diff --git a/advisories/unreviewed/2025/02/GHSA-8wp9-x25p-8794/GHSA-8wp9-x25p-8794.json b/advisories/github-reviewed/2025/02/GHSA-8wp9-x25p-8794/GHSA-8wp9-x25p-8794.json similarity index 66% rename from advisories/unreviewed/2025/02/GHSA-8wp9-x25p-8794/GHSA-8wp9-x25p-8794.json rename to advisories/github-reviewed/2025/02/GHSA-8wp9-x25p-8794/GHSA-8wp9-x25p-8794.json index 9851a3bb759..85a7126778d 100644 --- a/advisories/unreviewed/2025/02/GHSA-8wp9-x25p-8794/GHSA-8wp9-x25p-8794.json +++ b/advisories/github-reviewed/2025/02/GHSA-8wp9-x25p-8794/GHSA-8wp9-x25p-8794.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-8wp9-x25p-8794", - "modified": "2025-02-23T18:30:24Z", + "modified": "2025-02-24T18:30:26Z", "published": "2025-02-23T18:30:24Z", "aliases": [ "CVE-2025-1467" ], + "summary": "tarteaucitron Cross-site Scripting (XSS)", "details": "Versions of the package tarteaucitronjs before 1.17.0 are vulnerable to Cross-site Scripting (XSS) via the getElemWidth() and getElemHeight(). This is related to [SNYK-JS-TARTEAUCITRONJS-8366541](https://security.snyk.io/vuln/SNYK-JS-TARTEAUCITRONJS-8366541)", "severity": [ { @@ -14,10 +15,30 @@ }, { "type": "CVSS_V4", - "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N/E:P" + } + ], + "affected": [ + { + "package": { + "ecosystem": "npm", + "name": "tarteaucitronjs" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.17.0" + } + ] + } + ] } ], - "affected": [], "references": [ { "type": "ADVISORY", @@ -35,6 +56,10 @@ "type": "WEB", "url": "https://gist.github.com/Rudloff/d48f525215bd5426cbb076116c4422dd" }, + { + "type": "PACKAGE", + "url": "https://github.com/AmauriC/tarteaucitron.js" + }, { "type": "WEB", "url": "https://security.snyk.io/vuln/SNYK-JS-TARTEAUCITRONJS-8731160" @@ -44,9 +69,9 @@ "cwe_ids": [ "CWE-79" ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "severity": "LOW", + "github_reviewed": true, + "github_reviewed_at": "2025-02-24T18:30:25Z", "nvd_published_at": "2025-02-23T16:15:08Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-x8q6-cchr-p7m6/GHSA-x8q6-cchr-p7m6.json b/advisories/github-reviewed/2025/02/GHSA-x8q6-cchr-p7m6/GHSA-x8q6-cchr-p7m6.json similarity index 75% rename from advisories/unreviewed/2025/02/GHSA-x8q6-cchr-p7m6/GHSA-x8q6-cchr-p7m6.json rename to advisories/github-reviewed/2025/02/GHSA-x8q6-cchr-p7m6/GHSA-x8q6-cchr-p7m6.json index 5445f024811..3ba0e792544 100644 --- a/advisories/unreviewed/2025/02/GHSA-x8q6-cchr-p7m6/GHSA-x8q6-cchr-p7m6.json +++ b/advisories/github-reviewed/2025/02/GHSA-x8q6-cchr-p7m6/GHSA-x8q6-cchr-p7m6.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-x8q6-cchr-p7m6", - "modified": "2025-02-23T15:30:58Z", + "modified": "2025-02-24T18:31:10Z", "published": "2025-02-23T15:30:58Z", "aliases": [ "CVE-2025-1584" ], + "summary": "Solon Path Traversal", "details": "A vulnerability classified as problematic was found in opensolon Solon up to 3.0.8. This vulnerability affects unknown code of the file solon-projects/solon-web/solon-web-staticfiles/src/main/java/org/noear/solon/web/staticfiles/StaticMappings.java. The manipulation leads to path traversal: '../filedir'. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 3.0.9 is able to address this issue. The name of the patch is f46e47fd1f8455b9467d7ead3cdb0509115b2ef1. It is recommended to upgrade the affected component.", "severity": [ { @@ -14,10 +15,30 @@ }, { "type": "CVSS_V4", - "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Maven", + "name": "org.noear:solon-web-staticfiles" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "3.0.9" + } + ] + } + ] } ], - "affected": [], "references": [ { "type": "ADVISORY", @@ -39,6 +60,10 @@ "type": "WEB", "url": "https://github.com/opensolon/solon/commit/f46e47fd1f8455b9467d7ead3cdb0509115b2ef1" }, + { + "type": "PACKAGE", + "url": "https://github.com/opensolon/solon" + }, { "type": "WEB", "url": "https://vuldb.com/?ctiid.296560" @@ -57,8 +82,8 @@ "CWE-23" ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2025-02-24T18:31:10Z", "nvd_published_at": "2025-02-23T13:15:09Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2022/01/GHSA-6rrc-7vqp-364c/GHSA-6rrc-7vqp-364c.json b/advisories/unreviewed/2022/01/GHSA-6rrc-7vqp-364c/GHSA-6rrc-7vqp-364c.json index cbf85f62ba0..7f96e5cc663 100644 --- a/advisories/unreviewed/2022/01/GHSA-6rrc-7vqp-364c/GHSA-6rrc-7vqp-364c.json +++ b/advisories/unreviewed/2022/01/GHSA-6rrc-7vqp-364c/GHSA-6rrc-7vqp-364c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6rrc-7vqp-364c", - "modified": "2022-03-17T00:06:11Z", + "modified": "2025-02-24T18:32:07Z", "published": "2022-01-27T00:01:13Z", "aliases": [ "CVE-2021-22600" diff --git a/advisories/unreviewed/2022/05/GHSA-7cc9-8vjg-gpp8/GHSA-7cc9-8vjg-gpp8.json b/advisories/unreviewed/2022/05/GHSA-7cc9-8vjg-gpp8/GHSA-7cc9-8vjg-gpp8.json index 264c61c2b36..56e1555e76e 100644 --- a/advisories/unreviewed/2022/05/GHSA-7cc9-8vjg-gpp8/GHSA-7cc9-8vjg-gpp8.json +++ b/advisories/unreviewed/2022/05/GHSA-7cc9-8vjg-gpp8/GHSA-7cc9-8vjg-gpp8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7cc9-8vjg-gpp8", - "modified": "2022-05-13T01:17:39Z", + "modified": "2025-02-24T18:32:03Z", "published": "2022-05-13T01:17:39Z", "aliases": [ "CVE-2017-3066" diff --git a/advisories/unreviewed/2022/05/GHSA-87q2-rr35-r6c9/GHSA-87q2-rr35-r6c9.json b/advisories/unreviewed/2022/05/GHSA-87q2-rr35-r6c9/GHSA-87q2-rr35-r6c9.json index eee445372f2..39bc92a39bc 100644 --- a/advisories/unreviewed/2022/05/GHSA-87q2-rr35-r6c9/GHSA-87q2-rr35-r6c9.json +++ b/advisories/unreviewed/2022/05/GHSA-87q2-rr35-r6c9/GHSA-87q2-rr35-r6c9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-87q2-rr35-r6c9", - "modified": "2022-05-24T17:02:07Z", + "modified": "2025-02-24T18:32:03Z", "published": "2022-05-24T17:02:07Z", "aliases": [ "CVE-2019-15271" ], "details": "A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an authenticated, remote attacker to execute arbitrary commands with root privileges. The attacker must have either a valid credential or an active session token. The vulnerability is due to lack of input validation of the HTTP payload. An attacker could exploit this vulnerability by sending a malicious HTTP request to the web-based management interface of the targeted device. A successful exploit could allow the attacker to execute commands with root privileges.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-502" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/05/GHSA-f7vj-6cqm-9xgc/GHSA-f7vj-6cqm-9xgc.json b/advisories/unreviewed/2022/05/GHSA-f7vj-6cqm-9xgc/GHSA-f7vj-6cqm-9xgc.json index 2cb62eb80fe..8d0e84ee5ab 100644 --- a/advisories/unreviewed/2022/05/GHSA-f7vj-6cqm-9xgc/GHSA-f7vj-6cqm-9xgc.json +++ b/advisories/unreviewed/2022/05/GHSA-f7vj-6cqm-9xgc/GHSA-f7vj-6cqm-9xgc.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-134", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/05/GHSA-xpxv-rfwh-rcfc/GHSA-xpxv-rfwh-rcfc.json b/advisories/unreviewed/2022/05/GHSA-xpxv-rfwh-rcfc/GHSA-xpxv-rfwh-rcfc.json index 2b20ea057f6..c7d01ae3c70 100644 --- a/advisories/unreviewed/2022/05/GHSA-xpxv-rfwh-rcfc/GHSA-xpxv-rfwh-rcfc.json +++ b/advisories/unreviewed/2022/05/GHSA-xpxv-rfwh-rcfc/GHSA-xpxv-rfwh-rcfc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xpxv-rfwh-rcfc", - "modified": "2022-05-24T17:09:20Z", + "modified": "2025-02-24T18:32:03Z", "published": "2022-05-24T17:09:20Z", "aliases": [ "CVE-2020-3153" ], "details": "A vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated local attacker to copy user-supplied files to system level directories with system level privileges. The vulnerability is due to the incorrect handling of directory paths. An attacker could exploit this vulnerability by creating a malicious file and copying the file to a system directory. An exploit could allow the attacker to copy malicious files to arbitrary locations with system level privileges. This could include DLL pre-loading, DLL hijacking, and other related attacks. To exploit this vulnerability, the attacker needs valid credentials on the Windows system.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N" + } + ], "affected": [], "references": [ {