From 584213d3ee8025333620dac1e9f28aa28070eae1 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 11 Feb 2025 15:34:11 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-h9pf-hjmx-3mpq.json | 9 ++++- .../GHSA-26mv-q4q7-6xv2.json | 6 ++- .../GHSA-56xp-9hrv-5vvj.json | 6 ++- .../GHSA-7vww-mjq5-vh3j.json | 6 ++- .../GHSA-w6j9-gj52-h6wf.json | 6 ++- .../GHSA-xmcr-r54g-jx72.json | 6 ++- .../GHSA-gcp5-jr9j-3744.json | 6 ++- .../GHSA-5pvq-85hg-5rww.json | 3 +- .../GHSA-m84q-p89f-6cc5.json | 4 +- .../GHSA-vh5q-rxqq-3f32.json | 40 +++++++++++++++++++ .../GHSA-3px5-66w8-x4q8.json | 15 +++++-- .../GHSA-83c6-cpc7-fc84.json | 36 +++++++++++++++++ .../GHSA-8w92-pvrp-jcwv.json | 6 ++- .../GHSA-9cmp-ppm3-hp8w.json | 14 +++++-- .../GHSA-9fmx-g36w-qhc9.json | 11 +++-- .../GHSA-chvr-56gh-gq34.json | 6 ++- .../GHSA-h9f9-r2j7-9685.json | 11 +++-- .../GHSA-hrwq-g9x9-jmq2.json | 11 +++-- .../GHSA-hvw5-4g4q-2h8p.json | 15 +++++-- .../GHSA-jj4x-g447-hm4m.json | 11 +++-- .../GHSA-m62f-jrrh-2q4v.json | 6 ++- .../GHSA-mjmw-3m65-4c84.json | 36 +++++++++++++++++ .../GHSA-p2h9-63jc-gj67.json | 10 ++++- .../GHSA-pq6f-p382-p92m.json | 36 +++++++++++++++++ .../GHSA-r8rq-6jrf-gqrw.json | 36 +++++++++++++++++ .../GHSA-rf6c-m595-cvc8.json | 15 +++++-- .../GHSA-v7x9-h7r5-85q2.json | 3 +- .../GHSA-vv2h-2w3q-3fx7.json | 37 +++++++++++++++++ .../GHSA-vwpq-f3cq-q82w.json | 10 ++++- .../GHSA-xm77-x3f8-rr93.json | 4 +- 30 files changed, 374 insertions(+), 47 deletions(-) create mode 100644 advisories/unreviewed/2025/01/GHSA-vh5q-rxqq-3f32/GHSA-vh5q-rxqq-3f32.json create mode 100644 advisories/unreviewed/2025/02/GHSA-83c6-cpc7-fc84/GHSA-83c6-cpc7-fc84.json create mode 100644 advisories/unreviewed/2025/02/GHSA-mjmw-3m65-4c84/GHSA-mjmw-3m65-4c84.json create mode 100644 advisories/unreviewed/2025/02/GHSA-pq6f-p382-p92m/GHSA-pq6f-p382-p92m.json create mode 100644 advisories/unreviewed/2025/02/GHSA-r8rq-6jrf-gqrw/GHSA-r8rq-6jrf-gqrw.json create mode 100644 advisories/unreviewed/2025/02/GHSA-vv2h-2w3q-3fx7/GHSA-vv2h-2w3q-3fx7.json diff --git a/advisories/unreviewed/2021/12/GHSA-h9pf-hjmx-3mpq/GHSA-h9pf-hjmx-3mpq.json b/advisories/unreviewed/2021/12/GHSA-h9pf-hjmx-3mpq/GHSA-h9pf-hjmx-3mpq.json index bcdbac6b2a0..3db2c0a8542 100644 --- a/advisories/unreviewed/2021/12/GHSA-h9pf-hjmx-3mpq/GHSA-h9pf-hjmx-3mpq.json +++ b/advisories/unreviewed/2021/12/GHSA-h9pf-hjmx-3mpq/GHSA-h9pf-hjmx-3mpq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h9pf-hjmx-3mpq", - "modified": "2022-01-05T00:01:49Z", + "modified": "2025-02-11T15:32:20Z", "published": "2021-12-24T00:00:41Z", "aliases": [ "CVE-2021-44600" ], "details": "The password parameter on Simple Online Mens Salon Management System (MSMS) 1.0 appears to be vulnerable to SQL injection attacks through the password parameter. The predictive tests of this application interacted with that domain, indicating that the injected SQL query was executed. The attacker can retrieve all authentication and information about the users of this system.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2024/05/GHSA-26mv-q4q7-6xv2/GHSA-26mv-q4q7-6xv2.json b/advisories/unreviewed/2024/05/GHSA-26mv-q4q7-6xv2/GHSA-26mv-q4q7-6xv2.json index 8dfd83cb870..c1206fac071 100644 --- a/advisories/unreviewed/2024/05/GHSA-26mv-q4q7-6xv2/GHSA-26mv-q4q7-6xv2.json +++ b/advisories/unreviewed/2024/05/GHSA-26mv-q4q7-6xv2/GHSA-26mv-q4q7-6xv2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-26mv-q4q7-6xv2", - "modified": "2024-05-17T21:31:47Z", + "modified": "2025-02-11T15:32:20Z", "published": "2024-05-17T21:31:47Z", "aliases": [ "CVE-2024-5069" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/05/GHSA-56xp-9hrv-5vvj/GHSA-56xp-9hrv-5vvj.json b/advisories/unreviewed/2024/05/GHSA-56xp-9hrv-5vvj/GHSA-56xp-9hrv-5vvj.json index c460e73cb27..9bce73d12e2 100644 --- a/advisories/unreviewed/2024/05/GHSA-56xp-9hrv-5vvj/GHSA-56xp-9hrv-5vvj.json +++ b/advisories/unreviewed/2024/05/GHSA-56xp-9hrv-5vvj/GHSA-56xp-9hrv-5vvj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-56xp-9hrv-5vvj", - "modified": "2024-05-20T09:30:50Z", + "modified": "2025-02-11T15:32:21Z", "published": "2024-05-20T09:30:50Z", "aliases": [ "CVE-2024-5134" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/05/GHSA-7vww-mjq5-vh3j/GHSA-7vww-mjq5-vh3j.json b/advisories/unreviewed/2024/05/GHSA-7vww-mjq5-vh3j/GHSA-7vww-mjq5-vh3j.json index e3067673335..b3971cbdd41 100644 --- a/advisories/unreviewed/2024/05/GHSA-7vww-mjq5-vh3j/GHSA-7vww-mjq5-vh3j.json +++ b/advisories/unreviewed/2024/05/GHSA-7vww-mjq5-vh3j/GHSA-7vww-mjq5-vh3j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7vww-mjq5-vh3j", - "modified": "2024-05-14T18:30:57Z", + "modified": "2025-02-11T15:32:20Z", "published": "2024-05-14T18:30:57Z", "aliases": [ "CVE-2024-4809" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/05/GHSA-w6j9-gj52-h6wf/GHSA-w6j9-gj52-h6wf.json b/advisories/unreviewed/2024/05/GHSA-w6j9-gj52-h6wf/GHSA-w6j9-gj52-h6wf.json index b79e8b6e98f..7fe373a7794 100644 --- a/advisories/unreviewed/2024/05/GHSA-w6j9-gj52-h6wf/GHSA-w6j9-gj52-h6wf.json +++ b/advisories/unreviewed/2024/05/GHSA-w6j9-gj52-h6wf/GHSA-w6j9-gj52-h6wf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w6j9-gj52-h6wf", - "modified": "2024-05-14T18:30:57Z", + "modified": "2025-02-11T15:32:20Z", "published": "2024-05-14T18:30:57Z", "aliases": [ "CVE-2024-4820" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/05/GHSA-xmcr-r54g-jx72/GHSA-xmcr-r54g-jx72.json b/advisories/unreviewed/2024/05/GHSA-xmcr-r54g-jx72/GHSA-xmcr-r54g-jx72.json index 4714d7a68ce..e0f8d2372ca 100644 --- a/advisories/unreviewed/2024/05/GHSA-xmcr-r54g-jx72/GHSA-xmcr-r54g-jx72.json +++ b/advisories/unreviewed/2024/05/GHSA-xmcr-r54g-jx72/GHSA-xmcr-r54g-jx72.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xmcr-r54g-jx72", - "modified": "2024-05-14T18:30:57Z", + "modified": "2025-02-11T15:32:20Z", "published": "2024-05-14T18:30:57Z", "aliases": [ "CVE-2024-4798" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/06/GHSA-gcp5-jr9j-3744/GHSA-gcp5-jr9j-3744.json b/advisories/unreviewed/2024/06/GHSA-gcp5-jr9j-3744/GHSA-gcp5-jr9j-3744.json index 61197c81828..b61cc6b2542 100644 --- a/advisories/unreviewed/2024/06/GHSA-gcp5-jr9j-3744/GHSA-gcp5-jr9j-3744.json +++ b/advisories/unreviewed/2024/06/GHSA-gcp5-jr9j-3744/GHSA-gcp5-jr9j-3744.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gcp5-jr9j-3744", - "modified": "2024-06-02T15:30:37Z", + "modified": "2025-02-11T15:32:21Z", "published": "2024-06-02T15:30:37Z", "aliases": [ "CVE-2024-5588" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2024/12/GHSA-5pvq-85hg-5rww/GHSA-5pvq-85hg-5rww.json b/advisories/unreviewed/2024/12/GHSA-5pvq-85hg-5rww/GHSA-5pvq-85hg-5rww.json index ff7830b802c..361c3ac4277 100644 --- a/advisories/unreviewed/2024/12/GHSA-5pvq-85hg-5rww/GHSA-5pvq-85hg-5rww.json +++ b/advisories/unreviewed/2024/12/GHSA-5pvq-85hg-5rww/GHSA-5pvq-85hg-5rww.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-m84q-p89f-6cc5/GHSA-m84q-p89f-6cc5.json b/advisories/unreviewed/2024/12/GHSA-m84q-p89f-6cc5/GHSA-m84q-p89f-6cc5.json index 7a3b9074a4a..1767abe910e 100644 --- a/advisories/unreviewed/2024/12/GHSA-m84q-p89f-6cc5/GHSA-m84q-p89f-6cc5.json +++ b/advisories/unreviewed/2024/12/GHSA-m84q-p89f-6cc5/GHSA-m84q-p89f-6cc5.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-vh5q-rxqq-3f32/GHSA-vh5q-rxqq-3f32.json b/advisories/unreviewed/2025/01/GHSA-vh5q-rxqq-3f32/GHSA-vh5q-rxqq-3f32.json new file mode 100644 index 00000000000..166105305e3 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-vh5q-rxqq-3f32/GHSA-vh5q-rxqq-3f32.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vh5q-rxqq-3f32", + "modified": "2025-02-11T15:32:21Z", + "published": "2025-01-08T21:32:25Z", + "aliases": [ + "CVE-2025-0291" + ], + "details": "Type Confusion in V8 in Google Chrome prior to 131.0.6778.264 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0291" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2025/01/stable-channel-update-for-desktop.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/383356864" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-843" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-08T19:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-3px5-66w8-x4q8/GHSA-3px5-66w8-x4q8.json b/advisories/unreviewed/2025/02/GHSA-3px5-66w8-x4q8/GHSA-3px5-66w8-x4q8.json index a46eb4be0fc..5197da66f46 100644 --- a/advisories/unreviewed/2025/02/GHSA-3px5-66w8-x4q8/GHSA-3px5-66w8-x4q8.json +++ b/advisories/unreviewed/2025/02/GHSA-3px5-66w8-x4q8/GHSA-3px5-66w8-x4q8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3px5-66w8-x4q8", - "modified": "2025-02-10T21:31:37Z", + "modified": "2025-02-11T15:32:22Z", "published": "2025-02-10T21:31:37Z", "aliases": [ "CVE-2024-27859" ], "details": "The issue was addressed with improved memory handling. This issue is fixed in iOS 17.4 and iPadOS 17.4, tvOS 17.4, watchOS 10.4, visionOS 1.1, macOS Sonoma 14.4. Processing web content may lead to arbitrary code execution.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-10T19:15:37Z" diff --git a/advisories/unreviewed/2025/02/GHSA-83c6-cpc7-fc84/GHSA-83c6-cpc7-fc84.json b/advisories/unreviewed/2025/02/GHSA-83c6-cpc7-fc84/GHSA-83c6-cpc7-fc84.json new file mode 100644 index 00000000000..6fa7fd06c4e --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-83c6-cpc7-fc84/GHSA-83c6-cpc7-fc84.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-83c6-cpc7-fc84", + "modified": "2025-02-11T15:32:24Z", + "published": "2025-02-11T15:32:24Z", + "aliases": [ + "CVE-2025-26492" + ], + "details": "In JetBrains TeamCity before 2024.12.2 improper Kubernetes connection settings could expose sensitive resources", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26492" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-522" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T14:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-8w92-pvrp-jcwv/GHSA-8w92-pvrp-jcwv.json b/advisories/unreviewed/2025/02/GHSA-8w92-pvrp-jcwv/GHSA-8w92-pvrp-jcwv.json index fdde74d8f1f..f73cb41ff7f 100644 --- a/advisories/unreviewed/2025/02/GHSA-8w92-pvrp-jcwv/GHSA-8w92-pvrp-jcwv.json +++ b/advisories/unreviewed/2025/02/GHSA-8w92-pvrp-jcwv/GHSA-8w92-pvrp-jcwv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8w92-pvrp-jcwv", - "modified": "2025-02-11T12:30:55Z", + "modified": "2025-02-11T15:32:24Z", "published": "2025-02-11T12:30:55Z", "aliases": [ "CVE-2025-0588" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://advisories.octopus.com/post/2024/sa2025-05" + }, + { + "type": "WEB", + "url": "https://advisories.octopus.com/post/2025/sa2025-05" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/02/GHSA-9cmp-ppm3-hp8w/GHSA-9cmp-ppm3-hp8w.json b/advisories/unreviewed/2025/02/GHSA-9cmp-ppm3-hp8w/GHSA-9cmp-ppm3-hp8w.json index e85326464ac..26749f841dc 100644 --- a/advisories/unreviewed/2025/02/GHSA-9cmp-ppm3-hp8w/GHSA-9cmp-ppm3-hp8w.json +++ b/advisories/unreviewed/2025/02/GHSA-9cmp-ppm3-hp8w/GHSA-9cmp-ppm3-hp8w.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9cmp-ppm3-hp8w", - "modified": "2025-02-11T12:30:54Z", + "modified": "2025-02-11T15:32:23Z", "published": "2025-02-11T12:30:53Z", "aliases": [ "CVE-2025-26409" ], "details": "A serial interface can be accessed with physical access to the PCB of Wattsense Bridge devices. After connecting to the interface, access to the bootloader is possible, as well as a Linux login prompt. The bootloader access can be used to gain a root shell on the device. This issue is fixed in recent firmware versions BSP >= 6.4.1.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -25,9 +30,10 @@ ], "database_specific": { "cwe_ids": [ - "CWE-1191" + "CWE-1191", + "CWE-1299" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-11T10:15:09Z" diff --git a/advisories/unreviewed/2025/02/GHSA-9fmx-g36w-qhc9/GHSA-9fmx-g36w-qhc9.json b/advisories/unreviewed/2025/02/GHSA-9fmx-g36w-qhc9/GHSA-9fmx-g36w-qhc9.json index 9385b8dcd1e..4e7a09529fd 100644 --- a/advisories/unreviewed/2025/02/GHSA-9fmx-g36w-qhc9/GHSA-9fmx-g36w-qhc9.json +++ b/advisories/unreviewed/2025/02/GHSA-9fmx-g36w-qhc9/GHSA-9fmx-g36w-qhc9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9fmx-g36w-qhc9", - "modified": "2025-02-11T06:30:27Z", + "modified": "2025-02-11T15:32:22Z", "published": "2025-02-11T06:30:27Z", "aliases": [ "CVE-2024-13543" ], "details": "The Zarinpal Paid Download WordPress plugin through 2.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-11T06:15:19Z" diff --git a/advisories/unreviewed/2025/02/GHSA-chvr-56gh-gq34/GHSA-chvr-56gh-gq34.json b/advisories/unreviewed/2025/02/GHSA-chvr-56gh-gq34/GHSA-chvr-56gh-gq34.json index 4542af1e93f..be541302ad6 100644 --- a/advisories/unreviewed/2025/02/GHSA-chvr-56gh-gq34/GHSA-chvr-56gh-gq34.json +++ b/advisories/unreviewed/2025/02/GHSA-chvr-56gh-gq34/GHSA-chvr-56gh-gq34.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-chvr-56gh-gq34", - "modified": "2025-02-11T12:30:55Z", + "modified": "2025-02-11T15:32:24Z", "published": "2025-02-11T12:30:55Z", "aliases": [ "CVE-2025-26490" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://cert-portal.siemens.com/productcert/html/ssa-246355.html" + }, + { + "type": "WEB", + "url": "https://help.salesforce.com/s/articleView?id=000390611&type=1" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/02/GHSA-h9f9-r2j7-9685/GHSA-h9f9-r2j7-9685.json b/advisories/unreviewed/2025/02/GHSA-h9f9-r2j7-9685/GHSA-h9f9-r2j7-9685.json index 2fd14f2e0ed..35472ea1bbb 100644 --- a/advisories/unreviewed/2025/02/GHSA-h9f9-r2j7-9685/GHSA-h9f9-r2j7-9685.json +++ b/advisories/unreviewed/2025/02/GHSA-h9f9-r2j7-9685/GHSA-h9f9-r2j7-9685.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h9f9-r2j7-9685", - "modified": "2025-02-11T12:30:54Z", + "modified": "2025-02-11T15:32:24Z", "published": "2025-02-11T12:30:54Z", "aliases": [ "CVE-2025-26411" ], "details": "An authenticated attacker is able to use the Plugin Manager of the web interface of the Wattsense Bridge devices to upload malicious Python files to the device. This enables an attacker to gain remote root access to the device. An attacker needs a valid user account on the Wattsense web interface to be able to conduct this attack. This issue is fixed in recent firmware versions BSP >= 6.1.0.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -27,7 +32,7 @@ "cwe_ids": [ "CWE-434" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-11T10:15:09Z" diff --git a/advisories/unreviewed/2025/02/GHSA-hrwq-g9x9-jmq2/GHSA-hrwq-g9x9-jmq2.json b/advisories/unreviewed/2025/02/GHSA-hrwq-g9x9-jmq2/GHSA-hrwq-g9x9-jmq2.json index f3029f14e80..ffe58faaf7e 100644 --- a/advisories/unreviewed/2025/02/GHSA-hrwq-g9x9-jmq2/GHSA-hrwq-g9x9-jmq2.json +++ b/advisories/unreviewed/2025/02/GHSA-hrwq-g9x9-jmq2/GHSA-hrwq-g9x9-jmq2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hrwq-g9x9-jmq2", - "modified": "2025-02-11T12:30:54Z", + "modified": "2025-02-11T15:32:23Z", "published": "2025-02-11T12:30:53Z", "aliases": [ "CVE-2025-26408" ], "details": "The JTAG interface of Wattsense Bridge devices can be accessed with physical access to the PCB. After connecting to the interface, full access to the device is possible. This enables an attacker to extract information, modify and debug the device's firmware. All known versions are affected.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -27,7 +32,7 @@ "cwe_ids": [ "CWE-1191" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-11T10:15:09Z" diff --git a/advisories/unreviewed/2025/02/GHSA-hvw5-4g4q-2h8p/GHSA-hvw5-4g4q-2h8p.json b/advisories/unreviewed/2025/02/GHSA-hvw5-4g4q-2h8p/GHSA-hvw5-4g4q-2h8p.json index 66e360190a9..6abc7c0bae1 100644 --- a/advisories/unreviewed/2025/02/GHSA-hvw5-4g4q-2h8p/GHSA-hvw5-4g4q-2h8p.json +++ b/advisories/unreviewed/2025/02/GHSA-hvw5-4g4q-2h8p/GHSA-hvw5-4g4q-2h8p.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hvw5-4g4q-2h8p", - "modified": "2025-02-11T06:30:24Z", + "modified": "2025-02-11T15:32:22Z", "published": "2025-02-10T21:31:39Z", "aliases": [ "CVE-2025-24200" ], "details": "An authorization issue was addressed with improved state management. This issue is fixed in iPadOS 17.7.5, iOS 18.3.1 and iPadOS 18.3.1. A physical attack may disable USB Restricted Mode on a locked device. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-863" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-10T19:15:40Z" diff --git a/advisories/unreviewed/2025/02/GHSA-jj4x-g447-hm4m/GHSA-jj4x-g447-hm4m.json b/advisories/unreviewed/2025/02/GHSA-jj4x-g447-hm4m/GHSA-jj4x-g447-hm4m.json index 2b2d104af04..7c5ce3cdd90 100644 --- a/advisories/unreviewed/2025/02/GHSA-jj4x-g447-hm4m/GHSA-jj4x-g447-hm4m.json +++ b/advisories/unreviewed/2025/02/GHSA-jj4x-g447-hm4m/GHSA-jj4x-g447-hm4m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jj4x-g447-hm4m", - "modified": "2025-02-11T12:30:54Z", + "modified": "2025-02-11T15:32:23Z", "published": "2025-02-11T12:30:54Z", "aliases": [ "CVE-2025-26410" ], "details": "The firmware of all Wattsense Bridge devices contain the same hard-coded user and root credentials. The user password can be easily recovered via password cracking attempts. The recovered credentials can be used to log into the device via the login shell that is exposed by the serial interface. The backdoor user has been removed in firmware BSP >= 6.4.1.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -27,7 +32,7 @@ "cwe_ids": [ "CWE-798" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-11T10:15:09Z" diff --git a/advisories/unreviewed/2025/02/GHSA-m62f-jrrh-2q4v/GHSA-m62f-jrrh-2q4v.json b/advisories/unreviewed/2025/02/GHSA-m62f-jrrh-2q4v/GHSA-m62f-jrrh-2q4v.json index dcfcb3b23de..2b6f505b4f8 100644 --- a/advisories/unreviewed/2025/02/GHSA-m62f-jrrh-2q4v/GHSA-m62f-jrrh-2q4v.json +++ b/advisories/unreviewed/2025/02/GHSA-m62f-jrrh-2q4v/GHSA-m62f-jrrh-2q4v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m62f-jrrh-2q4v", - "modified": "2025-02-11T12:30:55Z", + "modified": "2025-02-11T15:32:24Z", "published": "2025-02-11T12:30:55Z", "aliases": [ "CVE-2025-26491" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://cert-portal.siemens.com/productcert/html/ssa-246355.html" + }, + { + "type": "WEB", + "url": "https://help.salesforce.com/s/articleView?id=001534936&type=1" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/02/GHSA-mjmw-3m65-4c84/GHSA-mjmw-3m65-4c84.json b/advisories/unreviewed/2025/02/GHSA-mjmw-3m65-4c84/GHSA-mjmw-3m65-4c84.json new file mode 100644 index 00000000000..f3deed1df1d --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-mjmw-3m65-4c84/GHSA-mjmw-3m65-4c84.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mjmw-3m65-4c84", + "modified": "2025-02-11T15:32:24Z", + "published": "2025-02-11T15:32:24Z", + "aliases": [ + "CVE-2025-1231" + ], + "details": "Improper password reset in PAM Module in Devolutions Server 2024.3.10.0 and earlier allows an authenticated user to reuse the oracle user password after check-in due to crash in the password reset functionality.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1231" + }, + { + "type": "WEB", + "url": "https://devolutions.net/security/advisories/DEVO-2025-0002" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T14:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-p2h9-63jc-gj67/GHSA-p2h9-63jc-gj67.json b/advisories/unreviewed/2025/02/GHSA-p2h9-63jc-gj67/GHSA-p2h9-63jc-gj67.json index 602f0767947..a5cc3d60dc5 100644 --- a/advisories/unreviewed/2025/02/GHSA-p2h9-63jc-gj67/GHSA-p2h9-63jc-gj67.json +++ b/advisories/unreviewed/2025/02/GHSA-p2h9-63jc-gj67/GHSA-p2h9-63jc-gj67.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-p2h9-63jc-gj67", - "modified": "2025-02-11T12:30:54Z", + "modified": "2025-02-11T15:32:24Z", "published": "2025-02-11T12:30:54Z", "aliases": [ "CVE-2025-0526" ], "details": "In affected versions of Octopus Deploy it was possible to upload files to unexpected locations on the host using an API endpoint. The field lacked validation which could potentially result in ways to circumvent expected workflows.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" @@ -25,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-22" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-pq6f-p382-p92m/GHSA-pq6f-p382-p92m.json b/advisories/unreviewed/2025/02/GHSA-pq6f-p382-p92m/GHSA-pq6f-p382-p92m.json new file mode 100644 index 00000000000..e5fa27a18d4 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-pq6f-p382-p92m/GHSA-pq6f-p382-p92m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pq6f-p382-p92m", + "modified": "2025-02-11T15:32:25Z", + "published": "2025-02-11T15:32:25Z", + "aliases": [ + "CVE-2025-26493" + ], + "details": "In JetBrains TeamCity before 2024.12.2 several DOM-based XSS were possible on the Code Inspection Report tab", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26493" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T14:15:31Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-r8rq-6jrf-gqrw/GHSA-r8rq-6jrf-gqrw.json b/advisories/unreviewed/2025/02/GHSA-r8rq-6jrf-gqrw/GHSA-r8rq-6jrf-gqrw.json new file mode 100644 index 00000000000..fd9bc8b25b0 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-r8rq-6jrf-gqrw/GHSA-r8rq-6jrf-gqrw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r8rq-6jrf-gqrw", + "modified": "2025-02-11T15:32:25Z", + "published": "2025-02-11T15:32:25Z", + "aliases": [ + "CVE-2024-33659" + ], + "details": "AMI APTIOV contains a vulnerability in BIOS where an attacker may cause an Improper Input Validation by a local attacker. Successful exploitation of these vulnerabilities may lead to overwriting arbitrary memory and execute arbitrary code at SMM level, also impacting Confidentiality, Integrity, and Availability.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:L/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33659" + }, + { + "type": "WEB", + "url": "https://9443417.fs1.hubspotusercontent-na1.net/hubfs/9443417/Security%20Advisories/2025/AMI-SA-2025002.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T15:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-rf6c-m595-cvc8/GHSA-rf6c-m595-cvc8.json b/advisories/unreviewed/2025/02/GHSA-rf6c-m595-cvc8/GHSA-rf6c-m595-cvc8.json index 7db8a8af855..a7c7dd246eb 100644 --- a/advisories/unreviewed/2025/02/GHSA-rf6c-m595-cvc8/GHSA-rf6c-m595-cvc8.json +++ b/advisories/unreviewed/2025/02/GHSA-rf6c-m595-cvc8/GHSA-rf6c-m595-cvc8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rf6c-m595-cvc8", - "modified": "2025-02-10T21:31:39Z", + "modified": "2025-02-11T15:32:22Z", "published": "2025-02-10T21:31:39Z", "aliases": [ "CVE-2024-54658" ], "details": "The issue was addressed with improved memory handling. This issue is fixed in iOS 17.4 and iPadOS 17.4, Safari 17.4, tvOS 17.4, watchOS 10.4, visionOS 1.1, macOS Sonoma 14.4. Processing web content may lead to a denial-of-service.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-770" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-10T19:15:39Z" diff --git a/advisories/unreviewed/2025/02/GHSA-v7x9-h7r5-85q2/GHSA-v7x9-h7r5-85q2.json b/advisories/unreviewed/2025/02/GHSA-v7x9-h7r5-85q2/GHSA-v7x9-h7r5-85q2.json index f0d9e07af3c..ada52754c2a 100644 --- a/advisories/unreviewed/2025/02/GHSA-v7x9-h7r5-85q2/GHSA-v7x9-h7r5-85q2.json +++ b/advisories/unreviewed/2025/02/GHSA-v7x9-h7r5-85q2/GHSA-v7x9-h7r5-85q2.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/02/GHSA-vv2h-2w3q-3fx7/GHSA-vv2h-2w3q-3fx7.json b/advisories/unreviewed/2025/02/GHSA-vv2h-2w3q-3fx7/GHSA-vv2h-2w3q-3fx7.json new file mode 100644 index 00000000000..a53c7db99d2 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-vv2h-2w3q-3fx7/GHSA-vv2h-2w3q-3fx7.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vv2h-2w3q-3fx7", + "modified": "2025-02-11T15:32:24Z", + "published": "2025-02-11T15:32:24Z", + "aliases": [ + "CVE-2024-12366" + ], + "details": "PandasAI uses an interactive prompt function that is vulnerable to prompt injection and run arbitrary Python code that can lead to Remote Code Execution (RCE) instead of the intended explanation of the natural language processing by the LLM.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12366" + }, + { + "type": "WEB", + "url": "https://docs.getpanda.ai/v3/privacy-security" + }, + { + "type": "WEB", + "url": "https://docs.pandas-ai.com/advanced-security-agent" + }, + { + "type": "WEB", + "url": "https://www.kb.cert.org/vuls/id/148244" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-11T13:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-vwpq-f3cq-q82w/GHSA-vwpq-f3cq-q82w.json b/advisories/unreviewed/2025/02/GHSA-vwpq-f3cq-q82w/GHSA-vwpq-f3cq-q82w.json index 3ed57bc0dd4..017b5e9e208 100644 --- a/advisories/unreviewed/2025/02/GHSA-vwpq-f3cq-q82w/GHSA-vwpq-f3cq-q82w.json +++ b/advisories/unreviewed/2025/02/GHSA-vwpq-f3cq-q82w/GHSA-vwpq-f3cq-q82w.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vwpq-f3cq-q82w", - "modified": "2025-02-11T12:30:54Z", + "modified": "2025-02-11T15:32:22Z", "published": "2025-02-11T12:30:54Z", "aliases": [ "CVE-2025-0525" ], "details": "In affected versions of Octopus Server the preview import feature could be leveraged to identify the existence of a target file. This could provide an adversary with information that may aid in further attacks against the server.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" @@ -25,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-xm77-x3f8-rr93/GHSA-xm77-x3f8-rr93.json b/advisories/unreviewed/2025/02/GHSA-xm77-x3f8-rr93/GHSA-xm77-x3f8-rr93.json index c1ec23412bc..05bfc472212 100644 --- a/advisories/unreviewed/2025/02/GHSA-xm77-x3f8-rr93/GHSA-xm77-x3f8-rr93.json +++ b/advisories/unreviewed/2025/02/GHSA-xm77-x3f8-rr93/GHSA-xm77-x3f8-rr93.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null,