diff --git a/advisories/unreviewed/2022/05/GHSA-22j7-69m5-2pqh/GHSA-22j7-69m5-2pqh.json b/advisories/unreviewed/2022/05/GHSA-22j7-69m5-2pqh/GHSA-22j7-69m5-2pqh.json index c231017ed9f..8c6d5dd7ada 100644 --- a/advisories/unreviewed/2022/05/GHSA-22j7-69m5-2pqh/GHSA-22j7-69m5-2pqh.json +++ b/advisories/unreviewed/2022/05/GHSA-22j7-69m5-2pqh/GHSA-22j7-69m5-2pqh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-22j7-69m5-2pqh", - "modified": "2022-05-14T03:35:51Z", + "modified": "2025-01-28T15:31:54Z", "published": "2022-05-14T03:35:51Z", "aliases": [ "CVE-2018-2380" diff --git a/advisories/unreviewed/2024/07/GHSA-8f6q-mph6-g8fx/GHSA-8f6q-mph6-g8fx.json b/advisories/unreviewed/2024/07/GHSA-8f6q-mph6-g8fx/GHSA-8f6q-mph6-g8fx.json index 6e153da56bd..ccfc81614ec 100644 --- a/advisories/unreviewed/2024/07/GHSA-8f6q-mph6-g8fx/GHSA-8f6q-mph6-g8fx.json +++ b/advisories/unreviewed/2024/07/GHSA-8f6q-mph6-g8fx/GHSA-8f6q-mph6-g8fx.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-276", "CWE-346" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2025/01/GHSA-2qww-mx2p-2v4m/GHSA-2qww-mx2p-2v4m.json b/advisories/unreviewed/2025/01/GHSA-2qww-mx2p-2v4m/GHSA-2qww-mx2p-2v4m.json index 0939f83be3c..23c335cff07 100644 --- a/advisories/unreviewed/2025/01/GHSA-2qww-mx2p-2v4m/GHSA-2qww-mx2p-2v4m.json +++ b/advisories/unreviewed/2025/01/GHSA-2qww-mx2p-2v4m/GHSA-2qww-mx2p-2v4m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2qww-mx2p-2v4m", - "modified": "2025-01-28T00:32:13Z", + "modified": "2025-01-28T15:31:56Z", "published": "2025-01-28T00:32:13Z", "aliases": [ "CVE-2024-54507" ], "details": "A type confusion issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.2, iOS 18.2 and iPadOS 18.2. An attacker with user privileges may be able to read kernel memory.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:12Z" diff --git a/advisories/unreviewed/2025/01/GHSA-46f6-cwr6-vh3q/GHSA-46f6-cwr6-vh3q.json b/advisories/unreviewed/2025/01/GHSA-46f6-cwr6-vh3q/GHSA-46f6-cwr6-vh3q.json index 29ca490fe81..63d9bfd0a6c 100644 --- a/advisories/unreviewed/2025/01/GHSA-46f6-cwr6-vh3q/GHSA-46f6-cwr6-vh3q.json +++ b/advisories/unreviewed/2025/01/GHSA-46f6-cwr6-vh3q/GHSA-46f6-cwr6-vh3q.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-46f6-cwr6-vh3q", - "modified": "2025-01-28T00:32:13Z", + "modified": "2025-01-28T15:31:56Z", "published": "2025-01-28T00:32:13Z", "aliases": [ "CVE-2024-54478" ], "details": "An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iPadOS 17.7.4, visionOS 2.2, tvOS 18.2, watchOS 11.2, iOS 18.2 and iPadOS 18.2, macOS Sonoma 14.7.2, macOS Sequoia 15.2. Processing maliciously crafted web content may lead to an unexpected process crash.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:12Z" diff --git a/advisories/unreviewed/2025/01/GHSA-5h7w-p832-4g53/GHSA-5h7w-p832-4g53.json b/advisories/unreviewed/2025/01/GHSA-5h7w-p832-4g53/GHSA-5h7w-p832-4g53.json index af70e14c0a7..06f690bbba9 100644 --- a/advisories/unreviewed/2025/01/GHSA-5h7w-p832-4g53/GHSA-5h7w-p832-4g53.json +++ b/advisories/unreviewed/2025/01/GHSA-5h7w-p832-4g53/GHSA-5h7w-p832-4g53.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5h7w-p832-4g53", - "modified": "2025-01-28T00:32:13Z", + "modified": "2025-01-28T15:31:56Z", "published": "2025-01-28T00:32:13Z", "aliases": [ "CVE-2024-54519" ], "details": "The issue was resolved by sanitizing logging. This issue is fixed in macOS Sonoma 14.7.2, macOS Sequoia 15.2. An app may be able to read sensitive location information.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -25,7 +30,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:13Z" diff --git a/advisories/unreviewed/2025/01/GHSA-75fm-2jm9-p338/GHSA-75fm-2jm9-p338.json b/advisories/unreviewed/2025/01/GHSA-75fm-2jm9-p338/GHSA-75fm-2jm9-p338.json new file mode 100644 index 00000000000..b7e75174d4a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-75fm-2jm9-p338/GHSA-75fm-2jm9-p338.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-75fm-2jm9-p338", + "modified": "2025-01-28T15:31:57Z", + "published": "2025-01-28T15:31:57Z", + "aliases": [ + "CVE-2024-7881" + ], + "details": "An unprivileged context can trigger a data\nmemory-dependent prefetch engine to fetch the contents of a privileged location\nand consume those contents as an address that is also dereferenced.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-7881" + }, + { + "type": "WEB", + "url": "https://developer.arm.com/Arm%20Security%20Center/Arm%20CPU%20Vulnerability%20CVE-2024-7881" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-28T15:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-7843-77v9-hw36/GHSA-7843-77v9-hw36.json b/advisories/unreviewed/2025/01/GHSA-7843-77v9-hw36/GHSA-7843-77v9-hw36.json index f6bb018f8c5..5551af58743 100644 --- a/advisories/unreviewed/2025/01/GHSA-7843-77v9-hw36/GHSA-7843-77v9-hw36.json +++ b/advisories/unreviewed/2025/01/GHSA-7843-77v9-hw36/GHSA-7843-77v9-hw36.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7843-77v9-hw36", - "modified": "2025-01-28T00:32:13Z", + "modified": "2025-01-28T15:31:56Z", "published": "2025-01-28T00:32:13Z", "aliases": [ "CVE-2024-54523" ], "details": "The issue was addressed with improved bounds checks. This issue is fixed in macOS Sequoia 15.2, watchOS 11.2, tvOS 18.2, iOS 18.2 and iPadOS 18.2. An app may be able to corrupt coprocessor memory.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -33,7 +38,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:13Z" diff --git a/advisories/unreviewed/2025/01/GHSA-826g-p4h4-g7x3/GHSA-826g-p4h4-g7x3.json b/advisories/unreviewed/2025/01/GHSA-826g-p4h4-g7x3/GHSA-826g-p4h4-g7x3.json index e4d4b68c5b0..d5c519af5d1 100644 --- a/advisories/unreviewed/2025/01/GHSA-826g-p4h4-g7x3/GHSA-826g-p4h4-g7x3.json +++ b/advisories/unreviewed/2025/01/GHSA-826g-p4h4-g7x3/GHSA-826g-p4h4-g7x3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-826g-p4h4-g7x3", - "modified": "2025-01-28T00:32:14Z", + "modified": "2025-01-28T15:31:56Z", "published": "2025-01-28T00:32:14Z", "aliases": [ "CVE-2025-24151" ], "details": "The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.7.3, macOS Sequoia 15.3, macOS Sonoma 14.7.3. An app may be able to cause unexpected system termination or corrupt kernel memory.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -29,7 +34,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:19Z" diff --git a/advisories/unreviewed/2025/01/GHSA-8m2r-x2m2-3wmw/GHSA-8m2r-x2m2-3wmw.json b/advisories/unreviewed/2025/01/GHSA-8m2r-x2m2-3wmw/GHSA-8m2r-x2m2-3wmw.json new file mode 100644 index 00000000000..6e220e62a70 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-8m2r-x2m2-3wmw/GHSA-8m2r-x2m2-3wmw.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8m2r-x2m2-3wmw", + "modified": "2025-01-28T15:31:57Z", + "published": "2025-01-28T15:31:57Z", + "aliases": [ + "CVE-2024-11954" + ], + "details": "A vulnerability classified as problematic was found in Pimcore 11.4.2. Affected by this vulnerability is an unknown functionality of the component Search Document. The manipulation leads to basic cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "WEB", + "url": "https://github.com/pimcore/pimcore/security/advisories/GHSA-xr3m-6gq6-22cg" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11954" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.293905" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.293905" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.451774" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-28T14:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-8m8m-98c9-vw7q/GHSA-8m8m-98c9-vw7q.json b/advisories/unreviewed/2025/01/GHSA-8m8m-98c9-vw7q/GHSA-8m8m-98c9-vw7q.json new file mode 100644 index 00000000000..221fa8df6f9 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-8m8m-98c9-vw7q/GHSA-8m8m-98c9-vw7q.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8m8m-98c9-vw7q", + "modified": "2025-01-28T15:31:57Z", + "published": "2025-01-28T15:31:57Z", + "aliases": [ + "CVE-2024-11956" + ], + "details": "A vulnerability, which was classified as critical, has been found in Pimcore customer-data-framework up to 4.2.0. Affected by this issue is some unknown functionality of the file /admin/customermanagementframework/customers/list. The manipulation of the argument filterDefinition/filter leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 4.2.1 is able to address this issue. It is recommended to upgrade the affected component.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "WEB", + "url": "https://github.com/pimcore/pimcore/security/advisories/GHSA-q53r-9hh9-w277" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-11956" + }, + { + "type": "WEB", + "url": "https://github.com/pimcore/customer-data-framework/releases/tag/v4.2.1" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.293906" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.293906" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.451863" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-28T14:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-95qw-rmjg-8mx8/GHSA-95qw-rmjg-8mx8.json b/advisories/unreviewed/2025/01/GHSA-95qw-rmjg-8mx8/GHSA-95qw-rmjg-8mx8.json index 8f41c1d8955..1ef13fb47cc 100644 --- a/advisories/unreviewed/2025/01/GHSA-95qw-rmjg-8mx8/GHSA-95qw-rmjg-8mx8.json +++ b/advisories/unreviewed/2025/01/GHSA-95qw-rmjg-8mx8/GHSA-95qw-rmjg-8mx8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-95qw-rmjg-8mx8", - "modified": "2025-01-28T00:32:13Z", + "modified": "2025-01-28T15:31:56Z", "published": "2025-01-28T00:32:13Z", "aliases": [ "CVE-2024-54518" ], "details": "The issue was addressed with improved bounds checks. This issue is fixed in macOS Sequoia 15.2, watchOS 11.2, tvOS 18.2, iOS 18.2 and iPadOS 18.2. An app may be able to corrupt coprocessor memory.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:13Z" diff --git a/advisories/unreviewed/2025/01/GHSA-ccj6-hxrm-3g5p/GHSA-ccj6-hxrm-3g5p.json b/advisories/unreviewed/2025/01/GHSA-ccj6-hxrm-3g5p/GHSA-ccj6-hxrm-3g5p.json index 6eedf7ed987..9b06138d47a 100644 --- a/advisories/unreviewed/2025/01/GHSA-ccj6-hxrm-3g5p/GHSA-ccj6-hxrm-3g5p.json +++ b/advisories/unreviewed/2025/01/GHSA-ccj6-hxrm-3g5p/GHSA-ccj6-hxrm-3g5p.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-ccj6-hxrm-3g5p", - "modified": "2025-01-28T00:32:14Z", + "modified": "2025-01-28T15:31:56Z", "published": "2025-01-28T00:32:14Z", "aliases": [ "CVE-2025-24130" ], "details": "The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.3, macOS Sequoia 15.3, macOS Sonoma 14.7.3. An app may be able to modify protected parts of the file system.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -29,7 +34,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:17Z" diff --git a/advisories/unreviewed/2025/01/GHSA-ggjg-gjpc-93cx/GHSA-ggjg-gjpc-93cx.json b/advisories/unreviewed/2025/01/GHSA-ggjg-gjpc-93cx/GHSA-ggjg-gjpc-93cx.json index d00229f6ff2..aacc1722480 100644 --- a/advisories/unreviewed/2025/01/GHSA-ggjg-gjpc-93cx/GHSA-ggjg-gjpc-93cx.json +++ b/advisories/unreviewed/2025/01/GHSA-ggjg-gjpc-93cx/GHSA-ggjg-gjpc-93cx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-ggjg-gjpc-93cx", - "modified": "2025-01-28T00:32:15Z", + "modified": "2025-01-28T15:31:56Z", "published": "2025-01-28T00:32:14Z", "aliases": [ "CVE-2025-24146" ], "details": "This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Ventura 13.7.3, macOS Sequoia 15.3, macOS Sonoma 14.7.3. Deleting a conversation in Messages may expose user contact information in system logging.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-203" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:19Z" diff --git a/advisories/unreviewed/2025/01/GHSA-mh68-7cw5-7m9v/GHSA-mh68-7cw5-7m9v.json b/advisories/unreviewed/2025/01/GHSA-mh68-7cw5-7m9v/GHSA-mh68-7cw5-7m9v.json index 61a63e1f210..7c3760cd016 100644 --- a/advisories/unreviewed/2025/01/GHSA-mh68-7cw5-7m9v/GHSA-mh68-7cw5-7m9v.json +++ b/advisories/unreviewed/2025/01/GHSA-mh68-7cw5-7m9v/GHSA-mh68-7cw5-7m9v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mh68-7cw5-7m9v", - "modified": "2025-01-28T00:32:14Z", + "modified": "2025-01-28T15:31:56Z", "published": "2025-01-28T00:32:14Z", "aliases": [ "CVE-2025-24126" ], "details": "An input validation issue was addressed. This issue is fixed in visionOS 2.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3. An attacker on the local network may be able to cause unexpected system termination or corrupt process memory.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -37,7 +42,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:17Z" diff --git a/advisories/unreviewed/2025/01/GHSA-mrx2-mvwr-fg6v/GHSA-mrx2-mvwr-fg6v.json b/advisories/unreviewed/2025/01/GHSA-mrx2-mvwr-fg6v/GHSA-mrx2-mvwr-fg6v.json index 90fd9e236c2..ce2462b7e33 100644 --- a/advisories/unreviewed/2025/01/GHSA-mrx2-mvwr-fg6v/GHSA-mrx2-mvwr-fg6v.json +++ b/advisories/unreviewed/2025/01/GHSA-mrx2-mvwr-fg6v/GHSA-mrx2-mvwr-fg6v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mrx2-mvwr-fg6v", - "modified": "2025-01-24T00:31:46Z", + "modified": "2025-01-28T15:31:55Z", "published": "2025-01-24T00:31:46Z", "aliases": [ "CVE-2024-55195" ], "details": "An allocation-size-too-big bug in the component /imagebuf.cpp of OpenImageIO v3.1.0.0dev may cause a Denial of Service (DoS) when the program to requests to allocate too much space.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-770" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-23T22:15:14Z" diff --git a/advisories/unreviewed/2025/01/GHSA-mx5v-hjgf-32j4/GHSA-mx5v-hjgf-32j4.json b/advisories/unreviewed/2025/01/GHSA-mx5v-hjgf-32j4/GHSA-mx5v-hjgf-32j4.json index ad708408480..3bc3710a62b 100644 --- a/advisories/unreviewed/2025/01/GHSA-mx5v-hjgf-32j4/GHSA-mx5v-hjgf-32j4.json +++ b/advisories/unreviewed/2025/01/GHSA-mx5v-hjgf-32j4/GHSA-mx5v-hjgf-32j4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mx5v-hjgf-32j4", - "modified": "2025-01-28T00:32:14Z", + "modified": "2025-01-28T15:31:56Z", "published": "2025-01-28T00:32:14Z", "aliases": [ "CVE-2025-24102" ], "details": "The issue was addressed with improved checks. This issue is fixed in iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. An app may be able to determine a user’s current location.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -33,7 +38,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:15Z" diff --git a/advisories/unreviewed/2025/01/GHSA-p953-3j66-hg45/GHSA-p953-3j66-hg45.json b/advisories/unreviewed/2025/01/GHSA-p953-3j66-hg45/GHSA-p953-3j66-hg45.json index 365114cbc88..a612934c6cb 100644 --- a/advisories/unreviewed/2025/01/GHSA-p953-3j66-hg45/GHSA-p953-3j66-hg45.json +++ b/advisories/unreviewed/2025/01/GHSA-p953-3j66-hg45/GHSA-p953-3j66-hg45.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p953-3j66-hg45", - "modified": "2025-01-28T09:32:34Z", + "modified": "2025-01-28T15:31:56Z", "published": "2025-01-28T09:32:34Z", "aliases": [ "CVE-2024-23953" ], "details": "Use of Arrays.equals() in LlapSignerImpl in Apache Hive to compare message signatures allows attacker to forge a valid signature for an arbitrary message byte by byte. The attacker should be an authorized user of the product to perform this attack. Users are recommended to upgrade to version 4.0.0, which fixes this issue.\n\nThe problem occurs when an application doesn’t use a constant-time algorithm for validating a signature. The method Arrays.equals() returns false right away when it sees that one of the input’s bytes are different. It means that the comparison time depends on the contents of the arrays. This little thing may allow an attacker to forge a valid signature for an arbitrary message byte by byte. So it might allow malicious users to submit splits/work with selected signatures to LLAP without running as a privileged user, potentially leading to DDoS attack.\n\nMore details in the reference section.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -41,9 +46,10 @@ ], "database_specific": { "cwe_ids": [ - "CWE-208" + "CWE-208", + "CWE-290" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-28T09:15:09Z" diff --git a/advisories/unreviewed/2025/01/GHSA-rr66-34m4-m7ww/GHSA-rr66-34m4-m7ww.json b/advisories/unreviewed/2025/01/GHSA-rr66-34m4-m7ww/GHSA-rr66-34m4-m7ww.json index a867eca3743..c0749088a5b 100644 --- a/advisories/unreviewed/2025/01/GHSA-rr66-34m4-m7ww/GHSA-rr66-34m4-m7ww.json +++ b/advisories/unreviewed/2025/01/GHSA-rr66-34m4-m7ww/GHSA-rr66-34m4-m7ww.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rr66-34m4-m7ww", - "modified": "2025-01-28T00:32:13Z", + "modified": "2025-01-28T15:31:56Z", "published": "2025-01-28T00:32:13Z", "aliases": [ "CVE-2024-54539" ], "details": "This issue was addressed through improved state management. This issue is fixed in macOS Sonoma 14.7.2, macOS Sequoia 15.2, macOS Ventura 13.7.2. An app may be able to capture keyboard events from the lock screen.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -29,7 +34,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:14Z" diff --git a/advisories/unreviewed/2025/01/GHSA-wxw4-9hr6-3vw4/GHSA-wxw4-9hr6-3vw4.json b/advisories/unreviewed/2025/01/GHSA-wxw4-9hr6-3vw4/GHSA-wxw4-9hr6-3vw4.json index a436014c276..a496f33f82b 100644 --- a/advisories/unreviewed/2025/01/GHSA-wxw4-9hr6-3vw4/GHSA-wxw4-9hr6-3vw4.json +++ b/advisories/unreviewed/2025/01/GHSA-wxw4-9hr6-3vw4/GHSA-wxw4-9hr6-3vw4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wxw4-9hr6-3vw4", - "modified": "2025-01-28T00:32:14Z", + "modified": "2025-01-28T15:31:56Z", "published": "2025-01-28T00:32:14Z", "aliases": [ "CVE-2025-24106" ], "details": "The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.3, macOS Sequoia 15.3, macOS Sonoma 14.7.3. Parsing a file may lead to an unexpected app termination.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-613" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:16Z" diff --git a/advisories/unreviewed/2025/01/GHSA-x7wf-f6c9-x89j/GHSA-x7wf-f6c9-x89j.json b/advisories/unreviewed/2025/01/GHSA-x7wf-f6c9-x89j/GHSA-x7wf-f6c9-x89j.json index e33fc1f3270..3437bcf5a00 100644 --- a/advisories/unreviewed/2025/01/GHSA-x7wf-f6c9-x89j/GHSA-x7wf-f6c9-x89j.json +++ b/advisories/unreviewed/2025/01/GHSA-x7wf-f6c9-x89j/GHSA-x7wf-f6c9-x89j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-x7wf-f6c9-x89j", - "modified": "2025-01-28T00:32:14Z", + "modified": "2025-01-28T15:31:56Z", "published": "2025-01-28T00:32:14Z", "aliases": [ "CVE-2025-24121" ], "details": "A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.3, macOS Sequoia 15.3, macOS Sonoma 14.7.3. An app may be able to modify protected parts of the file system.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-863" + ], + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:17Z" diff --git a/advisories/unreviewed/2025/01/GHSA-xpjh-vmfm-8qmf/GHSA-xpjh-vmfm-8qmf.json b/advisories/unreviewed/2025/01/GHSA-xpjh-vmfm-8qmf/GHSA-xpjh-vmfm-8qmf.json index 95c26d59370..5b4569692fc 100644 --- a/advisories/unreviewed/2025/01/GHSA-xpjh-vmfm-8qmf/GHSA-xpjh-vmfm-8qmf.json +++ b/advisories/unreviewed/2025/01/GHSA-xpjh-vmfm-8qmf/GHSA-xpjh-vmfm-8qmf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xpjh-vmfm-8qmf", - "modified": "2025-01-28T00:32:13Z", + "modified": "2025-01-28T15:31:56Z", "published": "2025-01-28T00:32:13Z", "aliases": [ "CVE-2024-54542" ], "details": "An authentication issue was addressed with improved state management. This issue is fixed in Safari 18.2, macOS Sequoia 15.2, watchOS 11.2, iOS 18.2 and iPadOS 18.2. Private Browsing tabs may be accessed without authentication.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-863" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-27T22:15:14Z"