From 6439f394961bf15006dc97dbd2e8ecf9b2487c9e Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 18 Apr 2025 00:31:48 +0000 Subject: [PATCH] Publish Advisories GHSA-24j3-w3xq-4r3w GHSA-27ww-388c-hfhf GHSA-2qhw-4vw3-x335 GHSA-3996-4m5r-mmwf GHSA-5vf8-pp4v-ccv9 GHSA-fvw7-7rxq-453v GHSA-g3x6-r9w9-mcxx GHSA-m3q4-379j-85vm GHSA-m746-cfp9-r2qh GHSA-mmp3-fv2j-fw7v GHSA-pmgr-28ph-jhmm --- .../GHSA-24j3-w3xq-4r3w.json | 29 +++++++++++ .../GHSA-27ww-388c-hfhf.json | 29 +++++++++++ .../GHSA-2qhw-4vw3-x335.json | 29 +++++++++++ .../GHSA-3996-4m5r-mmwf.json | 29 +++++++++++ .../GHSA-5vf8-pp4v-ccv9.json | 29 +++++++++++ .../GHSA-fvw7-7rxq-453v.json | 48 +++++++++++++++++++ .../GHSA-g3x6-r9w9-mcxx.json | 48 +++++++++++++++++++ .../GHSA-m3q4-379j-85vm.json | 36 ++++++++++++++ .../GHSA-m746-cfp9-r2qh.json | 29 +++++++++++ .../GHSA-mmp3-fv2j-fw7v.json | 36 ++++++++++++++ .../GHSA-pmgr-28ph-jhmm.json | 29 +++++++++++ 11 files changed, 371 insertions(+) create mode 100644 advisories/unreviewed/2025/04/GHSA-24j3-w3xq-4r3w/GHSA-24j3-w3xq-4r3w.json create mode 100644 advisories/unreviewed/2025/04/GHSA-27ww-388c-hfhf/GHSA-27ww-388c-hfhf.json create mode 100644 advisories/unreviewed/2025/04/GHSA-2qhw-4vw3-x335/GHSA-2qhw-4vw3-x335.json create mode 100644 advisories/unreviewed/2025/04/GHSA-3996-4m5r-mmwf/GHSA-3996-4m5r-mmwf.json create mode 100644 advisories/unreviewed/2025/04/GHSA-5vf8-pp4v-ccv9/GHSA-5vf8-pp4v-ccv9.json create mode 100644 advisories/unreviewed/2025/04/GHSA-fvw7-7rxq-453v/GHSA-fvw7-7rxq-453v.json create mode 100644 advisories/unreviewed/2025/04/GHSA-g3x6-r9w9-mcxx/GHSA-g3x6-r9w9-mcxx.json create mode 100644 advisories/unreviewed/2025/04/GHSA-m3q4-379j-85vm/GHSA-m3q4-379j-85vm.json create mode 100644 advisories/unreviewed/2025/04/GHSA-m746-cfp9-r2qh/GHSA-m746-cfp9-r2qh.json create mode 100644 advisories/unreviewed/2025/04/GHSA-mmp3-fv2j-fw7v/GHSA-mmp3-fv2j-fw7v.json create mode 100644 advisories/unreviewed/2025/04/GHSA-pmgr-28ph-jhmm/GHSA-pmgr-28ph-jhmm.json diff --git a/advisories/unreviewed/2025/04/GHSA-24j3-w3xq-4r3w/GHSA-24j3-w3xq-4r3w.json b/advisories/unreviewed/2025/04/GHSA-24j3-w3xq-4r3w/GHSA-24j3-w3xq-4r3w.json new file mode 100644 index 00000000000..17149f81d4a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-24j3-w3xq-4r3w/GHSA-24j3-w3xq-4r3w.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-24j3-w3xq-4r3w", + "modified": "2025-04-18T00:30:43Z", + "published": "2025-04-18T00:30:43Z", + "aliases": [ + "CVE-2025-29460" + ], + "details": "An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Add Mycode function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29460" + }, + { + "type": "WEB", + "url": "https://www.yuque.com/morysummer/vx41bz/fgg059stiog457ch" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T22:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-27ww-388c-hfhf/GHSA-27ww-388c-hfhf.json b/advisories/unreviewed/2025/04/GHSA-27ww-388c-hfhf/GHSA-27ww-388c-hfhf.json new file mode 100644 index 00000000000..f8de3eed727 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-27ww-388c-hfhf/GHSA-27ww-388c-hfhf.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-27ww-388c-hfhf", + "modified": "2025-04-18T00:30:43Z", + "published": "2025-04-18T00:30:43Z", + "aliases": [ + "CVE-2025-29457" + ], + "details": "An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Import a Theme function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29457" + }, + { + "type": "WEB", + "url": "https://www.yuque.com/morysummer/vx41bz/vro4dvxzuiwlg6uv" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T22:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2qhw-4vw3-x335/GHSA-2qhw-4vw3-x335.json b/advisories/unreviewed/2025/04/GHSA-2qhw-4vw3-x335/GHSA-2qhw-4vw3-x335.json new file mode 100644 index 00000000000..d244dec90b3 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2qhw-4vw3-x335/GHSA-2qhw-4vw3-x335.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2qhw-4vw3-x335", + "modified": "2025-04-18T00:30:43Z", + "published": "2025-04-18T00:30:43Z", + "aliases": [ + "CVE-2025-29459" + ], + "details": "An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Mail function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29459" + }, + { + "type": "WEB", + "url": "https://www.yuque.com/morysummer/vx41bz/ggnmg5nnu635kvrc" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T22:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3996-4m5r-mmwf/GHSA-3996-4m5r-mmwf.json b/advisories/unreviewed/2025/04/GHSA-3996-4m5r-mmwf/GHSA-3996-4m5r-mmwf.json new file mode 100644 index 00000000000..139fcc52709 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3996-4m5r-mmwf/GHSA-3996-4m5r-mmwf.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3996-4m5r-mmwf", + "modified": "2025-04-18T00:30:43Z", + "published": "2025-04-18T00:30:43Z", + "aliases": [ + "CVE-2025-29458" + ], + "details": "An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Change Avatar function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29458" + }, + { + "type": "WEB", + "url": "https://www.yuque.com/morysummer/vx41bz/qu7zyyxr84qno64e" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T22:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5vf8-pp4v-ccv9/GHSA-5vf8-pp4v-ccv9.json b/advisories/unreviewed/2025/04/GHSA-5vf8-pp4v-ccv9/GHSA-5vf8-pp4v-ccv9.json new file mode 100644 index 00000000000..76d7b40d92d --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5vf8-pp4v-ccv9/GHSA-5vf8-pp4v-ccv9.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5vf8-pp4v-ccv9", + "modified": "2025-04-18T00:30:43Z", + "published": "2025-04-18T00:30:43Z", + "aliases": [ + "CVE-2025-29453" + ], + "details": "An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the my-contacts-settings component.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29453" + }, + { + "type": "WEB", + "url": "https://www.yuque.com/morysummer/vx41bz/pgg9q7kdbkggtq08" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T22:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-fvw7-7rxq-453v/GHSA-fvw7-7rxq-453v.json b/advisories/unreviewed/2025/04/GHSA-fvw7-7rxq-453v/GHSA-fvw7-7rxq-453v.json new file mode 100644 index 00000000000..d0920f49900 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-fvw7-7rxq-453v/GHSA-fvw7-7rxq-453v.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fvw7-7rxq-453v", + "modified": "2025-04-18T00:30:44Z", + "published": "2025-04-18T00:30:44Z", + "aliases": [ + "CVE-2025-3124" + ], + "details": "A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed a user to see the names of private repositories that they wouldn't otherwise have access to in the Security Overview in GitHub Advanced Security. The Security Overview was required to be filtered only using the `archived:` filter and all other access controls were functioning normally. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.17 and was fixed in versions 3.13.14, 3.14.11, 3.15.6, and 3.16.2.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3124" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.13/admin/release-notes#3.13.14" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.14/admin/release-notes#3.14.11" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.15/admin/release-notes#3.15.6" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.16/admin/release-notes#3.16.2" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T23:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-g3x6-r9w9-mcxx/GHSA-g3x6-r9w9-mcxx.json b/advisories/unreviewed/2025/04/GHSA-g3x6-r9w9-mcxx/GHSA-g3x6-r9w9-mcxx.json new file mode 100644 index 00000000000..b5221b59ba2 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-g3x6-r9w9-mcxx/GHSA-g3x6-r9w9-mcxx.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g3x6-r9w9-mcxx", + "modified": "2025-04-18T00:30:44Z", + "published": "2025-04-18T00:30:44Z", + "aliases": [ + "CVE-2025-3509" + ], + "details": "A Remote Code Execution (RCE) vulnerability was identified in GitHub Enterprise Server that allowed attackers to execute arbitrary code by exploiting the pre-receive hook functionality, potentially leading to privilege escalation and system compromise. The vulnerability involves using dynamically allocated ports that become temporarily available, such as during a hot patch upgrade. This means the vulnerability is only exploitable during specific operational conditions, which limits the attack window. Exploitation required either site administrator permissions to enable and configure pre-receive hooks or a user with permissions to modify repositories containing pre-receive hooks where this functionality was already enabled. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.17 and was fixed in versions 3.16.2, 3.15.6, 3.14.11, 3.13.14. This vulnerability was reported via the GitHub Bug Bounty program.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:L/SC:L/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:C/RE:M/U:Amber" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3509" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.13/admin/release-notes#3.13.14" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.14/admin/release-notes#3.14.11" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.15/admin/release-notes#3.15.6" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.16/admin/release-notes#3.16.2" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T23:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-m3q4-379j-85vm/GHSA-m3q4-379j-85vm.json b/advisories/unreviewed/2025/04/GHSA-m3q4-379j-85vm/GHSA-m3q4-379j-85vm.json new file mode 100644 index 00000000000..4e914700b09 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-m3q4-379j-85vm/GHSA-m3q4-379j-85vm.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m3q4-379j-85vm", + "modified": "2025-04-18T00:30:44Z", + "published": "2025-04-18T00:30:44Z", + "aliases": [ + "CVE-2025-3246" + ], + "details": "An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allowed cross-site scripting in GitHub Markdown that used `$$..$$` math blocks. Exploitation required access to the target GitHub Enterprise Server instance and privileged user interaction with the malicious elements. This vulnerability affected version 3.16.1 of GitHub Enterprise Server and was fixed in version 3.16.2. This vulnerability was reported via the GitHub Bug Bounty program.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3246" + }, + { + "type": "WEB", + "url": "https://docs.github.com/en/enterprise-server@3.16/admin/release-notes#3.16.2" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T23:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-m746-cfp9-r2qh/GHSA-m746-cfp9-r2qh.json b/advisories/unreviewed/2025/04/GHSA-m746-cfp9-r2qh/GHSA-m746-cfp9-r2qh.json new file mode 100644 index 00000000000..ca2aca51e43 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-m746-cfp9-r2qh/GHSA-m746-cfp9-r2qh.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m746-cfp9-r2qh", + "modified": "2025-04-18T00:30:43Z", + "published": "2025-04-18T00:30:43Z", + "aliases": [ + "CVE-2025-29461" + ], + "details": "An issue in a-blogcms 3.1.15 allows a remote attacker to obtain sensitive information via the /bid/1/admin/entry-edit/ path.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29461" + }, + { + "type": "WEB", + "url": "https://www.yuque.com/morysummer/vx41bz/xagedb4qdy5gouep" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T22:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-mmp3-fv2j-fw7v/GHSA-mmp3-fv2j-fw7v.json b/advisories/unreviewed/2025/04/GHSA-mmp3-fv2j-fw7v/GHSA-mmp3-fv2j-fw7v.json new file mode 100644 index 00000000000..f0ea1f0ebcc --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-mmp3-fv2j-fw7v/GHSA-mmp3-fv2j-fw7v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mmp3-fv2j-fw7v", + "modified": "2025-04-18T00:30:43Z", + "published": "2025-04-18T00:30:43Z", + "aliases": [ + "CVE-2024-42178" + ], + "details": "HCL MyXalytics is affected by a failure to restrict URL access vulnerability. Unauthenticated users might gain unauthorized access to potentially confidential information, creating a risk of misuse, manipulation, or unauthorized distribution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-42178" + }, + { + "type": "WEB", + "url": "https://support.hcl-software.com/csm?id=kb_article&sysparm_article=KB0120502" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-288" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T22:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-pmgr-28ph-jhmm/GHSA-pmgr-28ph-jhmm.json b/advisories/unreviewed/2025/04/GHSA-pmgr-28ph-jhmm/GHSA-pmgr-28ph-jhmm.json new file mode 100644 index 00000000000..2f17e94910b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-pmgr-28ph-jhmm/GHSA-pmgr-28ph-jhmm.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pmgr-28ph-jhmm", + "modified": "2025-04-18T00:30:43Z", + "published": "2025-04-18T00:30:43Z", + "aliases": [ + "CVE-2025-29456" + ], + "details": "An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the create Notes function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29456" + }, + { + "type": "WEB", + "url": "https://www.yuque.com/morysummer/vx41bz/ckogwt5qwnkd821k" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-17T22:15:15Z" + } +} \ No newline at end of file