diff --git a/advisories/unreviewed/2023/01/GHSA-42pq-h6rj-6c6q/GHSA-42pq-h6rj-6c6q.json b/advisories/unreviewed/2023/01/GHSA-42pq-h6rj-6c6q/GHSA-42pq-h6rj-6c6q.json index 7da8c9d828f..072454f4158 100644 --- a/advisories/unreviewed/2023/01/GHSA-42pq-h6rj-6c6q/GHSA-42pq-h6rj-6c6q.json +++ b/advisories/unreviewed/2023/01/GHSA-42pq-h6rj-6c6q/GHSA-42pq-h6rj-6c6q.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-121", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/01/GHSA-4p77-587h-36q7/GHSA-4p77-587h-36q7.json b/advisories/unreviewed/2023/01/GHSA-4p77-587h-36q7/GHSA-4p77-587h-36q7.json index b878c1e5842..f89d6ffd4c6 100644 --- a/advisories/unreviewed/2023/01/GHSA-4p77-587h-36q7/GHSA-4p77-587h-36q7.json +++ b/advisories/unreviewed/2023/01/GHSA-4p77-587h-36q7/GHSA-4p77-587h-36q7.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/01/GHSA-4w9g-pxjp-v6rx/GHSA-4w9g-pxjp-v6rx.json b/advisories/unreviewed/2023/01/GHSA-4w9g-pxjp-v6rx/GHSA-4w9g-pxjp-v6rx.json index 88add08f9bc..c100d39f49e 100644 --- a/advisories/unreviewed/2023/01/GHSA-4w9g-pxjp-v6rx/GHSA-4w9g-pxjp-v6rx.json +++ b/advisories/unreviewed/2023/01/GHSA-4w9g-pxjp-v6rx/GHSA-4w9g-pxjp-v6rx.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-121", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/01/GHSA-5jj4-fh62-42vp/GHSA-5jj4-fh62-42vp.json b/advisories/unreviewed/2023/01/GHSA-5jj4-fh62-42vp/GHSA-5jj4-fh62-42vp.json index 40cf4f43ceb..024b90b4ca9 100644 --- a/advisories/unreviewed/2023/01/GHSA-5jj4-fh62-42vp/GHSA-5jj4-fh62-42vp.json +++ b/advisories/unreviewed/2023/01/GHSA-5jj4-fh62-42vp/GHSA-5jj4-fh62-42vp.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/01/GHSA-655p-xm4m-c6qj/GHSA-655p-xm4m-c6qj.json b/advisories/unreviewed/2023/01/GHSA-655p-xm4m-c6qj/GHSA-655p-xm4m-c6qj.json index 3f6f590d743..1677f5a5de6 100644 --- a/advisories/unreviewed/2023/01/GHSA-655p-xm4m-c6qj/GHSA-655p-xm4m-c6qj.json +++ b/advisories/unreviewed/2023/01/GHSA-655p-xm4m-c6qj/GHSA-655p-xm4m-c6qj.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-125" + "CWE-125", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/01/GHSA-669j-rxfq-2fvw/GHSA-669j-rxfq-2fvw.json b/advisories/unreviewed/2023/01/GHSA-669j-rxfq-2fvw/GHSA-669j-rxfq-2fvw.json index 23235005b89..d764ae45d79 100644 --- a/advisories/unreviewed/2023/01/GHSA-669j-rxfq-2fvw/GHSA-669j-rxfq-2fvw.json +++ b/advisories/unreviewed/2023/01/GHSA-669j-rxfq-2fvw/GHSA-669j-rxfq-2fvw.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/01/GHSA-7gjv-jhw8-w7hq/GHSA-7gjv-jhw8-w7hq.json b/advisories/unreviewed/2023/01/GHSA-7gjv-jhw8-w7hq/GHSA-7gjv-jhw8-w7hq.json index a20479bc361..ac125617028 100644 --- a/advisories/unreviewed/2023/01/GHSA-7gjv-jhw8-w7hq/GHSA-7gjv-jhw8-w7hq.json +++ b/advisories/unreviewed/2023/01/GHSA-7gjv-jhw8-w7hq/GHSA-7gjv-jhw8-w7hq.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-125" + "CWE-125", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/01/GHSA-7x7g-xq59-cqgh/GHSA-7x7g-xq59-cqgh.json b/advisories/unreviewed/2023/01/GHSA-7x7g-xq59-cqgh/GHSA-7x7g-xq59-cqgh.json index 8b0bad4aa9f..105987e6eaa 100644 --- a/advisories/unreviewed/2023/01/GHSA-7x7g-xq59-cqgh/GHSA-7x7g-xq59-cqgh.json +++ b/advisories/unreviewed/2023/01/GHSA-7x7g-xq59-cqgh/GHSA-7x7g-xq59-cqgh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7x7g-xq59-cqgh", - "modified": "2023-01-13T21:30:28Z", + "modified": "2025-04-09T15:31:53Z", "published": "2023-01-09T18:30:19Z", "aliases": [ "CVE-2022-46258" @@ -19,6 +19,22 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-46258" }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server%403.3/admin/release-notes#3.3.16" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server%403.4/admin/release-notes#3.4.11" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server%403.5/admin/release-notes#3.5.8" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server%403.6/admin/release-notes#3.6.4" + }, { "type": "WEB", "url": "https://docs.github.com/en/enterprise-server@3.3/admin/release-notes#3.3.16" diff --git a/advisories/unreviewed/2023/01/GHSA-99q2-r8wp-gv52/GHSA-99q2-r8wp-gv52.json b/advisories/unreviewed/2023/01/GHSA-99q2-r8wp-gv52/GHSA-99q2-r8wp-gv52.json index 0913b14ed05..01ebbfa3e46 100644 --- a/advisories/unreviewed/2023/01/GHSA-99q2-r8wp-gv52/GHSA-99q2-r8wp-gv52.json +++ b/advisories/unreviewed/2023/01/GHSA-99q2-r8wp-gv52/GHSA-99q2-r8wp-gv52.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-125", "CWE-20" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2023/01/GHSA-fg37-647w-pgrp/GHSA-fg37-647w-pgrp.json b/advisories/unreviewed/2023/01/GHSA-fg37-647w-pgrp/GHSA-fg37-647w-pgrp.json index 90b0c69a518..7f8c9df3406 100644 --- a/advisories/unreviewed/2023/01/GHSA-fg37-647w-pgrp/GHSA-fg37-647w-pgrp.json +++ b/advisories/unreviewed/2023/01/GHSA-fg37-647w-pgrp/GHSA-fg37-647w-pgrp.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-358" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/01/GHSA-gc9c-5cvm-jfhx/GHSA-gc9c-5cvm-jfhx.json b/advisories/unreviewed/2023/01/GHSA-gc9c-5cvm-jfhx/GHSA-gc9c-5cvm-jfhx.json index a8601cfc176..6d6f5fa27fd 100644 --- a/advisories/unreviewed/2023/01/GHSA-gc9c-5cvm-jfhx/GHSA-gc9c-5cvm-jfhx.json +++ b/advisories/unreviewed/2023/01/GHSA-gc9c-5cvm-jfhx/GHSA-gc9c-5cvm-jfhx.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-125" + "CWE-125", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/01/GHSA-gx87-5j8f-9f75/GHSA-gx87-5j8f-9f75.json b/advisories/unreviewed/2023/01/GHSA-gx87-5j8f-9f75/GHSA-gx87-5j8f-9f75.json index 5d39971cb5b..b52344e3ec2 100644 --- a/advisories/unreviewed/2023/01/GHSA-gx87-5j8f-9f75/GHSA-gx87-5j8f-9f75.json +++ b/advisories/unreviewed/2023/01/GHSA-gx87-5j8f-9f75/GHSA-gx87-5j8f-9f75.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-125" + "CWE-125", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/01/GHSA-j4gm-gvp6-xh87/GHSA-j4gm-gvp6-xh87.json b/advisories/unreviewed/2023/01/GHSA-j4gm-gvp6-xh87/GHSA-j4gm-gvp6-xh87.json index fed37e009cf..a85469471a8 100644 --- a/advisories/unreviewed/2023/01/GHSA-j4gm-gvp6-xh87/GHSA-j4gm-gvp6-xh87.json +++ b/advisories/unreviewed/2023/01/GHSA-j4gm-gvp6-xh87/GHSA-j4gm-gvp6-xh87.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/01/GHSA-jjmh-958w-rr2j/GHSA-jjmh-958w-rr2j.json b/advisories/unreviewed/2023/01/GHSA-jjmh-958w-rr2j/GHSA-jjmh-958w-rr2j.json index 5610118dac7..e855ce457fe 100644 --- a/advisories/unreviewed/2023/01/GHSA-jjmh-958w-rr2j/GHSA-jjmh-958w-rr2j.json +++ b/advisories/unreviewed/2023/01/GHSA-jjmh-958w-rr2j/GHSA-jjmh-958w-rr2j.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-125" + "CWE-125", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/01/GHSA-jr89-38hw-mr2v/GHSA-jr89-38hw-mr2v.json b/advisories/unreviewed/2023/01/GHSA-jr89-38hw-mr2v/GHSA-jr89-38hw-mr2v.json index 28a8aac24aa..5afee0d5a71 100644 --- a/advisories/unreviewed/2023/01/GHSA-jr89-38hw-mr2v/GHSA-jr89-38hw-mr2v.json +++ b/advisories/unreviewed/2023/01/GHSA-jr89-38hw-mr2v/GHSA-jr89-38hw-mr2v.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/01/GHSA-p4w7-qphw-gm3c/GHSA-p4w7-qphw-gm3c.json b/advisories/unreviewed/2023/01/GHSA-p4w7-qphw-gm3c/GHSA-p4w7-qphw-gm3c.json index 6f1aeb1d849..a295dc7be56 100644 --- a/advisories/unreviewed/2023/01/GHSA-p4w7-qphw-gm3c/GHSA-p4w7-qphw-gm3c.json +++ b/advisories/unreviewed/2023/01/GHSA-p4w7-qphw-gm3c/GHSA-p4w7-qphw-gm3c.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-400" + "CWE-400", + "CWE-693" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-4rgm-c3r2-2hwv/GHSA-4rgm-c3r2-2hwv.json b/advisories/unreviewed/2024/02/GHSA-4rgm-c3r2-2hwv/GHSA-4rgm-c3r2-2hwv.json index fc27117ece7..16155192cfa 100644 --- a/advisories/unreviewed/2024/02/GHSA-4rgm-c3r2-2hwv/GHSA-4rgm-c3r2-2hwv.json +++ b/advisories/unreviewed/2024/02/GHSA-4rgm-c3r2-2hwv/GHSA-4rgm-c3r2-2hwv.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-125" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-674m-75xm-cgv7/GHSA-674m-75xm-cgv7.json b/advisories/unreviewed/2024/03/GHSA-674m-75xm-cgv7/GHSA-674m-75xm-cgv7.json index 82cad87dbbd..c914c21d3fb 100644 --- a/advisories/unreviewed/2024/03/GHSA-674m-75xm-cgv7/GHSA-674m-75xm-cgv7.json +++ b/advisories/unreviewed/2024/03/GHSA-674m-75xm-cgv7/GHSA-674m-75xm-cgv7.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-502" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-xxpv-3q6j-c873/GHSA-xxpv-3q6j-c873.json b/advisories/unreviewed/2024/03/GHSA-xxpv-3q6j-c873/GHSA-xxpv-3q6j-c873.json index a8606130bad..a66c572f5d2 100644 --- a/advisories/unreviewed/2024/03/GHSA-xxpv-3q6j-c873/GHSA-xxpv-3q6j-c873.json +++ b/advisories/unreviewed/2024/03/GHSA-xxpv-3q6j-c873/GHSA-xxpv-3q6j-c873.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xxpv-3q6j-c873", - "modified": "2024-03-13T18:31:34Z", + "modified": "2025-04-09T15:32:07Z", "published": "2024-03-13T18:31:34Z", "aliases": [ "CVE-2024-1935" @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-5vfq-q3p7-564q/GHSA-5vfq-q3p7-564q.json b/advisories/unreviewed/2024/04/GHSA-5vfq-q3p7-564q/GHSA-5vfq-q3p7-564q.json index c976c89bd91..3d886de421a 100644 --- a/advisories/unreviewed/2024/04/GHSA-5vfq-q3p7-564q/GHSA-5vfq-q3p7-564q.json +++ b/advisories/unreviewed/2024/04/GHSA-5vfq-q3p7-564q/GHSA-5vfq-q3p7-564q.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/04/GHSA-p2g5-6h8g-6jr3/GHSA-p2g5-6h8g-6jr3.json b/advisories/unreviewed/2024/04/GHSA-p2g5-6h8g-6jr3/GHSA-p2g5-6h8g-6jr3.json index 47d2e0cdeef..b1256251e9c 100644 --- a/advisories/unreviewed/2024/04/GHSA-p2g5-6h8g-6jr3/GHSA-p2g5-6h8g-6jr3.json +++ b/advisories/unreviewed/2024/04/GHSA-p2g5-6h8g-6jr3/GHSA-p2g5-6h8g-6jr3.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-cc7f-xj8f-c4mm/GHSA-cc7f-xj8f-c4mm.json b/advisories/unreviewed/2024/05/GHSA-cc7f-xj8f-c4mm/GHSA-cc7f-xj8f-c4mm.json index 07d55c43f27..c1035992f1e 100644 --- a/advisories/unreviewed/2024/05/GHSA-cc7f-xj8f-c4mm/GHSA-cc7f-xj8f-c4mm.json +++ b/advisories/unreviewed/2024/05/GHSA-cc7f-xj8f-c4mm/GHSA-cc7f-xj8f-c4mm.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-259" + "CWE-259", + "CWE-798" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-5jh9-vq9c-95gr/GHSA-5jh9-vq9c-95gr.json b/advisories/unreviewed/2025/03/GHSA-5jh9-vq9c-95gr/GHSA-5jh9-vq9c-95gr.json index 91cc36ab0a3..fe957fad72a 100644 --- a/advisories/unreviewed/2025/03/GHSA-5jh9-vq9c-95gr/GHSA-5jh9-vq9c-95gr.json +++ b/advisories/unreviewed/2025/03/GHSA-5jh9-vq9c-95gr/GHSA-5jh9-vq9c-95gr.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-66q2-c4x8-8x2c/GHSA-66q2-c4x8-8x2c.json b/advisories/unreviewed/2025/03/GHSA-66q2-c4x8-8x2c/GHSA-66q2-c4x8-8x2c.json index 6d0ecc1a1d2..2e160504c46 100644 --- a/advisories/unreviewed/2025/03/GHSA-66q2-c4x8-8x2c/GHSA-66q2-c4x8-8x2c.json +++ b/advisories/unreviewed/2025/03/GHSA-66q2-c4x8-8x2c/GHSA-66q2-c4x8-8x2c.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-mcp2-9qpg-mmvj/GHSA-mcp2-9qpg-mmvj.json b/advisories/unreviewed/2025/03/GHSA-mcp2-9qpg-mmvj/GHSA-mcp2-9qpg-mmvj.json index 5d80fc2eb5d..149e10141df 100644 --- a/advisories/unreviewed/2025/03/GHSA-mcp2-9qpg-mmvj/GHSA-mcp2-9qpg-mmvj.json +++ b/advisories/unreviewed/2025/03/GHSA-mcp2-9qpg-mmvj/GHSA-mcp2-9qpg-mmvj.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-qjx4-5xpx-3mfc/GHSA-qjx4-5xpx-3mfc.json b/advisories/unreviewed/2025/03/GHSA-qjx4-5xpx-3mfc/GHSA-qjx4-5xpx-3mfc.json index 7d94ccd549a..3b1848c6a1b 100644 --- a/advisories/unreviewed/2025/03/GHSA-qjx4-5xpx-3mfc/GHSA-qjx4-5xpx-3mfc.json +++ b/advisories/unreviewed/2025/03/GHSA-qjx4-5xpx-3mfc/GHSA-qjx4-5xpx-3mfc.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-vff8-5vm8-wh67/GHSA-vff8-5vm8-wh67.json b/advisories/unreviewed/2025/03/GHSA-vff8-5vm8-wh67/GHSA-vff8-5vm8-wh67.json index 492d1ad07b6..28e6f8955ee 100644 --- a/advisories/unreviewed/2025/03/GHSA-vff8-5vm8-wh67/GHSA-vff8-5vm8-wh67.json +++ b/advisories/unreviewed/2025/03/GHSA-vff8-5vm8-wh67/GHSA-vff8-5vm8-wh67.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-xcfp-c436-mm2r/GHSA-xcfp-c436-mm2r.json b/advisories/unreviewed/2025/03/GHSA-xcfp-c436-mm2r/GHSA-xcfp-c436-mm2r.json index 8622ed82a69..606ec68f458 100644 --- a/advisories/unreviewed/2025/03/GHSA-xcfp-c436-mm2r/GHSA-xcfp-c436-mm2r.json +++ b/advisories/unreviewed/2025/03/GHSA-xcfp-c436-mm2r/GHSA-xcfp-c436-mm2r.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-552" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-223p-m2w6-92v2/GHSA-223p-m2w6-92v2.json b/advisories/unreviewed/2025/04/GHSA-223p-m2w6-92v2/GHSA-223p-m2w6-92v2.json new file mode 100644 index 00000000000..db9fc61401a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-223p-m2w6-92v2/GHSA-223p-m2w6-92v2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-223p-m2w6-92v2", + "modified": "2025-04-09T15:32:23Z", + "published": "2025-04-09T15:32:23Z", + "aliases": [ + "CVE-2025-25023" + ], + "details": "IBM Security Guardium 11.4 and 12.1 could allow a privileged user to read any file on the system due to incorrect privilege assignment.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25023" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7230467" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T14:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3ch3-mpx2-hj74/GHSA-3ch3-mpx2-hj74.json b/advisories/unreviewed/2025/04/GHSA-3ch3-mpx2-hj74/GHSA-3ch3-mpx2-hj74.json index 9b1b037b769..d6666f4a557 100644 --- a/advisories/unreviewed/2025/04/GHSA-3ch3-mpx2-hj74/GHSA-3ch3-mpx2-hj74.json +++ b/advisories/unreviewed/2025/04/GHSA-3ch3-mpx2-hj74/GHSA-3ch3-mpx2-hj74.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3ch3-mpx2-hj74", - "modified": "2025-04-07T21:32:08Z", + "modified": "2025-04-09T15:32:18Z", "published": "2025-04-07T21:32:08Z", "aliases": [ "CVE-2025-29481" ], "details": "Buffer Overflow vulnerability in libbpf 1.5.0 allows a local attacker to execute arbitrary code via the bpf_object__init_prog` function of libbpf.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-07T20:15:20Z" diff --git a/advisories/unreviewed/2025/04/GHSA-43jx-m6w2-jq4p/GHSA-43jx-m6w2-jq4p.json b/advisories/unreviewed/2025/04/GHSA-43jx-m6w2-jq4p/GHSA-43jx-m6w2-jq4p.json index 0e8678af171..cc4f6e87810 100644 --- a/advisories/unreviewed/2025/04/GHSA-43jx-m6w2-jq4p/GHSA-43jx-m6w2-jq4p.json +++ b/advisories/unreviewed/2025/04/GHSA-43jx-m6w2-jq4p/GHSA-43jx-m6w2-jq4p.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-43jx-m6w2-jq4p", - "modified": "2025-04-07T21:32:08Z", + "modified": "2025-04-09T15:32:18Z", "published": "2025-04-07T21:32:08Z", "aliases": [ "CVE-2025-29482" ], "details": "Buffer Overflow vulnerability in libheif 1.19.7 allows a local attacker to execute arbitrary code via the SAO (Sample Adaptive Offset) processing of libde265.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-07T20:15:20Z" diff --git a/advisories/unreviewed/2025/04/GHSA-928q-p6rr-68q8/GHSA-928q-p6rr-68q8.json b/advisories/unreviewed/2025/04/GHSA-928q-p6rr-68q8/GHSA-928q-p6rr-68q8.json index adb4436dc27..31f3c34406c 100644 --- a/advisories/unreviewed/2025/04/GHSA-928q-p6rr-68q8/GHSA-928q-p6rr-68q8.json +++ b/advisories/unreviewed/2025/04/GHSA-928q-p6rr-68q8/GHSA-928q-p6rr-68q8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-928q-p6rr-68q8", - "modified": "2025-04-07T21:32:08Z", + "modified": "2025-04-09T15:32:18Z", "published": "2025-04-07T21:32:08Z", "aliases": [ "CVE-2025-29479" ], "details": "Buffer Overflow in hiredis 1.2.0 allows a local attacker to cause a denial of service via the sdscatlen function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-07T20:15:20Z" diff --git a/advisories/unreviewed/2025/04/GHSA-gjx9-wg9x-7gvp/GHSA-gjx9-wg9x-7gvp.json b/advisories/unreviewed/2025/04/GHSA-gjx9-wg9x-7gvp/GHSA-gjx9-wg9x-7gvp.json index 3e9c9ce99bc..ffa628c3d5c 100644 --- a/advisories/unreviewed/2025/04/GHSA-gjx9-wg9x-7gvp/GHSA-gjx9-wg9x-7gvp.json +++ b/advisories/unreviewed/2025/04/GHSA-gjx9-wg9x-7gvp/GHSA-gjx9-wg9x-7gvp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gjx9-wg9x-7gvp", - "modified": "2025-04-09T12:30:24Z", + "modified": "2025-04-09T15:32:22Z", "published": "2025-04-09T12:30:24Z", "aliases": [ "CVE-2025-29189" ], "details": "Flowise <= 2.2.3 is vulnerable to SQL Injection. via tableName parameter at Postgres_VectorStores.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-09T12:15:15Z" diff --git a/advisories/unreviewed/2025/04/GHSA-gmg8-593g-7mv3/GHSA-gmg8-593g-7mv3.json b/advisories/unreviewed/2025/04/GHSA-gmg8-593g-7mv3/GHSA-gmg8-593g-7mv3.json index 254e936b664..893ff3c3424 100644 --- a/advisories/unreviewed/2025/04/GHSA-gmg8-593g-7mv3/GHSA-gmg8-593g-7mv3.json +++ b/advisories/unreviewed/2025/04/GHSA-gmg8-593g-7mv3/GHSA-gmg8-593g-7mv3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gmg8-593g-7mv3", - "modified": "2025-04-09T12:30:24Z", + "modified": "2025-04-09T15:32:22Z", "published": "2025-04-09T12:30:24Z", "aliases": [ "CVE-2025-31672" @@ -21,6 +21,10 @@ { "type": "WEB", "url": "https://lists.apache.org/thread/k14w8vcjqy4h34hh5kzldko78kpylkq5" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/04/08/2" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/04/GHSA-j2cv-mq44-5cqr/GHSA-j2cv-mq44-5cqr.json b/advisories/unreviewed/2025/04/GHSA-j2cv-mq44-5cqr/GHSA-j2cv-mq44-5cqr.json new file mode 100644 index 00000000000..480846cccec --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-j2cv-mq44-5cqr/GHSA-j2cv-mq44-5cqr.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j2cv-mq44-5cqr", + "modified": "2025-04-09T15:32:23Z", + "published": "2025-04-09T15:32:23Z", + "aliases": [ + "CVE-2025-29389" + ], + "details": "PbootCMS v3.2.9 contains a XSS vulnerability in admin.php?p=/Content/index/mcode/2#tab=t2.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29389" + }, + { + "type": "WEB", + "url": "https://github.com/jaylan545/security/issues/1" + }, + { + "type": "WEB", + "url": "https://gist.github.com/jaylan545/0540db17daca2bf42fe5a3ce864300c9" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T15:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-mrh3-4hmr-qq29/GHSA-mrh3-4hmr-qq29.json b/advisories/unreviewed/2025/04/GHSA-mrh3-4hmr-qq29/GHSA-mrh3-4hmr-qq29.json index 18f0593f94e..6c33baf4ceb 100644 --- a/advisories/unreviewed/2025/04/GHSA-mrh3-4hmr-qq29/GHSA-mrh3-4hmr-qq29.json +++ b/advisories/unreviewed/2025/04/GHSA-mrh3-4hmr-qq29/GHSA-mrh3-4hmr-qq29.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mrh3-4hmr-qq29", - "modified": "2025-04-01T00:30:45Z", + "modified": "2025-04-09T15:32:18Z", "published": "2025-04-01T00:30:45Z", "aliases": [ "CVE-2025-3060" ], "details": "Vulnerability in Drupal Flattern – Multipurpose Bootstrap Business Profile.This issue affects Flattern – Multipurpose Bootstrap Business Profile: *.*.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:30Z" diff --git a/advisories/unreviewed/2025/04/GHSA-pm4j-p7pm-fpvx/GHSA-pm4j-p7pm-fpvx.json b/advisories/unreviewed/2025/04/GHSA-pm4j-p7pm-fpvx/GHSA-pm4j-p7pm-fpvx.json new file mode 100644 index 00000000000..d05e4e1d6fc --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-pm4j-p7pm-fpvx/GHSA-pm4j-p7pm-fpvx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pm4j-p7pm-fpvx", + "modified": "2025-04-09T15:32:23Z", + "published": "2025-04-09T15:32:23Z", + "aliases": [ + "CVE-2025-27391" + ], + "details": "Insertion of Sensitive Information into Log File vulnerability in Apache ActiveMQ Artemis. All the values of the broker properties are logged when the org.apache.activemq.artemis.core.config.impl.ConfigurationImpl logger has the debug level enabled.\n\nThis issue affects Apache ActiveMQ Artemis: from 1.5.1 before 2.40.0. It can be mitigated by restricting log access to only trusted users.\n\nUsers are recommended to upgrade to version 2.40.0, which fixes the issue.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27391" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/25p96cvzl1mkt29lwm2d8knklkoqolps" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T15:16:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-q43q-mp42-75vm/GHSA-q43q-mp42-75vm.json b/advisories/unreviewed/2025/04/GHSA-q43q-mp42-75vm/GHSA-q43q-mp42-75vm.json new file mode 100644 index 00000000000..87612acae4b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-q43q-mp42-75vm/GHSA-q43q-mp42-75vm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q43q-mp42-75vm", + "modified": "2025-04-09T15:32:23Z", + "published": "2025-04-09T15:32:23Z", + "aliases": [ + "CVE-2025-1968" + ], + "details": "Insufficient Session Expiration vulnerability in Progress Software Corporation Sitefinity under some specific and uncommon circumstances allows reusing Session IDs (Session Replay Attacks).This issue affects Sitefinity: from 14.0 through 14.3, from 14.4 before 14.4.8145, from 15.0 before 15.0.8231, from 15.1 before 15.1.8332, from 15.2 before 15.2.8429.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1968" + }, + { + "type": "WEB", + "url": "https://community.progress.com/s/article/Sitefinity-Security-Advisory-for-Addressing-Security-Vulnerability-CVE-2025-1968-April-2025" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-613" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T14:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-r3wq-m83f-8qj7/GHSA-r3wq-m83f-8qj7.json b/advisories/unreviewed/2025/04/GHSA-r3wq-m83f-8qj7/GHSA-r3wq-m83f-8qj7.json index 8a00e7a6d57..e7f2c074972 100644 --- a/advisories/unreviewed/2025/04/GHSA-r3wq-m83f-8qj7/GHSA-r3wq-m83f-8qj7.json +++ b/advisories/unreviewed/2025/04/GHSA-r3wq-m83f-8qj7/GHSA-r3wq-m83f-8qj7.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-r5f5-x9h9-q3ch/GHSA-r5f5-x9h9-q3ch.json b/advisories/unreviewed/2025/04/GHSA-r5f5-x9h9-q3ch/GHSA-r5f5-x9h9-q3ch.json index dde60628210..bb53396b396 100644 --- a/advisories/unreviewed/2025/04/GHSA-r5f5-x9h9-q3ch/GHSA-r5f5-x9h9-q3ch.json +++ b/advisories/unreviewed/2025/04/GHSA-r5f5-x9h9-q3ch/GHSA-r5f5-x9h9-q3ch.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-r75x-m5pq-2c5m/GHSA-r75x-m5pq-2c5m.json b/advisories/unreviewed/2025/04/GHSA-r75x-m5pq-2c5m/GHSA-r75x-m5pq-2c5m.json index 6bd17332ba7..54d6272723d 100644 --- a/advisories/unreviewed/2025/04/GHSA-r75x-m5pq-2c5m/GHSA-r75x-m5pq-2c5m.json +++ b/advisories/unreviewed/2025/04/GHSA-r75x-m5pq-2c5m/GHSA-r75x-m5pq-2c5m.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-vcpm-vcmc-m56v/GHSA-vcpm-vcmc-m56v.json b/advisories/unreviewed/2025/04/GHSA-vcpm-vcmc-m56v/GHSA-vcpm-vcmc-m56v.json index f5ac7a1a2c2..b3b3ed52e06 100644 --- a/advisories/unreviewed/2025/04/GHSA-vcpm-vcmc-m56v/GHSA-vcpm-vcmc-m56v.json +++ b/advisories/unreviewed/2025/04/GHSA-vcpm-vcmc-m56v/GHSA-vcpm-vcmc-m56v.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-w9mh-mv37-65p8/GHSA-w9mh-mv37-65p8.json b/advisories/unreviewed/2025/04/GHSA-w9mh-mv37-65p8/GHSA-w9mh-mv37-65p8.json new file mode 100644 index 00000000000..e1033809888 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-w9mh-mv37-65p8/GHSA-w9mh-mv37-65p8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w9mh-mv37-65p8", + "modified": "2025-04-09T15:32:22Z", + "published": "2025-04-09T15:32:22Z", + "aliases": [ + "CVE-2023-33844" + ], + "details": "IBM Security Verify Governance 10.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-33844" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7230443" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-09T14:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-wp3g-9m76-xj95/GHSA-wp3g-9m76-xj95.json b/advisories/unreviewed/2025/04/GHSA-wp3g-9m76-xj95/GHSA-wp3g-9m76-xj95.json index 8b3bf314481..30cd81b2590 100644 --- a/advisories/unreviewed/2025/04/GHSA-wp3g-9m76-xj95/GHSA-wp3g-9m76-xj95.json +++ b/advisories/unreviewed/2025/04/GHSA-wp3g-9m76-xj95/GHSA-wp3g-9m76-xj95.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false,