From 452ac20293f6c5aa8c8654b034492b8c71405bc3 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 5 May 2025 15:31:50 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-3fq7-mmjq-fv4x.json | 2 +- .../GHSA-3r97-xp9v-83jf.json | 2 +- .../GHSA-4cm4-r3q9-95wh.json | 2 +- .../GHSA-5587-9qwv-rggc.json | 2 +- .../GHSA-6jrf-5qcg-qcqx.json | 2 +- .../GHSA-75xq-8h5m-hrpv.json | 1 + .../GHSA-8v8c-wrxg-38v2.json | 2 +- .../GHSA-942w-mcgr-2rjq.json | 2 +- .../GHSA-c524-q7r6-h3vj.json | 2 +- .../GHSA-cq68-4f8j-mf92.json | 4 +- .../GHSA-crwf-v7hm-2cqq.json | 2 +- .../GHSA-q4jp-rmff-g56p.json | 1 + .../GHSA-v9q2-jxcm-rm4c.json | 6 ++- .../GHSA-xhh6-6v9x-7wmr.json | 2 +- .../GHSA-27mv-5vpc-8g53.json | 6 ++- .../GHSA-7xfv-pf6f-p6v2.json | 6 ++- .../GHSA-qrgg-mgwx-hq8f.json | 6 ++- .../GHSA-vc5p-9c2v-8jwq.json | 6 ++- .../GHSA-xjvv-5w4r-hfmv.json | 6 ++- .../GHSA-6hjf-ffg5-v8w7.json | 2 +- .../GHSA-99gh-cvp7-vwp4.json | 4 +- .../GHSA-2h76-94rj-gp24.json | 3 +- .../GHSA-5frm-v73v-96vh.json | 3 +- .../GHSA-7jq5-8rmw-j9wh.json | 4 +- .../GHSA-9jrh-9382-49v4.json | 3 +- .../GHSA-f7hj-r8jj-3mf6.json | 3 +- .../GHSA-vq74-x79m-9v7c.json | 3 +- .../GHSA-wggv-mp5h-4gv5.json | 3 +- .../GHSA-gqcv-v7gm-vw94.json | 4 +- .../GHSA-h7mx-548v-cr9r.json | 10 ++++- .../GHSA-wqxv-v2vg-q37x.json | 6 ++- .../GHSA-28h8-49pj-mw67.json | 33 +++++++++++++++ .../GHSA-4grv-gh63-6248.json | 11 +++-- .../GHSA-5qcr-g689-6g4f.json | 31 ++++++++++++++ .../GHSA-89vf-65xc-w22w.json | 25 ++++++++++++ .../GHSA-8r3j-hpqx-m8fj.json | 6 ++- .../GHSA-c2mm-9c32-xc37.json | 40 +++++++++++++++++++ .../GHSA-c44x-92pj-2rvh.json | 33 +++++++++++++++ .../GHSA-hv6f-p3fq-464p.json | 33 +++++++++++++++ .../GHSA-mqrj-rhjj-jp5m.json | 33 +++++++++++++++ .../GHSA-x9rr-xwxc-jcjf.json | 33 +++++++++++++++ 41 files changed, 354 insertions(+), 34 deletions(-) create mode 100644 advisories/unreviewed/2025/05/GHSA-28h8-49pj-mw67/GHSA-28h8-49pj-mw67.json create mode 100644 advisories/unreviewed/2025/05/GHSA-5qcr-g689-6g4f/GHSA-5qcr-g689-6g4f.json create mode 100644 advisories/unreviewed/2025/05/GHSA-89vf-65xc-w22w/GHSA-89vf-65xc-w22w.json create mode 100644 advisories/unreviewed/2025/05/GHSA-c2mm-9c32-xc37/GHSA-c2mm-9c32-xc37.json create mode 100644 advisories/unreviewed/2025/05/GHSA-c44x-92pj-2rvh/GHSA-c44x-92pj-2rvh.json create mode 100644 advisories/unreviewed/2025/05/GHSA-hv6f-p3fq-464p/GHSA-hv6f-p3fq-464p.json create mode 100644 advisories/unreviewed/2025/05/GHSA-mqrj-rhjj-jp5m/GHSA-mqrj-rhjj-jp5m.json create mode 100644 advisories/unreviewed/2025/05/GHSA-x9rr-xwxc-jcjf/GHSA-x9rr-xwxc-jcjf.json diff --git a/advisories/unreviewed/2022/11/GHSA-3fq7-mmjq-fv4x/GHSA-3fq7-mmjq-fv4x.json b/advisories/unreviewed/2022/11/GHSA-3fq7-mmjq-fv4x/GHSA-3fq7-mmjq-fv4x.json index 210a823c2f3..e1c6eff5095 100644 --- a/advisories/unreviewed/2022/11/GHSA-3fq7-mmjq-fv4x/GHSA-3fq7-mmjq-fv4x.json +++ b/advisories/unreviewed/2022/11/GHSA-3fq7-mmjq-fv4x/GHSA-3fq7-mmjq-fv4x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3fq7-mmjq-fv4x", - "modified": "2022-11-04T19:01:16Z", + "modified": "2025-05-05T15:30:39Z", "published": "2022-11-03T19:00:23Z", "aliases": [ "CVE-2022-42751" diff --git a/advisories/unreviewed/2022/11/GHSA-3r97-xp9v-83jf/GHSA-3r97-xp9v-83jf.json b/advisories/unreviewed/2022/11/GHSA-3r97-xp9v-83jf/GHSA-3r97-xp9v-83jf.json index 9f39c516980..b491e6578d0 100644 --- a/advisories/unreviewed/2022/11/GHSA-3r97-xp9v-83jf/GHSA-3r97-xp9v-83jf.json +++ b/advisories/unreviewed/2022/11/GHSA-3r97-xp9v-83jf/GHSA-3r97-xp9v-83jf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3r97-xp9v-83jf", - "modified": "2022-11-03T12:00:27Z", + "modified": "2025-05-05T15:30:38Z", "published": "2022-11-02T19:00:31Z", "aliases": [ "CVE-2022-43995" diff --git a/advisories/unreviewed/2022/11/GHSA-4cm4-r3q9-95wh/GHSA-4cm4-r3q9-95wh.json b/advisories/unreviewed/2022/11/GHSA-4cm4-r3q9-95wh/GHSA-4cm4-r3q9-95wh.json index 969e68ed9a9..f4c3878ca2c 100644 --- a/advisories/unreviewed/2022/11/GHSA-4cm4-r3q9-95wh/GHSA-4cm4-r3q9-95wh.json +++ b/advisories/unreviewed/2022/11/GHSA-4cm4-r3q9-95wh/GHSA-4cm4-r3q9-95wh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4cm4-r3q9-95wh", - "modified": "2022-11-05T12:00:22Z", + "modified": "2025-05-05T15:30:39Z", "published": "2022-11-03T19:00:23Z", "aliases": [ "CVE-2022-42753" diff --git a/advisories/unreviewed/2022/11/GHSA-5587-9qwv-rggc/GHSA-5587-9qwv-rggc.json b/advisories/unreviewed/2022/11/GHSA-5587-9qwv-rggc/GHSA-5587-9qwv-rggc.json index 3400763d6cf..1565599a2b1 100644 --- a/advisories/unreviewed/2022/11/GHSA-5587-9qwv-rggc/GHSA-5587-9qwv-rggc.json +++ b/advisories/unreviewed/2022/11/GHSA-5587-9qwv-rggc/GHSA-5587-9qwv-rggc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5587-9qwv-rggc", - "modified": "2022-11-05T12:00:21Z", + "modified": "2025-05-05T15:30:42Z", "published": "2022-11-04T12:00:25Z", "aliases": [ "CVE-2022-42748" diff --git a/advisories/unreviewed/2022/11/GHSA-6jrf-5qcg-qcqx/GHSA-6jrf-5qcg-qcqx.json b/advisories/unreviewed/2022/11/GHSA-6jrf-5qcg-qcqx/GHSA-6jrf-5qcg-qcqx.json index e13748b6b84..ce74710a9dd 100644 --- a/advisories/unreviewed/2022/11/GHSA-6jrf-5qcg-qcqx/GHSA-6jrf-5qcg-qcqx.json +++ b/advisories/unreviewed/2022/11/GHSA-6jrf-5qcg-qcqx/GHSA-6jrf-5qcg-qcqx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6jrf-5qcg-qcqx", - "modified": "2022-11-04T19:01:16Z", + "modified": "2025-05-05T15:30:39Z", "published": "2022-11-03T19:00:23Z", "aliases": [ "CVE-2022-42750" diff --git a/advisories/unreviewed/2022/11/GHSA-75xq-8h5m-hrpv/GHSA-75xq-8h5m-hrpv.json b/advisories/unreviewed/2022/11/GHSA-75xq-8h5m-hrpv/GHSA-75xq-8h5m-hrpv.json index 08a602b54ef..892669c59d0 100644 --- a/advisories/unreviewed/2022/11/GHSA-75xq-8h5m-hrpv/GHSA-75xq-8h5m-hrpv.json +++ b/advisories/unreviewed/2022/11/GHSA-75xq-8h5m-hrpv/GHSA-75xq-8h5m-hrpv.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-284", "CWE-668" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/11/GHSA-8v8c-wrxg-38v2/GHSA-8v8c-wrxg-38v2.json b/advisories/unreviewed/2022/11/GHSA-8v8c-wrxg-38v2/GHSA-8v8c-wrxg-38v2.json index 9b38c2e12cd..1615457daab 100644 --- a/advisories/unreviewed/2022/11/GHSA-8v8c-wrxg-38v2/GHSA-8v8c-wrxg-38v2.json +++ b/advisories/unreviewed/2022/11/GHSA-8v8c-wrxg-38v2/GHSA-8v8c-wrxg-38v2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8v8c-wrxg-38v2", - "modified": "2022-11-05T12:00:20Z", + "modified": "2025-05-05T15:30:42Z", "published": "2022-11-04T12:00:25Z", "aliases": [ "CVE-2022-42749" diff --git a/advisories/unreviewed/2022/11/GHSA-942w-mcgr-2rjq/GHSA-942w-mcgr-2rjq.json b/advisories/unreviewed/2022/11/GHSA-942w-mcgr-2rjq/GHSA-942w-mcgr-2rjq.json index 34d6f8049d5..b88b8eb9171 100644 --- a/advisories/unreviewed/2022/11/GHSA-942w-mcgr-2rjq/GHSA-942w-mcgr-2rjq.json +++ b/advisories/unreviewed/2022/11/GHSA-942w-mcgr-2rjq/GHSA-942w-mcgr-2rjq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-942w-mcgr-2rjq", - "modified": "2022-11-05T12:00:21Z", + "modified": "2025-05-05T15:30:41Z", "published": "2022-11-04T12:00:25Z", "aliases": [ "CVE-2022-42744" diff --git a/advisories/unreviewed/2022/11/GHSA-c524-q7r6-h3vj/GHSA-c524-q7r6-h3vj.json b/advisories/unreviewed/2022/11/GHSA-c524-q7r6-h3vj/GHSA-c524-q7r6-h3vj.json index fced176e06b..9e1e414c027 100644 --- a/advisories/unreviewed/2022/11/GHSA-c524-q7r6-h3vj/GHSA-c524-q7r6-h3vj.json +++ b/advisories/unreviewed/2022/11/GHSA-c524-q7r6-h3vj/GHSA-c524-q7r6-h3vj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c524-q7r6-h3vj", - "modified": "2022-11-04T19:01:15Z", + "modified": "2025-05-05T15:30:39Z", "published": "2022-11-03T19:00:27Z", "aliases": [ "CVE-2022-43109" diff --git a/advisories/unreviewed/2022/11/GHSA-cq68-4f8j-mf92/GHSA-cq68-4f8j-mf92.json b/advisories/unreviewed/2022/11/GHSA-cq68-4f8j-mf92/GHSA-cq68-4f8j-mf92.json index aae2c789d60..b54a4521bdb 100644 --- a/advisories/unreviewed/2022/11/GHSA-cq68-4f8j-mf92/GHSA-cq68-4f8j-mf92.json +++ b/advisories/unreviewed/2022/11/GHSA-cq68-4f8j-mf92/GHSA-cq68-4f8j-mf92.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-crwf-v7hm-2cqq/GHSA-crwf-v7hm-2cqq.json b/advisories/unreviewed/2022/11/GHSA-crwf-v7hm-2cqq/GHSA-crwf-v7hm-2cqq.json index 80ca7170a1b..06a8c04c8f7 100644 --- a/advisories/unreviewed/2022/11/GHSA-crwf-v7hm-2cqq/GHSA-crwf-v7hm-2cqq.json +++ b/advisories/unreviewed/2022/11/GHSA-crwf-v7hm-2cqq/GHSA-crwf-v7hm-2cqq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-crwf-v7hm-2cqq", - "modified": "2022-11-05T12:00:21Z", + "modified": "2025-05-05T15:30:42Z", "published": "2022-11-04T12:00:25Z", "aliases": [ "CVE-2022-42747" diff --git a/advisories/unreviewed/2022/11/GHSA-q4jp-rmff-g56p/GHSA-q4jp-rmff-g56p.json b/advisories/unreviewed/2022/11/GHSA-q4jp-rmff-g56p/GHSA-q4jp-rmff-g56p.json index 9121fc75c36..922eac8cd27 100644 --- a/advisories/unreviewed/2022/11/GHSA-q4jp-rmff-g56p/GHSA-q4jp-rmff-g56p.json +++ b/advisories/unreviewed/2022/11/GHSA-q4jp-rmff-g56p/GHSA-q4jp-rmff-g56p.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-200", "CWE-668" ], "severity": "LOW", diff --git a/advisories/unreviewed/2022/11/GHSA-v9q2-jxcm-rm4c/GHSA-v9q2-jxcm-rm4c.json b/advisories/unreviewed/2022/11/GHSA-v9q2-jxcm-rm4c/GHSA-v9q2-jxcm-rm4c.json index 0c47b84f13c..84e9d716c16 100644 --- a/advisories/unreviewed/2022/11/GHSA-v9q2-jxcm-rm4c/GHSA-v9q2-jxcm-rm4c.json +++ b/advisories/unreviewed/2022/11/GHSA-v9q2-jxcm-rm4c/GHSA-v9q2-jxcm-rm4c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v9q2-jxcm-rm4c", - "modified": "2022-11-04T19:01:15Z", + "modified": "2025-05-05T15:30:38Z", "published": "2022-11-03T12:00:26Z", "aliases": [ "CVE-2021-46853" @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-367" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-xhh6-6v9x-7wmr/GHSA-xhh6-6v9x-7wmr.json b/advisories/unreviewed/2022/11/GHSA-xhh6-6v9x-7wmr/GHSA-xhh6-6v9x-7wmr.json index d7abba1be9d..511bf24aff0 100644 --- a/advisories/unreviewed/2022/11/GHSA-xhh6-6v9x-7wmr/GHSA-xhh6-6v9x-7wmr.json +++ b/advisories/unreviewed/2022/11/GHSA-xhh6-6v9x-7wmr/GHSA-xhh6-6v9x-7wmr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xhh6-6v9x-7wmr", - "modified": "2022-11-05T12:00:21Z", + "modified": "2025-05-05T15:30:41Z", "published": "2022-11-04T12:00:25Z", "aliases": [ "CVE-2022-42746" diff --git a/advisories/unreviewed/2023/08/GHSA-27mv-5vpc-8g53/GHSA-27mv-5vpc-8g53.json b/advisories/unreviewed/2023/08/GHSA-27mv-5vpc-8g53/GHSA-27mv-5vpc-8g53.json index 15941e2583e..99a0bc82196 100644 --- a/advisories/unreviewed/2023/08/GHSA-27mv-5vpc-8g53/GHSA-27mv-5vpc-8g53.json +++ b/advisories/unreviewed/2023/08/GHSA-27mv-5vpc-8g53/GHSA-27mv-5vpc-8g53.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-27mv-5vpc-8g53", - "modified": "2024-04-04T06:32:44Z", + "modified": "2025-05-05T15:30:43Z", "published": "2023-08-04T00:30:15Z", "aliases": [ "CVE-2023-38950" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://claroty.com/team82/disclosure-dashboard/cve-2023-38950" }, + { + "type": "WEB", + "url": "https://sploitus.com/exploit?id=PACKETSTORM:177859" + }, { "type": "WEB", "url": "http://zkteco.com" diff --git a/advisories/unreviewed/2023/08/GHSA-7xfv-pf6f-p6v2/GHSA-7xfv-pf6f-p6v2.json b/advisories/unreviewed/2023/08/GHSA-7xfv-pf6f-p6v2/GHSA-7xfv-pf6f-p6v2.json index 5763018bea9..39f05eb694d 100644 --- a/advisories/unreviewed/2023/08/GHSA-7xfv-pf6f-p6v2/GHSA-7xfv-pf6f-p6v2.json +++ b/advisories/unreviewed/2023/08/GHSA-7xfv-pf6f-p6v2/GHSA-7xfv-pf6f-p6v2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7xfv-pf6f-p6v2", - "modified": "2024-04-04T06:32:47Z", + "modified": "2025-05-05T15:30:44Z", "published": "2023-08-04T00:30:16Z", "aliases": [ "CVE-2023-38952" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://claroty.com/team82/disclosure-dashboard/cve-2023-38952" }, + { + "type": "WEB", + "url": "https://sploitus.com/exploit?id=PACKETSTORM:177859" + }, { "type": "WEB", "url": "http://zkteco.com" diff --git a/advisories/unreviewed/2023/08/GHSA-qrgg-mgwx-hq8f/GHSA-qrgg-mgwx-hq8f.json b/advisories/unreviewed/2023/08/GHSA-qrgg-mgwx-hq8f/GHSA-qrgg-mgwx-hq8f.json index b36a8f667a8..df737ec94bf 100644 --- a/advisories/unreviewed/2023/08/GHSA-qrgg-mgwx-hq8f/GHSA-qrgg-mgwx-hq8f.json +++ b/advisories/unreviewed/2023/08/GHSA-qrgg-mgwx-hq8f/GHSA-qrgg-mgwx-hq8f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qrgg-mgwx-hq8f", - "modified": "2023-11-26T00:30:25Z", + "modified": "2025-05-05T15:30:44Z", "published": "2023-08-22T21:30:25Z", "aliases": [ "CVE-2020-22524" @@ -42,6 +42,10 @@ { "type": "WEB", "url": "https://sourceforge.net/p/freeimage/bugs/319" + }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2023/dsa-5579" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/08/GHSA-vc5p-9c2v-8jwq/GHSA-vc5p-9c2v-8jwq.json b/advisories/unreviewed/2023/08/GHSA-vc5p-9c2v-8jwq/GHSA-vc5p-9c2v-8jwq.json index 7fcc9066dec..60bd06ad135 100644 --- a/advisories/unreviewed/2023/08/GHSA-vc5p-9c2v-8jwq/GHSA-vc5p-9c2v-8jwq.json +++ b/advisories/unreviewed/2023/08/GHSA-vc5p-9c2v-8jwq/GHSA-vc5p-9c2v-8jwq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vc5p-9c2v-8jwq", - "modified": "2024-04-04T06:32:46Z", + "modified": "2025-05-05T15:30:44Z", "published": "2023-08-04T00:30:16Z", "aliases": [ "CVE-2023-38951" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://claroty.com/team82/disclosure-dashboard/cve-2023-38951" }, + { + "type": "WEB", + "url": "https://sploitus.com/exploit?id=PACKETSTORM:177859" + }, { "type": "WEB", "url": "http://zkteco.com" diff --git a/advisories/unreviewed/2023/08/GHSA-xjvv-5w4r-hfmv/GHSA-xjvv-5w4r-hfmv.json b/advisories/unreviewed/2023/08/GHSA-xjvv-5w4r-hfmv/GHSA-xjvv-5w4r-hfmv.json index 2af38a1109a..c8feb825d4c 100644 --- a/advisories/unreviewed/2023/08/GHSA-xjvv-5w4r-hfmv/GHSA-xjvv-5w4r-hfmv.json +++ b/advisories/unreviewed/2023/08/GHSA-xjvv-5w4r-hfmv/GHSA-xjvv-5w4r-hfmv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xjvv-5w4r-hfmv", - "modified": "2023-11-26T00:30:25Z", + "modified": "2025-05-05T15:30:44Z", "published": "2023-08-22T21:30:25Z", "aliases": [ "CVE-2020-21427" @@ -42,6 +42,10 @@ { "type": "WEB", "url": "https://sourceforge.net/p/freeimage/bugs/298" + }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2023/dsa-5579" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/09/GHSA-6hjf-ffg5-v8w7/GHSA-6hjf-ffg5-v8w7.json b/advisories/unreviewed/2023/09/GHSA-6hjf-ffg5-v8w7/GHSA-6hjf-ffg5-v8w7.json index 1770adaa0fa..719e90d0712 100644 --- a/advisories/unreviewed/2023/09/GHSA-6hjf-ffg5-v8w7/GHSA-6hjf-ffg5-v8w7.json +++ b/advisories/unreviewed/2023/09/GHSA-6hjf-ffg5-v8w7/GHSA-6hjf-ffg5-v8w7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6hjf-ffg5-v8w7", - "modified": "2023-11-04T06:34:05Z", + "modified": "2025-05-05T15:30:45Z", "published": "2023-09-20T15:30:49Z", "aliases": [ "CVE-2023-32005" diff --git a/advisories/unreviewed/2024/03/GHSA-99gh-cvp7-vwp4/GHSA-99gh-cvp7-vwp4.json b/advisories/unreviewed/2024/03/GHSA-99gh-cvp7-vwp4/GHSA-99gh-cvp7-vwp4.json index 90a59901bd6..1bdc4c6a8fd 100644 --- a/advisories/unreviewed/2024/03/GHSA-99gh-cvp7-vwp4/GHSA-99gh-cvp7-vwp4.json +++ b/advisories/unreviewed/2024/03/GHSA-99gh-cvp7-vwp4/GHSA-99gh-cvp7-vwp4.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-89" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-2h76-94rj-gp24/GHSA-2h76-94rj-gp24.json b/advisories/unreviewed/2025/01/GHSA-2h76-94rj-gp24/GHSA-2h76-94rj-gp24.json index 74909000b3f..1804c622673 100644 --- a/advisories/unreviewed/2025/01/GHSA-2h76-94rj-gp24/GHSA-2h76-94rj-gp24.json +++ b/advisories/unreviewed/2025/01/GHSA-2h76-94rj-gp24/GHSA-2h76-94rj-gp24.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-5frm-v73v-96vh/GHSA-5frm-v73v-96vh.json b/advisories/unreviewed/2025/01/GHSA-5frm-v73v-96vh/GHSA-5frm-v73v-96vh.json index b7d74a66484..05545d50205 100644 --- a/advisories/unreviewed/2025/01/GHSA-5frm-v73v-96vh/GHSA-5frm-v73v-96vh.json +++ b/advisories/unreviewed/2025/01/GHSA-5frm-v73v-96vh/GHSA-5frm-v73v-96vh.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-7jq5-8rmw-j9wh/GHSA-7jq5-8rmw-j9wh.json b/advisories/unreviewed/2025/01/GHSA-7jq5-8rmw-j9wh/GHSA-7jq5-8rmw-j9wh.json index 595a40ac9a1..20f3fb4779b 100644 --- a/advisories/unreviewed/2025/01/GHSA-7jq5-8rmw-j9wh/GHSA-7jq5-8rmw-j9wh.json +++ b/advisories/unreviewed/2025/01/GHSA-7jq5-8rmw-j9wh/GHSA-7jq5-8rmw-j9wh.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-89" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-9jrh-9382-49v4/GHSA-9jrh-9382-49v4.json b/advisories/unreviewed/2025/01/GHSA-9jrh-9382-49v4/GHSA-9jrh-9382-49v4.json index 3ef7b96f280..2cd0b92d480 100644 --- a/advisories/unreviewed/2025/01/GHSA-9jrh-9382-49v4/GHSA-9jrh-9382-49v4.json +++ b/advisories/unreviewed/2025/01/GHSA-9jrh-9382-49v4/GHSA-9jrh-9382-49v4.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-f7hj-r8jj-3mf6/GHSA-f7hj-r8jj-3mf6.json b/advisories/unreviewed/2025/01/GHSA-f7hj-r8jj-3mf6/GHSA-f7hj-r8jj-3mf6.json index 51c3b8c365d..9d9ad64a101 100644 --- a/advisories/unreviewed/2025/01/GHSA-f7hj-r8jj-3mf6/GHSA-f7hj-r8jj-3mf6.json +++ b/advisories/unreviewed/2025/01/GHSA-f7hj-r8jj-3mf6/GHSA-f7hj-r8jj-3mf6.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-vq74-x79m-9v7c/GHSA-vq74-x79m-9v7c.json b/advisories/unreviewed/2025/01/GHSA-vq74-x79m-9v7c/GHSA-vq74-x79m-9v7c.json index 644bfec4698..46329bb23b0 100644 --- a/advisories/unreviewed/2025/01/GHSA-vq74-x79m-9v7c/GHSA-vq74-x79m-9v7c.json +++ b/advisories/unreviewed/2025/01/GHSA-vq74-x79m-9v7c/GHSA-vq74-x79m-9v7c.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-wggv-mp5h-4gv5/GHSA-wggv-mp5h-4gv5.json b/advisories/unreviewed/2025/01/GHSA-wggv-mp5h-4gv5/GHSA-wggv-mp5h-4gv5.json index 987392fc108..0425fa31855 100644 --- a/advisories/unreviewed/2025/01/GHSA-wggv-mp5h-4gv5/GHSA-wggv-mp5h-4gv5.json +++ b/advisories/unreviewed/2025/01/GHSA-wggv-mp5h-4gv5/GHSA-wggv-mp5h-4gv5.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-gqcv-v7gm-vw94/GHSA-gqcv-v7gm-vw94.json b/advisories/unreviewed/2025/03/GHSA-gqcv-v7gm-vw94/GHSA-gqcv-v7gm-vw94.json index b95da649e32..36872944d7a 100644 --- a/advisories/unreviewed/2025/03/GHSA-gqcv-v7gm-vw94/GHSA-gqcv-v7gm-vw94.json +++ b/advisories/unreviewed/2025/03/GHSA-gqcv-v7gm-vw94/GHSA-gqcv-v7gm-vw94.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-89" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-h7mx-548v-cr9r/GHSA-h7mx-548v-cr9r.json b/advisories/unreviewed/2025/04/GHSA-h7mx-548v-cr9r/GHSA-h7mx-548v-cr9r.json index 82c09c7a624..7d11b5908f9 100644 --- a/advisories/unreviewed/2025/04/GHSA-h7mx-548v-cr9r/GHSA-h7mx-548v-cr9r.json +++ b/advisories/unreviewed/2025/04/GHSA-h7mx-548v-cr9r/GHSA-h7mx-548v-cr9r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h7mx-548v-cr9r", - "modified": "2025-05-05T12:30:33Z", + "modified": "2025-05-05T15:30:53Z", "published": "2025-04-03T15:31:19Z", "aliases": [ "CVE-2025-3155" @@ -31,6 +31,14 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:4455" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:4456" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:4457" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-3155" diff --git a/advisories/unreviewed/2025/04/GHSA-wqxv-v2vg-q37x/GHSA-wqxv-v2vg-q37x.json b/advisories/unreviewed/2025/04/GHSA-wqxv-v2vg-q37x/GHSA-wqxv-v2vg-q37x.json index f45ac23d772..aedddf27661 100644 --- a/advisories/unreviewed/2025/04/GHSA-wqxv-v2vg-q37x/GHSA-wqxv-v2vg-q37x.json +++ b/advisories/unreviewed/2025/04/GHSA-wqxv-v2vg-q37x/GHSA-wqxv-v2vg-q37x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wqxv-v2vg-q37x", - "modified": "2025-05-02T03:30:34Z", + "modified": "2025-05-05T15:30:53Z", "published": "2025-04-25T18:31:12Z", "aliases": [ "CVE-2025-3928" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://documentation.commvault.com/securityadvisories/CV_2025_03_1.html" }, + { + "type": "WEB", + "url": "https://www.bleepingcomputer.com/news/security/commvault-says-recent-breach-didnt-impact-customer-backup-data" + }, { "type": "WEB", "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2025-3928" diff --git a/advisories/unreviewed/2025/05/GHSA-28h8-49pj-mw67/GHSA-28h8-49pj-mw67.json b/advisories/unreviewed/2025/05/GHSA-28h8-49pj-mw67/GHSA-28h8-49pj-mw67.json new file mode 100644 index 00000000000..ff9ae37784c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-28h8-49pj-mw67/GHSA-28h8-49pj-mw67.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-28h8-49pj-mw67", + "modified": "2025-05-05T15:30:53Z", + "published": "2025-05-05T15:30:53Z", + "aliases": [ + "CVE-2024-58100" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: check changes_pkt_data property for extension programs\n\nWhen processing calls to global sub-programs, verifier decides whether\nto invalidate all packet pointers in current state depending on the\nchanges_pkt_data property of the global sub-program.\n\nBecause of this, an extension program replacing a global sub-program\nmust be compatible with changes_pkt_data property of the sub-program\nbeing replaced.\n\nThis commit:\n- adds changes_pkt_data flag to struct bpf_prog_aux:\n - this flag is set in check_cfg() for main sub-program;\n - in jit_subprogs() for other sub-programs;\n- modifies bpf_check_attach_btf_id() to check changes_pkt_data flag;\n- moves call to check_attach_btf_id() after the call to check_cfg(),\n because it needs changes_pkt_data flag to be set:\n\n bpf_check:\n ... ...\n - check_attach_btf_id resolve_pseudo_ldimm64\n resolve_pseudo_ldimm64 --> bpf_prog_is_offloaded\n bpf_prog_is_offloaded check_cfg\n check_cfg + check_attach_btf_id\n ... ...\n\nThe following fields are set by check_attach_btf_id():\n- env->ops\n- prog->aux->attach_btf_trace\n- prog->aux->attach_func_name\n- prog->aux->attach_func_proto\n- prog->aux->dst_trampoline\n- prog->aux->mod\n- prog->aux->saved_dst_attach_type\n- prog->aux->saved_dst_prog_type\n- prog->expected_attach_type\n\nNeither of these fields are used by resolve_pseudo_ldimm64() or\nbpf_prog_offload_verifier_prep() (for netronome and netdevsim\ndrivers), so the reordering is safe.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-58100" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3846e2bea565ee1c5195dcc625fda9868fb0e3b3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/81f6d0530ba031b5f038a091619bf2ff29568852" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-05T15:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4grv-gh63-6248/GHSA-4grv-gh63-6248.json b/advisories/unreviewed/2025/05/GHSA-4grv-gh63-6248/GHSA-4grv-gh63-6248.json index 626de72fdcf..db280c448ba 100644 --- a/advisories/unreviewed/2025/05/GHSA-4grv-gh63-6248/GHSA-4grv-gh63-6248.json +++ b/advisories/unreviewed/2025/05/GHSA-4grv-gh63-6248/GHSA-4grv-gh63-6248.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4grv-gh63-6248", - "modified": "2025-05-05T06:30:25Z", + "modified": "2025-05-05T15:30:53Z", "published": "2025-05-05T06:30:24Z", "aliases": [ "CVE-2025-3583" ], "details": "The Newsletter WordPress plugin before 8.7.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-05T06:15:31Z" diff --git a/advisories/unreviewed/2025/05/GHSA-5qcr-g689-6g4f/GHSA-5qcr-g689-6g4f.json b/advisories/unreviewed/2025/05/GHSA-5qcr-g689-6g4f/GHSA-5qcr-g689-6g4f.json new file mode 100644 index 00000000000..92f979e20c1 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5qcr-g689-6g4f/GHSA-5qcr-g689-6g4f.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5qcr-g689-6g4f", + "modified": "2025-05-05T15:30:53Z", + "published": "2025-05-05T15:30:53Z", + "aliases": [ + "CVE-2025-4316" + ], + "details": "Improper access control in PAM feature in Devolutions Server 2025.1.6.0 and earlier allows a PAM user to self approve their PAM requests even if disallowed by the configured policy via specific user interface actions.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4316" + }, + { + "type": "WEB", + "url": "https://devolutions.net/security/advisories/DEVO-2025-0007" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-05T14:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-89vf-65xc-w22w/GHSA-89vf-65xc-w22w.json b/advisories/unreviewed/2025/05/GHSA-89vf-65xc-w22w/GHSA-89vf-65xc-w22w.json new file mode 100644 index 00000000000..3781b943e93 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-89vf-65xc-w22w/GHSA-89vf-65xc-w22w.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-89vf-65xc-w22w", + "modified": "2025-05-05T15:30:53Z", + "published": "2025-05-05T15:30:53Z", + "aliases": [ + "CVE-2025-47240" + ], + "details": "Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47240" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-05T15:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8r3j-hpqx-m8fj/GHSA-8r3j-hpqx-m8fj.json b/advisories/unreviewed/2025/05/GHSA-8r3j-hpqx-m8fj/GHSA-8r3j-hpqx-m8fj.json index d4f05c3b98f..ade5e8c1817 100644 --- a/advisories/unreviewed/2025/05/GHSA-8r3j-hpqx-m8fj/GHSA-8r3j-hpqx-m8fj.json +++ b/advisories/unreviewed/2025/05/GHSA-8r3j-hpqx-m8fj/GHSA-8r3j-hpqx-m8fj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8r3j-hpqx-m8fj", - "modified": "2025-05-01T12:31:16Z", + "modified": "2025-05-05T15:30:53Z", "published": "2025-05-01T12:31:16Z", "aliases": [ "CVE-2025-27007" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27007" }, + { + "type": "WEB", + "url": "https://patchstack.com/articles/additional-critical-ottokit-formerly-suretriggers-vulnerability-patched?_s_id=cve" + }, { "type": "WEB", "url": "https://patchstack.com/database/wordpress/plugin/suretriggers/vulnerability/wordpress-suretriggers-1-0-82-privilege-escalation-vulnerability?_s_id=cve" diff --git a/advisories/unreviewed/2025/05/GHSA-c2mm-9c32-xc37/GHSA-c2mm-9c32-xc37.json b/advisories/unreviewed/2025/05/GHSA-c2mm-9c32-xc37/GHSA-c2mm-9c32-xc37.json new file mode 100644 index 00000000000..d87ffc5d5b7 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-c2mm-9c32-xc37/GHSA-c2mm-9c32-xc37.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c2mm-9c32-xc37", + "modified": "2025-05-05T15:30:53Z", + "published": "2025-05-05T15:30:53Z", + "aliases": [ + "CVE-2025-47268" + ], + "details": "ping in iputils through 20240905 allows a denial of service (application error or incorrect data collection) via a crafted ICMP Echo Reply packet, because of a signed 64-bit integer overflow in timestamp multiplication.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47268" + }, + { + "type": "WEB", + "url": "https://github.com/iputils/iputils/issues/584" + }, + { + "type": "WEB", + "url": "https://github.com/Zephkek/ping-rtt-overflow" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-190" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-05T14:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-c44x-92pj-2rvh/GHSA-c44x-92pj-2rvh.json b/advisories/unreviewed/2025/05/GHSA-c44x-92pj-2rvh/GHSA-c44x-92pj-2rvh.json new file mode 100644 index 00000000000..6b798d77f46 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-c44x-92pj-2rvh/GHSA-c44x-92pj-2rvh.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c44x-92pj-2rvh", + "modified": "2025-05-05T15:30:53Z", + "published": "2025-05-05T15:30:53Z", + "aliases": [ + "CVE-2025-45751" + ], + "details": "SourceCodester Web Based Pharmacy Product Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in add-admin.php via the Fullname text field.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-45751" + }, + { + "type": "WEB", + "url": "https://github.com/sw8y/vulnerability_research/blob/main/CVE-2025-45751/CVE-2025-45751.md" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com/php/17883/web-based-product-alert-system.html" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-05T14:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hv6f-p3fq-464p/GHSA-hv6f-p3fq-464p.json b/advisories/unreviewed/2025/05/GHSA-hv6f-p3fq-464p/GHSA-hv6f-p3fq-464p.json new file mode 100644 index 00000000000..fb002eeaff3 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hv6f-p3fq-464p/GHSA-hv6f-p3fq-464p.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hv6f-p3fq-464p", + "modified": "2025-05-05T15:30:54Z", + "published": "2025-05-05T15:30:53Z", + "aliases": [ + "CVE-2024-58237" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: consider that tail calls invalidate packet pointers\n\nTail-called programs could execute any of the helpers that invalidate\npacket pointers. Hence, conservatively assume that each tail call\ninvalidates packet pointers.\n\nMaking the change in bpf_helper_changes_pkt_data() automatically makes\nuse of check_cfg() logic that computes 'changes_pkt_data' effect for\nglobal sub-programs, such that the following program could be\nrejected:\n\n int tail_call(struct __sk_buff *sk)\n {\n \tbpf_tail_call_static(sk, &jmp_table, 0);\n \treturn 0;\n }\n\n SEC(\"tc\")\n int not_safe(struct __sk_buff *sk)\n {\n \tint *p = (void *)(long)sk->data;\n \t... make p valid ...\n \ttail_call(sk);\n \t*p = 42; /* this is unsafe */\n \t...\n }\n\nThe tc_bpf2bpf.c:subprog_tc() needs change: mark it as a function that\ncan invalidate packet pointers. Otherwise, it can't be freplaced with\ntailcall_freplace.c:entry_freplace() that does a tail call.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-58237" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1a4607ffba35bf2a630aab299e34dd3f6e658d70" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1c2244437f9ad3dd91215f920401a14f2542dbfc" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-05T15:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-mqrj-rhjj-jp5m/GHSA-mqrj-rhjj-jp5m.json b/advisories/unreviewed/2025/05/GHSA-mqrj-rhjj-jp5m/GHSA-mqrj-rhjj-jp5m.json new file mode 100644 index 00000000000..24d10f8e056 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-mqrj-rhjj-jp5m/GHSA-mqrj-rhjj-jp5m.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mqrj-rhjj-jp5m", + "modified": "2025-05-05T15:30:53Z", + "published": "2025-05-05T15:30:53Z", + "aliases": [ + "CVE-2024-58098" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: track changes_pkt_data property for global functions\n\nWhen processing calls to certain helpers, verifier invalidates all\npacket pointers in a current state. For example, consider the\nfollowing program:\n\n __attribute__((__noinline__))\n long skb_pull_data(struct __sk_buff *sk, __u32 len)\n {\n return bpf_skb_pull_data(sk, len);\n }\n\n SEC(\"tc\")\n int test_invalidate_checks(struct __sk_buff *sk)\n {\n int *p = (void *)(long)sk->data;\n if ((void *)(p + 1) > (void *)(long)sk->data_end) return TCX_DROP;\n skb_pull_data(sk, 0);\n *p = 42;\n return TCX_PASS;\n }\n\nAfter a call to bpf_skb_pull_data() the pointer 'p' can't be used\nsafely. See function filter.c:bpf_helper_changes_pkt_data() for a list\nof such helpers.\n\nAt the moment verifier invalidates packet pointers when processing\nhelper function calls, and does not traverse global sub-programs when\nprocessing calls to global sub-programs. This means that calls to\nhelpers done from global sub-programs do not invalidate pointers in\nthe caller state. E.g. the program above is unsafe, but is not\nrejected by verifier.\n\nThis commit fixes the omission by computing field\nbpf_subprog_info->changes_pkt_data for each sub-program before main\nverification pass.\nchanges_pkt_data should be set if:\n- subprogram calls helper for which bpf_helper_changes_pkt_data\n returns true;\n- subprogram calls a global function,\n for which bpf_subprog_info->changes_pkt_data should be set.\n\nThe verifier.c:check_cfg() pass is modified to compute this\ninformation. The commit relies on depth first instruction traversal\ndone by check_cfg() and absence of recursive function calls:\n- check_cfg() would eventually visit every call to subprogram S in a\n state when S is fully explored;\n- when S is fully explored:\n - every direct helper call within S is explored\n (and thus changes_pkt_data is set if needed);\n - every call to subprogram S1 called by S was visited with S1 fully\n explored (and thus S inherits changes_pkt_data from S1).\n\nThe downside of such approach is that dead code elimination is not\ntaken into account: if a helper call inside global function is dead\nbecause of current configuration, verifier would conservatively assume\nthat the call occurs for the purpose of the changes_pkt_data\ncomputation.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-58098" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1d572c60488b52882b719ed273767ee3b280413d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/51081a3f25c742da5a659d7fc6fd77ebfdd555be" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-05T15:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-x9rr-xwxc-jcjf/GHSA-x9rr-xwxc-jcjf.json b/advisories/unreviewed/2025/05/GHSA-x9rr-xwxc-jcjf/GHSA-x9rr-xwxc-jcjf.json new file mode 100644 index 00000000000..3b9b19a9d4f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-x9rr-xwxc-jcjf/GHSA-x9rr-xwxc-jcjf.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x9rr-xwxc-jcjf", + "modified": "2025-05-05T15:30:53Z", + "published": "2025-05-05T15:30:53Z", + "aliases": [ + "CVE-2025-28168" + ], + "details": "Outsystems Multiple File Upload < 3.1.0 is vulnerable to Unrestricted File Upload. The vulnerability is because file extension and size validations are enforced solely on the client side. An attacker can intercept the upload request and modify the parameter to bypass extension restrictions and upload arbitrary files.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28168" + }, + { + "type": "WEB", + "url": "https://gist.github.com/IamLeandrooooo/01090be3023f5e7c7397bb9b1f5505b9" + }, + { + "type": "WEB", + "url": "https://www.outsystems.com/forge/component-overview/200/multiple-file-upload-o11" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-05T14:15:28Z" + } +} \ No newline at end of file