Publish Advisories

GHSA-7377-5g8x-pp8m
GHSA-f2x4-v4rc-rwrp
GHSA-p7mr-jqmx-qq7x
GHSA-r4j5-63wj-7p3r
GHSA-rc73-pc24-f3rr
GHSA-xpw4-hqm8-rj97
GHSA-35m2-m3ch-fgh4
GHSA-56r4-vj3r-h3vv
GHSA-764p-g9xx-6qm8
GHSA-cch3-2vm3-v73j
GHSA-ch5j-3wwr-pjvh
This commit is contained in:
advisory-database[bot]
2025-04-20 03:52:50 +00:00
parent b25b863fc9
commit 79353a7cd6
11 changed files with 222 additions and 6 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7377-5g8x-pp8m",
"modified": "2022-05-14T03:50:03Z",
"modified": "2025-04-20T03:50:41Z",
"published": "2022-05-14T03:50:03Z",
"aliases": [
"CVE-2017-18006"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f2x4-v4rc-rwrp",
"modified": "2022-05-14T03:21:36Z",
"modified": "2025-04-20T03:50:40Z",
"published": "2022-05-14T03:21:36Z",
"aliases": [
"CVE-2017-17975"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p7mr-jqmx-qq7x",
"modified": "2022-05-13T01:44:33Z",
"modified": "2025-04-20T03:50:41Z",
"published": "2022-05-13T01:44:33Z",
"aliases": [
"CVE-2017-18001"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r4j5-63wj-7p3r",
"modified": "2022-05-14T02:48:49Z",
"modified": "2025-04-20T03:50:40Z",
"published": "2022-05-14T02:48:49Z",
"aliases": [
"CVE-2015-3302"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rc73-pc24-f3rr",
"modified": "2022-05-14T01:29:45Z",
"modified": "2025-04-20T03:50:41Z",
"published": "2022-05-14T01:29:45Z",
"aliases": [
"CVE-2017-17997"
@@ -27,6 +27,10 @@
"type": "WEB",
"url": "https://code.wireshark.org/review/#/c/25063"
},
{
"type": "WEB",
"url": "https://code.wireshark.org/review/gitweb?p=wireshark.git%3Ba=commit%3Bh=80a695869c9aef2fb473d9361da068022be7cb50"
},
{
"type": "WEB",
"url": "https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=80a695869c9aef2fb473d9361da068022be7cb50"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xpw4-hqm8-rj97",
"modified": "2022-05-13T01:30:27Z",
"modified": "2025-04-20T03:50:40Z",
"published": "2022-05-13T01:30:27Z",
"aliases": [
"CVE-2014-3630"
@@ -27,6 +27,14 @@
"type": "WEB",
"url": "https://groups.google.com/forum/#!topic/play-framework/WdbFvemsFDQ"
},
{
"type": "WEB",
"url": "https://groups.google.com/forum/#%21msg/play-framework/7uNX_ImTW08/AogWSjsTAyQJ"
},
{
"type": "WEB",
"url": "https://groups.google.com/forum/#%21topic/play-framework/WdbFvemsFDQ"
},
{
"type": "WEB",
"url": "https://infocon.org/cons/SyScan/SyScan%202015%20Singapore/SyScan%202015%20Singapore%20presentations/SyScan15%20David%20Jorm%20-%20Finding%20and%20exploiting%20novel%20flaws%20in%20Java%20software.pdf"
@@ -0,0 +1,40 @@
{
"schema_version": "1.4.0",
"id": "GHSA-35m2-m3ch-fgh4",
"modified": "2025-04-20T03:50:41Z",
"published": "2025-04-20T03:50:41Z",
"aliases": [
"CVE-2025-43920"
],
"details": "GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to execute arbitrary OS commands via shell metacharacters in an email Subject line.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43920"
},
{
"type": "WEB",
"url": "https://code.launchpad.net/~mailman-coders/mailman/2.1"
},
{
"type": "WEB",
"url": "https://github.com/0NYX-MY7H/CVE-2025-43920"
}
],
"database_specific": {
"cwe_ids": [
"CWE-78"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-20T01:15:45Z"
}
}
@@ -0,0 +1,40 @@
{
"schema_version": "1.4.0",
"id": "GHSA-56r4-vj3r-h3vv",
"modified": "2025-04-20T03:50:41Z",
"published": "2025-04-20T03:50:41Z",
"aliases": [
"CVE-2025-43919"
],
"details": "GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to read arbitrary files via ../ directory traversal at /mailman/private/mailman (aka the private archive authentication endpoint) via the username parameter.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43919"
},
{
"type": "WEB",
"url": "https://code.launchpad.net/~mailman-coders/mailman/2.1"
},
{
"type": "WEB",
"url": "https://github.com/0NYX-MY7H/CVE-2025-43919"
}
],
"database_specific": {
"cwe_ids": [
"CWE-24"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-20T01:15:45Z"
}
}
@@ -0,0 +1,40 @@
{
"schema_version": "1.4.0",
"id": "GHSA-764p-g9xx-6qm8",
"modified": "2025-04-20T03:50:41Z",
"published": "2025-04-20T03:50:41Z",
"aliases": [
"CVE-2025-43928"
],
"details": "In Infodraw Media Relay Service (MRS) 7.1.0.0, the MRS web server (on port 12654) allows reading arbitrary files via ../ directory traversal in the username field. Reading ServerParameters.xml may reveal administrator credentials in cleartext or with MD5 hashing.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43928"
},
{
"type": "WEB",
"url": "https://cfp.eh22.easterhegg.eu/eh22/talk/9UDXSE"
},
{
"type": "WEB",
"url": "https://mint-secure.de/path-traversal-vulnerability-in-surveillance-software"
}
],
"database_specific": {
"cwe_ids": [
"CWE-24"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-20T03:15:35Z"
}
}
@@ -0,0 +1,44 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cch3-2vm3-v73j",
"modified": "2025-04-20T03:50:41Z",
"published": "2025-04-20T03:50:41Z",
"aliases": [
"CVE-2025-43929"
],
"details": "open_actions.py in kitty before 0.41.0 does not ask for user confirmation before running a local executable file that may have been linked from an untrusted document (e.g., a document opened in KDE ghostwriter).",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43929"
},
{
"type": "WEB",
"url": "https://github.com/kovidgoyal/kitty/commit/ce5cfdd9caf44c538af800a07162e1f49bd53c35"
},
{
"type": "WEB",
"url": "https://ghostwriter.kde.org/documentation/#links"
},
{
"type": "WEB",
"url": "https://github.com/kovidgoyal/kitty/compare/v0.40.1...v0.41.0"
}
],
"database_specific": {
"cwe_ids": [
"CWE-346"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-20T03:15:36Z"
}
}
@@ -0,0 +1,40 @@
{
"schema_version": "1.4.0",
"id": "GHSA-ch5j-3wwr-pjvh",
"modified": "2025-04-20T03:50:41Z",
"published": "2025-04-20T03:50:41Z",
"aliases": [
"CVE-2025-43921"
],
"details": "GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to create lists via the /mailman/create endpoint.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43921"
},
{
"type": "WEB",
"url": "https://code.launchpad.net/~mailman-coders/mailman/2.1"
},
{
"type": "WEB",
"url": "https://github.com/0NYX-MY7H/CVE-2025-43921"
}
],
"database_specific": {
"cwe_ids": [
"CWE-863"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-20T01:15:46Z"
}
}