diff --git a/advisories/github-reviewed/2025/03/GHSA-4v65-xqcj-wpgg/GHSA-4v65-xqcj-wpgg.json b/advisories/github-reviewed/2025/03/GHSA-4v65-xqcj-wpgg/GHSA-4v65-xqcj-wpgg.json new file mode 100644 index 00000000000..0cdf9e23f21 --- /dev/null +++ b/advisories/github-reviewed/2025/03/GHSA-4v65-xqcj-wpgg/GHSA-4v65-xqcj-wpgg.json @@ -0,0 +1,121 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4v65-xqcj-wpgg", + "modified": "2025-03-21T21:25:18Z", + "published": "2025-03-21T09:30:34Z", + "aliases": [ + "CVE-2025-25274" + ], + "summary": "Mattermost Fails to Restrict Command Execution in Archived Channels", + "details": "Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to restrict command execution in archived channels, which allows authenticated users to run commands in archived channels.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Go", + "name": "github.com/mattermost/mattermost/server/v8" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "10.4.0" + }, + { + "fixed": "10.4.3" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Go", + "name": "github.com/mattermost/mattermost/server/v8" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "10.3.0" + }, + { + "fixed": "10.3.4" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Go", + "name": "github.com/mattermost/mattermost/server/v8" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "9.11.0" + }, + { + "fixed": "9.11.9" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Go", + "name": "github.com/mattermost/mattermost/server/v8" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "10.5.0" + }, + { + "fixed": "10.5.1" + } + ] + } + ], + "versions": [ + "10.5.0" + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25274" + }, + { + "type": "PACKAGE", + "url": "https://github.com/mattermost/mattermost" + }, + { + "type": "WEB", + "url": "https://mattermost.com/security-updates" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2025-03-21T21:25:18Z", + "nvd_published_at": "2025-03-21T09:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5v9m-57mq-qc75/GHSA-5v9m-57mq-qc75.json b/advisories/github-reviewed/2025/03/GHSA-5v9m-57mq-qc75/GHSA-5v9m-57mq-qc75.json similarity index 54% rename from advisories/unreviewed/2025/03/GHSA-5v9m-57mq-qc75/GHSA-5v9m-57mq-qc75.json rename to advisories/github-reviewed/2025/03/GHSA-5v9m-57mq-qc75/GHSA-5v9m-57mq-qc75.json index 850f8e30201..3edd92cf32c 100644 --- a/advisories/unreviewed/2025/03/GHSA-5v9m-57mq-qc75/GHSA-5v9m-57mq-qc75.json +++ b/advisories/github-reviewed/2025/03/GHSA-5v9m-57mq-qc75/GHSA-5v9m-57mq-qc75.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-5v9m-57mq-qc75", - "modified": "2025-03-20T12:32:47Z", + "modified": "2025-03-21T21:23:47Z", "published": "2025-03-20T12:32:47Z", "aliases": [ "CVE-2024-7983" ], + "summary": "Open WebUI denial of service through endpoint for converting markdown", "details": "In version 0.3.8 of open-webui, an endpoint for converting markdown to HTML is exposed without authentication. A maliciously crafted markdown payload can cause the server to spend excessive time converting it, leading to a denial of service. The server becomes unresponsive to other requests until the conversion is complete.", "severity": [ { @@ -13,12 +14,40 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [], + "affected": [ + { + "package": { + "ecosystem": "PyPI", + "name": "open-webui" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "0.3.8" + } + ] + } + ] + } + ], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7983" }, + { + "type": "PACKAGE", + "url": "https://github.com/open-webui/open-webui" + }, + { + "type": "WEB", + "url": "https://github.com/open-webui/open-webui/blob/eff736acd2e0bbbdd0eeca4cc209b216a1f23b6a/backend/apps/webui/routers/utils.py#L49" + }, { "type": "WEB", "url": "https://huntr.com/bounties/f8156ca5-1328-480f-a72b-8d3dfdad87dc" @@ -29,8 +58,8 @@ "CWE-400" ], "severity": "HIGH", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2025-03-21T21:23:47Z", "nvd_published_at": "2025-03-20T10:15:38Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6w7p-xrvp-p7xv/GHSA-6w7p-xrvp-p7xv.json b/advisories/github-reviewed/2025/03/GHSA-6w7p-xrvp-p7xv/GHSA-6w7p-xrvp-p7xv.json similarity index 58% rename from advisories/unreviewed/2025/03/GHSA-6w7p-xrvp-p7xv/GHSA-6w7p-xrvp-p7xv.json rename to advisories/github-reviewed/2025/03/GHSA-6w7p-xrvp-p7xv/GHSA-6w7p-xrvp-p7xv.json index 65bc80c424b..a0c3c882277 100644 --- a/advisories/unreviewed/2025/03/GHSA-6w7p-xrvp-p7xv/GHSA-6w7p-xrvp-p7xv.json +++ b/advisories/github-reviewed/2025/03/GHSA-6w7p-xrvp-p7xv/GHSA-6w7p-xrvp-p7xv.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-6w7p-xrvp-p7xv", - "modified": "2025-03-20T12:32:47Z", + "modified": "2025-03-21T21:24:34Z", "published": "2025-03-20T12:32:47Z", "aliases": [ "CVE-2024-8061" ], + "summary": "Aim allows denial of service due to no timeouts for some tracking server endpoints", "details": "In version 3.23.0 of aimhubio/aim, certain methods that request data from external servers do not have set timeouts, causing the server to wait indefinitely for a response. This can lead to a denial of service, as the tracking server does not respond to other requests while waiting. The issue arises in the client used by the `aim` tracking server to communicate with external resources, specifically in the `_run_read_instructions` method and similar calls without timeouts.", "severity": [ { @@ -13,12 +14,40 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" } ], - "affected": [], + "affected": [ + { + "package": { + "ecosystem": "PyPI", + "name": "aim" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "3.23.0" + } + ] + } + ] + } + ], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8061" }, + { + "type": "PACKAGE", + "url": "https://github.com/aimhubio/aim" + }, + { + "type": "WEB", + "url": "https://github.com/aimhubio/aim/blob/a6c6f2fee0f1abe37c1d66701b0329fb6af31a3d/aim/ext/transport/client.py#L258" + }, { "type": "WEB", "url": "https://huntr.com/bounties/c85d005c-b354-4c51-a88f-adda2f09622b" @@ -29,8 +58,8 @@ "CWE-400" ], "severity": "HIGH", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2025-03-21T21:24:33Z", "nvd_published_at": "2025-03-20T10:15:40Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9vf8-xgwm-97r8/GHSA-9vf8-xgwm-97r8.json b/advisories/github-reviewed/2025/03/GHSA-9vf8-xgwm-97r8/GHSA-9vf8-xgwm-97r8.json similarity index 61% rename from advisories/unreviewed/2025/03/GHSA-9vf8-xgwm-97r8/GHSA-9vf8-xgwm-97r8.json rename to advisories/github-reviewed/2025/03/GHSA-9vf8-xgwm-97r8/GHSA-9vf8-xgwm-97r8.json index 3467461dd38..cf839f3eb57 100644 --- a/advisories/unreviewed/2025/03/GHSA-9vf8-xgwm-97r8/GHSA-9vf8-xgwm-97r8.json +++ b/advisories/github-reviewed/2025/03/GHSA-9vf8-xgwm-97r8/GHSA-9vf8-xgwm-97r8.json @@ -1,24 +1,49 @@ { "schema_version": "1.4.0", "id": "GHSA-9vf8-xgwm-97r8", - "modified": "2025-03-20T12:32:47Z", + "modified": "2025-03-21T21:23:57Z", "published": "2025-03-20T12:32:47Z", "aliases": [ "CVE-2024-8053" ], + "summary": "Open WebUI lacks authentication for the `api/v1/utils/pdf` endpoint", "details": "In version v0.3.10 of open-webui/open-webui, the `api/v1/utils/pdf` endpoint lacks authentication mechanisms, allowing unauthenticated attackers to access the PDF generation service. This vulnerability can be exploited by sending a POST request with an excessively large payload, potentially leading to server resource exhaustion and denial of service (DoS). Additionally, unauthorized users can misuse the endpoint to generate PDFs without verification, resulting in service misuse and potential operational and financial impacts.", "severity": [ { "type": "CVSS_V3", - "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [ + { + "package": { + "ecosystem": "PyPI", + "name": "open-webui" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "0.3.10" + } + ] + } + ] } ], - "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8053" }, + { + "type": "PACKAGE", + "url": "https://github.com/open-webui/open-webui" + }, { "type": "WEB", "url": "https://huntr.com/bounties/ebe8c1fa-113b-4df9-be03-a406b9adb9f4" @@ -29,8 +54,8 @@ "CWE-287" ], "severity": "HIGH", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2025-03-21T21:23:57Z", "nvd_published_at": "2025-03-20T10:15:39Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-ff5c-56m7-vc75/GHSA-ff5c-56m7-vc75.json b/advisories/github-reviewed/2025/03/GHSA-ff5c-56m7-vc75/GHSA-ff5c-56m7-vc75.json similarity index 57% rename from advisories/unreviewed/2025/03/GHSA-ff5c-56m7-vc75/GHSA-ff5c-56m7-vc75.json rename to advisories/github-reviewed/2025/03/GHSA-ff5c-56m7-vc75/GHSA-ff5c-56m7-vc75.json index f7f711d0ae1..5c068412c95 100644 --- a/advisories/unreviewed/2025/03/GHSA-ff5c-56m7-vc75/GHSA-ff5c-56m7-vc75.json +++ b/advisories/github-reviewed/2025/03/GHSA-ff5c-56m7-vc75/GHSA-ff5c-56m7-vc75.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-ff5c-56m7-vc75", - "modified": "2025-03-20T12:32:47Z", + "modified": "2025-03-21T21:24:09Z", "published": "2025-03-20T12:32:47Z", "aliases": [ "CVE-2024-8060" ], + "summary": "Open WebUI allows Remote Code Execution via Arbitrary File Upload to /audio/api/v1/transcriptions", "details": "OpenWebUI version 0.3.0 contains a vulnerability in the audio API endpoint `/audio/api/v1/transcriptions` that allows for arbitrary file upload. The application performs insufficient validation on the `file.content_type` and allows user-controlled filenames, leading to a path traversal vulnerability. This can be exploited by an authenticated user to overwrite critical files within the Docker container, potentially leading to remote code execution as the root user.", "severity": [ { @@ -13,12 +14,40 @@ "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" } ], - "affected": [], + "affected": [ + { + "package": { + "ecosystem": "PyPI", + "name": "open-webui" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.5.17" + } + ] + } + ] + } + ], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-8060" }, + { + "type": "WEB", + "url": "https://github.com/open-webui/open-webui/commit/613a087387c094e71ee91d29c015195ef401e160" + }, + { + "type": "PACKAGE", + "url": "https://github.com/open-webui/open-webui" + }, { "type": "WEB", "url": "https://huntr.com/bounties/a3b1a4b7-c723-496d-842c-844cc0988fe9" @@ -29,8 +58,8 @@ "CWE-434" ], "severity": "HIGH", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2025-03-21T21:24:09Z", "nvd_published_at": "2025-03-20T10:15:40Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-4v65-xqcj-wpgg/GHSA-4v65-xqcj-wpgg.json b/advisories/unreviewed/2025/03/GHSA-4v65-xqcj-wpgg/GHSA-4v65-xqcj-wpgg.json deleted file mode 100644 index d63277574f1..00000000000 --- a/advisories/unreviewed/2025/03/GHSA-4v65-xqcj-wpgg/GHSA-4v65-xqcj-wpgg.json +++ /dev/null @@ -1,36 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-4v65-xqcj-wpgg", - "modified": "2025-03-21T09:30:34Z", - "published": "2025-03-21T09:30:34Z", - "aliases": [ - "CVE-2025-25274" - ], - "details": "Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to restrict command execution in archived channels, which allows authenticated users to run commands in archived channels.", - "severity": [ - { - "type": "CVSS_V3", - "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" - } - ], - "affected": [], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25274" - }, - { - "type": "WEB", - "url": "https://mattermost.com/security-updates" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-863" - ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2025-03-21T09:15:12Z" - } -} \ No newline at end of file