From 81e28b4b8e29ccb687125528dba4586cc65a2991 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 2 Apr 2025 18:32:15 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-5cwq-39c4-23v7.json | 3 +- .../GHSA-mrph-rvc3-cv97.json | 2 +- .../GHSA-rg6m-2r9v-c5fj.json | 3 +- .../GHSA-4m2c-fvhc-6vr6.json | 4 ++- .../GHSA-5w4f-g47c-43mg.json | 2 +- .../GHSA-6243-j7h8-mqf5.json | 2 +- .../GHSA-6rfm-3v66-6wr2.json | 6 ++-- .../GHSA-7wj3-gw7r-qr35.json | 2 +- .../GHSA-845r-7x4c-q8qf.json | 18 ++++++++-- .../GHSA-9rpc-xc7c-jhmw.json | 2 +- .../GHSA-9xm2-vfqx-3hgq.json | 3 +- .../GHSA-cfwr-wq2f-j365.json | 6 ++-- .../GHSA-f7gw-576r-4q7w.json | 4 ++- .../GHSA-f99q-3688-gw8p.json | 2 +- .../GHSA-fj75-7hqx-qp2c.json | 3 +- .../GHSA-ggmm-62x9-fwmh.json | 6 ++-- .../GHSA-hq34-fgpx-qmf6.json | 2 +- .../GHSA-hxf9-8vg6-w44v.json | 1 + .../GHSA-j9cj-vhg7-rwqr.json | 1 + .../GHSA-mggm-2vjp-mrm8.json | 4 ++- .../GHSA-mw65-xrm6-grcv.json | 5 +-- .../GHSA-p7wr-9vm9-q49x.json | 2 +- .../GHSA-pw64-6v6v-94vp.json | 2 +- .../GHSA-v44r-r7pp-7r2w.json | 5 +-- .../GHSA-vmqj-wp2g-3jp7.json | 6 ++-- .../GHSA-qm75-wj63-4j3j.json | 2 +- .../GHSA-w2gx-4fh8-wm9f.json | 10 +++++- .../GHSA-4jg4-vxrf-wx9q.json | 4 +-- .../GHSA-h727-v4g2-pq85.json | 4 +-- .../GHSA-p979-f2q7-5cjj.json | 4 +-- .../GHSA-6vr9-h9pm-5frx.json | 4 ++- .../GHSA-8xch-h6xr-8gp4.json | 3 +- .../GHSA-jfwf-8826-6jjm.json | 3 +- .../GHSA-qq4f-w524-x6mg.json | 4 ++- .../GHSA-r96x-p6v3-j823.json | 6 +++- .../GHSA-vgcv-cmj2-4w37.json | 3 +- .../GHSA-x2qg-68hh-f96j.json | 3 +- .../GHSA-28qp-rcr7-xp4g.json | 36 +++++++++++++++++++ .../GHSA-3rwj-9q84-fmqw.json | 36 +++++++++++++++++++ .../GHSA-3v39-cfpx-f2w7.json | 36 +++++++++++++++++++ .../GHSA-4vjp-327p-w4qv.json | 15 +++++--- .../GHSA-565r-pf5q-45v6.json | 15 +++++--- .../GHSA-56rf-vwj9-f3p7.json | 15 +++++--- .../GHSA-57p2-mgfw-2w94.json | 15 +++++--- .../GHSA-5jpr-cwj3-v74m.json | 15 +++++--- .../GHSA-7mhw-3w3j-f4cw.json | 15 +++++--- .../GHSA-8mq5-f87c-x4p2.json | 11 ++++-- .../GHSA-8rp7-48wf-f389.json | 36 +++++++++++++++++++ .../GHSA-c55q-hcv9-5p27.json | 36 +++++++++++++++++++ .../GHSA-c98q-928m-f9h8.json | 36 +++++++++++++++++++ .../GHSA-f2wv-6cwg-48rq.json | 15 +++++--- .../GHSA-f39p-623w-5v5j.json | 36 +++++++++++++++++++ .../GHSA-g89f-x8cp-c435.json | 36 +++++++++++++++++++ .../GHSA-hc9m-f2mx-w9j7.json | 15 +++++--- .../GHSA-hcfh-qjcp-34q9.json | 15 +++++--- .../GHSA-hjjh-fr7g-hrm6.json | 36 +++++++++++++++++++ .../GHSA-mf93-68c7-8cg2.json | 36 +++++++++++++++++++ .../GHSA-mq8x-f2hr-qvjq.json | 36 +++++++++++++++++++ .../GHSA-p3gw-g89c-c3cq.json | 15 +++++--- .../GHSA-p57m-j445-jv2j.json | 15 +++++--- .../GHSA-pg82-qc3q-4772.json | 15 +++++--- .../GHSA-qpj9-jpjq-jm8g.json | 15 +++++--- .../GHSA-rv9g-c396-f836.json | 36 +++++++++++++++++++ .../GHSA-rx2w-x63r-4r67.json | 36 +++++++++++++++++++ .../GHSA-vx5w-r2jc-638h.json | 36 +++++++++++++++++++ .../GHSA-vx87-fgpc-jrg3.json | 36 +++++++++++++++++++ .../GHSA-w29g-jr2c-2x6r.json | 36 +++++++++++++++++++ .../GHSA-wr6w-jxg7-qpfh.json | 15 +++++--- .../GHSA-xf8m-87xc-5cw5.json | 36 +++++++++++++++++++ 69 files changed, 875 insertions(+), 104 deletions(-) create mode 100644 advisories/unreviewed/2025/04/GHSA-28qp-rcr7-xp4g/GHSA-28qp-rcr7-xp4g.json create mode 100644 advisories/unreviewed/2025/04/GHSA-3rwj-9q84-fmqw/GHSA-3rwj-9q84-fmqw.json create mode 100644 advisories/unreviewed/2025/04/GHSA-3v39-cfpx-f2w7/GHSA-3v39-cfpx-f2w7.json create mode 100644 advisories/unreviewed/2025/04/GHSA-8rp7-48wf-f389/GHSA-8rp7-48wf-f389.json create mode 100644 advisories/unreviewed/2025/04/GHSA-c55q-hcv9-5p27/GHSA-c55q-hcv9-5p27.json create mode 100644 advisories/unreviewed/2025/04/GHSA-c98q-928m-f9h8/GHSA-c98q-928m-f9h8.json create mode 100644 advisories/unreviewed/2025/04/GHSA-f39p-623w-5v5j/GHSA-f39p-623w-5v5j.json create mode 100644 advisories/unreviewed/2025/04/GHSA-g89f-x8cp-c435/GHSA-g89f-x8cp-c435.json create mode 100644 advisories/unreviewed/2025/04/GHSA-hjjh-fr7g-hrm6/GHSA-hjjh-fr7g-hrm6.json create mode 100644 advisories/unreviewed/2025/04/GHSA-mf93-68c7-8cg2/GHSA-mf93-68c7-8cg2.json create mode 100644 advisories/unreviewed/2025/04/GHSA-mq8x-f2hr-qvjq/GHSA-mq8x-f2hr-qvjq.json create mode 100644 advisories/unreviewed/2025/04/GHSA-rv9g-c396-f836/GHSA-rv9g-c396-f836.json create mode 100644 advisories/unreviewed/2025/04/GHSA-rx2w-x63r-4r67/GHSA-rx2w-x63r-4r67.json create mode 100644 advisories/unreviewed/2025/04/GHSA-vx5w-r2jc-638h/GHSA-vx5w-r2jc-638h.json create mode 100644 advisories/unreviewed/2025/04/GHSA-vx87-fgpc-jrg3/GHSA-vx87-fgpc-jrg3.json create mode 100644 advisories/unreviewed/2025/04/GHSA-w29g-jr2c-2x6r/GHSA-w29g-jr2c-2x6r.json create mode 100644 advisories/unreviewed/2025/04/GHSA-xf8m-87xc-5cw5/GHSA-xf8m-87xc-5cw5.json diff --git a/advisories/unreviewed/2022/05/GHSA-5cwq-39c4-23v7/GHSA-5cwq-39c4-23v7.json b/advisories/unreviewed/2022/05/GHSA-5cwq-39c4-23v7/GHSA-5cwq-39c4-23v7.json index feb771728e1..4b46963dd61 100644 --- a/advisories/unreviewed/2022/05/GHSA-5cwq-39c4-23v7/GHSA-5cwq-39c4-23v7.json +++ b/advisories/unreviewed/2022/05/GHSA-5cwq-39c4-23v7/GHSA-5cwq-39c4-23v7.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-mrph-rvc3-cv97/GHSA-mrph-rvc3-cv97.json b/advisories/unreviewed/2022/05/GHSA-mrph-rvc3-cv97/GHSA-mrph-rvc3-cv97.json index 0b1da4d5ce9..f0086107167 100644 --- a/advisories/unreviewed/2022/05/GHSA-mrph-rvc3-cv97/GHSA-mrph-rvc3-cv97.json +++ b/advisories/unreviewed/2022/05/GHSA-mrph-rvc3-cv97/GHSA-mrph-rvc3-cv97.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mrph-rvc3-cv97", - "modified": "2022-05-07T00:00:51Z", + "modified": "2025-04-02T18:30:37Z", "published": "2022-05-06T00:00:39Z", "aliases": [ "CVE-2022-1388" diff --git a/advisories/unreviewed/2022/05/GHSA-rg6m-2r9v-c5fj/GHSA-rg6m-2r9v-c5fj.json b/advisories/unreviewed/2022/05/GHSA-rg6m-2r9v-c5fj/GHSA-rg6m-2r9v-c5fj.json index b7524d8d2e3..d0b4319c75c 100644 --- a/advisories/unreviewed/2022/05/GHSA-rg6m-2r9v-c5fj/GHSA-rg6m-2r9v-c5fj.json +++ b/advisories/unreviewed/2022/05/GHSA-rg6m-2r9v-c5fj/GHSA-rg6m-2r9v-c5fj.json @@ -34,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-918" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/01/GHSA-4m2c-fvhc-6vr6/GHSA-4m2c-fvhc-6vr6.json b/advisories/unreviewed/2023/01/GHSA-4m2c-fvhc-6vr6/GHSA-4m2c-fvhc-6vr6.json index 552ef2ec803..0a4240a667f 100644 --- a/advisories/unreviewed/2023/01/GHSA-4m2c-fvhc-6vr6/GHSA-4m2c-fvhc-6vr6.json +++ b/advisories/unreviewed/2023/01/GHSA-4m2c-fvhc-6vr6/GHSA-4m2c-fvhc-6vr6.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-1021" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/01/GHSA-5w4f-g47c-43mg/GHSA-5w4f-g47c-43mg.json b/advisories/unreviewed/2023/01/GHSA-5w4f-g47c-43mg/GHSA-5w4f-g47c-43mg.json index 8b5824cf69a..11986e57d57 100644 --- a/advisories/unreviewed/2023/01/GHSA-5w4f-g47c-43mg/GHSA-5w4f-g47c-43mg.json +++ b/advisories/unreviewed/2023/01/GHSA-5w4f-g47c-43mg/GHSA-5w4f-g47c-43mg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5w4f-g47c-43mg", - "modified": "2023-01-31T18:30:24Z", + "modified": "2025-04-02T18:30:38Z", "published": "2023-01-23T15:30:33Z", "aliases": [ "CVE-2021-43446" diff --git a/advisories/unreviewed/2023/01/GHSA-6243-j7h8-mqf5/GHSA-6243-j7h8-mqf5.json b/advisories/unreviewed/2023/01/GHSA-6243-j7h8-mqf5/GHSA-6243-j7h8-mqf5.json index 3c188db1252..53aa14be494 100644 --- a/advisories/unreviewed/2023/01/GHSA-6243-j7h8-mqf5/GHSA-6243-j7h8-mqf5.json +++ b/advisories/unreviewed/2023/01/GHSA-6243-j7h8-mqf5/GHSA-6243-j7h8-mqf5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6243-j7h8-mqf5", - "modified": "2023-01-31T15:30:31Z", + "modified": "2025-04-02T18:30:38Z", "published": "2023-01-23T15:30:33Z", "aliases": [ "CVE-2021-43444" diff --git a/advisories/unreviewed/2023/01/GHSA-6rfm-3v66-6wr2/GHSA-6rfm-3v66-6wr2.json b/advisories/unreviewed/2023/01/GHSA-6rfm-3v66-6wr2/GHSA-6rfm-3v66-6wr2.json index 962d928f148..49e00f8605c 100644 --- a/advisories/unreviewed/2023/01/GHSA-6rfm-3v66-6wr2/GHSA-6rfm-3v66-6wr2.json +++ b/advisories/unreviewed/2023/01/GHSA-6rfm-3v66-6wr2/GHSA-6rfm-3v66-6wr2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6rfm-3v66-6wr2", - "modified": "2023-01-31T15:30:33Z", + "modified": "2025-04-02T18:30:38Z", "published": "2023-01-22T06:30:27Z", "aliases": [ "CVE-2023-24056" @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/01/GHSA-7wj3-gw7r-qr35/GHSA-7wj3-gw7r-qr35.json b/advisories/unreviewed/2023/01/GHSA-7wj3-gw7r-qr35/GHSA-7wj3-gw7r-qr35.json index 508d3b51de9..b5ee2240041 100644 --- a/advisories/unreviewed/2023/01/GHSA-7wj3-gw7r-qr35/GHSA-7wj3-gw7r-qr35.json +++ b/advisories/unreviewed/2023/01/GHSA-7wj3-gw7r-qr35/GHSA-7wj3-gw7r-qr35.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7wj3-gw7r-qr35", - "modified": "2023-01-31T15:30:31Z", + "modified": "2025-04-02T18:30:38Z", "published": "2023-01-23T15:30:33Z", "aliases": [ "CVE-2021-43445" diff --git a/advisories/unreviewed/2023/01/GHSA-845r-7x4c-q8qf/GHSA-845r-7x4c-q8qf.json b/advisories/unreviewed/2023/01/GHSA-845r-7x4c-q8qf/GHSA-845r-7x4c-q8qf.json index 475b3af1ad3..3597c81bf8e 100644 --- a/advisories/unreviewed/2023/01/GHSA-845r-7x4c-q8qf/GHSA-845r-7x4c-q8qf.json +++ b/advisories/unreviewed/2023/01/GHSA-845r-7x4c-q8qf/GHSA-845r-7x4c-q8qf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-845r-7x4c-q8qf", - "modified": "2023-01-30T21:30:44Z", + "modified": "2025-04-02T18:30:37Z", "published": "2023-01-20T21:30:29Z", "aliases": [ "CVE-2023-24021" @@ -35,6 +35,18 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2023/01/msg00023.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/52TGCZCOHYBDCVWJYNN2PS4QLOHCXWTQ" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SYRTXTOQQI6SB2TLI5QXU76DURSLS4XI" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WCH6JM4I4MD4YABYFHSBDDOUFDGIFJKL" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/52TGCZCOHYBDCVWJYNN2PS4QLOHCXWTQ" @@ -49,7 +61,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-170" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/01/GHSA-9rpc-xc7c-jhmw/GHSA-9rpc-xc7c-jhmw.json b/advisories/unreviewed/2023/01/GHSA-9rpc-xc7c-jhmw/GHSA-9rpc-xc7c-jhmw.json index 943bc1d9081..3f811264b8e 100644 --- a/advisories/unreviewed/2023/01/GHSA-9rpc-xc7c-jhmw/GHSA-9rpc-xc7c-jhmw.json +++ b/advisories/unreviewed/2023/01/GHSA-9rpc-xc7c-jhmw/GHSA-9rpc-xc7c-jhmw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9rpc-xc7c-jhmw", - "modified": "2023-01-27T15:30:31Z", + "modified": "2025-04-02T18:30:37Z", "published": "2023-01-20T18:30:22Z", "aliases": [ "CVE-2022-43704" diff --git a/advisories/unreviewed/2023/01/GHSA-9xm2-vfqx-3hgq/GHSA-9xm2-vfqx-3hgq.json b/advisories/unreviewed/2023/01/GHSA-9xm2-vfqx-3hgq/GHSA-9xm2-vfqx-3hgq.json index f6b51d6400e..5f2abf458a7 100644 --- a/advisories/unreviewed/2023/01/GHSA-9xm2-vfqx-3hgq/GHSA-9xm2-vfqx-3hgq.json +++ b/advisories/unreviewed/2023/01/GHSA-9xm2-vfqx-3hgq/GHSA-9xm2-vfqx-3hgq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9xm2-vfqx-3hgq", - "modified": "2023-02-02T15:30:44Z", + "modified": "2025-04-02T18:30:37Z", "published": "2023-01-20T15:30:27Z", "aliases": [ "CVE-2022-43959" @@ -34,6 +34,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-200", "CWE-522" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2023/01/GHSA-cfwr-wq2f-j365/GHSA-cfwr-wq2f-j365.json b/advisories/unreviewed/2023/01/GHSA-cfwr-wq2f-j365/GHSA-cfwr-wq2f-j365.json index bfec88b9a60..340db85fc39 100644 --- a/advisories/unreviewed/2023/01/GHSA-cfwr-wq2f-j365/GHSA-cfwr-wq2f-j365.json +++ b/advisories/unreviewed/2023/01/GHSA-cfwr-wq2f-j365/GHSA-cfwr-wq2f-j365.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cfwr-wq2f-j365", - "modified": "2023-01-31T18:30:20Z", + "modified": "2025-04-02T18:30:38Z", "published": "2023-01-22T06:30:27Z", "aliases": [ "CVE-2023-24058" @@ -49,7 +49,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/01/GHSA-f7gw-576r-4q7w/GHSA-f7gw-576r-4q7w.json b/advisories/unreviewed/2023/01/GHSA-f7gw-576r-4q7w/GHSA-f7gw-576r-4q7w.json index 120a60c7d51..7a208d98796 100644 --- a/advisories/unreviewed/2023/01/GHSA-f7gw-576r-4q7w/GHSA-f7gw-576r-4q7w.json +++ b/advisories/unreviewed/2023/01/GHSA-f7gw-576r-4q7w/GHSA-f7gw-576r-4q7w.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/01/GHSA-f99q-3688-gw8p/GHSA-f99q-3688-gw8p.json b/advisories/unreviewed/2023/01/GHSA-f99q-3688-gw8p/GHSA-f99q-3688-gw8p.json index ba65d35ef1f..17352248610 100644 --- a/advisories/unreviewed/2023/01/GHSA-f99q-3688-gw8p/GHSA-f99q-3688-gw8p.json +++ b/advisories/unreviewed/2023/01/GHSA-f99q-3688-gw8p/GHSA-f99q-3688-gw8p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f99q-3688-gw8p", - "modified": "2023-02-03T18:30:28Z", + "modified": "2025-04-02T18:30:43Z", "published": "2023-01-23T18:30:19Z", "aliases": [ "CVE-2022-37719" diff --git a/advisories/unreviewed/2023/01/GHSA-fj75-7hqx-qp2c/GHSA-fj75-7hqx-qp2c.json b/advisories/unreviewed/2023/01/GHSA-fj75-7hqx-qp2c/GHSA-fj75-7hqx-qp2c.json index a67884c174d..022aa03349a 100644 --- a/advisories/unreviewed/2023/01/GHSA-fj75-7hqx-qp2c/GHSA-fj75-7hqx-qp2c.json +++ b/advisories/unreviewed/2023/01/GHSA-fj75-7hqx-qp2c/GHSA-fj75-7hqx-qp2c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fj75-7hqx-qp2c", - "modified": "2023-02-08T21:30:22Z", + "modified": "2025-04-02T18:30:45Z", "published": "2023-01-23T21:30:24Z", "aliases": [ "CVE-2023-23560" @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-20", "CWE-918" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2023/01/GHSA-ggmm-62x9-fwmh/GHSA-ggmm-62x9-fwmh.json b/advisories/unreviewed/2023/01/GHSA-ggmm-62x9-fwmh/GHSA-ggmm-62x9-fwmh.json index be07c01a6e4..d511a509139 100644 --- a/advisories/unreviewed/2023/01/GHSA-ggmm-62x9-fwmh/GHSA-ggmm-62x9-fwmh.json +++ b/advisories/unreviewed/2023/01/GHSA-ggmm-62x9-fwmh/GHSA-ggmm-62x9-fwmh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ggmm-62x9-fwmh", - "modified": "2023-02-06T18:30:30Z", + "modified": "2025-04-02T18:30:46Z", "published": "2023-01-26T21:30:20Z", "aliases": [ "CVE-2022-48199" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-276" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/01/GHSA-hq34-fgpx-qmf6/GHSA-hq34-fgpx-qmf6.json b/advisories/unreviewed/2023/01/GHSA-hq34-fgpx-qmf6/GHSA-hq34-fgpx-qmf6.json index 4886cdaeec9..383b99e40d1 100644 --- a/advisories/unreviewed/2023/01/GHSA-hq34-fgpx-qmf6/GHSA-hq34-fgpx-qmf6.json +++ b/advisories/unreviewed/2023/01/GHSA-hq34-fgpx-qmf6/GHSA-hq34-fgpx-qmf6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hq34-fgpx-qmf6", - "modified": "2023-01-31T21:30:20Z", + "modified": "2025-04-02T18:30:39Z", "published": "2023-01-23T15:30:33Z", "aliases": [ "CVE-2021-43448" diff --git a/advisories/unreviewed/2023/01/GHSA-hxf9-8vg6-w44v/GHSA-hxf9-8vg6-w44v.json b/advisories/unreviewed/2023/01/GHSA-hxf9-8vg6-w44v/GHSA-hxf9-8vg6-w44v.json index 53904611385..a6f1b5d07c4 100644 --- a/advisories/unreviewed/2023/01/GHSA-hxf9-8vg6-w44v/GHSA-hxf9-8vg6-w44v.json +++ b/advisories/unreviewed/2023/01/GHSA-hxf9-8vg6-w44v/GHSA-hxf9-8vg6-w44v.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-121", "CWE-787" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/01/GHSA-j9cj-vhg7-rwqr/GHSA-j9cj-vhg7-rwqr.json b/advisories/unreviewed/2023/01/GHSA-j9cj-vhg7-rwqr/GHSA-j9cj-vhg7-rwqr.json index 875f232110f..7c808f6b700 100644 --- a/advisories/unreviewed/2023/01/GHSA-j9cj-vhg7-rwqr/GHSA-j9cj-vhg7-rwqr.json +++ b/advisories/unreviewed/2023/01/GHSA-j9cj-vhg7-rwqr/GHSA-j9cj-vhg7-rwqr.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-284", "CWE-307" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/01/GHSA-mggm-2vjp-mrm8/GHSA-mggm-2vjp-mrm8.json b/advisories/unreviewed/2023/01/GHSA-mggm-2vjp-mrm8/GHSA-mggm-2vjp-mrm8.json index 81b06583b5c..89a5d78cb59 100644 --- a/advisories/unreviewed/2023/01/GHSA-mggm-2vjp-mrm8/GHSA-mggm-2vjp-mrm8.json +++ b/advisories/unreviewed/2023/01/GHSA-mggm-2vjp-mrm8/GHSA-mggm-2vjp-mrm8.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-20" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/01/GHSA-mw65-xrm6-grcv/GHSA-mw65-xrm6-grcv.json b/advisories/unreviewed/2023/01/GHSA-mw65-xrm6-grcv/GHSA-mw65-xrm6-grcv.json index 9d333b939e7..c385e67b246 100644 --- a/advisories/unreviewed/2023/01/GHSA-mw65-xrm6-grcv/GHSA-mw65-xrm6-grcv.json +++ b/advisories/unreviewed/2023/01/GHSA-mw65-xrm6-grcv/GHSA-mw65-xrm6-grcv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mw65-xrm6-grcv", - "modified": "2023-02-03T18:30:28Z", + "modified": "2025-04-02T18:30:43Z", "published": "2023-01-23T18:30:19Z", "aliases": [ "CVE-2022-37718" @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/01/GHSA-p7wr-9vm9-q49x/GHSA-p7wr-9vm9-q49x.json b/advisories/unreviewed/2023/01/GHSA-p7wr-9vm9-q49x/GHSA-p7wr-9vm9-q49x.json index 85abb5da887..0980794aabc 100644 --- a/advisories/unreviewed/2023/01/GHSA-p7wr-9vm9-q49x/GHSA-p7wr-9vm9-q49x.json +++ b/advisories/unreviewed/2023/01/GHSA-p7wr-9vm9-q49x/GHSA-p7wr-9vm9-q49x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p7wr-9vm9-q49x", - "modified": "2023-01-27T15:30:37Z", + "modified": "2025-04-02T18:30:37Z", "published": "2023-01-20T15:30:26Z", "aliases": [ "CVE-2022-41441" diff --git a/advisories/unreviewed/2023/01/GHSA-pw64-6v6v-94vp/GHSA-pw64-6v6v-94vp.json b/advisories/unreviewed/2023/01/GHSA-pw64-6v6v-94vp/GHSA-pw64-6v6v-94vp.json index 406cf56b037..ee2a8f837f7 100644 --- a/advisories/unreviewed/2023/01/GHSA-pw64-6v6v-94vp/GHSA-pw64-6v6v-94vp.json +++ b/advisories/unreviewed/2023/01/GHSA-pw64-6v6v-94vp/GHSA-pw64-6v6v-94vp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pw64-6v6v-94vp", - "modified": "2023-01-31T15:30:33Z", + "modified": "2025-04-02T18:30:39Z", "published": "2023-01-23T15:30:33Z", "aliases": [ "CVE-2021-43449" diff --git a/advisories/unreviewed/2023/01/GHSA-v44r-r7pp-7r2w/GHSA-v44r-r7pp-7r2w.json b/advisories/unreviewed/2023/01/GHSA-v44r-r7pp-7r2w/GHSA-v44r-r7pp-7r2w.json index c2527a379a5..4c1cbe8b6bd 100644 --- a/advisories/unreviewed/2023/01/GHSA-v44r-r7pp-7r2w/GHSA-v44r-r7pp-7r2w.json +++ b/advisories/unreviewed/2023/01/GHSA-v44r-r7pp-7r2w/GHSA-v44r-r7pp-7r2w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v44r-r7pp-7r2w", - "modified": "2023-01-31T18:30:23Z", + "modified": "2025-04-02T18:30:39Z", "published": "2023-01-23T15:30:33Z", "aliases": [ "CVE-2021-43447" @@ -34,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-287" + "CWE-287", + "CWE-306" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/01/GHSA-vmqj-wp2g-3jp7/GHSA-vmqj-wp2g-3jp7.json b/advisories/unreviewed/2023/01/GHSA-vmqj-wp2g-3jp7/GHSA-vmqj-wp2g-3jp7.json index 6146f9e5ad6..cb0fef72a0d 100644 --- a/advisories/unreviewed/2023/01/GHSA-vmqj-wp2g-3jp7/GHSA-vmqj-wp2g-3jp7.json +++ b/advisories/unreviewed/2023/01/GHSA-vmqj-wp2g-3jp7/GHSA-vmqj-wp2g-3jp7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vmqj-wp2g-3jp7", - "modified": "2023-01-31T21:30:24Z", + "modified": "2025-04-02T18:30:38Z", "published": "2023-01-22T09:30:25Z", "aliases": [ "CVE-2023-24059" @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-94" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/07/GHSA-qm75-wj63-4j3j/GHSA-qm75-wj63-4j3j.json b/advisories/unreviewed/2023/07/GHSA-qm75-wj63-4j3j/GHSA-qm75-wj63-4j3j.json index 32f6385af9f..06689148a65 100644 --- a/advisories/unreviewed/2023/07/GHSA-qm75-wj63-4j3j/GHSA-qm75-wj63-4j3j.json +++ b/advisories/unreviewed/2023/07/GHSA-qm75-wj63-4j3j/GHSA-qm75-wj63-4j3j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qm75-wj63-4j3j", - "modified": "2024-04-04T05:31:44Z", + "modified": "2025-04-02T18:30:41Z", "published": "2023-07-06T19:24:07Z", "aliases": [ "CVE-2022-4693" diff --git a/advisories/unreviewed/2024/03/GHSA-w2gx-4fh8-wm9f/GHSA-w2gx-4fh8-wm9f.json b/advisories/unreviewed/2024/03/GHSA-w2gx-4fh8-wm9f/GHSA-w2gx-4fh8-wm9f.json index bb653a11dbf..6ef33de5603 100644 --- a/advisories/unreviewed/2024/03/GHSA-w2gx-4fh8-wm9f/GHSA-w2gx-4fh8-wm9f.json +++ b/advisories/unreviewed/2024/03/GHSA-w2gx-4fh8-wm9f/GHSA-w2gx-4fh8-wm9f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w2gx-4fh8-wm9f", - "modified": "2024-11-12T18:30:50Z", + "modified": "2025-04-02T18:30:47Z", "published": "2024-03-07T00:30:49Z", "aliases": [ "CVE-2024-2236" @@ -23,6 +23,14 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2024:9404" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:3530" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:3534" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-2236" diff --git a/advisories/unreviewed/2024/04/GHSA-4jg4-vxrf-wx9q/GHSA-4jg4-vxrf-wx9q.json b/advisories/unreviewed/2024/04/GHSA-4jg4-vxrf-wx9q/GHSA-4jg4-vxrf-wx9q.json index 1e082e9dc7d..9f220db72ab 100644 --- a/advisories/unreviewed/2024/04/GHSA-4jg4-vxrf-wx9q/GHSA-4jg4-vxrf-wx9q.json +++ b/advisories/unreviewed/2024/04/GHSA-4jg4-vxrf-wx9q/GHSA-4jg4-vxrf-wx9q.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-4jg4-vxrf-wx9q", - "modified": "2024-04-15T09:30:53Z", + "modified": "2025-04-02T18:30:47Z", "published": "2024-04-15T09:30:53Z", "aliases": [ "CVE-2024-32138" ], - "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in KaizenCoders Short URL allows Reflected XSS.This issue affects Short URL: from n/a through 1.6.8.\n\n", + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in KaizenCoders Short URL allows Reflected XSS.This issue affects Short URL: from n/a through 1.6.8.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-h727-v4g2-pq85/GHSA-h727-v4g2-pq85.json b/advisories/unreviewed/2024/04/GHSA-h727-v4g2-pq85/GHSA-h727-v4g2-pq85.json index d1abfe0b16a..59e6c1e8f46 100644 --- a/advisories/unreviewed/2024/04/GHSA-h727-v4g2-pq85/GHSA-h727-v4g2-pq85.json +++ b/advisories/unreviewed/2024/04/GHSA-h727-v4g2-pq85/GHSA-h727-v4g2-pq85.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-h727-v4g2-pq85", - "modified": "2024-04-15T09:30:53Z", + "modified": "2025-04-02T18:30:47Z", "published": "2024-04-15T09:30:53Z", "aliases": [ "CVE-2024-32133" ], - "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Schuppenies EZ Form Calculator allows Reflected XSS.This issue affects EZ Form Calculator: from n/a through 2.14.0.3.\n\n", + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Schuppenies EZ Form Calculator allows Reflected XSS.This issue affects EZ Form Calculator: from n/a through 2.14.0.3.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-p979-f2q7-5cjj/GHSA-p979-f2q7-5cjj.json b/advisories/unreviewed/2024/04/GHSA-p979-f2q7-5cjj/GHSA-p979-f2q7-5cjj.json index d426a2f3ad8..d799c5d9cb5 100644 --- a/advisories/unreviewed/2024/04/GHSA-p979-f2q7-5cjj/GHSA-p979-f2q7-5cjj.json +++ b/advisories/unreviewed/2024/04/GHSA-p979-f2q7-5cjj/GHSA-p979-f2q7-5cjj.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-p979-f2q7-5cjj", - "modified": "2024-04-15T09:30:54Z", + "modified": "2025-04-02T18:30:47Z", "published": "2024-04-15T09:30:54Z", "aliases": [ "CVE-2024-32430" ], - "details": "Server-Side Request Forgery (SSRF) vulnerability in ActiveCampaign.This issue affects ActiveCampaign: from n/a through 8.1.14.\n\n", + "details": "Server-Side Request Forgery (SSRF) vulnerability in ActiveCampaign.This issue affects ActiveCampaign: from n/a through 8.1.14.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2025/03/GHSA-6vr9-h9pm-5frx/GHSA-6vr9-h9pm-5frx.json b/advisories/unreviewed/2025/03/GHSA-6vr9-h9pm-5frx/GHSA-6vr9-h9pm-5frx.json index 116ec505821..7365206855a 100644 --- a/advisories/unreviewed/2025/03/GHSA-6vr9-h9pm-5frx/GHSA-6vr9-h9pm-5frx.json +++ b/advisories/unreviewed/2025/03/GHSA-6vr9-h9pm-5frx/GHSA-6vr9-h9pm-5frx.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-8xch-h6xr-8gp4/GHSA-8xch-h6xr-8gp4.json b/advisories/unreviewed/2025/03/GHSA-8xch-h6xr-8gp4/GHSA-8xch-h6xr-8gp4.json index 560b86e42f3..03cfdce8a28 100644 --- a/advisories/unreviewed/2025/03/GHSA-8xch-h6xr-8gp4/GHSA-8xch-h6xr-8gp4.json +++ b/advisories/unreviewed/2025/03/GHSA-8xch-h6xr-8gp4/GHSA-8xch-h6xr-8gp4.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-jfwf-8826-6jjm/GHSA-jfwf-8826-6jjm.json b/advisories/unreviewed/2025/03/GHSA-jfwf-8826-6jjm/GHSA-jfwf-8826-6jjm.json index 5d1f8e5627c..dcd4e8b43be 100644 --- a/advisories/unreviewed/2025/03/GHSA-jfwf-8826-6jjm/GHSA-jfwf-8826-6jjm.json +++ b/advisories/unreviewed/2025/03/GHSA-jfwf-8826-6jjm/GHSA-jfwf-8826-6jjm.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-qq4f-w524-x6mg/GHSA-qq4f-w524-x6mg.json b/advisories/unreviewed/2025/03/GHSA-qq4f-w524-x6mg/GHSA-qq4f-w524-x6mg.json index c68b7338b7e..93976bacdc4 100644 --- a/advisories/unreviewed/2025/03/GHSA-qq4f-w524-x6mg/GHSA-qq4f-w524-x6mg.json +++ b/advisories/unreviewed/2025/03/GHSA-qq4f-w524-x6mg/GHSA-qq4f-w524-x6mg.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/03/GHSA-r96x-p6v3-j823/GHSA-r96x-p6v3-j823.json b/advisories/unreviewed/2025/03/GHSA-r96x-p6v3-j823/GHSA-r96x-p6v3-j823.json index a65e078ecba..d46e7fcfa97 100644 --- a/advisories/unreviewed/2025/03/GHSA-r96x-p6v3-j823/GHSA-r96x-p6v3-j823.json +++ b/advisories/unreviewed/2025/03/GHSA-r96x-p6v3-j823/GHSA-r96x-p6v3-j823.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r96x-p6v3-j823", - "modified": "2025-03-05T12:31:12Z", + "modified": "2025-04-02T18:30:48Z", "published": "2025-03-05T12:31:12Z", "aliases": [ "CVE-2025-25015" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25015" }, + { + "type": "WEB", + "url": "https://discuss.elastic.co/t/kibana-8-17-3-8-16-6-security-update-esa-2025-06/375441" + }, { "type": "WEB", "url": "https://discuss.elastic.co/t/kibana-8-17-3-security-update-esa-2025-06/375441" diff --git a/advisories/unreviewed/2025/03/GHSA-vgcv-cmj2-4w37/GHSA-vgcv-cmj2-4w37.json b/advisories/unreviewed/2025/03/GHSA-vgcv-cmj2-4w37/GHSA-vgcv-cmj2-4w37.json index 9c773840deb..ae827b32e9d 100644 --- a/advisories/unreviewed/2025/03/GHSA-vgcv-cmj2-4w37/GHSA-vgcv-cmj2-4w37.json +++ b/advisories/unreviewed/2025/03/GHSA-vgcv-cmj2-4w37/GHSA-vgcv-cmj2-4w37.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-x2qg-68hh-f96j/GHSA-x2qg-68hh-f96j.json b/advisories/unreviewed/2025/03/GHSA-x2qg-68hh-f96j/GHSA-x2qg-68hh-f96j.json index 69a5a120fd7..7d68e1fed53 100644 --- a/advisories/unreviewed/2025/03/GHSA-x2qg-68hh-f96j/GHSA-x2qg-68hh-f96j.json +++ b/advisories/unreviewed/2025/03/GHSA-x2qg-68hh-f96j/GHSA-x2qg-68hh-f96j.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/04/GHSA-28qp-rcr7-xp4g/GHSA-28qp-rcr7-xp4g.json b/advisories/unreviewed/2025/04/GHSA-28qp-rcr7-xp4g/GHSA-28qp-rcr7-xp4g.json new file mode 100644 index 00000000000..271de56971f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-28qp-rcr7-xp4g/GHSA-28qp-rcr7-xp4g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-28qp-rcr7-xp4g", + "modified": "2025-04-02T18:30:51Z", + "published": "2025-04-02T18:30:51Z", + "aliases": [ + "CVE-2024-56475" + ], + "details": "IBM TXSeries for Multiplatforms 9.1 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56475" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7229880" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-02T16:17:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3rwj-9q84-fmqw/GHSA-3rwj-9q84-fmqw.json b/advisories/unreviewed/2025/04/GHSA-3rwj-9q84-fmqw/GHSA-3rwj-9q84-fmqw.json new file mode 100644 index 00000000000..84b90f62e2f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3rwj-9q84-fmqw/GHSA-3rwj-9q84-fmqw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3rwj-9q84-fmqw", + "modified": "2025-04-02T18:30:54Z", + "published": "2025-04-02T18:30:54Z", + "aliases": [ + "CVE-2025-31285" + ], + "details": "A broken access control vulnerability previously discovered in the Trend Vision One Role Name component could have allowed an administrator to create users who could then change the role of the account and ultimately escalate privileges. \n\nPlease note: ths issue has already been addressed on the backend service and is no longer considered an active vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31285" + }, + { + "type": "WEB", + "url": "https://success.trendmicro.com/en-US/solution/KA-0019386" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-02T17:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3v39-cfpx-f2w7/GHSA-3v39-cfpx-f2w7.json b/advisories/unreviewed/2025/04/GHSA-3v39-cfpx-f2w7/GHSA-3v39-cfpx-f2w7.json new file mode 100644 index 00000000000..4d9685e44ac --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-3v39-cfpx-f2w7/GHSA-3v39-cfpx-f2w7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3v39-cfpx-f2w7", + "modified": "2025-04-02T18:30:52Z", + "published": "2025-04-02T18:30:52Z", + "aliases": [ + "CVE-2025-0154" + ], + "details": "IBM TXSeries for Multiplatforms 9.1 and 11.1 could disclose sensitive information to a remote attacker due to improper neutralization of HTTP headers.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0154" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7229880" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-644" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-02T16:17:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-4vjp-327p-w4qv/GHSA-4vjp-327p-w4qv.json b/advisories/unreviewed/2025/04/GHSA-4vjp-327p-w4qv/GHSA-4vjp-327p-w4qv.json index 4374cd750bc..740de2d4791 100644 --- a/advisories/unreviewed/2025/04/GHSA-4vjp-327p-w4qv/GHSA-4vjp-327p-w4qv.json +++ b/advisories/unreviewed/2025/04/GHSA-4vjp-327p-w4qv/GHSA-4vjp-327p-w4qv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4vjp-327p-w4qv", - "modified": "2025-04-02T15:31:38Z", + "modified": "2025-04-02T18:30:50Z", "published": "2025-04-02T15:31:38Z", "aliases": [ "CVE-2025-31722" ], "details": "In Jenkins Templating Engine Plugin 2.5.3 and earlier, libraries defined in folders are not subject to sandbox protection, allowing attackers with Item/Configure permission to execute arbitrary code in the context of the Jenkins controller JVM.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-02T15:15:59Z" diff --git a/advisories/unreviewed/2025/04/GHSA-565r-pf5q-45v6/GHSA-565r-pf5q-45v6.json b/advisories/unreviewed/2025/04/GHSA-565r-pf5q-45v6/GHSA-565r-pf5q-45v6.json index 2cbff038fe4..0743cfe4a13 100644 --- a/advisories/unreviewed/2025/04/GHSA-565r-pf5q-45v6/GHSA-565r-pf5q-45v6.json +++ b/advisories/unreviewed/2025/04/GHSA-565r-pf5q-45v6/GHSA-565r-pf5q-45v6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-565r-pf5q-45v6", - "modified": "2025-04-02T15:31:38Z", + "modified": "2025-04-02T18:30:50Z", "published": "2025-04-02T15:31:38Z", "aliases": [ "CVE-2025-31720" ], "details": "A missing permission check in Jenkins 2.503 and earlier, LTS 2.492.2 and earlier allows attackers with Computer/Create permission but without Computer/Extended Read permission to copy an agent, gaining access to its configuration.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-02T15:15:59Z" diff --git a/advisories/unreviewed/2025/04/GHSA-56rf-vwj9-f3p7/GHSA-56rf-vwj9-f3p7.json b/advisories/unreviewed/2025/04/GHSA-56rf-vwj9-f3p7/GHSA-56rf-vwj9-f3p7.json index 3cec175a2ee..3d44cc65546 100644 --- a/advisories/unreviewed/2025/04/GHSA-56rf-vwj9-f3p7/GHSA-56rf-vwj9-f3p7.json +++ b/advisories/unreviewed/2025/04/GHSA-56rf-vwj9-f3p7/GHSA-56rf-vwj9-f3p7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-56rf-vwj9-f3p7", - "modified": "2025-04-01T00:30:41Z", + "modified": "2025-04-02T18:30:49Z", "published": "2025-04-01T00:30:41Z", "aliases": [ "CVE-2025-24283" ], "details": "A logging issue was addressed with improved data redaction. This issue is fixed in visionOS 2.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. An app may be able to access sensitive user data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:24Z" diff --git a/advisories/unreviewed/2025/04/GHSA-57p2-mgfw-2w94/GHSA-57p2-mgfw-2w94.json b/advisories/unreviewed/2025/04/GHSA-57p2-mgfw-2w94/GHSA-57p2-mgfw-2w94.json index e1463975aa3..78eb3175028 100644 --- a/advisories/unreviewed/2025/04/GHSA-57p2-mgfw-2w94/GHSA-57p2-mgfw-2w94.json +++ b/advisories/unreviewed/2025/04/GHSA-57p2-mgfw-2w94/GHSA-57p2-mgfw-2w94.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-57p2-mgfw-2w94", - "modified": "2025-04-01T00:30:35Z", + "modified": "2025-04-02T18:30:48Z", "published": "2025-04-01T00:30:35Z", "aliases": [ "CVE-2025-24148" ], "details": "This issue was addressed with improved handling of executable types. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A malicious JAR file may bypass Gatekeeper checks.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-354" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:16Z" diff --git a/advisories/unreviewed/2025/04/GHSA-5jpr-cwj3-v74m/GHSA-5jpr-cwj3-v74m.json b/advisories/unreviewed/2025/04/GHSA-5jpr-cwj3-v74m/GHSA-5jpr-cwj3-v74m.json index a8b7ca8ab43..0b31f8906a6 100644 --- a/advisories/unreviewed/2025/04/GHSA-5jpr-cwj3-v74m/GHSA-5jpr-cwj3-v74m.json +++ b/advisories/unreviewed/2025/04/GHSA-5jpr-cwj3-v74m/GHSA-5jpr-cwj3-v74m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5jpr-cwj3-v74m", - "modified": "2025-04-01T00:30:37Z", + "modified": "2025-04-02T18:30:49Z", "published": "2025-04-01T00:30:37Z", "aliases": [ "CVE-2025-24205" ], "details": "An authorization issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.7.5, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to access user-sensitive data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:18Z" diff --git a/advisories/unreviewed/2025/04/GHSA-7mhw-3w3j-f4cw/GHSA-7mhw-3w3j-f4cw.json b/advisories/unreviewed/2025/04/GHSA-7mhw-3w3j-f4cw/GHSA-7mhw-3w3j-f4cw.json index 1af5909ef20..3adac48233a 100644 --- a/advisories/unreviewed/2025/04/GHSA-7mhw-3w3j-f4cw/GHSA-7mhw-3w3j-f4cw.json +++ b/advisories/unreviewed/2025/04/GHSA-7mhw-3w3j-f4cw/GHSA-7mhw-3w3j-f4cw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7mhw-3w3j-f4cw", - "modified": "2025-04-01T00:30:41Z", + "modified": "2025-04-02T18:30:49Z", "published": "2025-04-01T00:30:41Z", "aliases": [ "CVE-2025-24276" ], "details": "This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A malicious app may be able to access private information.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:24Z" diff --git a/advisories/unreviewed/2025/04/GHSA-8mq5-f87c-x4p2/GHSA-8mq5-f87c-x4p2.json b/advisories/unreviewed/2025/04/GHSA-8mq5-f87c-x4p2/GHSA-8mq5-f87c-x4p2.json index 26c020ac6b7..da3e3b5c6f7 100644 --- a/advisories/unreviewed/2025/04/GHSA-8mq5-f87c-x4p2/GHSA-8mq5-f87c-x4p2.json +++ b/advisories/unreviewed/2025/04/GHSA-8mq5-f87c-x4p2/GHSA-8mq5-f87c-x4p2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8mq5-f87c-x4p2", - "modified": "2025-04-01T00:30:37Z", + "modified": "2025-04-02T18:30:48Z", "published": "2025-04-01T00:30:36Z", "aliases": [ "CVE-2025-24194" ], "details": "A logic issue was addressed with improved checks. This issue is fixed in visionOS 2.4, iOS 18.4 and iPadOS 18.4, tvOS 18.4, macOS Sequoia 15.4. Processing maliciously crafted web content may result in the disclosure of process memory.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -33,7 +38,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:17Z" diff --git a/advisories/unreviewed/2025/04/GHSA-8rp7-48wf-f389/GHSA-8rp7-48wf-f389.json b/advisories/unreviewed/2025/04/GHSA-8rp7-48wf-f389/GHSA-8rp7-48wf-f389.json new file mode 100644 index 00000000000..a749fc9d78c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8rp7-48wf-f389/GHSA-8rp7-48wf-f389.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8rp7-48wf-f389", + "modified": "2025-04-02T18:30:53Z", + "published": "2025-04-02T18:30:53Z", + "aliases": [ + "CVE-2025-20120" + ], + "details": "A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface on an affected device.\n\n This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20120" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-epnmpi-sxss-GSScPGY4" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-02T17:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-c55q-hcv9-5p27/GHSA-c55q-hcv9-5p27.json b/advisories/unreviewed/2025/04/GHSA-c55q-hcv9-5p27/GHSA-c55q-hcv9-5p27.json new file mode 100644 index 00000000000..d80e8e099a2 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-c55q-hcv9-5p27/GHSA-c55q-hcv9-5p27.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c55q-hcv9-5p27", + "modified": "2025-04-02T18:30:51Z", + "published": "2025-04-02T18:30:51Z", + "aliases": [ + "CVE-2024-56476" + ], + "details": "IBM TXSeries for Multiplatforms 9.1 and 11.1 could allow an attacker to enumerate usernames due to an observable login attempt response discrepancy.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56476" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7229880" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-204" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-02T16:17:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-c98q-928m-f9h8/GHSA-c98q-928m-f9h8.json b/advisories/unreviewed/2025/04/GHSA-c98q-928m-f9h8/GHSA-c98q-928m-f9h8.json new file mode 100644 index 00000000000..20da50c916e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-c98q-928m-f9h8/GHSA-c98q-928m-f9h8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c98q-928m-f9h8", + "modified": "2025-04-02T18:30:53Z", + "published": "2025-04-02T18:30:53Z", + "aliases": [ + "CVE-2025-31282" + ], + "details": "A broken access control vulnerability previously discovered in the Trend Vision One User Account component could have allowed an administrator to create users who could then change the role of the account and ultimately escalate privileges. \n\nPlease note: ths issue has already been addressed on the backend service and is no longer considered an active vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31282" + }, + { + "type": "WEB", + "url": "https://success.trendmicro.com/en-US/solution/KA-0019386" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-02T17:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-f2wv-6cwg-48rq/GHSA-f2wv-6cwg-48rq.json b/advisories/unreviewed/2025/04/GHSA-f2wv-6cwg-48rq/GHSA-f2wv-6cwg-48rq.json index ed992774ce3..13221bc2b5c 100644 --- a/advisories/unreviewed/2025/04/GHSA-f2wv-6cwg-48rq/GHSA-f2wv-6cwg-48rq.json +++ b/advisories/unreviewed/2025/04/GHSA-f2wv-6cwg-48rq/GHSA-f2wv-6cwg-48rq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-f2wv-6cwg-48rq", - "modified": "2025-04-01T00:30:39Z", + "modified": "2025-04-02T18:30:49Z", "published": "2025-04-01T00:30:39Z", "aliases": [ "CVE-2025-24244" ], "details": "The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.7.5, tvOS 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5. Processing a maliciously crafted font may result in the disclosure of process memory.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:21Z" diff --git a/advisories/unreviewed/2025/04/GHSA-f39p-623w-5v5j/GHSA-f39p-623w-5v5j.json b/advisories/unreviewed/2025/04/GHSA-f39p-623w-5v5j/GHSA-f39p-623w-5v5j.json new file mode 100644 index 00000000000..474b43b4dfa --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-f39p-623w-5v5j/GHSA-f39p-623w-5v5j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f39p-623w-5v5j", + "modified": "2025-04-02T18:30:54Z", + "published": "2025-04-02T18:30:54Z", + "aliases": [ + "CVE-2025-31286" + ], + "details": "An HTML injection vulnerability previously discovered in Trend Vision One could have allowed a malicious user to execute arbitrary code.\n\nPlease note: this issue has already been addressed on the backend service and is no longer considered an active vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31286" + }, + { + "type": "WEB", + "url": "https://success.trendmicro.com/en-US/solution/KA-0019386" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-02T17:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-g89f-x8cp-c435/GHSA-g89f-x8cp-c435.json b/advisories/unreviewed/2025/04/GHSA-g89f-x8cp-c435/GHSA-g89f-x8cp-c435.json new file mode 100644 index 00000000000..91e161bf315 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-g89f-x8cp-c435/GHSA-g89f-x8cp-c435.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g89f-x8cp-c435", + "modified": "2025-04-02T18:30:52Z", + "published": "2025-04-02T18:30:52Z", + "aliases": [ + "CVE-2025-0014" + ], + "details": "Incorrect default permissions on the AMD Ryzen(TM) AI installation folder could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0014" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7037.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-276" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-02T17:15:41Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hc9m-f2mx-w9j7/GHSA-hc9m-f2mx-w9j7.json b/advisories/unreviewed/2025/04/GHSA-hc9m-f2mx-w9j7/GHSA-hc9m-f2mx-w9j7.json index c55f81157ef..5e08e6052a0 100644 --- a/advisories/unreviewed/2025/04/GHSA-hc9m-f2mx-w9j7/GHSA-hc9m-f2mx-w9j7.json +++ b/advisories/unreviewed/2025/04/GHSA-hc9m-f2mx-w9j7/GHSA-hc9m-f2mx-w9j7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hc9m-f2mx-w9j7", - "modified": "2025-04-01T00:30:36Z", + "modified": "2025-04-02T18:30:48Z", "published": "2025-04-01T00:30:36Z", "aliases": [ "CVE-2025-24173" ], "details": "This issue was addressed with additional entitlement checks. This issue is fixed in visionOS 2.4, macOS Ventura 13.7.5, tvOS 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to break out of its sandbox.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:16Z" diff --git a/advisories/unreviewed/2025/04/GHSA-hcfh-qjcp-34q9/GHSA-hcfh-qjcp-34q9.json b/advisories/unreviewed/2025/04/GHSA-hcfh-qjcp-34q9/GHSA-hcfh-qjcp-34q9.json index 5535c9810ac..d84bdd8c625 100644 --- a/advisories/unreviewed/2025/04/GHSA-hcfh-qjcp-34q9/GHSA-hcfh-qjcp-34q9.json +++ b/advisories/unreviewed/2025/04/GHSA-hcfh-qjcp-34q9/GHSA-hcfh-qjcp-34q9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hcfh-qjcp-34q9", - "modified": "2025-04-02T15:31:38Z", + "modified": "2025-04-02T18:30:50Z", "published": "2025-04-02T15:31:38Z", "aliases": [ "CVE-2025-31723" ], "details": "A cross-site request forgery (CSRF) vulnerability in Jenkins Simple Queue Plugin 1.4.6 and earlier allows attackers to change and reset the build queue order.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-02T15:15:59Z" diff --git a/advisories/unreviewed/2025/04/GHSA-hjjh-fr7g-hrm6/GHSA-hjjh-fr7g-hrm6.json b/advisories/unreviewed/2025/04/GHSA-hjjh-fr7g-hrm6/GHSA-hjjh-fr7g-hrm6.json new file mode 100644 index 00000000000..824cc8709c8 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hjjh-fr7g-hrm6/GHSA-hjjh-fr7g-hrm6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hjjh-fr7g-hrm6", + "modified": "2025-04-02T18:30:52Z", + "published": "2025-04-02T18:30:52Z", + "aliases": [ + "CVE-2024-36336" + ], + "details": "Integer overflow within the AMD NPU Driver could allow a local attacker to write out of bounds, potentially leading to a loss of confidentiality, integrity, or availability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36336" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7037.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-190" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-02T17:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-mf93-68c7-8cg2/GHSA-mf93-68c7-8cg2.json b/advisories/unreviewed/2025/04/GHSA-mf93-68c7-8cg2/GHSA-mf93-68c7-8cg2.json new file mode 100644 index 00000000000..aabe33bf8b7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-mf93-68c7-8cg2/GHSA-mf93-68c7-8cg2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mf93-68c7-8cg2", + "modified": "2025-04-02T18:30:53Z", + "published": "2025-04-02T18:30:53Z", + "aliases": [ + "CVE-2025-20212" + ], + "details": "A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series devices could allow an authenticated, remote attacker to cause a denial of service (DoS) condition in the Cisco AnyConnect service on an affected device. To exploit this vulnerability, the attacker must have valid VPN user credentials on the affected device.\n\n This vulnerability exists because a variable is not initialized when an SSL VPN session is established. An attacker could exploit this vulnerability by supplying crafted attributes while establishing an SSL VPN session with an affected device. A successful exploit could allow the attacker to cause the Cisco AnyConnect VPN server to restart, resulting in the failure of the established SSL VPN sessions and forcing remote users to initiate a new VPN connection and reauthenticate. A sustained attack could prevent new SSL VPN connections from being established.\n\n Note: When the attack traffic stops, the Cisco AnyConnect VPN server recovers without manual intervention.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20212" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-meraki-mx-vpn-dos-vNRpDvfb" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-457" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-02T17:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-mq8x-f2hr-qvjq/GHSA-mq8x-f2hr-qvjq.json b/advisories/unreviewed/2025/04/GHSA-mq8x-f2hr-qvjq/GHSA-mq8x-f2hr-qvjq.json new file mode 100644 index 00000000000..7810397dd53 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-mq8x-f2hr-qvjq/GHSA-mq8x-f2hr-qvjq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mq8x-f2hr-qvjq", + "modified": "2025-04-02T18:30:53Z", + "published": "2025-04-02T18:30:53Z", + "aliases": [ + "CVE-2025-20203" + ], + "details": "A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against users of the interface of an affected system.\n\n The vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by inserting malicious code into specific data fields in the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker must have valid administrative credentials.\n\n \n\n {{value}} [\"%7b%7bvalue%7d%7d\"])}]]", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20203" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-epnmpi-sxss-GSScPGY4" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-02T17:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-p3gw-g89c-c3cq/GHSA-p3gw-g89c-c3cq.json b/advisories/unreviewed/2025/04/GHSA-p3gw-g89c-c3cq/GHSA-p3gw-g89c-c3cq.json index fc3ee552b37..706c5a3f975 100644 --- a/advisories/unreviewed/2025/04/GHSA-p3gw-g89c-c3cq/GHSA-p3gw-g89c-c3cq.json +++ b/advisories/unreviewed/2025/04/GHSA-p3gw-g89c-c3cq/GHSA-p3gw-g89c-c3cq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p3gw-g89c-c3cq", - "modified": "2025-04-01T00:30:39Z", + "modified": "2025-04-02T18:30:49Z", "published": "2025-04-01T00:30:38Z", "aliases": [ "CVE-2025-24236" ], "details": "An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to access sensitive user data.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:20Z" diff --git a/advisories/unreviewed/2025/04/GHSA-p57m-j445-jv2j/GHSA-p57m-j445-jv2j.json b/advisories/unreviewed/2025/04/GHSA-p57m-j445-jv2j/GHSA-p57m-j445-jv2j.json index 0e831e5ef50..dc5b18ffc36 100644 --- a/advisories/unreviewed/2025/04/GHSA-p57m-j445-jv2j/GHSA-p57m-j445-jv2j.json +++ b/advisories/unreviewed/2025/04/GHSA-p57m-j445-jv2j/GHSA-p57m-j445-jv2j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p57m-j445-jv2j", - "modified": "2025-04-01T00:30:42Z", + "modified": "2025-04-02T18:30:50Z", "published": "2025-04-01T00:30:42Z", "aliases": [ "CVE-2025-30438" ], "details": "This issue was addressed with improved access restrictions. This issue is fixed in visionOS 2.4, macOS Ventura 13.7.5, tvOS 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A malicious app may be able to dismiss the system notification on the Lock Screen that a recording was started.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:25Z" diff --git a/advisories/unreviewed/2025/04/GHSA-pg82-qc3q-4772/GHSA-pg82-qc3q-4772.json b/advisories/unreviewed/2025/04/GHSA-pg82-qc3q-4772/GHSA-pg82-qc3q-4772.json index 516378e1cc8..2a76f9f6857 100644 --- a/advisories/unreviewed/2025/04/GHSA-pg82-qc3q-4772/GHSA-pg82-qc3q-4772.json +++ b/advisories/unreviewed/2025/04/GHSA-pg82-qc3q-4772/GHSA-pg82-qc3q-4772.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pg82-qc3q-4772", - "modified": "2025-04-01T00:30:44Z", + "modified": "2025-04-02T18:30:50Z", "published": "2025-04-01T00:30:44Z", "aliases": [ "CVE-2025-30471" ], "details": "A validation issue was addressed with improved logic. This issue is fixed in visionOS 2.4, macOS Ventura 13.7.5, tvOS 18.4, iPadOS 17.7.6, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, macOS Sonoma 14.7.5. A remote user may be able to cause a denial-of-service.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:28Z" diff --git a/advisories/unreviewed/2025/04/GHSA-qpj9-jpjq-jm8g/GHSA-qpj9-jpjq-jm8g.json b/advisories/unreviewed/2025/04/GHSA-qpj9-jpjq-jm8g/GHSA-qpj9-jpjq-jm8g.json index f57272a08d1..13489de0f20 100644 --- a/advisories/unreviewed/2025/04/GHSA-qpj9-jpjq-jm8g/GHSA-qpj9-jpjq-jm8g.json +++ b/advisories/unreviewed/2025/04/GHSA-qpj9-jpjq-jm8g/GHSA-qpj9-jpjq-jm8g.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qpj9-jpjq-jm8g", - "modified": "2025-04-01T00:30:40Z", + "modified": "2025-04-02T18:30:49Z", "published": "2025-04-01T00:30:40Z", "aliases": [ "CVE-2025-24261" ], "details": "The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.5, macOS Sequoia 15.4, macOS Sonoma 14.7.5. An app may be able to modify protected parts of the file system.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-31T23:15:23Z" diff --git a/advisories/unreviewed/2025/04/GHSA-rv9g-c396-f836/GHSA-rv9g-c396-f836.json b/advisories/unreviewed/2025/04/GHSA-rv9g-c396-f836/GHSA-rv9g-c396-f836.json new file mode 100644 index 00000000000..8f75a98b48a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rv9g-c396-f836/GHSA-rv9g-c396-f836.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rv9g-c396-f836", + "modified": "2025-04-02T18:30:53Z", + "published": "2025-04-02T18:30:53Z", + "aliases": [ + "CVE-2025-31283" + ], + "details": "A broken access control vulnerability previously discovered in the Trend Vision One User Roles component could have allowed an administrator to create users who could then change the role of the account and ultimately escalate privileges. \n\nPlease note: ths issue has already been addressed on the backend service and is no longer considered an active vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31283" + }, + { + "type": "WEB", + "url": "https://success.trendmicro.com/en-US/solution/KA-0019386" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-02T17:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rx2w-x63r-4r67/GHSA-rx2w-x63r-4r67.json b/advisories/unreviewed/2025/04/GHSA-rx2w-x63r-4r67/GHSA-rx2w-x63r-4r67.json new file mode 100644 index 00000000000..89ffd157bbc --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rx2w-x63r-4r67/GHSA-rx2w-x63r-4r67.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rx2w-x63r-4r67", + "modified": "2025-04-02T18:30:53Z", + "published": "2025-04-02T18:30:53Z", + "aliases": [ + "CVE-2025-20139" + ], + "details": "A vulnerability in chat messaging features of Cisco Enterprise Chat and Email (ECE) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition.\n\n This vulnerability is due to improper validation of user-supplied input to chat entry points. An attacker could exploit this vulnerability by sending malicious requests to a messaging chat entry point in the affected application. A successful exploit could allow the attacker to cause the application to stop responding, resulting in a DoS condition. The application may not recover on its own and may need an administrator to manually restart services to recover.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20139" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ece-dos-tC6m9GZ8" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-185" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-02T17:15:43Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vx5w-r2jc-638h/GHSA-vx5w-r2jc-638h.json b/advisories/unreviewed/2025/04/GHSA-vx5w-r2jc-638h/GHSA-vx5w-r2jc-638h.json new file mode 100644 index 00000000000..1e1ec805647 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vx5w-r2jc-638h/GHSA-vx5w-r2jc-638h.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vx5w-r2jc-638h", + "modified": "2025-04-02T18:30:51Z", + "published": "2025-04-02T18:30:51Z", + "aliases": [ + "CVE-2024-56474" + ], + "details": "IBM TXSeries for Multiplatforms 9.1 and 11.1 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-56474" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7229880" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-02T16:17:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vx87-fgpc-jrg3/GHSA-vx87-fgpc-jrg3.json b/advisories/unreviewed/2025/04/GHSA-vx87-fgpc-jrg3/GHSA-vx87-fgpc-jrg3.json new file mode 100644 index 00000000000..b2d75b70ee0 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vx87-fgpc-jrg3/GHSA-vx87-fgpc-jrg3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vx87-fgpc-jrg3", + "modified": "2025-04-02T18:30:52Z", + "published": "2025-04-02T18:30:52Z", + "aliases": [ + "CVE-2024-36328" + ], + "details": "Integer overflow within AMD NPU Driver could allow a local attacker to write out of bounds, potentially leading to loss of integrity or availability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36328" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7037.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-190" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-02T17:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-w29g-jr2c-2x6r/GHSA-w29g-jr2c-2x6r.json b/advisories/unreviewed/2025/04/GHSA-w29g-jr2c-2x6r/GHSA-w29g-jr2c-2x6r.json new file mode 100644 index 00000000000..7f2e1b9a09e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-w29g-jr2c-2x6r/GHSA-w29g-jr2c-2x6r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w29g-jr2c-2x6r", + "modified": "2025-04-02T18:30:52Z", + "published": "2025-04-02T18:30:52Z", + "aliases": [ + "CVE-2024-36337" + ], + "details": "Integer overflow within AMD NPU Driver could allow a local attacker to write out of bounds, potentially leading to loss of confidentiality, integrity or availability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-36337" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7037.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-190" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-02T17:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-wr6w-jxg7-qpfh/GHSA-wr6w-jxg7-qpfh.json b/advisories/unreviewed/2025/04/GHSA-wr6w-jxg7-qpfh/GHSA-wr6w-jxg7-qpfh.json index 6f62ce77d19..fe2bd35de96 100644 --- a/advisories/unreviewed/2025/04/GHSA-wr6w-jxg7-qpfh/GHSA-wr6w-jxg7-qpfh.json +++ b/advisories/unreviewed/2025/04/GHSA-wr6w-jxg7-qpfh/GHSA-wr6w-jxg7-qpfh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wr6w-jxg7-qpfh", - "modified": "2025-04-02T15:31:38Z", + "modified": "2025-04-02T18:30:50Z", "published": "2025-04-02T15:31:38Z", "aliases": [ "CVE-2025-31721" ], "details": "A missing permission check in Jenkins 2.503 and earlier, LTS 2.492.2 and earlier allows attackers with Computer/Create permission but without Computer/Configure permission to copy an agent, gaining access to encrypted secrets in its configuration.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-02T15:15:59Z" diff --git a/advisories/unreviewed/2025/04/GHSA-xf8m-87xc-5cw5/GHSA-xf8m-87xc-5cw5.json b/advisories/unreviewed/2025/04/GHSA-xf8m-87xc-5cw5/GHSA-xf8m-87xc-5cw5.json new file mode 100644 index 00000000000..d80c320edc8 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-xf8m-87xc-5cw5/GHSA-xf8m-87xc-5cw5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xf8m-87xc-5cw5", + "modified": "2025-04-02T18:30:53Z", + "published": "2025-04-02T18:30:53Z", + "aliases": [ + "CVE-2025-31284" + ], + "details": "A broken access control vulnerability previously discovered in the Trend Vision One Status component could have allowed an administrator to create users who could then change the role of the account and ultimately escalate privileges. \n\nPlease note: ths issue has already been addressed on the backend service and is no longer considered an active vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-31284" + }, + { + "type": "WEB", + "url": "https://success.trendmicro.com/en-US/solution/KA-0019386" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-02T17:15:48Z" + } +} \ No newline at end of file