From 8bc8c1297a8a56c318974bd0f235010f1379834c Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 27 Mar 2025 21:32:03 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-2j3m-gwxg-45rx.json | 2 +- .../GHSA-f6h6-4v35-rxvq.json | 2 +- .../GHSA-h2v4-4v4p-2qvc.json | 2 +- .../GHSA-hppr-5p45-xr8c.json | 3 +- .../GHSA-jmj5-q6wr-x9v2.json | 2 +- .../GHSA-p8h8-37jj-3jqq.json | 2 +- .../GHSA-235p-3884-9g52.json | 4 +- .../GHSA-9w4v-2x3h-wxmw.json | 4 +- .../GHSA-fr5f-66rh-432p.json | 4 +- .../GHSA-fvh7-79fr-wwcg.json | 4 +- .../GHSA-mpjh-c64m-g538.json | 6 ++- .../GHSA-3v2h-jhg6-jj7v.json | 4 +- .../GHSA-cgpg-xpvx-xqxj.json | 4 +- .../GHSA-cqgm-hp7p-3m66.json | 3 +- .../GHSA-f3gj-969x-5q5x.json | 4 +- .../GHSA-frg3-hm7v-3rpf.json | 4 +- .../GHSA-h29x-5q67-v88m.json | 4 +- .../GHSA-j26p-3qqc-p3hw.json | 4 +- .../GHSA-3f88-vcg8-m5ph.json | 15 +++++-- .../GHSA-42vc-w257-pp26.json | 15 +++++-- .../GHSA-4466-5jhm-q8x8.json | 4 +- .../GHSA-4rxr-8xrx-9rf3.json | 4 +- .../GHSA-4xp8-3mc6-r83c.json | 6 ++- .../GHSA-54wh-fwqq-m49j.json | 8 ++-- .../GHSA-6276-35wc-6mcx.json | 15 +++++-- .../GHSA-6w43-jrpg-hc48.json | 15 +++++-- .../GHSA-7x8p-3pr3-73hp.json | 4 +- .../GHSA-7xrf-xg7m-8rqp.json | 15 +++++-- .../GHSA-8xjc-25qh-f5x2.json | 15 +++++-- .../GHSA-g6gj-xwhj-g7rm.json | 15 +++++-- .../GHSA-jv2q-4725-898c.json | 4 +- .../GHSA-ph77-97qp-2vrp.json | 11 +++-- .../GHSA-qr5m-2qmx-pvvm.json | 15 +++++-- .../GHSA-wgr7-wrhm-vcmg.json | 15 +++++-- .../GHSA-222x-r452-4688.json | 4 +- .../GHSA-2vvj-hm96-cr7r.json | 11 +++-- .../GHSA-3264-p6rp-pxp7.json | 11 +++-- .../GHSA-4jxh-5mmr-rhrf.json | 15 +++++-- .../GHSA-5gcf-h7r6-w82j.json | 11 +++-- .../GHSA-5r2r-xpfw-pmxc.json | 15 +++++-- .../GHSA-66fh-rmm8-p9q4.json | 11 +++-- .../GHSA-843f-6jw5-wr67.json | 15 +++++-- .../GHSA-84g6-j698-p58m.json | 15 +++++-- .../GHSA-87f6-4648-854h.json | 15 +++++-- .../GHSA-8c7c-3pvq-q9v3.json | 15 +++++-- .../GHSA-8fj4-3988-99m9.json | 15 +++++-- .../GHSA-8g9c-f7h3-mxcj.json | 4 +- .../GHSA-9w6w-gqmh-gxp9.json | 11 +++-- .../GHSA-c7qm-83h5-vx5f.json | 4 +- .../GHSA-c8fg-x59g-83c8.json | 11 +++-- .../GHSA-fqrj-wwq6-q94w.json | 11 +++-- .../GHSA-g77r-g63q-vjf8.json | 11 +++-- .../GHSA-gvmr-9xc2-m89g.json | 4 +- .../GHSA-gvqq-xg2j-r2p6.json | 4 +- .../GHSA-m59q-rgx4-6vq4.json | 15 +++++-- .../GHSA-mm47-557m-fxpp.json | 15 +++++-- .../GHSA-mw3g-jr7f-3gg4.json | 15 +++++-- .../GHSA-qfp6-v96m-74pc.json | 15 +++++-- .../GHSA-rg6q-wc9f-whjv.json | 15 +++++-- .../GHSA-rr47-vpr9-84rm.json | 15 +++++-- .../GHSA-vfr6-9rmm-7rvg.json | 11 +++-- .../GHSA-w94f-xh79-q24v.json | 15 +++++-- .../GHSA-xcf9-x48q-v8xv.json | 11 +++-- .../GHSA-xr98-c22v-cfcg.json | 15 +++++-- .../GHSA-442q-pmc8-45rg.json | 15 +++++-- .../GHSA-65fw-2c82-m8v2.json | 15 +++++-- .../GHSA-68wx-vmj5-rjxj.json | 15 +++++-- .../GHSA-7gh2-59h4-gcm3.json | 11 +++-- .../GHSA-8296-4xrf-2xw7.json | 15 +++++-- .../GHSA-8rjh-f75w-mvh9.json | 6 ++- .../GHSA-99x9-vrrc-xxw3.json | 6 ++- .../GHSA-g7qc-r5p9-r36r.json | 17 +++++--- .../GHSA-gvjh-r2g7-mjgx.json | 4 +- .../GHSA-pfmv-h3cf-mr72.json | 6 ++- .../GHSA-rc9x-h469-w6gc.json | 4 +- .../GHSA-vvrw-wrhf-4qp9.json | 15 +++++-- .../GHSA-vw93-wqr3-x7vr.json | 11 +++-- .../GHSA-2p44-rc6w-2rvw.json | 15 +++++-- .../GHSA-48fj-hh68-6w6q.json | 6 ++- .../GHSA-58c5-9mqc-q73p.json | 15 +++++-- .../GHSA-7f3w-mgjh-m27h.json | 4 +- .../GHSA-fqr7-35m8-f63c.json | 11 +++-- .../GHSA-g7xm-f45g-5wvg.json | 4 +- .../GHSA-r52c-mh2p-jmpj.json | 4 +- .../GHSA-v4wq-4595-gr53.json | 4 +- .../GHSA-vfmf-3vr6-j85g.json | 4 +- .../GHSA-6q6g-q64w-cwfh.json | 6 ++- .../GHSA-4hg3-3xxj-v749.json | 6 ++- .../GHSA-65g2-8fcx-v5pc.json | 15 +++++-- .../GHSA-6pcr-45mv-9gp3.json | 6 ++- .../GHSA-8gwj-x84v-j8cc.json | 29 ++++++++++++++ .../GHSA-8j55-mh7v-fc8w.json | 40 +++++++++++++++++++ .../GHSA-f6cx-2h32-33xm.json | 40 +++++++++++++++++++ .../GHSA-h8g5-2596-xjh9.json | 6 ++- .../GHSA-p5fr-9m6g-c94q.json | 40 +++++++++++++++++++ .../GHSA-v64g-gxm8-whwj.json | 29 ++++++++++++++ 96 files changed, 790 insertions(+), 227 deletions(-) create mode 100644 advisories/unreviewed/2025/03/GHSA-8gwj-x84v-j8cc/GHSA-8gwj-x84v-j8cc.json create mode 100644 advisories/unreviewed/2025/03/GHSA-8j55-mh7v-fc8w/GHSA-8j55-mh7v-fc8w.json create mode 100644 advisories/unreviewed/2025/03/GHSA-f6cx-2h32-33xm/GHSA-f6cx-2h32-33xm.json create mode 100644 advisories/unreviewed/2025/03/GHSA-p5fr-9m6g-c94q/GHSA-p5fr-9m6g-c94q.json create mode 100644 advisories/unreviewed/2025/03/GHSA-v64g-gxm8-whwj/GHSA-v64g-gxm8-whwj.json diff --git a/advisories/unreviewed/2023/01/GHSA-2j3m-gwxg-45rx/GHSA-2j3m-gwxg-45rx.json b/advisories/unreviewed/2023/01/GHSA-2j3m-gwxg-45rx/GHSA-2j3m-gwxg-45rx.json index 0ccd52ed359..0b885746f4a 100644 --- a/advisories/unreviewed/2023/01/GHSA-2j3m-gwxg-45rx/GHSA-2j3m-gwxg-45rx.json +++ b/advisories/unreviewed/2023/01/GHSA-2j3m-gwxg-45rx/GHSA-2j3m-gwxg-45rx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2j3m-gwxg-45rx", - "modified": "2023-02-06T21:30:33Z", + "modified": "2025-03-27T21:30:37Z", "published": "2023-01-30T09:30:40Z", "aliases": [ "CVE-2023-22322" diff --git a/advisories/unreviewed/2023/01/GHSA-f6h6-4v35-rxvq/GHSA-f6h6-4v35-rxvq.json b/advisories/unreviewed/2023/01/GHSA-f6h6-4v35-rxvq/GHSA-f6h6-4v35-rxvq.json index 477771ea870..cafef83097b 100644 --- a/advisories/unreviewed/2023/01/GHSA-f6h6-4v35-rxvq/GHSA-f6h6-4v35-rxvq.json +++ b/advisories/unreviewed/2023/01/GHSA-f6h6-4v35-rxvq/GHSA-f6h6-4v35-rxvq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f6h6-4v35-rxvq", - "modified": "2023-02-01T15:30:23Z", + "modified": "2025-03-27T21:30:36Z", "published": "2023-01-24T03:30:19Z", "aliases": [ "CVE-2023-23331" diff --git a/advisories/unreviewed/2023/01/GHSA-h2v4-4v4p-2qvc/GHSA-h2v4-4v4p-2qvc.json b/advisories/unreviewed/2023/01/GHSA-h2v4-4v4p-2qvc/GHSA-h2v4-4v4p-2qvc.json index cb21acfc4c7..6462a7886df 100644 --- a/advisories/unreviewed/2023/01/GHSA-h2v4-4v4p-2qvc/GHSA-h2v4-4v4p-2qvc.json +++ b/advisories/unreviewed/2023/01/GHSA-h2v4-4v4p-2qvc/GHSA-h2v4-4v4p-2qvc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h2v4-4v4p-2qvc", - "modified": "2023-02-07T21:30:25Z", + "modified": "2025-03-27T21:30:36Z", "published": "2023-01-30T06:30:27Z", "aliases": [ "CVE-2022-48303" diff --git a/advisories/unreviewed/2023/01/GHSA-hppr-5p45-xr8c/GHSA-hppr-5p45-xr8c.json b/advisories/unreviewed/2023/01/GHSA-hppr-5p45-xr8c/GHSA-hppr-5p45-xr8c.json index 319945308cc..367ea67ae77 100644 --- a/advisories/unreviewed/2023/01/GHSA-hppr-5p45-xr8c/GHSA-hppr-5p45-xr8c.json +++ b/advisories/unreviewed/2023/01/GHSA-hppr-5p45-xr8c/GHSA-hppr-5p45-xr8c.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-522" + "CWE-522", + "CWE-640" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/01/GHSA-jmj5-q6wr-x9v2/GHSA-jmj5-q6wr-x9v2.json b/advisories/unreviewed/2023/01/GHSA-jmj5-q6wr-x9v2/GHSA-jmj5-q6wr-x9v2.json index a775d017250..8af05650d13 100644 --- a/advisories/unreviewed/2023/01/GHSA-jmj5-q6wr-x9v2/GHSA-jmj5-q6wr-x9v2.json +++ b/advisories/unreviewed/2023/01/GHSA-jmj5-q6wr-x9v2/GHSA-jmj5-q6wr-x9v2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jmj5-q6wr-x9v2", - "modified": "2023-02-07T21:30:25Z", + "modified": "2025-03-27T21:30:36Z", "published": "2023-01-27T06:30:21Z", "aliases": [ "CVE-2023-24060" diff --git a/advisories/unreviewed/2023/01/GHSA-p8h8-37jj-3jqq/GHSA-p8h8-37jj-3jqq.json b/advisories/unreviewed/2023/01/GHSA-p8h8-37jj-3jqq/GHSA-p8h8-37jj-3jqq.json index a73504d2b0a..bfa27b9e1bd 100644 --- a/advisories/unreviewed/2023/01/GHSA-p8h8-37jj-3jqq/GHSA-p8h8-37jj-3jqq.json +++ b/advisories/unreviewed/2023/01/GHSA-p8h8-37jj-3jqq/GHSA-p8h8-37jj-3jqq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p8h8-37jj-3jqq", - "modified": "2023-02-08T00:30:35Z", + "modified": "2025-03-27T21:30:42Z", "published": "2023-01-31T18:30:22Z", "aliases": [ "CVE-2022-47035" diff --git a/advisories/unreviewed/2023/02/GHSA-235p-3884-9g52/GHSA-235p-3884-9g52.json b/advisories/unreviewed/2023/02/GHSA-235p-3884-9g52/GHSA-235p-3884-9g52.json index 704e778ad45..173c93c463d 100644 --- a/advisories/unreviewed/2023/02/GHSA-235p-3884-9g52/GHSA-235p-3884-9g52.json +++ b/advisories/unreviewed/2023/02/GHSA-235p-3884-9g52/GHSA-235p-3884-9g52.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-269" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-9w4v-2x3h-wxmw/GHSA-9w4v-2x3h-wxmw.json b/advisories/unreviewed/2023/02/GHSA-9w4v-2x3h-wxmw/GHSA-9w4v-2x3h-wxmw.json index 3a96092191a..7440fe45622 100644 --- a/advisories/unreviewed/2023/02/GHSA-9w4v-2x3h-wxmw/GHSA-9w4v-2x3h-wxmw.json +++ b/advisories/unreviewed/2023/02/GHSA-9w4v-2x3h-wxmw/GHSA-9w4v-2x3h-wxmw.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-269" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-fr5f-66rh-432p/GHSA-fr5f-66rh-432p.json b/advisories/unreviewed/2023/02/GHSA-fr5f-66rh-432p/GHSA-fr5f-66rh-432p.json index 0972b9e8daf..e3496a091ec 100644 --- a/advisories/unreviewed/2023/02/GHSA-fr5f-66rh-432p/GHSA-fr5f-66rh-432p.json +++ b/advisories/unreviewed/2023/02/GHSA-fr5f-66rh-432p/GHSA-fr5f-66rh-432p.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-269" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-fvh7-79fr-wwcg/GHSA-fvh7-79fr-wwcg.json b/advisories/unreviewed/2023/02/GHSA-fvh7-79fr-wwcg/GHSA-fvh7-79fr-wwcg.json index b91e2d3653c..44151e1a3d2 100644 --- a/advisories/unreviewed/2023/02/GHSA-fvh7-79fr-wwcg/GHSA-fvh7-79fr-wwcg.json +++ b/advisories/unreviewed/2023/02/GHSA-fvh7-79fr-wwcg/GHSA-fvh7-79fr-wwcg.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-269" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/02/GHSA-mpjh-c64m-g538/GHSA-mpjh-c64m-g538.json b/advisories/unreviewed/2023/02/GHSA-mpjh-c64m-g538/GHSA-mpjh-c64m-g538.json index dfc8247deaf..d8455839f24 100644 --- a/advisories/unreviewed/2023/02/GHSA-mpjh-c64m-g538/GHSA-mpjh-c64m-g538.json +++ b/advisories/unreviewed/2023/02/GHSA-mpjh-c64m-g538/GHSA-mpjh-c64m-g538.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mpjh-c64m-g538", - "modified": "2023-02-09T00:30:18Z", + "modified": "2025-03-27T21:30:42Z", "published": "2023-02-01T00:30:29Z", "aliases": [ "CVE-2022-32984" @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-3v2h-jhg6-jj7v/GHSA-3v2h-jhg6-jj7v.json b/advisories/unreviewed/2024/02/GHSA-3v2h-jhg6-jj7v/GHSA-3v2h-jhg6-jj7v.json index 041c1980c0a..51dcc3604df 100644 --- a/advisories/unreviewed/2024/02/GHSA-3v2h-jhg6-jj7v/GHSA-3v2h-jhg6-jj7v.json +++ b/advisories/unreviewed/2024/02/GHSA-3v2h-jhg6-jj7v/GHSA-3v2h-jhg6-jj7v.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-269" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-cgpg-xpvx-xqxj/GHSA-cgpg-xpvx-xqxj.json b/advisories/unreviewed/2024/02/GHSA-cgpg-xpvx-xqxj/GHSA-cgpg-xpvx-xqxj.json index 27037b84c4d..6f1ddd4f069 100644 --- a/advisories/unreviewed/2024/02/GHSA-cgpg-xpvx-xqxj/GHSA-cgpg-xpvx-xqxj.json +++ b/advisories/unreviewed/2024/02/GHSA-cgpg-xpvx-xqxj/GHSA-cgpg-xpvx-xqxj.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-94" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-cqgm-hp7p-3m66/GHSA-cqgm-hp7p-3m66.json b/advisories/unreviewed/2024/02/GHSA-cqgm-hp7p-3m66/GHSA-cqgm-hp7p-3m66.json index f4f388a8010..cbcb11e0ccf 100644 --- a/advisories/unreviewed/2024/02/GHSA-cqgm-hp7p-3m66/GHSA-cqgm-hp7p-3m66.json +++ b/advisories/unreviewed/2024/02/GHSA-cqgm-hp7p-3m66/GHSA-cqgm-hp7p-3m66.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-401" + "CWE-401", + "CWE-434" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/02/GHSA-f3gj-969x-5q5x/GHSA-f3gj-969x-5q5x.json b/advisories/unreviewed/2024/02/GHSA-f3gj-969x-5q5x/GHSA-f3gj-969x-5q5x.json index ff495c1e50d..27aae7c489d 100644 --- a/advisories/unreviewed/2024/02/GHSA-f3gj-969x-5q5x/GHSA-f3gj-969x-5q5x.json +++ b/advisories/unreviewed/2024/02/GHSA-f3gj-969x-5q5x/GHSA-f3gj-969x-5q5x.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-20" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-frg3-hm7v-3rpf/GHSA-frg3-hm7v-3rpf.json b/advisories/unreviewed/2024/02/GHSA-frg3-hm7v-3rpf/GHSA-frg3-hm7v-3rpf.json index 714631dd99b..0136b6fc3e1 100644 --- a/advisories/unreviewed/2024/02/GHSA-frg3-hm7v-3rpf/GHSA-frg3-hm7v-3rpf.json +++ b/advisories/unreviewed/2024/02/GHSA-frg3-hm7v-3rpf/GHSA-frg3-hm7v-3rpf.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-693" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-h29x-5q67-v88m/GHSA-h29x-5q67-v88m.json b/advisories/unreviewed/2024/02/GHSA-h29x-5q67-v88m/GHSA-h29x-5q67-v88m.json index 5f64319c6c3..a39a7dc7a80 100644 --- a/advisories/unreviewed/2024/02/GHSA-h29x-5q67-v88m/GHSA-h29x-5q67-v88m.json +++ b/advisories/unreviewed/2024/02/GHSA-h29x-5q67-v88m/GHSA-h29x-5q67-v88m.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/02/GHSA-j26p-3qqc-p3hw/GHSA-j26p-3qqc-p3hw.json b/advisories/unreviewed/2024/02/GHSA-j26p-3qqc-p3hw/GHSA-j26p-3qqc-p3hw.json index bb7cf438ad6..9a17d65abbc 100644 --- a/advisories/unreviewed/2024/02/GHSA-j26p-3qqc-p3hw/GHSA-j26p-3qqc-p3hw.json +++ b/advisories/unreviewed/2024/02/GHSA-j26p-3qqc-p3hw/GHSA-j26p-3qqc-p3hw.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-114" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-3f88-vcg8-m5ph/GHSA-3f88-vcg8-m5ph.json b/advisories/unreviewed/2024/03/GHSA-3f88-vcg8-m5ph/GHSA-3f88-vcg8-m5ph.json index f0c582c67ec..7ad3f08f217 100644 --- a/advisories/unreviewed/2024/03/GHSA-3f88-vcg8-m5ph/GHSA-3f88-vcg8-m5ph.json +++ b/advisories/unreviewed/2024/03/GHSA-3f88-vcg8-m5ph/GHSA-3f88-vcg8-m5ph.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3f88-vcg8-m5ph", - "modified": "2024-03-18T03:30:32Z", + "modified": "2025-03-27T21:31:03Z", "published": "2024-03-18T03:30:32Z", "aliases": [ "CVE-2023-39223" ], "details": "Stored cross-site scripting vulnerability exists in CGIs included in A.K.I Software's PMailServer/PMailServer2 products. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-18T01:15:48Z" diff --git a/advisories/unreviewed/2024/03/GHSA-42vc-w257-pp26/GHSA-42vc-w257-pp26.json b/advisories/unreviewed/2024/03/GHSA-42vc-w257-pp26/GHSA-42vc-w257-pp26.json index e6705e2dad3..1a4baf862bc 100644 --- a/advisories/unreviewed/2024/03/GHSA-42vc-w257-pp26/GHSA-42vc-w257-pp26.json +++ b/advisories/unreviewed/2024/03/GHSA-42vc-w257-pp26/GHSA-42vc-w257-pp26.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-42vc-w257-pp26", - "modified": "2024-03-18T06:30:51Z", + "modified": "2025-03-27T21:31:03Z", "published": "2024-03-18T06:30:51Z", "aliases": [ "CVE-2021-47156" ], "details": "The Net::IPAddress::Util module before 5.000 for Perl does not properly consider extraneous zero characters in an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-1287" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-18T05:15:06Z" diff --git a/advisories/unreviewed/2024/03/GHSA-4466-5jhm-q8x8/GHSA-4466-5jhm-q8x8.json b/advisories/unreviewed/2024/03/GHSA-4466-5jhm-q8x8/GHSA-4466-5jhm-q8x8.json index 1e2ad56a99e..76b7460298d 100644 --- a/advisories/unreviewed/2024/03/GHSA-4466-5jhm-q8x8/GHSA-4466-5jhm-q8x8.json +++ b/advisories/unreviewed/2024/03/GHSA-4466-5jhm-q8x8/GHSA-4466-5jhm-q8x8.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-4rxr-8xrx-9rf3/GHSA-4rxr-8xrx-9rf3.json b/advisories/unreviewed/2024/03/GHSA-4rxr-8xrx-9rf3/GHSA-4rxr-8xrx-9rf3.json index 008fb1950a5..09d5aaccef4 100644 --- a/advisories/unreviewed/2024/03/GHSA-4rxr-8xrx-9rf3/GHSA-4rxr-8xrx-9rf3.json +++ b/advisories/unreviewed/2024/03/GHSA-4rxr-8xrx-9rf3/GHSA-4rxr-8xrx-9rf3.json @@ -57,7 +57,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-4xp8-3mc6-r83c/GHSA-4xp8-3mc6-r83c.json b/advisories/unreviewed/2024/03/GHSA-4xp8-3mc6-r83c/GHSA-4xp8-3mc6-r83c.json index 9ec07a1cf9d..b1e5d75e080 100644 --- a/advisories/unreviewed/2024/03/GHSA-4xp8-3mc6-r83c/GHSA-4xp8-3mc6-r83c.json +++ b/advisories/unreviewed/2024/03/GHSA-4xp8-3mc6-r83c/GHSA-4xp8-3mc6-r83c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4xp8-3mc6-r83c", - "modified": "2024-03-05T18:31:14Z", + "modified": "2025-03-27T21:30:59Z", "published": "2024-03-05T18:31:13Z", "aliases": [ "CVE-2024-22252" @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-416" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-54wh-fwqq-m49j/GHSA-54wh-fwqq-m49j.json b/advisories/unreviewed/2024/03/GHSA-54wh-fwqq-m49j/GHSA-54wh-fwqq-m49j.json index dbe8e3cdc26..9c1e2eb3d0d 100644 --- a/advisories/unreviewed/2024/03/GHSA-54wh-fwqq-m49j/GHSA-54wh-fwqq-m49j.json +++ b/advisories/unreviewed/2024/03/GHSA-54wh-fwqq-m49j/GHSA-54wh-fwqq-m49j.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-54wh-fwqq-m49j", - "modified": "2024-03-05T21:30:25Z", + "modified": "2025-03-27T21:30:59Z", "published": "2024-03-05T21:30:25Z", "aliases": [ "CVE-2024-25615" ], - "details": " An unauthenticated Denial-of-Service (DoS) vulnerability exists in the Spectrum service accessed via the PAPI protocol in ArubaOS 8.x. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected service.\n\n", + "details": "An unauthenticated Denial-of-Service (DoS) vulnerability exists in the Spectrum service accessed via the PAPI protocol in ArubaOS 8.x. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected service.", "severity": [ { "type": "CVSS_V3", @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-6276-35wc-6mcx/GHSA-6276-35wc-6mcx.json b/advisories/unreviewed/2024/03/GHSA-6276-35wc-6mcx/GHSA-6276-35wc-6mcx.json index 4336df594c5..b95055900eb 100644 --- a/advisories/unreviewed/2024/03/GHSA-6276-35wc-6mcx/GHSA-6276-35wc-6mcx.json +++ b/advisories/unreviewed/2024/03/GHSA-6276-35wc-6mcx/GHSA-6276-35wc-6mcx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6276-35wc-6mcx", - "modified": "2024-03-15T03:30:52Z", + "modified": "2025-03-27T21:31:02Z", "published": "2024-03-15T03:30:52Z", "aliases": [ "CVE-2024-26454" ], "details": "A Cross Site Scripting vulnerability in Healthcare-Chatbot through 9b7058a can occur via a crafted payload to the email1 or pwd1 parameter in login.php.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-15T01:15:58Z" diff --git a/advisories/unreviewed/2024/03/GHSA-6w43-jrpg-hc48/GHSA-6w43-jrpg-hc48.json b/advisories/unreviewed/2024/03/GHSA-6w43-jrpg-hc48/GHSA-6w43-jrpg-hc48.json index 9a23e4378b6..3e42d6f5e52 100644 --- a/advisories/unreviewed/2024/03/GHSA-6w43-jrpg-hc48/GHSA-6w43-jrpg-hc48.json +++ b/advisories/unreviewed/2024/03/GHSA-6w43-jrpg-hc48/GHSA-6w43-jrpg-hc48.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6w43-jrpg-hc48", - "modified": "2024-03-07T03:30:41Z", + "modified": "2025-03-27T21:31:00Z", "published": "2024-03-07T03:30:41Z", "aliases": [ "CVE-2024-24389" ], "details": "A cross-site scripting (XSS) vulnerability in XunRuiCMS up to v4.6.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Add Column Name parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-07T02:15:51Z" diff --git a/advisories/unreviewed/2024/03/GHSA-7x8p-3pr3-73hp/GHSA-7x8p-3pr3-73hp.json b/advisories/unreviewed/2024/03/GHSA-7x8p-3pr3-73hp/GHSA-7x8p-3pr3-73hp.json index a06da66257e..7dbdf531689 100644 --- a/advisories/unreviewed/2024/03/GHSA-7x8p-3pr3-73hp/GHSA-7x8p-3pr3-73hp.json +++ b/advisories/unreviewed/2024/03/GHSA-7x8p-3pr3-73hp/GHSA-7x8p-3pr3-73hp.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-7x8p-3pr3-73hp", - "modified": "2024-03-26T15:30:50Z", + "modified": "2025-03-27T21:31:03Z", "published": "2024-03-26T15:30:50Z", "aliases": [ "CVE-2024-30234" ], - "details": "Missing Authorization vulnerability in Wholesale Team WholesaleX.This issue affects WholesaleX: from n/a through 1.3.1.\n\n", + "details": "Missing Authorization vulnerability in Wholesale Team WholesaleX.This issue affects WholesaleX: from n/a through 1.3.1.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/03/GHSA-7xrf-xg7m-8rqp/GHSA-7xrf-xg7m-8rqp.json b/advisories/unreviewed/2024/03/GHSA-7xrf-xg7m-8rqp/GHSA-7xrf-xg7m-8rqp.json index dc79dc29fbd..fb55d1d27e4 100644 --- a/advisories/unreviewed/2024/03/GHSA-7xrf-xg7m-8rqp/GHSA-7xrf-xg7m-8rqp.json +++ b/advisories/unreviewed/2024/03/GHSA-7xrf-xg7m-8rqp/GHSA-7xrf-xg7m-8rqp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7xrf-xg7m-8rqp", - "modified": "2024-03-29T00:30:34Z", + "modified": "2025-03-27T21:31:03Z", "published": "2024-03-29T00:30:34Z", "aliases": [ "CVE-2024-28456" ], "details": "Cross Site Scripting vulnerability in Campcodes Online Marriage Registration System v.1.0 allows a remote attacker to execute arbitrary code via the text fields in the marriage registration request form.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-28T23:15:46Z" diff --git a/advisories/unreviewed/2024/03/GHSA-8xjc-25qh-f5x2/GHSA-8xjc-25qh-f5x2.json b/advisories/unreviewed/2024/03/GHSA-8xjc-25qh-f5x2/GHSA-8xjc-25qh-f5x2.json index 7e8ed2a18ae..fdd153c3ddd 100644 --- a/advisories/unreviewed/2024/03/GHSA-8xjc-25qh-f5x2/GHSA-8xjc-25qh-f5x2.json +++ b/advisories/unreviewed/2024/03/GHSA-8xjc-25qh-f5x2/GHSA-8xjc-25qh-f5x2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8xjc-25qh-f5x2", - "modified": "2024-03-18T09:30:30Z", + "modified": "2025-03-27T21:31:03Z", "published": "2024-03-18T09:30:30Z", "aliases": [ "CVE-2024-23604" ], "details": "Cross-site scripting vulnerability exists in FitNesse all releases, which may allow a remote unauthenticated attacker to execute an arbitrary script on the web browser of the user who is using the product and accessing a link with specially crafted multiple parameters.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-18T08:15:06Z" diff --git a/advisories/unreviewed/2024/03/GHSA-g6gj-xwhj-g7rm/GHSA-g6gj-xwhj-g7rm.json b/advisories/unreviewed/2024/03/GHSA-g6gj-xwhj-g7rm/GHSA-g6gj-xwhj-g7rm.json index 355b75c9622..bed481d487a 100644 --- a/advisories/unreviewed/2024/03/GHSA-g6gj-xwhj-g7rm/GHSA-g6gj-xwhj-g7rm.json +++ b/advisories/unreviewed/2024/03/GHSA-g6gj-xwhj-g7rm/GHSA-g6gj-xwhj-g7rm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-g6gj-xwhj-g7rm", - "modified": "2024-03-20T15:32:58Z", + "modified": "2025-03-27T21:31:03Z", "published": "2024-03-20T15:32:58Z", "aliases": [ "CVE-2024-29419" ], "details": "There is a Cross-site scripting (XSS) vulnerability in the Wireless settings under the Easy Setup Page of TOTOLINK X2000R before v1.0.0-B20231213.1013.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-20T15:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-jv2q-4725-898c/GHSA-jv2q-4725-898c.json b/advisories/unreviewed/2024/03/GHSA-jv2q-4725-898c/GHSA-jv2q-4725-898c.json index b426c9da581..1916f18db80 100644 --- a/advisories/unreviewed/2024/03/GHSA-jv2q-4725-898c/GHSA-jv2q-4725-898c.json +++ b/advisories/unreviewed/2024/03/GHSA-jv2q-4725-898c/GHSA-jv2q-4725-898c.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-922" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-ph77-97qp-2vrp/GHSA-ph77-97qp-2vrp.json b/advisories/unreviewed/2024/03/GHSA-ph77-97qp-2vrp/GHSA-ph77-97qp-2vrp.json index cc9584166a1..54f4d30aa5b 100644 --- a/advisories/unreviewed/2024/03/GHSA-ph77-97qp-2vrp/GHSA-ph77-97qp-2vrp.json +++ b/advisories/unreviewed/2024/03/GHSA-ph77-97qp-2vrp/GHSA-ph77-97qp-2vrp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-ph77-97qp-2vrp", - "modified": "2024-03-19T15:30:34Z", + "modified": "2025-03-27T21:31:03Z", "published": "2024-03-19T15:30:34Z", "aliases": [ "CVE-2024-1401" ], "details": "The Profile Box Shortcode And Widget WordPress plugin before 1.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-19T15:15:07Z" diff --git a/advisories/unreviewed/2024/03/GHSA-qr5m-2qmx-pvvm/GHSA-qr5m-2qmx-pvvm.json b/advisories/unreviewed/2024/03/GHSA-qr5m-2qmx-pvvm/GHSA-qr5m-2qmx-pvvm.json index 828c80ee798..8f47bb0c32d 100644 --- a/advisories/unreviewed/2024/03/GHSA-qr5m-2qmx-pvvm/GHSA-qr5m-2qmx-pvvm.json +++ b/advisories/unreviewed/2024/03/GHSA-qr5m-2qmx-pvvm/GHSA-qr5m-2qmx-pvvm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qr5m-2qmx-pvvm", - "modified": "2024-03-13T21:31:02Z", + "modified": "2025-03-27T21:31:01Z", "published": "2024-03-13T21:31:02Z", "aliases": [ "CVE-2024-24105" ], "details": "SQL Injection vulnerability in Code-projects Computer Science Time Table System 1.0 allows attackers to run arbitrary code via adminFormvalidation.php.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-13T21:15:58Z" diff --git a/advisories/unreviewed/2024/03/GHSA-wgr7-wrhm-vcmg/GHSA-wgr7-wrhm-vcmg.json b/advisories/unreviewed/2024/03/GHSA-wgr7-wrhm-vcmg/GHSA-wgr7-wrhm-vcmg.json index 761b124c9d5..b302ac0a368 100644 --- a/advisories/unreviewed/2024/03/GHSA-wgr7-wrhm-vcmg/GHSA-wgr7-wrhm-vcmg.json +++ b/advisories/unreviewed/2024/03/GHSA-wgr7-wrhm-vcmg/GHSA-wgr7-wrhm-vcmg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wgr7-wrhm-vcmg", - "modified": "2024-03-22T00:31:14Z", + "modified": "2025-03-27T21:31:03Z", "published": "2024-03-22T00:31:14Z", "aliases": [ "CVE-2024-24272" ], "details": "An issue in iTop DualSafe Password Manager & Digital Vault before 1.4.24 allows a local attacker to obtain sensitive information via leaked credentials as plaintext in a log file that can be accessed by the local user without knowledge of the master secret.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-532" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-03-21T22:15:10Z" diff --git a/advisories/unreviewed/2024/04/GHSA-222x-r452-4688/GHSA-222x-r452-4688.json b/advisories/unreviewed/2024/04/GHSA-222x-r452-4688/GHSA-222x-r452-4688.json index d229ed8ef3e..236e19f4430 100644 --- a/advisories/unreviewed/2024/04/GHSA-222x-r452-4688/GHSA-222x-r452-4688.json +++ b/advisories/unreviewed/2024/04/GHSA-222x-r452-4688/GHSA-222x-r452-4688.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-285" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-2vvj-hm96-cr7r/GHSA-2vvj-hm96-cr7r.json b/advisories/unreviewed/2024/04/GHSA-2vvj-hm96-cr7r/GHSA-2vvj-hm96-cr7r.json index c4e4cfc2aa2..9f5aa1afb20 100644 --- a/advisories/unreviewed/2024/04/GHSA-2vvj-hm96-cr7r/GHSA-2vvj-hm96-cr7r.json +++ b/advisories/unreviewed/2024/04/GHSA-2vvj-hm96-cr7r/GHSA-2vvj-hm96-cr7r.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2vvj-hm96-cr7r", - "modified": "2024-06-27T12:30:45Z", + "modified": "2025-03-27T21:31:08Z", "published": "2024-04-17T12:32:02Z", "aliases": [ "CVE-2024-26820" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nhv_netvsc: Register VF in netvsc_probe if NET_DEVICE_REGISTER missed\n\nIf hv_netvsc driver is unloaded and reloaded, the NET_DEVICE_REGISTER\nhandler cannot perform VF register successfully as the register call\nis received before netvsc_probe is finished. This is because we\nregister register_netdevice_notifier() very early( even before\nvmbus_driver_register()).\nTo fix this, we try to register each such matching VF( if it is visible\nas a netdevice) at the end of netvsc_probe.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -57,7 +62,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T10:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-3264-p6rp-pxp7/GHSA-3264-p6rp-pxp7.json b/advisories/unreviewed/2024/04/GHSA-3264-p6rp-pxp7/GHSA-3264-p6rp-pxp7.json index 72930a45ae8..8a85b32f1ca 100644 --- a/advisories/unreviewed/2024/04/GHSA-3264-p6rp-pxp7/GHSA-3264-p6rp-pxp7.json +++ b/advisories/unreviewed/2024/04/GHSA-3264-p6rp-pxp7/GHSA-3264-p6rp-pxp7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3264-p6rp-pxp7", - "modified": "2024-04-17T12:32:02Z", + "modified": "2025-03-27T21:31:08Z", "published": "2024-04-17T12:32:02Z", "aliases": [ "CVE-2024-26818" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ntools/rtla: Fix clang warning about mount_point var size\n\nclang is reporting this warning:\n\n$ make HOSTCC=clang CC=clang LLVM_IAS=1\n[...]\nclang -O -g -DVERSION=\\\"6.8.0-rc3\\\" -flto=auto -fexceptions\n\t-fstack-protector-strong -fasynchronous-unwind-tables\n\t-fstack-clash-protection -Wall -Werror=format-security\n\t-Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS\n\t$(pkg-config --cflags libtracefs) -c -o src/utils.o src/utils.c\n\nsrc/utils.c:548:66: warning: 'fscanf' may overflow; destination buffer in argument 3 has size 1024, but the corresponding specifier may require size 1025 [-Wfortify-source]\n 548 | while (fscanf(fp, \"%*s %\" STR(MAX_PATH) \"s %99s %*s %*d %*d\\n\", mount_point, type) == 2) {\n | ^\n\nIncrease mount_point variable size to MAX_PATH+1 to avoid the overflow.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -29,7 +34,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T10:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-4jxh-5mmr-rhrf/GHSA-4jxh-5mmr-rhrf.json b/advisories/unreviewed/2024/04/GHSA-4jxh-5mmr-rhrf/GHSA-4jxh-5mmr-rhrf.json index 4cae49e1c02..da6d0d407df 100644 --- a/advisories/unreviewed/2024/04/GHSA-4jxh-5mmr-rhrf/GHSA-4jxh-5mmr-rhrf.json +++ b/advisories/unreviewed/2024/04/GHSA-4jxh-5mmr-rhrf/GHSA-4jxh-5mmr-rhrf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-4jxh-5mmr-rhrf", - "modified": "2024-06-26T00:31:36Z", + "modified": "2025-03-27T21:31:08Z", "published": "2024-04-17T12:32:02Z", "aliases": [ "CVE-2023-52642" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: rc: bpf attach/detach requires write permission\n\nNote that bpf attach/detach also requires CAP_NET_ADMIN.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -44,8 +49,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T10:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-5gcf-h7r6-w82j/GHSA-5gcf-h7r6-w82j.json b/advisories/unreviewed/2024/04/GHSA-5gcf-h7r6-w82j/GHSA-5gcf-h7r6-w82j.json index e523f990835..4efb68f79ee 100644 --- a/advisories/unreviewed/2024/04/GHSA-5gcf-h7r6-w82j/GHSA-5gcf-h7r6-w82j.json +++ b/advisories/unreviewed/2024/04/GHSA-5gcf-h7r6-w82j/GHSA-5gcf-h7r6-w82j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5gcf-h7r6-w82j", - "modified": "2024-04-17T12:32:02Z", + "modified": "2025-03-27T21:31:09Z", "published": "2024-04-17T12:32:02Z", "aliases": [ "CVE-2024-26822" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: set correct id, uid and cruid for multiuser automounts\n\nWhen uid, gid and cruid are not specified, we need to dynamically\nset them into the filesystem context used for automounting otherwise\nthey'll end up reusing the values from the parent mount.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -29,7 +34,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T10:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-5r2r-xpfw-pmxc/GHSA-5r2r-xpfw-pmxc.json b/advisories/unreviewed/2024/04/GHSA-5r2r-xpfw-pmxc/GHSA-5r2r-xpfw-pmxc.json index 0130388d652..d2d6664f720 100644 --- a/advisories/unreviewed/2024/04/GHSA-5r2r-xpfw-pmxc/GHSA-5r2r-xpfw-pmxc.json +++ b/advisories/unreviewed/2024/04/GHSA-5r2r-xpfw-pmxc/GHSA-5r2r-xpfw-pmxc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5r2r-xpfw-pmxc", - "modified": "2024-06-27T12:30:45Z", + "modified": "2025-03-27T21:31:09Z", "published": "2024-04-17T12:32:02Z", "aliases": [ "CVE-2024-26825" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnfc: nci: free rx_data_reassembly skb on NCI device cleanup\n\nrx_data_reassembly skb is stored during NCI data exchange for processing\nfragmented packets. It is dropped only when the last fragment is processed\nor when an NTF packet with NCI_OP_RF_DEACTIVATE_NTF opcode is received.\nHowever, the NCI device may be deallocated before that which leads to skb\nleak.\n\nAs by design the rx_data_reassembly skb is bound to the NCI device and\nnothing prevents the device to be freed before the skb is processed in\nsome way and cleaned, free it on the NCI device cleanup.\n\nFound by Linux Verification Center (linuxtesting.org) with Syzkaller.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -56,8 +61,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-459" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T10:15:09Z" diff --git a/advisories/unreviewed/2024/04/GHSA-66fh-rmm8-p9q4/GHSA-66fh-rmm8-p9q4.json b/advisories/unreviewed/2024/04/GHSA-66fh-rmm8-p9q4/GHSA-66fh-rmm8-p9q4.json index d37da7ec13a..3544fcb9dc0 100644 --- a/advisories/unreviewed/2024/04/GHSA-66fh-rmm8-p9q4/GHSA-66fh-rmm8-p9q4.json +++ b/advisories/unreviewed/2024/04/GHSA-66fh-rmm8-p9q4/GHSA-66fh-rmm8-p9q4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-66fh-rmm8-p9q4", - "modified": "2024-04-10T21:30:32Z", + "modified": "2025-03-27T21:31:08Z", "published": "2024-04-10T21:30:32Z", "aliases": [ "CVE-2021-47215" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: kTLS, Fix crash in RX resync flow\n\nFor the TLS RX resync flow, we maintain a list of TLS contexts\nthat require some attention, to communicate their resync information\nto the HW.\nHere we fix list corruptions, by protecting the entries against\nmovements coming from resync_handle_seq_match(), until their resync\nhandling in napi is fully completed.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -25,7 +30,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-10T19:15:48Z" diff --git a/advisories/unreviewed/2024/04/GHSA-843f-6jw5-wr67/GHSA-843f-6jw5-wr67.json b/advisories/unreviewed/2024/04/GHSA-843f-6jw5-wr67/GHSA-843f-6jw5-wr67.json index 3bee9edbd19..17f74502340 100644 --- a/advisories/unreviewed/2024/04/GHSA-843f-6jw5-wr67/GHSA-843f-6jw5-wr67.json +++ b/advisories/unreviewed/2024/04/GHSA-843f-6jw5-wr67/GHSA-843f-6jw5-wr67.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-843f-6jw5-wr67", - "modified": "2024-04-22T15:30:42Z", + "modified": "2025-03-27T21:31:10Z", "published": "2024-04-22T15:30:42Z", "aliases": [ "CVE-2023-38302" ], "details": "A certain software build for the Sharp Rouvo V device (SHARP/VZW_STTM21VAPP/STTM21VAPP:12/SP1A.210812.016/1KN0_0_530:user/release-keys) leaks the Wi-Fi MAC address and the Bluetooth MAC address to system properties that can be accessed by any local app on the device without any permissions or special privileges. Google restricted third-party apps from directly obtaining non-resettable device identifiers in Android 10 and higher, but in this instance they are leaked by a high-privilege process and can be obtained indirectly. This malicious app reads from the \"ro.boot.wifi_mac\" system property to indirectly obtain the Wi-Fi MAC address and reads the \"ro.boot.bt_mac\" system property to obtain the Bluetooth MAC address.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-22T15:15:47Z" diff --git a/advisories/unreviewed/2024/04/GHSA-84g6-j698-p58m/GHSA-84g6-j698-p58m.json b/advisories/unreviewed/2024/04/GHSA-84g6-j698-p58m/GHSA-84g6-j698-p58m.json index 8f8c998442e..1d0e3d16764 100644 --- a/advisories/unreviewed/2024/04/GHSA-84g6-j698-p58m/GHSA-84g6-j698-p58m.json +++ b/advisories/unreviewed/2024/04/GHSA-84g6-j698-p58m/GHSA-84g6-j698-p58m.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-84g6-j698-p58m", - "modified": "2024-04-10T21:30:31Z", + "modified": "2025-03-27T21:31:08Z", "published": "2024-04-10T21:30:31Z", "aliases": [ "CVE-2021-47203" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: lpfc: Fix list_add() corruption in lpfc_drain_txq()\n\nWhen parsing the txq list in lpfc_drain_txq(), the driver attempts to pass\nthe requests to the adapter. If such an attempt fails, a local \"fail_msg\"\nstring is set and a log message output. The job is then added to a\ncompletions list for cancellation.\n\nProcessing of any further jobs from the txq list continues, but since\n\"fail_msg\" remains set, jobs are added to the completions list regardless\nof whether a wqe was passed to the adapter. If successfully added to\ntxcmplq, jobs are added to both lists resulting in list corruption.\n\nFix by clearing the fail_msg string after adding a job to the completions\nlist. This stops the subsequent jobs from being added to the completions\nlist unless they had an appropriate failure.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -48,8 +53,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-10T19:15:48Z" diff --git a/advisories/unreviewed/2024/04/GHSA-87f6-4648-854h/GHSA-87f6-4648-854h.json b/advisories/unreviewed/2024/04/GHSA-87f6-4648-854h/GHSA-87f6-4648-854h.json index 7c51883865a..0bf67e92ff6 100644 --- a/advisories/unreviewed/2024/04/GHSA-87f6-4648-854h/GHSA-87f6-4648-854h.json +++ b/advisories/unreviewed/2024/04/GHSA-87f6-4648-854h/GHSA-87f6-4648-854h.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-87f6-4648-854h", - "modified": "2024-04-05T21:32:44Z", + "modified": "2025-03-27T21:31:04Z", "published": "2024-04-05T21:32:44Z", "aliases": [ "CVE-2024-29754" ], "details": "In TMU_IPC_GET_TABLE, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-05T20:15:08Z" diff --git a/advisories/unreviewed/2024/04/GHSA-8c7c-3pvq-q9v3/GHSA-8c7c-3pvq-q9v3.json b/advisories/unreviewed/2024/04/GHSA-8c7c-3pvq-q9v3/GHSA-8c7c-3pvq-q9v3.json index 5d1aa7127ba..3cf6b7f7fb5 100644 --- a/advisories/unreviewed/2024/04/GHSA-8c7c-3pvq-q9v3/GHSA-8c7c-3pvq-q9v3.json +++ b/advisories/unreviewed/2024/04/GHSA-8c7c-3pvq-q9v3/GHSA-8c7c-3pvq-q9v3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8c7c-3pvq-q9v3", - "modified": "2024-04-10T21:30:32Z", + "modified": "2025-03-27T21:31:08Z", "published": "2024-04-10T21:30:32Z", "aliases": [ "CVE-2021-47210" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: typec: tipd: Remove WARN_ON in tps6598x_block_read\n\nCalling tps6598x_block_read with a higher than allowed len can be\nhandled by just returning an error. There's no need to crash systems\nwith panic-on-warn enabled.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-10T19:15:48Z" diff --git a/advisories/unreviewed/2024/04/GHSA-8fj4-3988-99m9/GHSA-8fj4-3988-99m9.json b/advisories/unreviewed/2024/04/GHSA-8fj4-3988-99m9/GHSA-8fj4-3988-99m9.json index 3047c4e0e45..be5387ec9c5 100644 --- a/advisories/unreviewed/2024/04/GHSA-8fj4-3988-99m9/GHSA-8fj4-3988-99m9.json +++ b/advisories/unreviewed/2024/04/GHSA-8fj4-3988-99m9/GHSA-8fj4-3988-99m9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8fj4-3988-99m9", - "modified": "2024-04-12T06:33:24Z", + "modified": "2025-03-27T21:31:08Z", "published": "2024-04-12T06:33:24Z", "aliases": [ "CVE-2024-30614" ], "details": "An issue in Ametys CMS v4.5.0 and before allows attackers to obtain sensitive information via exposed resources to the error scope.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-209" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-12T06:15:06Z" diff --git a/advisories/unreviewed/2024/04/GHSA-8g9c-f7h3-mxcj/GHSA-8g9c-f7h3-mxcj.json b/advisories/unreviewed/2024/04/GHSA-8g9c-f7h3-mxcj/GHSA-8g9c-f7h3-mxcj.json index 2a2d4715638..ac6b3ab5781 100644 --- a/advisories/unreviewed/2024/04/GHSA-8g9c-f7h3-mxcj/GHSA-8g9c-f7h3-mxcj.json +++ b/advisories/unreviewed/2024/04/GHSA-8g9c-f7h3-mxcj/GHSA-8g9c-f7h3-mxcj.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-285" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-9w6w-gqmh-gxp9/GHSA-9w6w-gqmh-gxp9.json b/advisories/unreviewed/2024/04/GHSA-9w6w-gqmh-gxp9/GHSA-9w6w-gqmh-gxp9.json index 9d61759defb..cdf07bbce57 100644 --- a/advisories/unreviewed/2024/04/GHSA-9w6w-gqmh-gxp9/GHSA-9w6w-gqmh-gxp9.json +++ b/advisories/unreviewed/2024/04/GHSA-9w6w-gqmh-gxp9/GHSA-9w6w-gqmh-gxp9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9w6w-gqmh-gxp9", - "modified": "2024-04-10T21:30:32Z", + "modified": "2025-03-27T21:31:08Z", "published": "2024-04-10T21:30:32Z", "aliases": [ "CVE-2021-47212" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: Update error handler for UCTX and UMEM\n\nIn the fast unload flow, the device state is set to internal error,\nwhich indicates that the driver started the destroy process.\nIn this case, when a destroy command is being executed, it should return\nMLX5_CMD_STAT_OK.\nFix MLX5_CMD_OP_DESTROY_UCTX and MLX5_CMD_OP_DESTROY_UMEM to return OK\ninstead of EIO.\n\nThis fixes a call trace in the umem release process -\n[ 2633.536695] Call Trace:\n[ 2633.537518] ib_uverbs_remove_one+0xc3/0x140 [ib_uverbs]\n[ 2633.538596] remove_client_context+0x8b/0xd0 [ib_core]\n[ 2633.539641] disable_device+0x8c/0x130 [ib_core]\n[ 2633.540615] __ib_unregister_device+0x35/0xa0 [ib_core]\n[ 2633.541640] ib_unregister_device+0x21/0x30 [ib_core]\n[ 2633.542663] __mlx5_ib_remove+0x38/0x90 [mlx5_ib]\n[ 2633.543640] auxiliary_bus_remove+0x1e/0x30 [auxiliary]\n[ 2633.544661] device_release_driver_internal+0x103/0x1f0\n[ 2633.545679] bus_remove_device+0xf7/0x170\n[ 2633.546640] device_del+0x181/0x410\n[ 2633.547606] mlx5_rescan_drivers_locked.part.10+0x63/0x160 [mlx5_core]\n[ 2633.548777] mlx5_unregister_device+0x27/0x40 [mlx5_core]\n[ 2633.549841] mlx5_uninit_one+0x21/0xc0 [mlx5_core]\n[ 2633.550864] remove_one+0x69/0xe0 [mlx5_core]\n[ 2633.551819] pci_device_remove+0x3b/0xc0\n[ 2633.552731] device_release_driver_internal+0x103/0x1f0\n[ 2633.553746] unbind_store+0xf6/0x130\n[ 2633.554657] kernfs_fop_write+0x116/0x190\n[ 2633.555567] vfs_write+0xa5/0x1a0\n[ 2633.556407] ksys_write+0x4f/0xb0\n[ 2633.557233] do_syscall_64+0x5b/0x1a0\n[ 2633.558071] entry_SYSCALL_64_after_hwframe+0x65/0xca\n[ 2633.559018] RIP: 0033:0x7f9977132648\n[ 2633.559821] Code: 89 02 48 c7 c0 ff ff ff ff eb b3 0f 1f 80 00 00 00 00 f3 0f 1e fa 48 8d 05 55 6f 2d 00 8b 00 85 c0 75 17 b8 01 00 00 00 0f 05 <48> 3d 00 f0 ff ff 77 58 c3 0f 1f 80 00 00 00 00 41 54 49 89 d4 55\n[ 2633.562332] RSP: 002b:00007fffb1a83888 EFLAGS: 00000246 ORIG_RAX: 0000000000000001\n[ 2633.563472] RAX: ffffffffffffffda RBX: 000000000000000c RCX: 00007f9977132648\n[ 2633.564541] RDX: 000000000000000c RSI: 000055b90546e230 RDI: 0000000000000001\n[ 2633.565596] RBP: 000055b90546e230 R08: 00007f9977406860 R09: 00007f9977a54740\n[ 2633.566653] R10: 0000000000000000 R11: 0000000000000246 R12: 00007f99774056e0\n[ 2633.567692] R13: 000000000000000c R14: 00007f9977400880 R15: 000000000000000c\n[ 2633.568725] ---[ end trace 10b4fe52945e544d ]---", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -25,7 +30,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-10T19:15:48Z" diff --git a/advisories/unreviewed/2024/04/GHSA-c7qm-83h5-vx5f/GHSA-c7qm-83h5-vx5f.json b/advisories/unreviewed/2024/04/GHSA-c7qm-83h5-vx5f/GHSA-c7qm-83h5-vx5f.json index 52773785b19..3f592702421 100644 --- a/advisories/unreviewed/2024/04/GHSA-c7qm-83h5-vx5f/GHSA-c7qm-83h5-vx5f.json +++ b/advisories/unreviewed/2024/04/GHSA-c7qm-83h5-vx5f/GHSA-c7qm-83h5-vx5f.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-120" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-c8fg-x59g-83c8/GHSA-c8fg-x59g-83c8.json b/advisories/unreviewed/2024/04/GHSA-c8fg-x59g-83c8/GHSA-c8fg-x59g-83c8.json index 3155c3e0d3a..82d59ea20c1 100644 --- a/advisories/unreviewed/2024/04/GHSA-c8fg-x59g-83c8/GHSA-c8fg-x59g-83c8.json +++ b/advisories/unreviewed/2024/04/GHSA-c8fg-x59g-83c8/GHSA-c8fg-x59g-83c8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c8fg-x59g-83c8", - "modified": "2024-04-17T12:32:02Z", + "modified": "2025-03-27T21:31:09Z", "published": "2024-04-17T12:32:02Z", "aliases": [ "CVE-2024-26824" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: algif_hash - Remove bogus SGL free on zero-length error path\n\nWhen a zero-length message is hashed by algif_hash, and an error\nis triggered, it tries to free an SG list that was never allocated\nin the first place. Fix this by not freeing the SG list on the\nzero-length error path.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -29,7 +34,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T10:15:09Z" diff --git a/advisories/unreviewed/2024/04/GHSA-fqrj-wwq6-q94w/GHSA-fqrj-wwq6-q94w.json b/advisories/unreviewed/2024/04/GHSA-fqrj-wwq6-q94w/GHSA-fqrj-wwq6-q94w.json index 2b757adfec7..09aed45014d 100644 --- a/advisories/unreviewed/2024/04/GHSA-fqrj-wwq6-q94w/GHSA-fqrj-wwq6-q94w.json +++ b/advisories/unreviewed/2024/04/GHSA-fqrj-wwq6-q94w/GHSA-fqrj-wwq6-q94w.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fqrj-wwq6-q94w", - "modified": "2024-04-15T06:30:34Z", + "modified": "2025-03-27T21:31:08Z", "published": "2024-04-15T06:30:34Z", "aliases": [ "CVE-2024-0399" ], "details": "The WooCommerce Customers Manager WordPress plugin before 29.7 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to an SQL injection exploitable by Subscriber+ role.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-15T05:15:14Z" diff --git a/advisories/unreviewed/2024/04/GHSA-g77r-g63q-vjf8/GHSA-g77r-g63q-vjf8.json b/advisories/unreviewed/2024/04/GHSA-g77r-g63q-vjf8/GHSA-g77r-g63q-vjf8.json index 9bb5bd4cf2c..989e97a03ed 100644 --- a/advisories/unreviewed/2024/04/GHSA-g77r-g63q-vjf8/GHSA-g77r-g63q-vjf8.json +++ b/advisories/unreviewed/2024/04/GHSA-g77r-g63q-vjf8/GHSA-g77r-g63q-vjf8.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-g77r-g63q-vjf8", - "modified": "2024-04-10T21:30:31Z", + "modified": "2025-03-27T21:31:07Z", "published": "2024-04-10T21:30:31Z", "aliases": [ "CVE-2021-47201" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\niavf: free q_vectors before queues in iavf_disable_vf\n\niavf_free_queues() clears adapter->num_active_queues, which\niavf_free_q_vectors() relies on, so swap the order of these two function\ncalls in iavf_disable_vf(). This resolves a panic encountered when the\ninterface is disabled and then later brought up again after PF\ncommunication is restored.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -33,7 +38,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-10T19:15:48Z" diff --git a/advisories/unreviewed/2024/04/GHSA-gvmr-9xc2-m89g/GHSA-gvmr-9xc2-m89g.json b/advisories/unreviewed/2024/04/GHSA-gvmr-9xc2-m89g/GHSA-gvmr-9xc2-m89g.json index 20973b88ab7..537c6f82e44 100644 --- a/advisories/unreviewed/2024/04/GHSA-gvmr-9xc2-m89g/GHSA-gvmr-9xc2-m89g.json +++ b/advisories/unreviewed/2024/04/GHSA-gvmr-9xc2-m89g/GHSA-gvmr-9xc2-m89g.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-gvqq-xg2j-r2p6/GHSA-gvqq-xg2j-r2p6.json b/advisories/unreviewed/2024/04/GHSA-gvqq-xg2j-r2p6/GHSA-gvqq-xg2j-r2p6.json index 11499df9841..646017ab0dd 100644 --- a/advisories/unreviewed/2024/04/GHSA-gvqq-xg2j-r2p6/GHSA-gvqq-xg2j-r2p6.json +++ b/advisories/unreviewed/2024/04/GHSA-gvqq-xg2j-r2p6/GHSA-gvqq-xg2j-r2p6.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-269" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-m59q-rgx4-6vq4/GHSA-m59q-rgx4-6vq4.json b/advisories/unreviewed/2024/04/GHSA-m59q-rgx4-6vq4/GHSA-m59q-rgx4-6vq4.json index 614ce840534..5170547dd7e 100644 --- a/advisories/unreviewed/2024/04/GHSA-m59q-rgx4-6vq4/GHSA-m59q-rgx4-6vq4.json +++ b/advisories/unreviewed/2024/04/GHSA-m59q-rgx4-6vq4/GHSA-m59q-rgx4-6vq4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-m59q-rgx4-6vq4", - "modified": "2024-04-10T21:30:32Z", + "modified": "2025-03-27T21:31:08Z", "published": "2024-04-10T21:30:32Z", "aliases": [ "CVE-2021-47209" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsched/fair: Prevent dead task groups from regaining cfs_rq's\n\nKevin is reporting crashes which point to a use-after-free of a cfs_rq\nin update_blocked_averages(). Initial debugging revealed that we've\nlive cfs_rq's (on_list=1) in an about to be kfree()'d task group in\nfree_fair_sched_group(). However, it was unclear how that can happen.\n\nHis kernel config happened to lead to a layout of struct sched_entity\nthat put the 'my_q' member directly into the middle of the object\nwhich makes it incidentally overlap with SLUB's freelist pointer.\nThat, in combination with SLAB_FREELIST_HARDENED's freelist pointer\nmangling, leads to a reliable access violation in form of a #GP which\nmade the UAF fail fast.\n\nMichal seems to have run into the same issue[1]. He already correctly\ndiagnosed that commit a7b359fc6a37 (\"sched/fair: Correctly insert\ncfs_rq's to list on unthrottle\") is causing the preconditions for the\nUAF to happen by re-adding cfs_rq's also to task groups that have no\nmore running tasks, i.e. also to dead ones. His analysis, however,\nmisses the real root cause and it cannot be seen from the crash\nbacktrace only, as the real offender is tg_unthrottle_up() getting\ncalled via sched_cfs_period_timer() via the timer interrupt at an\ninconvenient time.\n\nWhen unregister_fair_sched_group() unlinks all cfs_rq's from the dying\ntask group, it doesn't protect itself from getting interrupted. If the\ntimer interrupt triggers while we iterate over all CPUs or after\nunregister_fair_sched_group() has finished but prior to unlinking the\ntask group, sched_cfs_period_timer() will execute and walk the list of\ntask groups, trying to unthrottle cfs_rq's, i.e. re-add them to the\ndying task group. These will later -- in free_fair_sched_group() -- be\nkfree()'ed while still being linked, leading to the fireworks Kevin\nand Michal are seeing.\n\nTo fix this race, ensure the dying task group gets unlinked first.\nHowever, simply switching the order of unregistering and unlinking the\ntask group isn't sufficient, as concurrent RCU walkers might still see\nit, as can be seen below:\n\n CPU1: CPU2:\n : timer IRQ:\n : do_sched_cfs_period_timer():\n : :\n : distribute_cfs_runtime():\n : rcu_read_lock();\n : :\n : unthrottle_cfs_rq():\n sched_offline_group(): :\n : walk_tg_tree_from(…,tg_unthrottle_up,…):\n list_del_rcu(&tg->list); :\n (1) : list_for_each_entry_rcu(child, &parent->children, siblings)\n : :\n (2) list_del_rcu(&tg->siblings); :\n : tg_unthrottle_up():\n unregister_fair_sched_group(): struct cfs_rq *cfs_rq = tg->cfs_rq[cpu_of(rq)];\n : :\n list_del_leaf_cfs_rq(tg->cfs_rq[cpu]); :\n : :\n : if (!cfs_rq_is_decayed(cfs_rq) || cfs_rq->nr_running)\n (3) : list_add_leaf_cfs_rq(cfs_rq);\n : :\n : :\n : :\n : :\n : \n---truncated---", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-10T19:15:48Z" diff --git a/advisories/unreviewed/2024/04/GHSA-mm47-557m-fxpp/GHSA-mm47-557m-fxpp.json b/advisories/unreviewed/2024/04/GHSA-mm47-557m-fxpp/GHSA-mm47-557m-fxpp.json index ffff8a4efda..a808ded3a9e 100644 --- a/advisories/unreviewed/2024/04/GHSA-mm47-557m-fxpp/GHSA-mm47-557m-fxpp.json +++ b/advisories/unreviewed/2024/04/GHSA-mm47-557m-fxpp/GHSA-mm47-557m-fxpp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mm47-557m-fxpp", - "modified": "2024-04-04T00:33:13Z", + "modified": "2025-03-27T21:31:03Z", "published": "2024-04-04T00:33:13Z", "aliases": [ "CVE-2024-29225" ], "details": "WRC-X3200GST3-B v1.25 and earlier, and WRC-G01-W v1.24 and earlier allow a network-adjacent unauthenticated attacker to obtain the configuration file containing sensitive information by sending a specially crafted request.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-552" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-04T00:15:07Z" diff --git a/advisories/unreviewed/2024/04/GHSA-mw3g-jr7f-3gg4/GHSA-mw3g-jr7f-3gg4.json b/advisories/unreviewed/2024/04/GHSA-mw3g-jr7f-3gg4/GHSA-mw3g-jr7f-3gg4.json index 7ce2a2d0ec8..a8f514a00e2 100644 --- a/advisories/unreviewed/2024/04/GHSA-mw3g-jr7f-3gg4/GHSA-mw3g-jr7f-3gg4.json +++ b/advisories/unreviewed/2024/04/GHSA-mw3g-jr7f-3gg4/GHSA-mw3g-jr7f-3gg4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mw3g-jr7f-3gg4", - "modified": "2024-06-27T12:30:45Z", + "modified": "2025-03-27T21:31:06Z", "published": "2024-04-10T15:30:40Z", "aliases": [ "CVE-2024-26816" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86, relocs: Ignore relocations in .notes section\n\nWhen building with CONFIG_XEN_PV=y, .text symbols are emitted into\nthe .notes section so that Xen can find the \"startup_xen\" entry point.\nThis information is used prior to booting the kernel, so relocations\nare not useful. In fact, performing relocations against the .notes\nsection means that the KASLR base is exposed since /sys/kernel/notes\nis world-readable.\n\nTo avoid leaking the KASLR base without breaking unprivileged tools that\nare expecting to read /sys/kernel/notes, skip performing relocations in\nthe .notes section. The values readable in .notes are then identical to\nthose found in System.map.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -60,8 +65,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-770" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-10T14:15:07Z" diff --git a/advisories/unreviewed/2024/04/GHSA-qfp6-v96m-74pc/GHSA-qfp6-v96m-74pc.json b/advisories/unreviewed/2024/04/GHSA-qfp6-v96m-74pc/GHSA-qfp6-v96m-74pc.json index 0f3e40de932..666c36279b5 100644 --- a/advisories/unreviewed/2024/04/GHSA-qfp6-v96m-74pc/GHSA-qfp6-v96m-74pc.json +++ b/advisories/unreviewed/2024/04/GHSA-qfp6-v96m-74pc/GHSA-qfp6-v96m-74pc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qfp6-v96m-74pc", - "modified": "2024-04-24T06:30:31Z", + "modified": "2025-03-27T21:31:11Z", "published": "2024-04-24T06:30:30Z", "aliases": [ "CVE-2024-28613" ], "details": "SQL Injection vulnerability in PHP Task Management System v.1.0 allows a remote attacker to escalate privileges and obtain sensitive information via the task_id parameter of the task-details.php, and edit-task.php component.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-24T04:15:18Z" diff --git a/advisories/unreviewed/2024/04/GHSA-rg6q-wc9f-whjv/GHSA-rg6q-wc9f-whjv.json b/advisories/unreviewed/2024/04/GHSA-rg6q-wc9f-whjv/GHSA-rg6q-wc9f-whjv.json index 8bda375d041..73e9e6585d1 100644 --- a/advisories/unreviewed/2024/04/GHSA-rg6q-wc9f-whjv/GHSA-rg6q-wc9f-whjv.json +++ b/advisories/unreviewed/2024/04/GHSA-rg6q-wc9f-whjv/GHSA-rg6q-wc9f-whjv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rg6q-wc9f-whjv", - "modified": "2024-04-03T18:30:40Z", + "modified": "2025-03-27T21:31:03Z", "published": "2024-04-03T18:30:40Z", "aliases": [ "CVE-2023-45552" ], "details": "In VeridiumID before 3.5.0, a stored cross-site scripting (XSS) vulnerability has been discovered in the admin portal that allows an authenticated attacker to take over all accounts by sending malicious input via the self-service portal.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-03T17:15:47Z" diff --git a/advisories/unreviewed/2024/04/GHSA-rr47-vpr9-84rm/GHSA-rr47-vpr9-84rm.json b/advisories/unreviewed/2024/04/GHSA-rr47-vpr9-84rm/GHSA-rr47-vpr9-84rm.json index 0afed9a331b..f84e9950790 100644 --- a/advisories/unreviewed/2024/04/GHSA-rr47-vpr9-84rm/GHSA-rr47-vpr9-84rm.json +++ b/advisories/unreviewed/2024/04/GHSA-rr47-vpr9-84rm/GHSA-rr47-vpr9-84rm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rr47-vpr9-84rm", - "modified": "2024-04-10T21:30:32Z", + "modified": "2025-03-27T21:31:08Z", "published": "2024-04-10T21:30:32Z", "aliases": [ "CVE-2021-47214" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nhugetlb, userfaultfd: fix reservation restore on userfaultfd error\n\nCurrently in the is_continue case in hugetlb_mcopy_atomic_pte(), if we\nbail out using \"goto out_release_unlock;\" in the cases where idx >=\nsize, or !huge_pte_none(), the code will detect that new_pagecache_page\n== false, and so call restore_reserve_on_error(). In this case I see\nrestore_reserve_on_error() delete the reservation, and the following\ncall to remove_inode_hugepages() will increment h->resv_hugepages\ncausing a 100% reproducible leak.\n\nWe should treat the is_continue case similar to adding a page into the\npagecache and set new_pagecache_page to true, to indicate that there is\nno reservation to restore on the error path, and we need not call\nrestore_reserve_on_error(). Rename new_pagecache_page to\npage_in_pagecache to make that clear.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-10T19:15:48Z" diff --git a/advisories/unreviewed/2024/04/GHSA-vfr6-9rmm-7rvg/GHSA-vfr6-9rmm-7rvg.json b/advisories/unreviewed/2024/04/GHSA-vfr6-9rmm-7rvg/GHSA-vfr6-9rmm-7rvg.json index 7a201408c52..ab015272c2e 100644 --- a/advisories/unreviewed/2024/04/GHSA-vfr6-9rmm-7rvg/GHSA-vfr6-9rmm-7rvg.json +++ b/advisories/unreviewed/2024/04/GHSA-vfr6-9rmm-7rvg/GHSA-vfr6-9rmm-7rvg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vfr6-9rmm-7rvg", - "modified": "2024-04-17T12:32:02Z", + "modified": "2025-03-27T21:31:10Z", "published": "2024-04-17T12:32:02Z", "aliases": [ "CVE-2024-26826" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: fix data re-injection from stale subflow\n\nWhen the MPTCP PM detects that a subflow is stale, all the packet\nscheduler must re-inject all the mptcp-level unacked data. To avoid\nacquiring unneeded locks, it first try to check if any unacked data\nis present at all in the RTX queue, but such check is currently\nbroken, as it uses TCP-specific helper on an MPTCP socket.\n\nFunnily enough fuzzers and static checkers are happy, as the accessed\nmemory still belongs to the mptcp_sock struct, and even from a\nfunctional perspective the recovery completed successfully, as\nthe short-cut test always failed.\n\nA recent unrelated TCP change - commit d5fed5addb2b (\"tcp: reorganize\ntcp_sock fast path variables\") - exposed the issue, as the tcp field\nreorganization makes the mptcp code always skip the re-inection.\n\nFix the issue dropping the bogus call: we are on a slow path, the early\noptimization proved once again to be evil.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -37,7 +42,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T10:15:09Z" diff --git a/advisories/unreviewed/2024/04/GHSA-w94f-xh79-q24v/GHSA-w94f-xh79-q24v.json b/advisories/unreviewed/2024/04/GHSA-w94f-xh79-q24v/GHSA-w94f-xh79-q24v.json index 6e823242395..faac4942315 100644 --- a/advisories/unreviewed/2024/04/GHSA-w94f-xh79-q24v/GHSA-w94f-xh79-q24v.json +++ b/advisories/unreviewed/2024/04/GHSA-w94f-xh79-q24v/GHSA-w94f-xh79-q24v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w94f-xh79-q24v", - "modified": "2024-04-04T09:30:36Z", + "modified": "2025-03-27T21:31:04Z", "published": "2024-04-04T09:30:36Z", "aliases": [ "CVE-2024-26806" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nspi: cadence-qspi: remove system-wide suspend helper calls from runtime PM hooks\n\nThe ->runtime_suspend() and ->runtime_resume() callbacks are not\nexpected to call spi_controller_suspend() and spi_controller_resume().\nRemove calls to those in the cadence-qspi driver.\n\nThose helpers have two roles currently:\n - They stop/start the queue, including dealing with the kworker.\n - They toggle the SPI controller SPI_CONTROLLER_SUSPENDED flag. It\n requires acquiring ctlr->bus_lock_mutex.\n\nStep one is irrelevant because cadence-qspi is not queued. Step two\nhowever has two implications:\n - A deadlock occurs, because ->runtime_resume() is called in a context\n where the lock is already taken (in the ->exec_op() callback, where\n the usage count is incremented).\n - It would disallow all operations once the device is auto-suspended.\n\nHere is a brief call tree highlighting the mutex deadlock:\n\nspi_mem_exec_op()\n ...\n spi_mem_access_start()\n mutex_lock(&ctlr->bus_lock_mutex)\n\n cqspi_exec_mem_op()\n pm_runtime_resume_and_get()\n cqspi_resume()\n spi_controller_resume()\n mutex_lock(&ctlr->bus_lock_mutex)\n ...\n\n spi_mem_access_end()\n mutex_unlock(&ctlr->bus_lock_mutex)\n ...", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-667" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-04T09:15:09Z" diff --git a/advisories/unreviewed/2024/04/GHSA-xcf9-x48q-v8xv/GHSA-xcf9-x48q-v8xv.json b/advisories/unreviewed/2024/04/GHSA-xcf9-x48q-v8xv/GHSA-xcf9-x48q-v8xv.json index d91df20e866..2f01dc26db4 100644 --- a/advisories/unreviewed/2024/04/GHSA-xcf9-x48q-v8xv/GHSA-xcf9-x48q-v8xv.json +++ b/advisories/unreviewed/2024/04/GHSA-xcf9-x48q-v8xv/GHSA-xcf9-x48q-v8xv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xcf9-x48q-v8xv", - "modified": "2024-04-17T12:32:02Z", + "modified": "2025-03-27T21:31:09Z", "published": "2024-04-17T12:32:02Z", "aliases": [ "CVE-2024-26823" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nirqchip/gic-v3-its: Restore quirk probing for ACPI-based systems\n\nWhile refactoring the way the ITSs are probed, the handling of quirks\napplicable to ACPI-based platforms was lost. As a result, systems such as\nHIP07 lose their GICv4 functionnality, and some other may even fail to\nboot, unless they are configured to boot with DT.\n\nMove the enabling of quirks into its_probe_one(), making it common to all\nfirmware implementations.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -29,7 +34,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-17T10:15:09Z" diff --git a/advisories/unreviewed/2024/04/GHSA-xr98-c22v-cfcg/GHSA-xr98-c22v-cfcg.json b/advisories/unreviewed/2024/04/GHSA-xr98-c22v-cfcg/GHSA-xr98-c22v-cfcg.json index 44a18803e46..92399cb6932 100644 --- a/advisories/unreviewed/2024/04/GHSA-xr98-c22v-cfcg/GHSA-xr98-c22v-cfcg.json +++ b/advisories/unreviewed/2024/04/GHSA-xr98-c22v-cfcg/GHSA-xr98-c22v-cfcg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xr98-c22v-cfcg", - "modified": "2024-04-10T15:30:40Z", + "modified": "2025-03-27T21:31:06Z", "published": "2024-04-10T15:30:40Z", "aliases": [ "CVE-2024-26815" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: taprio: proper TCA_TAPRIO_TC_ENTRY_INDEX check\n\ntaprio_parse_tc_entry() is not correctly checking\nTCA_TAPRIO_TC_ENTRY_INDEX attribute:\n\n\tint tc; // Signed value\n\n\ttc = nla_get_u32(tb[TCA_TAPRIO_TC_ENTRY_INDEX]);\n\tif (tc >= TC_QOPT_MAX_QUEUE) {\n\t\tNL_SET_ERR_MSG_MOD(extack, \"TC entry index out of range\");\n\t\treturn -ERANGE;\n\t}\n\nsyzbot reported that it could fed arbitary negative values:\n\nUBSAN: shift-out-of-bounds in net/sched/sch_taprio.c:1722:18\nshift exponent -2147418108 is negative\nCPU: 0 PID: 5066 Comm: syz-executor367 Not tainted 6.8.0-rc7-syzkaller-00136-gc8a5c731fd12 #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/29/2024\nCall Trace:\n \n __dump_stack lib/dump_stack.c:88 [inline]\n dump_stack_lvl+0x1e7/0x2e0 lib/dump_stack.c:106\n ubsan_epilogue lib/ubsan.c:217 [inline]\n __ubsan_handle_shift_out_of_bounds+0x3c7/0x420 lib/ubsan.c:386\n taprio_parse_tc_entry net/sched/sch_taprio.c:1722 [inline]\n taprio_parse_tc_entries net/sched/sch_taprio.c:1768 [inline]\n taprio_change+0xb87/0x57d0 net/sched/sch_taprio.c:1877\n taprio_init+0x9da/0xc80 net/sched/sch_taprio.c:2134\n qdisc_create+0x9d4/0x1190 net/sched/sch_api.c:1355\n tc_modify_qdisc+0xa26/0x1e40 net/sched/sch_api.c:1776\n rtnetlink_rcv_msg+0x885/0x1040 net/core/rtnetlink.c:6617\n netlink_rcv_skb+0x1e3/0x430 net/netlink/af_netlink.c:2543\n netlink_unicast_kernel net/netlink/af_netlink.c:1341 [inline]\n netlink_unicast+0x7ea/0x980 net/netlink/af_netlink.c:1367\n netlink_sendmsg+0xa3b/0xd70 net/netlink/af_netlink.c:1908\n sock_sendmsg_nosec net/socket.c:730 [inline]\n __sock_sendmsg+0x221/0x270 net/socket.c:745\n ____sys_sendmsg+0x525/0x7d0 net/socket.c:2584\n ___sys_sendmsg net/socket.c:2638 [inline]\n __sys_sendmsg+0x2b0/0x3a0 net/socket.c:2667\n do_syscall_64+0xf9/0x240\n entry_SYSCALL_64_after_hwframe+0x6f/0x77\nRIP: 0033:0x7f1b2dea3759\nCode: 48 83 c4 28 c3 e8 d7 19 00 00 0f 1f 80 00 00 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 b8 ff ff ff f7 d8 64 89 01 48\nRSP: 002b:00007ffd4de452f8 EFLAGS: 00000246 ORIG_RAX: 000000000000002e\nRAX: ffffffffffffffda RBX: 00007f1b2def0390 RCX: 00007f1b2dea3759\nRDX: 0000000000000000 RSI: 00000000200007c0 RDI: 0000000000000004\nRBP: 0000000000000003 R08: 0000555500000000 R09: 0000555500000000\nR10: 0000555500000000 R11: 0000000000000246 R12: 00007ffd4de45340\nR13: 00007ffd4de45310 R14: 0000000000000001 R15: 00007ffd4de45340", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -36,8 +41,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-787" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-04-10T11:15:49Z" diff --git a/advisories/unreviewed/2024/05/GHSA-442q-pmc8-45rg/GHSA-442q-pmc8-45rg.json b/advisories/unreviewed/2024/05/GHSA-442q-pmc8-45rg/GHSA-442q-pmc8-45rg.json index c5b350583b6..2b306e70920 100644 --- a/advisories/unreviewed/2024/05/GHSA-442q-pmc8-45rg/GHSA-442q-pmc8-45rg.json +++ b/advisories/unreviewed/2024/05/GHSA-442q-pmc8-45rg/GHSA-442q-pmc8-45rg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-442q-pmc8-45rg", - "modified": "2024-05-06T21:30:38Z", + "modified": "2025-03-27T21:31:12Z", "published": "2024-05-06T21:30:38Z", "aliases": [ "CVE-2023-33548" ], "details": "Cross Site Scripting (XSS) vulnerability in ASUS RT-AC51U with firmware versions up to and including 3.0.0.4.380.8591 allows attackers to run arbitrary code via the WPA Pre-Shared Key field.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-06T21:15:48Z" diff --git a/advisories/unreviewed/2024/05/GHSA-65fw-2c82-m8v2/GHSA-65fw-2c82-m8v2.json b/advisories/unreviewed/2024/05/GHSA-65fw-2c82-m8v2/GHSA-65fw-2c82-m8v2.json index 28c38e25cc7..c6d8977056f 100644 --- a/advisories/unreviewed/2024/05/GHSA-65fw-2c82-m8v2/GHSA-65fw-2c82-m8v2.json +++ b/advisories/unreviewed/2024/05/GHSA-65fw-2c82-m8v2/GHSA-65fw-2c82-m8v2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-65fw-2c82-m8v2", - "modified": "2024-05-01T21:30:38Z", + "modified": "2025-03-27T21:31:12Z", "published": "2024-05-01T21:30:38Z", "aliases": [ "CVE-2024-33307" ], "details": "SourceCodester Laboratory Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via \"Last Name\" parameter in Create User.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-01T20:15:12Z" diff --git a/advisories/unreviewed/2024/05/GHSA-68wx-vmj5-rjxj/GHSA-68wx-vmj5-rjxj.json b/advisories/unreviewed/2024/05/GHSA-68wx-vmj5-rjxj/GHSA-68wx-vmj5-rjxj.json index a7a85c73cfe..b463d5ad087 100644 --- a/advisories/unreviewed/2024/05/GHSA-68wx-vmj5-rjxj/GHSA-68wx-vmj5-rjxj.json +++ b/advisories/unreviewed/2024/05/GHSA-68wx-vmj5-rjxj/GHSA-68wx-vmj5-rjxj.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-68wx-vmj5-rjxj", - "modified": "2024-05-22T18:30:41Z", + "modified": "2025-03-27T21:31:14Z", "published": "2024-05-22T18:30:41Z", "aliases": [ "CVE-2024-35362" ], "details": "Ecshop 3.6 is vulnerable to Cross Site Scripting (XSS) via ecshop/article_cat.php.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-22T16:15:10Z" diff --git a/advisories/unreviewed/2024/05/GHSA-7gh2-59h4-gcm3/GHSA-7gh2-59h4-gcm3.json b/advisories/unreviewed/2024/05/GHSA-7gh2-59h4-gcm3/GHSA-7gh2-59h4-gcm3.json index 7aae2b6e1e8..f00be133718 100644 --- a/advisories/unreviewed/2024/05/GHSA-7gh2-59h4-gcm3/GHSA-7gh2-59h4-gcm3.json +++ b/advisories/unreviewed/2024/05/GHSA-7gh2-59h4-gcm3/GHSA-7gh2-59h4-gcm3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7gh2-59h4-gcm3", - "modified": "2024-05-15T06:30:44Z", + "modified": "2025-03-27T21:31:14Z", "published": "2024-05-15T06:30:44Z", "aliases": [ "CVE-2024-3823" ], "details": "The Base64 Encoder/Decoder WordPress plugin through 0.9.2 does not have CSRF check when updating its settings, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-15T06:15:14Z" diff --git a/advisories/unreviewed/2024/05/GHSA-8296-4xrf-2xw7/GHSA-8296-4xrf-2xw7.json b/advisories/unreviewed/2024/05/GHSA-8296-4xrf-2xw7/GHSA-8296-4xrf-2xw7.json index e6710019b75..67f4b4753a2 100644 --- a/advisories/unreviewed/2024/05/GHSA-8296-4xrf-2xw7/GHSA-8296-4xrf-2xw7.json +++ b/advisories/unreviewed/2024/05/GHSA-8296-4xrf-2xw7/GHSA-8296-4xrf-2xw7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8296-4xrf-2xw7", - "modified": "2024-05-20T15:31:45Z", + "modified": "2025-03-27T21:31:14Z", "published": "2024-05-20T15:31:45Z", "aliases": [ "CVE-2024-34952" ], "details": "taurusxin ncmdump v1.3.2 was discovered to contain a segmentation violation via the NeteaseCrypt::FixMetadata() function at /src/ncmcrypt.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted .ncm file.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-20T14:15:09Z" diff --git a/advisories/unreviewed/2024/05/GHSA-8rjh-f75w-mvh9/GHSA-8rjh-f75w-mvh9.json b/advisories/unreviewed/2024/05/GHSA-8rjh-f75w-mvh9/GHSA-8rjh-f75w-mvh9.json index abf4a7ca626..50ceeef21c5 100644 --- a/advisories/unreviewed/2024/05/GHSA-8rjh-f75w-mvh9/GHSA-8rjh-f75w-mvh9.json +++ b/advisories/unreviewed/2024/05/GHSA-8rjh-f75w-mvh9/GHSA-8rjh-f75w-mvh9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8rjh-f75w-mvh9", - "modified": "2024-05-21T18:31:24Z", + "modified": "2025-03-27T21:31:14Z", "published": "2024-05-21T18:31:24Z", "aliases": [ "CVE-2024-22275" @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-99x9-vrrc-xxw3/GHSA-99x9-vrrc-xxw3.json b/advisories/unreviewed/2024/05/GHSA-99x9-vrrc-xxw3/GHSA-99x9-vrrc-xxw3.json index 6771deb000f..eeaec76fc9d 100644 --- a/advisories/unreviewed/2024/05/GHSA-99x9-vrrc-xxw3/GHSA-99x9-vrrc-xxw3.json +++ b/advisories/unreviewed/2024/05/GHSA-99x9-vrrc-xxw3/GHSA-99x9-vrrc-xxw3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-99x9-vrrc-xxw3", - "modified": "2024-05-31T18:31:16Z", + "modified": "2025-03-27T21:31:15Z", "published": "2024-05-31T18:31:16Z", "aliases": [ "CVE-2023-38551" @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-93" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-g7qc-r5p9-r36r/GHSA-g7qc-r5p9-r36r.json b/advisories/unreviewed/2024/05/GHSA-g7qc-r5p9-r36r/GHSA-g7qc-r5p9-r36r.json index 76c96c336f6..e1f37178a86 100644 --- a/advisories/unreviewed/2024/05/GHSA-g7qc-r5p9-r36r/GHSA-g7qc-r5p9-r36r.json +++ b/advisories/unreviewed/2024/05/GHSA-g7qc-r5p9-r36r/GHSA-g7qc-r5p9-r36r.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-g7qc-r5p9-r36r", - "modified": "2024-05-16T15:31:37Z", + "modified": "2025-03-27T21:31:14Z", "published": "2024-05-16T15:31:37Z", "aliases": [ "CVE-2024-31142" ], - "details": "Because of a logical error in XSA-407 (Branch Type Confusion), the\nmitigation is not applied properly when it is intended to be used.\nXSA-434 (Speculative Return Stack Overflow) uses the same\ninfrastructure, so is equally impacted.\n\nFor more details, see:\n https://xenbits.xen.org/xsa/advisory-407.html\n https://xenbits.xen.org/xsa/advisory-434.html\n", - "severity": [], + "details": "Because of a logical error in XSA-407 (Branch Type Confusion), the\nmitigation is not applied properly when it is intended to be used.\nXSA-434 (Speculative Return Stack Overflow) uses the same\ninfrastructure, so is equally impacted.\n\nFor more details, see:\n https://xenbits.xen.org/xsa/advisory-407.html\n https://xenbits.xen.org/xsa/advisory-434.html", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-693" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-16T14:15:08Z" diff --git a/advisories/unreviewed/2024/05/GHSA-gvjh-r2g7-mjgx/GHSA-gvjh-r2g7-mjgx.json b/advisories/unreviewed/2024/05/GHSA-gvjh-r2g7-mjgx/GHSA-gvjh-r2g7-mjgx.json index d6903c4db04..81f4cf52b7d 100644 --- a/advisories/unreviewed/2024/05/GHSA-gvjh-r2g7-mjgx/GHSA-gvjh-r2g7-mjgx.json +++ b/advisories/unreviewed/2024/05/GHSA-gvjh-r2g7-mjgx/GHSA-gvjh-r2g7-mjgx.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-20" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-pfmv-h3cf-mr72/GHSA-pfmv-h3cf-mr72.json b/advisories/unreviewed/2024/05/GHSA-pfmv-h3cf-mr72/GHSA-pfmv-h3cf-mr72.json index 75c05bd522a..99e5e26302a 100644 --- a/advisories/unreviewed/2024/05/GHSA-pfmv-h3cf-mr72/GHSA-pfmv-h3cf-mr72.json +++ b/advisories/unreviewed/2024/05/GHSA-pfmv-h3cf-mr72/GHSA-pfmv-h3cf-mr72.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pfmv-h3cf-mr72", - "modified": "2024-05-08T06:30:48Z", + "modified": "2025-03-27T21:31:13Z", "published": "2024-05-08T06:30:48Z", "aliases": [ "CVE-2024-22264" @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-269" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-rc9x-h469-w6gc/GHSA-rc9x-h469-w6gc.json b/advisories/unreviewed/2024/05/GHSA-rc9x-h469-w6gc/GHSA-rc9x-h469-w6gc.json index 6bc6eac5e8d..69195959682 100644 --- a/advisories/unreviewed/2024/05/GHSA-rc9x-h469-w6gc/GHSA-rc9x-h469-w6gc.json +++ b/advisories/unreviewed/2024/05/GHSA-rc9x-h469-w6gc/GHSA-rc9x-h469-w6gc.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-vvrw-wrhf-4qp9/GHSA-vvrw-wrhf-4qp9.json b/advisories/unreviewed/2024/05/GHSA-vvrw-wrhf-4qp9/GHSA-vvrw-wrhf-4qp9.json index cdd77a2629f..3875abf8219 100644 --- a/advisories/unreviewed/2024/05/GHSA-vvrw-wrhf-4qp9/GHSA-vvrw-wrhf-4qp9.json +++ b/advisories/unreviewed/2024/05/GHSA-vvrw-wrhf-4qp9/GHSA-vvrw-wrhf-4qp9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vvrw-wrhf-4qp9", - "modified": "2024-05-19T21:30:23Z", + "modified": "2025-03-27T21:31:14Z", "published": "2024-05-19T21:30:23Z", "aliases": [ "CVE-2024-36070" ], "details": "tine before 2023.11.8, when an LDAP backend is used, allows anonymous remote attackers to obtain sensitive authentication information via setup.php because of getRegistryData in Setup/Frontend/Json.php. (An update is also available for the 2022.11 series.)", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-497" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-19T19:15:48Z" diff --git a/advisories/unreviewed/2024/05/GHSA-vw93-wqr3-x7vr/GHSA-vw93-wqr3-x7vr.json b/advisories/unreviewed/2024/05/GHSA-vw93-wqr3-x7vr/GHSA-vw93-wqr3-x7vr.json index 438b444831c..94269fa6de1 100644 --- a/advisories/unreviewed/2024/05/GHSA-vw93-wqr3-x7vr/GHSA-vw93-wqr3-x7vr.json +++ b/advisories/unreviewed/2024/05/GHSA-vw93-wqr3-x7vr/GHSA-vw93-wqr3-x7vr.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vw93-wqr3-x7vr", - "modified": "2024-05-21T06:30:51Z", + "modified": "2025-03-27T21:31:14Z", "published": "2024-05-21T06:30:51Z", "aliases": [ "CVE-2024-4372" ], "details": "The Carousel Slider WordPress plugin before 2.2.11 does not sanitise and escape some parameters, which could allow users with a role as low as editor to perform Cross-Site Scripting attacks", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-05-21T06:15:10Z" diff --git a/advisories/unreviewed/2024/06/GHSA-2p44-rc6w-2rvw/GHSA-2p44-rc6w-2rvw.json b/advisories/unreviewed/2024/06/GHSA-2p44-rc6w-2rvw/GHSA-2p44-rc6w-2rvw.json index 2846269439f..f96a6e1163e 100644 --- a/advisories/unreviewed/2024/06/GHSA-2p44-rc6w-2rvw/GHSA-2p44-rc6w-2rvw.json +++ b/advisories/unreviewed/2024/06/GHSA-2p44-rc6w-2rvw/GHSA-2p44-rc6w-2rvw.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2p44-rc6w-2rvw", - "modified": "2024-06-04T06:30:36Z", + "modified": "2025-03-27T21:31:15Z", "published": "2024-06-04T06:30:36Z", "aliases": [ "CVE-2024-0757" ], "details": "The Insert or Embed Articulate Content into WordPress plugin through 4.3000000023 is not properly filtering which file extensions are allowed to be imported on the server, allowing the uploading of malicious code within zip files", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-434" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-04T06:15:08Z" diff --git a/advisories/unreviewed/2024/06/GHSA-48fj-hh68-6w6q/GHSA-48fj-hh68-6w6q.json b/advisories/unreviewed/2024/06/GHSA-48fj-hh68-6w6q/GHSA-48fj-hh68-6w6q.json index ffcc10cd9cf..ceaf62d746e 100644 --- a/advisories/unreviewed/2024/06/GHSA-48fj-hh68-6w6q/GHSA-48fj-hh68-6w6q.json +++ b/advisories/unreviewed/2024/06/GHSA-48fj-hh68-6w6q/GHSA-48fj-hh68-6w6q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-48fj-hh68-6w6q", - "modified": "2024-06-05T18:30:36Z", + "modified": "2025-03-27T21:31:19Z", "published": "2024-06-05T18:30:36Z", "aliases": [ "CVE-2024-4009" @@ -11,6 +11,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:H/SC:L/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:X/V:D/RE:M/U:Green" } ], "affected": [], diff --git a/advisories/unreviewed/2024/06/GHSA-58c5-9mqc-q73p/GHSA-58c5-9mqc-q73p.json b/advisories/unreviewed/2024/06/GHSA-58c5-9mqc-q73p/GHSA-58c5-9mqc-q73p.json index b68828eb585..79c2feaebff 100644 --- a/advisories/unreviewed/2024/06/GHSA-58c5-9mqc-q73p/GHSA-58c5-9mqc-q73p.json +++ b/advisories/unreviewed/2024/06/GHSA-58c5-9mqc-q73p/GHSA-58c5-9mqc-q73p.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-58c5-9mqc-q73p", - "modified": "2024-06-03T21:30:43Z", + "modified": "2025-03-27T21:31:15Z", "published": "2024-06-03T21:30:43Z", "aliases": [ "CVE-2022-1242" ], "details": "Apport can be tricked into connecting to arbitrary sockets as the root user", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-20" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-03T19:15:09Z" diff --git a/advisories/unreviewed/2024/06/GHSA-7f3w-mgjh-m27h/GHSA-7f3w-mgjh-m27h.json b/advisories/unreviewed/2024/06/GHSA-7f3w-mgjh-m27h/GHSA-7f3w-mgjh-m27h.json index e54874b0284..4fa5265bdfb 100644 --- a/advisories/unreviewed/2024/06/GHSA-7f3w-mgjh-m27h/GHSA-7f3w-mgjh-m27h.json +++ b/advisories/unreviewed/2024/06/GHSA-7f3w-mgjh-m27h/GHSA-7f3w-mgjh-m27h.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-89" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-fqr7-35m8-f63c/GHSA-fqr7-35m8-f63c.json b/advisories/unreviewed/2024/06/GHSA-fqr7-35m8-f63c/GHSA-fqr7-35m8-f63c.json index 26a7a8cc736..a3c1091f8ce 100644 --- a/advisories/unreviewed/2024/06/GHSA-fqr7-35m8-f63c/GHSA-fqr7-35m8-f63c.json +++ b/advisories/unreviewed/2024/06/GHSA-fqr7-35m8-f63c/GHSA-fqr7-35m8-f63c.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fqr7-35m8-f63c", - "modified": "2024-06-04T06:30:37Z", + "modified": "2025-03-27T21:31:15Z", "published": "2024-06-04T06:30:37Z", "aliases": [ "CVE-2024-4750" ], "details": "The buddyboss-platform WordPress plugin before 2.6.0 contains an IDOR vulnerability that allows a user to like a private post by manipulating the ID included in the request", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-06-04T06:15:11Z" diff --git a/advisories/unreviewed/2024/06/GHSA-g7xm-f45g-5wvg/GHSA-g7xm-f45g-5wvg.json b/advisories/unreviewed/2024/06/GHSA-g7xm-f45g-5wvg/GHSA-g7xm-f45g-5wvg.json index f918ba72186..153d415b5e9 100644 --- a/advisories/unreviewed/2024/06/GHSA-g7xm-f45g-5wvg/GHSA-g7xm-f45g-5wvg.json +++ b/advisories/unreviewed/2024/06/GHSA-g7xm-f45g-5wvg/GHSA-g7xm-f45g-5wvg.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-269" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-r52c-mh2p-jmpj/GHSA-r52c-mh2p-jmpj.json b/advisories/unreviewed/2024/06/GHSA-r52c-mh2p-jmpj/GHSA-r52c-mh2p-jmpj.json index 453cadc2a35..5ed39c6c38e 100644 --- a/advisories/unreviewed/2024/06/GHSA-r52c-mh2p-jmpj/GHSA-r52c-mh2p-jmpj.json +++ b/advisories/unreviewed/2024/06/GHSA-r52c-mh2p-jmpj/GHSA-r52c-mh2p-jmpj.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-1390" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-v4wq-4595-gr53/GHSA-v4wq-4595-gr53.json b/advisories/unreviewed/2024/06/GHSA-v4wq-4595-gr53/GHSA-v4wq-4595-gr53.json index ceb07961ac0..4a7358f6c5b 100644 --- a/advisories/unreviewed/2024/06/GHSA-v4wq-4595-gr53/GHSA-v4wq-4595-gr53.json +++ b/advisories/unreviewed/2024/06/GHSA-v4wq-4595-gr53/GHSA-v4wq-4595-gr53.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-704" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-vfmf-3vr6-j85g/GHSA-vfmf-3vr6-j85g.json b/advisories/unreviewed/2024/06/GHSA-vfmf-3vr6-j85g/GHSA-vfmf-3vr6-j85g.json index 9cbc5aa9695..f9805f785cc 100644 --- a/advisories/unreviewed/2024/06/GHSA-vfmf-3vr6-j85g/GHSA-vfmf-3vr6-j85g.json +++ b/advisories/unreviewed/2024/06/GHSA-vfmf-3vr6-j85g/GHSA-vfmf-3vr6-j85g.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-798" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-6q6g-q64w-cwfh/GHSA-6q6g-q64w-cwfh.json b/advisories/unreviewed/2025/01/GHSA-6q6g-q64w-cwfh/GHSA-6q6g-q64w-cwfh.json index b3940fcad4c..ece68221447 100644 --- a/advisories/unreviewed/2025/01/GHSA-6q6g-q64w-cwfh/GHSA-6q6g-q64w-cwfh.json +++ b/advisories/unreviewed/2025/01/GHSA-6q6g-q64w-cwfh/GHSA-6q6g-q64w-cwfh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6q6g-q64w-cwfh", - "modified": "2025-01-28T06:30:40Z", + "modified": "2025-03-27T21:31:19Z", "published": "2025-01-28T06:30:40Z", "aliases": [ "CVE-2024-0149" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5614" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/03/27/7" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/03/GHSA-4hg3-3xxj-v749/GHSA-4hg3-3xxj-v749.json b/advisories/unreviewed/2025/03/GHSA-4hg3-3xxj-v749/GHSA-4hg3-3xxj-v749.json index a55691b9ea2..76107535b00 100644 --- a/advisories/unreviewed/2025/03/GHSA-4hg3-3xxj-v749/GHSA-4hg3-3xxj-v749.json +++ b/advisories/unreviewed/2025/03/GHSA-4hg3-3xxj-v749/GHSA-4hg3-3xxj-v749.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4hg3-3xxj-v749", - "modified": "2025-03-22T00:31:11Z", + "modified": "2025-03-27T21:31:20Z", "published": "2025-03-17T06:30:25Z", "aliases": [ "CVE-2025-2361" @@ -23,6 +23,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2361" }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00020.html" + }, { "type": "WEB", "url": "https://vuldb.com/?ctiid.299860" diff --git a/advisories/unreviewed/2025/03/GHSA-65g2-8fcx-v5pc/GHSA-65g2-8fcx-v5pc.json b/advisories/unreviewed/2025/03/GHSA-65g2-8fcx-v5pc/GHSA-65g2-8fcx-v5pc.json index d639283bd97..5e1607c1c59 100644 --- a/advisories/unreviewed/2025/03/GHSA-65g2-8fcx-v5pc/GHSA-65g2-8fcx-v5pc.json +++ b/advisories/unreviewed/2025/03/GHSA-65g2-8fcx-v5pc/GHSA-65g2-8fcx-v5pc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-65g2-8fcx-v5pc", - "modified": "2025-03-27T15:31:13Z", + "modified": "2025-03-27T21:31:20Z", "published": "2025-03-27T15:31:13Z", "aliases": [ "CVE-2025-29483" ], "details": "libming v0.4.8 was discovered to contain a memory leak via the parseSWF_ENABLEDEBUGGER2 function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-401" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-03-27T15:15:59Z" diff --git a/advisories/unreviewed/2025/03/GHSA-6pcr-45mv-9gp3/GHSA-6pcr-45mv-9gp3.json b/advisories/unreviewed/2025/03/GHSA-6pcr-45mv-9gp3/GHSA-6pcr-45mv-9gp3.json index 1d80a258358..66cea7fbe2b 100644 --- a/advisories/unreviewed/2025/03/GHSA-6pcr-45mv-9gp3/GHSA-6pcr-45mv-9gp3.json +++ b/advisories/unreviewed/2025/03/GHSA-6pcr-45mv-9gp3/GHSA-6pcr-45mv-9gp3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6pcr-45mv-9gp3", - "modified": "2025-03-04T18:33:30Z", + "modified": "2025-03-27T21:31:19Z", "published": "2025-03-03T18:31:28Z", "aliases": [ "CVE-2025-0286" @@ -26,6 +26,10 @@ { "type": "WEB", "url": "https://www.kb.cert.org/vuls/id/726882" + }, + { + "type": "WEB", + "url": "https://www.paragon-software.com/support/#patches" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/03/GHSA-8gwj-x84v-j8cc/GHSA-8gwj-x84v-j8cc.json b/advisories/unreviewed/2025/03/GHSA-8gwj-x84v-j8cc/GHSA-8gwj-x84v-j8cc.json new file mode 100644 index 00000000000..cc36bff20a6 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-8gwj-x84v-j8cc/GHSA-8gwj-x84v-j8cc.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8gwj-x84v-j8cc", + "modified": "2025-03-27T21:31:21Z", + "published": "2025-03-27T21:31:21Z", + "aliases": [ + "CVE-2025-29306" + ], + "details": "An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.html component.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29306" + }, + { + "type": "WEB", + "url": "https://github.com/somatrasss/CVE-2025-29306" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T19:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-8j55-mh7v-fc8w/GHSA-8j55-mh7v-fc8w.json b/advisories/unreviewed/2025/03/GHSA-8j55-mh7v-fc8w/GHSA-8j55-mh7v-fc8w.json new file mode 100644 index 00000000000..6902692517f --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-8j55-mh7v-fc8w/GHSA-8j55-mh7v-fc8w.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8j55-mh7v-fc8w", + "modified": "2025-03-27T21:31:22Z", + "published": "2025-03-27T21:31:22Z", + "aliases": [ + "CVE-2024-55070" + ], + "details": "A Broken Object Level Authorization vulnerability in the component /households/permissions of hay-kot mealie v2.2.0 allows group managers to edit their own permissions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55070" + }, + { + "type": "WEB", + "url": "https://github.com/mealie-recipes/mealie/issues/4593" + }, + { + "type": "WEB", + "url": "https://m10x.de/posts/2025/03/all-your-recipe-are-belong-to-us-part-3/3-broken-access-controls-leading-to-privilege-escalation-and-more-in-mealie" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T20:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-f6cx-2h32-33xm/GHSA-f6cx-2h32-33xm.json b/advisories/unreviewed/2025/03/GHSA-f6cx-2h32-33xm/GHSA-f6cx-2h32-33xm.json new file mode 100644 index 00000000000..5349ccd1ecc --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-f6cx-2h32-33xm/GHSA-f6cx-2h32-33xm.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f6cx-2h32-33xm", + "modified": "2025-03-27T21:31:21Z", + "published": "2025-03-27T21:31:21Z", + "aliases": [ + "CVE-2024-55073" + ], + "details": "A Broken Object Level Authorization vulnerability in the component /api/users/{user-id} of hay-kot mealie v2.2.0 allows users to edit their own profile in order to give themselves more permissions or to change their household.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55073" + }, + { + "type": "WEB", + "url": "https://github.com/mealie-recipes/mealie/issues/4593" + }, + { + "type": "WEB", + "url": "https://m10x.de/posts/2025/03/all-your-recipe-are-belong-to-us-part-3/3-broken-access-controls-leading-to-privilege-escalation-and-more-in-mealie" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T19:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-h8g5-2596-xjh9/GHSA-h8g5-2596-xjh9.json b/advisories/unreviewed/2025/03/GHSA-h8g5-2596-xjh9/GHSA-h8g5-2596-xjh9.json index 051552aae40..b45006ed637 100644 --- a/advisories/unreviewed/2025/03/GHSA-h8g5-2596-xjh9/GHSA-h8g5-2596-xjh9.json +++ b/advisories/unreviewed/2025/03/GHSA-h8g5-2596-xjh9/GHSA-h8g5-2596-xjh9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h8g5-2596-xjh9", - "modified": "2025-03-27T15:31:10Z", + "modified": "2025-03-27T21:31:20Z", "published": "2025-03-27T15:31:10Z", "aliases": [ "CVE-2025-2857" @@ -22,6 +22,10 @@ "type": "WEB", "url": "https://issues.chromium.org/issues/405143032" }, + { + "type": "WEB", + "url": "https://www.cve.org/CVERecord?id=CVE-2025-2783" + }, { "type": "WEB", "url": "https://www.mozilla.org/security/advisories/mfsa2025-19" diff --git a/advisories/unreviewed/2025/03/GHSA-p5fr-9m6g-c94q/GHSA-p5fr-9m6g-c94q.json b/advisories/unreviewed/2025/03/GHSA-p5fr-9m6g-c94q/GHSA-p5fr-9m6g-c94q.json new file mode 100644 index 00000000000..2514011bdb6 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-p5fr-9m6g-c94q/GHSA-p5fr-9m6g-c94q.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p5fr-9m6g-c94q", + "modified": "2025-03-27T21:31:21Z", + "published": "2025-03-27T21:31:21Z", + "aliases": [ + "CVE-2024-55072" + ], + "details": "A Broken Object Level Authorization vulnerability in the component /api/users/{user-id} of hay-kot mealie v2.2.0 allows users to edit their own profile in order to give themselves more permissions or to change their household.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55072" + }, + { + "type": "WEB", + "url": "https://github.com/mealie-recipes/mealie/issues/4593" + }, + { + "type": "WEB", + "url": "https://m10x.de/posts/2025/03/all-your-recipe-are-belong-to-us-part-3/3-broken-access-controls-leading-to-privilege-escalation-and-more-in-mealie" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T19:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-v64g-gxm8-whwj/GHSA-v64g-gxm8-whwj.json b/advisories/unreviewed/2025/03/GHSA-v64g-gxm8-whwj/GHSA-v64g-gxm8-whwj.json new file mode 100644 index 00000000000..9bf5b45c851 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-v64g-gxm8-whwj/GHSA-v64g-gxm8-whwj.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v64g-gxm8-whwj", + "modified": "2025-03-27T21:31:21Z", + "published": "2025-03-27T21:31:21Z", + "aliases": [ + "CVE-2025-30093" + ], + "details": "HTCondor 23.0.x before 23.0.22, 23.10.x before 23.10.22, 24.0.x before 24.0.6, and 24.6.x before 24.6.1 allows authenticated attackers to bypass authorization restrictions.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30093" + }, + { + "type": "WEB", + "url": "https://htcondor.org/security/vulnerabilities/HTCONDOR-2025-0001.html" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-27T19:15:49Z" + } +} \ No newline at end of file