diff --git a/advisories/unreviewed/2025/03/GHSA-2rrx-p33r-295r/GHSA-2rrx-p33r-295r.json b/advisories/unreviewed/2025/03/GHSA-2rrx-p33r-295r/GHSA-2rrx-p33r-295r.json new file mode 100644 index 00000000000..bb7e6d4e270 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-2rrx-p33r-295r/GHSA-2rrx-p33r-295r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2rrx-p33r-295r", + "modified": "2025-03-13T12:30:32Z", + "published": "2025-03-13T12:30:32Z", + "aliases": [ + "CVE-2025-29995" + ], + "details": "This vulnerability exists in the CAP back office application due to a weak password-reset mechanism implemented at API endpoints. An authenticated remote attacker with a valid login ID could exploit this vulnerability through vulnerable API endpoint which could lead to account takeover of targeted users.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29995" + }, + { + "type": "WEB", + "url": "https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2025-0048" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-640" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-13T12:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5c7g-5xj5-gpx3/GHSA-5c7g-5xj5-gpx3.json b/advisories/unreviewed/2025/03/GHSA-5c7g-5xj5-gpx3/GHSA-5c7g-5xj5-gpx3.json new file mode 100644 index 00000000000..93414904ceb --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5c7g-5xj5-gpx3/GHSA-5c7g-5xj5-gpx3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5c7g-5xj5-gpx3", + "modified": "2025-03-13T12:30:32Z", + "published": "2025-03-13T12:30:32Z", + "aliases": [ + "CVE-2025-21104" + ], + "details": "Dell NetWorker, 19.11.0.3 and below versions, contain(s) an Open Redirect Vulnerability in NMC. An unauthenticated attacker with remoter access could potentially exploit this vulnerability, leading to a targeted application user being redirected to arbitrary web URLs. The vulnerability could be leveraged by attackers to conduct phishing attacks that cause users to divulge sensitive information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21104" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000294392/dsa-2025-124-security-update-for-dell-networker-management-console-for-http-host-header-injection-vulnerability" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-13T12:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-69gq-6xvx-r4vv/GHSA-69gq-6xvx-r4vv.json b/advisories/unreviewed/2025/03/GHSA-69gq-6xvx-r4vv/GHSA-69gq-6xvx-r4vv.json new file mode 100644 index 00000000000..d90e1c4615c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-69gq-6xvx-r4vv/GHSA-69gq-6xvx-r4vv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-69gq-6xvx-r4vv", + "modified": "2025-03-13T12:30:32Z", + "published": "2025-03-13T12:30:32Z", + "aliases": [ + "CVE-2025-29997" + ], + "details": "This vulnerability exists in the CAP back office application due to improper authorization checks on certain API endpoints. An authenticated remote attacker could exploit this vulnerability by manipulating API request URL to gain unauthorized access to other user accounts.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29997" + }, + { + "type": "WEB", + "url": "https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2025-0048" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-13T12:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9qpx-c9x4-hcg8/GHSA-9qpx-c9x4-hcg8.json b/advisories/unreviewed/2025/03/GHSA-9qpx-c9x4-hcg8/GHSA-9qpx-c9x4-hcg8.json new file mode 100644 index 00000000000..3a9994ac024 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-9qpx-c9x4-hcg8/GHSA-9qpx-c9x4-hcg8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9qpx-c9x4-hcg8", + "modified": "2025-03-13T12:30:32Z", + "published": "2025-03-13T12:30:32Z", + "aliases": [ + "CVE-2025-29996" + ], + "details": "This vulnerability exists in the CAP back office application due to improper implementation of OTP verification mechanism in its API based login. A remote attacker with valid credentials could exploit this vulnerability by manipulating API request URL/payload. Successful exploitation of this vulnerability could allow the attacker to bypass Two-Factor Authentication (2FA) for other user accounts.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29996" + }, + { + "type": "WEB", + "url": "https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2025-0048" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-288" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-13T12:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-cwqf-2qf9-9mh4/GHSA-cwqf-2qf9-9mh4.json b/advisories/unreviewed/2025/03/GHSA-cwqf-2qf9-9mh4/GHSA-cwqf-2qf9-9mh4.json new file mode 100644 index 00000000000..8390d913005 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-cwqf-2qf9-9mh4/GHSA-cwqf-2qf9-9mh4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cwqf-2qf9-9mh4", + "modified": "2025-03-13T12:30:32Z", + "published": "2025-03-13T12:30:32Z", + "aliases": [ + "CVE-2025-29998" + ], + "details": "This vulnerability exists in the CAP back office application due to missing rate limiting on OTP requests in an API endpoint. An authenticated remote attacker could exploit this vulnerability by sending multiple OTP request through vulnerable API endpoint which could lead to the OTP bombing/flooding on the targeted system.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29998" + }, + { + "type": "WEB", + "url": "https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2025-0048" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-799" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-13T12:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-j28r-mxrm-39f3/GHSA-j28r-mxrm-39f3.json b/advisories/unreviewed/2025/03/GHSA-j28r-mxrm-39f3/GHSA-j28r-mxrm-39f3.json new file mode 100644 index 00000000000..de53d6742e5 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-j28r-mxrm-39f3/GHSA-j28r-mxrm-39f3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j28r-mxrm-39f3", + "modified": "2025-03-13T12:30:32Z", + "published": "2025-03-13T12:30:32Z", + "aliases": [ + "CVE-2025-29994" + ], + "details": "This vulnerability exists in the CAP back office application due to improper authentication check at the API endpoint. An unauthenticated remote attacker with a valid login ID could exploit this vulnerability by manipulating API input parameters through API request URL/payload leading to unauthorized access to other user accounts.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29994" + }, + { + "type": "WEB", + "url": "https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2025-0048" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1390" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-13T12:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jcwm-grfm-4xmh/GHSA-jcwm-grfm-4xmh.json b/advisories/unreviewed/2025/03/GHSA-jcwm-grfm-4xmh/GHSA-jcwm-grfm-4xmh.json index 2d4c03481e4..57e6be89a91 100644 --- a/advisories/unreviewed/2025/03/GHSA-jcwm-grfm-4xmh/GHSA-jcwm-grfm-4xmh.json +++ b/advisories/unreviewed/2025/03/GHSA-jcwm-grfm-4xmh/GHSA-jcwm-grfm-4xmh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jcwm-grfm-4xmh", - "modified": "2025-03-12T18:32:52Z", + "modified": "2025-03-13T12:30:32Z", "published": "2025-03-12T18:32:52Z", "aliases": [ "CVE-2025-1683" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://cwe.mitre.org/data/definitions/59.html" }, + { + "type": "WEB", + "url": "https://www.1e.com/trust-security-compliance/?ac=0-4" + }, { "type": "WEB", "url": "https://www.1e.com/trust-security-compliance/cve-info" diff --git a/advisories/unreviewed/2025/03/GHSA-p557-g28f-mg4p/GHSA-p557-g28f-mg4p.json b/advisories/unreviewed/2025/03/GHSA-p557-g28f-mg4p/GHSA-p557-g28f-mg4p.json new file mode 100644 index 00000000000..c0e48d60918 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-p557-g28f-mg4p/GHSA-p557-g28f-mg4p.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p557-g28f-mg4p", + "modified": "2025-03-13T12:30:32Z", + "published": "2025-03-13T12:30:32Z", + "aliases": [ + "CVE-2025-2275" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2275" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-13T11:15:36Z" + } +} \ No newline at end of file