Publish Advisories

GHSA-5v8v-cp6r-mq7c
GHSA-q58r-hwc8-rm9j
GHSA-3jxj-c73c-7933
GHSA-3qr2-2p78-j25q
GHSA-7fxh-qxmw-7xh7
GHSA-7wff-7hq6-6m3g
GHSA-fvv5-x89c-vh93
This commit is contained in:
advisory-database[bot]
2025-06-01 12:31:38 +00:00
parent 0c7e621c89
commit 4a83c7d9c2
7 changed files with 190 additions and 2 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5v8v-cp6r-mq7c",
"modified": "2025-05-27T15:31:17Z",
"modified": "2025-06-01T12:30:24Z",
"published": "2022-09-25T00:00:27Z",
"aliases": [
"CVE-2022-41322"
@@ -31,6 +31,10 @@
"type": "WEB",
"url": "https://github.com/kovidgoyal/kitty/compare/v0.26.1...v0.26.2"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2025/06/msg00000.html"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/47RK7MBSVY5BWDUTYMJUFPBAYFSWMTOI"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-q58r-hwc8-rm9j",
"modified": "2025-05-15T18:31:47Z",
"modified": "2025-06-01T12:30:24Z",
"published": "2025-05-15T18:31:47Z",
"aliases": [
"CVE-2025-1647"
@@ -19,6 +19,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1647"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2025/06/msg00001.html"
},
{
"type": "WEB",
"url": "https://www.herodevs.com/vulnerability-directory/cve-2025-1647"
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3jxj-c73c-7933",
"modified": "2025-06-01T12:30:24Z",
"published": "2025-06-01T12:30:24Z",
"aliases": [
"CVE-2025-1499"
],
"details": "IBM InfoSphere Information Server 11.7 stores credential information for database authentication in a cleartext parameter file that could be viewed by an authenticated user.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1499"
},
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/7233154"
}
],
"database_specific": {
"cwe_ids": [
"CWE-312"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-06-01T12:15:24Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3qr2-2p78-j25q",
"modified": "2025-06-01T12:30:24Z",
"published": "2025-06-01T12:30:24Z",
"aliases": [
"CVE-2025-2896"
],
"details": "IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2896"
},
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/7235182"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-06-01T12:15:25Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7fxh-qxmw-7xh7",
"modified": "2025-06-01T12:30:25Z",
"published": "2025-06-01T12:30:25Z",
"aliases": [
"CVE-2025-33005"
],
"details": "IBM Planning Analytics Local 2.0 and 2.1 does not invalidate session after a logout which could allow an authenticated user to impersonate another user on the system.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-33005"
},
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/7235182"
}
],
"database_specific": {
"cwe_ids": [
"CWE-613"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-06-01T12:15:25Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7wff-7hq6-6m3g",
"modified": "2025-06-01T12:30:24Z",
"published": "2025-06-01T12:30:24Z",
"aliases": [
"CVE-2025-33004"
],
"details": "IBM Planning Analytics Local 2.0 and 2.1 could allow a privileged user to delete files from directories due to improper pathname restriction.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-33004"
},
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/7235182"
}
],
"database_specific": {
"cwe_ids": [
"CWE-22"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-06-01T12:15:25Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fvv5-x89c-vh93",
"modified": "2025-06-01T12:30:24Z",
"published": "2025-06-01T12:30:24Z",
"aliases": [
"CVE-2025-25044"
],
"details": "IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25044"
},
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/7235182"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-06-01T12:15:25Z"
}
}