diff --git a/advisories/unreviewed/2023/02/GHSA-35p8-j96m-5g6p/GHSA-35p8-j96m-5g6p.json b/advisories/unreviewed/2023/02/GHSA-35p8-j96m-5g6p/GHSA-35p8-j96m-5g6p.json index 06eb80ee774..6be9b7e48ba 100644 --- a/advisories/unreviewed/2023/02/GHSA-35p8-j96m-5g6p/GHSA-35p8-j96m-5g6p.json +++ b/advisories/unreviewed/2023/02/GHSA-35p8-j96m-5g6p/GHSA-35p8-j96m-5g6p.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-125" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-4948-rc3p-cvv8/GHSA-4948-rc3p-cvv8.json b/advisories/unreviewed/2023/02/GHSA-4948-rc3p-cvv8/GHSA-4948-rc3p-cvv8.json index 33fc0668c65..20aeff42f2e 100644 --- a/advisories/unreviewed/2023/02/GHSA-4948-rc3p-cvv8/GHSA-4948-rc3p-cvv8.json +++ b/advisories/unreviewed/2023/02/GHSA-4948-rc3p-cvv8/GHSA-4948-rc3p-cvv8.json @@ -41,7 +41,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-125" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-9vvm-3ggf-936m/GHSA-9vvm-3ggf-936m.json b/advisories/unreviewed/2023/02/GHSA-9vvm-3ggf-936m/GHSA-9vvm-3ggf-936m.json index c34ab3e5b13..1108f041c3d 100644 --- a/advisories/unreviewed/2023/02/GHSA-9vvm-3ggf-936m/GHSA-9vvm-3ggf-936m.json +++ b/advisories/unreviewed/2023/02/GHSA-9vvm-3ggf-936m/GHSA-9vvm-3ggf-936m.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-c8gv-h2p7-9j69/GHSA-c8gv-h2p7-9j69.json b/advisories/unreviewed/2023/02/GHSA-c8gv-h2p7-9j69/GHSA-c8gv-h2p7-9j69.json index ce0b880e28c..d6c9e672757 100644 --- a/advisories/unreviewed/2023/02/GHSA-c8gv-h2p7-9j69/GHSA-c8gv-h2p7-9j69.json +++ b/advisories/unreviewed/2023/02/GHSA-c8gv-h2p7-9j69/GHSA-c8gv-h2p7-9j69.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c8gv-h2p7-9j69", - "modified": "2023-03-03T03:30:24Z", + "modified": "2025-03-12T15:31:48Z", "published": "2023-02-23T06:30:16Z", "aliases": [ "CVE-2022-48341" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-269" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-h8qq-2m4g-fp6f/GHSA-h8qq-2m4g-fp6f.json b/advisories/unreviewed/2023/02/GHSA-h8qq-2m4g-fp6f/GHSA-h8qq-2m4g-fp6f.json index 7e4b1e12d71..07c4cb2b558 100644 --- a/advisories/unreviewed/2023/02/GHSA-h8qq-2m4g-fp6f/GHSA-h8qq-2m4g-fp6f.json +++ b/advisories/unreviewed/2023/02/GHSA-h8qq-2m4g-fp6f/GHSA-h8qq-2m4g-fp6f.json @@ -41,7 +41,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-288" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-mfq6-mjjx-mp7f/GHSA-mfq6-mjjx-mp7f.json b/advisories/unreviewed/2023/02/GHSA-mfq6-mjjx-mp7f/GHSA-mfq6-mjjx-mp7f.json index a35daca626c..529b635040d 100644 --- a/advisories/unreviewed/2023/02/GHSA-mfq6-mjjx-mp7f/GHSA-mfq6-mjjx-mp7f.json +++ b/advisories/unreviewed/2023/02/GHSA-mfq6-mjjx-mp7f/GHSA-mfq6-mjjx-mp7f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mfq6-mjjx-mp7f", - "modified": "2023-03-03T21:30:18Z", + "modified": "2025-03-12T15:31:49Z", "published": "2023-02-23T21:30:16Z", "aliases": [ "CVE-2023-23919" diff --git a/advisories/unreviewed/2023/02/GHSA-r43f-xq38-4w4r/GHSA-r43f-xq38-4w4r.json b/advisories/unreviewed/2023/02/GHSA-r43f-xq38-4w4r/GHSA-r43f-xq38-4w4r.json index a22d336f4d8..ba3bf2ddb17 100644 --- a/advisories/unreviewed/2023/02/GHSA-r43f-xq38-4w4r/GHSA-r43f-xq38-4w4r.json +++ b/advisories/unreviewed/2023/02/GHSA-r43f-xq38-4w4r/GHSA-r43f-xq38-4w4r.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-200", "CWE-668" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/03/GHSA-26x3-cx3r-433v/GHSA-26x3-cx3r-433v.json b/advisories/unreviewed/2024/03/GHSA-26x3-cx3r-433v/GHSA-26x3-cx3r-433v.json index 6cc8254ef78..9b0c5112c88 100644 --- a/advisories/unreviewed/2024/03/GHSA-26x3-cx3r-433v/GHSA-26x3-cx3r-433v.json +++ b/advisories/unreviewed/2024/03/GHSA-26x3-cx3r-433v/GHSA-26x3-cx3r-433v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-26x3-cx3r-433v", - "modified": "2024-03-01T09:31:06Z", + "modified": "2025-03-12T15:31:50Z", "published": "2024-03-01T09:31:06Z", "aliases": [ "CVE-2024-1859" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-502" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-62g5-mhwv-6rw4/GHSA-62g5-mhwv-6rw4.json b/advisories/unreviewed/2024/03/GHSA-62g5-mhwv-6rw4/GHSA-62g5-mhwv-6rw4.json index ab8c26a9292..33ac5f22429 100644 --- a/advisories/unreviewed/2024/03/GHSA-62g5-mhwv-6rw4/GHSA-62g5-mhwv-6rw4.json +++ b/advisories/unreviewed/2024/03/GHSA-62g5-mhwv-6rw4/GHSA-62g5-mhwv-6rw4.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-8p4p-wmq5-rmgp/GHSA-8p4p-wmq5-rmgp.json b/advisories/unreviewed/2024/03/GHSA-8p4p-wmq5-rmgp/GHSA-8p4p-wmq5-rmgp.json index 47c4b37b79f..4ccadd7ea4f 100644 --- a/advisories/unreviewed/2024/03/GHSA-8p4p-wmq5-rmgp/GHSA-8p4p-wmq5-rmgp.json +++ b/advisories/unreviewed/2024/03/GHSA-8p4p-wmq5-rmgp/GHSA-8p4p-wmq5-rmgp.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-9vgg-w578-gv86/GHSA-9vgg-w578-gv86.json b/advisories/unreviewed/2024/03/GHSA-9vgg-w578-gv86/GHSA-9vgg-w578-gv86.json index f4ea6d1f2fd..3a4ac6f999e 100644 --- a/advisories/unreviewed/2024/03/GHSA-9vgg-w578-gv86/GHSA-9vgg-w578-gv86.json +++ b/advisories/unreviewed/2024/03/GHSA-9vgg-w578-gv86/GHSA-9vgg-w578-gv86.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-9wpf-67qh-4ww2/GHSA-9wpf-67qh-4ww2.json b/advisories/unreviewed/2024/03/GHSA-9wpf-67qh-4ww2/GHSA-9wpf-67qh-4ww2.json index 7bf87e9a832..b7eeff88c3a 100644 --- a/advisories/unreviewed/2024/03/GHSA-9wpf-67qh-4ww2/GHSA-9wpf-67qh-4ww2.json +++ b/advisories/unreviewed/2024/03/GHSA-9wpf-67qh-4ww2/GHSA-9wpf-67qh-4ww2.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-c23g-g2cr-qgh6/GHSA-c23g-g2cr-qgh6.json b/advisories/unreviewed/2024/03/GHSA-c23g-g2cr-qgh6/GHSA-c23g-g2cr-qgh6.json index 53a1ccd84d9..d66b3501ab2 100644 --- a/advisories/unreviewed/2024/03/GHSA-c23g-g2cr-qgh6/GHSA-c23g-g2cr-qgh6.json +++ b/advisories/unreviewed/2024/03/GHSA-c23g-g2cr-qgh6/GHSA-c23g-g2cr-qgh6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c23g-g2cr-qgh6", - "modified": "2024-03-08T06:30:32Z", + "modified": "2025-03-12T15:31:54Z", "published": "2024-03-08T06:30:32Z", "aliases": [ "CVE-2024-27613" ], "details": "Numbas editor before 7.3 mishandles reading of themes and extensions.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -25,7 +30,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-08T06:15:52Z" diff --git a/advisories/unreviewed/2024/03/GHSA-gjp2-mc5q-q2cp/GHSA-gjp2-mc5q-q2cp.json b/advisories/unreviewed/2024/03/GHSA-gjp2-mc5q-q2cp/GHSA-gjp2-mc5q-q2cp.json index 3859774777b..590053bd201 100644 --- a/advisories/unreviewed/2024/03/GHSA-gjp2-mc5q-q2cp/GHSA-gjp2-mc5q-q2cp.json +++ b/advisories/unreviewed/2024/03/GHSA-gjp2-mc5q-q2cp/GHSA-gjp2-mc5q-q2cp.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-gw98-m2pc-8pgp/GHSA-gw98-m2pc-8pgp.json b/advisories/unreviewed/2024/03/GHSA-gw98-m2pc-8pgp/GHSA-gw98-m2pc-8pgp.json index e4b99ae4dcc..4d66aa2198a 100644 --- a/advisories/unreviewed/2024/03/GHSA-gw98-m2pc-8pgp/GHSA-gw98-m2pc-8pgp.json +++ b/advisories/unreviewed/2024/03/GHSA-gw98-m2pc-8pgp/GHSA-gw98-m2pc-8pgp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gw98-m2pc-8pgp", - "modified": "2024-03-13T18:31:33Z", + "modified": "2025-03-12T15:31:55Z", "published": "2024-03-13T18:31:33Z", "aliases": [ "CVE-2024-1203" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-89" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-jh7h-6rpx-g936/GHSA-jh7h-6rpx-g936.json b/advisories/unreviewed/2024/03/GHSA-jh7h-6rpx-g936/GHSA-jh7h-6rpx-g936.json index b3d592a641a..a2a3e942da8 100644 --- a/advisories/unreviewed/2024/03/GHSA-jh7h-6rpx-g936/GHSA-jh7h-6rpx-g936.json +++ b/advisories/unreviewed/2024/03/GHSA-jh7h-6rpx-g936/GHSA-jh7h-6rpx-g936.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jh7h-6rpx-g936", - "modified": "2024-03-20T15:32:28Z", + "modified": "2025-03-12T15:31:55Z", "published": "2024-03-20T15:32:28Z", "aliases": [ "CVE-2024-2460" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-m54j-7m8g-cj89/GHSA-m54j-7m8g-cj89.json b/advisories/unreviewed/2024/03/GHSA-m54j-7m8g-cj89/GHSA-m54j-7m8g-cj89.json index 775310976d2..e825507ce95 100644 --- a/advisories/unreviewed/2024/03/GHSA-m54j-7m8g-cj89/GHSA-m54j-7m8g-cj89.json +++ b/advisories/unreviewed/2024/03/GHSA-m54j-7m8g-cj89/GHSA-m54j-7m8g-cj89.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-m54j-7m8g-cj89", - "modified": "2024-03-19T15:30:35Z", + "modified": "2025-03-12T15:31:55Z", "published": "2024-03-19T15:30:35Z", "aliases": [ "CVE-2024-29114" ], - "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in W3 Eden, Inc. Download Manager allows Stored XSS.This issue affects Download Manager: from n/a through 3.2.84.\n\n", + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in W3 Eden, Inc. Download Manager allows Stored XSS.This issue affects Download Manager: from n/a through 3.2.84.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/03/GHSA-rx45-mwg6-x9hq/GHSA-rx45-mwg6-x9hq.json b/advisories/unreviewed/2024/03/GHSA-rx45-mwg6-x9hq/GHSA-rx45-mwg6-x9hq.json index 541f2230dca..171477b6f9e 100644 --- a/advisories/unreviewed/2024/03/GHSA-rx45-mwg6-x9hq/GHSA-rx45-mwg6-x9hq.json +++ b/advisories/unreviewed/2024/03/GHSA-rx45-mwg6-x9hq/GHSA-rx45-mwg6-x9hq.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-89" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-8f7x-6mj4-c65f/GHSA-8f7x-6mj4-c65f.json b/advisories/unreviewed/2024/04/GHSA-8f7x-6mj4-c65f/GHSA-8f7x-6mj4-c65f.json index 5a5a941ac1d..e6371ee4a53 100644 --- a/advisories/unreviewed/2024/04/GHSA-8f7x-6mj4-c65f/GHSA-8f7x-6mj4-c65f.json +++ b/advisories/unreviewed/2024/04/GHSA-8f7x-6mj4-c65f/GHSA-8f7x-6mj4-c65f.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-89" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-3f7x-54cr-7w35/GHSA-3f7x-54cr-7w35.json b/advisories/unreviewed/2025/03/GHSA-3f7x-54cr-7w35/GHSA-3f7x-54cr-7w35.json new file mode 100644 index 00000000000..5abf2547ce4 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-3f7x-54cr-7w35/GHSA-3f7x-54cr-7w35.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3f7x-54cr-7w35", + "modified": "2025-03-12T15:32:05Z", + "published": "2025-03-12T15:32:05Z", + "aliases": [ + "CVE-2025-22954" + ], + "details": "Koha <= 21.11 is contains a SQL Injection vulnerability in /serials/lateissues-export.pl via the supplierid parameter.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22954" + }, + { + "type": "WEB", + "url": "https://bugs.koha-community.org/bugzilla3/show_bug.cgi?id=38829" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-12T15:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-564p-v49m-6qxf/GHSA-564p-v49m-6qxf.json b/advisories/unreviewed/2025/03/GHSA-564p-v49m-6qxf/GHSA-564p-v49m-6qxf.json index a3b13881781..c00aa2de6c5 100644 --- a/advisories/unreviewed/2025/03/GHSA-564p-v49m-6qxf/GHSA-564p-v49m-6qxf.json +++ b/advisories/unreviewed/2025/03/GHSA-564p-v49m-6qxf/GHSA-564p-v49m-6qxf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-564p-v49m-6qxf", - "modified": "2025-03-11T18:32:20Z", + "modified": "2025-03-12T15:32:00Z", "published": "2025-03-11T18:32:20Z", "aliases": [ "CVE-2025-27163" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://helpx.adobe.com/security/products/acrobat/apsb25-14.html" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2134" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/03/GHSA-5cmf-phhp-vr9w/GHSA-5cmf-phhp-vr9w.json b/advisories/unreviewed/2025/03/GHSA-5cmf-phhp-vr9w/GHSA-5cmf-phhp-vr9w.json new file mode 100644 index 00000000000..e7cb53bcdb1 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5cmf-phhp-vr9w/GHSA-5cmf-phhp-vr9w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5cmf-phhp-vr9w", + "modified": "2025-03-12T15:32:05Z", + "published": "2025-03-12T15:32:05Z", + "aliases": [ + "CVE-2025-29903" + ], + "details": "In JetBrains Runtime before 21.0.6b872.80 arbitrary dynamic library execution due to insecure macOS flags was possible", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29903" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-426" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-12T13:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-5rg8-g76j-7fw7/GHSA-5rg8-g76j-7fw7.json b/advisories/unreviewed/2025/03/GHSA-5rg8-g76j-7fw7/GHSA-5rg8-g76j-7fw7.json new file mode 100644 index 00000000000..365f0689785 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-5rg8-g76j-7fw7/GHSA-5rg8-g76j-7fw7.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5rg8-g76j-7fw7", + "modified": "2025-03-12T15:32:06Z", + "published": "2025-03-12T15:32:06Z", + "aliases": [ + "CVE-2025-27915" + ], + "details": "An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A stored cross-site scripting (XSS) vulnerability exists in the Classic Web Client due to insufficient sanitization of HTML content in ICS files. When a user views an e-mail message containing a malicious ICS entry, its embedded JavaScript executes via an ontoggle event inside a
tag. This allows an attacker to run arbitrary JavaScript within the victim's session, potentially leading to unauthorized actions such as setting e-mail filters to redirect messages to an attacker-controlled address. As a result, an attacker can perform unauthorized actions on the victim's account, including e-mail redirection and data exfiltration.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27915" + }, + { + "type": "WEB", + "url": "https://wiki.zimbra.com/wiki/Security_Center" + }, + { + "type": "WEB", + "url": "https://wiki.zimbra.com/wiki/Zimbra_Releases/10.0.13#Security_Fixes" + }, + { + "type": "WEB", + "url": "https://wiki.zimbra.com/wiki/Zimbra_Releases/10.1.5#Security_Fixes" + }, + { + "type": "WEB", + "url": "https://wiki.zimbra.com/wiki/Zimbra_Releases/9.0.0/P44#Security_Fixes" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-12T15:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-6fp2-jjv9-q3w2/GHSA-6fp2-jjv9-q3w2.json b/advisories/unreviewed/2025/03/GHSA-6fp2-jjv9-q3w2/GHSA-6fp2-jjv9-q3w2.json index b53b48c46aa..8c31d629ee9 100644 --- a/advisories/unreviewed/2025/03/GHSA-6fp2-jjv9-q3w2/GHSA-6fp2-jjv9-q3w2.json +++ b/advisories/unreviewed/2025/03/GHSA-6fp2-jjv9-q3w2/GHSA-6fp2-jjv9-q3w2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6fp2-jjv9-q3w2", - "modified": "2025-03-11T18:32:20Z", + "modified": "2025-03-12T15:32:00Z", "published": "2025-03-11T18:32:20Z", "aliases": [ "CVE-2025-27158" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://helpx.adobe.com/security/products/acrobat/apsb25-14.html" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2135" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/03/GHSA-6q4f-hgf7-r6p8/GHSA-6q4f-hgf7-r6p8.json b/advisories/unreviewed/2025/03/GHSA-6q4f-hgf7-r6p8/GHSA-6q4f-hgf7-r6p8.json index 6a1cf33fd61..cd15b6fd2c0 100644 --- a/advisories/unreviewed/2025/03/GHSA-6q4f-hgf7-r6p8/GHSA-6q4f-hgf7-r6p8.json +++ b/advisories/unreviewed/2025/03/GHSA-6q4f-hgf7-r6p8/GHSA-6q4f-hgf7-r6p8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6q4f-hgf7-r6p8", - "modified": "2025-03-11T18:32:21Z", + "modified": "2025-03-12T15:32:00Z", "published": "2025-03-11T18:32:21Z", "aliases": [ "CVE-2025-27164" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://helpx.adobe.com/security/products/acrobat/apsb25-14.html" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2136" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/03/GHSA-86w8-vhw6-q9qq/GHSA-86w8-vhw6-q9qq.json b/advisories/unreviewed/2025/03/GHSA-86w8-vhw6-q9qq/GHSA-86w8-vhw6-q9qq.json new file mode 100644 index 00000000000..66a1dc4d8d2 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-86w8-vhw6-q9qq/GHSA-86w8-vhw6-q9qq.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-86w8-vhw6-q9qq", + "modified": "2025-03-12T15:32:06Z", + "published": "2025-03-12T15:32:06Z", + "aliases": [ + "CVE-2024-27763" + ], + "details": "XPixelGroup BasicSR through 1.4.2 might locally allow code execution in contrived situations where \"scontrol show hostname\" is executed in the presence of a crafted SLURM_NODELIST environment variable.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-27763" + }, + { + "type": "WEB", + "url": "https://gist.github.com/aydinnyunus/40e1d8a3b529261ae654ff4891f1e192" + }, + { + "type": "WEB", + "url": "https://github.com/XPixelGroup/BasicSR/blob/master/basicsr/utils/dist_util.py#L44" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-12T15:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-96v5-c2h5-56hm/GHSA-96v5-c2h5-56hm.json b/advisories/unreviewed/2025/03/GHSA-96v5-c2h5-56hm/GHSA-96v5-c2h5-56hm.json new file mode 100644 index 00000000000..6017c580f59 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-96v5-c2h5-56hm/GHSA-96v5-c2h5-56hm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-96v5-c2h5-56hm", + "modified": "2025-03-12T15:32:06Z", + "published": "2025-03-12T15:32:06Z", + "aliases": [ + "CVE-2025-29891" + ], + "details": "Bypass/Injection vulnerability in Apache Camel.\n\nThis issue affects Apache Camel: from 4.10.0 before 4.10.2, from 4.8.0 before 4.8.5, from 3.10.0 before 3.22.4.\n\nUsers are recommended to upgrade to version 4.10.2 for 4.10.x LTS, 4.8.5 for 4.8.x LTS and 3.22.4 for 3.x releases.\n\nThis vulnerability is present in Camel's default incoming header filter, that allows an attacker to include Camel specific headers that for some Camel components can alter the behaviours such as the camel-bean component, or the camel-exec component.\n\nIf you have Camel applications that are directly connected to the internet via HTTP, then an attacker could include parameters in the HTTP requests that are sent to the Camel application that incorrectly get translated into headers. \n\nThe headers could be both provided as request parameters for an HTTP methods invocation or as part of the payload of the HTTP methods invocation.\n\nAll the known Camel HTTP component such as camel-servlet, camel-jetty, camel-undertow, camel-platform-http, and camel-netty-http would be vulnerable out of the box.\n\nThis CVE is related to the CVE-2025-27636: while they have the same root cause and are fixed with the same fix, CVE-2025-27636 was assumed to only be exploitable if an attacker could add malicious HTTP headers, while we have now determined that it is also exploitable via HTTP parameters. Like in CVE-2025-27636, exploitation is only possible if the Camel route uses particular vulnerable components.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29891" + }, + { + "type": "WEB", + "url": "https://camel.apache.org/security/CVE-2025-27636.html" + }, + { + "type": "WEB", + "url": "https://camel.apache.org/security/CVE-2025-29891.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-164" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-12T15:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-97hp-c3p8-8ggc/GHSA-97hp-c3p8-8ggc.json b/advisories/unreviewed/2025/03/GHSA-97hp-c3p8-8ggc/GHSA-97hp-c3p8-8ggc.json new file mode 100644 index 00000000000..6e279f3f61b --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-97hp-c3p8-8ggc/GHSA-97hp-c3p8-8ggc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-97hp-c3p8-8ggc", + "modified": "2025-03-12T15:32:05Z", + "published": "2025-03-12T15:32:05Z", + "aliases": [ + "CVE-2024-52362" + ], + "details": "IBM App Connect Enterprise Certified Container 7.2, 8.0, 8.1, 8.2, 9.0, 9.1, 9.2, 10.0, 10.1, 11.0, 11.1, 11.2, 11.3, 11.4, 11.5, 11.6, 12.0, 12.1, 12.2, 12.3, 12.4, 12.5, 12.6, 12.7, and 12.8 could allow an authenticated user to cause a denial of service in the App Connect flow due to improper validation of server-side input.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52362" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7185527" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1286" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-12T14:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-cqw7-466v-f9g6/GHSA-cqw7-466v-f9g6.json b/advisories/unreviewed/2025/03/GHSA-cqw7-466v-f9g6/GHSA-cqw7-466v-f9g6.json new file mode 100644 index 00000000000..b7cf8569e2c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-cqw7-466v-f9g6/GHSA-cqw7-466v-f9g6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cqw7-466v-f9g6", + "modified": "2025-03-12T15:32:05Z", + "published": "2025-03-12T15:32:05Z", + "aliases": [ + "CVE-2025-29904" + ], + "details": "In JetBrains Ktor before 3.1.1 an HTTP Request Smuggling was possible", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29904" + }, + { + "type": "WEB", + "url": "https://www.jetbrains.com/privacy-security/issues-fixed" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-444" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-12T13:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-gfh6-3pqw-x2j4/GHSA-gfh6-3pqw-x2j4.json b/advisories/unreviewed/2025/03/GHSA-gfh6-3pqw-x2j4/GHSA-gfh6-3pqw-x2j4.json new file mode 100644 index 00000000000..329f0b7282d --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-gfh6-3pqw-x2j4/GHSA-gfh6-3pqw-x2j4.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gfh6-3pqw-x2j4", + "modified": "2025-03-12T15:32:06Z", + "published": "2025-03-12T15:32:06Z", + "aliases": [ + "CVE-2025-2240" + ], + "details": "A flaw was found in Smallrye, where smallrye-fault-tolerance is vulnerable to an out-of-memory (OOM) issue. This vulnerability is externally triggered when calling the metrics URI. Every call creates a new object within meterMap and may lead to a denial of service (DoS) issue.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2240" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2025-2240" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2351452" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1325" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-12T15:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-jwv5-xmf5-mp56/GHSA-jwv5-xmf5-mp56.json b/advisories/unreviewed/2025/03/GHSA-jwv5-xmf5-mp56/GHSA-jwv5-xmf5-mp56.json new file mode 100644 index 00000000000..72b47e0a0c0 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-jwv5-xmf5-mp56/GHSA-jwv5-xmf5-mp56.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jwv5-xmf5-mp56", + "modified": "2025-03-12T15:32:06Z", + "published": "2025-03-12T15:32:05Z", + "aliases": [ + "CVE-2025-21590" + ], + "details": "An Improper Isolation or Compartmentalization vulnerability in the kernel of Juniper Networks Junos OS allows a local attacker with high privileges to compromise the integrity of the device.\n\nA local attacker with access to the shell is able to inject arbitrary code which can compromise an affected device.\nThis issue is not exploitable from the Junos CLI.\nThis issue affects Junos OS: \n\n\n\n * All versions before 21.2R3-S9,\n * 21.4 versions before 21.4R3-S10, \n * 22.2 versions before 22.2R3-S6, \n * 22.4 versions before 22.4R3-S6, \n * 23.2 versions before 23.2R2-S3, \n * 23.4 versions before 23.4R2-S4,\n * 24.2 versions before 24.2R1-S2, 24.2R2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21590" + }, + { + "type": "WEB", + "url": "https://cloud.google.com/blog/topics/threat-intelligence/china-nexus-espionage-targets-juniper-routers" + }, + { + "type": "WEB", + "url": "https://supportportal.juniper.net/JSA93446" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-653" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-12T14:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-qrxw-r57w-jjv2/GHSA-qrxw-r57w-jjv2.json b/advisories/unreviewed/2025/03/GHSA-qrxw-r57w-jjv2/GHSA-qrxw-r57w-jjv2.json new file mode 100644 index 00000000000..660ad79782c --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-qrxw-r57w-jjv2/GHSA-qrxw-r57w-jjv2.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qrxw-r57w-jjv2", + "modified": "2025-03-12T15:32:05Z", + "published": "2025-03-12T15:32:05Z", + "aliases": [ + "CVE-2025-25709" + ], + "details": "An issue in dtp.ae tNexus Airport View v.2.8 allows a remote attacker to escalate privileges via the addUser and updateUser endpoints", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25709" + }, + { + "type": "WEB", + "url": "https://github.com/z5jt/vulnerability-research/tree/main/CVE-2025-25709" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-12T14:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-r9xq-fh23-wm6f/GHSA-r9xq-fh23-wm6f.json b/advisories/unreviewed/2025/03/GHSA-r9xq-fh23-wm6f/GHSA-r9xq-fh23-wm6f.json index 732139b2c02..0a494e61459 100644 --- a/advisories/unreviewed/2025/03/GHSA-r9xq-fh23-wm6f/GHSA-r9xq-fh23-wm6f.json +++ b/advisories/unreviewed/2025/03/GHSA-r9xq-fh23-wm6f/GHSA-r9xq-fh23-wm6f.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-r9xq-fh23-wm6f", - "modified": "2025-03-12T12:30:59Z", + "modified": "2025-03-12T15:32:05Z", "published": "2025-03-12T12:30:59Z", "aliases": [ "CVE-2025-21858" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ngeneve: Fix use-after-free in geneve_find_dev().\n\nsyzkaller reported a use-after-free in geneve_find_dev() [0]\nwithout repro.\n\ngeneve_configure() links struct geneve_dev.next to\nnet_generic(net, geneve_net_id)->geneve_list.\n\nThe net here could differ from dev_net(dev) if IFLA_NET_NS_PID,\nIFLA_NET_NS_FD, or IFLA_TARGET_NETNSID is set.\n\nWhen dev_net(dev) is dismantled, geneve_exit_batch_rtnl() finally\ncalls unregister_netdevice_queue() for each dev in the netns,\nand later the dev is freed.\n\nHowever, its geneve_dev.next is still linked to the backend UDP\nsocket netns.\n\nThen, use-after-free will occur when another geneve dev is created\nin the netns.\n\nLet's call geneve_dellink() instead in geneve_destroy_tunnels().\n\n[0]:\nBUG: KASAN: slab-use-after-free in geneve_find_dev drivers/net/geneve.c:1295 [inline]\nBUG: KASAN: slab-use-after-free in geneve_configure+0x234/0x858 drivers/net/geneve.c:1343\nRead of size 2 at addr ffff000054d6ee24 by task syz.1.4029/13441\n\nCPU: 1 UID: 0 PID: 13441 Comm: syz.1.4029 Not tainted 6.13.0-g0ad9617c78ac #24 dc35ca22c79fb82e8e7bc5c9c9adafea898b1e3d\nHardware name: linux,dummy-virt (DT)\nCall trace:\n show_stack+0x38/0x50 arch/arm64/kernel/stacktrace.c:466 (C)\n __dump_stack lib/dump_stack.c:94 [inline]\n dump_stack_lvl+0xbc/0x108 lib/dump_stack.c:120\n print_address_description mm/kasan/report.c:378 [inline]\n print_report+0x16c/0x6f0 mm/kasan/report.c:489\n kasan_report+0xc0/0x120 mm/kasan/report.c:602\n __asan_report_load2_noabort+0x20/0x30 mm/kasan/report_generic.c:379\n geneve_find_dev drivers/net/geneve.c:1295 [inline]\n geneve_configure+0x234/0x858 drivers/net/geneve.c:1343\n geneve_newlink+0xb8/0x128 drivers/net/geneve.c:1634\n rtnl_newlink_create+0x23c/0x868 net/core/rtnetlink.c:3795\n __rtnl_newlink net/core/rtnetlink.c:3906 [inline]\n rtnl_newlink+0x1054/0x1630 net/core/rtnetlink.c:4021\n rtnetlink_rcv_msg+0x61c/0x918 net/core/rtnetlink.c:6911\n netlink_rcv_skb+0x1dc/0x398 net/netlink/af_netlink.c:2543\n rtnetlink_rcv+0x34/0x50 net/core/rtnetlink.c:6938\n netlink_unicast_kernel net/netlink/af_netlink.c:1322 [inline]\n netlink_unicast+0x618/0x838 net/netlink/af_netlink.c:1348\n netlink_sendmsg+0x5fc/0x8b0 net/netlink/af_netlink.c:1892\n sock_sendmsg_nosec net/socket.c:713 [inline]\n __sock_sendmsg net/socket.c:728 [inline]\n ____sys_sendmsg+0x410/0x6f8 net/socket.c:2568\n ___sys_sendmsg+0x178/0x1d8 net/socket.c:2622\n __sys_sendmsg net/socket.c:2654 [inline]\n __do_sys_sendmsg net/socket.c:2659 [inline]\n __se_sys_sendmsg net/socket.c:2657 [inline]\n __arm64_sys_sendmsg+0x12c/0x1c8 net/socket.c:2657\n __invoke_syscall arch/arm64/kernel/syscall.c:35 [inline]\n invoke_syscall+0x90/0x278 arch/arm64/kernel/syscall.c:49\n el0_svc_common+0x13c/0x250 arch/arm64/kernel/syscall.c:132\n do_el0_svc+0x54/0x70 arch/arm64/kernel/syscall.c:151\n el0_svc+0x4c/0xa8 arch/arm64/kernel/entry-common.c:744\n el0t_64_sync_handler+0x78/0x108 arch/arm64/kernel/entry-common.c:762\n el0t_64_sync+0x198/0x1a0 arch/arm64/kernel/entry.S:600\n\nAllocated by task 13247:\n kasan_save_stack mm/kasan/common.c:47 [inline]\n kasan_save_track+0x30/0x68 mm/kasan/common.c:68\n kasan_save_alloc_info+0x44/0x58 mm/kasan/generic.c:568\n poison_kmalloc_redzone mm/kasan/common.c:377 [inline]\n __kasan_kmalloc+0x84/0xa0 mm/kasan/common.c:394\n kasan_kmalloc include/linux/kasan.h:260 [inline]\n __do_kmalloc_node mm/slub.c:4298 [inline]\n __kmalloc_node_noprof+0x2a0/0x560 mm/slub.c:4304\n __kvmalloc_node_noprof+0x9c/0x230 mm/util.c:645\n alloc_netdev_mqs+0xb8/0x11a0 net/core/dev.c:11470\n rtnl_create_link+0x2b8/0xb50 net/core/rtnetlink.c:3604\n rtnl_newlink_create+0x19c/0x868 net/core/rtnetlink.c:3780\n __rtnl_newlink net/core/rtnetlink.c:3906 [inline]\n rtnl_newlink+0x1054/0x1630 net/core/rtnetlink.c:4021\n rtnetlink_rcv_msg+0x61c/0x918 net/core/rtnetlink.c:6911\n netlink_rcv_skb+0x1dc/0x398 net/netlink/af_netlink.c:2543\n rtnetlink_rcv+0x34/0x50 net/core/rtnetlink.c:6938\n netlink_unicast_kernel net/netlink/af_n\n---truncated---", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-12T10:15:18Z" diff --git a/advisories/unreviewed/2025/03/GHSA-x2cr-cpw2-j9x5/GHSA-x2cr-cpw2-j9x5.json b/advisories/unreviewed/2025/03/GHSA-x2cr-cpw2-j9x5/GHSA-x2cr-cpw2-j9x5.json index c0e135a6dc0..341ecd0dcab 100644 --- a/advisories/unreviewed/2025/03/GHSA-x2cr-cpw2-j9x5/GHSA-x2cr-cpw2-j9x5.json +++ b/advisories/unreviewed/2025/03/GHSA-x2cr-cpw2-j9x5/GHSA-x2cr-cpw2-j9x5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x2cr-cpw2-j9x5", - "modified": "2025-03-07T21:31:09Z", + "modified": "2025-03-12T15:32:00Z", "published": "2025-03-06T21:31:26Z", "aliases": [ "CVE-2025-25381" @@ -19,9 +19,17 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25381" }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-x2cr-cpw2-j9x5" + }, { "type": "WEB", "url": "https://github.com/edwin-0990/CVE_ID/blob/main/CVE-2025-25381/README.md" + }, + { + "type": "WEB", + "url": "https://www.tenable.com/cve/CVE-2025-25381" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/03/GHSA-xr5m-494h-32gf/GHSA-xr5m-494h-32gf.json b/advisories/unreviewed/2025/03/GHSA-xr5m-494h-32gf/GHSA-xr5m-494h-32gf.json new file mode 100644 index 00000000000..462dabb5258 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-xr5m-494h-32gf/GHSA-xr5m-494h-32gf.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xr5m-494h-32gf", + "modified": "2025-03-12T15:32:05Z", + "published": "2025-03-12T15:32:05Z", + "aliases": [ + "CVE-2025-27914" + ], + "details": "An issue was discovered in Zimbra Collaboration (ZCS) 9.0 and 10.0 and 10.1. A Reflected Cross-Site Scripting (XSS) vulnerability exists in the /h/rest endpoint, allowing authenticated attackers to inject and execute arbitrary JavaScript in a victim's session. Exploitation requires a valid auth token and involves a crafted URL with manipulated query parameters that triggers XSS when accessed by a victim.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27914" + }, + { + "type": "WEB", + "url": "https://wiki.zimbra.com/wiki/Zimbra_Releases/10.0.11#Security_Fixes" + }, + { + "type": "WEB", + "url": "https://wiki.zimbra.com/wiki/Zimbra_Responsible_Disclosure_Policy" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-12T15:15:39Z" + } +} \ No newline at end of file