From 6e9794fbedd9cd43e7eea869bb23f10ae843b355 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 13 Feb 2025 09:32:55 +0000 Subject: [PATCH] Publish Advisories GHSA-42vr-8wv2-vg62 GHSA-4v4v-fcfx-x6mg GHSA-5p42-3p77-wc39 GHSA-6v5g-5362-mj6f GHSA-8572-xjmw-7fq3 GHSA-f3gr-2wrv-hwpx GHSA-fv2m-95rx-m47j GHSA-mf38-7xr2-g2q7 GHSA-p232-9vcm-fcxv GHSA-pmqm-wjf2-4fv5 GHSA-vq42-xjx3-xh4r GHSA-wx3f-pjjp-293h GHSA-x3v6-f5fr-4wwv --- .../GHSA-42vr-8wv2-vg62.json | 36 +++++++++++++ .../GHSA-4v4v-fcfx-x6mg.json | 40 ++++++++++++++ .../GHSA-5p42-3p77-wc39.json | 40 ++++++++++++++ .../GHSA-6v5g-5362-mj6f.json | 40 ++++++++++++++ .../GHSA-8572-xjmw-7fq3.json | 38 ++++++++++++++ .../GHSA-f3gr-2wrv-hwpx.json | 36 +++++++++++++ .../GHSA-fv2m-95rx-m47j.json | 40 ++++++++++++++ .../GHSA-mf38-7xr2-g2q7.json | 40 ++++++++++++++ .../GHSA-p232-9vcm-fcxv.json | 36 +++++++++++++ .../GHSA-pmqm-wjf2-4fv5.json | 52 +++++++++++++++++++ .../GHSA-vq42-xjx3-xh4r.json | 40 ++++++++++++++ .../GHSA-wx3f-pjjp-293h.json | 40 ++++++++++++++ .../GHSA-x3v6-f5fr-4wwv.json | 35 +++++++++++++ 13 files changed, 513 insertions(+) create mode 100644 advisories/unreviewed/2025/02/GHSA-42vr-8wv2-vg62/GHSA-42vr-8wv2-vg62.json create mode 100644 advisories/unreviewed/2025/02/GHSA-4v4v-fcfx-x6mg/GHSA-4v4v-fcfx-x6mg.json create mode 100644 advisories/unreviewed/2025/02/GHSA-5p42-3p77-wc39/GHSA-5p42-3p77-wc39.json create mode 100644 advisories/unreviewed/2025/02/GHSA-6v5g-5362-mj6f/GHSA-6v5g-5362-mj6f.json create mode 100644 advisories/unreviewed/2025/02/GHSA-8572-xjmw-7fq3/GHSA-8572-xjmw-7fq3.json create mode 100644 advisories/unreviewed/2025/02/GHSA-f3gr-2wrv-hwpx/GHSA-f3gr-2wrv-hwpx.json create mode 100644 advisories/unreviewed/2025/02/GHSA-fv2m-95rx-m47j/GHSA-fv2m-95rx-m47j.json create mode 100644 advisories/unreviewed/2025/02/GHSA-mf38-7xr2-g2q7/GHSA-mf38-7xr2-g2q7.json create mode 100644 advisories/unreviewed/2025/02/GHSA-p232-9vcm-fcxv/GHSA-p232-9vcm-fcxv.json create mode 100644 advisories/unreviewed/2025/02/GHSA-pmqm-wjf2-4fv5/GHSA-pmqm-wjf2-4fv5.json create mode 100644 advisories/unreviewed/2025/02/GHSA-vq42-xjx3-xh4r/GHSA-vq42-xjx3-xh4r.json create mode 100644 advisories/unreviewed/2025/02/GHSA-wx3f-pjjp-293h/GHSA-wx3f-pjjp-293h.json create mode 100644 advisories/unreviewed/2025/02/GHSA-x3v6-f5fr-4wwv/GHSA-x3v6-f5fr-4wwv.json diff --git a/advisories/unreviewed/2025/02/GHSA-42vr-8wv2-vg62/GHSA-42vr-8wv2-vg62.json b/advisories/unreviewed/2025/02/GHSA-42vr-8wv2-vg62/GHSA-42vr-8wv2-vg62.json new file mode 100644 index 00000000000..c43215f8293 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-42vr-8wv2-vg62/GHSA-42vr-8wv2-vg62.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-42vr-8wv2-vg62", + "modified": "2025-02-13T09:31:26Z", + "published": "2025-02-13T09:31:26Z", + "aliases": [ + "CVE-2024-47265" + ], + "details": "Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in encrypted share umount functionality in Synology Active Backup for Business before 2.7.1-13234, 2.7.1-23234 and 2.7.1-3234 allows remote authenticated users to write specific files via unspecified vectors.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47265" + }, + { + "type": "WEB", + "url": "https://www.synology.com/en-global/security/advisory/Synology_SA_25_02" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-13T07:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-4v4v-fcfx-x6mg/GHSA-4v4v-fcfx-x6mg.json b/advisories/unreviewed/2025/02/GHSA-4v4v-fcfx-x6mg/GHSA-4v4v-fcfx-x6mg.json new file mode 100644 index 00000000000..d1cbed3ee83 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-4v4v-fcfx-x6mg/GHSA-4v4v-fcfx-x6mg.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4v4v-fcfx-x6mg", + "modified": "2025-02-13T09:31:26Z", + "published": "2025-02-13T09:31:26Z", + "aliases": [ + "CVE-2025-0327" + ], + "details": "CWE-269: Improper Privilege Management vulnerability exists for two services (of which one managing audit\ntrail data and the other acting as server managing client request) that could cause a loss of Confidentiality,\nIntegrity and Availability of engineering workstation when an attacker with standard privilege modifies the\nexecutable path of the windows services. To be exploited, services need to be restarted.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0327" + }, + { + "type": "WEB", + "url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2025-042-03&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2025-042-03.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-13T07:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-5p42-3p77-wc39/GHSA-5p42-3p77-wc39.json b/advisories/unreviewed/2025/02/GHSA-5p42-3p77-wc39/GHSA-5p42-3p77-wc39.json new file mode 100644 index 00000000000..52ed831f74b --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-5p42-3p77-wc39/GHSA-5p42-3p77-wc39.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5p42-3p77-wc39", + "modified": "2025-02-13T09:31:26Z", + "published": "2025-02-13T09:31:26Z", + "aliases": [ + "CVE-2025-0816" + ], + "details": "CWE-20: Improper Input Validation vulnerability exists that could cause Denial-of-Service of the\nproduct when malicious IPV6 packets are sent to the device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0816" + }, + { + "type": "WEB", + "url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2025-042-04&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2025-042-04.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-13T07:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-6v5g-5362-mj6f/GHSA-6v5g-5362-mj6f.json b/advisories/unreviewed/2025/02/GHSA-6v5g-5362-mj6f/GHSA-6v5g-5362-mj6f.json new file mode 100644 index 00000000000..5560630d842 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-6v5g-5362-mj6f/GHSA-6v5g-5362-mj6f.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6v5g-5362-mj6f", + "modified": "2025-02-13T09:31:25Z", + "published": "2025-02-13T09:31:25Z", + "aliases": [ + "CVE-2024-13346" + ], + "details": "The Avada | Website Builder For WordPress & WooCommerce theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 7.11.13. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13346" + }, + { + "type": "WEB", + "url": "https://avada.com/documentation/avada-changelog" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/1f2f390b-332b-452c-9fe7-ccd1a45390dd?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-13T07:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-8572-xjmw-7fq3/GHSA-8572-xjmw-7fq3.json b/advisories/unreviewed/2025/02/GHSA-8572-xjmw-7fq3/GHSA-8572-xjmw-7fq3.json new file mode 100644 index 00000000000..2180f41da38 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-8572-xjmw-7fq3/GHSA-8572-xjmw-7fq3.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8572-xjmw-7fq3", + "modified": "2025-02-13T09:31:26Z", + "published": "2025-02-13T09:31:26Z", + "aliases": [ + "CVE-2024-3303" + ], + "details": "An issue was discovered in GitLab EE affecting all versions starting from 16.0 prior to 17.6.5, starting from 17.7 prior to 17.7.4, and starting from 17.8 prior to 17.8.2, which allows an attacker to exfiltrate contents of a private issue using prompt injection.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3303" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2418620" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/454460" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-13T09:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-f3gr-2wrv-hwpx/GHSA-f3gr-2wrv-hwpx.json b/advisories/unreviewed/2025/02/GHSA-f3gr-2wrv-hwpx/GHSA-f3gr-2wrv-hwpx.json new file mode 100644 index 00000000000..953a69e2796 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-f3gr-2wrv-hwpx/GHSA-f3gr-2wrv-hwpx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f3gr-2wrv-hwpx", + "modified": "2025-02-13T09:31:25Z", + "published": "2025-02-13T09:31:25Z", + "aliases": [ + "CVE-2024-47264" + ], + "details": "Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in agent-related functionality in Synology Active Backup for Business before 2.7.1-13234, 2.7.1-23234 and 2.7.1-3234 allows remote authenticated users with administrator privileges to delete arbitrary files via unspecified vectors.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47264" + }, + { + "type": "WEB", + "url": "https://www.synology.com/en-global/security/advisory/Synology_SA_25_02" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-13T07:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-fv2m-95rx-m47j/GHSA-fv2m-95rx-m47j.json b/advisories/unreviewed/2025/02/GHSA-fv2m-95rx-m47j/GHSA-fv2m-95rx-m47j.json new file mode 100644 index 00000000000..d2b5f549604 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-fv2m-95rx-m47j/GHSA-fv2m-95rx-m47j.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fv2m-95rx-m47j", + "modified": "2025-02-13T09:31:25Z", + "published": "2025-02-13T09:31:25Z", + "aliases": [ + "CVE-2024-13345" + ], + "details": "The Avada Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.11.13. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13345" + }, + { + "type": "WEB", + "url": "https://avada.com/documentation/avada-changelog" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/94f6aab3-49a7-4837-a424-e40e483f3f68?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-13T07:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-mf38-7xr2-g2q7/GHSA-mf38-7xr2-g2q7.json b/advisories/unreviewed/2025/02/GHSA-mf38-7xr2-g2q7/GHSA-mf38-7xr2-g2q7.json new file mode 100644 index 00000000000..8bda4ab569e --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-mf38-7xr2-g2q7/GHSA-mf38-7xr2-g2q7.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mf38-7xr2-g2q7", + "modified": "2025-02-13T09:31:26Z", + "published": "2025-02-13T09:31:26Z", + "aliases": [ + "CVE-2025-0814" + ], + "details": "CWE-20: Improper Input Validation vulnerability exists that could cause Denial-of-Service of the network\nservices running on the product when malicious IEC61850-MMS packets are sent to the device. The core\nfunctionality of the breaker remains intact during the attack.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0814" + }, + { + "type": "WEB", + "url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2025-042-04&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2025-042-04.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-13T07:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-p232-9vcm-fcxv/GHSA-p232-9vcm-fcxv.json b/advisories/unreviewed/2025/02/GHSA-p232-9vcm-fcxv/GHSA-p232-9vcm-fcxv.json new file mode 100644 index 00000000000..546d9252e1b --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-p232-9vcm-fcxv/GHSA-p232-9vcm-fcxv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p232-9vcm-fcxv", + "modified": "2025-02-13T09:31:25Z", + "published": "2025-02-13T09:31:25Z", + "aliases": [ + "CVE-2024-47266" + ], + "details": "Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in share file list functionality in Synology Active Backup for Business before 2.7.1-13234, 2.7.1-23234 and 2.7.1-3234 allows remote authenticated users with administrator privileges to read specific files containing non-sensitive information via unspecified vectors.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47266" + }, + { + "type": "WEB", + "url": "https://www.synology.com/en-global/security/advisory/Synology_SA_25_02" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-13T07:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-pmqm-wjf2-4fv5/GHSA-pmqm-wjf2-4fv5.json b/advisories/unreviewed/2025/02/GHSA-pmqm-wjf2-4fv5/GHSA-pmqm-wjf2-4fv5.json new file mode 100644 index 00000000000..0ff642c7bcd --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-pmqm-wjf2-4fv5/GHSA-pmqm-wjf2-4fv5.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pmqm-wjf2-4fv5", + "modified": "2025-02-13T09:31:26Z", + "published": "2025-02-13T09:31:26Z", + "aliases": [ + "CVE-2024-13639" + ], + "details": "The Read More & Accordion plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the expmDeleteData() function in all versions up to, and including, 3.4.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary 'read more' posts.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13639" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/expand-maker/trunk/files/ReadMoreAdminPost.php#L9" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/expand-maker/trunk/files/ReadMoreAdminPost.php#L98" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3239533" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/expand-maker" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/65849267-8bb5-48fd-b95e-e89a1e744fe0?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-13T09:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-vq42-xjx3-xh4r/GHSA-vq42-xjx3-xh4r.json b/advisories/unreviewed/2025/02/GHSA-vq42-xjx3-xh4r/GHSA-vq42-xjx3-xh4r.json new file mode 100644 index 00000000000..e4de2e9df13 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-vq42-xjx3-xh4r/GHSA-vq42-xjx3-xh4r.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vq42-xjx3-xh4r", + "modified": "2025-02-13T09:31:26Z", + "published": "2025-02-13T09:31:26Z", + "aliases": [ + "CVE-2025-0815" + ], + "details": "CWE-20: Improper Input Validation vulnerability exists that could cause Denial-of-Service of the\nproduct when malicious ICMPV6 packets are sent to the device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0815" + }, + { + "type": "WEB", + "url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2025-042-04&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2025-042-04.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-13T07:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-wx3f-pjjp-293h/GHSA-wx3f-pjjp-293h.json b/advisories/unreviewed/2025/02/GHSA-wx3f-pjjp-293h/GHSA-wx3f-pjjp-293h.json new file mode 100644 index 00000000000..34ce4ed0987 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-wx3f-pjjp-293h/GHSA-wx3f-pjjp-293h.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wx3f-pjjp-293h", + "modified": "2025-02-13T09:31:26Z", + "published": "2025-02-13T09:31:26Z", + "aliases": [ + "CVE-2025-0661" + ], + "details": "The DethemeKit For Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.36 via the duplicate_post() function due to insufficient restrictions on which posts can be duplicated. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract data from password protected, private, draft, or scheduled posts that they should not have access to by duplicating the post.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0661" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3236114/dethemekit-for-elementor/trunk/admin/includes/dep/admin-helper.php" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/1e2c937c-1ff8-4bcc-913b-83bade37d754?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-639" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-13T07:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-x3v6-f5fr-4wwv/GHSA-x3v6-f5fr-4wwv.json b/advisories/unreviewed/2025/02/GHSA-x3v6-f5fr-4wwv/GHSA-x3v6-f5fr-4wwv.json new file mode 100644 index 00000000000..8355191aeaf --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-x3v6-f5fr-4wwv/GHSA-x3v6-f5fr-4wwv.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x3v6-f5fr-4wwv", + "modified": "2025-02-13T09:31:26Z", + "published": "2025-02-13T09:31:26Z", + "aliases": [ + "CVE-2024-46910" + ], + "details": "An authenticated user can perform XSS and potentially impersonate another user.\n\nThis issue affects Apache Atlas versions 2.3.0 and earlier.\n\nUsers are recommended to upgrade to version 2.4.0, which fixes the issue.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46910" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/sqzp34l4cdk21zoq5g31qlsvr7jvb1fy" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/02/12/2" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-80" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-13T09:15:09Z" + } +} \ No newline at end of file