From 68cb5ad8dcce803ee3ce61b38864866b59046a80 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 11 Apr 2025 21:32:31 +0000 Subject: [PATCH] Publish Advisories GHSA-54hw-8q4q-2g6m GHSA-32rr-g2cq-v328 GHSA-9xg5-c6xr-xwgc GHSA-qm95-9v2h-5rq5 GHSA-5rmc-9cm9-28cr GHSA-66mh-pcv7-gg73 GHSA-8pmj-vrj3-r692 GHSA-fgjj-2m6m-vf56 GHSA-gfmx-hgrp-xwrv GHSA-gxwf-3xjr-jjqf GHSA-jm38-gf7c-9f3f GHSA-vf8c-ccvq-v376 GHSA-mj4r-rr6h-q62g GHSA-p8w2-9mpv-5ccm --- .../GHSA-54hw-8q4q-2g6m.json | 4 +- .../GHSA-32rr-g2cq-v328.json | 4 +- .../GHSA-9xg5-c6xr-xwgc.json | 3 +- .../GHSA-qm95-9v2h-5rq5.json | 3 +- .../GHSA-5rmc-9cm9-28cr.json | 10 ++++- .../GHSA-66mh-pcv7-gg73.json | 10 ++++- .../GHSA-8pmj-vrj3-r692.json | 10 ++++- .../GHSA-fgjj-2m6m-vf56.json | 10 ++++- .../GHSA-gfmx-hgrp-xwrv.json | 10 ++++- .../GHSA-gxwf-3xjr-jjqf.json | 10 ++++- .../GHSA-jm38-gf7c-9f3f.json | 10 ++++- .../GHSA-vf8c-ccvq-v376.json | 10 ++++- .../GHSA-mj4r-rr6h-q62g.json | 15 +++++-- .../GHSA-p8w2-9mpv-5ccm.json | 40 +++++++++++++++++++ 14 files changed, 132 insertions(+), 17 deletions(-) create mode 100644 advisories/unreviewed/2025/04/GHSA-p8w2-9mpv-5ccm/GHSA-p8w2-9mpv-5ccm.json diff --git a/advisories/unreviewed/2022/12/GHSA-54hw-8q4q-2g6m/GHSA-54hw-8q4q-2g6m.json b/advisories/unreviewed/2022/12/GHSA-54hw-8q4q-2g6m/GHSA-54hw-8q4q-2g6m.json index c3fc320f739..cbf955313ab 100644 --- a/advisories/unreviewed/2022/12/GHSA-54hw-8q4q-2g6m/GHSA-54hw-8q4q-2g6m.json +++ b/advisories/unreviewed/2022/12/GHSA-54hw-8q4q-2g6m/GHSA-54hw-8q4q-2g6m.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-269" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-32rr-g2cq-v328/GHSA-32rr-g2cq-v328.json b/advisories/unreviewed/2024/03/GHSA-32rr-g2cq-v328/GHSA-32rr-g2cq-v328.json index 9c4c00186e6..b7b8825892b 100644 --- a/advisories/unreviewed/2024/03/GHSA-32rr-g2cq-v328/GHSA-32rr-g2cq-v328.json +++ b/advisories/unreviewed/2024/03/GHSA-32rr-g2cq-v328/GHSA-32rr-g2cq-v328.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-32rr-g2cq-v328", - "modified": "2024-03-27T09:30:40Z", + "modified": "2025-04-11T21:30:34Z", "published": "2024-03-27T09:30:40Z", "aliases": [ "CVE-2024-29918" ], - "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Survey Maker team Survey Maker allows Reflected XSS.This issue affects Survey Maker: from n/a through 4.0.6.\n\n", + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Survey Maker team Survey Maker allows Reflected XSS.This issue affects Survey Maker: from n/a through 4.0.6.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2025/02/GHSA-9xg5-c6xr-xwgc/GHSA-9xg5-c6xr-xwgc.json b/advisories/unreviewed/2025/02/GHSA-9xg5-c6xr-xwgc/GHSA-9xg5-c6xr-xwgc.json index f393dcd0204..d522249696e 100644 --- a/advisories/unreviewed/2025/02/GHSA-9xg5-c6xr-xwgc/GHSA-9xg5-c6xr-xwgc.json +++ b/advisories/unreviewed/2025/02/GHSA-9xg5-c6xr-xwgc/GHSA-9xg5-c6xr-xwgc.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/02/GHSA-qm95-9v2h-5rq5/GHSA-qm95-9v2h-5rq5.json b/advisories/unreviewed/2025/02/GHSA-qm95-9v2h-5rq5/GHSA-qm95-9v2h-5rq5.json index a3f5051588e..31bb543e1fe 100644 --- a/advisories/unreviewed/2025/02/GHSA-qm95-9v2h-5rq5/GHSA-qm95-9v2h-5rq5.json +++ b/advisories/unreviewed/2025/02/GHSA-qm95-9v2h-5rq5/GHSA-qm95-9v2h-5rq5.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-5rmc-9cm9-28cr/GHSA-5rmc-9cm9-28cr.json b/advisories/unreviewed/2025/03/GHSA-5rmc-9cm9-28cr/GHSA-5rmc-9cm9-28cr.json index cc3b3c9e2f7..6a77cba3c61 100644 --- a/advisories/unreviewed/2025/03/GHSA-5rmc-9cm9-28cr/GHSA-5rmc-9cm9-28cr.json +++ b/advisories/unreviewed/2025/03/GHSA-5rmc-9cm9-28cr/GHSA-5rmc-9cm9-28cr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5rmc-9cm9-28cr", - "modified": "2025-03-25T03:30:25Z", + "modified": "2025-04-11T21:30:35Z", "published": "2025-03-25T03:30:25Z", "aliases": [ "CVE-2025-2728" @@ -38,6 +38,14 @@ { "type": "WEB", "url": "https://vuldb.com/?submit.520462" + }, + { + "type": "WEB", + "url": "https://www.h3c.com/cn/Service/Document_Software/Software_Download/Consume_product" + }, + { + "type": "WEB", + "url": "https://zhiliao.h3c.com/theme/details/229784" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/03/GHSA-66mh-pcv7-gg73/GHSA-66mh-pcv7-gg73.json b/advisories/unreviewed/2025/03/GHSA-66mh-pcv7-gg73/GHSA-66mh-pcv7-gg73.json index 241775cc124..d76e19c50bb 100644 --- a/advisories/unreviewed/2025/03/GHSA-66mh-pcv7-gg73/GHSA-66mh-pcv7-gg73.json +++ b/advisories/unreviewed/2025/03/GHSA-66mh-pcv7-gg73/GHSA-66mh-pcv7-gg73.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-66mh-pcv7-gg73", - "modified": "2025-03-25T03:30:25Z", + "modified": "2025-04-11T21:30:35Z", "published": "2025-03-25T03:30:25Z", "aliases": [ "CVE-2025-2727" @@ -38,6 +38,14 @@ { "type": "WEB", "url": "https://vuldb.com/?submit.520394" + }, + { + "type": "WEB", + "url": "https://www.h3c.com/cn/Service/Document_Software/Software_Download/Consume_product" + }, + { + "type": "WEB", + "url": "https://zhiliao.h3c.com/theme/details/229784" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/03/GHSA-8pmj-vrj3-r692/GHSA-8pmj-vrj3-r692.json b/advisories/unreviewed/2025/03/GHSA-8pmj-vrj3-r692/GHSA-8pmj-vrj3-r692.json index 513686ee952..0c2c0c5790f 100644 --- a/advisories/unreviewed/2025/03/GHSA-8pmj-vrj3-r692/GHSA-8pmj-vrj3-r692.json +++ b/advisories/unreviewed/2025/03/GHSA-8pmj-vrj3-r692/GHSA-8pmj-vrj3-r692.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8pmj-vrj3-r692", - "modified": "2025-03-25T03:30:25Z", + "modified": "2025-04-11T21:30:36Z", "published": "2025-03-25T03:30:25Z", "aliases": [ "CVE-2025-2729" @@ -38,6 +38,14 @@ { "type": "WEB", "url": "https://vuldb.com/?submit.520494" + }, + { + "type": "WEB", + "url": "https://www.h3c.com/cn/Service/Document_Software/Software_Download/Consume_product" + }, + { + "type": "WEB", + "url": "https://zhiliao.h3c.com/theme/details/229784" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/03/GHSA-fgjj-2m6m-vf56/GHSA-fgjj-2m6m-vf56.json b/advisories/unreviewed/2025/03/GHSA-fgjj-2m6m-vf56/GHSA-fgjj-2m6m-vf56.json index 85182803bfa..23c60450025 100644 --- a/advisories/unreviewed/2025/03/GHSA-fgjj-2m6m-vf56/GHSA-fgjj-2m6m-vf56.json +++ b/advisories/unreviewed/2025/03/GHSA-fgjj-2m6m-vf56/GHSA-fgjj-2m6m-vf56.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fgjj-2m6m-vf56", - "modified": "2025-03-25T03:30:24Z", + "modified": "2025-04-11T21:30:35Z", "published": "2025-03-25T03:30:24Z", "aliases": [ "CVE-2025-2726" @@ -38,6 +38,14 @@ { "type": "WEB", "url": "https://vuldb.com/?submit.520393" + }, + { + "type": "WEB", + "url": "https://www.h3c.com/cn/Service/Document_Software/Software_Download/Consume_product" + }, + { + "type": "WEB", + "url": "https://zhiliao.h3c.com/theme/details/229784" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/03/GHSA-gfmx-hgrp-xwrv/GHSA-gfmx-hgrp-xwrv.json b/advisories/unreviewed/2025/03/GHSA-gfmx-hgrp-xwrv/GHSA-gfmx-hgrp-xwrv.json index 40fa4ac39bb..6fc69195176 100644 --- a/advisories/unreviewed/2025/03/GHSA-gfmx-hgrp-xwrv/GHSA-gfmx-hgrp-xwrv.json +++ b/advisories/unreviewed/2025/03/GHSA-gfmx-hgrp-xwrv/GHSA-gfmx-hgrp-xwrv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gfmx-hgrp-xwrv", - "modified": "2025-03-25T06:30:26Z", + "modified": "2025-04-11T21:30:36Z", "published": "2025-03-25T06:30:26Z", "aliases": [ "CVE-2025-2731" @@ -38,6 +38,14 @@ { "type": "WEB", "url": "https://vuldb.com/?submit.520497" + }, + { + "type": "WEB", + "url": "https://www.h3c.com/cn/Service/Document_Software/Software_Download/Consume_product" + }, + { + "type": "WEB", + "url": "https://zhiliao.h3c.com/theme/details/229784" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/03/GHSA-gxwf-3xjr-jjqf/GHSA-gxwf-3xjr-jjqf.json b/advisories/unreviewed/2025/03/GHSA-gxwf-3xjr-jjqf/GHSA-gxwf-3xjr-jjqf.json index 69c12e47414..62b3a084122 100644 --- a/advisories/unreviewed/2025/03/GHSA-gxwf-3xjr-jjqf/GHSA-gxwf-3xjr-jjqf.json +++ b/advisories/unreviewed/2025/03/GHSA-gxwf-3xjr-jjqf/GHSA-gxwf-3xjr-jjqf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gxwf-3xjr-jjqf", - "modified": "2025-03-25T06:30:26Z", + "modified": "2025-04-11T21:30:36Z", "published": "2025-03-25T06:30:26Z", "aliases": [ "CVE-2025-2732" @@ -38,6 +38,14 @@ { "type": "WEB", "url": "https://vuldb.com/?submit.520499" + }, + { + "type": "WEB", + "url": "https://www.h3c.com/cn/Service/Document_Software/Software_Download/Consume_product" + }, + { + "type": "WEB", + "url": "https://zhiliao.h3c.com/theme/details/229784" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/03/GHSA-jm38-gf7c-9f3f/GHSA-jm38-gf7c-9f3f.json b/advisories/unreviewed/2025/03/GHSA-jm38-gf7c-9f3f/GHSA-jm38-gf7c-9f3f.json index d01f49dad17..cfd30ec88b1 100644 --- a/advisories/unreviewed/2025/03/GHSA-jm38-gf7c-9f3f/GHSA-jm38-gf7c-9f3f.json +++ b/advisories/unreviewed/2025/03/GHSA-jm38-gf7c-9f3f/GHSA-jm38-gf7c-9f3f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jm38-gf7c-9f3f", - "modified": "2025-03-25T03:30:25Z", + "modified": "2025-04-11T21:30:36Z", "published": "2025-03-25T03:30:25Z", "aliases": [ "CVE-2025-2730" @@ -38,6 +38,14 @@ { "type": "WEB", "url": "https://vuldb.com/?submit.520495" + }, + { + "type": "WEB", + "url": "https://www.h3c.com/cn/Service/Document_Software/Software_Download/Consume_product" + }, + { + "type": "WEB", + "url": "https://zhiliao.h3c.com/theme/details/229784" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/03/GHSA-vf8c-ccvq-v376/GHSA-vf8c-ccvq-v376.json b/advisories/unreviewed/2025/03/GHSA-vf8c-ccvq-v376/GHSA-vf8c-ccvq-v376.json index 05dd1980547..d8e10fa62f0 100644 --- a/advisories/unreviewed/2025/03/GHSA-vf8c-ccvq-v376/GHSA-vf8c-ccvq-v376.json +++ b/advisories/unreviewed/2025/03/GHSA-vf8c-ccvq-v376/GHSA-vf8c-ccvq-v376.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vf8c-ccvq-v376", - "modified": "2025-03-25T03:30:24Z", + "modified": "2025-04-11T21:30:35Z", "published": "2025-03-25T03:30:24Z", "aliases": [ "CVE-2025-2725" @@ -38,6 +38,14 @@ { "type": "WEB", "url": "https://vuldb.com/?submit.520390" + }, + { + "type": "WEB", + "url": "https://www.h3c.com/cn/Service/Document_Software/Software_Download/Consume_product" + }, + { + "type": "WEB", + "url": "https://zhiliao.h3c.com/theme/details/229784" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/04/GHSA-mj4r-rr6h-q62g/GHSA-mj4r-rr6h-q62g.json b/advisories/unreviewed/2025/04/GHSA-mj4r-rr6h-q62g/GHSA-mj4r-rr6h-q62g.json index 128a4173afd..a2f3e2022f8 100644 --- a/advisories/unreviewed/2025/04/GHSA-mj4r-rr6h-q62g/GHSA-mj4r-rr6h-q62g.json +++ b/advisories/unreviewed/2025/04/GHSA-mj4r-rr6h-q62g/GHSA-mj4r-rr6h-q62g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mj4r-rr6h-q62g", - "modified": "2025-04-10T15:31:48Z", + "modified": "2025-04-11T21:30:36Z", "published": "2025-04-10T15:31:48Z", "aliases": [ "CVE-2025-29088" ], "details": "An issue in sqlite v.3.49.0 allows an attacker to cause a denial of service via the SQLITE_DBCONFIG_LOOKASIDE component", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-400" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-10T14:15:27Z" diff --git a/advisories/unreviewed/2025/04/GHSA-p8w2-9mpv-5ccm/GHSA-p8w2-9mpv-5ccm.json b/advisories/unreviewed/2025/04/GHSA-p8w2-9mpv-5ccm/GHSA-p8w2-9mpv-5ccm.json new file mode 100644 index 00000000000..f2528d098cb --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-p8w2-9mpv-5ccm/GHSA-p8w2-9mpv-5ccm.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p8w2-9mpv-5ccm", + "modified": "2025-04-11T21:30:36Z", + "published": "2025-04-11T21:30:36Z", + "aliases": [ + "CVE-2024-11679" + ], + "details": "An input validation weakness was reported in the TpmSetup module for some legacy System x server products that could allow a local attacker with elevated privileges to read the contents of memory.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11679" + }, + { + "type": "WEB", + "url": "https://support.lenovo.com/us/en/product_security/LEN-193044" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-11T19:15:41Z" + } +} \ No newline at end of file