diff --git a/advisories/unreviewed/2022/05/GHSA-4v96-m8xv-x83v/GHSA-4v96-m8xv-x83v.json b/advisories/unreviewed/2022/05/GHSA-4v96-m8xv-x83v/GHSA-4v96-m8xv-x83v.json index 0dd078e398e..a7924b4c1ef 100644 --- a/advisories/unreviewed/2022/05/GHSA-4v96-m8xv-x83v/GHSA-4v96-m8xv-x83v.json +++ b/advisories/unreviewed/2022/05/GHSA-4v96-m8xv-x83v/GHSA-4v96-m8xv-x83v.json @@ -1,19 +1,28 @@ { "schema_version": "1.4.0", "id": "GHSA-4v96-m8xv-x83v", - "modified": "2022-05-24T22:28:12Z", + "modified": "2025-02-12T21:31:46Z", "published": "2022-05-24T22:28:12Z", "aliases": [ "CVE-2021-26073" ], "details": "Broken Authentication in Atlassian Connect Express (ACE) from version 3.0.2 before version 6.6.0: Atlassian Connect Express is a Node.js package for building Atlassian Connect apps. Authentication between Atlassian products and the Atlassian Connect Express app occurs with a server-to-server JWT or a context JWT. Atlassian Connect Express versions between 3.0.2 - 6.5.0 erroneously accept context JWTs in lifecycle endpoints (such as installation) where only server-to-server JWTs should be accepted, permitting an attacker to send authenticated re-installation events to an app.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N" + } + ], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-26073" }, + { + "type": "WEB", + "url": "https://community.developer.atlassian.com/t/action-required-atlassian-connect-vulnerability-a%5B%E2%80%A6%5Dypass-of-app-qsh-verification-via-context-jwts/47072" + }, { "type": "WEB", "url": "https://community.developer.atlassian.com/t/action-required-atlassian-connect-vulnerability-a[…]ypass-of-app-qsh-verification-via-context-jwts/47072" diff --git a/advisories/unreviewed/2022/05/GHSA-7w3v-7x22-4g8v/GHSA-7w3v-7x22-4g8v.json b/advisories/unreviewed/2022/05/GHSA-7w3v-7x22-4g8v/GHSA-7w3v-7x22-4g8v.json index 02149b28c47..91d251070b7 100644 --- a/advisories/unreviewed/2022/05/GHSA-7w3v-7x22-4g8v/GHSA-7w3v-7x22-4g8v.json +++ b/advisories/unreviewed/2022/05/GHSA-7w3v-7x22-4g8v/GHSA-7w3v-7x22-4g8v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7w3v-7x22-4g8v", - "modified": "2025-02-07T18:31:03Z", + "modified": "2025-02-12T21:31:46Z", "published": "2022-05-24T22:28:24Z", "aliases": [ "CVE-2021-36741" diff --git a/advisories/unreviewed/2022/05/GHSA-j3xh-c39x-qghw/GHSA-j3xh-c39x-qghw.json b/advisories/unreviewed/2022/05/GHSA-j3xh-c39x-qghw/GHSA-j3xh-c39x-qghw.json index dece424049f..16003f7ad37 100644 --- a/advisories/unreviewed/2022/05/GHSA-j3xh-c39x-qghw/GHSA-j3xh-c39x-qghw.json +++ b/advisories/unreviewed/2022/05/GHSA-j3xh-c39x-qghw/GHSA-j3xh-c39x-qghw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-j3xh-c39x-qghw", - "modified": "2022-05-24T19:14:55Z", + "modified": "2025-02-12T21:31:46Z", "published": "2022-05-24T19:14:55Z", "aliases": [ "CVE-2021-38406" ], "details": "Delta Electronic DOPSoft 2 (Version 2.00.07 and prior) lacks proper validation of user-supplied data when parsing specific project files. This could result in multiple out-of-bounds write instances. An attacker could leverage this vulnerability to execute code in the context of the current process.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2023/04/GHSA-94g5-g8cc-mwfw/GHSA-94g5-g8cc-mwfw.json b/advisories/unreviewed/2023/04/GHSA-94g5-g8cc-mwfw/GHSA-94g5-g8cc-mwfw.json index e5c8163c5cf..dece92a681b 100644 --- a/advisories/unreviewed/2023/04/GHSA-94g5-g8cc-mwfw/GHSA-94g5-g8cc-mwfw.json +++ b/advisories/unreviewed/2023/04/GHSA-94g5-g8cc-mwfw/GHSA-94g5-g8cc-mwfw.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-94" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/04/GHSA-jw8g-rg5r-2x5j/GHSA-jw8g-rg5r-2x5j.json b/advisories/unreviewed/2023/04/GHSA-jw8g-rg5r-2x5j/GHSA-jw8g-rg5r-2x5j.json index 961248e9b33..67342cd3b2f 100644 --- a/advisories/unreviewed/2023/04/GHSA-jw8g-rg5r-2x5j/GHSA-jw8g-rg5r-2x5j.json +++ b/advisories/unreviewed/2023/04/GHSA-jw8g-rg5r-2x5j/GHSA-jw8g-rg5r-2x5j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jw8g-rg5r-2x5j", - "modified": "2023-04-13T18:30:30Z", + "modified": "2025-02-12T21:31:46Z", "published": "2023-04-07T03:30:18Z", "aliases": [ "CVE-2023-25218" diff --git a/advisories/unreviewed/2023/04/GHSA-qc2w-qcmx-m375/GHSA-qc2w-qcmx-m375.json b/advisories/unreviewed/2023/04/GHSA-qc2w-qcmx-m375/GHSA-qc2w-qcmx-m375.json index b245478cb99..90c76710372 100644 --- a/advisories/unreviewed/2023/04/GHSA-qc2w-qcmx-m375/GHSA-qc2w-qcmx-m375.json +++ b/advisories/unreviewed/2023/04/GHSA-qc2w-qcmx-m375/GHSA-qc2w-qcmx-m375.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qc2w-qcmx-m375", - "modified": "2023-04-13T18:30:30Z", + "modified": "2025-02-12T21:31:46Z", "published": "2023-04-07T03:30:18Z", "aliases": [ "CVE-2023-25220" diff --git a/advisories/unreviewed/2023/08/GHSA-9m3r-v8gg-v29j/GHSA-9m3r-v8gg-v29j.json b/advisories/unreviewed/2023/08/GHSA-9m3r-v8gg-v29j/GHSA-9m3r-v8gg-v29j.json index d64404572d7..f2dcc2084dd 100644 --- a/advisories/unreviewed/2023/08/GHSA-9m3r-v8gg-v29j/GHSA-9m3r-v8gg-v29j.json +++ b/advisories/unreviewed/2023/08/GHSA-9m3r-v8gg-v29j/GHSA-9m3r-v8gg-v29j.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-121", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/02/GHSA-2q9p-5gw5-gr76/GHSA-2q9p-5gw5-gr76.json b/advisories/unreviewed/2024/02/GHSA-2q9p-5gw5-gr76/GHSA-2q9p-5gw5-gr76.json index f12b83598ab..508aaa7637f 100644 --- a/advisories/unreviewed/2024/02/GHSA-2q9p-5gw5-gr76/GHSA-2q9p-5gw5-gr76.json +++ b/advisories/unreviewed/2024/02/GHSA-2q9p-5gw5-gr76/GHSA-2q9p-5gw5-gr76.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2q9p-5gw5-gr76", - "modified": "2024-02-21T09:31:00Z", + "modified": "2025-02-12T21:31:47Z", "published": "2024-02-20T09:30:32Z", "aliases": [ "CVE-2024-25973" ], - "details": "The Frentix GmbH OpenOlat LMS is affected by multiple stored Cross-Site Scripting (XSS) vulnerabilities. An attacker with rights to create or edit groups can create a course with a name that contains an XSS payload. Furthermore, attackers with the permissions to create or rename a catalog (sub-category) can enter unfiltered input in the name field. In addition, attackers who are allowed to create curriculums can also enter unfiltered input in the name field. This allows an attacker to execute stored JavaScript code with the permissions of the victim in the context of the user's browser.\n\n", - "severity": [], + "details": "The Frentix GmbH OpenOlat LMS is affected by multiple stored Cross-Site Scripting (XSS) vulnerabilities. An attacker with rights to create or edit groups can create a course with a name that contains an XSS payload. Furthermore, attackers with the permissions to create or rename a catalog (sub-category) can enter unfiltered input in the name field. In addition, attackers who are allowed to create curriculums can also enter unfiltered input in the name field. This allows an attacker to execute stored JavaScript code with the permissions of the victim in the context of the user's browser.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -25,9 +30,10 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-20T08:15:07Z" diff --git a/advisories/unreviewed/2024/02/GHSA-3hwp-p2jw-j4xh/GHSA-3hwp-p2jw-j4xh.json b/advisories/unreviewed/2024/02/GHSA-3hwp-p2jw-j4xh/GHSA-3hwp-p2jw-j4xh.json index 6560821364b..f13ef13f2b6 100644 --- a/advisories/unreviewed/2024/02/GHSA-3hwp-p2jw-j4xh/GHSA-3hwp-p2jw-j4xh.json +++ b/advisories/unreviewed/2024/02/GHSA-3hwp-p2jw-j4xh/GHSA-3hwp-p2jw-j4xh.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-3hwp-p2jw-j4xh", - "modified": "2024-02-20T15:31:06Z", + "modified": "2025-02-12T21:31:48Z", "published": "2024-02-20T15:31:06Z", "aliases": [ "CVE-2024-1155" ], - "details": "Incorrect permissions in the installation directories for shared SystemLink Elixir based services may allow an authenticated user to potentially enable escalation of privilege via local access. \n", + "details": "Incorrect permissions in the installation directories for shared SystemLink Elixir based services may allow an authenticated user to potentially enable escalation of privilege via local access.", "severity": [ { "type": "CVSS_V3", @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-276" + "CWE-276", + "CWE-863" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-42c4-hvg2-mp96/GHSA-42c4-hvg2-mp96.json b/advisories/unreviewed/2024/02/GHSA-42c4-hvg2-mp96/GHSA-42c4-hvg2-mp96.json index a2de85162cf..49e44c2f97f 100644 --- a/advisories/unreviewed/2024/02/GHSA-42c4-hvg2-mp96/GHSA-42c4-hvg2-mp96.json +++ b/advisories/unreviewed/2024/02/GHSA-42c4-hvg2-mp96/GHSA-42c4-hvg2-mp96.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-42c4-hvg2-mp96", - "modified": "2024-02-26T18:30:31Z", + "modified": "2025-02-12T21:31:49Z", "published": "2024-02-26T18:30:31Z", "aliases": [ "CVE-2024-24402" ], "details": "An issue in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted script to the /usr/local/nagios/bin/npcd component.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-26T17:15:10Z" diff --git a/advisories/unreviewed/2024/02/GHSA-4mgv-g5j9-fr8q/GHSA-4mgv-g5j9-fr8q.json b/advisories/unreviewed/2024/02/GHSA-4mgv-g5j9-fr8q/GHSA-4mgv-g5j9-fr8q.json index 560fd3f0c80..1ebffe63ff0 100644 --- a/advisories/unreviewed/2024/02/GHSA-4mgv-g5j9-fr8q/GHSA-4mgv-g5j9-fr8q.json +++ b/advisories/unreviewed/2024/02/GHSA-4mgv-g5j9-fr8q/GHSA-4mgv-g5j9-fr8q.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-126" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/02/GHSA-5998-89hj-xhfc/GHSA-5998-89hj-xhfc.json b/advisories/unreviewed/2024/02/GHSA-5998-89hj-xhfc/GHSA-5998-89hj-xhfc.json index 016027aea30..a42c3d1d0db 100644 --- a/advisories/unreviewed/2024/02/GHSA-5998-89hj-xhfc/GHSA-5998-89hj-xhfc.json +++ b/advisories/unreviewed/2024/02/GHSA-5998-89hj-xhfc/GHSA-5998-89hj-xhfc.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-190" + "CWE-190", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-7v7g-38mv-3237/GHSA-7v7g-38mv-3237.json b/advisories/unreviewed/2024/02/GHSA-7v7g-38mv-3237/GHSA-7v7g-38mv-3237.json index 9fa77f7c22e..39b6beccec5 100644 --- a/advisories/unreviewed/2024/02/GHSA-7v7g-38mv-3237/GHSA-7v7g-38mv-3237.json +++ b/advisories/unreviewed/2024/02/GHSA-7v7g-38mv-3237/GHSA-7v7g-38mv-3237.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-126" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/02/GHSA-c9jh-pp3m-mqr9/GHSA-c9jh-pp3m-mqr9.json b/advisories/unreviewed/2024/02/GHSA-c9jh-pp3m-mqr9/GHSA-c9jh-pp3m-mqr9.json index 546735466c9..21f6036cd8e 100644 --- a/advisories/unreviewed/2024/02/GHSA-c9jh-pp3m-mqr9/GHSA-c9jh-pp3m-mqr9.json +++ b/advisories/unreviewed/2024/02/GHSA-c9jh-pp3m-mqr9/GHSA-c9jh-pp3m-mqr9.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-190" + "CWE-190", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-ccq4-9qhm-55xx/GHSA-ccq4-9qhm-55xx.json b/advisories/unreviewed/2024/02/GHSA-ccq4-9qhm-55xx/GHSA-ccq4-9qhm-55xx.json index af1c72c4093..f8e1b3d4438 100644 --- a/advisories/unreviewed/2024/02/GHSA-ccq4-9qhm-55xx/GHSA-ccq4-9qhm-55xx.json +++ b/advisories/unreviewed/2024/02/GHSA-ccq4-9qhm-55xx/GHSA-ccq4-9qhm-55xx.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-276" + "CWE-276", + "CWE-863" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-fhv7-8956-mv3h/GHSA-fhv7-8956-mv3h.json b/advisories/unreviewed/2024/02/GHSA-fhv7-8956-mv3h/GHSA-fhv7-8956-mv3h.json index ebc10d3dd4d..12f2cd291f9 100644 --- a/advisories/unreviewed/2024/02/GHSA-fhv7-8956-mv3h/GHSA-fhv7-8956-mv3h.json +++ b/advisories/unreviewed/2024/02/GHSA-fhv7-8956-mv3h/GHSA-fhv7-8956-mv3h.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-190" + "CWE-190", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-gwh5-fh5x-ww83/GHSA-gwh5-fh5x-ww83.json b/advisories/unreviewed/2024/02/GHSA-gwh5-fh5x-ww83/GHSA-gwh5-fh5x-ww83.json index d19f96535ee..7be9f4d0d1d 100644 --- a/advisories/unreviewed/2024/02/GHSA-gwh5-fh5x-ww83/GHSA-gwh5-fh5x-ww83.json +++ b/advisories/unreviewed/2024/02/GHSA-gwh5-fh5x-ww83/GHSA-gwh5-fh5x-ww83.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-j494-r8wx-qpjr/GHSA-j494-r8wx-qpjr.json b/advisories/unreviewed/2024/02/GHSA-j494-r8wx-qpjr/GHSA-j494-r8wx-qpjr.json index 73a003750a7..f7ab609e9b2 100644 --- a/advisories/unreviewed/2024/02/GHSA-j494-r8wx-qpjr/GHSA-j494-r8wx-qpjr.json +++ b/advisories/unreviewed/2024/02/GHSA-j494-r8wx-qpjr/GHSA-j494-r8wx-qpjr.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-mc8m-4r3w-q2hw/GHSA-mc8m-4r3w-q2hw.json b/advisories/unreviewed/2024/02/GHSA-mc8m-4r3w-q2hw/GHSA-mc8m-4r3w-q2hw.json index 603218d7584..0c0b16cad29 100644 --- a/advisories/unreviewed/2024/02/GHSA-mc8m-4r3w-q2hw/GHSA-mc8m-4r3w-q2hw.json +++ b/advisories/unreviewed/2024/02/GHSA-mc8m-4r3w-q2hw/GHSA-mc8m-4r3w-q2hw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mc8m-4r3w-q2hw", - "modified": "2024-02-20T06:30:29Z", + "modified": "2025-02-12T21:31:47Z", "published": "2024-02-20T06:30:29Z", "aliases": [ "CVE-2022-45320" ], "details": "Liferay Portal before 7.4.3.16 and Liferay DXP before 7.2 fix pack 19, 7.3 before update 6, and 7.4 before update 16 allow remote authenticated users to become the owner of a wiki page by editing the wiki page.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-20T05:15:07Z" diff --git a/advisories/unreviewed/2024/02/GHSA-w4wv-vq5v-xp26/GHSA-w4wv-vq5v-xp26.json b/advisories/unreviewed/2024/02/GHSA-w4wv-vq5v-xp26/GHSA-w4wv-vq5v-xp26.json index 7deb959e606..3e04ea6054c 100644 --- a/advisories/unreviewed/2024/02/GHSA-w4wv-vq5v-xp26/GHSA-w4wv-vq5v-xp26.json +++ b/advisories/unreviewed/2024/02/GHSA-w4wv-vq5v-xp26/GHSA-w4wv-vq5v-xp26.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-190" + "CWE-190", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-5rwj-59p7-5wj5/GHSA-5rwj-59p7-5wj5.json b/advisories/unreviewed/2024/03/GHSA-5rwj-59p7-5wj5/GHSA-5rwj-59p7-5wj5.json index 34b0aed54de..9b188a9f0ba 100644 --- a/advisories/unreviewed/2024/03/GHSA-5rwj-59p7-5wj5/GHSA-5rwj-59p7-5wj5.json +++ b/advisories/unreviewed/2024/03/GHSA-5rwj-59p7-5wj5/GHSA-5rwj-59p7-5wj5.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-5rwj-59p7-5wj5", - "modified": "2024-03-21T18:32:03Z", + "modified": "2025-02-12T21:31:49Z", "published": "2024-03-21T18:32:03Z", "aliases": [ "CVE-2024-27968" ], - "details": "Cross-Site Request Forgery (CSRF) vulnerability in Optimole Super Page Cache for Cloudflare allows Stored XSS.This issue affects Super Page Cache for Cloudflare: from n/a through 4.7.5.\n\n", + "details": "Cross-Site Request Forgery (CSRF) vulnerability in Optimole Super Page Cache for Cloudflare allows Stored XSS.This issue affects Super Page Cache for Cloudflare: from n/a through 4.7.5.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2025/02/GHSA-2mff-4q5m-q2cm/GHSA-2mff-4q5m-q2cm.json b/advisories/unreviewed/2025/02/GHSA-2mff-4q5m-q2cm/GHSA-2mff-4q5m-q2cm.json new file mode 100644 index 00000000000..a1b9417489a --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-2mff-4q5m-q2cm/GHSA-2mff-4q5m-q2cm.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2mff-4q5m-q2cm", + "modified": "2025-02-12T21:31:54Z", + "published": "2025-02-12T21:31:54Z", + "aliases": [ + "CVE-2025-1227" + ], + "details": "A vulnerability was found in ywoa up to 2024.07.03. It has been rated as critical. This issue affects the function selectList of the file com/cloudweb/oa/mapper/xml/AddressDao.xml. The manipulation leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2024.07.04 is able to address this issue. It is recommended to upgrade the affected component.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1227" + }, + { + "type": "WEB", + "url": "https://gitee.com/r1bbit/yimioa/issues/IBI7XH" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.295217" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.295217" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T21:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-36j9-fp7f-7f7m/GHSA-36j9-fp7f-7f7m.json b/advisories/unreviewed/2025/02/GHSA-36j9-fp7f-7f7m/GHSA-36j9-fp7f-7f7m.json index fba4606574b..081d092018f 100644 --- a/advisories/unreviewed/2025/02/GHSA-36j9-fp7f-7f7m/GHSA-36j9-fp7f-7f7m.json +++ b/advisories/unreviewed/2025/02/GHSA-36j9-fp7f-7f7m/GHSA-36j9-fp7f-7f7m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-36j9-fp7f-7f7m", - "modified": "2025-02-03T21:31:49Z", + "modified": "2025-02-12T21:31:51Z", "published": "2025-02-03T21:31:49Z", "aliases": [ "CVE-2024-57004" ], "details": "Cross-Site Scripting (XSS) vulnerability in Roundcube Webmail 1.6.9 allows remote authenticated users to upload a malicious file as an email attachment, leading to the triggering of the XSS by visiting the SENT session.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-80" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-03T19:15:12Z" diff --git a/advisories/unreviewed/2025/02/GHSA-3hxq-f9p6-ww56/GHSA-3hxq-f9p6-ww56.json b/advisories/unreviewed/2025/02/GHSA-3hxq-f9p6-ww56/GHSA-3hxq-f9p6-ww56.json new file mode 100644 index 00000000000..4dd3ee6e04b --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-3hxq-f9p6-ww56/GHSA-3hxq-f9p6-ww56.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3hxq-f9p6-ww56", + "modified": "2025-02-12T21:31:54Z", + "published": "2025-02-12T21:31:54Z", + "aliases": [ + "CVE-2024-12673" + ], + "details": "An improper privilege vulnerability was reported in a BIOS customization feature of Lenovo Vantage on SMB notebook devices which could allow a local attacker to elevate privileges on the system.\n\nThis vulnerability only affects Vantage installed on these devices:\n\n * Lenovo V Series (Gen 5)\n * ThinkBook 14 (Gen 6, 7)\n * ThinkBook 16 (Gen 6, 7)\n * ThinkPad E Series (Gen 1)", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12673" + }, + { + "type": "WEB", + "url": "https://support.lenovo.com/us/en/product_security/LEN-183176" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-250" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T21:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-4f3f-g69r-4597/GHSA-4f3f-g69r-4597.json b/advisories/unreviewed/2025/02/GHSA-4f3f-g69r-4597/GHSA-4f3f-g69r-4597.json index 54e0311d6f4..0c63649728e 100644 --- a/advisories/unreviewed/2025/02/GHSA-4f3f-g69r-4597/GHSA-4f3f-g69r-4597.json +++ b/advisories/unreviewed/2025/02/GHSA-4f3f-g69r-4597/GHSA-4f3f-g69r-4597.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4f3f-g69r-4597", - "modified": "2025-02-03T21:31:49Z", + "modified": "2025-02-12T21:31:52Z", "published": "2025-02-03T21:31:49Z", "aliases": [ "CVE-2024-57238" ], "details": "Prolink 4G LTE Mobile Wi-Fi DL-7203E V4.0.0B05 is vulnerable to SQL Injection in in the /reqproc/proc_get endpoint. The vulnerability allows an attacker to manipulate SQL queries by injecting malicious SQL code into the order_by parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-03T19:15:13Z" diff --git a/advisories/unreviewed/2025/02/GHSA-5f2r-hqc4-68xm/GHSA-5f2r-hqc4-68xm.json b/advisories/unreviewed/2025/02/GHSA-5f2r-hqc4-68xm/GHSA-5f2r-hqc4-68xm.json index b50633d7bb0..bc553d6ca2a 100644 --- a/advisories/unreviewed/2025/02/GHSA-5f2r-hqc4-68xm/GHSA-5f2r-hqc4-68xm.json +++ b/advisories/unreviewed/2025/02/GHSA-5f2r-hqc4-68xm/GHSA-5f2r-hqc4-68xm.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1021", "CWE-451" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2025/02/GHSA-5mx9-vcf9-4hvc/GHSA-5mx9-vcf9-4hvc.json b/advisories/unreviewed/2025/02/GHSA-5mx9-vcf9-4hvc/GHSA-5mx9-vcf9-4hvc.json new file mode 100644 index 00000000000..0734a221bcd --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-5mx9-vcf9-4hvc/GHSA-5mx9-vcf9-4hvc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5mx9-vcf9-4hvc", + "modified": "2025-02-12T21:31:53Z", + "published": "2025-02-12T21:31:53Z", + "aliases": [ + "CVE-2025-0937" + ], + "details": "Nomad Community and Nomad Enterprise (\"Nomad\") event stream configured with a wildcard namespace can bypass the ACL Policy allowing reads on other namespaces.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0937" + }, + { + "type": "WEB", + "url": "https://discuss.hashicorp.com/t/hcsec-2025-02-nomad-vulnerable-to-event-stream-namespace-acl-policy-bypass-through-wildcard-namespace/73191" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T19:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-6wvf-533r-84vc/GHSA-6wvf-533r-84vc.json b/advisories/unreviewed/2025/02/GHSA-6wvf-533r-84vc/GHSA-6wvf-533r-84vc.json new file mode 100644 index 00000000000..8b0da112ab5 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-6wvf-533r-84vc/GHSA-6wvf-533r-84vc.json @@ -0,0 +1,60 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6wvf-533r-84vc", + "modified": "2025-02-12T21:31:53Z", + "published": "2025-02-12T21:31:53Z", + "aliases": [ + "CVE-2025-1215" + ], + "details": "A vulnerability classified as problematic was found in vim up to 9.1.1096. This vulnerability affects unknown code of the file src/main.c. The manipulation of the argument --log leads to memory corruption. It is possible to launch the attack on the local host. Upgrading to version 9.1.1097 is able to address this issue. The patch is identified as c5654b84480822817bb7b69ebc97c174c91185e9. It is recommended to upgrade the affected component.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1215" + }, + { + "type": "WEB", + "url": "https://github.com/vim/vim/issues/16606" + }, + { + "type": "WEB", + "url": "https://github.com/vim/vim/commit/c5654b84480822817bb7b69ebc97c174c91185e9" + }, + { + "type": "WEB", + "url": "https://github.com/vim/vim/releases/tag/v9.1.1097" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.295174" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.295174" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.497546" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T19:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-7m23-4qgm-g7v4/GHSA-7m23-4qgm-g7v4.json b/advisories/unreviewed/2025/02/GHSA-7m23-4qgm-g7v4/GHSA-7m23-4qgm-g7v4.json new file mode 100644 index 00000000000..77e02c5b1ba --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-7m23-4qgm-g7v4/GHSA-7m23-4qgm-g7v4.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7m23-4qgm-g7v4", + "modified": "2025-02-12T21:31:54Z", + "published": "2025-02-12T21:31:54Z", + "aliases": [ + "CVE-2025-1225" + ], + "details": "A vulnerability, which was classified as problematic, has been found in ywoa up to 2024.07.03. This issue affects the function extract of the file c-main/src/main/java/com/redmoon/weixin/aes/XMLParse.java of the component WXCallBack Interface. The manipulation leads to xml external entity reference. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2024.07.04 is able to address this issue. It is recommended to upgrade the affected component.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1225" + }, + { + "type": "WEB", + "url": "https://gitee.com/r1bbit/yimioa/issues/IBI81R" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.295211" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.295211" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-610" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T20:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-7v4m-vwhv-fmx7/GHSA-7v4m-vwhv-fmx7.json b/advisories/unreviewed/2025/02/GHSA-7v4m-vwhv-fmx7/GHSA-7v4m-vwhv-fmx7.json new file mode 100644 index 00000000000..13a8cde4b7c --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-7v4m-vwhv-fmx7/GHSA-7v4m-vwhv-fmx7.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7v4m-vwhv-fmx7", + "modified": "2025-02-12T21:31:53Z", + "published": "2025-02-12T21:31:53Z", + "aliases": [ + "CVE-2025-25343" + ], + "details": "Tenda AC6 V15.03.05.16 firmware has a buffer overflow vulnerability in the formexeCommand function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25343" + }, + { + "type": "WEB", + "url": "https://github.com/wy876/cve/issues/4" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T19:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-844x-j3wf-r5rf/GHSA-844x-j3wf-r5rf.json b/advisories/unreviewed/2025/02/GHSA-844x-j3wf-r5rf/GHSA-844x-j3wf-r5rf.json new file mode 100644 index 00000000000..e243b7b7f80 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-844x-j3wf-r5rf/GHSA-844x-j3wf-r5rf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-844x-j3wf-r5rf", + "modified": "2025-02-12T21:31:53Z", + "published": "2025-02-12T21:31:53Z", + "aliases": [ + "CVE-2025-1146" + ], + "details": "CrowdStrike uses industry-standard TLS (transport layer security) to secure communications from the Falcon sensor to the CrowdStrike cloud. CrowdStrike has identified a validation logic error in the Falcon sensor for Linux, Falcon Kubernetes Admission Controller, and Falcon Container Sensor where our TLS connection routine to the CrowdStrike cloud can incorrectly process server certificate validation. This could allow an attacker with the ability to control network traffic to potentially conduct a man-in-the-middle (MiTM) attack. CrowdStrike identified this issue internally and released a security fix in all Falcon sensor for Linux, Falcon Kubernetes Admission Controller, and Falcon Container Sensor versions 7.06 and above.\n\n \nCrowdStrike identified this issue through our longstanding, rigorous security review process, which has been continually strengthened with deeper source code analysis and ongoing program enhancements as part of our commitment to security resilience. CrowdStrike has no indication of any exploitation of this issue in the wild. CrowdStrike has leveraged its world class threat hunting and intelligence capabilities to actively monitor for signs of abuse or usage of this flaw and will continue to do so. \n\n\nWindows and Mac sensors are not affected by this.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1146" + }, + { + "type": "WEB", + "url": "https://www.crowdstrike.com/security-advisories/cve-2025-1146" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-296" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T19:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-8c29-j4ww-m2vq/GHSA-8c29-j4ww-m2vq.json b/advisories/unreviewed/2025/02/GHSA-8c29-j4ww-m2vq/GHSA-8c29-j4ww-m2vq.json index d72a84b97f7..46938540fd7 100644 --- a/advisories/unreviewed/2025/02/GHSA-8c29-j4ww-m2vq/GHSA-8c29-j4ww-m2vq.json +++ b/advisories/unreviewed/2025/02/GHSA-8c29-j4ww-m2vq/GHSA-8c29-j4ww-m2vq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8c29-j4ww-m2vq", - "modified": "2025-02-03T21:31:49Z", + "modified": "2025-02-12T21:31:51Z", "published": "2025-02-03T21:31:49Z", "aliases": [ "CVE-2024-57237" ], "details": "Prolink 4G LTE Mobile Wi-Fi DL-7203E V4.0.0B05 is vulnerable to Cross Site Scripting (XSS) in the /reqproc/proc_get endpoint. The vulnerability arises because the cmd parameter does not properly sanitize input and the response is served with a Content-Type of text/html. This behavior allows the browser to execute injected JavaScript code.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-03T19:15:13Z" diff --git a/advisories/unreviewed/2025/02/GHSA-9jp4-rjhp-hhpx/GHSA-9jp4-rjhp-hhpx.json b/advisories/unreviewed/2025/02/GHSA-9jp4-rjhp-hhpx/GHSA-9jp4-rjhp-hhpx.json new file mode 100644 index 00000000000..444ec8bc1cb --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-9jp4-rjhp-hhpx/GHSA-9jp4-rjhp-hhpx.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9jp4-rjhp-hhpx", + "modified": "2025-02-12T21:31:53Z", + "published": "2025-02-12T21:31:53Z", + "aliases": [ + "CVE-2025-1216" + ], + "details": "A vulnerability, which was classified as critical, has been found in ywoa up to 2024.07.03. This issue affects the function selectNoticeList of the file com/cloudweb/oa/mapper/xml/OaNoticeMapper.xml. The manipulation of the argument sort leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2024.07.04 is able to address this issue. It is recommended to upgrade the affected component.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1216" + }, + { + "type": "WEB", + "url": "https://gitee.com/r1bbit/yimioa/issues/IBI74K" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.295175" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.295175" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T19:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-9vcr-v878-4x73/GHSA-9vcr-v878-4x73.json b/advisories/unreviewed/2025/02/GHSA-9vcr-v878-4x73/GHSA-9vcr-v878-4x73.json new file mode 100644 index 00000000000..3cc457a1da0 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-9vcr-v878-4x73/GHSA-9vcr-v878-4x73.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9vcr-v878-4x73", + "modified": "2025-02-12T21:31:54Z", + "published": "2025-02-12T21:31:54Z", + "aliases": [ + "CVE-2025-1226" + ], + "details": "A vulnerability was found in ywoa up to 2024.07.03. It has been declared as critical. This vulnerability affects unknown code of the file /oa/setup/setup.jsp. The manipulation leads to improper authorization. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2024.07.04 is able to address this issue. It is recommended to upgrade the affected component.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1226" + }, + { + "type": "WEB", + "url": "https://gitee.com/r1bbit/yimioa/issues/IBI7PG" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.295216" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.295216" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T21:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-fq6v-7fwh-v7j7/GHSA-fq6v-7fwh-v7j7.json b/advisories/unreviewed/2025/02/GHSA-fq6v-7fwh-v7j7/GHSA-fq6v-7fwh-v7j7.json index b12a5f23a6c..01d5ac07fbb 100644 --- a/advisories/unreviewed/2025/02/GHSA-fq6v-7fwh-v7j7/GHSA-fq6v-7fwh-v7j7.json +++ b/advisories/unreviewed/2025/02/GHSA-fq6v-7fwh-v7j7/GHSA-fq6v-7fwh-v7j7.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/02/GHSA-g2v4-64gq-v8vx/GHSA-g2v4-64gq-v8vx.json b/advisories/unreviewed/2025/02/GHSA-g2v4-64gq-v8vx/GHSA-g2v4-64gq-v8vx.json new file mode 100644 index 00000000000..d68ab7c03c5 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-g2v4-64gq-v8vx/GHSA-g2v4-64gq-v8vx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g2v4-64gq-v8vx", + "modified": "2025-02-12T21:31:54Z", + "published": "2025-02-12T21:31:54Z", + "aliases": [ + "CVE-2025-0109" + ], + "details": "An unauthenticated file deletion vulnerability in the Palo Alto Networks PAN-OS management web interface enables an unauthenticated attacker with network access to the management web interface to delete certain files as the “nobody” user; this includes limited logs and configuration files but does not include system files.\n\n\nYou can greatly reduce the risk of this issue by restricting access to the management web interface to only trusted internal IP addresses according to our recommended best practices deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 .\n\nThis issue does not affect Cloud NGFW or Prisma Access software.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:M/U:Amber" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0109" + }, + { + "type": "WEB", + "url": "https://security.paloaltonetworks.com/CVE-2024-0109" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-73" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T21:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-h5xq-6mp2-ff67/GHSA-h5xq-6mp2-ff67.json b/advisories/unreviewed/2025/02/GHSA-h5xq-6mp2-ff67/GHSA-h5xq-6mp2-ff67.json new file mode 100644 index 00000000000..bc96f3d22fa --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-h5xq-6mp2-ff67/GHSA-h5xq-6mp2-ff67.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h5xq-6mp2-ff67", + "modified": "2025-02-12T21:31:54Z", + "published": "2025-02-12T21:31:54Z", + "aliases": [ + "CVE-2025-0110" + ], + "details": "A command injection vulnerability in the Palo Alto Networks PAN-OS OpenConfig plugin enables an authenticated administrator with the ability to make gNMI requests to the PAN-OS management web interface to bypass system restrictions and run arbitrary commands. The commands are run as the “__openconfig” user (which has the Device Administrator role) on the firewall.\n\nYou can greatly reduce the risk of this issue by restricting access to the management web interface to only trusted internal IP addresses according to our recommended best practices deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 .", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:M/U:Amber" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0110" + }, + { + "type": "WEB", + "url": "https://security.paloaltonetworks.com/CVE-2025-0110" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T21:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-hvqq-hwj3-c54m/GHSA-hvqq-hwj3-c54m.json b/advisories/unreviewed/2025/02/GHSA-hvqq-hwj3-c54m/GHSA-hvqq-hwj3-c54m.json new file mode 100644 index 00000000000..15c40856fd5 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-hvqq-hwj3-c54m/GHSA-hvqq-hwj3-c54m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hvqq-hwj3-c54m", + "modified": "2025-02-12T21:31:53Z", + "published": "2025-02-12T21:31:53Z", + "aliases": [ + "CVE-2025-0108" + ], + "details": "An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to bypass the authentication otherwise required by the PAN-OS management web interface and invoke certain PHP scripts. While invoking these PHP scripts does not enable remote code execution, it can negatively impact integrity and confidentiality of PAN-OS.\n\nYou can greatly reduce the risk of this issue by restricting access to the management web interface to only trusted internal IP addresses according to our recommended best practices deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 .\n\nThis issue does not affect Cloud NGFW or Prisma Access software.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:M/U:Amber" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0108" + }, + { + "type": "WEB", + "url": "https://security.paloaltonetworks.com/CVE-2025-0108" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T21:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-j8x5-54p6-cqvm/GHSA-j8x5-54p6-cqvm.json b/advisories/unreviewed/2025/02/GHSA-j8x5-54p6-cqvm/GHSA-j8x5-54p6-cqvm.json new file mode 100644 index 00000000000..ef222a4c448 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-j8x5-54p6-cqvm/GHSA-j8x5-54p6-cqvm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j8x5-54p6-cqvm", + "modified": "2025-02-12T21:31:54Z", + "published": "2025-02-12T21:31:54Z", + "aliases": [ + "CVE-2025-0113" + ], + "details": "A problem with the network isolation mechanism of the Palo Alto Networks Cortex XDR Broker VM allows attackers unauthorized access to Docker containers from the host network used by Broker VM. This may allow access to read files sent for analysis and logs transmitted by the Cortex XDR Agent to the Cortex XDR server.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:C/RE:M/U:Amber" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0113" + }, + { + "type": "WEB", + "url": "https://security.paloaltonetworks.com/CVE-2024-0113" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-424" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T21:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-m5q8-8x36-w25p/GHSA-m5q8-8x36-w25p.json b/advisories/unreviewed/2025/02/GHSA-m5q8-8x36-w25p/GHSA-m5q8-8x36-w25p.json index 1387343ed38..63628d7b379 100644 --- a/advisories/unreviewed/2025/02/GHSA-m5q8-8x36-w25p/GHSA-m5q8-8x36-w25p.json +++ b/advisories/unreviewed/2025/02/GHSA-m5q8-8x36-w25p/GHSA-m5q8-8x36-w25p.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-m5q8-8x36-w25p", - "modified": "2025-02-06T18:31:05Z", + "modified": "2025-02-12T21:31:52Z", "published": "2025-02-06T18:31:05Z", "aliases": [ "CVE-2025-0994" ], "details": "Trimble Cityworks versions prior to 15.8.9 and Cityworks with office companion versions prior to 23.10 are vulnerable to a deserialization vulnerability. This could allow an authenticated user to perform a remote code execution attack against a customer’s Microsoft Internet Information Services (IIS) web server.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2025/02/GHSA-wmcv-pj3g-38rp/GHSA-wmcv-pj3g-38rp.json b/advisories/unreviewed/2025/02/GHSA-wmcv-pj3g-38rp/GHSA-wmcv-pj3g-38rp.json new file mode 100644 index 00000000000..cc7e4f48288 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-wmcv-pj3g-38rp/GHSA-wmcv-pj3g-38rp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wmcv-pj3g-38rp", + "modified": "2025-02-12T21:31:54Z", + "published": "2025-02-12T21:31:54Z", + "aliases": [ + "CVE-2025-0111" + ], + "details": "An authenticated file read vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker with network access to the management web interface to read files on the PAN-OS filesystem that are readable by the “nobody” user.\n\nYou can greatly reduce the risk of this issue by restricting access to the management web interface to only trusted internal IP addresses according to our recommended best practices deployment guidelines https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431 .\n\n\n\nThis issue does not affect Cloud NGFW or Prisma Access software.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:M/U:Amber" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0111" + }, + { + "type": "WEB", + "url": "https://security.paloaltonetworks.com/CVE-2025-0111" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-73" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T21:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-xpm3-5wvv-pxfh/GHSA-xpm3-5wvv-pxfh.json b/advisories/unreviewed/2025/02/GHSA-xpm3-5wvv-pxfh/GHSA-xpm3-5wvv-pxfh.json new file mode 100644 index 00000000000..8b10fc56de1 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-xpm3-5wvv-pxfh/GHSA-xpm3-5wvv-pxfh.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xpm3-5wvv-pxfh", + "modified": "2025-02-12T21:31:54Z", + "published": "2025-02-12T21:31:53Z", + "aliases": [ + "CVE-2025-1224" + ], + "details": "A vulnerability classified as critical was found in ywoa up to 2024.07.03. This vulnerability affects the function listNameBySql of the file com/cloudweb/oa/mapper/xml/UserMapper.xml. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2024.07.04 is able to address this issue. It is recommended to upgrade the affected component.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1224" + }, + { + "type": "WEB", + "url": "https://gitee.com/r1bbit/yimioa/issues/IBI731" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.295210" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.295210" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-12T20:15:40Z" + } +} \ No newline at end of file