From 6ba83c9751ea8d7aaf0e34ef914500a47d426bf3 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 20 May 2025 09:32:44 +0000 Subject: [PATCH] Publish Advisories GHSA-68c3-2gxf-hpcv GHSA-p6vf-3g57-hjv6 GHSA-v69j-q2rv-25rq GHSA-qhmg-pv98-3cg7 GHSA-v92h-jfmf-wx2h GHSA-x5qc-9crp-x6hr GHSA-62gh-q5g8-jv59 GHSA-f252-qh43-5v8p GHSA-x48w-vp6x-g2px --- .../GHSA-68c3-2gxf-hpcv.json | 6 ++- .../GHSA-p6vf-3g57-hjv6.json | 8 +++- .../GHSA-v69j-q2rv-25rq.json | 8 +++- .../GHSA-qhmg-pv98-3cg7.json | 12 ++++- .../GHSA-v92h-jfmf-wx2h.json | 8 +++- .../GHSA-x5qc-9crp-x6hr.json | 6 ++- .../GHSA-62gh-q5g8-jv59.json | 6 ++- .../GHSA-f252-qh43-5v8p.json | 36 ++++++++++++++ .../GHSA-x48w-vp6x-g2px.json | 48 +++++++++++++++++++ 9 files changed, 127 insertions(+), 11 deletions(-) create mode 100644 advisories/unreviewed/2025/05/GHSA-f252-qh43-5v8p/GHSA-f252-qh43-5v8p.json create mode 100644 advisories/unreviewed/2025/05/GHSA-x48w-vp6x-g2px/GHSA-x48w-vp6x-g2px.json diff --git a/advisories/unreviewed/2023/10/GHSA-68c3-2gxf-hpcv/GHSA-68c3-2gxf-hpcv.json b/advisories/unreviewed/2023/10/GHSA-68c3-2gxf-hpcv/GHSA-68c3-2gxf-hpcv.json index db26921ef4f..f5580025b2a 100644 --- a/advisories/unreviewed/2023/10/GHSA-68c3-2gxf-hpcv/GHSA-68c3-2gxf-hpcv.json +++ b/advisories/unreviewed/2023/10/GHSA-68c3-2gxf-hpcv/GHSA-68c3-2gxf-hpcv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-68c3-2gxf-hpcv", - "modified": "2024-04-04T08:37:45Z", + "modified": "2025-05-20T09:30:59Z", "published": "2023-10-13T15:30:19Z", "aliases": [ "CVE-2023-45162" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://www.1e.com/trust-security-compliance/cve-info" + }, + { + "type": "WEB", + "url": "https://www.teamviewer.com/en/resources/trust-center/security-bulletins/1e-2023-2004" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-p6vf-3g57-hjv6/GHSA-p6vf-3g57-hjv6.json b/advisories/unreviewed/2023/10/GHSA-p6vf-3g57-hjv6/GHSA-p6vf-3g57-hjv6.json index 8b5dd932059..ee32f5abd20 100644 --- a/advisories/unreviewed/2023/10/GHSA-p6vf-3g57-hjv6/GHSA-p6vf-3g57-hjv6.json +++ b/advisories/unreviewed/2023/10/GHSA-p6vf-3g57-hjv6/GHSA-p6vf-3g57-hjv6.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-p6vf-3g57-hjv6", - "modified": "2024-04-04T08:19:13Z", + "modified": "2025-05-20T09:30:59Z", "published": "2023-10-05T12:30:21Z", "aliases": [ "CVE-2023-45159" ], - "details": "1E Client installer can perform arbitrary file deletion on protected files.  \n\nA non-privileged user could provide a symbolic link or Windows junction to point to a protected directory in the installer that the 1E Client would then clear on service startup. A hotfix is available Q23092 that forces the 1E Client to check for a symbolic link or junction and if it finds one refuses to use that path and instead creates a path involving a random GUID.\n\n", + "details": "1E Client installer can perform arbitrary file deletion on protected files.  \n\nA non-privileged user could provide a symbolic link or Windows junction to point to a protected directory in the installer that the 1E Client would then clear on service startup. A hotfix is available Q23092 that forces the 1E Client to check for a symbolic link or junction and if it finds one refuses to use that path and instead creates a path involving a random GUID.", "severity": [ { "type": "CVSS_V3", @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://www.1e.com/trust-security-compliance/cve-info" + }, + { + "type": "WEB", + "url": "https://www.teamviewer.com/en/resources/trust-center/security-bulletins/1e-2023-2001" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/10/GHSA-v69j-q2rv-25rq/GHSA-v69j-q2rv-25rq.json b/advisories/unreviewed/2023/10/GHSA-v69j-q2rv-25rq/GHSA-v69j-q2rv-25rq.json index 76f4e07ca57..ec0964c7dcb 100644 --- a/advisories/unreviewed/2023/10/GHSA-v69j-q2rv-25rq/GHSA-v69j-q2rv-25rq.json +++ b/advisories/unreviewed/2023/10/GHSA-v69j-q2rv-25rq/GHSA-v69j-q2rv-25rq.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-v69j-q2rv-25rq", - "modified": "2023-11-02T12:30:16Z", + "modified": "2025-05-20T09:30:59Z", "published": "2023-10-05T18:31:34Z", "aliases": [ "CVE-2023-45160" ], - "details": "\nIn the affected version of the 1E Client, an ordinary user could subvert downloaded instruction resource files, e.g., to substitute a harmful script. by replacing a resource script file created by an instruction at run time with a malicious script. This has been fixed in patch Q23094 as the 1E Client's temporary directory is now locked down\n\n", + "details": "In the affected version of the 1E Client, an ordinary user could subvert downloaded instruction resource files, e.g., to substitute a harmful script. by replacing a resource script file created by an instruction at run time with a malicious script. This has been fixed in patch Q23094 as the 1E Client's temporary directory is now locked down", "severity": [ { "type": "CVSS_V3", @@ -30,6 +30,10 @@ { "type": "WEB", "url": "https://www.1e.com/vulnerability-disclosure-policy" + }, + { + "type": "WEB", + "url": "https://www.teamviewer.com/en/resources/trust-center/security-bulletins/1e-2023-2002" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/11/GHSA-qhmg-pv98-3cg7/GHSA-qhmg-pv98-3cg7.json b/advisories/unreviewed/2023/11/GHSA-qhmg-pv98-3cg7/GHSA-qhmg-pv98-3cg7.json index 86337031425..d45e5a8225c 100644 --- a/advisories/unreviewed/2023/11/GHSA-qhmg-pv98-3cg7/GHSA-qhmg-pv98-3cg7.json +++ b/advisories/unreviewed/2023/11/GHSA-qhmg-pv98-3cg7/GHSA-qhmg-pv98-3cg7.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-qhmg-pv98-3cg7", - "modified": "2024-09-05T15:33:30Z", + "modified": "2025-05-20T09:30:59Z", "published": "2023-11-06T15:30:32Z", "aliases": [ "CVE-2023-45163" ], - "details": "\nThe 1E-Exchange-CommandLinePing instruction that is part of the Network product pack available on the 1E Exchange does not properly validate the input parameter, which allows for a specially crafted input to perform arbitrary code execution with SYSTEM permissions.\n\nTo remediate this issue download the updated Network product pack from the 1E Exchange and update the 1E-Exchange-CommandLinePing instruction to v18.1 by uploading it through the 1E Platform instruction upload UI\n\n", + "details": "The 1E-Exchange-CommandLinePing instruction that is part of the Network product pack available on the 1E Exchange does not properly validate the input parameter, which allows for a specially crafted input to perform arbitrary code execution with SYSTEM permissions.\n\nTo remediate this issue download the updated Network product pack from the 1E Exchange and update the 1E-Exchange-CommandLinePing instruction to v18.1 by uploading it through the 1E Platform instruction upload UI", "severity": [ { "type": "CVSS_V3", @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-45163" }, + { + "type": "WEB", + "url": "https://exchange.1e.com/product-packs/network" + }, { "type": "WEB", "url": "https://https://exchange.1e.com/product-packs/network" @@ -26,6 +30,10 @@ { "type": "WEB", "url": "https://www.1e.com/trust-security-compliance/cve-info" + }, + { + "type": "WEB", + "url": "https://www.teamviewer.com/en/resources/trust-center/security-bulletins/1e-2023-2005" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/11/GHSA-v92h-jfmf-wx2h/GHSA-v92h-jfmf-wx2h.json b/advisories/unreviewed/2023/11/GHSA-v92h-jfmf-wx2h/GHSA-v92h-jfmf-wx2h.json index 232caad1356..c865faec3c9 100644 --- a/advisories/unreviewed/2023/11/GHSA-v92h-jfmf-wx2h/GHSA-v92h-jfmf-wx2h.json +++ b/advisories/unreviewed/2023/11/GHSA-v92h-jfmf-wx2h/GHSA-v92h-jfmf-wx2h.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-v92h-jfmf-wx2h", - "modified": "2023-11-21T18:30:26Z", + "modified": "2025-05-20T09:31:00Z", "published": "2023-11-06T15:30:32Z", "aliases": [ "CVE-2023-5964" ], - "details": "\nThe 1E-Exchange-DisplayMessageinstruction that is part of the End-User Interaction product pack available on the 1E Exchange does not properly validate the Caption or Message parameters, which allows for a specially crafted input to perform arbitrary code execution with SYSTEM permissions.\n\nTo remediate this issue DELETE the instruction “Show dialogue with caption %Caption% and message %Message%” from the list of instructions in the Settings UI, and replace it with the new instruction 1E-Exchange-ShowNotification instruction available in the updated End-User Interaction product pack. The new instruction should show as “Show %Type% type notification with header %Header% and message %Message%” with a version of 7.1 or above.", + "details": "The 1E-Exchange-DisplayMessageinstruction that is part of the End-User Interaction product pack available on the 1E Exchange does not properly validate the Caption or Message parameters, which allows for a specially crafted input to perform arbitrary code execution with SYSTEM permissions.\n\nTo remediate this issue DELETE the instruction “Show dialogue with caption %Caption% and message %Message%” from the list of instructions in the Settings UI, and replace it with the new instruction 1E-Exchange-ShowNotification instruction available in the updated End-User Interaction product pack. The new instruction should show as “Show %Type% type notification with header %Header% and message %Message%” with a version of 7.1 or above.", "severity": [ { "type": "CVSS_V3", @@ -26,6 +26,10 @@ { "type": "WEB", "url": "https://www.1e.com/trust-security-compliance/cve-info" + }, + { + "type": "WEB", + "url": "https://www.teamviewer.com/en/resources/trust-center/security-bulletins/1e-2023-2006" } ], "database_specific": { diff --git a/advisories/unreviewed/2023/11/GHSA-x5qc-9crp-x6hr/GHSA-x5qc-9crp-x6hr.json b/advisories/unreviewed/2023/11/GHSA-x5qc-9crp-x6hr/GHSA-x5qc-9crp-x6hr.json index 5ad76f3a94b..510a236321f 100644 --- a/advisories/unreviewed/2023/11/GHSA-x5qc-9crp-x6hr/GHSA-x5qc-9crp-x6hr.json +++ b/advisories/unreviewed/2023/11/GHSA-x5qc-9crp-x6hr/GHSA-x5qc-9crp-x6hr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x5qc-9crp-x6hr", - "modified": "2024-09-05T15:33:30Z", + "modified": "2025-05-20T09:30:59Z", "published": "2023-11-06T15:30:32Z", "aliases": [ "CVE-2023-45161" @@ -26,6 +26,10 @@ { "type": "WEB", "url": "https://www.1e.com/trust-security-compliance/cve-info" + }, + { + "type": "WEB", + "url": "https://www.teamviewer.com/en/resources/trust-center/security-bulletins/1e-2023-2003" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/08/GHSA-62gh-q5g8-jv59/GHSA-62gh-q5g8-jv59.json b/advisories/unreviewed/2024/08/GHSA-62gh-q5g8-jv59/GHSA-62gh-q5g8-jv59.json index 1565ac744e0..3ab896719c8 100644 --- a/advisories/unreviewed/2024/08/GHSA-62gh-q5g8-jv59/GHSA-62gh-q5g8-jv59.json +++ b/advisories/unreviewed/2024/08/GHSA-62gh-q5g8-jv59/GHSA-62gh-q5g8-jv59.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-62gh-q5g8-jv59", - "modified": "2024-08-01T18:32:50Z", + "modified": "2025-05-20T09:30:59Z", "published": "2024-08-01T18:32:50Z", "aliases": [ "CVE-2024-7211" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://www.1e.com/trust-security-compliance/cve-info" + }, + { + "type": "WEB", + "url": "https://www.teamviewer.com/en/resources/trust-center/security-bulletins/1e-2024-2001" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/05/GHSA-f252-qh43-5v8p/GHSA-f252-qh43-5v8p.json b/advisories/unreviewed/2025/05/GHSA-f252-qh43-5v8p/GHSA-f252-qh43-5v8p.json new file mode 100644 index 00000000000..131d0cef7fa --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-f252-qh43-5v8p/GHSA-f252-qh43-5v8p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f252-qh43-5v8p", + "modified": "2025-05-20T09:31:00Z", + "published": "2025-05-20T09:31:00Z", + "aliases": [ + "CVE-2025-4951" + ], + "details": "Editions of Rapid7 AppSpider Pro before version 7.5.018 is vulnerable to a stored cross-site scripting vulnerability in the \"ScanName\" field.\nDespite the application preventing the inclusion of special characters within the \"ScanName\" field, this could be bypassed by modifying the configuration file directly.\n\nThis is fixed as of version 7.5.018", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4951" + }, + { + "type": "WEB", + "url": "https://docs.rapid7.com/release-notes/appspider/20250516" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-20T09:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-x48w-vp6x-g2px/GHSA-x48w-vp6x-g2px.json b/advisories/unreviewed/2025/05/GHSA-x48w-vp6x-g2px/GHSA-x48w-vp6x-g2px.json new file mode 100644 index 00000000000..71cce780a6a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-x48w-vp6x-g2px/GHSA-x48w-vp6x-g2px.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x48w-vp6x-g2px", + "modified": "2025-05-20T09:31:00Z", + "published": "2025-05-20T09:30:59Z", + "aliases": [ + "CVE-2024-5878" + ], + "details": "Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled SimpleLightbox JavaScript library (version 2.1.5) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5878" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/nextgen-gallery/trunk/static/Lightbox/simplelightbox/nextgen_simple_lightbox_init.js" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/simplelightbox/trunk/dist/simple-lightbox.js" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3157076/nextgen-gallery" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/bcbc8ce6-5eb7-4599-b844-72eb2ff3093c?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-20T08:15:32Z" + } +} \ No newline at end of file