From 846d62cfc24b8c6cc8c7a2e9a72e639d35fb9e75 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 6 Feb 2025 15:34:21 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-cwxx-ph2v-87p8.json | 9 +++- .../GHSA-mmm5-f82c-58j8.json | 6 ++- .../GHSA-x5v2-fv6f-w5rh.json | 2 +- .../GHSA-c5gr-hg39-gr5m.json | 4 +- .../GHSA-7f69-3jw6-qjqw.json | 2 +- .../GHSA-35p2-5vrh-m3p6.json | 15 ++++-- .../GHSA-5pwm-738f-25mv.json | 3 +- .../GHSA-5wjw-qjhm-v43h.json | 15 ++++-- .../GHSA-m777-hj92-cw6q.json | 6 ++- .../GHSA-wv7p-rjf3-9fr5.json | 4 +- .../GHSA-237v-gpwr-jc57.json | 11 ++-- .../GHSA-2cmr-4r4h-w563.json | 15 ++++-- .../GHSA-4rjf-p248-343v.json | 36 +++++++++++++ .../GHSA-53rp-33p8-4hm8.json | 15 ++++-- .../GHSA-7qgg-vw88-cc99.json | 15 ++++-- .../GHSA-7vpm-4pp6-mgv3.json | 34 ++++++++++++ .../GHSA-7xvx-6q95-x86w.json | 15 ++++-- .../GHSA-9j5q-479x-43g2.json | 15 ++++-- .../GHSA-c42g-rmxf-64ch.json | 11 ++-- .../GHSA-cr8h-hqjg-7fqq.json | 36 +++++++++++++ .../GHSA-fc8m-34jj-34w4.json | 36 +++++++++++++ .../GHSA-ffm7-29rh-wg67.json | 36 +++++++++++++ .../GHSA-fg4m-w35q-vfg2.json | 15 ++++-- .../GHSA-frw2-p5ff-q77v.json | 52 +++++++++++++++++++ .../GHSA-g6j3-54g7-68jx.json | 36 +++++++++++++ .../GHSA-hg2p-7794-g6x3.json | 36 +++++++++++++ .../GHSA-hgwc-25jp-vvqf.json | 36 +++++++++++++ .../GHSA-hmf6-8vmc-33g5.json | 36 +++++++++++++ .../GHSA-mg63-673f-rg9p.json | 36 +++++++++++++ .../GHSA-mx24-hwqm-5vf7.json | 36 +++++++++++++ .../GHSA-pc47-g7gv-4gpw.json | 15 ++++-- .../GHSA-pm4j-w673-3p6x.json | 15 ++++-- .../GHSA-qqpw-72j3-h9jj.json | 2 +- .../GHSA-r5mv-57ph-669q.json | 31 +++++++++++ .../GHSA-r7jx-5m6m-cpg9.json | 15 ++++-- .../GHSA-v37g-gf72-65f5.json | 36 +++++++++++++ .../GHSA-v55m-3w98-233j.json | 15 ++++-- .../GHSA-vg5c-jm85-v84v.json | 11 ++-- .../GHSA-vrfh-ph2r-gxr9.json | 15 ++++-- 39 files changed, 707 insertions(+), 72 deletions(-) create mode 100644 advisories/unreviewed/2025/02/GHSA-4rjf-p248-343v/GHSA-4rjf-p248-343v.json create mode 100644 advisories/unreviewed/2025/02/GHSA-7vpm-4pp6-mgv3/GHSA-7vpm-4pp6-mgv3.json create mode 100644 advisories/unreviewed/2025/02/GHSA-cr8h-hqjg-7fqq/GHSA-cr8h-hqjg-7fqq.json create mode 100644 advisories/unreviewed/2025/02/GHSA-fc8m-34jj-34w4/GHSA-fc8m-34jj-34w4.json create mode 100644 advisories/unreviewed/2025/02/GHSA-ffm7-29rh-wg67/GHSA-ffm7-29rh-wg67.json create mode 100644 advisories/unreviewed/2025/02/GHSA-frw2-p5ff-q77v/GHSA-frw2-p5ff-q77v.json create mode 100644 advisories/unreviewed/2025/02/GHSA-g6j3-54g7-68jx/GHSA-g6j3-54g7-68jx.json create mode 100644 advisories/unreviewed/2025/02/GHSA-hg2p-7794-g6x3/GHSA-hg2p-7794-g6x3.json create mode 100644 advisories/unreviewed/2025/02/GHSA-hgwc-25jp-vvqf/GHSA-hgwc-25jp-vvqf.json create mode 100644 advisories/unreviewed/2025/02/GHSA-hmf6-8vmc-33g5/GHSA-hmf6-8vmc-33g5.json create mode 100644 advisories/unreviewed/2025/02/GHSA-mg63-673f-rg9p/GHSA-mg63-673f-rg9p.json create mode 100644 advisories/unreviewed/2025/02/GHSA-mx24-hwqm-5vf7/GHSA-mx24-hwqm-5vf7.json create mode 100644 advisories/unreviewed/2025/02/GHSA-r5mv-57ph-669q/GHSA-r5mv-57ph-669q.json create mode 100644 advisories/unreviewed/2025/02/GHSA-v37g-gf72-65f5/GHSA-v37g-gf72-65f5.json diff --git a/advisories/unreviewed/2022/05/GHSA-cwxx-ph2v-87p8/GHSA-cwxx-ph2v-87p8.json b/advisories/unreviewed/2022/05/GHSA-cwxx-ph2v-87p8/GHSA-cwxx-ph2v-87p8.json index 4bf7a157b23..6caf3e97625 100644 --- a/advisories/unreviewed/2022/05/GHSA-cwxx-ph2v-87p8/GHSA-cwxx-ph2v-87p8.json +++ b/advisories/unreviewed/2022/05/GHSA-cwxx-ph2v-87p8/GHSA-cwxx-ph2v-87p8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cwxx-ph2v-87p8", - "modified": "2022-05-24T17:30:26Z", + "modified": "2025-02-06T15:32:50Z", "published": "2022-05-24T17:30:26Z", "aliases": [ "CVE-2020-26919" ], "details": "NETGEAR JGS516PE devices before 2.6.0.43 are affected by lack of access control at the function level.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { diff --git a/advisories/unreviewed/2022/05/GHSA-mmm5-f82c-58j8/GHSA-mmm5-f82c-58j8.json b/advisories/unreviewed/2022/05/GHSA-mmm5-f82c-58j8/GHSA-mmm5-f82c-58j8.json index 611e2985555..01330ff7413 100644 --- a/advisories/unreviewed/2022/05/GHSA-mmm5-f82c-58j8/GHSA-mmm5-f82c-58j8.json +++ b/advisories/unreviewed/2022/05/GHSA-mmm5-f82c-58j8/GHSA-mmm5-f82c-58j8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mmm5-f82c-58j8", - "modified": "2025-01-24T18:31:04Z", + "modified": "2025-02-06T15:32:51Z", "published": "2022-05-24T19:01:29Z", "aliases": [ "CVE-2021-32030" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://www.asus.com/Networking-IoT-Servers/WiFi-Routers/ASUS-Gaming-Routers/RT-AC2900/HelpDesk_BIOS" }, + { + "type": "WEB", + "url": "https://www.asus.com/us/supportonly/lyra%20mini/helpdesk_bios" + }, { "type": "WEB", "url": "https://www.atredis.com/blog/2021/4/30/asus-authentication-bypass" diff --git a/advisories/unreviewed/2022/05/GHSA-x5v2-fv6f-w5rh/GHSA-x5v2-fv6f-w5rh.json b/advisories/unreviewed/2022/05/GHSA-x5v2-fv6f-w5rh/GHSA-x5v2-fv6f-w5rh.json index 143c70c8e2a..d864c65329b 100644 --- a/advisories/unreviewed/2022/05/GHSA-x5v2-fv6f-w5rh/GHSA-x5v2-fv6f-w5rh.json +++ b/advisories/unreviewed/2022/05/GHSA-x5v2-fv6f-w5rh/GHSA-x5v2-fv6f-w5rh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x5v2-fv6f-w5rh", - "modified": "2022-07-13T00:00:50Z", + "modified": "2025-02-06T15:32:50Z", "published": "2022-05-24T17:40:34Z", "aliases": [ "CVE-2020-29557" diff --git a/advisories/unreviewed/2023/04/GHSA-c5gr-hg39-gr5m/GHSA-c5gr-hg39-gr5m.json b/advisories/unreviewed/2023/04/GHSA-c5gr-hg39-gr5m/GHSA-c5gr-hg39-gr5m.json index b39c95fad2d..c7e245c4349 100644 --- a/advisories/unreviewed/2023/04/GHSA-c5gr-hg39-gr5m/GHSA-c5gr-hg39-gr5m.json +++ b/advisories/unreviewed/2023/04/GHSA-c5gr-hg39-gr5m/GHSA-c5gr-hg39-gr5m.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-276" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/12/GHSA-7f69-3jw6-qjqw/GHSA-7f69-3jw6-qjqw.json b/advisories/unreviewed/2024/12/GHSA-7f69-3jw6-qjqw/GHSA-7f69-3jw6-qjqw.json index 57e7499680a..2781e952ead 100644 --- a/advisories/unreviewed/2024/12/GHSA-7f69-3jw6-qjqw/GHSA-7f69-3jw6-qjqw.json +++ b/advisories/unreviewed/2024/12/GHSA-7f69-3jw6-qjqw/GHSA-7f69-3jw6-qjqw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7f69-3jw6-qjqw", - "modified": "2024-12-14T09:30:30Z", + "modified": "2025-02-06T15:32:51Z", "published": "2024-12-14T09:30:30Z", "aliases": [ "CVE-2024-11715" diff --git a/advisories/unreviewed/2025/01/GHSA-35p2-5vrh-m3p6/GHSA-35p2-5vrh-m3p6.json b/advisories/unreviewed/2025/01/GHSA-35p2-5vrh-m3p6/GHSA-35p2-5vrh-m3p6.json index 2dc42550e25..f9b4f48a5ae 100644 --- a/advisories/unreviewed/2025/01/GHSA-35p2-5vrh-m3p6/GHSA-35p2-5vrh-m3p6.json +++ b/advisories/unreviewed/2025/01/GHSA-35p2-5vrh-m3p6/GHSA-35p2-5vrh-m3p6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-35p2-5vrh-m3p6", - "modified": "2025-01-30T15:31:39Z", + "modified": "2025-02-06T15:32:52Z", "published": "2025-01-30T15:31:39Z", "aliases": [ "CVE-2024-55417" ], "details": "DevDojo Voyager through version 1.8.0 is vulnerable to bypassing the file type verification when an authenticated user uploads a file via /admin/media/upload. An authenticated user can upload a web shell causing arbitrary code execution on the server.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-30T15:15:17Z" diff --git a/advisories/unreviewed/2025/01/GHSA-5pwm-738f-25mv/GHSA-5pwm-738f-25mv.json b/advisories/unreviewed/2025/01/GHSA-5pwm-738f-25mv/GHSA-5pwm-738f-25mv.json index 374a54ec90a..98b75a39073 100644 --- a/advisories/unreviewed/2025/01/GHSA-5pwm-738f-25mv/GHSA-5pwm-738f-25mv.json +++ b/advisories/unreviewed/2025/01/GHSA-5pwm-738f-25mv/GHSA-5pwm-738f-25mv.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-276" + "CWE-276", + "CWE-862" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-5wjw-qjhm-v43h/GHSA-5wjw-qjhm-v43h.json b/advisories/unreviewed/2025/01/GHSA-5wjw-qjhm-v43h/GHSA-5wjw-qjhm-v43h.json index 82a5c50612c..0ab1a7901a1 100644 --- a/advisories/unreviewed/2025/01/GHSA-5wjw-qjhm-v43h/GHSA-5wjw-qjhm-v43h.json +++ b/advisories/unreviewed/2025/01/GHSA-5wjw-qjhm-v43h/GHSA-5wjw-qjhm-v43h.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5wjw-qjhm-v43h", - "modified": "2025-01-30T15:31:39Z", + "modified": "2025-02-06T15:32:51Z", "published": "2025-01-30T15:31:39Z", "aliases": [ "CVE-2024-53615" ], "details": "A command injection vulnerability in the video thumbnail rendering component of Karl Ward's files.gallery v0.3.0 through 0.11.0 allows remote attackers to execute arbitrary code via a crafted video file.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-30T15:15:17Z" diff --git a/advisories/unreviewed/2025/01/GHSA-m777-hj92-cw6q/GHSA-m777-hj92-cw6q.json b/advisories/unreviewed/2025/01/GHSA-m777-hj92-cw6q/GHSA-m777-hj92-cw6q.json index 93135e99872..2717909959e 100644 --- a/advisories/unreviewed/2025/01/GHSA-m777-hj92-cw6q/GHSA-m777-hj92-cw6q.json +++ b/advisories/unreviewed/2025/01/GHSA-m777-hj92-cw6q/GHSA-m777-hj92-cw6q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m777-hj92-cw6q", - "modified": "2025-01-30T18:32:07Z", + "modified": "2025-02-06T15:32:52Z", "published": "2025-01-30T18:32:07Z", "aliases": [ "CVE-2025-22220" @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-269" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-wv7p-rjf3-9fr5/GHSA-wv7p-rjf3-9fr5.json b/advisories/unreviewed/2025/01/GHSA-wv7p-rjf3-9fr5/GHSA-wv7p-rjf3-9fr5.json index b94226f6051..2f045ad2321 100644 --- a/advisories/unreviewed/2025/01/GHSA-wv7p-rjf3-9fr5/GHSA-wv7p-rjf3-9fr5.json +++ b/advisories/unreviewed/2025/01/GHSA-wv7p-rjf3-9fr5/GHSA-wv7p-rjf3-9fr5.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-237v-gpwr-jc57/GHSA-237v-gpwr-jc57.json b/advisories/unreviewed/2025/02/GHSA-237v-gpwr-jc57/GHSA-237v-gpwr-jc57.json index 284414ea7e9..6653b23dc22 100644 --- a/advisories/unreviewed/2025/02/GHSA-237v-gpwr-jc57/GHSA-237v-gpwr-jc57.json +++ b/advisories/unreviewed/2025/02/GHSA-237v-gpwr-jc57/GHSA-237v-gpwr-jc57.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-237v-gpwr-jc57", - "modified": "2025-02-05T03:32:13Z", + "modified": "2025-02-06T15:32:52Z", "published": "2025-02-05T00:31:13Z", "aliases": [ "CVE-2024-13722" ], "details": "The \"NagVis\" component within Checkmk is vulnerable to reflected cross-site scripting. An attacker can craft a malicious link that will execute arbitrary JavaScript in the context of the browser once clicked. The attack can be performed on both authenticated and unauthenticated users.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -39,7 +44,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-04T22:15:40Z" diff --git a/advisories/unreviewed/2025/02/GHSA-2cmr-4r4h-w563/GHSA-2cmr-4r4h-w563.json b/advisories/unreviewed/2025/02/GHSA-2cmr-4r4h-w563/GHSA-2cmr-4r4h-w563.json index 870f6a6fcf6..c699c01926a 100644 --- a/advisories/unreviewed/2025/02/GHSA-2cmr-4r4h-w563/GHSA-2cmr-4r4h-w563.json +++ b/advisories/unreviewed/2025/02/GHSA-2cmr-4r4h-w563/GHSA-2cmr-4r4h-w563.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2cmr-4r4h-w563", - "modified": "2025-02-06T06:31:26Z", + "modified": "2025-02-06T15:32:52Z", "published": "2025-02-06T06:31:26Z", "aliases": [ "CVE-2025-1066" ], "details": "OpenPLC_V3 contains an arbitrary file upload vulnerability, which could be leveraged for malvertising or phishing campaigns.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-06T00:15:27Z" diff --git a/advisories/unreviewed/2025/02/GHSA-4rjf-p248-343v/GHSA-4rjf-p248-343v.json b/advisories/unreviewed/2025/02/GHSA-4rjf-p248-343v/GHSA-4rjf-p248-343v.json new file mode 100644 index 00000000000..cfcc926ca8c --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-4rjf-p248-343v/GHSA-4rjf-p248-343v.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4rjf-p248-343v", + "modified": "2025-02-06T15:32:52Z", + "published": "2025-02-06T15:32:52Z", + "aliases": [ + "CVE-2024-57958" + ], + "details": "Out-of-bounds array read vulnerability in the FFRT module\nImpact: Successful exploitation of this vulnerability may cause features to perform abnormally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57958" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2025/2" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-06T13:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-53rp-33p8-4hm8/GHSA-53rp-33p8-4hm8.json b/advisories/unreviewed/2025/02/GHSA-53rp-33p8-4hm8/GHSA-53rp-33p8-4hm8.json index a5108a16a74..cdb92bbb737 100644 --- a/advisories/unreviewed/2025/02/GHSA-53rp-33p8-4hm8/GHSA-53rp-33p8-4hm8.json +++ b/advisories/unreviewed/2025/02/GHSA-53rp-33p8-4hm8/GHSA-53rp-33p8-4hm8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-53rp-33p8-4hm8", - "modified": "2025-02-06T06:31:26Z", + "modified": "2025-02-06T15:32:52Z", "published": "2025-02-06T06:31:26Z", "aliases": [ "CVE-2024-57074" ], "details": "A prototype pollution in the lib.merge function of xe-utils v3.5.31 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-1321" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-05T22:15:31Z" diff --git a/advisories/unreviewed/2025/02/GHSA-7qgg-vw88-cc99/GHSA-7qgg-vw88-cc99.json b/advisories/unreviewed/2025/02/GHSA-7qgg-vw88-cc99/GHSA-7qgg-vw88-cc99.json index e1afd12cf70..aa5038bcf05 100644 --- a/advisories/unreviewed/2025/02/GHSA-7qgg-vw88-cc99/GHSA-7qgg-vw88-cc99.json +++ b/advisories/unreviewed/2025/02/GHSA-7qgg-vw88-cc99/GHSA-7qgg-vw88-cc99.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7qgg-vw88-cc99", - "modified": "2025-02-06T06:31:26Z", + "modified": "2025-02-06T15:32:52Z", "published": "2025-02-06T06:31:26Z", "aliases": [ "CVE-2024-57077" ], "details": "The latest version of utils-extend (1.0.8) is vulnerable to Prototype Pollution through the entry function(s) lib.extend. An attacker can supply a payload with Object.prototype setter to introduce or modify properties within the global prototype chain, causing denial of service (DoS) a the minimum consequence.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-1321" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-05T22:15:31Z" diff --git a/advisories/unreviewed/2025/02/GHSA-7vpm-4pp6-mgv3/GHSA-7vpm-4pp6-mgv3.json b/advisories/unreviewed/2025/02/GHSA-7vpm-4pp6-mgv3/GHSA-7vpm-4pp6-mgv3.json new file mode 100644 index 00000000000..ace9ef27439 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-7vpm-4pp6-mgv3/GHSA-7vpm-4pp6-mgv3.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7vpm-4pp6-mgv3", + "modified": "2025-02-06T15:32:53Z", + "published": "2025-02-06T15:32:53Z", + "aliases": [ + "CVE-2024-57962" + ], + "details": "Vulnerability of incomplete verification information in the VPN service module\nImpact: Successful exploitation of this vulnerability may affect availability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57962" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2025/2" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-06T13:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-7xvx-6q95-x86w/GHSA-7xvx-6q95-x86w.json b/advisories/unreviewed/2025/02/GHSA-7xvx-6q95-x86w/GHSA-7xvx-6q95-x86w.json index f9c89476ec6..50b23d6869e 100644 --- a/advisories/unreviewed/2025/02/GHSA-7xvx-6q95-x86w/GHSA-7xvx-6q95-x86w.json +++ b/advisories/unreviewed/2025/02/GHSA-7xvx-6q95-x86w/GHSA-7xvx-6q95-x86w.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7xvx-6q95-x86w", - "modified": "2025-02-05T00:31:13Z", + "modified": "2025-02-06T15:32:52Z", "published": "2025-02-05T00:31:13Z", "aliases": [ "CVE-2024-48445" ], "details": "An issue in compop.ca ONLINE MALL v.3.5.3 allows a remote attacker to execute arbitrary code via the rid, tid, et, and ts parameters.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-287" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-04T23:15:08Z" diff --git a/advisories/unreviewed/2025/02/GHSA-9j5q-479x-43g2/GHSA-9j5q-479x-43g2.json b/advisories/unreviewed/2025/02/GHSA-9j5q-479x-43g2/GHSA-9j5q-479x-43g2.json index e78cec1ffa5..bd743609b82 100644 --- a/advisories/unreviewed/2025/02/GHSA-9j5q-479x-43g2/GHSA-9j5q-479x-43g2.json +++ b/advisories/unreviewed/2025/02/GHSA-9j5q-479x-43g2/GHSA-9j5q-479x-43g2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9j5q-479x-43g2", - "modified": "2025-02-06T06:31:26Z", + "modified": "2025-02-06T15:32:52Z", "published": "2025-02-06T06:31:26Z", "aliases": [ "CVE-2024-57085" ], "details": "A prototype pollution in the function deepMerge of @stryker-mutator/util v8.6.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-1321" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-05T22:15:32Z" diff --git a/advisories/unreviewed/2025/02/GHSA-c42g-rmxf-64ch/GHSA-c42g-rmxf-64ch.json b/advisories/unreviewed/2025/02/GHSA-c42g-rmxf-64ch/GHSA-c42g-rmxf-64ch.json index 3f95b8d0975..387811665c3 100644 --- a/advisories/unreviewed/2025/02/GHSA-c42g-rmxf-64ch/GHSA-c42g-rmxf-64ch.json +++ b/advisories/unreviewed/2025/02/GHSA-c42g-rmxf-64ch/GHSA-c42g-rmxf-64ch.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c42g-rmxf-64ch", - "modified": "2025-02-05T12:33:07Z", + "modified": "2025-02-06T15:32:52Z", "published": "2025-02-05T12:33:07Z", "aliases": [ "CVE-2025-0167" ], "details": "When asked to use a `.netrc` file for credentials **and** to follow HTTP\nredirects, curl could leak the password used for the first host to the\nfollowed-to host under certain circumstances.\n\nThis flaw only manifests itself if the netrc file has a `default` entry that\nomits both login and password. A rare circumstance.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -29,7 +34,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-05T10:15:22Z" diff --git a/advisories/unreviewed/2025/02/GHSA-cr8h-hqjg-7fqq/GHSA-cr8h-hqjg-7fqq.json b/advisories/unreviewed/2025/02/GHSA-cr8h-hqjg-7fqq/GHSA-cr8h-hqjg-7fqq.json new file mode 100644 index 00000000000..f505889f94a --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-cr8h-hqjg-7fqq/GHSA-cr8h-hqjg-7fqq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cr8h-hqjg-7fqq", + "modified": "2025-02-06T15:32:52Z", + "published": "2025-02-06T15:32:52Z", + "aliases": [ + "CVE-2024-57961" + ], + "details": "Out-of-bounds write vulnerability in the emcom module\nImpact: Successful exploitation of this vulnerability may cause features to perform abnormally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57961" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2025/2" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-06T13:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-fc8m-34jj-34w4/GHSA-fc8m-34jj-34w4.json b/advisories/unreviewed/2025/02/GHSA-fc8m-34jj-34w4/GHSA-fc8m-34jj-34w4.json new file mode 100644 index 00000000000..d2592753908 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-fc8m-34jj-34w4/GHSA-fc8m-34jj-34w4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fc8m-34jj-34w4", + "modified": "2025-02-06T15:32:52Z", + "published": "2025-02-06T15:32:52Z", + "aliases": [ + "CVE-2024-57960" + ], + "details": "Input verification vulnerability in the ExternalStorageProvider module\nImpact: Successful exploitation of this vulnerability may affect service confidentiality.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57960" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2025/2" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-06T13:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-ffm7-29rh-wg67/GHSA-ffm7-29rh-wg67.json b/advisories/unreviewed/2025/02/GHSA-ffm7-29rh-wg67/GHSA-ffm7-29rh-wg67.json new file mode 100644 index 00000000000..84fb5cfc437 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-ffm7-29rh-wg67/GHSA-ffm7-29rh-wg67.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ffm7-29rh-wg67", + "modified": "2025-02-06T15:32:52Z", + "published": "2025-02-06T15:32:52Z", + "aliases": [ + "CVE-2024-57955" + ], + "details": "Arbitrary write vulnerability in the Gallery module \nImpact: Successful exploitation of this vulnerability may affect service confidentiality.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57955" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2025/2" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-06T13:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-fg4m-w35q-vfg2/GHSA-fg4m-w35q-vfg2.json b/advisories/unreviewed/2025/02/GHSA-fg4m-w35q-vfg2/GHSA-fg4m-w35q-vfg2.json index d4f58fa66c1..b8ccfe226a1 100644 --- a/advisories/unreviewed/2025/02/GHSA-fg4m-w35q-vfg2/GHSA-fg4m-w35q-vfg2.json +++ b/advisories/unreviewed/2025/02/GHSA-fg4m-w35q-vfg2/GHSA-fg4m-w35q-vfg2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fg4m-w35q-vfg2", - "modified": "2025-02-06T06:31:26Z", + "modified": "2025-02-06T15:32:52Z", "published": "2025-02-06T06:31:26Z", "aliases": [ "CVE-2024-57079" ], "details": "A prototype pollution in the lib.deepMerge function of @zag-js/core v0.50.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-1321" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-05T22:15:32Z" diff --git a/advisories/unreviewed/2025/02/GHSA-frw2-p5ff-q77v/GHSA-frw2-p5ff-q77v.json b/advisories/unreviewed/2025/02/GHSA-frw2-p5ff-q77v/GHSA-frw2-p5ff-q77v.json new file mode 100644 index 00000000000..c69ddacee17 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-frw2-p5ff-q77v/GHSA-frw2-p5ff-q77v.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-frw2-p5ff-q77v", + "modified": "2025-02-06T15:32:53Z", + "published": "2025-02-06T15:32:53Z", + "aliases": [ + "CVE-2025-1074" + ], + "details": "A vulnerability, which was classified as problematic, was found in Webkul QloApps 1.6.1. Affected is the function logout of the file /en/?mylogout of the component URL Handler. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure. They are aware about it and are working on resolving it.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1074" + }, + { + "type": "WEB", + "url": "https://github.com/mano257200/qloapps-csrf-logout-vulnerability" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.294834" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.294834" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.491600" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-06T14:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-g6j3-54g7-68jx/GHSA-g6j3-54g7-68jx.json b/advisories/unreviewed/2025/02/GHSA-g6j3-54g7-68jx/GHSA-g6j3-54g7-68jx.json new file mode 100644 index 00000000000..12cc2d845b9 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-g6j3-54g7-68jx/GHSA-g6j3-54g7-68jx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g6j3-54g7-68jx", + "modified": "2025-02-06T15:32:52Z", + "published": "2025-02-06T15:32:52Z", + "aliases": [ + "CVE-2024-57954" + ], + "details": "Permission verification vulnerability in the media library module\nImpact: Successful exploitation of this vulnerability may affect service confidentiality.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57954" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2025/2" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-06T13:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-hg2p-7794-g6x3/GHSA-hg2p-7794-g6x3.json b/advisories/unreviewed/2025/02/GHSA-hg2p-7794-g6x3/GHSA-hg2p-7794-g6x3.json new file mode 100644 index 00000000000..34bef9a9b67 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-hg2p-7794-g6x3/GHSA-hg2p-7794-g6x3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hg2p-7794-g6x3", + "modified": "2025-02-06T15:32:53Z", + "published": "2025-02-06T15:32:53Z", + "aliases": [ + "CVE-2025-1076" + ], + "details": "A Stored Cross-Site Scripting (Stored XSS) vulnerability has been found in the Holded application. This vulnerability could allow an attacker to store a JavaScript payload within the editable ‘name’ and ‘icon’ parameters of the Activities functionality.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1076" + }, + { + "type": "WEB", + "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/stored-cross-site-scripting-vulnerability-holded" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-06T14:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-hgwc-25jp-vvqf/GHSA-hgwc-25jp-vvqf.json b/advisories/unreviewed/2025/02/GHSA-hgwc-25jp-vvqf/GHSA-hgwc-25jp-vvqf.json new file mode 100644 index 00000000000..99b0160b572 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-hgwc-25jp-vvqf/GHSA-hgwc-25jp-vvqf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hgwc-25jp-vvqf", + "modified": "2025-02-06T15:32:53Z", + "published": "2025-02-06T15:32:53Z", + "aliases": [ + "CVE-2024-24911" + ], + "details": "In rare scenarios, the cpca process on the Security Management Server / Domain Management Server may exit unexpectedly, creating a core dump file. When the cpca process is down, VPN and SIC connectivity issues may occur if the CRL is not present in the Security Gateway's CRL cache.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-24911" + }, + { + "type": "WEB", + "url": "https://support.checkpoint.com/results/sk/sk183101" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-06T14:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-hmf6-8vmc-33g5/GHSA-hmf6-8vmc-33g5.json b/advisories/unreviewed/2025/02/GHSA-hmf6-8vmc-33g5/GHSA-hmf6-8vmc-33g5.json new file mode 100644 index 00000000000..6ce59cac1d3 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-hmf6-8vmc-33g5/GHSA-hmf6-8vmc-33g5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hmf6-8vmc-33g5", + "modified": "2025-02-06T15:32:52Z", + "published": "2025-02-06T15:32:52Z", + "aliases": [ + "CVE-2024-57957" + ], + "details": "Vulnerability of improper log information control in the UI framework module\nImpact: Successful exploitation of this vulnerability may affect service confidentiality.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57957" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2025/2" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-657" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-06T13:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-mg63-673f-rg9p/GHSA-mg63-673f-rg9p.json b/advisories/unreviewed/2025/02/GHSA-mg63-673f-rg9p/GHSA-mg63-673f-rg9p.json new file mode 100644 index 00000000000..e15c2a0cacd --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-mg63-673f-rg9p/GHSA-mg63-673f-rg9p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mg63-673f-rg9p", + "modified": "2025-02-06T15:32:52Z", + "published": "2025-02-06T15:32:52Z", + "aliases": [ + "CVE-2024-12602" + ], + "details": "Identity verification vulnerability in the ParamWatcher module\nImpact: Successful exploitation of this vulnerability may affect service confidentiality.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12602" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2025/2" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-300" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-06T13:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-mx24-hwqm-5vf7/GHSA-mx24-hwqm-5vf7.json b/advisories/unreviewed/2025/02/GHSA-mx24-hwqm-5vf7/GHSA-mx24-hwqm-5vf7.json new file mode 100644 index 00000000000..2b388181a9f --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-mx24-hwqm-5vf7/GHSA-mx24-hwqm-5vf7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mx24-hwqm-5vf7", + "modified": "2025-02-06T15:32:52Z", + "published": "2025-02-06T15:32:52Z", + "aliases": [ + "CVE-2024-57959" + ], + "details": "Use-After-Free (UAF) vulnerability in the display module\nImpact: Successful exploitation of this vulnerability may cause features to perform abnormally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57959" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2025/2" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-06T13:15:40Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-pc47-g7gv-4gpw/GHSA-pc47-g7gv-4gpw.json b/advisories/unreviewed/2025/02/GHSA-pc47-g7gv-4gpw/GHSA-pc47-g7gv-4gpw.json index e9c93c0c5e3..ad47ccf5c84 100644 --- a/advisories/unreviewed/2025/02/GHSA-pc47-g7gv-4gpw/GHSA-pc47-g7gv-4gpw.json +++ b/advisories/unreviewed/2025/02/GHSA-pc47-g7gv-4gpw/GHSA-pc47-g7gv-4gpw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pc47-g7gv-4gpw", - "modified": "2025-02-06T06:31:26Z", + "modified": "2025-02-06T15:32:52Z", "published": "2025-02-06T06:31:26Z", "aliases": [ "CVE-2024-57082" ], "details": "A prototype pollution in the lib.createUploader function of @rpldy/uploader v1.8.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-1321" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-05T22:15:32Z" diff --git a/advisories/unreviewed/2025/02/GHSA-pm4j-w673-3p6x/GHSA-pm4j-w673-3p6x.json b/advisories/unreviewed/2025/02/GHSA-pm4j-w673-3p6x/GHSA-pm4j-w673-3p6x.json index 0f15e6577a2..1e23e2e86fc 100644 --- a/advisories/unreviewed/2025/02/GHSA-pm4j-w673-3p6x/GHSA-pm4j-w673-3p6x.json +++ b/advisories/unreviewed/2025/02/GHSA-pm4j-w673-3p6x/GHSA-pm4j-w673-3p6x.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pm4j-w673-3p6x", - "modified": "2025-02-06T06:31:26Z", + "modified": "2025-02-06T15:32:52Z", "published": "2025-02-06T06:31:26Z", "aliases": [ "CVE-2025-0522" ], "details": "The LikeBot WordPress plugin through 0.85 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-06T06:15:30Z" diff --git a/advisories/unreviewed/2025/02/GHSA-qqpw-72j3-h9jj/GHSA-qqpw-72j3-h9jj.json b/advisories/unreviewed/2025/02/GHSA-qqpw-72j3-h9jj/GHSA-qqpw-72j3-h9jj.json index 3da0189a44f..3d924ef07b4 100644 --- a/advisories/unreviewed/2025/02/GHSA-qqpw-72j3-h9jj/GHSA-qqpw-72j3-h9jj.json +++ b/advisories/unreviewed/2025/02/GHSA-qqpw-72j3-h9jj/GHSA-qqpw-72j3-h9jj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qqpw-72j3-h9jj", - "modified": "2025-02-06T09:31:46Z", + "modified": "2025-02-06T15:32:52Z", "published": "2025-02-06T09:31:46Z", "aliases": [ "CVE-2024-13487" diff --git a/advisories/unreviewed/2025/02/GHSA-r5mv-57ph-669q/GHSA-r5mv-57ph-669q.json b/advisories/unreviewed/2025/02/GHSA-r5mv-57ph-669q/GHSA-r5mv-57ph-669q.json new file mode 100644 index 00000000000..82074fe7fec --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-r5mv-57ph-669q/GHSA-r5mv-57ph-669q.json @@ -0,0 +1,31 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r5mv-57ph-669q", + "modified": "2025-02-06T15:32:53Z", + "published": "2025-02-06T15:32:53Z", + "aliases": [ + "CVE-2022-31764" + ], + "details": "The Lite UI of Apache ShardingSphere ElasticJob-UI allows an attacker to perform RCE by constructing a special JDBC URL of H2 database. This issue affects Apache ShardingSphere ElasticJob-UI version 3.0.1 and prior versions. This vulnerability has been fixed in ElasticJob-UI 3.0.2.\nThe premise of this attack is that the attacker has obtained the account and password. Otherwise, the attacker cannot perform this attack.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-31764" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/pg0k223m4hsnnzg4nh7lxvdxxgbkrlqb" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-913" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-06T15:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-r7jx-5m6m-cpg9/GHSA-r7jx-5m6m-cpg9.json b/advisories/unreviewed/2025/02/GHSA-r7jx-5m6m-cpg9/GHSA-r7jx-5m6m-cpg9.json index 26b931e5d83..53841296395 100644 --- a/advisories/unreviewed/2025/02/GHSA-r7jx-5m6m-cpg9/GHSA-r7jx-5m6m-cpg9.json +++ b/advisories/unreviewed/2025/02/GHSA-r7jx-5m6m-cpg9/GHSA-r7jx-5m6m-cpg9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-r7jx-5m6m-cpg9", - "modified": "2025-02-06T06:31:26Z", + "modified": "2025-02-06T15:32:52Z", "published": "2025-02-06T06:31:26Z", "aliases": [ "CVE-2024-57075" ], "details": "A prototype pollution in the lib.Logger function of eazy-logger v4.0.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-1321" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-05T22:15:31Z" diff --git a/advisories/unreviewed/2025/02/GHSA-v37g-gf72-65f5/GHSA-v37g-gf72-65f5.json b/advisories/unreviewed/2025/02/GHSA-v37g-gf72-65f5/GHSA-v37g-gf72-65f5.json new file mode 100644 index 00000000000..16ebf86091c --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-v37g-gf72-65f5/GHSA-v37g-gf72-65f5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v37g-gf72-65f5", + "modified": "2025-02-06T15:32:52Z", + "published": "2025-02-06T15:32:52Z", + "aliases": [ + "CVE-2024-57956" + ], + "details": "Out-of-bounds read vulnerability in the interpreter string module\nImpact: Successful exploitation of this vulnerability may affect availability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57956" + }, + { + "type": "WEB", + "url": "https://consumer.huawei.com/en/support/bulletin/2025/2" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-680" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-06T13:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-v55m-3w98-233j/GHSA-v55m-3w98-233j.json b/advisories/unreviewed/2025/02/GHSA-v55m-3w98-233j/GHSA-v55m-3w98-233j.json index 0df494320f1..621078918df 100644 --- a/advisories/unreviewed/2025/02/GHSA-v55m-3w98-233j/GHSA-v55m-3w98-233j.json +++ b/advisories/unreviewed/2025/02/GHSA-v55m-3w98-233j/GHSA-v55m-3w98-233j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-v55m-3w98-233j", - "modified": "2025-02-06T06:31:26Z", + "modified": "2025-02-06T15:32:52Z", "published": "2025-02-06T06:31:26Z", "aliases": [ "CVE-2024-57081" ], "details": "A prototype pollution in the lib.fromQuery function of underscore-contrib v0.3.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-1321" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-05T22:15:32Z" diff --git a/advisories/unreviewed/2025/02/GHSA-vg5c-jm85-v84v/GHSA-vg5c-jm85-v84v.json b/advisories/unreviewed/2025/02/GHSA-vg5c-jm85-v84v/GHSA-vg5c-jm85-v84v.json index 7238fc31426..92a77c64d55 100644 --- a/advisories/unreviewed/2025/02/GHSA-vg5c-jm85-v84v/GHSA-vg5c-jm85-v84v.json +++ b/advisories/unreviewed/2025/02/GHSA-vg5c-jm85-v84v/GHSA-vg5c-jm85-v84v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vg5c-jm85-v84v", - "modified": "2025-02-05T03:32:13Z", + "modified": "2025-02-06T15:32:52Z", "published": "2025-02-05T00:31:13Z", "aliases": [ "CVE-2024-13723" ], "details": "The \"NagVis\" component within Checkmk is vulnerable to remote code execution. An authenticated attacker with administrative level privileges is able to upload a malicious PHP file and modify specific settings to execute the contents of the file as PHP.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -39,7 +44,7 @@ "cwe_ids": [ "CWE-434" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-04T22:15:40Z" diff --git a/advisories/unreviewed/2025/02/GHSA-vrfh-ph2r-gxr9/GHSA-vrfh-ph2r-gxr9.json b/advisories/unreviewed/2025/02/GHSA-vrfh-ph2r-gxr9/GHSA-vrfh-ph2r-gxr9.json index 214430cca0b..f2c628663f7 100644 --- a/advisories/unreviewed/2025/02/GHSA-vrfh-ph2r-gxr9/GHSA-vrfh-ph2r-gxr9.json +++ b/advisories/unreviewed/2025/02/GHSA-vrfh-ph2r-gxr9/GHSA-vrfh-ph2r-gxr9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vrfh-ph2r-gxr9", - "modified": "2025-02-06T06:31:26Z", + "modified": "2025-02-06T15:32:52Z", "published": "2025-02-06T06:31:26Z", "aliases": [ "CVE-2024-57076" ], "details": "A prototype pollution in the lib.post function of ajax-request v1.2.3 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-1321" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-05T22:15:31Z"