From 5913d4ba5f4e48d304304db6d905da2b357bb687 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 17 Mar 2025 06:31:56 +0000 Subject: [PATCH] Publish Advisories GHSA-53x3-6ggr-2vp5 GHSA-7q4p-93g6-4wf9 GHSA-7qjx-378m-p8hm GHSA-9c2w-rfmh-q65f GHSA-c28h-3w95-v6xg GHSA-c52f-45m8-h2r6 GHSA-gc32-fmf5-c742 GHSA-gf8x-6jh7-3mjv GHSA-hp9r-wcfh-72pr GHSA-q3rr-g46f-jgqr GHSA-wv34-xcj8-f3mq GHSA-4hg3-3xxj-v749 GHSA-7477-x7rw-jvh6 GHSA-8wxh-j3rh-hq7g GHSA-9wfr-r3p3-m3fw GHSA-g3h4-pvrv-w9c2 GHSA-qvh6-jh7v-8fmr GHSA-r2xw-g69f-4fpr GHSA-rgc8-9ff9-6j39 --- .../GHSA-53x3-6ggr-2vp5.json | 6 +- .../GHSA-7q4p-93g6-4wf9.json | 22 +++++++- .../GHSA-7qjx-378m-p8hm.json | 22 +++++++- .../GHSA-9c2w-rfmh-q65f.json | 6 +- .../GHSA-c28h-3w95-v6xg.json | 22 +++++++- .../GHSA-c52f-45m8-h2r6.json | 22 +++++++- .../GHSA-gc32-fmf5-c742.json | 22 +++++++- .../GHSA-gf8x-6jh7-3mjv.json | 22 +++++++- .../GHSA-hp9r-wcfh-72pr.json | 22 +++++++- .../GHSA-q3rr-g46f-jgqr.json | 6 +- .../GHSA-wv34-xcj8-f3mq.json | 22 +++++++- .../GHSA-4hg3-3xxj-v749.json | 48 ++++++++++++++++ .../GHSA-7477-x7rw-jvh6.json | 52 +++++++++++++++++ .../GHSA-8wxh-j3rh-hq7g.json | 40 +++++++++++++ .../GHSA-9wfr-r3p3-m3fw.json | 56 +++++++++++++++++++ .../GHSA-g3h4-pvrv-w9c2.json | 40 +++++++++++++ .../GHSA-qvh6-jh7v-8fmr.json | 56 +++++++++++++++++++ .../GHSA-r2xw-g69f-4fpr.json | 52 +++++++++++++++++ .../GHSA-rgc8-9ff9-6j39.json | 56 +++++++++++++++++++ 19 files changed, 583 insertions(+), 11 deletions(-) create mode 100644 advisories/unreviewed/2025/03/GHSA-4hg3-3xxj-v749/GHSA-4hg3-3xxj-v749.json create mode 100644 advisories/unreviewed/2025/03/GHSA-7477-x7rw-jvh6/GHSA-7477-x7rw-jvh6.json create mode 100644 advisories/unreviewed/2025/03/GHSA-8wxh-j3rh-hq7g/GHSA-8wxh-j3rh-hq7g.json create mode 100644 advisories/unreviewed/2025/03/GHSA-9wfr-r3p3-m3fw/GHSA-9wfr-r3p3-m3fw.json create mode 100644 advisories/unreviewed/2025/03/GHSA-g3h4-pvrv-w9c2/GHSA-g3h4-pvrv-w9c2.json create mode 100644 advisories/unreviewed/2025/03/GHSA-qvh6-jh7v-8fmr/GHSA-qvh6-jh7v-8fmr.json create mode 100644 advisories/unreviewed/2025/03/GHSA-r2xw-g69f-4fpr/GHSA-r2xw-g69f-4fpr.json create mode 100644 advisories/unreviewed/2025/03/GHSA-rgc8-9ff9-6j39/GHSA-rgc8-9ff9-6j39.json diff --git a/advisories/unreviewed/2025/02/GHSA-53x3-6ggr-2vp5/GHSA-53x3-6ggr-2vp5.json b/advisories/unreviewed/2025/02/GHSA-53x3-6ggr-2vp5/GHSA-53x3-6ggr-2vp5.json index 902a0233e58..766b0a3e11a 100644 --- a/advisories/unreviewed/2025/02/GHSA-53x3-6ggr-2vp5/GHSA-53x3-6ggr-2vp5.json +++ b/advisories/unreviewed/2025/02/GHSA-53x3-6ggr-2vp5/GHSA-53x3-6ggr-2vp5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-53x3-6ggr-2vp5", - "modified": "2025-03-07T00:31:55Z", + "modified": "2025-03-17T06:30:25Z", "published": "2025-02-28T18:31:04Z", "aliases": [ "CVE-2025-26263" @@ -26,6 +26,10 @@ { "type": "WEB", "url": "https://www.geovision.com.tw/download/product/GV-ASManager" + }, + { + "type": "WEB", + "url": "https://www.geovision.com.tw/download/product/GV-ASManager%20%28Access%20Control%29" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/02/GHSA-7q4p-93g6-4wf9/GHSA-7q4p-93g6-4wf9.json b/advisories/unreviewed/2025/02/GHSA-7q4p-93g6-4wf9/GHSA-7q4p-93g6-4wf9.json index 7e09eafc19e..c9fbdec92c7 100644 --- a/advisories/unreviewed/2025/02/GHSA-7q4p-93g6-4wf9/GHSA-7q4p-93g6-4wf9.json +++ b/advisories/unreviewed/2025/02/GHSA-7q4p-93g6-4wf9/GHSA-7q4p-93g6-4wf9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7q4p-93g6-4wf9", - "modified": "2025-03-17T03:30:23Z", + "modified": "2025-03-17T06:30:24Z", "published": "2025-02-25T18:31:24Z", "aliases": [ "CVE-2025-26600" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:2502" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2861" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:2862" @@ -35,6 +39,14 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:2865" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2866" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2873" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:2874" @@ -43,6 +55,14 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:2875" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2879" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2880" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-26600" diff --git a/advisories/unreviewed/2025/02/GHSA-7qjx-378m-p8hm/GHSA-7qjx-378m-p8hm.json b/advisories/unreviewed/2025/02/GHSA-7qjx-378m-p8hm/GHSA-7qjx-378m-p8hm.json index fa8ed84045b..2655d919e95 100644 --- a/advisories/unreviewed/2025/02/GHSA-7qjx-378m-p8hm/GHSA-7qjx-378m-p8hm.json +++ b/advisories/unreviewed/2025/02/GHSA-7qjx-378m-p8hm/GHSA-7qjx-378m-p8hm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7qjx-378m-p8hm", - "modified": "2025-03-17T03:30:22Z", + "modified": "2025-03-17T06:30:24Z", "published": "2025-02-25T18:31:24Z", "aliases": [ "CVE-2025-26597" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:2502" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2861" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:2862" @@ -35,6 +39,14 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:2865" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2866" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2873" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:2874" @@ -43,6 +55,14 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:2875" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2879" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2880" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-26597" diff --git a/advisories/unreviewed/2025/02/GHSA-9c2w-rfmh-q65f/GHSA-9c2w-rfmh-q65f.json b/advisories/unreviewed/2025/02/GHSA-9c2w-rfmh-q65f/GHSA-9c2w-rfmh-q65f.json index a4e9ce66241..a4cb1146ebb 100644 --- a/advisories/unreviewed/2025/02/GHSA-9c2w-rfmh-q65f/GHSA-9c2w-rfmh-q65f.json +++ b/advisories/unreviewed/2025/02/GHSA-9c2w-rfmh-q65f/GHSA-9c2w-rfmh-q65f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9c2w-rfmh-q65f", - "modified": "2025-02-28T18:31:02Z", + "modified": "2025-03-17T06:30:24Z", "published": "2025-02-28T00:30:51Z", "aliases": [ "CVE-2025-26264" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://github.com/DRAGOWN/CVE-2025-26264" + }, + { + "type": "WEB", + "url": "https://www.geovision.com.tw/download/product/GV-ASManager%20%28Access%20Control%29" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/02/GHSA-c28h-3w95-v6xg/GHSA-c28h-3w95-v6xg.json b/advisories/unreviewed/2025/02/GHSA-c28h-3w95-v6xg/GHSA-c28h-3w95-v6xg.json index 6fce98a069d..118322f8867 100644 --- a/advisories/unreviewed/2025/02/GHSA-c28h-3w95-v6xg/GHSA-c28h-3w95-v6xg.json +++ b/advisories/unreviewed/2025/02/GHSA-c28h-3w95-v6xg/GHSA-c28h-3w95-v6xg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c28h-3w95-v6xg", - "modified": "2025-03-17T03:30:23Z", + "modified": "2025-03-17T06:30:24Z", "published": "2025-02-25T18:31:24Z", "aliases": [ "CVE-2025-26598" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:2502" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2861" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:2862" @@ -35,6 +39,14 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:2865" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2866" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2873" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:2874" @@ -43,6 +55,14 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:2875" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2879" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2880" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-26598" diff --git a/advisories/unreviewed/2025/02/GHSA-c52f-45m8-h2r6/GHSA-c52f-45m8-h2r6.json b/advisories/unreviewed/2025/02/GHSA-c52f-45m8-h2r6/GHSA-c52f-45m8-h2r6.json index efd9e143ff6..453fa19eeb5 100644 --- a/advisories/unreviewed/2025/02/GHSA-c52f-45m8-h2r6/GHSA-c52f-45m8-h2r6.json +++ b/advisories/unreviewed/2025/02/GHSA-c52f-45m8-h2r6/GHSA-c52f-45m8-h2r6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c52f-45m8-h2r6", - "modified": "2025-03-17T03:30:22Z", + "modified": "2025-03-17T06:30:24Z", "published": "2025-02-25T18:31:24Z", "aliases": [ "CVE-2025-26596" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:2502" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2861" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:2862" @@ -35,6 +39,14 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:2865" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2866" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2873" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:2874" @@ -43,6 +55,14 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:2875" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2879" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2880" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-26596" diff --git a/advisories/unreviewed/2025/02/GHSA-gc32-fmf5-c742/GHSA-gc32-fmf5-c742.json b/advisories/unreviewed/2025/02/GHSA-gc32-fmf5-c742/GHSA-gc32-fmf5-c742.json index 3574bb7dd8f..a0bcd1d98f3 100644 --- a/advisories/unreviewed/2025/02/GHSA-gc32-fmf5-c742/GHSA-gc32-fmf5-c742.json +++ b/advisories/unreviewed/2025/02/GHSA-gc32-fmf5-c742/GHSA-gc32-fmf5-c742.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gc32-fmf5-c742", - "modified": "2025-03-17T03:30:22Z", + "modified": "2025-03-17T06:30:24Z", "published": "2025-02-25T18:31:24Z", "aliases": [ "CVE-2025-26594" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:2502" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2861" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:2862" @@ -35,6 +39,14 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:2865" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2866" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2873" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:2874" @@ -43,6 +55,14 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:2875" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2879" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2880" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-26594" diff --git a/advisories/unreviewed/2025/02/GHSA-gf8x-6jh7-3mjv/GHSA-gf8x-6jh7-3mjv.json b/advisories/unreviewed/2025/02/GHSA-gf8x-6jh7-3mjv/GHSA-gf8x-6jh7-3mjv.json index cd8e4d52c75..00930a66c15 100644 --- a/advisories/unreviewed/2025/02/GHSA-gf8x-6jh7-3mjv/GHSA-gf8x-6jh7-3mjv.json +++ b/advisories/unreviewed/2025/02/GHSA-gf8x-6jh7-3mjv/GHSA-gf8x-6jh7-3mjv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gf8x-6jh7-3mjv", - "modified": "2025-03-17T03:30:22Z", + "modified": "2025-03-17T06:30:25Z", "published": "2025-02-25T18:31:24Z", "aliases": [ "CVE-2025-26601" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:2502" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2861" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:2862" @@ -35,6 +39,14 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:2865" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2866" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2873" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:2874" @@ -43,6 +55,14 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:2875" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2879" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2880" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-26601" diff --git a/advisories/unreviewed/2025/02/GHSA-hp9r-wcfh-72pr/GHSA-hp9r-wcfh-72pr.json b/advisories/unreviewed/2025/02/GHSA-hp9r-wcfh-72pr/GHSA-hp9r-wcfh-72pr.json index a9bb648928c..459511fcf56 100644 --- a/advisories/unreviewed/2025/02/GHSA-hp9r-wcfh-72pr/GHSA-hp9r-wcfh-72pr.json +++ b/advisories/unreviewed/2025/02/GHSA-hp9r-wcfh-72pr/GHSA-hp9r-wcfh-72pr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hp9r-wcfh-72pr", - "modified": "2025-03-17T03:30:22Z", + "modified": "2025-03-17T06:30:24Z", "published": "2025-02-25T18:31:24Z", "aliases": [ "CVE-2025-26595" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:2502" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2861" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:2862" @@ -35,6 +39,14 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:2865" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2866" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2873" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:2874" @@ -43,6 +55,14 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:2875" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2879" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2880" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-26595" diff --git a/advisories/unreviewed/2025/02/GHSA-q3rr-g46f-jgqr/GHSA-q3rr-g46f-jgqr.json b/advisories/unreviewed/2025/02/GHSA-q3rr-g46f-jgqr/GHSA-q3rr-g46f-jgqr.json index 32dff6e24f0..2ae7ca7c541 100644 --- a/advisories/unreviewed/2025/02/GHSA-q3rr-g46f-jgqr/GHSA-q3rr-g46f-jgqr.json +++ b/advisories/unreviewed/2025/02/GHSA-q3rr-g46f-jgqr/GHSA-q3rr-g46f-jgqr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q3rr-g46f-jgqr", - "modified": "2025-03-17T03:30:22Z", + "modified": "2025-03-17T06:30:24Z", "published": "2025-02-19T21:31:38Z", "aliases": [ "CVE-2025-0624" @@ -47,6 +47,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:2867" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2869" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-0624" diff --git a/advisories/unreviewed/2025/02/GHSA-wv34-xcj8-f3mq/GHSA-wv34-xcj8-f3mq.json b/advisories/unreviewed/2025/02/GHSA-wv34-xcj8-f3mq/GHSA-wv34-xcj8-f3mq.json index ca1e185822a..c72af7e9c61 100644 --- a/advisories/unreviewed/2025/02/GHSA-wv34-xcj8-f3mq/GHSA-wv34-xcj8-f3mq.json +++ b/advisories/unreviewed/2025/02/GHSA-wv34-xcj8-f3mq/GHSA-wv34-xcj8-f3mq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wv34-xcj8-f3mq", - "modified": "2025-03-17T03:30:22Z", + "modified": "2025-03-17T06:30:24Z", "published": "2025-02-25T18:31:24Z", "aliases": [ "CVE-2025-26599" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:2502" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2861" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:2862" @@ -35,6 +39,14 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:2865" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2866" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2873" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:2874" @@ -43,6 +55,14 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:2875" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2879" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:2880" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-26599" diff --git a/advisories/unreviewed/2025/03/GHSA-4hg3-3xxj-v749/GHSA-4hg3-3xxj-v749.json b/advisories/unreviewed/2025/03/GHSA-4hg3-3xxj-v749/GHSA-4hg3-3xxj-v749.json new file mode 100644 index 00000000000..cbc9d786af7 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-4hg3-3xxj-v749/GHSA-4hg3-3xxj-v749.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4hg3-3xxj-v749", + "modified": "2025-03-17T06:30:25Z", + "published": "2025-03-17T06:30:25Z", + "aliases": [ + "CVE-2025-2361" + ], + "details": "A vulnerability was found in Mercurial SCM 4.5.3/71.19.145.211. It has been declared as problematic. This vulnerability affects unknown code of the component Web Interface. The manipulation of the argument cmd leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2361" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.299860" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.299860" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.514024" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T05:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-7477-x7rw-jvh6/GHSA-7477-x7rw-jvh6.json b/advisories/unreviewed/2025/03/GHSA-7477-x7rw-jvh6/GHSA-7477-x7rw-jvh6.json new file mode 100644 index 00000000000..c8c41bcb0d3 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-7477-x7rw-jvh6/GHSA-7477-x7rw-jvh6.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7477-x7rw-jvh6", + "modified": "2025-03-17T06:30:25Z", + "published": "2025-03-17T06:30:25Z", + "aliases": [ + "CVE-2025-2363" + ], + "details": "A vulnerability classified as critical has been found in lenve VBlog up to 1.0.0. Affected is the function uploadImg of the file blogserver/src/main/java/org/sang/controller/ArticleController.java. The manipulation of the argument filename leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2363" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.299862" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.299862" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.514721" + }, + { + "type": "WEB", + "url": "https://www.notion.so/Arbitrary-File-Upload-Vulnerability-in-VBlog-1-0-0-1adc693918ed8067b19ed9c61381024b" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T06:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-8wxh-j3rh-hq7g/GHSA-8wxh-j3rh-hq7g.json b/advisories/unreviewed/2025/03/GHSA-8wxh-j3rh-hq7g/GHSA-8wxh-j3rh-hq7g.json new file mode 100644 index 00000000000..daca421ca6d --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-8wxh-j3rh-hq7g/GHSA-8wxh-j3rh-hq7g.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8wxh-j3rh-hq7g", + "modified": "2025-03-17T06:30:25Z", + "published": "2025-03-17T06:30:25Z", + "aliases": [ + "CVE-2025-2395" + ], + "details": "The U-Office Force from e-Excellence has an Improper Authentication vulnerability, allowing unauthenticated remote attackers to use a particular API and alter cookies to log in as an administrator.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2395" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/en/cp-139-10012-d5bbc-2.html" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/tw/cp-132-10011-3de72-1.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-565" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T06:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9wfr-r3p3-m3fw/GHSA-9wfr-r3p3-m3fw.json b/advisories/unreviewed/2025/03/GHSA-9wfr-r3p3-m3fw/GHSA-9wfr-r3p3-m3fw.json new file mode 100644 index 00000000000..a768af613a1 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-9wfr-r3p3-m3fw/GHSA-9wfr-r3p3-m3fw.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9wfr-r3p3-m3fw", + "modified": "2025-03-17T06:30:25Z", + "published": "2025-03-17T06:30:25Z", + "aliases": [ + "CVE-2025-2360" + ], + "details": "A vulnerability classified as critical was found in D-Link DIR-823G 1.0.2B05_20181207. Affected by this vulnerability is the function SetUpnpSettings of the file /HNAP1/ of the component UPnP Service. The manipulation of the argument SOAPAction leads to improper authorization. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2360" + }, + { + "type": "WEB", + "url": "https://lavender-bicycle-a5a.notion.site/D-Link-DIR-823G-SetUpnpSettings-1ac53a41781f80d1a290c8d5da3e795e?pvs=4" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.299827" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.299827" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.513751" + }, + { + "type": "WEB", + "url": "https://www.dlink.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T04:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-g3h4-pvrv-w9c2/GHSA-g3h4-pvrv-w9c2.json b/advisories/unreviewed/2025/03/GHSA-g3h4-pvrv-w9c2/GHSA-g3h4-pvrv-w9c2.json new file mode 100644 index 00000000000..6ec19bbf2c7 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-g3h4-pvrv-w9c2/GHSA-g3h4-pvrv-w9c2.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g3h4-pvrv-w9c2", + "modified": "2025-03-17T06:30:25Z", + "published": "2025-03-17T06:30:25Z", + "aliases": [ + "CVE-2025-2396" + ], + "details": "The U-Office Force from e-Excellence has an Arbitrary File Upload vulnerability, allowing remote attackers with regular privileges to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2396" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/en/cp-139-10014-69aa5-2.html" + }, + { + "type": "WEB", + "url": "https://www.twcert.org.tw/tw/cp-132-10013-0d371-1.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-434" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T06:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-qvh6-jh7v-8fmr/GHSA-qvh6-jh7v-8fmr.json b/advisories/unreviewed/2025/03/GHSA-qvh6-jh7v-8fmr/GHSA-qvh6-jh7v-8fmr.json new file mode 100644 index 00000000000..232097c9bca --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-qvh6-jh7v-8fmr/GHSA-qvh6-jh7v-8fmr.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qvh6-jh7v-8fmr", + "modified": "2025-03-17T06:30:25Z", + "published": "2025-03-17T06:30:25Z", + "aliases": [ + "CVE-2025-2359" + ], + "details": "A vulnerability classified as critical has been found in D-Link DIR-823G 1.0.2B05_20181207. Affected is the function SetDDNSSettings of the file /HNAP1/ of the component DDNS Service. The manipulation of the argument SOAPAction leads to improper authorization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2359" + }, + { + "type": "WEB", + "url": "https://lavender-bicycle-a5a.notion.site/D-Link-DIR-823G-SetDDNSSettings-1ac53a41781f80d98649dd3cbe106e9b?pvs=4" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.299826" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.299826" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.513750" + }, + { + "type": "WEB", + "url": "https://www.dlink.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T04:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-r2xw-g69f-4fpr/GHSA-r2xw-g69f-4fpr.json b/advisories/unreviewed/2025/03/GHSA-r2xw-g69f-4fpr/GHSA-r2xw-g69f-4fpr.json new file mode 100644 index 00000000000..82a1cb3fdac --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-r2xw-g69f-4fpr/GHSA-r2xw-g69f-4fpr.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r2xw-g69f-4fpr", + "modified": "2025-03-17T06:30:25Z", + "published": "2025-03-17T06:30:25Z", + "aliases": [ + "CVE-2025-2364" + ], + "details": "A vulnerability classified as problematic was found in lenve VBlog up to 1.0.0. Affected by this vulnerability is the function addNewArticle of the file blogserver/src/main/java/org/sang/service/ArticleService.java. The manipulation of the argument mdContent/htmlContent leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2364" + }, + { + "type": "WEB", + "url": "https://magnificent-dill-351.notion.site/Stored-XSS-Vulnerability-in-VBlog-1-0-0-1adc693918ed80d9bd08e03df0ed7a98" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.299863" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.299863" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.514763" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T06:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-rgc8-9ff9-6j39/GHSA-rgc8-9ff9-6j39.json b/advisories/unreviewed/2025/03/GHSA-rgc8-9ff9-6j39/GHSA-rgc8-9ff9-6j39.json new file mode 100644 index 00000000000..2141a87b97e --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-rgc8-9ff9-6j39/GHSA-rgc8-9ff9-6j39.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rgc8-9ff9-6j39", + "modified": "2025-03-17T06:30:25Z", + "published": "2025-03-17T06:30:25Z", + "aliases": [ + "CVE-2025-2362" + ], + "details": "A vulnerability was found in PHPGurukul Pre-School Enrollment System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/contact-us.php. The manipulation of the argument mobnum leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2362" + }, + { + "type": "WEB", + "url": "https://github.com/12T40910/CVE/issues/3" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.299861" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.299861" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.514464" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-17T05:15:37Z" + } +} \ No newline at end of file