diff --git a/advisories/github-reviewed/2025/04/GHSA-5r66-vgc7-2mm3/GHSA-5r66-vgc7-2mm3.json b/advisories/github-reviewed/2025/04/GHSA-5r66-vgc7-2mm3/GHSA-5r66-vgc7-2mm3.json new file mode 100644 index 00000000000..b81ad8b5ee0 --- /dev/null +++ b/advisories/github-reviewed/2025/04/GHSA-5r66-vgc7-2mm3/GHSA-5r66-vgc7-2mm3.json @@ -0,0 +1,65 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5r66-vgc7-2mm3", + "modified": "2025-04-02T17:16:39Z", + "published": "2025-04-01T00:30:35Z", + "aliases": [ + "CVE-2025-31697" + ], + "summary": "Drupal Formatter Suite Vulnerable to Cross-Site Scripting (XSS) via Link Element Attributes", + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Formatter Suite allows Cross-Site Scripting (XSS).This issue affects Formatter Suite: from 0.0.0 before 2.1.0.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "drupal/formatter_suite" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.1.0" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31697" + }, + { + "type": "PACKAGE", + "url": "https://git.drupalcode.org/project/formatter_suite" + }, + { + "type": "WEB", + "url": "https://git.drupalcode.org/project/formatter_suite/-/commit/58adb4168466b056e33fc4f356f43dd000e3765b" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-026" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "LOW", + "github_reviewed": true, + "github_reviewed_at": "2025-04-02T17:16:39Z", + "nvd_published_at": "2025-03-31T22:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2025/04/GHSA-86h4-w859-3hhv/GHSA-86h4-w859-3hhv.json b/advisories/github-reviewed/2025/04/GHSA-86h4-w859-3hhv/GHSA-86h4-w859-3hhv.json new file mode 100644 index 00000000000..84c5c75ef71 --- /dev/null +++ b/advisories/github-reviewed/2025/04/GHSA-86h4-w859-3hhv/GHSA-86h4-w859-3hhv.json @@ -0,0 +1,61 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-86h4-w859-3hhv", + "modified": "2025-04-02T17:16:22Z", + "published": "2025-04-01T00:30:35Z", + "aliases": [ + "CVE-2025-31696" + ], + "summary": "Drupal RapiDoc OAS Field Formatter Cross-Site Scripting (XSS) vulnerability", + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal RapiDoc OAS Field Formatter allows Cross-Site Scripting (XSS). This issue affects RapiDoc OAS Field Formatter: from 0.0.0 before 1.0.1.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "drupal/rapidoc_elements_field_formatter" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.0.1" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31696" + }, + { + "type": "PACKAGE", + "url": "https://git.drupalcode.org/project/rapidoc_elements_field_formatter" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-025" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "LOW", + "github_reviewed": true, + "github_reviewed_at": "2025-04-02T17:16:22Z", + "nvd_published_at": "2025-03-31T22:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2025/04/GHSA-hf6c-fgp3-jfch/GHSA-hf6c-fgp3-jfch.json b/advisories/github-reviewed/2025/04/GHSA-hf6c-fgp3-jfch/GHSA-hf6c-fgp3-jfch.json new file mode 100644 index 00000000000..ba89549fa89 --- /dev/null +++ b/advisories/github-reviewed/2025/04/GHSA-hf6c-fgp3-jfch/GHSA-hf6c-fgp3-jfch.json @@ -0,0 +1,62 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hf6c-fgp3-jfch", + "modified": "2025-04-02T17:15:20Z", + "published": "2025-04-01T00:30:35Z", + "aliases": [ + "CVE-2025-31694" + ], + "summary": "Drupal Two-factor Authentication (TFA) Vulnerable to Forceful Browsing", + "details": "Incorrect Authorization vulnerability in Drupal Two-factor Authentication (TFA) allows Forceful Browsing. This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.10.0.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "drupal/tfa" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.10.0" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31694" + }, + { + "type": "PACKAGE", + "url": "https://git.drupalcode.org/project/tfa" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-023" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-288", + "CWE-863" + ], + "severity": "LOW", + "github_reviewed": true, + "github_reviewed_at": "2025-04-02T17:15:20Z", + "nvd_published_at": "2025-03-31T22:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2025/04/GHSA-p2wg-8h29-874v/GHSA-p2wg-8h29-874v.json b/advisories/github-reviewed/2025/04/GHSA-p2wg-8h29-874v/GHSA-p2wg-8h29-874v.json new file mode 100644 index 00000000000..a09ba2859c2 --- /dev/null +++ b/advisories/github-reviewed/2025/04/GHSA-p2wg-8h29-874v/GHSA-p2wg-8h29-874v.json @@ -0,0 +1,61 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p2wg-8h29-874v", + "modified": "2025-04-02T17:15:52Z", + "published": "2025-04-01T00:30:35Z", + "aliases": [ + "CVE-2025-31695" + ], + "summary": "Drupal Link field display mode formatter Cross-Site Scripting (XSS) vulnerability", + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Link field display mode formatter allows Cross-Site Scripting (XSS). This issue affects Link field display mode formatter: from 0.0.0 before 1.6.0.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "drupal/link_field_display_mode_formatter" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.6.0" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31695" + }, + { + "type": "PACKAGE", + "url": "https://git.drupalcode.org/project/link_field_display_mode_formatter" + }, + { + "type": "WEB", + "url": "https://www.drupal.org/sa-contrib-2025-024" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "LOW", + "github_reviewed": true, + "github_reviewed_at": "2025-04-02T17:15:52Z", + "nvd_published_at": "2025-03-31T22:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5r66-vgc7-2mm3/GHSA-5r66-vgc7-2mm3.json b/advisories/unreviewed/2025/04/GHSA-5r66-vgc7-2mm3/GHSA-5r66-vgc7-2mm3.json deleted file mode 100644 index e039ef7fb55..00000000000 --- a/advisories/unreviewed/2025/04/GHSA-5r66-vgc7-2mm3/GHSA-5r66-vgc7-2mm3.json +++ /dev/null @@ -1,31 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-5r66-vgc7-2mm3", - "modified": "2025-04-01T00:30:35Z", - "published": "2025-04-01T00:30:35Z", - "aliases": [ - "CVE-2025-31697" - ], - "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Formatter Suite allows Cross-Site Scripting (XSS).This issue affects Formatter Suite: from 0.0.0 before 2.1.0.", - "severity": [], - "affected": [], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31697" - }, - { - "type": "WEB", - "url": "https://www.drupal.org/sa-contrib-2025-026" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-79" - ], - "severity": null, - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2025-03-31T22:15:22Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-86h4-w859-3hhv/GHSA-86h4-w859-3hhv.json b/advisories/unreviewed/2025/04/GHSA-86h4-w859-3hhv/GHSA-86h4-w859-3hhv.json deleted file mode 100644 index af8e1b5919a..00000000000 --- a/advisories/unreviewed/2025/04/GHSA-86h4-w859-3hhv/GHSA-86h4-w859-3hhv.json +++ /dev/null @@ -1,31 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-86h4-w859-3hhv", - "modified": "2025-04-01T00:30:35Z", - "published": "2025-04-01T00:30:35Z", - "aliases": [ - "CVE-2025-31696" - ], - "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal RapiDoc OAS Field Formatter allows Cross-Site Scripting (XSS).This issue affects RapiDoc OAS Field Formatter: from 0.0.0 before 1.0.1.", - "severity": [], - "affected": [], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31696" - }, - { - "type": "WEB", - "url": "https://www.drupal.org/sa-contrib-2025-025" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-79" - ], - "severity": null, - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2025-03-31T22:15:22Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hf6c-fgp3-jfch/GHSA-hf6c-fgp3-jfch.json b/advisories/unreviewed/2025/04/GHSA-hf6c-fgp3-jfch/GHSA-hf6c-fgp3-jfch.json deleted file mode 100644 index 8e06740984e..00000000000 --- a/advisories/unreviewed/2025/04/GHSA-hf6c-fgp3-jfch/GHSA-hf6c-fgp3-jfch.json +++ /dev/null @@ -1,32 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-hf6c-fgp3-jfch", - "modified": "2025-04-01T00:30:35Z", - "published": "2025-04-01T00:30:35Z", - "aliases": [ - "CVE-2025-31694" - ], - "details": "Incorrect Authorization vulnerability in Drupal Two-factor Authentication (TFA) allows Forceful Browsing.This issue affects Two-factor Authentication (TFA): from 0.0.0 before 1.10.0.", - "severity": [], - "affected": [], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31694" - }, - { - "type": "WEB", - "url": "https://www.drupal.org/sa-contrib-2025-023" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-288", - "CWE-863" - ], - "severity": null, - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2025-03-31T22:15:22Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-p2wg-8h29-874v/GHSA-p2wg-8h29-874v.json b/advisories/unreviewed/2025/04/GHSA-p2wg-8h29-874v/GHSA-p2wg-8h29-874v.json deleted file mode 100644 index 82efc3d80f5..00000000000 --- a/advisories/unreviewed/2025/04/GHSA-p2wg-8h29-874v/GHSA-p2wg-8h29-874v.json +++ /dev/null @@ -1,31 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-p2wg-8h29-874v", - "modified": "2025-04-01T00:30:35Z", - "published": "2025-04-01T00:30:35Z", - "aliases": [ - "CVE-2025-31695" - ], - "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Link field display mode formatter allows Cross-Site Scripting (XSS).This issue affects Link field display mode formatter: from 0.0.0 before 1.6.0.", - "severity": [], - "affected": [], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31695" - }, - { - "type": "WEB", - "url": "https://www.drupal.org/sa-contrib-2025-024" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-79" - ], - "severity": null, - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2025-03-31T22:15:22Z" - } -} \ No newline at end of file