From 38f5b57e81c04408de08cfe29b538d18f2f886ca Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Sat, 5 Apr 2025 00:31:51 +0000 Subject: [PATCH] Publish Advisories GHSA-mgcv-6r68-pw73 GHSA-r2j9-gh64-cp47 GHSA-79wf-qgrg-2p6c GHSA-ph84-rcj2-fxxm GHSA-3frg-24qp-xxv2 GHSA-73x9-xqqp-w963 GHSA-gqj6-fppc-vr34 GHSA-rp6w-32qw-r275 --- .../GHSA-mgcv-6r68-pw73.json | 5 ++- .../GHSA-r2j9-gh64-cp47.json | 7 +++- .../GHSA-79wf-qgrg-2p6c.json | 6 ++- .../GHSA-ph84-rcj2-fxxm.json | 6 ++- .../GHSA-3frg-24qp-xxv2.json | 6 ++- .../GHSA-73x9-xqqp-w963.json | 9 ++++- .../GHSA-gqj6-fppc-vr34.json | 6 ++- .../GHSA-rp6w-32qw-r275.json | 40 +++++++++++++++++++ 8 files changed, 76 insertions(+), 9 deletions(-) create mode 100644 advisories/unreviewed/2025/04/GHSA-rp6w-32qw-r275/GHSA-rp6w-32qw-r275.json diff --git a/advisories/unreviewed/2024/06/GHSA-mgcv-6r68-pw73/GHSA-mgcv-6r68-pw73.json b/advisories/unreviewed/2024/06/GHSA-mgcv-6r68-pw73/GHSA-mgcv-6r68-pw73.json index 3d4e6639fac..643fb261af8 100644 --- a/advisories/unreviewed/2024/06/GHSA-mgcv-6r68-pw73/GHSA-mgcv-6r68-pw73.json +++ b/advisories/unreviewed/2024/06/GHSA-mgcv-6r68-pw73/GHSA-mgcv-6r68-pw73.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mgcv-6r68-pw73", - "modified": "2024-06-25T21:31:16Z", + "modified": "2025-04-05T00:30:25Z", "published": "2024-06-25T21:31:16Z", "aliases": [ "CVE-2024-5276" @@ -34,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-89" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/07/GHSA-r2j9-gh64-cp47/GHSA-r2j9-gh64-cp47.json b/advisories/unreviewed/2024/07/GHSA-r2j9-gh64-cp47/GHSA-r2j9-gh64-cp47.json index 010c1b5805f..2efa746008f 100644 --- a/advisories/unreviewed/2024/07/GHSA-r2j9-gh64-cp47/GHSA-r2j9-gh64-cp47.json +++ b/advisories/unreviewed/2024/07/GHSA-r2j9-gh64-cp47/GHSA-r2j9-gh64-cp47.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r2j9-gh64-cp47", - "modified": "2024-07-20T09:30:36Z", + "modified": "2025-04-05T00:30:26Z", "published": "2024-07-20T09:30:36Z", "aliases": [ "CVE-2024-6497" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6497" }, + { + "type": "WEB", + "url": "https://nowotarski.info/wordpress-nonce-authorization" + }, { "type": "WEB", "url": "https://plugins.trac.wordpress.org/browser/squirrly-seo/trunk/controllers/Api.php#L267" @@ -38,6 +42,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-79", "CWE-89" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/10/GHSA-79wf-qgrg-2p6c/GHSA-79wf-qgrg-2p6c.json b/advisories/unreviewed/2024/10/GHSA-79wf-qgrg-2p6c/GHSA-79wf-qgrg-2p6c.json index 6d506011aca..85f4bab2eb1 100644 --- a/advisories/unreviewed/2024/10/GHSA-79wf-qgrg-2p6c/GHSA-79wf-qgrg-2p6c.json +++ b/advisories/unreviewed/2024/10/GHSA-79wf-qgrg-2p6c/GHSA-79wf-qgrg-2p6c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-79wf-qgrg-2p6c", - "modified": "2024-10-30T21:30:38Z", + "modified": "2025-04-05T00:30:26Z", "published": "2024-10-27T06:30:47Z", "aliases": [ "CVE-2024-50602" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://github.com/libexpat/libexpat/pull/915" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250404-0008" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/12/GHSA-ph84-rcj2-fxxm/GHSA-ph84-rcj2-fxxm.json b/advisories/unreviewed/2024/12/GHSA-ph84-rcj2-fxxm/GHSA-ph84-rcj2-fxxm.json index 890fca5d609..04c591b675e 100644 --- a/advisories/unreviewed/2024/12/GHSA-ph84-rcj2-fxxm/GHSA-ph84-rcj2-fxxm.json +++ b/advisories/unreviewed/2024/12/GHSA-ph84-rcj2-fxxm/GHSA-ph84-rcj2-fxxm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ph84-rcj2-fxxm", - "modified": "2025-01-31T21:32:44Z", + "modified": "2025-04-05T00:30:26Z", "published": "2024-12-06T18:30:45Z", "aliases": [ "CVE-2024-12254" @@ -47,6 +47,10 @@ "type": "WEB", "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/H4O3UBAOAQQXGT4RE3E4XQYR5XLROORB" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250404-0010" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2024/12/06/1" diff --git a/advisories/unreviewed/2025/02/GHSA-3frg-24qp-xxv2/GHSA-3frg-24qp-xxv2.json b/advisories/unreviewed/2025/02/GHSA-3frg-24qp-xxv2/GHSA-3frg-24qp-xxv2.json index 476e3c33a54..361c2c8e663 100644 --- a/advisories/unreviewed/2025/02/GHSA-3frg-24qp-xxv2/GHSA-3frg-24qp-xxv2.json +++ b/advisories/unreviewed/2025/02/GHSA-3frg-24qp-xxv2/GHSA-3frg-24qp-xxv2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3frg-24qp-xxv2", - "modified": "2025-02-10T21:31:39Z", + "modified": "2025-04-05T00:30:27Z", "published": "2025-02-10T21:31:39Z", "aliases": [ "CVE-2025-1153" @@ -23,6 +23,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1153" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250404-0005" + }, { "type": "WEB", "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=32603" diff --git a/advisories/unreviewed/2025/02/GHSA-73x9-xqqp-w963/GHSA-73x9-xqqp-w963.json b/advisories/unreviewed/2025/02/GHSA-73x9-xqqp-w963/GHSA-73x9-xqqp-w963.json index d6262df84e6..7325a960e08 100644 --- a/advisories/unreviewed/2025/02/GHSA-73x9-xqqp-w963/GHSA-73x9-xqqp-w963.json +++ b/advisories/unreviewed/2025/02/GHSA-73x9-xqqp-w963/GHSA-73x9-xqqp-w963.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-73x9-xqqp-w963", - "modified": "2025-02-10T15:32:22Z", + "modified": "2025-04-05T00:30:26Z", "published": "2025-02-10T15:32:22Z", "aliases": [ "CVE-2025-1147" @@ -23,6 +23,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1147" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250404-0003" + }, { "type": "WEB", "url": "https://sourceware.org/bugzilla/attachment.cgi?id=15881" @@ -50,7 +54,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "LOW", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/02/GHSA-gqj6-fppc-vr34/GHSA-gqj6-fppc-vr34.json b/advisories/unreviewed/2025/02/GHSA-gqj6-fppc-vr34/GHSA-gqj6-fppc-vr34.json index 99425c874b6..5940236394a 100644 --- a/advisories/unreviewed/2025/02/GHSA-gqj6-fppc-vr34/GHSA-gqj6-fppc-vr34.json +++ b/advisories/unreviewed/2025/02/GHSA-gqj6-fppc-vr34/GHSA-gqj6-fppc-vr34.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gqj6-fppc-vr34", - "modified": "2025-02-10T15:32:22Z", + "modified": "2025-04-05T00:30:27Z", "published": "2025-02-10T15:32:22Z", "aliases": [ "CVE-2025-1148" @@ -23,6 +23,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1148" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250404-0004" + }, { "type": "WEB", "url": "https://sourceware.org/bugzilla/attachment.cgi?id=15887" diff --git a/advisories/unreviewed/2025/04/GHSA-rp6w-32qw-r275/GHSA-rp6w-32qw-r275.json b/advisories/unreviewed/2025/04/GHSA-rp6w-32qw-r275/GHSA-rp6w-32qw-r275.json new file mode 100644 index 00000000000..1af0e35ac9c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rp6w-32qw-r275/GHSA-rp6w-32qw-r275.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rp6w-32qw-r275", + "modified": "2025-04-05T00:30:27Z", + "published": "2025-04-05T00:30:27Z", + "aliases": [ + "CVE-2025-2889" + ], + "details": "The Link Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Link Additional Parameters in all versions up to, and including, 7.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2889" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/link-library/tags/7.7.3/link-library-admin.php#L7610" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/0881efbe-9b47-4b56-be2d-12258460b429?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-05T00:15:15Z" + } +} \ No newline at end of file