From 66b2d56a7079ce56175ccd4a7282ac45ee0b0391 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 10 Jun 2025 09:31:48 +0000 Subject: [PATCH] Publish Advisories GHSA-4wm4-5vmp-66g7 GHSA-5q32-895v-vf2f GHSA-r2jx-292h-wx26 GHSA-9m9c-m3m8-59vc GHSA-6mv2-8pp6-4rv3 GHSA-76qp-h5mr-frr4 GHSA-7pwx-q393-6cwf GHSA-crjm-6cjg-8rjx GHSA-cw8c-6ffq-p4hh GHSA-f2qx-w367-78j3 GHSA-hxx3-p6px-cf6j GHSA-j34m-g9vq-47p3 GHSA-jqqm-2p4m-968q GHSA-jqw9-2xg8-2hvh GHSA-mcwh-c9pg-xw43 GHSA-r2gg-7x5x-xgpx GHSA-vgq5-3255-v292 GHSA-ww37-xgr7-c25p GHSA-x3hv-q6h3-h9ph GHSA-xmv7-64fr-2r3x --- .../GHSA-4wm4-5vmp-66g7.json | 10 ++++- .../GHSA-5q32-895v-vf2f.json | 15 ++++++- .../GHSA-r2jx-292h-wx26.json | 14 ++++++- .../GHSA-9m9c-m3m8-59vc.json | 2 +- .../GHSA-6mv2-8pp6-4rv3.json | 40 +++++++++++++++++++ .../GHSA-76qp-h5mr-frr4.json | 35 ++++++++++++++++ .../GHSA-7pwx-q393-6cwf.json | 36 +++++++++++++++++ .../GHSA-crjm-6cjg-8rjx.json | 36 +++++++++++++++++ .../GHSA-cw8c-6ffq-p4hh.json | 40 +++++++++++++++++++ .../GHSA-f2qx-w367-78j3.json | 40 +++++++++++++++++++ .../GHSA-hxx3-p6px-cf6j.json | 40 +++++++++++++++++++ .../GHSA-j34m-g9vq-47p3.json | 40 +++++++++++++++++++ .../GHSA-jqqm-2p4m-968q.json | 40 +++++++++++++++++++ .../GHSA-jqw9-2xg8-2hvh.json | 40 +++++++++++++++++++ .../GHSA-mcwh-c9pg-xw43.json | 31 ++++++++++++++ .../GHSA-r2gg-7x5x-xgpx.json | 25 ++++++++++++ .../GHSA-vgq5-3255-v292.json | 33 +++++++++++++++ .../GHSA-ww37-xgr7-c25p.json | 40 +++++++++++++++++++ .../GHSA-x3hv-q6h3-h9ph.json | 40 +++++++++++++++++++ .../GHSA-xmv7-64fr-2r3x.json | 40 +++++++++++++++++++ 20 files changed, 632 insertions(+), 5 deletions(-) create mode 100644 advisories/unreviewed/2025/06/GHSA-6mv2-8pp6-4rv3/GHSA-6mv2-8pp6-4rv3.json create mode 100644 advisories/unreviewed/2025/06/GHSA-76qp-h5mr-frr4/GHSA-76qp-h5mr-frr4.json create mode 100644 advisories/unreviewed/2025/06/GHSA-7pwx-q393-6cwf/GHSA-7pwx-q393-6cwf.json create mode 100644 advisories/unreviewed/2025/06/GHSA-crjm-6cjg-8rjx/GHSA-crjm-6cjg-8rjx.json create mode 100644 advisories/unreviewed/2025/06/GHSA-cw8c-6ffq-p4hh/GHSA-cw8c-6ffq-p4hh.json create mode 100644 advisories/unreviewed/2025/06/GHSA-f2qx-w367-78j3/GHSA-f2qx-w367-78j3.json create mode 100644 advisories/unreviewed/2025/06/GHSA-hxx3-p6px-cf6j/GHSA-hxx3-p6px-cf6j.json create mode 100644 advisories/unreviewed/2025/06/GHSA-j34m-g9vq-47p3/GHSA-j34m-g9vq-47p3.json create mode 100644 advisories/unreviewed/2025/06/GHSA-jqqm-2p4m-968q/GHSA-jqqm-2p4m-968q.json create mode 100644 advisories/unreviewed/2025/06/GHSA-jqw9-2xg8-2hvh/GHSA-jqw9-2xg8-2hvh.json create mode 100644 advisories/unreviewed/2025/06/GHSA-mcwh-c9pg-xw43/GHSA-mcwh-c9pg-xw43.json create mode 100644 advisories/unreviewed/2025/06/GHSA-r2gg-7x5x-xgpx/GHSA-r2gg-7x5x-xgpx.json create mode 100644 advisories/unreviewed/2025/06/GHSA-vgq5-3255-v292/GHSA-vgq5-3255-v292.json create mode 100644 advisories/unreviewed/2025/06/GHSA-ww37-xgr7-c25p/GHSA-ww37-xgr7-c25p.json create mode 100644 advisories/unreviewed/2025/06/GHSA-x3hv-q6h3-h9ph/GHSA-x3hv-q6h3-h9ph.json create mode 100644 advisories/unreviewed/2025/06/GHSA-xmv7-64fr-2r3x/GHSA-xmv7-64fr-2r3x.json diff --git a/advisories/unreviewed/2022/05/GHSA-4wm4-5vmp-66g7/GHSA-4wm4-5vmp-66g7.json b/advisories/unreviewed/2022/05/GHSA-4wm4-5vmp-66g7/GHSA-4wm4-5vmp-66g7.json index cecf843209a..00c156f696e 100644 --- a/advisories/unreviewed/2022/05/GHSA-4wm4-5vmp-66g7/GHSA-4wm4-5vmp-66g7.json +++ b/advisories/unreviewed/2022/05/GHSA-4wm4-5vmp-66g7/GHSA-4wm4-5vmp-66g7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4wm4-5vmp-66g7", - "modified": "2022-05-24T17:35:21Z", + "modified": "2025-06-10T09:30:30Z", "published": "2022-05-24T17:35:21Z", "aliases": [ "CVE-2020-7533" @@ -19,13 +19,19 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-7533" }, + { + "type": "WEB", + "url": "https://download.schneider-electric.com/files?p_File_Name=SEVD-2020-287-01_Modicon_Web_Server_Security_Notificatiton.pdf&p_Doc_Ref=SEVD-2020-287-01&p_enDocType=Security+and+Safety+Notice" + }, { "type": "WEB", "url": "https://www.se.com/ww/en/download/document/SEVD-2020-287-01" } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-287" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-5q32-895v-vf2f/GHSA-5q32-895v-vf2f.json b/advisories/unreviewed/2024/03/GHSA-5q32-895v-vf2f/GHSA-5q32-895v-vf2f.json index 54321d2ef86..aa329298a25 100644 --- a/advisories/unreviewed/2024/03/GHSA-5q32-895v-vf2f/GHSA-5q32-895v-vf2f.json +++ b/advisories/unreviewed/2024/03/GHSA-5q32-895v-vf2f/GHSA-5q32-895v-vf2f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5q32-895v-vf2f", - "modified": "2024-03-08T15:30:32Z", + "modified": "2025-06-10T09:30:30Z", "published": "2024-03-08T15:30:32Z", "aliases": [ "CVE-2024-2318" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], @@ -30,11 +34,20 @@ { "type": "WEB", "url": "https://vuldb.com/?id.256272" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.288530" + }, + { + "type": "WEB", + "url": "https://www.zkteco.com/en/Security_Bulletinsibs/11" } ], "database_specific": { "cwe_ids": [ "CWE-22", + "CWE-23", "CWE-24" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/07/GHSA-r2jx-292h-wx26/GHSA-r2jx-292h-wx26.json b/advisories/unreviewed/2024/07/GHSA-r2jx-292h-wx26/GHSA-r2jx-292h-wx26.json index 79289eac284..1f690b84625 100644 --- a/advisories/unreviewed/2024/07/GHSA-r2jx-292h-wx26/GHSA-r2jx-292h-wx26.json +++ b/advisories/unreviewed/2024/07/GHSA-r2jx-292h-wx26/GHSA-r2jx-292h-wx26.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r2jx-292h-wx26", - "modified": "2024-08-26T06:30:46Z", + "modified": "2025-06-10T09:30:30Z", "published": "2024-07-17T06:30:47Z", "aliases": [ "CVE-2024-6807" @@ -51,6 +51,18 @@ "type": "WEB", "url": "https://vuldb.com/?submit.374853" }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.374859" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.374861" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.374923" + }, { "type": "WEB", "url": "https://www.sourcecodester.com" diff --git a/advisories/unreviewed/2025/05/GHSA-9m9c-m3m8-59vc/GHSA-9m9c-m3m8-59vc.json b/advisories/unreviewed/2025/05/GHSA-9m9c-m3m8-59vc/GHSA-9m9c-m3m8-59vc.json index 638e9a7ad76..131f545bedc 100644 --- a/advisories/unreviewed/2025/05/GHSA-9m9c-m3m8-59vc/GHSA-9m9c-m3m8-59vc.json +++ b/advisories/unreviewed/2025/05/GHSA-9m9c-m3m8-59vc/GHSA-9m9c-m3m8-59vc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9m9c-m3m8-59vc", - "modified": "2025-05-30T18:31:13Z", + "modified": "2025-06-10T09:30:30Z", "published": "2025-05-30T18:31:13Z", "aliases": [ "CVE-2024-13915" diff --git a/advisories/unreviewed/2025/06/GHSA-6mv2-8pp6-4rv3/GHSA-6mv2-8pp6-4rv3.json b/advisories/unreviewed/2025/06/GHSA-6mv2-8pp6-4rv3/GHSA-6mv2-8pp6-4rv3.json new file mode 100644 index 00000000000..d2c7153e9b9 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-6mv2-8pp6-4rv3/GHSA-6mv2-8pp6-4rv3.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6mv2-8pp6-4rv3", + "modified": "2025-06-10T09:30:31Z", + "published": "2025-06-10T09:30:31Z", + "aliases": [ + "CVE-2025-5742" + ], + "details": "CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)\nvulnerability exists when an authenticated user modifies configuration parameters on the web server", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5742" + }, + { + "type": "WEB", + "url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2025-161-03&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2025-161-03.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T09:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-76qp-h5mr-frr4/GHSA-76qp-h5mr-frr4.json b/advisories/unreviewed/2025/06/GHSA-76qp-h5mr-frr4/GHSA-76qp-h5mr-frr4.json new file mode 100644 index 00000000000..96dffcdfce1 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-76qp-h5mr-frr4/GHSA-76qp-h5mr-frr4.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-76qp-h5mr-frr4", + "modified": "2025-06-10T09:30:31Z", + "published": "2025-06-10T09:30:31Z", + "aliases": [ + "CVE-2025-27818" + ], + "details": "A possible security vulnerability has been identified in Apache Kafka.\nThis requires access to a alterConfig to the cluster resource, or Kafka Connect worker, and the ability to create/modify connectors on it with an arbitrary Kafka client SASL JAAS config\nand a SASL-based security protocol, which has been possible on Kafka clusters since Apache Kafka 2.0.0 (Kafka Connect 2.3.0).\nWhen configuring the broker via config file or AlterConfig command, or connector via the Kafka Kafka Connect REST API, an authenticated operator can set the `sasl.jaas.config`\nproperty for any of the connector's Kafka clients to \"com.sun.security.auth.module.LdapLoginModule\", which can be done via the\n`producer.override.sasl.jaas.config`, `consumer.override.sasl.jaas.config`, or `admin.override.sasl.jaas.config` properties.\nThis will allow the server to connect to the attacker's LDAP server\nand deserialize the LDAP response, which the attacker can use to execute java deserialization gadget chains on the Kafka connect server.\nAttacker can cause unrestricted deserialization of untrusted data (or) RCE vulnerability when there are gadgets in the classpath.\n\nSince Apache Kafka 3.0.0, users are allowed to specify these properties in connector configurations for Kafka Connect clusters running with out-of-the-box\nconfigurations. Before Apache Kafka 3.0.0, users may not specify these properties unless the Kafka Connect cluster has been reconfigured with a connector\nclient override policy that permits them.\n\nSince Apache Kafka 3.9.1/4.0.0, we have added a system property (\"-Dorg.apache.kafka.disallowed.login.modules\") to disable the problematic login modules usage\nin SASL JAAS configuration. Also by default \"com.sun.security.auth.module.JndiLoginModule,com.sun.security.auth.module.LdapLoginModule\" are disabled in Apache Kafka Connect 3.9.1/4.0.0. \n\nWe advise the Kafka users to validate connector configurations and only allow trusted LDAP configurations. Also examine connector dependencies for \nvulnerable versions and either upgrade their connectors, upgrading that specific dependency, or removing the connectors as options for remediation. Finally,\nin addition to leveraging the \"org.apache.kafka.disallowed.login.modules\" system property, Kafka Connect users can also implement their own connector\nclient config override policy, which can be used to control which Kafka client properties can be overridden directly in a connector config and which cannot.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27818" + }, + { + "type": "WEB", + "url": "https://kafka.apache.org/cve-list" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/06/09/2" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T08:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-7pwx-q393-6cwf/GHSA-7pwx-q393-6cwf.json b/advisories/unreviewed/2025/06/GHSA-7pwx-q393-6cwf/GHSA-7pwx-q393-6cwf.json new file mode 100644 index 00000000000..324bda594d0 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-7pwx-q393-6cwf/GHSA-7pwx-q393-6cwf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7pwx-q393-6cwf", + "modified": "2025-06-10T09:30:31Z", + "published": "2025-06-10T09:30:31Z", + "aliases": [ + "CVE-2025-4681" + ], + "details": "Improper Privilege Management vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Privilege Abuse.This issue affects upKeeper Instant Privilege Access: before 1.4.0.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4681" + }, + { + "type": "WEB", + "url": "https://support.upkeeper.se/hc/en-us/articles/20159882527772-CVE-2025-4681-Improper-Privilege-Management" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T09:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-crjm-6cjg-8rjx/GHSA-crjm-6cjg-8rjx.json b/advisories/unreviewed/2025/06/GHSA-crjm-6cjg-8rjx/GHSA-crjm-6cjg-8rjx.json new file mode 100644 index 00000000000..c28916540df --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-crjm-6cjg-8rjx/GHSA-crjm-6cjg-8rjx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-crjm-6cjg-8rjx", + "modified": "2025-06-10T09:30:31Z", + "published": "2025-06-10T09:30:31Z", + "aliases": [ + "CVE-2025-4680" + ], + "details": "Improper Input Validation vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects upKeeper Instant Privilege Access: before 1.4.0.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4680" + }, + { + "type": "WEB", + "url": "https://support.upkeeper.se/hc/en-us/articles/20159822847900-CVE-2025-4680-Improper-Input-Validation" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T09:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-cw8c-6ffq-p4hh/GHSA-cw8c-6ffq-p4hh.json b/advisories/unreviewed/2025/06/GHSA-cw8c-6ffq-p4hh/GHSA-cw8c-6ffq-p4hh.json new file mode 100644 index 00000000000..a115cd24fee --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-cw8c-6ffq-p4hh/GHSA-cw8c-6ffq-p4hh.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cw8c-6ffq-p4hh", + "modified": "2025-06-10T09:30:31Z", + "published": "2025-06-10T09:30:31Z", + "aliases": [ + "CVE-2025-5740" + ], + "details": "CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that\ncould cause arbitrary file writes when an unauthenticated user on the web server manipulates file path.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5740" + }, + { + "type": "WEB", + "url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2025-161-03&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2025-161-03.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T09:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-f2qx-w367-78j3/GHSA-f2qx-w367-78j3.json b/advisories/unreviewed/2025/06/GHSA-f2qx-w367-78j3/GHSA-f2qx-w367-78j3.json new file mode 100644 index 00000000000..ae5fe1aa5d9 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-f2qx-w367-78j3/GHSA-f2qx-w367-78j3.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f2qx-w367-78j3", + "modified": "2025-06-10T09:30:31Z", + "published": "2025-06-10T09:30:31Z", + "aliases": [ + "CVE-2025-3117" + ], + "details": "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability\nexists impacting configuration file paths that could cause an unvalidated data injected by authenticated\nmalicious user leading to modify or read data in a victim’s browser.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3117" + }, + { + "type": "WEB", + "url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2025-161-02&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2025-161-02.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T09:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-hxx3-p6px-cf6j/GHSA-hxx3-p6px-cf6j.json b/advisories/unreviewed/2025/06/GHSA-hxx3-p6px-cf6j/GHSA-hxx3-p6px-cf6j.json new file mode 100644 index 00000000000..15e3183ccc1 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-hxx3-p6px-cf6j/GHSA-hxx3-p6px-cf6j.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hxx3-p6px-cf6j", + "modified": "2025-06-10T09:30:31Z", + "published": "2025-06-10T09:30:31Z", + "aliases": [ + "CVE-2025-3898" + ], + "details": "CWE-20: Improper Input Validation vulnerability exists that could cause Denial of Service when an\nauthenticated malicious user sends HTTPS request containing invalid data type to the webserver.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3898" + }, + { + "type": "WEB", + "url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2025-161-02&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2025-161-02.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T09:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-j34m-g9vq-47p3/GHSA-j34m-g9vq-47p3.json b/advisories/unreviewed/2025/06/GHSA-j34m-g9vq-47p3/GHSA-j34m-g9vq-47p3.json new file mode 100644 index 00000000000..ce6402ce2e8 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-j34m-g9vq-47p3/GHSA-j34m-g9vq-47p3.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j34m-g9vq-47p3", + "modified": "2025-06-10T09:30:31Z", + "published": "2025-06-10T09:30:31Z", + "aliases": [ + "CVE-2025-3899" + ], + "details": "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability\nexists in Certificates page on Webserver that could cause an unvalidated data injected by authenticated\nmalicious user leading to modify or read data in a victim’s browser.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3899" + }, + { + "type": "WEB", + "url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2025-161-02&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2025-161-02.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T09:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-jqqm-2p4m-968q/GHSA-jqqm-2p4m-968q.json b/advisories/unreviewed/2025/06/GHSA-jqqm-2p4m-968q/GHSA-jqqm-2p4m-968q.json new file mode 100644 index 00000000000..e18044f8d46 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-jqqm-2p4m-968q/GHSA-jqqm-2p4m-968q.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jqqm-2p4m-968q", + "modified": "2025-06-10T09:30:31Z", + "published": "2025-06-10T09:30:31Z", + "aliases": [ + "CVE-2025-5743" + ], + "details": "CWE-78: I Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')\nvulnerability exists that could cause remote control over the charging station when an authenticated user\nmodifies configuration parameters on the web server.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5743" + }, + { + "type": "WEB", + "url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2025-161-03&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2025-161-03.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T09:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-jqw9-2xg8-2hvh/GHSA-jqw9-2xg8-2hvh.json b/advisories/unreviewed/2025/06/GHSA-jqw9-2xg8-2hvh/GHSA-jqw9-2xg8-2hvh.json new file mode 100644 index 00000000000..c8d2a2e5333 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-jqw9-2xg8-2hvh/GHSA-jqw9-2xg8-2hvh.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jqw9-2xg8-2hvh", + "modified": "2025-06-10T09:30:31Z", + "published": "2025-06-10T09:30:31Z", + "aliases": [ + "CVE-2025-5741" + ], + "details": "CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that\ncould cause arbitrary file reads from the charging station. The exploitation of this vulnerability does require an\nauthenticated session of the web server.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5741" + }, + { + "type": "WEB", + "url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2025-161-03&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2025-161-03.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T09:15:25Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-mcwh-c9pg-xw43/GHSA-mcwh-c9pg-xw43.json b/advisories/unreviewed/2025/06/GHSA-mcwh-c9pg-xw43/GHSA-mcwh-c9pg-xw43.json new file mode 100644 index 00000000000..9d6fe621c1d --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-mcwh-c9pg-xw43/GHSA-mcwh-c9pg-xw43.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mcwh-c9pg-xw43", + "modified": "2025-06-10T09:30:31Z", + "published": "2025-06-10T09:30:31Z", + "aliases": [ + "CVE-2025-27819" + ], + "details": "In CVE-2023-25194, we announced the RCE/Denial of service attack via SASL JAAS JndiLoginModule configuration in Kafka Connect API. But not only Kafka Connect API is vulnerable to this attack, the Apache Kafka brokers also have this vulnerability. To exploit this vulnerability, the attacker needs to be able to connect to the Kafka cluster and have the AlterConfigs permission on the cluster resource.\n\n\nSince Apache Kafka 3.4.0, we have added a system property (\"-Dorg.apache.kafka.disallowed.login.modules\") to disable the problematic login modules usage in SASL JAAS configuration. Also by default \"com.sun.security.auth.module.JndiLoginModule\" is disabled in Apache Kafka 3.4.0, and \"com.sun.security.auth.module.JndiLoginModule,com.sun.security.auth.module.LdapLoginModule\" is disabled by default in in Apache Kafka 3.9.1/4.0.0", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27819" + }, + { + "type": "WEB", + "url": "https://kafka.apache.org/cve-list" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T08:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-r2gg-7x5x-xgpx/GHSA-r2gg-7x5x-xgpx.json b/advisories/unreviewed/2025/06/GHSA-r2gg-7x5x-xgpx/GHSA-r2gg-7x5x-xgpx.json new file mode 100644 index 00000000000..d3e72151f78 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-r2gg-7x5x-xgpx/GHSA-r2gg-7x5x-xgpx.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r2gg-7x5x-xgpx", + "modified": "2025-06-10T09:30:31Z", + "published": "2025-06-10T09:30:31Z", + "aliases": [ + "CVE-2025-5945" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5945" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T08:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-vgq5-3255-v292/GHSA-vgq5-3255-v292.json b/advisories/unreviewed/2025/06/GHSA-vgq5-3255-v292/GHSA-vgq5-3255-v292.json new file mode 100644 index 00000000000..e356c0a13ab --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-vgq5-3255-v292/GHSA-vgq5-3255-v292.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vgq5-3255-v292", + "modified": "2025-06-10T09:30:31Z", + "published": "2025-06-10T09:30:31Z", + "aliases": [ + "CVE-2025-27817" + ], + "details": "A possible arbitrary file read and SSRF vulnerability has been identified in Apache Kafka Client. Apache Kafka Clients accept configuration data for setting the SASL/OAUTHBEARER connection with the brokers, including \"sasl.oauthbearer.token.endpoint.url\" and \"sasl.oauthbearer.jwks.endpoint.url\". Apache Kafka allows clients to read an arbitrary file and return the content in the error log, or sending requests to an unintended location. In applications where Apache Kafka Clients configurations can be specified by an untrusted party, attackers may use the \"sasl.oauthbearer.token.endpoint.url\" and \"sasl.oauthbearer.jwks.endpoint.url\" configuratin to read arbitrary contents of the disk and environment variables or make requests to an unintended location. In particular, this flaw may be used in Apache Kafka Connect to escalate from REST API access to filesystem/environment/URL access, which may be undesirable in certain environments, including SaaS products. \n\nSince Apache Kafka 3.9.1/4.0.0, we have added a system property (\"-Dorg.apache.kafka.sasl.oauthbearer.allowed.urls\") to set the allowed urls in SASL JAAS configuration. In 3.9.1, it accepts all urls by default for backward compatibility. However in 4.0.0 and newer, the default value is empty list and users have to set the allowed urls explicitly.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27817" + }, + { + "type": "WEB", + "url": "https://kafka.apache.org/cve-list" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/06/09/1" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T08:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-ww37-xgr7-c25p/GHSA-ww37-xgr7-c25p.json b/advisories/unreviewed/2025/06/GHSA-ww37-xgr7-c25p/GHSA-ww37-xgr7-c25p.json new file mode 100644 index 00000000000..b6c5a113bdf --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-ww37-xgr7-c25p/GHSA-ww37-xgr7-c25p.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ww37-xgr7-c25p", + "modified": "2025-06-10T09:30:31Z", + "published": "2025-06-10T09:30:31Z", + "aliases": [ + "CVE-2025-3112" + ], + "details": "CWE-400: Uncontrolled Resource Consumption vulnerability exists that could cause Denial of Service when an\nauthenticated malicious user sends manipulated HTTPS Content-Length header to the webserver.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3112" + }, + { + "type": "WEB", + "url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2025-161-02&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2025-161-02.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T09:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-x3hv-q6h3-h9ph/GHSA-x3hv-q6h3-h9ph.json b/advisories/unreviewed/2025/06/GHSA-x3hv-q6h3-h9ph/GHSA-x3hv-q6h3-h9ph.json new file mode 100644 index 00000000000..8e18bd919d7 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-x3hv-q6h3-h9ph/GHSA-x3hv-q6h3-h9ph.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x3hv-q6h3-h9ph", + "modified": "2025-06-10T09:30:31Z", + "published": "2025-06-10T09:30:31Z", + "aliases": [ + "CVE-2025-3905" + ], + "details": "CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability\nexists impacting PLC system variables that could cause an unvalidated data injected by authenticated\nmalicious user leading to modify or read data in a victim’s browser.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3905" + }, + { + "type": "WEB", + "url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2025-161-02&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2025-161-02.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T09:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-xmv7-64fr-2r3x/GHSA-xmv7-64fr-2r3x.json b/advisories/unreviewed/2025/06/GHSA-xmv7-64fr-2r3x/GHSA-xmv7-64fr-2r3x.json new file mode 100644 index 00000000000..dc99d14566d --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-xmv7-64fr-2r3x/GHSA-xmv7-64fr-2r3x.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xmv7-64fr-2r3x", + "modified": "2025-06-10T09:30:31Z", + "published": "2025-06-10T09:30:31Z", + "aliases": [ + "CVE-2025-3116" + ], + "details": "CWE-20: Improper Input Validation vulnerability exists that could cause Denial of Service when an\nauthenticated malicious user sends special malformed HTTPS request containing improper formatted body\ndata to the controller.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3116" + }, + { + "type": "WEB", + "url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2025-161-02&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2025-161-02.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T09:15:23Z" + } +} \ No newline at end of file