diff --git a/advisories/unreviewed/2022/09/GHSA-5v8v-cp6r-mq7c/GHSA-5v8v-cp6r-mq7c.json b/advisories/unreviewed/2022/09/GHSA-5v8v-cp6r-mq7c/GHSA-5v8v-cp6r-mq7c.json index 80969354f75..6b302840f34 100644 --- a/advisories/unreviewed/2022/09/GHSA-5v8v-cp6r-mq7c/GHSA-5v8v-cp6r-mq7c.json +++ b/advisories/unreviewed/2022/09/GHSA-5v8v-cp6r-mq7c/GHSA-5v8v-cp6r-mq7c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5v8v-cp6r-mq7c", - "modified": "2025-05-27T15:31:17Z", + "modified": "2025-06-01T12:30:24Z", "published": "2022-09-25T00:00:27Z", "aliases": [ "CVE-2022-41322" @@ -31,6 +31,10 @@ "type": "WEB", "url": "https://github.com/kovidgoyal/kitty/compare/v0.26.1...v0.26.2" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2025/06/msg00000.html" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/47RK7MBSVY5BWDUTYMJUFPBAYFSWMTOI" diff --git a/advisories/unreviewed/2025/05/GHSA-q58r-hwc8-rm9j/GHSA-q58r-hwc8-rm9j.json b/advisories/unreviewed/2025/05/GHSA-q58r-hwc8-rm9j/GHSA-q58r-hwc8-rm9j.json index 308f0e8664f..0ed58717c47 100644 --- a/advisories/unreviewed/2025/05/GHSA-q58r-hwc8-rm9j/GHSA-q58r-hwc8-rm9j.json +++ b/advisories/unreviewed/2025/05/GHSA-q58r-hwc8-rm9j/GHSA-q58r-hwc8-rm9j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q58r-hwc8-rm9j", - "modified": "2025-05-15T18:31:47Z", + "modified": "2025-06-01T12:30:24Z", "published": "2025-05-15T18:31:47Z", "aliases": [ "CVE-2025-1647" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1647" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2025/06/msg00001.html" + }, { "type": "WEB", "url": "https://www.herodevs.com/vulnerability-directory/cve-2025-1647" diff --git a/advisories/unreviewed/2025/06/GHSA-3jxj-c73c-7933/GHSA-3jxj-c73c-7933.json b/advisories/unreviewed/2025/06/GHSA-3jxj-c73c-7933/GHSA-3jxj-c73c-7933.json new file mode 100644 index 00000000000..b7679e43d50 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-3jxj-c73c-7933/GHSA-3jxj-c73c-7933.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3jxj-c73c-7933", + "modified": "2025-06-01T12:30:24Z", + "published": "2025-06-01T12:30:24Z", + "aliases": [ + "CVE-2025-1499" + ], + "details": "IBM InfoSphere Information Server 11.7 stores credential information for database authentication in a cleartext parameter file that could be viewed by an authenticated user.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1499" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7233154" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-312" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-01T12:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-3qr2-2p78-j25q/GHSA-3qr2-2p78-j25q.json b/advisories/unreviewed/2025/06/GHSA-3qr2-2p78-j25q/GHSA-3qr2-2p78-j25q.json new file mode 100644 index 00000000000..49eb21a8417 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-3qr2-2p78-j25q/GHSA-3qr2-2p78-j25q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3qr2-2p78-j25q", + "modified": "2025-06-01T12:30:24Z", + "published": "2025-06-01T12:30:24Z", + "aliases": [ + "CVE-2025-2896" + ], + "details": "IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2896" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7235182" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-01T12:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-7fxh-qxmw-7xh7/GHSA-7fxh-qxmw-7xh7.json b/advisories/unreviewed/2025/06/GHSA-7fxh-qxmw-7xh7/GHSA-7fxh-qxmw-7xh7.json new file mode 100644 index 00000000000..8598872ae0e --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-7fxh-qxmw-7xh7/GHSA-7fxh-qxmw-7xh7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7fxh-qxmw-7xh7", + "modified": "2025-06-01T12:30:25Z", + "published": "2025-06-01T12:30:25Z", + "aliases": [ + "CVE-2025-33005" + ], + "details": "IBM Planning Analytics Local 2.0 and 2.1 does not invalidate session after a logout which could allow an authenticated user to impersonate another user on the system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-33005" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7235182" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-613" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-01T12:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-7wff-7hq6-6m3g/GHSA-7wff-7hq6-6m3g.json b/advisories/unreviewed/2025/06/GHSA-7wff-7hq6-6m3g/GHSA-7wff-7hq6-6m3g.json new file mode 100644 index 00000000000..2185abbc033 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-7wff-7hq6-6m3g/GHSA-7wff-7hq6-6m3g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7wff-7hq6-6m3g", + "modified": "2025-06-01T12:30:24Z", + "published": "2025-06-01T12:30:24Z", + "aliases": [ + "CVE-2025-33004" + ], + "details": "IBM Planning Analytics Local 2.0 and 2.1 could allow a privileged user to delete files from directories due to improper pathname restriction.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-33004" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7235182" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-01T12:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-fvv5-x89c-vh93/GHSA-fvv5-x89c-vh93.json b/advisories/unreviewed/2025/06/GHSA-fvv5-x89c-vh93/GHSA-fvv5-x89c-vh93.json new file mode 100644 index 00000000000..b49a81a1090 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-fvv5-x89c-vh93/GHSA-fvv5-x89c-vh93.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fvv5-x89c-vh93", + "modified": "2025-06-01T12:30:24Z", + "published": "2025-06-01T12:30:24Z", + "aliases": [ + "CVE-2025-25044" + ], + "details": "IBM Planning Analytics Local 2.0 and 2.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25044" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7235182" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-01T12:15:25Z" + } +} \ No newline at end of file