From 4e5c3e6086134527299507bbf040609754fc9123 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 8 Apr 2025 15:32:35 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-85q4-chqw-w4gj.json | 6 +++- .../GHSA-cc3r-wqmp-6h2g.json | 3 +- .../GHSA-cqj2-v4jv-jmhc.json | 4 ++- .../GHSA-mffv-q36c-x853.json | 2 +- .../GHSA-w5c5-f46c-8j6x.json | 3 +- .../GHSA-xc2q-prrj-8cp6.json | 3 +- .../GHSA-6rqp-hf8j-7x29.json | 2 +- .../GHSA-cpmq-c39j-pm97.json | 1 + .../GHSA-4hjm-m2c9-868g.json | 4 ++- .../GHSA-5gr3-55rj-mm4c.json | 4 ++- .../GHSA-62pr-mr57-m7xm.json | 4 ++- .../GHSA-rw5h-h7xq-wc78.json | 4 ++- .../GHSA-vv74-wh7g-52xw.json | 4 ++- .../GHSA-596j-m7rx-58pm.json | 6 ++-- .../GHSA-5vpv-8mpr-5w3p.json | 6 ++-- .../GHSA-fw35-8hjm-jw2p.json | 6 +++- .../GHSA-wh9j-8hrm-2g7r.json | 4 +-- .../GHSA-x8m7-f4f6-46c2.json | 4 +-- .../GHSA-hgfg-h695-mm36.json | 4 ++- .../GHSA-wgx4-5qgj-vf8m.json | 4 ++- .../GHSA-48pm-jhrv-8jrv.json | 36 +++++++++++++++++++ .../GHSA-57cc-74xg-cqvg.json | 15 +++++--- .../GHSA-6j35-rq42-fv6v.json | 15 +++++--- .../GHSA-6xq3-jgfv-2jh3.json | 36 +++++++++++++++++++ .../GHSA-79gc-w327-w4f2.json | 36 +++++++++++++++++++ .../GHSA-7fmq-3cjw-pvhf.json | 36 +++++++++++++++++++ .../GHSA-83g9-r3gv-pq9c.json | 36 +++++++++++++++++++ .../GHSA-8cv2-v24w-8j7h.json | 3 +- .../GHSA-962v-6x3f-5mw4.json | 36 +++++++++++++++++++ .../GHSA-9xjh-c5x2-3cqm.json | 3 +- .../GHSA-c3q8-4394-xw76.json | 6 +++- .../GHSA-cwrm-9wh5-jq4m.json | 36 +++++++++++++++++++ .../GHSA-fr9r-mwp9-h3cg.json | 4 ++- .../GHSA-h57j-9v3r-347h.json | 3 +- .../GHSA-h7mx-548v-cr9r.json | 6 +++- .../GHSA-hvmf-h8x8-34xp.json | 3 +- .../GHSA-j27p-5p5f-gjjv.json | 36 +++++++++++++++++++ .../GHSA-j94p-gv3v-cg5q.json | 36 +++++++++++++++++++ .../GHSA-jjr5-fpcg-gc53.json | 3 +- .../GHSA-jr95-cvrj-r656.json | 36 +++++++++++++++++++ .../GHSA-m9g2-wm3w-q6rv.json | 36 +++++++++++++++++++ .../GHSA-p7jp-69j5-crrv.json | 15 +++++--- .../GHSA-q7jr-v677-ww76.json | 36 +++++++++++++++++++ .../GHSA-r5hc-g9j9-f2mf.json | 36 +++++++++++++++++++ .../GHSA-v5pc-4rpg-jmh7.json | 36 +++++++++++++++++++ .../GHSA-vh9f-239f-vjhp.json | 6 +++- .../GHSA-vx7x-6r6q-pwq4.json | 36 +++++++++++++++++++ .../GHSA-wq26-hpcc-wh38.json | 36 +++++++++++++++++++ .../GHSA-x4c3-chf9-qj4x.json | 36 +++++++++++++++++++ .../GHSA-xw8c-3xf4-r67j.json | 15 +++++--- 50 files changed, 739 insertions(+), 48 deletions(-) create mode 100644 advisories/unreviewed/2025/04/GHSA-48pm-jhrv-8jrv/GHSA-48pm-jhrv-8jrv.json create mode 100644 advisories/unreviewed/2025/04/GHSA-6xq3-jgfv-2jh3/GHSA-6xq3-jgfv-2jh3.json create mode 100644 advisories/unreviewed/2025/04/GHSA-79gc-w327-w4f2/GHSA-79gc-w327-w4f2.json create mode 100644 advisories/unreviewed/2025/04/GHSA-7fmq-3cjw-pvhf/GHSA-7fmq-3cjw-pvhf.json create mode 100644 advisories/unreviewed/2025/04/GHSA-83g9-r3gv-pq9c/GHSA-83g9-r3gv-pq9c.json create mode 100644 advisories/unreviewed/2025/04/GHSA-962v-6x3f-5mw4/GHSA-962v-6x3f-5mw4.json create mode 100644 advisories/unreviewed/2025/04/GHSA-cwrm-9wh5-jq4m/GHSA-cwrm-9wh5-jq4m.json create mode 100644 advisories/unreviewed/2025/04/GHSA-j27p-5p5f-gjjv/GHSA-j27p-5p5f-gjjv.json create mode 100644 advisories/unreviewed/2025/04/GHSA-j94p-gv3v-cg5q/GHSA-j94p-gv3v-cg5q.json create mode 100644 advisories/unreviewed/2025/04/GHSA-jr95-cvrj-r656/GHSA-jr95-cvrj-r656.json create mode 100644 advisories/unreviewed/2025/04/GHSA-m9g2-wm3w-q6rv/GHSA-m9g2-wm3w-q6rv.json create mode 100644 advisories/unreviewed/2025/04/GHSA-q7jr-v677-ww76/GHSA-q7jr-v677-ww76.json create mode 100644 advisories/unreviewed/2025/04/GHSA-r5hc-g9j9-f2mf/GHSA-r5hc-g9j9-f2mf.json create mode 100644 advisories/unreviewed/2025/04/GHSA-v5pc-4rpg-jmh7/GHSA-v5pc-4rpg-jmh7.json create mode 100644 advisories/unreviewed/2025/04/GHSA-vx7x-6r6q-pwq4/GHSA-vx7x-6r6q-pwq4.json create mode 100644 advisories/unreviewed/2025/04/GHSA-wq26-hpcc-wh38/GHSA-wq26-hpcc-wh38.json create mode 100644 advisories/unreviewed/2025/04/GHSA-x4c3-chf9-qj4x/GHSA-x4c3-chf9-qj4x.json diff --git a/advisories/unreviewed/2023/01/GHSA-85q4-chqw-w4gj/GHSA-85q4-chqw-w4gj.json b/advisories/unreviewed/2023/01/GHSA-85q4-chqw-w4gj/GHSA-85q4-chqw-w4gj.json index de74706348d..a46be0e225c 100644 --- a/advisories/unreviewed/2023/01/GHSA-85q4-chqw-w4gj/GHSA-85q4-chqw-w4gj.json +++ b/advisories/unreviewed/2023/01/GHSA-85q4-chqw-w4gj/GHSA-85q4-chqw-w4gj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-85q4-chqw-w4gj", - "modified": "2023-01-23T15:30:33Z", + "modified": "2025-04-08T15:30:37Z", "published": "2023-01-12T21:30:30Z", "aliases": [ "CVE-2022-4842" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-4842" }, + { + "type": "WEB", + "url": "https://lore.kernel.org/ntfs3/784f82c4-de71-b8c3-afd6-468869a369af%40paragon-software.com/T/#t" + }, { "type": "WEB", "url": "https://lore.kernel.org/ntfs3/784f82c4-de71-b8c3-afd6-468869a369af@paragon-software.com/T/#t" diff --git a/advisories/unreviewed/2023/01/GHSA-cc3r-wqmp-6h2g/GHSA-cc3r-wqmp-6h2g.json b/advisories/unreviewed/2023/01/GHSA-cc3r-wqmp-6h2g/GHSA-cc3r-wqmp-6h2g.json index 11943f8304b..49f3c13e4b8 100644 --- a/advisories/unreviewed/2023/01/GHSA-cc3r-wqmp-6h2g/GHSA-cc3r-wqmp-6h2g.json +++ b/advisories/unreviewed/2023/01/GHSA-cc3r-wqmp-6h2g/GHSA-cc3r-wqmp-6h2g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cc3r-wqmp-6h2g", - "modified": "2023-01-23T18:30:20Z", + "modified": "2025-04-08T15:30:39Z", "published": "2023-01-13T00:30:38Z", "aliases": [ "CVE-2022-25027" @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-287", "CWE-640" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/01/GHSA-cqj2-v4jv-jmhc/GHSA-cqj2-v4jv-jmhc.json b/advisories/unreviewed/2023/01/GHSA-cqj2-v4jv-jmhc/GHSA-cqj2-v4jv-jmhc.json index 9e6233eae71..a8627ceeacc 100644 --- a/advisories/unreviewed/2023/01/GHSA-cqj2-v4jv-jmhc/GHSA-cqj2-v4jv-jmhc.json +++ b/advisories/unreviewed/2023/01/GHSA-cqj2-v4jv-jmhc/GHSA-cqj2-v4jv-jmhc.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-732" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/01/GHSA-mffv-q36c-x853/GHSA-mffv-q36c-x853.json b/advisories/unreviewed/2023/01/GHSA-mffv-q36c-x853/GHSA-mffv-q36c-x853.json index 8157bd526a2..f482dad9fcd 100644 --- a/advisories/unreviewed/2023/01/GHSA-mffv-q36c-x853/GHSA-mffv-q36c-x853.json +++ b/advisories/unreviewed/2023/01/GHSA-mffv-q36c-x853/GHSA-mffv-q36c-x853.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mffv-q36c-x853", - "modified": "2023-01-23T18:30:19Z", + "modified": "2025-04-08T15:30:39Z", "published": "2023-01-13T00:30:38Z", "aliases": [ "CVE-2022-25026" diff --git a/advisories/unreviewed/2023/01/GHSA-w5c5-f46c-8j6x/GHSA-w5c5-f46c-8j6x.json b/advisories/unreviewed/2023/01/GHSA-w5c5-f46c-8j6x/GHSA-w5c5-f46c-8j6x.json index 8a78da01109..50f65beb6fe 100644 --- a/advisories/unreviewed/2023/01/GHSA-w5c5-f46c-8j6x/GHSA-w5c5-f46c-8j6x.json +++ b/advisories/unreviewed/2023/01/GHSA-w5c5-f46c-8j6x/GHSA-w5c5-f46c-8j6x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w5c5-f46c-8j6x", - "modified": "2023-01-23T18:30:19Z", + "modified": "2025-04-08T15:30:38Z", "published": "2023-01-13T00:30:39Z", "aliases": [ "CVE-2017-5242" @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-321", "CWE-330" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/06/GHSA-xc2q-prrj-8cp6/GHSA-xc2q-prrj-8cp6.json b/advisories/unreviewed/2023/06/GHSA-xc2q-prrj-8cp6/GHSA-xc2q-prrj-8cp6.json index b5dcb7aa4e2..e55c6b066a7 100644 --- a/advisories/unreviewed/2023/06/GHSA-xc2q-prrj-8cp6/GHSA-xc2q-prrj-8cp6.json +++ b/advisories/unreviewed/2023/06/GHSA-xc2q-prrj-8cp6/GHSA-xc2q-prrj-8cp6.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-668" + "CWE-668", + "CWE-908" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/07/GHSA-6rqp-hf8j-7x29/GHSA-6rqp-hf8j-7x29.json b/advisories/unreviewed/2023/07/GHSA-6rqp-hf8j-7x29/GHSA-6rqp-hf8j-7x29.json index d0da350c7ff..886c0529b65 100644 --- a/advisories/unreviewed/2023/07/GHSA-6rqp-hf8j-7x29/GHSA-6rqp-hf8j-7x29.json +++ b/advisories/unreviewed/2023/07/GHSA-6rqp-hf8j-7x29/GHSA-6rqp-hf8j-7x29.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6rqp-hf8j-7x29", - "modified": "2024-04-04T05:31:18Z", + "modified": "2025-04-08T15:30:36Z", "published": "2023-07-06T19:24:06Z", "aliases": [ "CVE-2022-46370" diff --git a/advisories/unreviewed/2023/09/GHSA-cpmq-c39j-pm97/GHSA-cpmq-c39j-pm97.json b/advisories/unreviewed/2023/09/GHSA-cpmq-c39j-pm97/GHSA-cpmq-c39j-pm97.json index 98733fdd4cc..e9ef978e285 100644 --- a/advisories/unreviewed/2023/09/GHSA-cpmq-c39j-pm97/GHSA-cpmq-c39j-pm97.json +++ b/advisories/unreviewed/2023/09/GHSA-cpmq-c39j-pm97/GHSA-cpmq-c39j-pm97.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-416", "CWE-668" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/03/GHSA-4hjm-m2c9-868g/GHSA-4hjm-m2c9-868g.json b/advisories/unreviewed/2024/03/GHSA-4hjm-m2c9-868g/GHSA-4hjm-m2c9-868g.json index 34a4624c596..399d22a3a8c 100644 --- a/advisories/unreviewed/2024/03/GHSA-4hjm-m2c9-868g/GHSA-4hjm-m2c9-868g.json +++ b/advisories/unreviewed/2024/03/GHSA-4hjm-m2c9-868g/GHSA-4hjm-m2c9-868g.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-401" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-5gr3-55rj-mm4c/GHSA-5gr3-55rj-mm4c.json b/advisories/unreviewed/2024/03/GHSA-5gr3-55rj-mm4c/GHSA-5gr3-55rj-mm4c.json index c7fbc7c6eb7..99042711691 100644 --- a/advisories/unreviewed/2024/03/GHSA-5gr3-55rj-mm4c/GHSA-5gr3-55rj-mm4c.json +++ b/advisories/unreviewed/2024/03/GHSA-5gr3-55rj-mm4c/GHSA-5gr3-55rj-mm4c.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-908" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-62pr-mr57-m7xm/GHSA-62pr-mr57-m7xm.json b/advisories/unreviewed/2024/03/GHSA-62pr-mr57-m7xm/GHSA-62pr-mr57-m7xm.json index c5c3b5279ee..1af5b1a7c5b 100644 --- a/advisories/unreviewed/2024/03/GHSA-62pr-mr57-m7xm/GHSA-62pr-mr57-m7xm.json +++ b/advisories/unreviewed/2024/03/GHSA-62pr-mr57-m7xm/GHSA-62pr-mr57-m7xm.json @@ -53,7 +53,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-459" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-rw5h-h7xq-wc78/GHSA-rw5h-h7xq-wc78.json b/advisories/unreviewed/2024/03/GHSA-rw5h-h7xq-wc78/GHSA-rw5h-h7xq-wc78.json index 4c3e5de0e32..3e421a936ca 100644 --- a/advisories/unreviewed/2024/03/GHSA-rw5h-h7xq-wc78/GHSA-rw5h-h7xq-wc78.json +++ b/advisories/unreviewed/2024/03/GHSA-rw5h-h7xq-wc78/GHSA-rw5h-h7xq-wc78.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-476" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-vv74-wh7g-52xw/GHSA-vv74-wh7g-52xw.json b/advisories/unreviewed/2024/03/GHSA-vv74-wh7g-52xw/GHSA-vv74-wh7g-52xw.json index 36ef72671d7..a5f25065a0c 100644 --- a/advisories/unreviewed/2024/03/GHSA-vv74-wh7g-52xw/GHSA-vv74-wh7g-52xw.json +++ b/advisories/unreviewed/2024/03/GHSA-vv74-wh7g-52xw/GHSA-vv74-wh7g-52xw.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-401" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-596j-m7rx-58pm/GHSA-596j-m7rx-58pm.json b/advisories/unreviewed/2024/04/GHSA-596j-m7rx-58pm/GHSA-596j-m7rx-58pm.json index 068edd87f41..1288d6f4acb 100644 --- a/advisories/unreviewed/2024/04/GHSA-596j-m7rx-58pm/GHSA-596j-m7rx-58pm.json +++ b/advisories/unreviewed/2024/04/GHSA-596j-m7rx-58pm/GHSA-596j-m7rx-58pm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-596j-m7rx-58pm", - "modified": "2024-04-12T03:30:44Z", + "modified": "2025-04-08T15:30:58Z", "published": "2024-04-12T03:30:44Z", "aliases": [ "CVE-2024-2137" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-5vpv-8mpr-5w3p/GHSA-5vpv-8mpr-5w3p.json b/advisories/unreviewed/2024/04/GHSA-5vpv-8mpr-5w3p/GHSA-5vpv-8mpr-5w3p.json index 761e539a932..a8582945641 100644 --- a/advisories/unreviewed/2024/04/GHSA-5vpv-8mpr-5w3p/GHSA-5vpv-8mpr-5w3p.json +++ b/advisories/unreviewed/2024/04/GHSA-5vpv-8mpr-5w3p/GHSA-5vpv-8mpr-5w3p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5vpv-8mpr-5w3p", - "modified": "2024-04-11T09:30:56Z", + "modified": "2025-04-08T15:30:56Z", "published": "2024-04-11T09:30:56Z", "aliases": [ "CVE-2024-3285" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-fw35-8hjm-jw2p/GHSA-fw35-8hjm-jw2p.json b/advisories/unreviewed/2024/04/GHSA-fw35-8hjm-jw2p/GHSA-fw35-8hjm-jw2p.json index dadd01fa4fa..c40385063b8 100644 --- a/advisories/unreviewed/2024/04/GHSA-fw35-8hjm-jw2p/GHSA-fw35-8hjm-jw2p.json +++ b/advisories/unreviewed/2024/04/GHSA-fw35-8hjm-jw2p/GHSA-fw35-8hjm-jw2p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fw35-8hjm-jw2p", - "modified": "2024-11-06T18:31:04Z", + "modified": "2025-04-08T15:30:55Z", "published": "2024-04-10T15:30:40Z", "aliases": [ "CVE-2024-27477" @@ -30,6 +30,10 @@ { "type": "WEB", "url": "https://github.com/dead1nfluence/Leantime-POC/blob/main/README.md" + }, + { + "type": "WEB", + "url": "https://www.vicarius.io/vsociety/posts/analyzing-leantime-xss-for-the-fun-time-diving-into-cve-2024-27477-for-a-beginner" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/04/GHSA-wh9j-8hrm-2g7r/GHSA-wh9j-8hrm-2g7r.json b/advisories/unreviewed/2024/04/GHSA-wh9j-8hrm-2g7r/GHSA-wh9j-8hrm-2g7r.json index d59ba43e840..0a5916a0ee8 100644 --- a/advisories/unreviewed/2024/04/GHSA-wh9j-8hrm-2g7r/GHSA-wh9j-8hrm-2g7r.json +++ b/advisories/unreviewed/2024/04/GHSA-wh9j-8hrm-2g7r/GHSA-wh9j-8hrm-2g7r.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-wh9j-8hrm-2g7r", - "modified": "2024-04-10T18:30:47Z", + "modified": "2025-04-08T15:30:55Z", "published": "2024-04-10T18:30:47Z", "aliases": [ "CVE-2024-31282" ], - "details": "URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Appcheap.Io App Builder.This issue affects App Builder: from n/a through 3.8.7.\n\n", + "details": "URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Appcheap.Io App Builder.This issue affects App Builder: from n/a through 3.8.7.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-x8m7-f4f6-46c2/GHSA-x8m7-f4f6-46c2.json b/advisories/unreviewed/2024/04/GHSA-x8m7-f4f6-46c2/GHSA-x8m7-f4f6-46c2.json index 49486793b8a..f1bec25ab1e 100644 --- a/advisories/unreviewed/2024/04/GHSA-x8m7-f4f6-46c2/GHSA-x8m7-f4f6-46c2.json +++ b/advisories/unreviewed/2024/04/GHSA-x8m7-f4f6-46c2/GHSA-x8m7-f4f6-46c2.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-x8m7-f4f6-46c2", - "modified": "2024-04-10T18:30:47Z", + "modified": "2025-04-08T15:30:55Z", "published": "2024-04-10T18:30:47Z", "aliases": [ "CVE-2024-31298" ], - "details": "Insertion of Sensitive Information into Log File vulnerability in Joel Hardi User Spam Remover.This issue affects User Spam Remover: from n/a through 1.0.\n\n", + "details": "Insertion of Sensitive Information into Log File vulnerability in Joel Hardi User Spam Remover.This issue affects User Spam Remover: from n/a through 1.0.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2025/03/GHSA-hgfg-h695-mm36/GHSA-hgfg-h695-mm36.json b/advisories/unreviewed/2025/03/GHSA-hgfg-h695-mm36/GHSA-hgfg-h695-mm36.json index a641211d984..211e2b7d2e4 100644 --- a/advisories/unreviewed/2025/03/GHSA-hgfg-h695-mm36/GHSA-hgfg-h695-mm36.json +++ b/advisories/unreviewed/2025/03/GHSA-hgfg-h695-mm36/GHSA-hgfg-h695-mm36.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-wgx4-5qgj-vf8m/GHSA-wgx4-5qgj-vf8m.json b/advisories/unreviewed/2025/03/GHSA-wgx4-5qgj-vf8m/GHSA-wgx4-5qgj-vf8m.json index 57693ee05f5..c03bd265079 100644 --- a/advisories/unreviewed/2025/03/GHSA-wgx4-5qgj-vf8m/GHSA-wgx4-5qgj-vf8m.json +++ b/advisories/unreviewed/2025/03/GHSA-wgx4-5qgj-vf8m/GHSA-wgx4-5qgj-vf8m.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-48pm-jhrv-8jrv/GHSA-48pm-jhrv-8jrv.json b/advisories/unreviewed/2025/04/GHSA-48pm-jhrv-8jrv/GHSA-48pm-jhrv-8jrv.json new file mode 100644 index 00000000000..922f83e1847 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-48pm-jhrv-8jrv/GHSA-48pm-jhrv-8jrv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-48pm-jhrv-8jrv", + "modified": "2025-04-08T15:31:04Z", + "published": "2025-04-08T15:31:04Z", + "aliases": [ + "CVE-2023-37930" + ], + "details": "Multiple issues including the use of uninitialized ressources [CWE-908] and excessive iteration [CWE-834] vulnerabilities in Fortinet FortiOS SSL VPN webmode version 7.4.0, version 7.2.0 through 7.2.5, version 7.0.1 through 7.0.11 and version 6.4.7 through 6.4.14 and Fortinet FortiProxy SSL VPN webmode version 7.2.0 through 7.2.6 and version 7.0.0 through 7.0.12 allows a VPN user to corrupt memory potentially leading to code or commands execution via specifically crafted requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-37930" + }, + { + "type": "WEB", + "url": "https://fortiguard.com/psirt/FG-IR-23-165" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-908" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T14:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-57cc-74xg-cqvg/GHSA-57cc-74xg-cqvg.json b/advisories/unreviewed/2025/04/GHSA-57cc-74xg-cqvg/GHSA-57cc-74xg-cqvg.json index c86abab81ac..a34d4a1ddac 100644 --- a/advisories/unreviewed/2025/04/GHSA-57cc-74xg-cqvg/GHSA-57cc-74xg-cqvg.json +++ b/advisories/unreviewed/2025/04/GHSA-57cc-74xg-cqvg/GHSA-57cc-74xg-cqvg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-57cc-74xg-cqvg", - "modified": "2025-04-07T21:32:08Z", + "modified": "2025-04-08T15:31:02Z", "published": "2025-04-07T21:32:08Z", "aliases": [ "CVE-2025-29478" ], "details": "An issue in fluent-bit v.3.7.2 allows a local attacker to cause a denial of service via the cfl_list_size in cfl_list.h:165.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-07T20:15:20Z" diff --git a/advisories/unreviewed/2025/04/GHSA-6j35-rq42-fv6v/GHSA-6j35-rq42-fv6v.json b/advisories/unreviewed/2025/04/GHSA-6j35-rq42-fv6v/GHSA-6j35-rq42-fv6v.json index a88b7efe6f3..5238c64e7a3 100644 --- a/advisories/unreviewed/2025/04/GHSA-6j35-rq42-fv6v/GHSA-6j35-rq42-fv6v.json +++ b/advisories/unreviewed/2025/04/GHSA-6j35-rq42-fv6v/GHSA-6j35-rq42-fv6v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6j35-rq42-fv6v", - "modified": "2025-04-07T21:32:08Z", + "modified": "2025-04-08T15:31:02Z", "published": "2025-04-07T21:32:08Z", "aliases": [ "CVE-2025-29087" ], "details": "Sqlite 3.49.0 is susceptible to integer overflow through the concat function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-190" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-07T20:15:20Z" diff --git a/advisories/unreviewed/2025/04/GHSA-6xq3-jgfv-2jh3/GHSA-6xq3-jgfv-2jh3.json b/advisories/unreviewed/2025/04/GHSA-6xq3-jgfv-2jh3/GHSA-6xq3-jgfv-2jh3.json new file mode 100644 index 00000000000..555d8eb81a1 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6xq3-jgfv-2jh3/GHSA-6xq3-jgfv-2jh3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6xq3-jgfv-2jh3", + "modified": "2025-04-08T15:31:06Z", + "published": "2025-04-08T15:31:06Z", + "aliases": [ + "CVE-2025-32406" + ], + "details": "An XXE issue in the Director NBR component in NAKIVO Backup & Replication 10.3.x through 11.0.1 before 11.0.2 allows remote attackers fetch and parse the XML response.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32406" + }, + { + "type": "WEB", + "url": "https://helpcenter.nakivo.com/Knowledge-Base/Content/Security-Advisory/CVE-2025-32406.htm" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-611" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T15:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-79gc-w327-w4f2/GHSA-79gc-w327-w4f2.json b/advisories/unreviewed/2025/04/GHSA-79gc-w327-w4f2/GHSA-79gc-w327-w4f2.json new file mode 100644 index 00000000000..1dfde8c3004 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-79gc-w327-w4f2/GHSA-79gc-w327-w4f2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-79gc-w327-w4f2", + "modified": "2025-04-08T15:31:05Z", + "published": "2025-04-08T15:31:05Z", + "aliases": [ + "CVE-2024-32122" + ], + "details": "A storing passwords in a recoverable format in Fortinet FortiOS versions 7.2.0 through 7.2.1 allows attacker to information disclosure via modification of LDAP server IP to point to a malicious server.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-32122" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-111" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-257" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T14:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-7fmq-3cjw-pvhf/GHSA-7fmq-3cjw-pvhf.json b/advisories/unreviewed/2025/04/GHSA-7fmq-3cjw-pvhf/GHSA-7fmq-3cjw-pvhf.json new file mode 100644 index 00000000000..dea8201fdd8 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-7fmq-3cjw-pvhf/GHSA-7fmq-3cjw-pvhf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7fmq-3cjw-pvhf", + "modified": "2025-04-08T15:31:06Z", + "published": "2025-04-08T15:31:06Z", + "aliases": [ + "CVE-2025-22459" + ], + "details": "Improper certificate validation in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote unauthenticated attacker to intercept limited traffic between clients and servers.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22459" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-EPM-April-2025-for-EPM-2024-and-EPM-2022-SU6" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-296" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T15:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-83g9-r3gv-pq9c/GHSA-83g9-r3gv-pq9c.json b/advisories/unreviewed/2025/04/GHSA-83g9-r3gv-pq9c/GHSA-83g9-r3gv-pq9c.json new file mode 100644 index 00000000000..c95e626f05f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-83g9-r3gv-pq9c/GHSA-83g9-r3gv-pq9c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-83g9-r3gv-pq9c", + "modified": "2025-04-08T15:31:05Z", + "published": "2025-04-08T15:31:05Z", + "aliases": [ + "CVE-2024-54024" + ], + "details": "An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiIsolator before version 2.4.6 allows a privileged attacker with super-admin profile and CLI access to execute unauthorized code via specifically crafted HTTP requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54024" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-397" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T14:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8cv2-v24w-8j7h/GHSA-8cv2-v24w-8j7h.json b/advisories/unreviewed/2025/04/GHSA-8cv2-v24w-8j7h/GHSA-8cv2-v24w-8j7h.json index fded84ac1d5..c063d642d60 100644 --- a/advisories/unreviewed/2025/04/GHSA-8cv2-v24w-8j7h/GHSA-8cv2-v24w-8j7h.json +++ b/advisories/unreviewed/2025/04/GHSA-8cv2-v24w-8j7h/GHSA-8cv2-v24w-8j7h.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-962v-6x3f-5mw4/GHSA-962v-6x3f-5mw4.json b/advisories/unreviewed/2025/04/GHSA-962v-6x3f-5mw4/GHSA-962v-6x3f-5mw4.json new file mode 100644 index 00000000000..e384303821a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-962v-6x3f-5mw4/GHSA-962v-6x3f-5mw4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-962v-6x3f-5mw4", + "modified": "2025-04-08T15:31:06Z", + "published": "2025-04-08T15:31:06Z", + "aliases": [ + "CVE-2025-22855" + ], + "details": "An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Fortinet FortiClient before 7.4.1 may allow the EMS administrator to send messages containing javascript code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22855" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-23-344" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T14:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-9xjh-c5x2-3cqm/GHSA-9xjh-c5x2-3cqm.json b/advisories/unreviewed/2025/04/GHSA-9xjh-c5x2-3cqm/GHSA-9xjh-c5x2-3cqm.json index 9b8b7ca1361..7f8bae44497 100644 --- a/advisories/unreviewed/2025/04/GHSA-9xjh-c5x2-3cqm/GHSA-9xjh-c5x2-3cqm.json +++ b/advisories/unreviewed/2025/04/GHSA-9xjh-c5x2-3cqm/GHSA-9xjh-c5x2-3cqm.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-c3q8-4394-xw76/GHSA-c3q8-4394-xw76.json b/advisories/unreviewed/2025/04/GHSA-c3q8-4394-xw76/GHSA-c3q8-4394-xw76.json index acf719f9dac..80e5022f45e 100644 --- a/advisories/unreviewed/2025/04/GHSA-c3q8-4394-xw76/GHSA-c3q8-4394-xw76.json +++ b/advisories/unreviewed/2025/04/GHSA-c3q8-4394-xw76/GHSA-c3q8-4394-xw76.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c3q8-4394-xw76", - "modified": "2025-04-02T15:31:32Z", + "modified": "2025-04-08T15:30:59Z", "published": "2025-04-02T03:31:42Z", "aliases": [ "CVE-2025-3067" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2025/04/GHSA-cwrm-9wh5-jq4m/GHSA-cwrm-9wh5-jq4m.json b/advisories/unreviewed/2025/04/GHSA-cwrm-9wh5-jq4m/GHSA-cwrm-9wh5-jq4m.json new file mode 100644 index 00000000000..3e5a6f15338 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-cwrm-9wh5-jq4m/GHSA-cwrm-9wh5-jq4m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cwrm-9wh5-jq4m", + "modified": "2025-04-08T15:31:05Z", + "published": "2025-04-08T15:31:05Z", + "aliases": [ + "CVE-2024-46671" + ], + "details": "An Incorrect User Management vulnerability [CWE-286] in FortiWeb version 7.6.2 and below, version 7.4.6 and below, version 7.2.10 and below, version 7.0.11 and below widgets dashboard may allow an authenticated attacker with at least read-only admin permission to perform operations on the dashboard of other administrators via crafted requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46671" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-184" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-286" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T14:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fr9r-mwp9-h3cg/GHSA-fr9r-mwp9-h3cg.json b/advisories/unreviewed/2025/04/GHSA-fr9r-mwp9-h3cg/GHSA-fr9r-mwp9-h3cg.json index c785c617bf3..f0873223479 100644 --- a/advisories/unreviewed/2025/04/GHSA-fr9r-mwp9-h3cg/GHSA-fr9r-mwp9-h3cg.json +++ b/advisories/unreviewed/2025/04/GHSA-fr9r-mwp9-h3cg/GHSA-fr9r-mwp9-h3cg.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-926" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-h57j-9v3r-347h/GHSA-h57j-9v3r-347h.json b/advisories/unreviewed/2025/04/GHSA-h57j-9v3r-347h/GHSA-h57j-9v3r-347h.json index 517572dc712..d3251f8e18e 100644 --- a/advisories/unreviewed/2025/04/GHSA-h57j-9v3r-347h/GHSA-h57j-9v3r-347h.json +++ b/advisories/unreviewed/2025/04/GHSA-h57j-9v3r-347h/GHSA-h57j-9v3r-347h.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-h7mx-548v-cr9r/GHSA-h7mx-548v-cr9r.json b/advisories/unreviewed/2025/04/GHSA-h7mx-548v-cr9r/GHSA-h7mx-548v-cr9r.json index 170fdd01799..db1e4bb0069 100644 --- a/advisories/unreviewed/2025/04/GHSA-h7mx-548v-cr9r/GHSA-h7mx-548v-cr9r.json +++ b/advisories/unreviewed/2025/04/GHSA-h7mx-548v-cr9r/GHSA-h7mx-548v-cr9r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h7mx-548v-cr9r", - "modified": "2025-04-04T21:30:50Z", + "modified": "2025-04-08T15:31:00Z", "published": "2025-04-03T15:31:19Z", "aliases": [ "CVE-2025-3155" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2357091" }, + { + "type": "WEB", + "url": "https://gist.github.com/parrot409/e970b155358d45b298d7024edd9b17f2" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2025/04/04/1" diff --git a/advisories/unreviewed/2025/04/GHSA-hvmf-h8x8-34xp/GHSA-hvmf-h8x8-34xp.json b/advisories/unreviewed/2025/04/GHSA-hvmf-h8x8-34xp/GHSA-hvmf-h8x8-34xp.json index 7ef35db09cf..ebe839b54e7 100644 --- a/advisories/unreviewed/2025/04/GHSA-hvmf-h8x8-34xp/GHSA-hvmf-h8x8-34xp.json +++ b/advisories/unreviewed/2025/04/GHSA-hvmf-h8x8-34xp/GHSA-hvmf-h8x8-34xp.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-j27p-5p5f-gjjv/GHSA-j27p-5p5f-gjjv.json b/advisories/unreviewed/2025/04/GHSA-j27p-5p5f-gjjv/GHSA-j27p-5p5f-gjjv.json new file mode 100644 index 00000000000..7c3968fce71 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-j27p-5p5f-gjjv/GHSA-j27p-5p5f-gjjv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j27p-5p5f-gjjv", + "modified": "2025-04-08T15:31:05Z", + "published": "2025-04-08T15:31:05Z", + "aliases": [ + "CVE-2024-52962" + ], + "details": "AnĀ Improper Output Neutralization for Logs vulnerability [CWE-117] in FortiAnalyzer version 7.6.1 and below, version 7.4.5 and below, version 7.2.8 and below, version 7.0.13 and below and FortiManager version 7.6.1 and below, version 7.4.5 and below, version 7.2.8 and below, version 7.0.12 and below may allow an unauthenticated remote attacker to pollute the logs via crafted login requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52962" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-453" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-117" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T14:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-j94p-gv3v-cg5q/GHSA-j94p-gv3v-cg5q.json b/advisories/unreviewed/2025/04/GHSA-j94p-gv3v-cg5q/GHSA-j94p-gv3v-cg5q.json new file mode 100644 index 00000000000..8e1e2df2059 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-j94p-gv3v-cg5q/GHSA-j94p-gv3v-cg5q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j94p-gv3v-cg5q", + "modified": "2025-04-08T15:31:05Z", + "published": "2025-04-08T15:31:05Z", + "aliases": [ + "CVE-2024-50565" + ], + "details": "A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7.2.7, 7.0.0 through 7.0.14, 6.4.0 through 6.4.15 and 6.2.0 through 6.2.16, Fortinet FortiProxy version 7.4.0 through 7.4.2, 7.2.0 through 7.2.9, 7.0.0 through 7.0.15 and 2.0.0 through 2.0.14, Fortinet FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.14 and 6.2.0 through 6.2.13, Fortinet FortiAnalyzer version 7.4.0 through 7.4.2, 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.14 and 6.2.0 through 6.2.13, Fortinet FortiVoice version 7.0.0 through 7.0.2, 6.4.0 through 6.4.8 and 6.0.0 through 6.0.12 and Fortinet FortiWeb version 7.4.0 through 7.4.2, 7.2.0 through 7.2.10, 7.0.0 through 7.0.10 allows an unauthenticated attacker in a man-in-the-middle position to impersonate the management device (FortiCloud server or/and in certain conditions, FortiManager), via intercepting the FGFM authentication request between the management device and the managed device", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50565" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-046" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-300" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T14:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-jjr5-fpcg-gc53/GHSA-jjr5-fpcg-gc53.json b/advisories/unreviewed/2025/04/GHSA-jjr5-fpcg-gc53/GHSA-jjr5-fpcg-gc53.json index 96cbf748780..5fdc600f81a 100644 --- a/advisories/unreviewed/2025/04/GHSA-jjr5-fpcg-gc53/GHSA-jjr5-fpcg-gc53.json +++ b/advisories/unreviewed/2025/04/GHSA-jjr5-fpcg-gc53/GHSA-jjr5-fpcg-gc53.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-jr95-cvrj-r656/GHSA-jr95-cvrj-r656.json b/advisories/unreviewed/2025/04/GHSA-jr95-cvrj-r656/GHSA-jr95-cvrj-r656.json new file mode 100644 index 00000000000..6712eee128b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-jr95-cvrj-r656/GHSA-jr95-cvrj-r656.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jr95-cvrj-r656", + "modified": "2025-04-08T15:31:05Z", + "published": "2025-04-08T15:31:05Z", + "aliases": [ + "CVE-2024-54025" + ], + "details": "An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiIsolator CLI before version 2.4.6 allows a privileged attacker to execute unauthorized code or commands via crafted CLI requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54025" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-392" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T14:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-m9g2-wm3w-q6rv/GHSA-m9g2-wm3w-q6rv.json b/advisories/unreviewed/2025/04/GHSA-m9g2-wm3w-q6rv/GHSA-m9g2-wm3w-q6rv.json new file mode 100644 index 00000000000..2c46453dd3e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-m9g2-wm3w-q6rv/GHSA-m9g2-wm3w-q6rv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m9g2-wm3w-q6rv", + "modified": "2025-04-08T15:31:04Z", + "published": "2025-04-08T15:31:04Z", + "aliases": [ + "CVE-2024-26013" + ], + "details": "A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet FortiOS version 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 through 7.0.15, 6.4.0 through 6.4.15 and before 6.2.16, Fortinet FortiProxy version 7.4.0 through 7.4.2, 7.2.0 through 7.2.9 and before 7.0.15, Fortinet FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.14 and before 6.2.13, Fortinet FortiAnalyzer version 7.4.0 through 7.4.2, 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.14 and before 6.2.13, Fortinet FortiVoice version 7.0.0 through 7.0.2 before 6.4.8 and Fortinet FortiWeb before 7.4.2 may allow an unauthenticated attacker in a man-in-the-middle position to impersonate the management device (FortiCloud server or/and in certain conditions, FortiManager), via intercepting the FGFM authentication request between the management device and the managed device", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26013" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-046" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-923" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T14:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-p7jp-69j5-crrv/GHSA-p7jp-69j5-crrv.json b/advisories/unreviewed/2025/04/GHSA-p7jp-69j5-crrv/GHSA-p7jp-69j5-crrv.json index 3f85b97529e..45d02a24a89 100644 --- a/advisories/unreviewed/2025/04/GHSA-p7jp-69j5-crrv/GHSA-p7jp-69j5-crrv.json +++ b/advisories/unreviewed/2025/04/GHSA-p7jp-69j5-crrv/GHSA-p7jp-69j5-crrv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p7jp-69j5-crrv", - "modified": "2025-04-07T21:32:08Z", + "modified": "2025-04-08T15:31:02Z", "published": "2025-04-07T21:32:08Z", "aliases": [ "CVE-2025-29480" ], "details": "Buffer Overflow vulnerability in gdal 3.10.2 allows a local attacker to cause a denial of service via the OGRSpatialReference::Release function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-07T20:15:20Z" diff --git a/advisories/unreviewed/2025/04/GHSA-q7jr-v677-ww76/GHSA-q7jr-v677-ww76.json b/advisories/unreviewed/2025/04/GHSA-q7jr-v677-ww76/GHSA-q7jr-v677-ww76.json new file mode 100644 index 00000000000..42d9f18e1a4 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-q7jr-v677-ww76/GHSA-q7jr-v677-ww76.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q7jr-v677-ww76", + "modified": "2025-04-08T15:31:06Z", + "published": "2025-04-08T15:31:06Z", + "aliases": [ + "CVE-2025-25254" + ], + "details": "An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in FortiWeb version 7.6.2 and below, version 7.4.6 and below, 7.2 all versions, 7.0 all versions endpoint may allow an authenticated admin to access and modify the filesystem via crafted requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25254" + }, + { + "type": "WEB", + "url": "https://fortiguard.fortinet.com/psirt/FG-IR-24-474" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T14:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-r5hc-g9j9-f2mf/GHSA-r5hc-g9j9-f2mf.json b/advisories/unreviewed/2025/04/GHSA-r5hc-g9j9-f2mf/GHSA-r5hc-g9j9-f2mf.json new file mode 100644 index 00000000000..b97632fd252 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-r5hc-g9j9-f2mf/GHSA-r5hc-g9j9-f2mf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r5hc-g9j9-f2mf", + "modified": "2025-04-08T15:31:06Z", + "published": "2025-04-08T15:31:06Z", + "aliases": [ + "CVE-2025-22464" + ], + "details": "An untrusted pointer dereference vulnerability in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows an attacker with local access to write arbitrary data into memory causing a denial-of-service condition.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22464" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-EPM-April-2025-for-EPM-2024-and-EPM-2022-SU6" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-822" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T15:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-v5pc-4rpg-jmh7/GHSA-v5pc-4rpg-jmh7.json b/advisories/unreviewed/2025/04/GHSA-v5pc-4rpg-jmh7/GHSA-v5pc-4rpg-jmh7.json new file mode 100644 index 00000000000..1dc89972d16 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-v5pc-4rpg-jmh7/GHSA-v5pc-4rpg-jmh7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v5pc-4rpg-jmh7", + "modified": "2025-04-08T15:31:06Z", + "published": "2025-04-08T15:31:06Z", + "aliases": [ + "CVE-2025-22466" + ], + "details": "Reflected XSS in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote unauthenticated attacker to obtain admin privileges. User interaction is required.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22466" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-EPM-April-2025-for-EPM-2024-and-EPM-2022-SU6" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T15:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vh9f-239f-vjhp/GHSA-vh9f-239f-vjhp.json b/advisories/unreviewed/2025/04/GHSA-vh9f-239f-vjhp/GHSA-vh9f-239f-vjhp.json index 801f7c63655..74665c94359 100644 --- a/advisories/unreviewed/2025/04/GHSA-vh9f-239f-vjhp/GHSA-vh9f-239f-vjhp.json +++ b/advisories/unreviewed/2025/04/GHSA-vh9f-239f-vjhp/GHSA-vh9f-239f-vjhp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vh9f-239f-vjhp", - "modified": "2025-04-08T03:32:37Z", + "modified": "2025-04-08T15:31:03Z", "published": "2025-04-08T03:32:37Z", "aliases": [ "CVE-2025-3397" @@ -38,6 +38,10 @@ { "type": "WEB", "url": "https://www.yuque.com/baimatangseng-iyusa/qwwm81/sqn7nf0irphq7f1k?singleDoc" + }, + { + "type": "WEB", + "url": "https://www.yuque.com/baimatangseng-iyusa/qwwm81/sqn7nf0irphq7f1k?singleDoc#" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/04/GHSA-vx7x-6r6q-pwq4/GHSA-vx7x-6r6q-pwq4.json b/advisories/unreviewed/2025/04/GHSA-vx7x-6r6q-pwq4/GHSA-vx7x-6r6q-pwq4.json new file mode 100644 index 00000000000..e06be935194 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vx7x-6r6q-pwq4/GHSA-vx7x-6r6q-pwq4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vx7x-6r6q-pwq4", + "modified": "2025-04-08T15:31:06Z", + "published": "2025-04-08T15:31:06Z", + "aliases": [ + "CVE-2025-22461" + ], + "details": "SQL injection in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote authenticated attacker with admin privileges to achieve code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22461" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-EPM-April-2025-for-EPM-2024-and-EPM-2022-SU6" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T15:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-wq26-hpcc-wh38/GHSA-wq26-hpcc-wh38.json b/advisories/unreviewed/2025/04/GHSA-wq26-hpcc-wh38/GHSA-wq26-hpcc-wh38.json new file mode 100644 index 00000000000..03aa0d24655 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-wq26-hpcc-wh38/GHSA-wq26-hpcc-wh38.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wq26-hpcc-wh38", + "modified": "2025-04-08T15:31:06Z", + "published": "2025-04-08T15:31:06Z", + "aliases": [ + "CVE-2025-22458" + ], + "details": "DLL hijacking in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows an authenticated attacker to escalate to System.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22458" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-EPM-April-2025-for-EPM-2024-and-EPM-2022-SU6" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-427" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T15:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-x4c3-chf9-qj4x/GHSA-x4c3-chf9-qj4x.json b/advisories/unreviewed/2025/04/GHSA-x4c3-chf9-qj4x/GHSA-x4c3-chf9-qj4x.json new file mode 100644 index 00000000000..fa9ca5815c1 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-x4c3-chf9-qj4x/GHSA-x4c3-chf9-qj4x.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x4c3-chf9-qj4x", + "modified": "2025-04-08T15:31:06Z", + "published": "2025-04-08T15:31:06Z", + "aliases": [ + "CVE-2025-22465" + ], + "details": "Reflected XSS in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote unauthenticated attacker to execute arbitrary javascript in a victim's browser. Unlikely user interaction is required.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22465" + }, + { + "type": "WEB", + "url": "https://forums.ivanti.com/s/article/Security-Advisory-EPM-April-2025-for-EPM-2024-and-EPM-2022-SU6" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T15:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xw8c-3xf4-r67j/GHSA-xw8c-3xf4-r67j.json b/advisories/unreviewed/2025/04/GHSA-xw8c-3xf4-r67j/GHSA-xw8c-3xf4-r67j.json index e5726a54b19..fdea20d65c6 100644 --- a/advisories/unreviewed/2025/04/GHSA-xw8c-3xf4-r67j/GHSA-xw8c-3xf4-r67j.json +++ b/advisories/unreviewed/2025/04/GHSA-xw8c-3xf4-r67j/GHSA-xw8c-3xf4-r67j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xw8c-3xf4-r67j", - "modified": "2025-04-07T21:32:08Z", + "modified": "2025-04-08T15:31:02Z", "published": "2025-04-07T21:32:08Z", "aliases": [ "CVE-2025-29594" ], "details": "A vulnerability exists in the errorpage.php file of the CS2-WeaponPaints-Website v2.1.7 where user-controlled input is not adequately validated before being processed. Specifically, the $_GET['errorcode'] parameter can be manipulated to access unauthorized error codes, leading to Cross-Site Scripting (XSS) attacks and information disclosure.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-07T20:15:20Z"