From 6c0bb60ef58798afad15960663dc1099773aae8d Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 19 May 2025 12:32:11 +0000 Subject: [PATCH] Publish Advisories GHSA-6w3v-8x64-r348 GHSA-256j-g634-v955 GHSA-6wpw-9mr8-qhv3 GHSA-7f35-3w2m-gw5h GHSA-fr77-hc38-f46p GHSA-g83m-h37w-pr8h GHSA-g8h9-5wwm-pj6c GHSA-j8r3-cghj-9jhg GHSA-qq3j-4f4f-9583 GHSA-rfhm-m5c8-xx3j --- .../GHSA-6w3v-8x64-r348.json | 8 ++- .../GHSA-256j-g634-v955.json | 52 +++++++++++++++++ .../GHSA-6wpw-9mr8-qhv3.json | 56 +++++++++++++++++++ .../GHSA-7f35-3w2m-gw5h.json | 56 +++++++++++++++++++ .../GHSA-fr77-hc38-f46p.json | 56 +++++++++++++++++++ .../GHSA-g83m-h37w-pr8h.json | 56 +++++++++++++++++++ .../GHSA-g8h9-5wwm-pj6c.json | 52 +++++++++++++++++ .../GHSA-j8r3-cghj-9jhg.json | 6 +- .../GHSA-qq3j-4f4f-9583.json | 40 +++++++++++++ .../GHSA-rfhm-m5c8-xx3j.json | 3 +- 10 files changed, 381 insertions(+), 4 deletions(-) create mode 100644 advisories/unreviewed/2025/05/GHSA-256j-g634-v955/GHSA-256j-g634-v955.json create mode 100644 advisories/unreviewed/2025/05/GHSA-6wpw-9mr8-qhv3/GHSA-6wpw-9mr8-qhv3.json create mode 100644 advisories/unreviewed/2025/05/GHSA-7f35-3w2m-gw5h/GHSA-7f35-3w2m-gw5h.json create mode 100644 advisories/unreviewed/2025/05/GHSA-fr77-hc38-f46p/GHSA-fr77-hc38-f46p.json create mode 100644 advisories/unreviewed/2025/05/GHSA-g83m-h37w-pr8h/GHSA-g83m-h37w-pr8h.json create mode 100644 advisories/unreviewed/2025/05/GHSA-g8h9-5wwm-pj6c/GHSA-g8h9-5wwm-pj6c.json create mode 100644 advisories/unreviewed/2025/05/GHSA-qq3j-4f4f-9583/GHSA-qq3j-4f4f-9583.json diff --git a/advisories/unreviewed/2024/04/GHSA-6w3v-8x64-r348/GHSA-6w3v-8x64-r348.json b/advisories/unreviewed/2024/04/GHSA-6w3v-8x64-r348/GHSA-6w3v-8x64-r348.json index 7d64f4a6656..ec41f03db80 100644 --- a/advisories/unreviewed/2024/04/GHSA-6w3v-8x64-r348/GHSA-6w3v-8x64-r348.json +++ b/advisories/unreviewed/2024/04/GHSA-6w3v-8x64-r348/GHSA-6w3v-8x64-r348.json @@ -1,16 +1,20 @@ { "schema_version": "1.4.0", "id": "GHSA-6w3v-8x64-r348", - "modified": "2024-05-16T21:31:56Z", + "modified": "2025-05-19T12:30:33Z", "published": "2024-04-12T15:37:22Z", "aliases": [ "CVE-2024-21610" ], - "details": "An Improper Handling of Exceptional Conditions vulnerability in the Class of Service daemon (cosd) of Juniper Networks Junos OS on MX Series allows an authenticated, network-based attacker with low privileges to cause a limited Denial of Service (DoS).\n\nIn a scaled subscriber scenario when specific low privileged commands, received over NETCONF, SSH or telnet, are handled by cosd on behalf of mgd, the respective child management daemon (mgd) processes will get stuck. In case of (Netconf over) SSH this leads to stuck SSH sessions, so that when the connection-limit for SSH is reached new sessions can't be established anymore. A similar behavior will be seen for telnet etc.\n\nStuck mgd processes can be monitored by executing the following command:\n\n  user@host> show system processes extensive | match mgd | match sbwait\n\nThis issue affects Juniper Networks Junos OS on MX Series:\nAll versions earlier than 20.4R3-S9;\n21.2 versions earlier than 21.2R3-S7;\n21.3 versions earlier than 21.3R3-S5;\n21.4 versions earlier than 21.4R3-S5;\n22.1 versions earlier than 22.1R3-S4;\n22.2 versions earlier than 22.2R3-S3;\n22.3 versions earlier than 22.3R3-S2;\n22.4 versions earlier than 22.4R3;\n23.2 versions earlier than 23.2R1-S2, 23.2R2.\n", + "details": "An Improper Handling of Exceptional Conditions vulnerability in the Class of Service daemon (cosd) of Juniper Networks Junos OS on MX Series allows an authenticated, network-based attacker with low privileges to cause a limited Denial of Service (DoS).\n\nIn a scaled subscriber scenario when specific low privileged commands, received over NETCONF, SSH or telnet, are handled by cosd on behalf of mgd, the respective child management daemon (mgd) processes will get stuck. In case of (Netconf over) SSH this leads to stuck SSH sessions, so that when the connection-limit for SSH is reached new sessions can't be established anymore. A similar behavior will be seen for telnet etc.\n\nStuck mgd processes can be monitored by executing the following command:\n\n  user@host> show system processes extensive | match mgd | match sbwait\n\nThis issue affects Juniper Networks Junos OS on MX Series:\nAll versions earlier than 20.4R3-S9;\n21.2 versions earlier than 21.2R3-S7;\n21.3 versions earlier than 21.3R3-S5;\n21.4 versions earlier than 21.4R3-S5;\n22.1 versions earlier than 22.1R3-S4;\n22.2 versions earlier than 22.2R3-S3;\n22.3 versions earlier than 22.3R3-S2;\n22.4 versions earlier than 22.4R3;\n23.2 versions earlier than 23.2R1-S2, 23.2R2.", "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" } ], "affected": [], diff --git a/advisories/unreviewed/2025/05/GHSA-256j-g634-v955/GHSA-256j-g634-v955.json b/advisories/unreviewed/2025/05/GHSA-256j-g634-v955/GHSA-256j-g634-v955.json new file mode 100644 index 00000000000..04ef08800fd --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-256j-g634-v955/GHSA-256j-g634-v955.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-256j-g634-v955", + "modified": "2025-05-19T12:30:33Z", + "published": "2025-05-19T12:30:33Z", + "aliases": [ + "CVE-2025-4928" + ], + "details": "A vulnerability was found in projectworlds Online Lawyer Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /save_lawyer_edit_profile.php. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Multiple parameters might be affected.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4928" + }, + { + "type": "WEB", + "url": "https://github.com/hhhanxx/attack/issues/8" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309490" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309490" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.579313" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T11:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-6wpw-9mr8-qhv3/GHSA-6wpw-9mr8-qhv3.json b/advisories/unreviewed/2025/05/GHSA-6wpw-9mr8-qhv3/GHSA-6wpw-9mr8-qhv3.json new file mode 100644 index 00000000000..2d05fb46c69 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-6wpw-9mr8-qhv3/GHSA-6wpw-9mr8-qhv3.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6wpw-9mr8-qhv3", + "modified": "2025-05-19T12:30:34Z", + "published": "2025-05-19T12:30:34Z", + "aliases": [ + "CVE-2025-4930" + ], + "details": "A vulnerability classified as critical has been found in Campcodes Online Shopping Portal 1.0. Affected is an unknown function of the file /my-cart.php. The manipulation of the argument billingaddress leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4930" + }, + { + "type": "WEB", + "url": "https://github.com/N1sa26/CVE/issues/2" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309492" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309492" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.579468" + }, + { + "type": "WEB", + "url": "https://www.campcodes.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T12:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7f35-3w2m-gw5h/GHSA-7f35-3w2m-gw5h.json b/advisories/unreviewed/2025/05/GHSA-7f35-3w2m-gw5h/GHSA-7f35-3w2m-gw5h.json new file mode 100644 index 00000000000..8ae47704c71 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7f35-3w2m-gw5h/GHSA-7f35-3w2m-gw5h.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7f35-3w2m-gw5h", + "modified": "2025-05-19T12:30:34Z", + "published": "2025-05-19T12:30:33Z", + "aliases": [ + "CVE-2025-4929" + ], + "details": "A vulnerability was found in Campcodes Online Shopping Portal 1.0. It has been rated as critical. This issue affects some unknown processing of the file /my-account.php. The manipulation of the argument Name leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4929" + }, + { + "type": "WEB", + "url": "https://github.com/N1sa26/CVE/issues/1" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309491" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309491" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.579467" + }, + { + "type": "WEB", + "url": "https://www.campcodes.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T11:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-fr77-hc38-f46p/GHSA-fr77-hc38-f46p.json b/advisories/unreviewed/2025/05/GHSA-fr77-hc38-f46p/GHSA-fr77-hc38-f46p.json new file mode 100644 index 00000000000..f967e64c935 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-fr77-hc38-f46p/GHSA-fr77-hc38-f46p.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fr77-hc38-f46p", + "modified": "2025-05-19T12:30:34Z", + "published": "2025-05-19T12:30:34Z", + "aliases": [ + "CVE-2025-4927" + ], + "details": "A vulnerability was found in PHPGurukul Online Marriage Registration System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/between-dates-application-report.php. The manipulation of the argument fromdate/todate leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4927" + }, + { + "type": "WEB", + "url": "https://github.com/sknadklasdls/CVE/issues/1" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309489" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309489" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.579300" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T10:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-g83m-h37w-pr8h/GHSA-g83m-h37w-pr8h.json b/advisories/unreviewed/2025/05/GHSA-g83m-h37w-pr8h/GHSA-g83m-h37w-pr8h.json new file mode 100644 index 00000000000..02e3bb5c1ee --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-g83m-h37w-pr8h/GHSA-g83m-h37w-pr8h.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g83m-h37w-pr8h", + "modified": "2025-05-19T12:30:33Z", + "published": "2025-05-19T12:30:33Z", + "aliases": [ + "CVE-2025-4926" + ], + "details": "A vulnerability was found in PHPGurukul Car Rental Project 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/post-avehical.php. The manipulation of the argument img1/img2/img3/img4/img5 leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4926" + }, + { + "type": "WEB", + "url": "https://github.com/6BXK6/cve/issues/4" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309488" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309488" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.579163" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T10:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-g8h9-5wwm-pj6c/GHSA-g8h9-5wwm-pj6c.json b/advisories/unreviewed/2025/05/GHSA-g8h9-5wwm-pj6c/GHSA-g8h9-5wwm-pj6c.json new file mode 100644 index 00000000000..8c63c0a1aaf --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-g8h9-5wwm-pj6c/GHSA-g8h9-5wwm-pj6c.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g8h9-5wwm-pj6c", + "modified": "2025-05-19T12:30:34Z", + "published": "2025-05-19T12:30:34Z", + "aliases": [ + "CVE-2025-4931" + ], + "details": "A vulnerability classified as critical was found in projectworlds Online Lawyer Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /user_registation.php. The manipulation of the argument email leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4931" + }, + { + "type": "WEB", + "url": "https://github.com/hhhanxx/attack/issues/11" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.309493" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.309493" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.579481" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T12:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-j8r3-cghj-9jhg/GHSA-j8r3-cghj-9jhg.json b/advisories/unreviewed/2025/05/GHSA-j8r3-cghj-9jhg/GHSA-j8r3-cghj-9jhg.json index 041e7586aec..13579703ad4 100644 --- a/advisories/unreviewed/2025/05/GHSA-j8r3-cghj-9jhg/GHSA-j8r3-cghj-9jhg.json +++ b/advisories/unreviewed/2025/05/GHSA-j8r3-cghj-9jhg/GHSA-j8r3-cghj-9jhg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j8r3-cghj-9jhg", - "modified": "2025-05-16T18:31:05Z", + "modified": "2025-05-19T12:30:33Z", "published": "2025-05-15T15:31:27Z", "aliases": [ "CVE-2025-4516" @@ -42,6 +42,10 @@ { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2025/05/16/4" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/05/19/1" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/05/GHSA-qq3j-4f4f-9583/GHSA-qq3j-4f4f-9583.json b/advisories/unreviewed/2025/05/GHSA-qq3j-4f4f-9583/GHSA-qq3j-4f4f-9583.json new file mode 100644 index 00000000000..0da67b0ce7d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-qq3j-4f4f-9583/GHSA-qq3j-4f4f-9583.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qq3j-4f4f-9583", + "modified": "2025-05-19T12:30:33Z", + "published": "2025-05-19T12:30:33Z", + "aliases": [ + "CVE-2025-2099" + ], + "details": "A vulnerability in the `preprocess_string()` function of the `transformers.testing_utils` module in huggingface/transformers version v4.48.3 allows for a Regular Expression Denial of Service (ReDoS) attack. The regular expression used to process code blocks in docstrings contains nested quantifiers, leading to exponential backtracking when processing input with a large number of newline characters. An attacker can exploit this by providing a specially crafted payload, causing high CPU usage and potential application downtime, effectively resulting in a Denial of Service (DoS) scenario.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2099" + }, + { + "type": "WEB", + "url": "https://github.com/huggingface/transformers/commit/8cb522b4190bd556ce51be04942720650b1a3e57" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/97b780f3-ffca-424f-ad5d-0e1c57a5bde4" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1333" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-19T12:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rfhm-m5c8-xx3j/GHSA-rfhm-m5c8-xx3j.json b/advisories/unreviewed/2025/05/GHSA-rfhm-m5c8-xx3j/GHSA-rfhm-m5c8-xx3j.json index dacc9c0fc1d..9cec0635160 100644 --- a/advisories/unreviewed/2025/05/GHSA-rfhm-m5c8-xx3j/GHSA-rfhm-m5c8-xx3j.json +++ b/advisories/unreviewed/2025/05/GHSA-rfhm-m5c8-xx3j/GHSA-rfhm-m5c8-xx3j.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-120" ], "severity": "HIGH", "github_reviewed": false,