2024/05/GHSA-973h-x7w2-jgpx/GHSA-973h-x7w2-jgpx.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-476" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-cx5c-hrvr-85gj/GHSA-cx5c-hrvr-85gj.json b/advisories/unreviewed/2024/05/GHSA-cx5c-hrvr-85gj/GHSA-cx5c-hrvr-85gj.json index 14cb0e59035..936102f624b 100644 --- a/advisories/unreviewed/2024/05/GHSA-cx5c-hrvr-85gj/GHSA-cx5c-hrvr-85gj.json +++ b/advisories/unreviewed/2024/05/GHSA-cx5c-hrvr-85gj/GHSA-cx5c-hrvr-85gj.json @@ -45,7 +45,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-667" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-fx68-rvxh-32hf/GHSA-fx68-rvxh-32hf.json b/advisories/unreviewed/2024/05/GHSA-fx68-rvxh-32hf/GHSA-fx68-rvxh-32hf.json index 5ce31ae36b1..7781eb506b9 100644 --- a/advisories/unreviewed/2024/05/GHSA-fx68-rvxh-32hf/GHSA-fx68-rvxh-32hf.json +++ b/advisories/unreviewed/2024/05/GHSA-fx68-rvxh-32hf/GHSA-fx68-rvxh-32hf.json @@ -41,7 +41,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-835" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-g77r-j94w-3wm3/GHSA-g77r-j94w-3wm3.json b/advisories/unreviewed/2024/05/GHSA-g77r-j94w-3wm3/GHSA-g77r-j94w-3wm3.json index e6a967ebafb..6a204589583 100644 --- a/advisories/unreviewed/2024/05/GHSA-g77r-j94w-3wm3/GHSA-g77r-j94w-3wm3.json +++ b/advisories/unreviewed/2024/05/GHSA-g77r-j94w-3wm3/GHSA-g77r-j94w-3wm3.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-401" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-gghh-gpx3-pmx6/GHSA-gghh-gpx3-pmx6.json b/advisories/unreviewed/2024/05/GHSA-gghh-gpx3-pmx6/GHSA-gghh-gpx3-pmx6.json index ca5566f5b7c..36501f9fe3d 100644 --- a/advisories/unreviewed/2024/05/GHSA-gghh-gpx3-pmx6/GHSA-gghh-gpx3-pmx6.json +++ b/advisories/unreviewed/2024/05/GHSA-gghh-gpx3-pmx6/GHSA-gghh-gpx3-pmx6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gghh-gpx3-pmx6", - "modified": "2024-05-01T06:31:41Z", + "modified": "2025-04-08T21:31:29Z", "published": "2024-05-01T06:31:41Z", "aliases": [ "CVE-2024-26939" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/i915/vma: Fix UAF on destroy against retire race\n\nObject debugging tools were sporadically reporting illegal attempts to\nfree a still active i915 VMA object when parking a GT believed to be idle.\n\n[161.359441] ODEBUG: free active (active state 0) object: ffff88811643b958 object type: i915_active hint: __i915_vma_active+0x0/0x50 [i915]\n[161.360082] WARNING: CPU: 5 PID: 276 at lib/debugobjects.c:514 debug_print_object+0x80/0xb0\n...\n[161.360304] CPU: 5 PID: 276 Comm: kworker/5:2 Not tainted 6.5.0-rc1-CI_DRM_13375-g003f860e5577+ #1\n[161.360314] Hardware name: Intel Corporation Rocket Lake Client Platform/RocketLake S UDIMM 6L RVP, BIOS RKLSFWI1.R00.3173.A03.2204210138 04/21/2022\n[161.360322] Workqueue: i915-unordered __intel_wakeref_put_work [i915]\n[161.360592] RIP: 0010:debug_print_object+0x80/0xb0\n...\n[161.361347] debug_object_free+0xeb/0x110\n[161.361362] i915_active_fini+0x14/0x130 [i915]\n[161.361866] release_references+0xfe/0x1f0 [i915]\n[161.362543] i915_vma_parked+0x1db/0x380 [i915]\n[161.363129] __gt_park+0x121/0x230 [i915]\n[161.363515] ____intel_wakeref_put_last+0x1f/0x70 [i915]\n\nThat has been tracked down to be happening when another thread is\ndeactivating the VMA inside __active_retire() helper, after the VMA's\nactive counter has been already decremented to 0, but before deactivation\nof the VMA's object is reported to the object debugging tool.\n\nWe could prevent from that race by serializing i915_active_fini() with\n__active_retire() via ref->tree_lock, but that wouldn't stop the VMA from\nbeing used, e.g. from __i915_vma_retire() called at the end of\n__active_retire(), after that VMA has been already freed by a concurrent\ni915_vma_destroy() on return from the i915_active_fini(). Then, we should\nrather fix the issue at the VMA level, not in i915_active.\n\nSince __i915_vma_parked() is called from __gt_park() on last put of the\nGT's wakeref, the issue could be addressed by holding the GT wakeref long\nenough for __active_retire() to complete before that wakeref is released\nand the GT parked.\n\nI believe the issue was introduced by commit d93939730347 (\"drm/i915:\nRemove the vma refcount\") which moved a call to i915_active_fini() from\na dropped i915_vma_release(), called on last put of the removed VMA kref,\nto i915_vma_parked() processing path called on last put of a GT wakeref.\nHowever, its visibility to the object debugging tool was suppressed by a\nbug in i915_active that was fixed two weeks later with commit e92eb246feb9\n(\"drm/i915/active: Fix missing debug object activation\").\n\nA VMA associated with a request doesn't acquire a GT wakeref by itself.\nInstead, it depends on a wakeref held directly by the request's active\nintel_context for a GT associated with its VM, and indirectly on that\nintel_context's engine wakeref if the engine belongs to the same GT as the\nVMA's VM. Those wakerefs are released asynchronously to VMA deactivation.\n\nFix the issue by getting a wakeref for the VMA's GT when activating it,\nand putting that wakeref only after the VMA is deactivated. However,\nexclude global GTT from that processing path, otherwise the GPU never goes\nidle. Since __i915_vma_retire() may be called from atomic contexts, use\nasync variant of wakeref put. Also, to avoid circular locking dependency,\ntake care of acquiring the wakeref before VM mutex when both are needed.\n\nv7: Add inline comments with justifications for:\n - using untracked variants of intel_gt_pm_get/put() (Nirmoy),\n - using async variant of _put(),\n - not getting the wakeref in case of a global GTT,\n - always getting the first wakeref outside vm->mutex.\nv6: Since __i915_vma_active/retire() callbacks are not serialized, storing\n a wakeref tracking handle inside struct i915_vma is not safe, and\n there is no other good place for that. Use untracked variants of\n intel_gt_pm_get/put_async().\nv5: Replace \"tile\" with \"GT\" across commit description (Rodrigo),\n - \n---truncated---", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -35,7 +40,7 @@ "cwe_ids": [ "CWE-416" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-01T06:15:09Z" diff --git a/advisories/unreviewed/2024/05/GHSA-j4gv-c6jh-pvhm/GHSA-j4gv-c6jh-pvhm.json b/advisories/unreviewed/2024/05/GHSA-j4gv-c6jh-pvhm/GHSA-j4gv-c6jh-pvhm.json index 4cba2ad4a74..4c8207e7c8a 100644 --- a/advisories/unreviewed/2024/05/GHSA-j4gv-c6jh-pvhm/GHSA-j4gv-c6jh-pvhm.json +++ b/advisories/unreviewed/2024/05/GHSA-j4gv-c6jh-pvhm/GHSA-j4gv-c6jh-pvhm.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-362" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-j9g6-83mp-8mvr/GHSA-j9g6-83mp-8mvr.json b/advisories/unreviewed/2024/05/GHSA-j9g6-83mp-8mvr/GHSA-j9g6-83mp-8mvr.json index 4b19b2635ae..4afed5c0786 100644 --- a/advisories/unreviewed/2024/05/GHSA-j9g6-83mp-8mvr/GHSA-j9g6-83mp-8mvr.json +++ b/advisories/unreviewed/2024/05/GHSA-j9g6-83mp-8mvr/GHSA-j9g6-83mp-8mvr.json @@ -57,7 +57,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-401" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-p437-j6g9-3f2f/GHSA-p437-j6g9-3f2f.json b/advisories/unreviewed/2024/05/GHSA-p437-j6g9-3f2f/GHSA-p437-j6g9-3f2f.json index 456e2f732c3..b9ed8b04257 100644 --- a/advisories/unreviewed/2024/05/GHSA-p437-j6g9-3f2f/GHSA-p437-j6g9-3f2f.json +++ b/advisories/unreviewed/2024/05/GHSA-p437-j6g9-3f2f/GHSA-p437-j6g9-3f2f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p437-j6g9-3f2f", - "modified": "2024-11-07T21:31:37Z", + "modified": "2025-04-08T21:31:30Z", "published": "2024-05-01T06:31:43Z", "aliases": [ "CVE-2024-26991" @@ -41,7 +41,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-125" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-p565-x5fx-43j3/GHSA-p565-x5fx-43j3.json b/advisories/unreviewed/2024/05/GHSA-p565-x5fx-43j3/GHSA-p565-x5fx-43j3.json index 956430eda52..ff5517c7450 100644 --- a/advisories/unreviewed/2024/05/GHSA-p565-x5fx-43j3/GHSA-p565-x5fx-43j3.json +++ b/advisories/unreviewed/2024/05/GHSA-p565-x5fx-43j3/GHSA-p565-x5fx-43j3.json @@ -41,7 +41,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-401" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-p672-9qr7-4cmf/GHSA-p672-9qr7-4cmf.json b/advisories/unreviewed/2024/05/GHSA-p672-9qr7-4cmf/GHSA-p672-9qr7-4cmf.json index 86b1fba2746..c8f2b2f6f99 100644 --- a/advisories/unreviewed/2024/05/GHSA-p672-9qr7-4cmf/GHSA-p672-9qr7-4cmf.json +++ b/advisories/unreviewed/2024/05/GHSA-p672-9qr7-4cmf/GHSA-p672-9qr7-4cmf.json @@ -45,7 +45,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-362" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-rmx7-cw76-79w4/GHSA-rmx7-cw76-79w4.json b/advisories/unreviewed/2024/05/GHSA-rmx7-cw76-79w4/GHSA-rmx7-cw76-79w4.json index 7fc4267c237..394950b6b6b 100644 --- a/advisories/unreviewed/2024/05/GHSA-rmx7-cw76-79w4/GHSA-rmx7-cw76-79w4.json +++ b/advisories/unreviewed/2024/05/GHSA-rmx7-cw76-79w4/GHSA-rmx7-cw76-79w4.json @@ -53,7 +53,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-125" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-rr8j-q4x4-g24r/GHSA-rr8j-q4x4-g24r.json b/advisories/unreviewed/2024/05/GHSA-rr8j-q4x4-g24r/GHSA-rr8j-q4x4-g24r.json index 4579ec7984b..03a970f65eb 100644 --- a/advisories/unreviewed/2024/05/GHSA-rr8j-q4x4-g24r/GHSA-rr8j-q4x4-g24r.json +++ b/advisories/unreviewed/2024/05/GHSA-rr8j-q4x4-g24r/GHSA-rr8j-q4x4-g24r.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-362" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-7w4w-ph42-vrfq/GHSA-7w4w-ph42-vrfq.json b/advisories/unreviewed/2025/03/GHSA-7w4w-ph42-vrfq/GHSA-7w4w-ph42-vrfq.json index 07af3a5d8aa..5b6723436b1 100644 --- a/advisories/unreviewed/2025/03/GHSA-7w4w-ph42-vrfq/GHSA-7w4w-ph42-vrfq.json +++ b/advisories/unreviewed/2025/03/GHSA-7w4w-ph42-vrfq/GHSA-7w4w-ph42-vrfq.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-fpm3-qrmh-vx5x/GHSA-fpm3-qrmh-vx5x.json b/advisories/unreviewed/2025/03/GHSA-fpm3-qrmh-vx5x/GHSA-fpm3-qrmh-vx5x.json index 96f69e806c8..c4c5369c557 100644 --- a/advisories/unreviewed/2025/03/GHSA-fpm3-qrmh-vx5x/GHSA-fpm3-qrmh-vx5x.json +++ b/advisories/unreviewed/2025/03/GHSA-fpm3-qrmh-vx5x/GHSA-fpm3-qrmh-vx5x.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-h42g-49qq-h3x6/GHSA-h42g-49qq-h3x6.json b/advisories/unreviewed/2025/03/GHSA-h42g-49qq-h3x6/GHSA-h42g-49qq-h3x6.json index 87e4ef002dd..910db5c489e 100644 --- a/advisories/unreviewed/2025/03/GHSA-h42g-49qq-h3x6/GHSA-h42g-49qq-h3x6.json +++ b/advisories/unreviewed/2025/03/GHSA-h42g-49qq-h3x6/GHSA-h42g-49qq-h3x6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h42g-49qq-h3x6", - "modified": "2025-03-26T21:31:07Z", + "modified": "2025-04-08T21:31:34Z", "published": "2025-03-26T21:31:07Z", "aliases": [ "CVE-2025-29322" ], "details": "A cross-site scripting (XSS) vulnerability in ScriptCase before v1.0.003 - Build 3 allows attackers to execute arbitrary code via a crafted payload to the \"Connection Name\" in the New Connection and Rename Connection pages.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-26T19:15:27Z" diff --git a/advisories/unreviewed/2025/03/GHSA-qccg-v3f9-84pm/GHSA-qccg-v3f9-84pm.json b/advisories/unreviewed/2025/03/GHSA-qccg-v3f9-84pm/GHSA-qccg-v3f9-84pm.json index 52217730be1..4c2be3ca1c4 100644 --- a/advisories/unreviewed/2025/03/GHSA-qccg-v3f9-84pm/GHSA-qccg-v3f9-84pm.json +++ b/advisories/unreviewed/2025/03/GHSA-qccg-v3f9-84pm/GHSA-qccg-v3f9-84pm.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-2qhj-xvhg-5rmf/GHSA-2qhj-xvhg-5rmf.json b/advisories/unreviewed/2025/04/GHSA-2qhj-xvhg-5rmf/GHSA-2qhj-xvhg-5rmf.json new file mode 100644 index 00000000000..c7611291c23 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2qhj-xvhg-5rmf/GHSA-2qhj-xvhg-5rmf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2qhj-xvhg-5rmf", + "modified": "2025-04-08T21:31:39Z", + "published": "2025-04-08T21:31:39Z", + "aliases": [ + "CVE-2025-30296" + ], + "details": "Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30296" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/framemaker/apsb25-33.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-191" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T19:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2r94-wm5v-4prx/GHSA-2r94-wm5v-4prx.json b/advisories/unreviewed/2025/04/GHSA-2r94-wm5v-4prx/GHSA-2r94-wm5v-4prx.json new file mode 100644 index 00000000000..376efb47321 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2r94-wm5v-4prx/GHSA-2r94-wm5v-4prx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2r94-wm5v-4prx", + "modified": "2025-04-08T21:31:41Z", + "published": "2025-04-08T21:31:41Z", + "aliases": [ + "CVE-2025-27192" + ], + "details": "Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Insufficiently Protected Credentials vulnerability that could lead to a security feature bypass. A high privileged attacker could exploit this vulnerability to gain unauthorized access to protected resources by obtaining sensitive credential information. Exploitation of this issue does not require user interaction.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27192" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/magento/apsb25-26.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-522" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T21:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2wf7-238m-g5qh/GHSA-2wf7-238m-g5qh.json b/advisories/unreviewed/2025/04/GHSA-2wf7-238m-g5qh/GHSA-2wf7-238m-g5qh.json index 34f7898173b..215e1f04acf 100644 --- a/advisories/unreviewed/2025/04/GHSA-2wf7-238m-g5qh/GHSA-2wf7-238m-g5qh.json +++ b/advisories/unreviewed/2025/04/GHSA-2wf7-238m-g5qh/GHSA-2wf7-238m-g5qh.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-33qf-6xj8-p2pq/GHSA-33qf-6xj8-p2pq.json b/advisories/unreviewed/2025/04/GHSA-33qf-6xj8-p2pq/GHSA-33qf-6xj8-p2pq.json index 2e5dcb2e788..589fcb6493d 100644 --- a/advisories/unreviewed/2025/04/GHSA-33qf-6xj8-p2pq/GHSA-33qf-6xj8-p2pq.json +++ b/advisories/unreviewed/2025/04/GHSA-33qf-6xj8-p2pq/GHSA-33qf-6xj8-p2pq.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-3cg4-jf33-6fwh/GHSA-3cg4-jf33-6fwh.json b/advisories/unreviewed/2025/04/GHSA-3cg4-jf33-6fwh/GHSA-3cg4-jf33-6fwh.json new file mode 100644 index 00000000000..316727a2cba --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3cg4-jf33-6fwh/GHSA-3cg4-jf33-6fwh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3cg4-jf33-6fwh", + "modified": "2025-04-08T21:31:40Z", + "published": "2025-04-08T21:31:40Z", + "aliases": [ + "CVE-2025-30284" + ], + "details": "ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30284" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/coldfusion/apsb25-15.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T20:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3gxj-2579-vrcc/GHSA-3gxj-2579-vrcc.json b/advisories/unreviewed/2025/04/GHSA-3gxj-2579-vrcc/GHSA-3gxj-2579-vrcc.json new file mode 100644 index 00000000000..c2a1d2540bb --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3gxj-2579-vrcc/GHSA-3gxj-2579-vrcc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3gxj-2579-vrcc", + "modified": "2025-04-08T21:31:41Z", + "published": "2025-04-08T21:31:41Z", + "aliases": [ + "CVE-2025-30290" + ], + "details": "ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to a security feature bypass. An attacker could exploit this vulnerability to access files and directories that are stored outside the intended restricted directory. Exploitation of this issue requires user interaction.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30290" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/coldfusion/apsb25-15.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T20:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3qpv-2q49-9qj8/GHSA-3qpv-2q49-9qj8.json b/advisories/unreviewed/2025/04/GHSA-3qpv-2q49-9qj8/GHSA-3qpv-2q49-9qj8.json index b561df03d67..b37b552be25 100644 --- a/advisories/unreviewed/2025/04/GHSA-3qpv-2q49-9qj8/GHSA-3qpv-2q49-9qj8.json +++ b/advisories/unreviewed/2025/04/GHSA-3qpv-2q49-9qj8/GHSA-3qpv-2q49-9qj8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3qpv-2q49-9qj8", - "modified": "2025-04-07T21:32:08Z", + "modified": "2025-04-08T21:31:38Z", "published": "2025-04-07T21:32:08Z", "aliases": [ "CVE-2024-46494" ], "details": "A cross-site scripting (XSS) vulnerability in Typecho v1.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into Name parameter under a comment for an Article.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-07T20:15:19Z" diff --git a/advisories/unreviewed/2025/04/GHSA-527p-356f-cgq4/GHSA-527p-356f-cgq4.json b/advisories/unreviewed/2025/04/GHSA-527p-356f-cgq4/GHSA-527p-356f-cgq4.json index 418981b8a5a..09d888b92f4 100644 --- a/advisories/unreviewed/2025/04/GHSA-527p-356f-cgq4/GHSA-527p-356f-cgq4.json +++ b/advisories/unreviewed/2025/04/GHSA-527p-356f-cgq4/GHSA-527p-356f-cgq4.json @@ -41,7 +41,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-319" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-5x84-fgc9-6qq4/GHSA-5x84-fgc9-6qq4.json b/advisories/unreviewed/2025/04/GHSA-5x84-fgc9-6qq4/GHSA-5x84-fgc9-6qq4.json index 7ad520230d9..9151869cd26 100644 --- a/advisories/unreviewed/2025/04/GHSA-5x84-fgc9-6qq4/GHSA-5x84-fgc9-6qq4.json +++ b/advisories/unreviewed/2025/04/GHSA-5x84-fgc9-6qq4/GHSA-5x84-fgc9-6qq4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5x84-fgc9-6qq4", - "modified": "2025-04-06T15:30:33Z", + "modified": "2025-04-08T21:31:35Z", "published": "2025-04-06T15:30:33Z", "aliases": [ "CVE-2025-3318" @@ -38,7 +38,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-633m-895c-3f9g/GHSA-633m-895c-3f9g.json b/advisories/unreviewed/2025/04/GHSA-633m-895c-3f9g/GHSA-633m-895c-3f9g.json index a354300f081..2a8b3166ea2 100644 --- a/advisories/unreviewed/2025/04/GHSA-633m-895c-3f9g/GHSA-633m-895c-3f9g.json +++ b/advisories/unreviewed/2025/04/GHSA-633m-895c-3f9g/GHSA-633m-895c-3f9g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-633m-895c-3f9g", - "modified": "2025-04-07T12:33:19Z", + "modified": "2025-04-08T21:31:37Z", "published": "2025-04-07T12:33:19Z", "aliases": [ "CVE-2025-0050" ], "details": "Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Arm Ltd Bifrost GPU Userspace Driver, Arm Ltd Valhall GPU Userspace Driver, Arm Ltd Arm 5th Gen GPU Architecture Userspace Driver allows a non-privileged user process to make valid GPU processing operations, including via WebGL or WebGPU, to access a limited amount outside of buffer bounds.This issue affects Bifrost GPU Userspace Driver: from r0p0 through r49p2, from r50p0 through r51p0; Valhall GPU Userspace Driver: from r19p0 through r49p2, from r50p0 through r53p0; Arm 5th Gen GPU Architecture Userspace Driver: from r41p0 through r49p2, from r50p0 through r53p0.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-119" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-07T12:15:15Z" diff --git a/advisories/unreviewed/2025/04/GHSA-6423-85cc-8gf6/GHSA-6423-85cc-8gf6.json b/advisories/unreviewed/2025/04/GHSA-6423-85cc-8gf6/GHSA-6423-85cc-8gf6.json index 4d1dee757e0..195c57336bc 100644 --- a/advisories/unreviewed/2025/04/GHSA-6423-85cc-8gf6/GHSA-6423-85cc-8gf6.json +++ b/advisories/unreviewed/2025/04/GHSA-6423-85cc-8gf6/GHSA-6423-85cc-8gf6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6423-85cc-8gf6", - "modified": "2025-04-08T18:34:43Z", + "modified": "2025-04-08T21:31:38Z", "published": "2025-04-08T18:34:43Z", "aliases": [ "CVE-2025-25227" ], "details": "Insufficient state checks lead to a vector that allows to bypass 2FA checks.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-287" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-08T17:15:35Z" diff --git a/advisories/unreviewed/2025/04/GHSA-64wf-mpw9-cw5v/GHSA-64wf-mpw9-cw5v.json b/advisories/unreviewed/2025/04/GHSA-64wf-mpw9-cw5v/GHSA-64wf-mpw9-cw5v.json new file mode 100644 index 00000000000..20637c18bda --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-64wf-mpw9-cw5v/GHSA-64wf-mpw9-cw5v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-64wf-mpw9-cw5v", + "modified": "2025-04-08T21:31:40Z", + "published": "2025-04-08T21:31:40Z", + "aliases": [ + "CVE-2025-24447" + ], + "details": "ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24447" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/coldfusion/apsb25-15.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T20:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-658h-wc48-rw6r/GHSA-658h-wc48-rw6r.json b/advisories/unreviewed/2025/04/GHSA-658h-wc48-rw6r/GHSA-658h-wc48-rw6r.json new file mode 100644 index 00000000000..29d74c89e13 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-658h-wc48-rw6r/GHSA-658h-wc48-rw6r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-658h-wc48-rw6r", + "modified": "2025-04-08T21:31:40Z", + "published": "2025-04-08T21:31:40Z", + "aliases": [ + "CVE-2025-24446" + ], + "details": "ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24446" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/coldfusion/apsb25-15.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T20:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-65g2-h96w-cwp4/GHSA-65g2-h96w-cwp4.json b/advisories/unreviewed/2025/04/GHSA-65g2-h96w-cwp4/GHSA-65g2-h96w-cwp4.json new file mode 100644 index 00000000000..18bb4250c57 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-65g2-h96w-cwp4/GHSA-65g2-h96w-cwp4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-65g2-h96w-cwp4", + "modified": "2025-04-08T21:31:40Z", + "published": "2025-04-08T21:31:40Z", + "aliases": [ + "CVE-2025-30309" + ], + "details": "XMP Toolkit versions 2023.12 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30309" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/xmpcore/apsb25-34.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T19:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6j75-9vmv-439p/GHSA-6j75-9vmv-439p.json b/advisories/unreviewed/2025/04/GHSA-6j75-9vmv-439p/GHSA-6j75-9vmv-439p.json index 3d444070be0..ef027260015 100644 --- a/advisories/unreviewed/2025/04/GHSA-6j75-9vmv-439p/GHSA-6j75-9vmv-439p.json +++ b/advisories/unreviewed/2025/04/GHSA-6j75-9vmv-439p/GHSA-6j75-9vmv-439p.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-6wq7-cg9h-mj6q/GHSA-6wq7-cg9h-mj6q.json b/advisories/unreviewed/2025/04/GHSA-6wq7-cg9h-mj6q/GHSA-6wq7-cg9h-mj6q.json new file mode 100644 index 00000000000..24d015af924 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6wq7-cg9h-mj6q/GHSA-6wq7-cg9h-mj6q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6wq7-cg9h-mj6q", + "modified": "2025-04-08T21:31:41Z", + "published": "2025-04-08T21:31:41Z", + "aliases": [ + "CVE-2025-27190" + ], + "details": "Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue does not require user interaction.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27190" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/magento/apsb25-26.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T21:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-73gg-qjfg-4g7x/GHSA-73gg-qjfg-4g7x.json b/advisories/unreviewed/2025/04/GHSA-73gg-qjfg-4g7x/GHSA-73gg-qjfg-4g7x.json new file mode 100644 index 00000000000..31a230adec5 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-73gg-qjfg-4g7x/GHSA-73gg-qjfg-4g7x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-73gg-qjfg-4g7x", + "modified": "2025-04-08T21:31:39Z", + "published": "2025-04-08T21:31:39Z", + "aliases": [ + "CVE-2025-30295" + ], + "details": "Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30295" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/framemaker/apsb25-33.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T19:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-796g-c5p5-hfrr/GHSA-796g-c5p5-hfrr.json b/advisories/unreviewed/2025/04/GHSA-796g-c5p5-hfrr/GHSA-796g-c5p5-hfrr.json index 5d49306e289..2178f7549c4 100644 --- a/advisories/unreviewed/2025/04/GHSA-796g-c5p5-hfrr/GHSA-796g-c5p5-hfrr.json +++ b/advisories/unreviewed/2025/04/GHSA-796g-c5p5-hfrr/GHSA-796g-c5p5-hfrr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-796g-c5p5-hfrr", - "modified": "2025-04-07T18:30:48Z", + "modified": "2025-04-08T21:31:37Z", "published": "2025-04-07T18:30:48Z", "aliases": [ "CVE-2025-28410" ], "details": "An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the cancelAuthUserAll method does not properly validate whether the requesting user has administrative privileges", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-07T16:15:25Z" diff --git a/advisories/unreviewed/2025/04/GHSA-7c4q-68g6-pmr5/GHSA-7c4q-68g6-pmr5.json b/advisories/unreviewed/2025/04/GHSA-7c4q-68g6-pmr5/GHSA-7c4q-68g6-pmr5.json new file mode 100644 index 00000000000..3b8c0322b27 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7c4q-68g6-pmr5/GHSA-7c4q-68g6-pmr5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7c4q-68g6-pmr5", + "modified": "2025-04-08T21:31:41Z", + "published": "2025-04-08T21:31:41Z", + "aliases": [ + "CVE-2025-30289" + ], + "details": "ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an attacker. Exploitation of this issue does not require user interaction.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30289" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/coldfusion/apsb25-15.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T20:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7frx-2jch-mmcm/GHSA-7frx-2jch-mmcm.json b/advisories/unreviewed/2025/04/GHSA-7frx-2jch-mmcm/GHSA-7frx-2jch-mmcm.json index 5ef6d3e535c..782a1217873 100644 --- a/advisories/unreviewed/2025/04/GHSA-7frx-2jch-mmcm/GHSA-7frx-2jch-mmcm.json +++ b/advisories/unreviewed/2025/04/GHSA-7frx-2jch-mmcm/GHSA-7frx-2jch-mmcm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7frx-2jch-mmcm", - "modified": "2025-04-07T18:30:47Z", + "modified": "2025-04-08T21:31:37Z", "published": "2025-04-07T18:30:47Z", "aliases": [ "CVE-2025-28409" ], "details": "An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the add method of the /add/{parentId} endpoint does not properly validate whether the requesting user has permission to add a menu item under the specified parentId", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-07T16:15:25Z" diff --git a/advisories/unreviewed/2025/04/GHSA-7r4x-ff5h-ghvg/GHSA-7r4x-ff5h-ghvg.json b/advisories/unreviewed/2025/04/GHSA-7r4x-ff5h-ghvg/GHSA-7r4x-ff5h-ghvg.json index 7c278d57019..8d3b243a733 100644 --- a/advisories/unreviewed/2025/04/GHSA-7r4x-ff5h-ghvg/GHSA-7r4x-ff5h-ghvg.json +++ b/advisories/unreviewed/2025/04/GHSA-7r4x-ff5h-ghvg/GHSA-7r4x-ff5h-ghvg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7r4x-ff5h-ghvg", - "modified": "2025-04-07T15:31:14Z", + "modified": "2025-04-08T21:31:36Z", "published": "2025-04-07T15:31:14Z", "aliases": [ "CVE-2025-3325" @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-266" + "CWE-266", + "CWE-434" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-86h2-47xr-3w77/GHSA-86h2-47xr-3w77.json b/advisories/unreviewed/2025/04/GHSA-86h2-47xr-3w77/GHSA-86h2-47xr-3w77.json new file mode 100644 index 00000000000..0b1989635d8 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-86h2-47xr-3w77/GHSA-86h2-47xr-3w77.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-86h2-47xr-3w77", + "modified": "2025-04-08T21:31:41Z", + "published": "2025-04-08T21:31:41Z", + "aliases": [ + "CVE-2025-30285" + ], + "details": "ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30285" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/coldfusion/apsb25-15.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T20:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8843-g665-5rpj/GHSA-8843-g665-5rpj.json b/advisories/unreviewed/2025/04/GHSA-8843-g665-5rpj/GHSA-8843-g665-5rpj.json index 0735a07addd..835ba6fc1a1 100644 --- a/advisories/unreviewed/2025/04/GHSA-8843-g665-5rpj/GHSA-8843-g665-5rpj.json +++ b/advisories/unreviewed/2025/04/GHSA-8843-g665-5rpj/GHSA-8843-g665-5rpj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8843-g665-5rpj", - "modified": "2025-04-07T18:30:47Z", + "modified": "2025-04-08T21:31:37Z", "published": "2025-04-07T18:30:47Z", "aliases": [ "CVE-2025-28408" ], "details": "An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the selectDeptTree method of the /selectDeptTree/{deptId} endpoint does not properly validate the deptId parameter", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-07T16:15:24Z" diff --git a/advisories/unreviewed/2025/04/GHSA-8w94-ggwf-26rw/GHSA-8w94-ggwf-26rw.json b/advisories/unreviewed/2025/04/GHSA-8w94-ggwf-26rw/GHSA-8w94-ggwf-26rw.json index 724d566c52d..4653bf30727 100644 --- a/advisories/unreviewed/2025/04/GHSA-8w94-ggwf-26rw/GHSA-8w94-ggwf-26rw.json +++ b/advisories/unreviewed/2025/04/GHSA-8w94-ggwf-26rw/GHSA-8w94-ggwf-26rw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8w94-ggwf-26rw", - "modified": "2025-04-07T18:30:48Z", + "modified": "2025-04-08T21:31:38Z", "published": "2025-04-07T18:30:48Z", "aliases": [ "CVE-2025-28412" ], "details": "An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the /editSave method in SysNoticeController", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-07T16:15:25Z" diff --git a/advisories/unreviewed/2025/04/GHSA-8xhv-fwf3-q27f/GHSA-8xhv-fwf3-q27f.json b/advisories/unreviewed/2025/04/GHSA-8xhv-fwf3-q27f/GHSA-8xhv-fwf3-q27f.json index 7dc41c88725..8e9911d4451 100644 --- a/advisories/unreviewed/2025/04/GHSA-8xhv-fwf3-q27f/GHSA-8xhv-fwf3-q27f.json +++ b/advisories/unreviewed/2025/04/GHSA-8xhv-fwf3-q27f/GHSA-8xhv-fwf3-q27f.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-96jf-mvrm-934f/GHSA-96jf-mvrm-934f.json b/advisories/unreviewed/2025/04/GHSA-96jf-mvrm-934f/GHSA-96jf-mvrm-934f.json new file mode 100644 index 00000000000..204c97c83b7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-96jf-mvrm-934f/GHSA-96jf-mvrm-934f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-96jf-mvrm-934f", + "modified": "2025-04-08T21:31:39Z", + "published": "2025-04-08T21:31:39Z", + "aliases": [ + "CVE-2025-30298" + ], + "details": "Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30298" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/framemaker/apsb25-33.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T19:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-98gx-7m8x-x64f/GHSA-98gx-7m8x-x64f.json b/advisories/unreviewed/2025/04/GHSA-98gx-7m8x-x64f/GHSA-98gx-7m8x-x64f.json new file mode 100644 index 00000000000..5e4e1658b57 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-98gx-7m8x-x64f/GHSA-98gx-7m8x-x64f.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-98gx-7m8x-x64f", + "modified": "2025-04-08T21:31:40Z", + "published": "2025-04-08T21:31:40Z", + "aliases": [ + "CVE-2025-30304" + ], + "details": "Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30304" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/framemaker/apsb25-33.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T19:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9f8p-m62j-44x8/GHSA-9f8p-m62j-44x8.json b/advisories/unreviewed/2025/04/GHSA-9f8p-m62j-44x8/GHSA-9f8p-m62j-44x8.json new file mode 100644 index 00000000000..267618f71ef --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-9f8p-m62j-44x8/GHSA-9f8p-m62j-44x8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9f8p-m62j-44x8", + "modified": "2025-04-08T21:31:39Z", + "published": "2025-04-08T21:31:39Z", + "aliases": [ + "CVE-2025-30301" + ], + "details": "Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30301" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/framemaker/apsb25-33.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T19:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-cp9f-7jr4-m2mj/GHSA-cp9f-7jr4-m2mj.json b/advisories/unreviewed/2025/04/GHSA-cp9f-7jr4-m2mj/GHSA-cp9f-7jr4-m2mj.json new file mode 100644 index 00000000000..d5582af0599 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-cp9f-7jr4-m2mj/GHSA-cp9f-7jr4-m2mj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cp9f-7jr4-m2mj", + "modified": "2025-04-08T21:31:40Z", + "published": "2025-04-08T21:31:40Z", + "aliases": [ + "CVE-2025-30282" + ], + "details": "ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Authentication vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could leverage this vulnerability to bypass authentication mechanisms and execute code with the privileges of the authenticated user. Exploitation of this issue requires user interaction in that a victim must be coerced into performing actions within the application.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30282" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/coldfusion/apsb25-15.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T20:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-cqwm-8779-r274/GHSA-cqwm-8779-r274.json b/advisories/unreviewed/2025/04/GHSA-cqwm-8779-r274/GHSA-cqwm-8779-r274.json new file mode 100644 index 00000000000..f33fcc83edf --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-cqwm-8779-r274/GHSA-cqwm-8779-r274.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cqwm-8779-r274", + "modified": "2025-04-08T21:31:40Z", + "published": "2025-04-08T21:31:40Z", + "aliases": [ + "CVE-2025-30307" + ], + "details": "XMP Toolkit versions 2023.12 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30307" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/xmpcore/apsb25-34.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T19:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-f29x-f897-g8f9/GHSA-f29x-f897-g8f9.json b/advisories/unreviewed/2025/04/GHSA-f29x-f897-g8f9/GHSA-f29x-f897-g8f9.json new file mode 100644 index 00000000000..a8dc602494d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-f29x-f897-g8f9/GHSA-f29x-f897-g8f9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f29x-f897-g8f9", + "modified": "2025-04-08T21:31:40Z", + "published": "2025-04-08T21:31:40Z", + "aliases": [ + "CVE-2025-30303" + ], + "details": "Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30303" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/framemaker/apsb25-33.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T19:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-f2ff-9j2m-p32f/GHSA-f2ff-9j2m-p32f.json b/advisories/unreviewed/2025/04/GHSA-f2ff-9j2m-p32f/GHSA-f2ff-9j2m-p32f.json index 1939eac6805..1fd628ed26a 100644 --- a/advisories/unreviewed/2025/04/GHSA-f2ff-9j2m-p32f/GHSA-f2ff-9j2m-p32f.json +++ b/advisories/unreviewed/2025/04/GHSA-f2ff-9j2m-p32f/GHSA-f2ff-9j2m-p32f.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-fhq8-pvx2-r42x/GHSA-fhq8-pvx2-r42x.json b/advisories/unreviewed/2025/04/GHSA-fhq8-pvx2-r42x/GHSA-fhq8-pvx2-r42x.json new file mode 100644 index 00000000000..2a486e0a73d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fhq8-pvx2-r42x/GHSA-fhq8-pvx2-r42x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fhq8-pvx2-r42x", + "modified": "2025-04-08T21:31:39Z", + "published": "2025-04-08T21:31:39Z", + "aliases": [ + "CVE-2025-30300" + ], + "details": "Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial of service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30300" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/framemaker/apsb25-33.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T19:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fpf8-39f6-cgrc/GHSA-fpf8-39f6-cgrc.json b/advisories/unreviewed/2025/04/GHSA-fpf8-39f6-cgrc/GHSA-fpf8-39f6-cgrc.json new file mode 100644 index 00000000000..a8348385928 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fpf8-39f6-cgrc/GHSA-fpf8-39f6-cgrc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fpf8-39f6-cgrc", + "modified": "2025-04-08T21:31:41Z", + "published": "2025-04-08T21:31:41Z", + "aliases": [ + "CVE-2025-27189" + ], + "details": "Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by a Cross-Site Request Forgery (CSRF) vulnerability that could be exploited to cause a denial-of-service condition. An attacker could trick a logged-in user into submitting a forged request to the vulnerable application, which may disrupt service availability. Exploitation of this issue requires user interaction, typically in the form of clicking a malicious link or visiting an attacker-controlled website.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27189" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/magento/apsb25-26.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T21:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fv2f-q5hc-738w/GHSA-fv2f-q5hc-738w.json b/advisories/unreviewed/2025/04/GHSA-fv2f-q5hc-738w/GHSA-fv2f-q5hc-738w.json index dabe7e97e62..79d709df6d1 100644 --- a/advisories/unreviewed/2025/04/GHSA-fv2f-q5hc-738w/GHSA-fv2f-q5hc-738w.json +++ b/advisories/unreviewed/2025/04/GHSA-fv2f-q5hc-738w/GHSA-fv2f-q5hc-738w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fv2f-q5hc-738w", - "modified": "2025-04-07T15:31:14Z", + "modified": "2025-04-08T21:31:36Z", "published": "2025-04-07T15:31:14Z", "aliases": [ "CVE-2025-3327" diff --git a/advisories/unreviewed/2025/04/GHSA-g2qq-97wv-38qx/GHSA-g2qq-97wv-38qx.json b/advisories/unreviewed/2025/04/GHSA-g2qq-97wv-38qx/GHSA-g2qq-97wv-38qx.json index 4029410403f..03245d5c33d 100644 --- a/advisories/unreviewed/2025/04/GHSA-g2qq-97wv-38qx/GHSA-g2qq-97wv-38qx.json +++ b/advisories/unreviewed/2025/04/GHSA-g2qq-97wv-38qx/GHSA-g2qq-97wv-38qx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-g2qq-97wv-38qx", - "modified": "2025-04-07T18:30:47Z", + "modified": "2025-04-08T21:31:37Z", "published": "2025-04-07T18:30:47Z", "aliases": [ "CVE-2025-28402" ], "details": "An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the jobId parameter", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-07T16:15:24Z" diff --git a/advisories/unreviewed/2025/04/GHSA-g9pc-8g42-g6vq/GHSA-g9pc-8g42-g6vq.json b/advisories/unreviewed/2025/04/GHSA-g9pc-8g42-g6vq/GHSA-g9pc-8g42-g6vq.json new file mode 100644 index 00000000000..7a6ffbc0b44 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-g9pc-8g42-g6vq/GHSA-g9pc-8g42-g6vq.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g9pc-8g42-g6vq", + "modified": "2025-04-08T21:31:40Z", + "published": "2025-04-08T21:31:40Z", + "aliases": [ + "CVE-2025-22871" + ], + "details": "The net/http package improperly accepts a bare LF as a line terminator in chunked data chunk-size lines. This can permit request smuggling if a net/http server is used in conjunction with a server that incorrectly accepts a bare LF as part of a chunk-ext.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22871" + }, + { + "type": "WEB", + "url": "https://go.dev/cl/652998" + }, + { + "type": "WEB", + "url": "https://go.dev/issue/71988" + }, + { + "type": "WEB", + "url": "https://groups.google.com/g/golang-announce/c/Y2uBTVKjBQk" + }, + { + "type": "WEB", + "url": "https://pkg.go.dev/vuln/GO-2025-3563" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/04/04/4" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T20:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-gx9w-r4j8-6p7h/GHSA-gx9w-r4j8-6p7h.json b/advisories/unreviewed/2025/04/GHSA-gx9w-r4j8-6p7h/GHSA-gx9w-r4j8-6p7h.json new file mode 100644 index 00000000000..69d6aa9cd23 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-gx9w-r4j8-6p7h/GHSA-gx9w-r4j8-6p7h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gx9w-r4j8-6p7h", + "modified": "2025-04-08T21:31:40Z", + "published": "2025-04-08T21:31:40Z", + "aliases": [ + "CVE-2025-30308" + ], + "details": "XMP Toolkit versions 2023.12 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30308" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/xmpcore/apsb25-34.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T19:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-h78g-f5x3-jrm2/GHSA-h78g-f5x3-jrm2.json b/advisories/unreviewed/2025/04/GHSA-h78g-f5x3-jrm2/GHSA-h78g-f5x3-jrm2.json index 0122e9b6d14..cfd32ce896c 100644 --- a/advisories/unreviewed/2025/04/GHSA-h78g-f5x3-jrm2/GHSA-h78g-f5x3-jrm2.json +++ b/advisories/unreviewed/2025/04/GHSA-h78g-f5x3-jrm2/GHSA-h78g-f5x3-jrm2.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-434" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-hpc9-p79m-q8wm/GHSA-hpc9-p79m-q8wm.json b/advisories/unreviewed/2025/04/GHSA-hpc9-p79m-q8wm/GHSA-hpc9-p79m-q8wm.json new file mode 100644 index 00000000000..c4494361e8d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hpc9-p79m-q8wm/GHSA-hpc9-p79m-q8wm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hpc9-p79m-q8wm", + "modified": "2025-04-08T21:31:41Z", + "published": "2025-04-08T21:31:41Z", + "aliases": [ + "CVE-2025-30287" + ], + "details": "ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Authentication vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could leverage this vulnerability to bypass authentication mechanisms and execute code with the privileges of the authenticated user. Exploitation of this issue requires user interaction in that a victim must be coerced into performing actions within the application.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30287" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/coldfusion/apsb25-15.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T20:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-j46p-wfvm-g6pg/GHSA-j46p-wfvm-g6pg.json b/advisories/unreviewed/2025/04/GHSA-j46p-wfvm-g6pg/GHSA-j46p-wfvm-g6pg.json index 8441786dcec..80633e2e835 100644 --- a/advisories/unreviewed/2025/04/GHSA-j46p-wfvm-g6pg/GHSA-j46p-wfvm-g6pg.json +++ b/advisories/unreviewed/2025/04/GHSA-j46p-wfvm-g6pg/GHSA-j46p-wfvm-g6pg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-j46p-wfvm-g6pg", - "modified": "2025-04-07T18:30:47Z", + "modified": "2025-04-08T21:31:37Z", "published": "2025-04-07T18:30:47Z", "aliases": [ "CVE-2025-28407" ], "details": "An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the edit method of the /edit/{dictId} endpoint does not properly validate whether the requesting user has permission to modify the specified dictId", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-07T16:15:24Z" diff --git a/advisories/unreviewed/2025/04/GHSA-j72q-qc2x-rq8g/GHSA-j72q-qc2x-rq8g.json b/advisories/unreviewed/2025/04/GHSA-j72q-qc2x-rq8g/GHSA-j72q-qc2x-rq8g.json new file mode 100644 index 00000000000..be238e8d677 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-j72q-qc2x-rq8g/GHSA-j72q-qc2x-rq8g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j72q-qc2x-rq8g", + "modified": "2025-04-08T21:31:41Z", + "published": "2025-04-08T21:31:41Z", + "aliases": [ + "CVE-2025-30288" + ], + "details": "ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue does not require user interaction.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30288" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/coldfusion/apsb25-15.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T20:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-jhqq-vcx8-rp7q/GHSA-jhqq-vcx8-rp7q.json b/advisories/unreviewed/2025/04/GHSA-jhqq-vcx8-rp7q/GHSA-jhqq-vcx8-rp7q.json new file mode 100644 index 00000000000..769906c1447 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jhqq-vcx8-rp7q/GHSA-jhqq-vcx8-rp7q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jhqq-vcx8-rp7q", + "modified": "2025-04-08T21:31:40Z", + "published": "2025-04-08T21:31:40Z", + "aliases": [ + "CVE-2025-30302" + ], + "details": "Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30302" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/framemaker/apsb25-33.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T19:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-mgh2-hf68-73c8/GHSA-mgh2-hf68-73c8.json b/advisories/unreviewed/2025/04/GHSA-mgh2-hf68-73c8/GHSA-mgh2-hf68-73c8.json new file mode 100644 index 00000000000..e98c18135e4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-mgh2-hf68-73c8/GHSA-mgh2-hf68-73c8.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mgh2-hf68-73c8", + "modified": "2025-04-08T21:31:40Z", + "published": "2025-04-08T21:31:40Z", + "aliases": [ + "CVE-2025-3416" + ], + "details": "A flaw was found in OpenSSL's handling of the properties argument in certain functions. This vulnerability can allow use-after-free exploitation, which may result in undefined behavior or incorrect property parsing, leading to OpenSSL treating the input as an empty string.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3416" + }, + { + "type": "WEB", + "url": "https://github.com/sfackler/rust-openssl/pull/2390" + }, + { + "type": "WEB", + "url": "https://github.com/sfackler/rust-openssl/commit/87085bd67896b7f92e6de35d081f607a334beae4" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2025-3416" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2357560" + }, + { + "type": "WEB", + "url": "https://github.com/sfackler/rust-openssl" + }, + { + "type": "WEB", + "url": "https://rustsec.org/advisories/RUSTSEC-2025-0022.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T19:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-mrv4-mqvc-q66g/GHSA-mrv4-mqvc-q66g.json b/advisories/unreviewed/2025/04/GHSA-mrv4-mqvc-q66g/GHSA-mrv4-mqvc-q66g.json index cf58c935276..67a7f00b477 100644 --- a/advisories/unreviewed/2025/04/GHSA-mrv4-mqvc-q66g/GHSA-mrv4-mqvc-q66g.json +++ b/advisories/unreviewed/2025/04/GHSA-mrv4-mqvc-q66g/GHSA-mrv4-mqvc-q66g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mrv4-mqvc-q66g", - "modified": "2025-04-07T18:30:47Z", + "modified": "2025-04-08T21:31:37Z", "published": "2025-04-07T18:30:47Z", "aliases": [ "CVE-2025-28405" ], "details": "An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the changeStatus method", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-07T16:15:24Z" diff --git a/advisories/unreviewed/2025/04/GHSA-mw45-m2cr-q9jj/GHSA-mw45-m2cr-q9jj.json b/advisories/unreviewed/2025/04/GHSA-mw45-m2cr-q9jj/GHSA-mw45-m2cr-q9jj.json new file mode 100644 index 00000000000..9b3e0ecda69 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-mw45-m2cr-q9jj/GHSA-mw45-m2cr-q9jj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mw45-m2cr-q9jj", + "modified": "2025-04-08T21:31:41Z", + "published": "2025-04-08T21:31:41Z", + "aliases": [ + "CVE-2025-30292" + ], + "details": "ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30292" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/coldfusion/apsb25-15.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T20:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-pc39-7549-89wv/GHSA-pc39-7549-89wv.json b/advisories/unreviewed/2025/04/GHSA-pc39-7549-89wv/GHSA-pc39-7549-89wv.json new file mode 100644 index 00000000000..788e37eebea --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-pc39-7549-89wv/GHSA-pc39-7549-89wv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pc39-7549-89wv", + "modified": "2025-04-08T21:31:41Z", + "published": "2025-04-08T21:31:41Z", + "aliases": [ + "CVE-2025-30291" + ], + "details": "ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Information Exposure vulnerability that could result in a security feature bypass. An attacker could leverage this vulnerability to gain access to sensitive information which could be used to further compromise the system or bypass security mechanisms. Exploitation of this issue does not require user interaction.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30291" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/coldfusion/apsb25-15.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T20:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-ppxr-f836-phpf/GHSA-ppxr-f836-phpf.json b/advisories/unreviewed/2025/04/GHSA-ppxr-f836-phpf/GHSA-ppxr-f836-phpf.json index 075efa09c14..f9ccb8c3319 100644 --- a/advisories/unreviewed/2025/04/GHSA-ppxr-f836-phpf/GHSA-ppxr-f836-phpf.json +++ b/advisories/unreviewed/2025/04/GHSA-ppxr-f836-phpf/GHSA-ppxr-f836-phpf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-ppxr-f836-phpf", - "modified": "2025-04-07T18:30:47Z", + "modified": "2025-04-08T21:31:37Z", "published": "2025-04-07T18:30:47Z", "aliases": [ "CVE-2025-28406" ], "details": "An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the jobLogId parameter", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-07T16:15:24Z" diff --git a/advisories/unreviewed/2025/04/GHSA-q969-vh79-2qg8/GHSA-q969-vh79-2qg8.json b/advisories/unreviewed/2025/04/GHSA-q969-vh79-2qg8/GHSA-q969-vh79-2qg8.json new file mode 100644 index 00000000000..2a1aee1dbd6 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-q969-vh79-2qg8/GHSA-q969-vh79-2qg8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q969-vh79-2qg8", + "modified": "2025-04-08T21:31:39Z", + "published": "2025-04-08T21:31:39Z", + "aliases": [ + "CVE-2025-30297" + ], + "details": "Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30297" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/framemaker/apsb25-33.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T19:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qj34-w7fp-qg2w/GHSA-qj34-w7fp-qg2w.json b/advisories/unreviewed/2025/04/GHSA-qj34-w7fp-qg2w/GHSA-qj34-w7fp-qg2w.json new file mode 100644 index 00000000000..2ba4f63eb04 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qj34-w7fp-qg2w/GHSA-qj34-w7fp-qg2w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qj34-w7fp-qg2w", + "modified": "2025-04-08T21:31:41Z", + "published": "2025-04-08T21:31:41Z", + "aliases": [ + "CVE-2025-30293" + ], + "details": "ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30293" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/coldfusion/apsb25-15.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T20:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-r3m2-p27f-8635/GHSA-r3m2-p27f-8635.json b/advisories/unreviewed/2025/04/GHSA-r3m2-p27f-8635/GHSA-r3m2-p27f-8635.json new file mode 100644 index 00000000000..150d28dd632 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-r3m2-p27f-8635/GHSA-r3m2-p27f-8635.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r3m2-p27f-8635", + "modified": "2025-04-08T21:31:40Z", + "published": "2025-04-08T21:31:40Z", + "aliases": [ + "CVE-2025-30281" + ], + "details": "ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. An attacker could leverage this vulnerability to access or modify sensitive data without proper authorization. Exploitation of this issue does not require user interaction.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30281" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/coldfusion/apsb25-15.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T20:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-r4wm-j267-rq33/GHSA-r4wm-j267-rq33.json b/advisories/unreviewed/2025/04/GHSA-r4wm-j267-rq33/GHSA-r4wm-j267-rq33.json new file mode 100644 index 00000000000..2a499bc8091 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-r4wm-j267-rq33/GHSA-r4wm-j267-rq33.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r4wm-j267-rq33", + "modified": "2025-04-08T21:31:41Z", + "published": "2025-04-08T21:31:41Z", + "aliases": [ + "CVE-2025-30286" + ], + "details": "ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an attacker. Exploitation of this issue does not require user interaction.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30286" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/coldfusion/apsb25-15.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T20:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rqjr-gvph-vqwr/GHSA-rqjr-gvph-vqwr.json b/advisories/unreviewed/2025/04/GHSA-rqjr-gvph-vqwr/GHSA-rqjr-gvph-vqwr.json index 8a5832323f3..9801c7cffb9 100644 --- a/advisories/unreviewed/2025/04/GHSA-rqjr-gvph-vqwr/GHSA-rqjr-gvph-vqwr.json +++ b/advisories/unreviewed/2025/04/GHSA-rqjr-gvph-vqwr/GHSA-rqjr-gvph-vqwr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rqjr-gvph-vqwr", - "modified": "2025-04-07T18:30:48Z", + "modified": "2025-04-08T21:31:38Z", "published": "2025-04-07T18:30:47Z", "aliases": [ "CVE-2025-28411" ], "details": "An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the editSave method in /tool/gen/editSave", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-07T16:15:25Z" diff --git a/advisories/unreviewed/2025/04/GHSA-rr2g-rrjj-xw86/GHSA-rr2g-rrjj-xw86.json b/advisories/unreviewed/2025/04/GHSA-rr2g-rrjj-xw86/GHSA-rr2g-rrjj-xw86.json new file mode 100644 index 00000000000..f7f274c4afa --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rr2g-rrjj-xw86/GHSA-rr2g-rrjj-xw86.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rr2g-rrjj-xw86", + "modified": "2025-04-08T21:31:41Z", + "published": "2025-04-08T21:31:41Z", + "aliases": [ + "CVE-2025-27188" + ], + "details": "Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Improper Authorization vulnerability that could result in Privilege escalation. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue does not require user interaction.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27188" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/magento/apsb25-26.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-285" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T21:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rv7x-66xx-8rvv/GHSA-rv7x-66xx-8rvv.json b/advisories/unreviewed/2025/04/GHSA-rv7x-66xx-8rvv/GHSA-rv7x-66xx-8rvv.json new file mode 100644 index 00000000000..8fc8006fa78 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rv7x-66xx-8rvv/GHSA-rv7x-66xx-8rvv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rv7x-66xx-8rvv", + "modified": "2025-04-08T21:31:41Z", + "published": "2025-04-08T21:31:41Z", + "aliases": [ + "CVE-2025-30294" + ], + "details": "ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30294" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/coldfusion/apsb25-15.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T20:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rvvc-m8pv-rj9r/GHSA-rvvc-m8pv-rj9r.json b/advisories/unreviewed/2025/04/GHSA-rvvc-m8pv-rj9r/GHSA-rvvc-m8pv-rj9r.json index 1ed87493a73..3f567fad407 100644 --- a/advisories/unreviewed/2025/04/GHSA-rvvc-m8pv-rj9r/GHSA-rvvc-m8pv-rj9r.json +++ b/advisories/unreviewed/2025/04/GHSA-rvvc-m8pv-rj9r/GHSA-rvvc-m8pv-rj9r.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rvvc-m8pv-rj9r", - "modified": "2025-04-07T18:30:47Z", + "modified": "2025-04-08T21:31:37Z", "published": "2025-04-07T18:30:47Z", "aliases": [ "CVE-2025-28403" ], "details": "An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the editSave method does not properly validate whether the requesting user has administrative privileges before allowing modifications to system configuration settings", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-07T16:15:24Z" diff --git a/advisories/unreviewed/2025/04/GHSA-v236-qrg8-r7vx/GHSA-v236-qrg8-r7vx.json b/advisories/unreviewed/2025/04/GHSA-v236-qrg8-r7vx/GHSA-v236-qrg8-r7vx.json new file mode 100644 index 00000000000..4695cad8bde --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-v236-qrg8-r7vx/GHSA-v236-qrg8-r7vx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v236-qrg8-r7vx", + "modified": "2025-04-08T21:31:40Z", + "published": "2025-04-08T21:31:40Z", + "aliases": [ + "CVE-2025-30306" + ], + "details": "XMP Toolkit versions 2023.12 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30306" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/xmpcore/apsb25-34.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T19:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vc28-9jgm-3qpx/GHSA-vc28-9jgm-3qpx.json b/advisories/unreviewed/2025/04/GHSA-vc28-9jgm-3qpx/GHSA-vc28-9jgm-3qpx.json index 68ba6d287f2..be097acd576 100644 --- a/advisories/unreviewed/2025/04/GHSA-vc28-9jgm-3qpx/GHSA-vc28-9jgm-3qpx.json +++ b/advisories/unreviewed/2025/04/GHSA-vc28-9jgm-3qpx/GHSA-vc28-9jgm-3qpx.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-434", "CWE-912" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2025/04/GHSA-vcfm-2r3w-vjx5/GHSA-vcfm-2r3w-vjx5.json b/advisories/unreviewed/2025/04/GHSA-vcfm-2r3w-vjx5/GHSA-vcfm-2r3w-vjx5.json new file mode 100644 index 00000000000..0f941d354cc --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vcfm-2r3w-vjx5/GHSA-vcfm-2r3w-vjx5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vcfm-2r3w-vjx5", + "modified": "2025-04-08T21:31:39Z", + "published": "2025-04-08T21:31:39Z", + "aliases": [ + "CVE-2025-30299" + ], + "details": "Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30299" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/framemaker/apsb25-33.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-122" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T19:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vhcq-4xrm-2cr2/GHSA-vhcq-4xrm-2cr2.json b/advisories/unreviewed/2025/04/GHSA-vhcq-4xrm-2cr2/GHSA-vhcq-4xrm-2cr2.json new file mode 100644 index 00000000000..05a7011680e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vhcq-4xrm-2cr2/GHSA-vhcq-4xrm-2cr2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vhcq-4xrm-2cr2", + "modified": "2025-04-08T21:31:41Z", + "published": "2025-04-08T21:31:41Z", + "aliases": [ + "CVE-2025-27191" + ], + "details": "Adobe Commerce versions 2.4.7-p4, 2.4.6-p9, 2.4.5-p11, 2.4.4-p12, 2.4.8-beta2 and earlier are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue does not require user interaction.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27191" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/magento/apsb25-26.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T21:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-wgxm-3jgj-5pwf/GHSA-wgxm-3jgj-5pwf.json b/advisories/unreviewed/2025/04/GHSA-wgxm-3jgj-5pwf/GHSA-wgxm-3jgj-5pwf.json new file mode 100644 index 00000000000..f92e9b39d1d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-wgxm-3jgj-5pwf/GHSA-wgxm-3jgj-5pwf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wgxm-3jgj-5pwf", + "modified": "2025-04-08T21:31:40Z", + "published": "2025-04-08T21:31:40Z", + "aliases": [ + "CVE-2025-30305" + ], + "details": "XMP Toolkit versions 2023.12 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30305" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/xmpcore/apsb25-34.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T19:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-ww98-mrx2-m82h/GHSA-ww98-mrx2-m82h.json b/advisories/unreviewed/2025/04/GHSA-ww98-mrx2-m82h/GHSA-ww98-mrx2-m82h.json new file mode 100644 index 00000000000..aa7db528a18 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-ww98-mrx2-m82h/GHSA-ww98-mrx2-m82h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ww98-mrx2-m82h", + "modified": "2025-04-08T21:31:40Z", + "published": "2025-04-08T21:31:40Z", + "aliases": [ + "CVE-2024-12556" + ], + "details": "Prototype Pollution in Kibana can lead to code injection via unrestricted file upload combined with path traversal.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12556" + }, + { + "type": "WEB", + "url": "https://discuss.elastic.co/t/kibana-8-16-4-and-8-17-2-security-update-esa-2025-02/376918" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1321" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T20:15:19Z" + } +} \ No newline at end of file