From 6e049e9168017c1dfb7831a633e6370ba9ccd8ff Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 15 May 2025 03:33:27 +0000 Subject: [PATCH] Publish Advisories GHSA-gwr6-5fvh-8v7r GHSA-3mp3-6fg3-7hxj GHSA-45rh-35p3-x338 GHSA-j75p-7hp3-3p63 --- .../GHSA-gwr6-5fvh-8v7r.json | 6 ++- .../GHSA-3mp3-6fg3-7hxj.json | 14 +++++- .../GHSA-45rh-35p3-x338.json | 10 +++- .../GHSA-j75p-7hp3-3p63.json | 48 +++++++++++++++++++ 4 files changed, 75 insertions(+), 3 deletions(-) create mode 100644 advisories/unreviewed/2025/05/GHSA-j75p-7hp3-3p63/GHSA-j75p-7hp3-3p63.json diff --git a/advisories/unreviewed/2024/07/GHSA-gwr6-5fvh-8v7r/GHSA-gwr6-5fvh-8v7r.json b/advisories/unreviewed/2024/07/GHSA-gwr6-5fvh-8v7r/GHSA-gwr6-5fvh-8v7r.json index 9066e30eafc..271f4f1369f 100644 --- a/advisories/unreviewed/2024/07/GHSA-gwr6-5fvh-8v7r/GHSA-gwr6-5fvh-8v7r.json +++ b/advisories/unreviewed/2024/07/GHSA-gwr6-5fvh-8v7r/GHSA-gwr6-5fvh-8v7r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gwr6-5fvh-8v7r", - "modified": "2025-05-09T06:32:36Z", + "modified": "2025-05-15T03:31:28Z", "published": "2024-07-26T15:31:51Z", "aliases": [ "CVE-2024-7128" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:4427" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:4723" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-7128" diff --git a/advisories/unreviewed/2024/12/GHSA-3mp3-6fg3-7hxj/GHSA-3mp3-6fg3-7hxj.json b/advisories/unreviewed/2024/12/GHSA-3mp3-6fg3-7hxj/GHSA-3mp3-6fg3-7hxj.json index a09cb4dfe4a..8196a9b1fe7 100644 --- a/advisories/unreviewed/2024/12/GHSA-3mp3-6fg3-7hxj/GHSA-3mp3-6fg3-7hxj.json +++ b/advisories/unreviewed/2024/12/GHSA-3mp3-6fg3-7hxj/GHSA-3mp3-6fg3-7hxj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3mp3-6fg3-7hxj", - "modified": "2024-12-27T21:30:30Z", + "modified": "2025-05-15T03:31:28Z", "published": "2024-12-27T18:30:26Z", "aliases": [ "CVE-2024-12987" @@ -23,6 +23,18 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12987" }, + { + "type": "WEB", + "url": "https://fw.draytek.com.tw/Vigor2960/Firmware/v1.5.1.5/DrayTek_Vigor2960_V1.5.1.5_01release-note.pdf" + }, + { + "type": "WEB", + "url": "https://fw.draytek.com.tw/Vigor300B/Firmware/v1.5.1.5/DrayTek_Vigor300B_V1.5.1.5_01release-note.pdf" + }, + { + "type": "WEB", + "url": "https://fw.draytek.com.tw/Vigor3900/Firmware/v1.5.1.5/DrayTek_Vigor3900_V1.5.1.5_01release-note.pdf" + }, { "type": "WEB", "url": "https://netsecfish.notion.site/Command-Injection-in-apmcfgupload-endpoint-for-DrayTek-Gateway-Devices-1676b683e67c8040b7f1f0ffe29ce18f" diff --git a/advisories/unreviewed/2025/04/GHSA-45rh-35p3-x338/GHSA-45rh-35p3-x338.json b/advisories/unreviewed/2025/04/GHSA-45rh-35p3-x338/GHSA-45rh-35p3-x338.json index 96e59eafc55..d2f46babba5 100644 --- a/advisories/unreviewed/2025/04/GHSA-45rh-35p3-x338/GHSA-45rh-35p3-x338.json +++ b/advisories/unreviewed/2025/04/GHSA-45rh-35p3-x338/GHSA-45rh-35p3-x338.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-45rh-35p3-x338", - "modified": "2025-04-23T21:30:36Z", + "modified": "2025-05-15T03:31:28Z", "published": "2025-04-23T21:30:36Z", "aliases": [ "CVE-2025-46400" @@ -19,6 +19,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46400" }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2025-46400" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2362054" + }, { "type": "WEB", "url": "https://sourceforge.net/p/mcj/tickets/187" diff --git a/advisories/unreviewed/2025/05/GHSA-j75p-7hp3-3p63/GHSA-j75p-7hp3-3p63.json b/advisories/unreviewed/2025/05/GHSA-j75p-7hp3-3p63/GHSA-j75p-7hp3-3p63.json new file mode 100644 index 00000000000..9a9d3caa24f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-j75p-7hp3-3p63/GHSA-j75p-7hp3-3p63.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j75p-7hp3-3p63", + "modified": "2025-05-15T03:31:28Z", + "published": "2025-05-15T03:31:28Z", + "aliases": [ + "CVE-2025-4579" + ], + "details": "The WP Content Security Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the blocked-uri and effective-directive parameters in all versions up to, and including, 2.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4579" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wp-content-security-policy/tags/2.3/includes/WP_CSP.php#L597" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wp-content-security-policy/tags/2.3/includes/WP_CSP.php#L612" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/wp-content-security-policy/tags/2.3/includes/WP_CSP.php#L659" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/f3c4ba08-a9fa-439a-a887-b8c113f78e20?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-15T02:15:21Z" + } +} \ No newline at end of file