From 8859de588adc6647d2c559108b1add151fe00bc7 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 26 Feb 2025 18:32:33 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-4gcf-523q-9gmp.json | 3 +- .../GHSA-5rrh-5q4p-7p4x.json | 2 +- .../GHSA-85q7-h847-vf82.json | 14 +++++- .../GHSA-8jmw-qhrj-j54v.json | 4 +- .../GHSA-8xwh-69g8-mr3r.json | 2 +- .../GHSA-c9qp-jr36-5vxw.json | 2 +- .../GHSA-cfq4-hg5x-x4r5.json | 2 +- .../GHSA-gxq9-mjwg-92mf.json | 4 +- .../GHSA-j658-jwc9-69qv.json | 6 ++- .../GHSA-jm4q-f3h3-j5cf.json | 2 +- .../GHSA-qjr7-px55-gpcc.json | 14 +++++- .../GHSA-qwhm-4rh7-6qr6.json | 14 +++++- .../GHSA-qwv6-2vxv-h2vg.json | 4 +- .../GHSA-r9mc-9qw4-qm7r.json | 6 ++- .../GHSA-vxx2-f897-g654.json | 2 +- .../GHSA-wm53-7w82-c6x3.json | 14 +++++- .../GHSA-p72q-v88c-rprq.json | 2 +- .../GHSA-fvm8-pgm7-cg8j.json | 4 +- .../GHSA-4fwr-mh5q-hchh.json | 40 +++++++++++++++++ .../GHSA-4q44-89v6-r47v.json | 34 ++++++++++++++ .../GHSA-62xm-fg6r-jmpc.json | 36 +++++++++++++++ .../GHSA-67vp-c4w5-vvmh.json | 44 +++++++++++++++++++ .../GHSA-727m-hgm4-397c.json | 34 ++++++++++++++ .../GHSA-74v8-fv3x-8rq3.json | 36 +++++++++++++++ .../GHSA-7c47-rxv3-c2fv.json | 34 ++++++++++++++ .../GHSA-7hc3-j2x7-vm7q.json | 36 +++++++++++++++ .../GHSA-7jc8-c5qp-jxfp.json | 34 ++++++++++++++ .../GHSA-8mxc-vqrq-gcm8.json | 29 ++++++++++++ .../GHSA-9mmv-7xvp-7q48.json | 34 ++++++++++++++ .../GHSA-fj42-7xm3-95v2.json | 36 +++++++++++++++ .../GHSA-gxwp-4448-26fp.json | 34 ++++++++++++++ .../GHSA-hgqp-f75h-6p8r.json | 36 +++++++++++++++ .../GHSA-jcr3-f52g-5gj4.json | 36 +++++++++++++++ .../GHSA-mrrm-jfxh-4cwj.json | 34 ++++++++++++++ .../GHSA-pq8f-mw6x-f2j2.json | 29 ++++++++++++ .../GHSA-q737-5cw3-3g78.json | 36 +++++++++++++++ .../GHSA-rjgv-6mwj-prq2.json | 6 ++- .../GHSA-v9mp-cw5f-943w.json | 34 ++++++++++++++ .../GHSA-wc27-6x2h-q38w.json | 36 +++++++++++++++ 39 files changed, 788 insertions(+), 21 deletions(-) create mode 100644 advisories/unreviewed/2025/02/GHSA-4fwr-mh5q-hchh/GHSA-4fwr-mh5q-hchh.json create mode 100644 advisories/unreviewed/2025/02/GHSA-4q44-89v6-r47v/GHSA-4q44-89v6-r47v.json create mode 100644 advisories/unreviewed/2025/02/GHSA-62xm-fg6r-jmpc/GHSA-62xm-fg6r-jmpc.json create mode 100644 advisories/unreviewed/2025/02/GHSA-67vp-c4w5-vvmh/GHSA-67vp-c4w5-vvmh.json create mode 100644 advisories/unreviewed/2025/02/GHSA-727m-hgm4-397c/GHSA-727m-hgm4-397c.json create mode 100644 advisories/unreviewed/2025/02/GHSA-74v8-fv3x-8rq3/GHSA-74v8-fv3x-8rq3.json create mode 100644 advisories/unreviewed/2025/02/GHSA-7c47-rxv3-c2fv/GHSA-7c47-rxv3-c2fv.json create mode 100644 advisories/unreviewed/2025/02/GHSA-7hc3-j2x7-vm7q/GHSA-7hc3-j2x7-vm7q.json create mode 100644 advisories/unreviewed/2025/02/GHSA-7jc8-c5qp-jxfp/GHSA-7jc8-c5qp-jxfp.json create mode 100644 advisories/unreviewed/2025/02/GHSA-8mxc-vqrq-gcm8/GHSA-8mxc-vqrq-gcm8.json create mode 100644 advisories/unreviewed/2025/02/GHSA-9mmv-7xvp-7q48/GHSA-9mmv-7xvp-7q48.json create mode 100644 advisories/unreviewed/2025/02/GHSA-fj42-7xm3-95v2/GHSA-fj42-7xm3-95v2.json create mode 100644 advisories/unreviewed/2025/02/GHSA-gxwp-4448-26fp/GHSA-gxwp-4448-26fp.json create mode 100644 advisories/unreviewed/2025/02/GHSA-hgqp-f75h-6p8r/GHSA-hgqp-f75h-6p8r.json create mode 100644 advisories/unreviewed/2025/02/GHSA-jcr3-f52g-5gj4/GHSA-jcr3-f52g-5gj4.json create mode 100644 advisories/unreviewed/2025/02/GHSA-mrrm-jfxh-4cwj/GHSA-mrrm-jfxh-4cwj.json create mode 100644 advisories/unreviewed/2025/02/GHSA-pq8f-mw6x-f2j2/GHSA-pq8f-mw6x-f2j2.json create mode 100644 advisories/unreviewed/2025/02/GHSA-q737-5cw3-3g78/GHSA-q737-5cw3-3g78.json create mode 100644 advisories/unreviewed/2025/02/GHSA-v9mp-cw5f-943w/GHSA-v9mp-cw5f-943w.json create mode 100644 advisories/unreviewed/2025/02/GHSA-wc27-6x2h-q38w/GHSA-wc27-6x2h-q38w.json diff --git a/advisories/unreviewed/2023/03/GHSA-4gcf-523q-9gmp/GHSA-4gcf-523q-9gmp.json b/advisories/unreviewed/2023/03/GHSA-4gcf-523q-9gmp/GHSA-4gcf-523q-9gmp.json index 0030de55bc7..f30f84c36d2 100644 --- a/advisories/unreviewed/2023/03/GHSA-4gcf-523q-9gmp/GHSA-4gcf-523q-9gmp.json +++ b/advisories/unreviewed/2023/03/GHSA-4gcf-523q-9gmp/GHSA-4gcf-523q-9gmp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4gcf-523q-9gmp", - "modified": "2023-03-28T00:34:27Z", + "modified": "2025-02-26T18:30:37Z", "published": "2023-03-21T21:30:19Z", "aliases": [ "CVE-2023-0391" @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-321", "CWE-798" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/03/GHSA-5rrh-5q4p-7p4x/GHSA-5rrh-5q4p-7p4x.json b/advisories/unreviewed/2023/03/GHSA-5rrh-5q4p-7p4x/GHSA-5rrh-5q4p-7p4x.json index f76f9dd6e62..24038640499 100644 --- a/advisories/unreviewed/2023/03/GHSA-5rrh-5q4p-7p4x/GHSA-5rrh-5q4p-7p4x.json +++ b/advisories/unreviewed/2023/03/GHSA-5rrh-5q4p-7p4x/GHSA-5rrh-5q4p-7p4x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5rrh-5q4p-7p4x", - "modified": "2023-03-24T21:30:53Z", + "modified": "2025-02-26T18:30:37Z", "published": "2023-03-21T18:30:20Z", "aliases": [ "CVE-2023-27570" diff --git a/advisories/unreviewed/2023/03/GHSA-85q7-h847-vf82/GHSA-85q7-h847-vf82.json b/advisories/unreviewed/2023/03/GHSA-85q7-h847-vf82/GHSA-85q7-h847-vf82.json index 7576e9a87d0..a0085fd38a9 100644 --- a/advisories/unreviewed/2023/03/GHSA-85q7-h847-vf82/GHSA-85q7-h847-vf82.json +++ b/advisories/unreviewed/2023/03/GHSA-85q7-h847-vf82/GHSA-85q7-h847-vf82.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-85q7-h847-vf82", - "modified": "2023-03-23T18:30:18Z", + "modified": "2025-02-26T18:30:36Z", "published": "2023-03-16T15:30:19Z", "aliases": [ "CVE-2023-27787" @@ -23,6 +23,18 @@ "type": "WEB", "url": "https://github.com/appneta/tcpreplay/issues/788" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R3ER3YTFR3XIDMYEB7LMFWFTPVQALBHC" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UE3J4LKYFNKPKNSLDQK4JG36THQMQH3V" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UK2BRH3W3ECF5FDXP6QM3ZEDTHIOE4M5" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/R3ER3YTFR3XIDMYEB7LMFWFTPVQALBHC" diff --git a/advisories/unreviewed/2023/03/GHSA-8jmw-qhrj-j54v/GHSA-8jmw-qhrj-j54v.json b/advisories/unreviewed/2023/03/GHSA-8jmw-qhrj-j54v/GHSA-8jmw-qhrj-j54v.json index 13c24913422..fe4f79cbe43 100644 --- a/advisories/unreviewed/2023/03/GHSA-8jmw-qhrj-j54v/GHSA-8jmw-qhrj-j54v.json +++ b/advisories/unreviewed/2023/03/GHSA-8jmw-qhrj-j54v/GHSA-8jmw-qhrj-j54v.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/03/GHSA-8xwh-69g8-mr3r/GHSA-8xwh-69g8-mr3r.json b/advisories/unreviewed/2023/03/GHSA-8xwh-69g8-mr3r/GHSA-8xwh-69g8-mr3r.json index 10ff07f4a91..9a3d852bd09 100644 --- a/advisories/unreviewed/2023/03/GHSA-8xwh-69g8-mr3r/GHSA-8xwh-69g8-mr3r.json +++ b/advisories/unreviewed/2023/03/GHSA-8xwh-69g8-mr3r/GHSA-8xwh-69g8-mr3r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8xwh-69g8-mr3r", - "modified": "2023-03-28T18:30:29Z", + "modified": "2025-02-26T18:30:37Z", "published": "2023-03-21T18:30:20Z", "aliases": [ "CVE-2023-1306" diff --git a/advisories/unreviewed/2023/03/GHSA-c9qp-jr36-5vxw/GHSA-c9qp-jr36-5vxw.json b/advisories/unreviewed/2023/03/GHSA-c9qp-jr36-5vxw/GHSA-c9qp-jr36-5vxw.json index 55d011dfc52..b41b49a6b25 100644 --- a/advisories/unreviewed/2023/03/GHSA-c9qp-jr36-5vxw/GHSA-c9qp-jr36-5vxw.json +++ b/advisories/unreviewed/2023/03/GHSA-c9qp-jr36-5vxw/GHSA-c9qp-jr36-5vxw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c9qp-jr36-5vxw", - "modified": "2023-03-24T06:30:16Z", + "modified": "2025-02-26T18:30:37Z", "published": "2023-03-22T15:30:20Z", "aliases": [ "CVE-2023-27637" diff --git a/advisories/unreviewed/2023/03/GHSA-cfq4-hg5x-x4r5/GHSA-cfq4-hg5x-x4r5.json b/advisories/unreviewed/2023/03/GHSA-cfq4-hg5x-x4r5/GHSA-cfq4-hg5x-x4r5.json index 3261cd5362b..ceaab60b2e3 100644 --- a/advisories/unreviewed/2023/03/GHSA-cfq4-hg5x-x4r5/GHSA-cfq4-hg5x-x4r5.json +++ b/advisories/unreviewed/2023/03/GHSA-cfq4-hg5x-x4r5/GHSA-cfq4-hg5x-x4r5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cfq4-hg5x-x4r5", - "modified": "2023-03-24T21:30:48Z", + "modified": "2025-02-26T18:30:37Z", "published": "2023-03-22T15:30:19Z", "aliases": [ "CVE-2022-4095" diff --git a/advisories/unreviewed/2023/03/GHSA-gxq9-mjwg-92mf/GHSA-gxq9-mjwg-92mf.json b/advisories/unreviewed/2023/03/GHSA-gxq9-mjwg-92mf/GHSA-gxq9-mjwg-92mf.json index f77cebae37c..b665d911be8 100644 --- a/advisories/unreviewed/2023/03/GHSA-gxq9-mjwg-92mf/GHSA-gxq9-mjwg-92mf.json +++ b/advisories/unreviewed/2023/03/GHSA-gxq9-mjwg-92mf/GHSA-gxq9-mjwg-92mf.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-94" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/03/GHSA-j658-jwc9-69qv/GHSA-j658-jwc9-69qv.json b/advisories/unreviewed/2023/03/GHSA-j658-jwc9-69qv/GHSA-j658-jwc9-69qv.json index 0a65b45dc03..e4fe83cbc8b 100644 --- a/advisories/unreviewed/2023/03/GHSA-j658-jwc9-69qv/GHSA-j658-jwc9-69qv.json +++ b/advisories/unreviewed/2023/03/GHSA-j658-jwc9-69qv/GHSA-j658-jwc9-69qv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j658-jwc9-69qv", - "modified": "2023-03-28T21:30:20Z", + "modified": "2025-02-26T18:30:38Z", "published": "2023-03-23T00:30:16Z", "aliases": [ "CVE-2023-27060" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-306" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/03/GHSA-jm4q-f3h3-j5cf/GHSA-jm4q-f3h3-j5cf.json b/advisories/unreviewed/2023/03/GHSA-jm4q-f3h3-j5cf/GHSA-jm4q-f3h3-j5cf.json index 49ed1bdd3f9..36d67c98fa1 100644 --- a/advisories/unreviewed/2023/03/GHSA-jm4q-f3h3-j5cf/GHSA-jm4q-f3h3-j5cf.json +++ b/advisories/unreviewed/2023/03/GHSA-jm4q-f3h3-j5cf/GHSA-jm4q-f3h3-j5cf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jm4q-f3h3-j5cf", - "modified": "2023-03-24T06:30:16Z", + "modified": "2025-02-26T18:30:37Z", "published": "2023-03-22T15:30:20Z", "aliases": [ "CVE-2023-27638" diff --git a/advisories/unreviewed/2023/03/GHSA-qjr7-px55-gpcc/GHSA-qjr7-px55-gpcc.json b/advisories/unreviewed/2023/03/GHSA-qjr7-px55-gpcc/GHSA-qjr7-px55-gpcc.json index 0cbfd2a45ed..5b35b43431b 100644 --- a/advisories/unreviewed/2023/03/GHSA-qjr7-px55-gpcc/GHSA-qjr7-px55-gpcc.json +++ b/advisories/unreviewed/2023/03/GHSA-qjr7-px55-gpcc/GHSA-qjr7-px55-gpcc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qjr7-px55-gpcc", - "modified": "2023-03-23T18:30:18Z", + "modified": "2025-02-26T18:30:36Z", "published": "2023-03-16T15:30:19Z", "aliases": [ "CVE-2023-27788" @@ -23,6 +23,18 @@ "type": "WEB", "url": "https://github.com/appneta/tcpreplay/issues/786" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R3ER3YTFR3XIDMYEB7LMFWFTPVQALBHC" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UE3J4LKYFNKPKNSLDQK4JG36THQMQH3V" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UK2BRH3W3ECF5FDXP6QM3ZEDTHIOE4M5" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/R3ER3YTFR3XIDMYEB7LMFWFTPVQALBHC" diff --git a/advisories/unreviewed/2023/03/GHSA-qwhm-4rh7-6qr6/GHSA-qwhm-4rh7-6qr6.json b/advisories/unreviewed/2023/03/GHSA-qwhm-4rh7-6qr6/GHSA-qwhm-4rh7-6qr6.json index 209edf215a7..c0c9d5d4d33 100644 --- a/advisories/unreviewed/2023/03/GHSA-qwhm-4rh7-6qr6/GHSA-qwhm-4rh7-6qr6.json +++ b/advisories/unreviewed/2023/03/GHSA-qwhm-4rh7-6qr6/GHSA-qwhm-4rh7-6qr6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qwhm-4rh7-6qr6", - "modified": "2023-03-23T18:30:17Z", + "modified": "2025-02-26T18:30:36Z", "published": "2023-03-16T15:30:19Z", "aliases": [ "CVE-2023-27786" @@ -27,6 +27,18 @@ "type": "WEB", "url": "https://github.com/appneta/tcpreplay/pull/783" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R3ER3YTFR3XIDMYEB7LMFWFTPVQALBHC" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UE3J4LKYFNKPKNSLDQK4JG36THQMQH3V" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UK2BRH3W3ECF5FDXP6QM3ZEDTHIOE4M5" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/R3ER3YTFR3XIDMYEB7LMFWFTPVQALBHC" diff --git a/advisories/unreviewed/2023/03/GHSA-qwv6-2vxv-h2vg/GHSA-qwv6-2vxv-h2vg.json b/advisories/unreviewed/2023/03/GHSA-qwv6-2vxv-h2vg/GHSA-qwv6-2vxv-h2vg.json index 19f1d4de2a2..22416cd5729 100644 --- a/advisories/unreviewed/2023/03/GHSA-qwv6-2vxv-h2vg/GHSA-qwv6-2vxv-h2vg.json +++ b/advisories/unreviewed/2023/03/GHSA-qwv6-2vxv-h2vg/GHSA-qwv6-2vxv-h2vg.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-77" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/03/GHSA-r9mc-9qw4-qm7r/GHSA-r9mc-9qw4-qm7r.json b/advisories/unreviewed/2023/03/GHSA-r9mc-9qw4-qm7r/GHSA-r9mc-9qw4-qm7r.json index 69084cfb93d..03448a1c51b 100644 --- a/advisories/unreviewed/2023/03/GHSA-r9mc-9qw4-qm7r/GHSA-r9mc-9qw4-qm7r.json +++ b/advisories/unreviewed/2023/03/GHSA-r9mc-9qw4-qm7r/GHSA-r9mc-9qw4-qm7r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r9mc-9qw4-qm7r", - "modified": "2023-03-27T15:30:17Z", + "modified": "2025-02-26T18:30:36Z", "published": "2023-03-21T15:30:15Z", "aliases": [ "CVE-2023-27842" @@ -41,7 +41,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-277" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/03/GHSA-vxx2-f897-g654/GHSA-vxx2-f897-g654.json b/advisories/unreviewed/2023/03/GHSA-vxx2-f897-g654/GHSA-vxx2-f897-g654.json index 13b20984da6..5d2342d6d04 100644 --- a/advisories/unreviewed/2023/03/GHSA-vxx2-f897-g654/GHSA-vxx2-f897-g654.json +++ b/advisories/unreviewed/2023/03/GHSA-vxx2-f897-g654/GHSA-vxx2-f897-g654.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vxx2-f897-g654", - "modified": "2023-03-28T00:34:27Z", + "modified": "2025-02-26T18:30:37Z", "published": "2023-03-22T00:30:19Z", "aliases": [ "CVE-2023-28725" diff --git a/advisories/unreviewed/2023/03/GHSA-wm53-7w82-c6x3/GHSA-wm53-7w82-c6x3.json b/advisories/unreviewed/2023/03/GHSA-wm53-7w82-c6x3/GHSA-wm53-7w82-c6x3.json index 7637c24fa68..ca49f003f3f 100644 --- a/advisories/unreviewed/2023/03/GHSA-wm53-7w82-c6x3/GHSA-wm53-7w82-c6x3.json +++ b/advisories/unreviewed/2023/03/GHSA-wm53-7w82-c6x3/GHSA-wm53-7w82-c6x3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wm53-7w82-c6x3", - "modified": "2023-03-23T18:30:18Z", + "modified": "2025-02-26T18:30:36Z", "published": "2023-03-16T15:30:19Z", "aliases": [ "CVE-2023-27789" @@ -27,6 +27,18 @@ "type": "WEB", "url": "https://github.com/appneta/tcpreplay/pull/783" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R3ER3YTFR3XIDMYEB7LMFWFTPVQALBHC" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UE3J4LKYFNKPKNSLDQK4JG36THQMQH3V" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UK2BRH3W3ECF5FDXP6QM3ZEDTHIOE4M5" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/R3ER3YTFR3XIDMYEB7LMFWFTPVQALBHC" diff --git a/advisories/unreviewed/2023/07/GHSA-p72q-v88c-rprq/GHSA-p72q-v88c-rprq.json b/advisories/unreviewed/2023/07/GHSA-p72q-v88c-rprq/GHSA-p72q-v88c-rprq.json index 11f75e6fa26..aac299878c2 100644 --- a/advisories/unreviewed/2023/07/GHSA-p72q-v88c-rprq/GHSA-p72q-v88c-rprq.json +++ b/advisories/unreviewed/2023/07/GHSA-p72q-v88c-rprq/GHSA-p72q-v88c-rprq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p72q-v88c-rprq", - "modified": "2024-06-27T12:30:42Z", + "modified": "2025-02-26T18:30:37Z", "published": "2023-07-06T19:24:12Z", "aliases": [ "CVE-2023-0386" diff --git a/advisories/unreviewed/2024/04/GHSA-fvm8-pgm7-cg8j/GHSA-fvm8-pgm7-cg8j.json b/advisories/unreviewed/2024/04/GHSA-fvm8-pgm7-cg8j/GHSA-fvm8-pgm7-cg8j.json index 486ed0d6695..a4ac7361d92 100644 --- a/advisories/unreviewed/2024/04/GHSA-fvm8-pgm7-cg8j/GHSA-fvm8-pgm7-cg8j.json +++ b/advisories/unreviewed/2024/04/GHSA-fvm8-pgm7-cg8j/GHSA-fvm8-pgm7-cg8j.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-35" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/02/GHSA-4fwr-mh5q-hchh/GHSA-4fwr-mh5q-hchh.json b/advisories/unreviewed/2025/02/GHSA-4fwr-mh5q-hchh/GHSA-4fwr-mh5q-hchh.json new file mode 100644 index 00000000000..99814c0d3ad --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-4fwr-mh5q-hchh/GHSA-4fwr-mh5q-hchh.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4fwr-mh5q-hchh", + "modified": "2025-02-26T18:30:39Z", + "published": "2025-02-26T18:30:39Z", + "aliases": [ + "CVE-2025-1634" + ], + "details": "A flaw was found in the quarkus-resteasy extension, which causes memory leaks when client requests with low timeouts are made. If a client request times out, a buffer is not released correctly, leading to increased memory usage and eventual application crash due to OutOfMemoryError.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1634" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2025-1634" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2347319" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-401" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T17:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-4q44-89v6-r47v/GHSA-4q44-89v6-r47v.json b/advisories/unreviewed/2025/02/GHSA-4q44-89v6-r47v/GHSA-4q44-89v6-r47v.json new file mode 100644 index 00000000000..bb8582f1e66 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-4q44-89v6-r47v/GHSA-4q44-89v6-r47v.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4q44-89v6-r47v", + "modified": "2025-02-26T18:30:38Z", + "published": "2025-02-26T18:30:38Z", + "aliases": [ + "CVE-2024-13631" + ], + "details": "The Om Stripe WordPress plugin through 02.00.00 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13631" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/c991fdd0-cb9d-43ea-bafa-df3b2e806013" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T13:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-62xm-fg6r-jmpc/GHSA-62xm-fg6r-jmpc.json b/advisories/unreviewed/2025/02/GHSA-62xm-fg6r-jmpc/GHSA-62xm-fg6r-jmpc.json new file mode 100644 index 00000000000..3a031a275cb --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-62xm-fg6r-jmpc/GHSA-62xm-fg6r-jmpc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-62xm-fg6r-jmpc", + "modified": "2025-02-26T18:30:39Z", + "published": "2025-02-26T18:30:39Z", + "aliases": [ + "CVE-2025-20119" + ], + "details": "A vulnerability in the system file permission handling of Cisco APIC could allow an authenticated, local attacker to overwrite critical system files, which could cause a DoS condition. To exploit this vulnerability, the attacker must have valid administrative credentials.\n\nThis vulnerability is due to a race condition with handling system files. An attacker could exploit this vulnerability by doing specific operations on the file system. A successful exploit could allow the attacker to overwrite system files, which could lead to the device being in an inconsistent state and cause a DoS condition.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20119" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apic-multi-vulns-9ummtg5" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-362" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T17:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-67vp-c4w5-vvmh/GHSA-67vp-c4w5-vvmh.json b/advisories/unreviewed/2025/02/GHSA-67vp-c4w5-vvmh/GHSA-67vp-c4w5-vvmh.json new file mode 100644 index 00000000000..43e9e46bddc --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-67vp-c4w5-vvmh/GHSA-67vp-c4w5-vvmh.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-67vp-c4w5-vvmh", + "modified": "2025-02-26T18:30:38Z", + "published": "2025-02-26T18:30:38Z", + "aliases": [ + "CVE-2025-25800" + ], + "details": "SeaCMS 13.3 was discovered to contain an arbitrary file read vulnerability in the file_get_contents function at admin_safe_file.php.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25800" + }, + { + "type": "WEB", + "url": "https://github.com/Ka7arotto/Seacms/blob/main/Seacms13.3-lrf-2.md" + }, + { + "type": "WEB", + "url": "https://www.seacms.com" + }, + { + "type": "WEB", + "url": "http://seacms.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T15:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-727m-hgm4-397c/GHSA-727m-hgm4-397c.json b/advisories/unreviewed/2025/02/GHSA-727m-hgm4-397c/GHSA-727m-hgm4-397c.json new file mode 100644 index 00000000000..df4fa684629 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-727m-hgm4-397c/GHSA-727m-hgm4-397c.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-727m-hgm4-397c", + "modified": "2025-02-26T18:30:38Z", + "published": "2025-02-26T18:30:38Z", + "aliases": [ + "CVE-2024-10483" + ], + "details": "The Simple:Press Forum WordPress plugin before 6.10.11 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10483" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/c7e3c473-09b2-473b-87d7-0a01d8f52086" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T13:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-74v8-fv3x-8rq3/GHSA-74v8-fv3x-8rq3.json b/advisories/unreviewed/2025/02/GHSA-74v8-fv3x-8rq3/GHSA-74v8-fv3x-8rq3.json new file mode 100644 index 00000000000..72b163b7c11 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-74v8-fv3x-8rq3/GHSA-74v8-fv3x-8rq3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-74v8-fv3x-8rq3", + "modified": "2025-02-26T18:30:39Z", + "published": "2025-02-26T18:30:39Z", + "aliases": [ + "CVE-2025-0941" + ], + "details": "MET ONE 3400+ instruments running software v1.0.41 can, under rare conditions, temporarily store credentials in plain text within the system. This data is not available to unauthenticated users.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0941" + }, + { + "type": "WEB", + "url": "https://www.beckman.com/about-us/compliance/coordinated-vulnerability-disclosure/product-security-updates" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-209" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T17:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-7c47-rxv3-c2fv/GHSA-7c47-rxv3-c2fv.json b/advisories/unreviewed/2025/02/GHSA-7c47-rxv3-c2fv/GHSA-7c47-rxv3-c2fv.json new file mode 100644 index 00000000000..8d0ea691bd8 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-7c47-rxv3-c2fv/GHSA-7c47-rxv3-c2fv.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7c47-rxv3-c2fv", + "modified": "2025-02-26T18:30:38Z", + "published": "2025-02-26T18:30:38Z", + "aliases": [ + "CVE-2024-12878" + ], + "details": "The Custom Block Builder WordPress plugin before 3.8.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12878" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/827444d1-87cb-4057-827a-d802eac82cf8" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T13:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-7hc3-j2x7-vm7q/GHSA-7hc3-j2x7-vm7q.json b/advisories/unreviewed/2025/02/GHSA-7hc3-j2x7-vm7q/GHSA-7hc3-j2x7-vm7q.json new file mode 100644 index 00000000000..161f07c1489 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-7hc3-j2x7-vm7q/GHSA-7hc3-j2x7-vm7q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7hc3-j2x7-vm7q", + "modified": "2025-02-26T18:30:39Z", + "published": "2025-02-26T18:30:39Z", + "aliases": [ + "CVE-2025-20116" + ], + "details": "A vulnerability in the web UI of Cisco APIC could allow an authenticated, remote attacker to perform a stored XSS attack on an affected system. To exploit this vulnerability, the attacker must have valid administrative credentials.\n\nThis vulnerability is due to improper input validation in the web UI. An authenticated attacker could exploit this vulnerability by injecting malicious code into specific pages of the web UI. A successful exploit could allow the attacker to execute arbitrary script code in the context of the web UI or access sensitive, browser-based information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20116" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apic-multi-vulns-9ummtg5" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T17:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-7jc8-c5qp-jxfp/GHSA-7jc8-c5qp-jxfp.json b/advisories/unreviewed/2025/02/GHSA-7jc8-c5qp-jxfp/GHSA-7jc8-c5qp-jxfp.json new file mode 100644 index 00000000000..3c318b95df9 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-7jc8-c5qp-jxfp/GHSA-7jc8-c5qp-jxfp.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7jc8-c5qp-jxfp", + "modified": "2025-02-26T18:30:38Z", + "published": "2025-02-26T18:30:38Z", + "aliases": [ + "CVE-2024-13624" + ], + "details": "The WPMovieLibrary WordPress plugin through 2.1.4.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13624" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/c19b56cc-634f-420f-b6a0-9a10ad159049" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T13:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-8mxc-vqrq-gcm8/GHSA-8mxc-vqrq-gcm8.json b/advisories/unreviewed/2025/02/GHSA-8mxc-vqrq-gcm8/GHSA-8mxc-vqrq-gcm8.json new file mode 100644 index 00000000000..f98c1acceb3 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-8mxc-vqrq-gcm8/GHSA-8mxc-vqrq-gcm8.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8mxc-vqrq-gcm8", + "modified": "2025-02-26T18:30:38Z", + "published": "2025-02-26T18:30:38Z", + "aliases": [ + "CVE-2024-53427" + ], + "details": "jq v1.7.1 contains a stack-buffer-overflow in the decNumberCopy function within decNumber.c.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53427" + }, + { + "type": "WEB", + "url": "https://github.com/jqlang/jq/issues/3196" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T16:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-9mmv-7xvp-7q48/GHSA-9mmv-7xvp-7q48.json b/advisories/unreviewed/2025/02/GHSA-9mmv-7xvp-7q48/GHSA-9mmv-7xvp-7q48.json new file mode 100644 index 00000000000..0ce29085bc3 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-9mmv-7xvp-7q48/GHSA-9mmv-7xvp-7q48.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9mmv-7xvp-7q48", + "modified": "2025-02-26T18:30:38Z", + "published": "2025-02-26T18:30:38Z", + "aliases": [ + "CVE-2024-13571" + ], + "details": "The Post Timeline WordPress plugin before 2.3.10 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13571" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/ad6ad44d-fdc3-494c-a371-5d7959d1fd23" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T13:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-fj42-7xm3-95v2/GHSA-fj42-7xm3-95v2.json b/advisories/unreviewed/2025/02/GHSA-fj42-7xm3-95v2/GHSA-fj42-7xm3-95v2.json new file mode 100644 index 00000000000..0613ee7eb98 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-fj42-7xm3-95v2/GHSA-fj42-7xm3-95v2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fj42-7xm3-95v2", + "modified": "2025-02-26T18:30:39Z", + "published": "2025-02-26T18:30:39Z", + "aliases": [ + "CVE-2025-20117" + ], + "details": "A vulnerability in the CLI of Cisco APIC could allow an authenticated, local attacker to execute arbitrary commands as root on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials.\n\nThis vulnerability is due to insufficient validation of arguments that are passed to specific CLI commands. An attacker could exploit this vulnerability by including crafted input as the argument of an affected CLI command. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the privileges of root.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20117" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apic-multi-vulns-9ummtg5" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T17:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-gxwp-4448-26fp/GHSA-gxwp-4448-26fp.json b/advisories/unreviewed/2025/02/GHSA-gxwp-4448-26fp/GHSA-gxwp-4448-26fp.json new file mode 100644 index 00000000000..290a727878b --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-gxwp-4448-26fp/GHSA-gxwp-4448-26fp.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gxwp-4448-26fp", + "modified": "2025-02-26T18:30:38Z", + "published": "2025-02-26T18:30:38Z", + "aliases": [ + "CVE-2024-13113" + ], + "details": "The Countdown Timer for Elementor WordPress plugin before 1.3.7 does not sanitise and escape some parameters when outputting them on the page, which could allow users with a role as low as contributor to perform Cross-Site Scripting attacks.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13113" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/ffc31d9d-d245-4c4b-992d-394a01798117" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T13:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-hgqp-f75h-6p8r/GHSA-hgqp-f75h-6p8r.json b/advisories/unreviewed/2025/02/GHSA-hgqp-f75h-6p8r/GHSA-hgqp-f75h-6p8r.json new file mode 100644 index 00000000000..78f1c32db0b --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-hgqp-f75h-6p8r/GHSA-hgqp-f75h-6p8r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hgqp-f75h-6p8r", + "modified": "2025-02-26T18:30:39Z", + "published": "2025-02-26T18:30:39Z", + "aliases": [ + "CVE-2025-20118" + ], + "details": "A vulnerability in the implementation of the internal system processes of Cisco APIC could allow an authenticated, local attacker to access sensitive information on an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials.\n\nThis vulnerability is due to insufficient masking of sensitive information that is displayed through system CLI commands. An attacker could exploit this vulnerability by using reconnaissance techniques at the device CLI. A successful exploit could allow the attacker to access sensitive information on an affected device that could be used for additional attacks.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20118" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apic-multi-vulns-9ummtg5" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-212" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T17:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-jcr3-f52g-5gj4/GHSA-jcr3-f52g-5gj4.json b/advisories/unreviewed/2025/02/GHSA-jcr3-f52g-5gj4/GHSA-jcr3-f52g-5gj4.json new file mode 100644 index 00000000000..509283fc409 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-jcr3-f52g-5gj4/GHSA-jcr3-f52g-5gj4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jcr3-f52g-5gj4", + "modified": "2025-02-26T18:30:38Z", + "published": "2025-02-26T18:30:38Z", + "aliases": [ + "CVE-2024-46226" + ], + "details": "A stored cross site scripting (XSS) vulnerability in HelpDeskZ < v2.0.2 allows remote attackers to execute arbitrary JavaScript in the administration panel by including a malicious payload into the file name and upload file function when creating a new ticket.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-46226" + }, + { + "type": "WEB", + "url": "https://www.exploit-db.com/exploits/52068" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T16:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-mrrm-jfxh-4cwj/GHSA-mrrm-jfxh-4cwj.json b/advisories/unreviewed/2025/02/GHSA-mrrm-jfxh-4cwj/GHSA-mrrm-jfxh-4cwj.json new file mode 100644 index 00000000000..f7afab5b78a --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-mrrm-jfxh-4cwj/GHSA-mrrm-jfxh-4cwj.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mrrm-jfxh-4cwj", + "modified": "2025-02-26T18:30:38Z", + "published": "2025-02-26T18:30:38Z", + "aliases": [ + "CVE-2024-13632" + ], + "details": "The WP Extra Fields WordPress plugin through 1.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13632" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/85c5b465-afce-4c68-b5e3-214ec4b5c9f2" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T13:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-pq8f-mw6x-f2j2/GHSA-pq8f-mw6x-f2j2.json b/advisories/unreviewed/2025/02/GHSA-pq8f-mw6x-f2j2/GHSA-pq8f-mw6x-f2j2.json new file mode 100644 index 00000000000..2a6cbc518e7 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-pq8f-mw6x-f2j2/GHSA-pq8f-mw6x-f2j2.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pq8f-mw6x-f2j2", + "modified": "2025-02-26T18:30:38Z", + "published": "2025-02-26T18:30:38Z", + "aliases": [ + "CVE-2025-25462" + ], + "details": "A SQL Injection vulnerability was found in /admin/add-propertytype.php in PHPGurukul Land Record System Project in PHP v1.0 allows remote attackers to execute arbitrary code via the propertytype POST request parameter.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25462" + }, + { + "type": "WEB", + "url": "https://github.com/terrasystemlabs/CVE-IDs/blob/main/PHP-Gurukul/Land-record/Land_SQL_Injection.pdf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T16:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-q737-5cw3-3g78/GHSA-q737-5cw3-3g78.json b/advisories/unreviewed/2025/02/GHSA-q737-5cw3-3g78/GHSA-q737-5cw3-3g78.json new file mode 100644 index 00000000000..f425957b307 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-q737-5cw3-3g78/GHSA-q737-5cw3-3g78.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q737-5cw3-3g78", + "modified": "2025-02-26T18:30:39Z", + "published": "2025-02-26T18:30:39Z", + "aliases": [ + "CVE-2025-20111" + ], + "details": "A vulnerability in the health monitoring diagnostics of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, adjacent attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.\n\nThis vulnerability is due to the incorrect handling of specific Ethernet frames. An attacker could exploit this vulnerability by sending a sustained rate of crafted Ethernet frames to an affected device. A successful exploit could allow the attacker to cause the device to reload.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20111" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-n3kn9k-healthdos-eOqSWK4g" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1220" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T17:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-rjgv-6mwj-prq2/GHSA-rjgv-6mwj-prq2.json b/advisories/unreviewed/2025/02/GHSA-rjgv-6mwj-prq2/GHSA-rjgv-6mwj-prq2.json index 65300aa5259..efce41d479f 100644 --- a/advisories/unreviewed/2025/02/GHSA-rjgv-6mwj-prq2/GHSA-rjgv-6mwj-prq2.json +++ b/advisories/unreviewed/2025/02/GHSA-rjgv-6mwj-prq2/GHSA-rjgv-6mwj-prq2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rjgv-6mwj-prq2", - "modified": "2025-02-26T00:32:19Z", + "modified": "2025-02-26T18:30:38Z", "published": "2025-02-26T00:32:19Z", "aliases": [ "CVE-2025-22211" @@ -14,6 +14,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22211" }, + { + "type": "WEB", + "url": "https://github.com/AdamWallwork/CVEs/tree/main/2025/CVE-2025-22211" + }, { "type": "WEB", "url": "https://www.webdesigner-profi.de" diff --git a/advisories/unreviewed/2025/02/GHSA-v9mp-cw5f-943w/GHSA-v9mp-cw5f-943w.json b/advisories/unreviewed/2025/02/GHSA-v9mp-cw5f-943w/GHSA-v9mp-cw5f-943w.json new file mode 100644 index 00000000000..1c4b4ad9a06 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-v9mp-cw5f-943w/GHSA-v9mp-cw5f-943w.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v9mp-cw5f-943w", + "modified": "2025-02-26T18:30:38Z", + "published": "2025-02-26T18:30:38Z", + "aliases": [ + "CVE-2024-10152" + ], + "details": "The Simple Certain Time to Show Content WordPress plugin before 1.3.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10152" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/b4d17da2-4c47-4fd1-a6bd-6692b07cf710" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T13:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-wc27-6x2h-q38w/GHSA-wc27-6x2h-q38w.json b/advisories/unreviewed/2025/02/GHSA-wc27-6x2h-q38w/GHSA-wc27-6x2h-q38w.json new file mode 100644 index 00000000000..78614f3cd01 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-wc27-6x2h-q38w/GHSA-wc27-6x2h-q38w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wc27-6x2h-q38w", + "modified": "2025-02-26T18:30:39Z", + "published": "2025-02-26T18:30:39Z", + "aliases": [ + "CVE-2025-20161" + ], + "details": "A vulnerability in the software upgrade process of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an authenticated, local attacker with valid Administrator credentials to execute a command injection attack on the underlying operating system of an affected device.\n\nThis vulnerability is due to insufficient validation of specific elements within a software image. An attacker could exploit this vulnerability by installing a crafted image. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with root privileges. \nNote: Administrators should validate the hash of any software image before installation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-20161" + }, + { + "type": "WEB", + "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nxos-ici-dpOjbWxk" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T17:15:23Z" + } +} \ No newline at end of file