Advisory Database Sync

This commit is contained in:
advisory-database[bot]
2025-04-07 18:32:23 +00:00
parent 38aeea5e53
commit 3cdb5e1b3f
44 changed files with 917 additions and 28 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2v87-869h-xp3x",
"modified": "2023-01-26T18:30:48Z",
"modified": "2025-04-07T18:30:33Z",
"published": "2023-01-13T06:30:24Z",
"aliases": [
"CVE-2023-23566"
@@ -37,7 +37,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-276"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3886-rc87-ccgx",
"modified": "2023-01-24T21:30:29Z",
"modified": "2025-04-07T18:30:36Z",
"published": "2023-01-17T18:30:43Z",
"aliases": [
"CVE-2022-41861"
@@ -45,7 +45,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-200"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5r4m-496r-7wqm",
"modified": "2023-01-23T21:30:26Z",
"modified": "2025-04-07T18:30:34Z",
"published": "2023-01-17T18:30:43Z",
"aliases": [
"CVE-2022-41858"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cfm7-f9p7-7m2w",
"modified": "2023-01-24T21:30:29Z",
"modified": "2025-04-07T18:30:35Z",
"published": "2023-01-17T18:30:43Z",
"aliases": [
"CVE-2022-41860"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cmvm-c7qf-pmc5",
"modified": "2023-01-24T21:30:29Z",
"modified": "2025-04-07T18:30:35Z",
"published": "2023-01-17T18:30:43Z",
"aliases": [
"CVE-2022-41859"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gqq3-j944-f364",
"modified": "2023-01-24T18:30:32Z",
"modified": "2025-04-07T18:30:33Z",
"published": "2023-01-15T06:30:21Z",
"aliases": [
"CVE-2023-23590"
@@ -23,13 +23,19 @@
"type": "WEB",
"url": "https://b2bconnect.mercedes-benz.com/gb/workshop-solutions/diagnosis/retail-data-storage"
},
{
"type": "WEB",
"url": "https://medium.com/%40windsormoreira/xentry-retail-data-storage-v7-8-1-denial-of-service-cve-2023-23590-60b65f5fa358"
},
{
"type": "WEB",
"url": "https://medium.com/@windsormoreira/xentry-retail-data-storage-v7-8-1-denial-of-service-cve-2023-23590-60b65f5fa358"
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-400"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -25,7 +25,9 @@
}
],
"database_specific": {
"cwe_ids": [],
"cwe_ids": [
"CWE-306"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wfxf-3935-5jgv",
"modified": "2025-03-28T15:31:56Z",
"modified": "2025-04-07T18:30:40Z",
"published": "2025-03-28T15:31:56Z",
"aliases": [
"CVE-2025-2877"
@@ -19,6 +19,14 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2877"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:3636"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2025:3637"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2025-2877"
@@ -50,7 +50,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-119"
"CWE-119",
"CWE-787"
],
"severity": "HIGH",
"github_reviewed": false,
@@ -0,0 +1,52 @@
{
"schema_version": "1.4.0",
"id": "GHSA-342r-jhx2-whjj",
"modified": "2025-04-07T18:30:48Z",
"published": "2025-04-07T18:30:48Z",
"aliases": [
"CVE-2025-3377"
],
"details": "A vulnerability was found in PCMan FTP Server 2.0.7. It has been rated as critical. This issue affects some unknown processing of the component ENC Command Handler. The manipulation leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3377"
},
{
"type": "WEB",
"url": "https://fitoxs.com/exploit/exploit-c72a40d2a3b5d9dc02aef891ea1788bc.txt"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.303623"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.303623"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.552339"
}
],
"database_specific": {
"cwe_ids": [
"CWE-119"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-07T18:15:45Z"
}
}
@@ -0,0 +1,33 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3pxq-xg4j-rgqx",
"modified": "2025-04-07T18:30:48Z",
"published": "2025-04-07T18:30:48Z",
"aliases": [
"CVE-2025-28413"
],
"details": "An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the SysDictTypeController component",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28413"
},
{
"type": "WEB",
"url": "https://github.com/20210607/cve_public/blob/main/ruoyi_case/CVE-2025-28413.md"
},
{
"type": "WEB",
"url": "https://github.com/yangzongzhuan/RuoYi"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-07T16:15:25Z"
}
}
@@ -0,0 +1,52 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4cm6-mqjg-249c",
"modified": "2025-04-07T18:30:48Z",
"published": "2025-04-07T18:30:48Z",
"aliases": [
"CVE-2025-3378"
],
"details": "A vulnerability classified as critical has been found in PCMan FTP Server 2.0.7. Affected is an unknown function of the component EPRT Command Handler. The manipulation leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3378"
},
{
"type": "WEB",
"url": "https://fitoxs.com/exploit/exploit-0f5ecb9a57beef4e5b35111c1beccdcf.txt"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.303624"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.303624"
},
{
"type": "WEB",
"url": "https://vuldb.com/?submit.552340"
}
],
"database_specific": {
"cwe_ids": [
"CWE-119"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-07T18:15:45Z"
}
}
@@ -42,7 +42,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-284"
"CWE-284",
"CWE-434"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5gwv-2q72-gxrm",
"modified": "2025-04-03T04:41:18Z",
"modified": "2025-04-07T18:30:41Z",
"published": "2025-04-02T21:30:51Z",
"aliases": [
"CVE-2025-2704"
],
"details": "OpenVPN version 2.6.1 through 2.6.13 in server mode using TLS-crypt-v2 allows remote attackers to trigger a denial of service by corrupting and replaying network packets in the early handshake phase",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [],
"references": [
{
@@ -27,7 +32,7 @@
"cwe_ids": [
"CWE-754"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-02T21:15:32Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5r62-mjf5-xwhj",
"modified": "2025-04-07T09:30:23Z",
"modified": "2025-04-07T18:30:46Z",
"published": "2025-04-07T09:30:23Z",
"aliases": [
"CVE-2025-30473"
],
"details": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Airflow Common SQL Provider.\n\nWhen using the partition clause in SQLTableCheckOperator as parameter (which was a recommended pattern), Authenticated UI User could inject arbitrary SQL command when triggering DAG exposing partition_clause to the user.\nThis allowed the DAG Triggering user to escalate privileges to execute those arbitrary commands which they normally would not have.\n\n\nThis issue affects Apache Airflow Common SQL Provider: before 1.24.1.\n\nUsers are recommended to upgrade to version 1.24.1, which fixes the issue.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -43,7 +48,7 @@
"cwe_ids": [
"CWE-89"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-07T09:15:16Z"
@@ -46,7 +46,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-74"
"CWE-74",
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -42,7 +42,8 @@
],
"database_specific": {
"cwe_ids": [
"CWE-74"
"CWE-74",
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
@@ -0,0 +1,33 @@
{
"schema_version": "1.4.0",
"id": "GHSA-796g-c5p5-hfrr",
"modified": "2025-04-07T18:30:48Z",
"published": "2025-04-07T18:30:48Z",
"aliases": [
"CVE-2025-28410"
],
"details": "An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the cancelAuthUserAll method does not properly validate whether the requesting user has administrative privileges",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28410"
},
{
"type": "WEB",
"url": "https://github.com/20210607/cve_public/blob/main/ruoyi_case/CVE-2025-28409.md"
},
{
"type": "WEB",
"url": "https://github.com/yangzongzhuan/RuoYi"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-07T16:15:25Z"
}
}
@@ -0,0 +1,33 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7frx-2jch-mmcm",
"modified": "2025-04-07T18:30:47Z",
"published": "2025-04-07T18:30:47Z",
"aliases": [
"CVE-2025-28409"
],
"details": "An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the add method of the /add/{parentId} endpoint does not properly validate whether the requesting user has permission to add a menu item under the specified parentId",
"severity": [],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28409"
},
{
"type": "WEB",
"url": "https://github.com/20210607/cve_public/blob/main/ruoyi_case/CVE-2025-28408.md"
},
{
"type": "WEB",
"url": "https://github.com/yangzongzhuan/RuoYi"
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-07T16:15:25Z"
}
}

Some files were not shown because too many files have changed in this diff Show More