From 8c01e2657a08cd45c1a4a5b4beb5faca4b5e0412 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Sat, 12 Apr 2025 00:31:58 +0000 Subject: [PATCH] Publish Advisories GHSA-jm5g-mv3f-pjfw GHSA-r8rm-jw25-4h55 GHSA-h3qj-j9m5-8ffr GHSA-2cj9-wjmr-5w57 GHSA-q262-3hfr-f5q4 GHSA-xhf3-pp4q-gxh5 GHSA-qxg5-mcmp-m3m9 GHSA-6cwx-2fwm-4jvm GHSA-9373-29x4-fjwq GHSA-hcg3-q754-cr77 GHSA-hw2v-r646-wgxr GHSA-qrjv-gffj-m676 --- .../GHSA-jm5g-mv3f-pjfw.json | 1 + .../GHSA-r8rm-jw25-4h55.json | 1 + .../GHSA-h3qj-j9m5-8ffr.json | 6 ++- .../GHSA-2cj9-wjmr-5w57.json | 6 ++- .../GHSA-q262-3hfr-f5q4.json | 6 ++- .../GHSA-xhf3-pp4q-gxh5.json | 6 ++- .../GHSA-qxg5-mcmp-m3m9.json | 6 ++- .../GHSA-6cwx-2fwm-4jvm.json | 6 ++- .../GHSA-9373-29x4-fjwq.json | 6 ++- .../GHSA-hcg3-q754-cr77.json | 48 +++++++++++++++++++ .../GHSA-hw2v-r646-wgxr.json | 34 +++++++++++++ .../GHSA-qrjv-gffj-m676.json | 40 ++++++++++++++++ 12 files changed, 159 insertions(+), 7 deletions(-) create mode 100644 advisories/unreviewed/2025/04/GHSA-hcg3-q754-cr77/GHSA-hcg3-q754-cr77.json create mode 100644 advisories/unreviewed/2025/04/GHSA-hw2v-r646-wgxr/GHSA-hw2v-r646-wgxr.json create mode 100644 advisories/unreviewed/2025/04/GHSA-qrjv-gffj-m676/GHSA-qrjv-gffj-m676.json diff --git a/advisories/unreviewed/2022/12/GHSA-jm5g-mv3f-pjfw/GHSA-jm5g-mv3f-pjfw.json b/advisories/unreviewed/2022/12/GHSA-jm5g-mv3f-pjfw/GHSA-jm5g-mv3f-pjfw.json index d1bde0df11e..fb32c0c1e55 100644 --- a/advisories/unreviewed/2022/12/GHSA-jm5g-mv3f-pjfw/GHSA-jm5g-mv3f-pjfw.json +++ b/advisories/unreviewed/2022/12/GHSA-jm5g-mv3f-pjfw/GHSA-jm5g-mv3f-pjfw.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-284", "CWE-287" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/12/GHSA-r8rm-jw25-4h55/GHSA-r8rm-jw25-4h55.json b/advisories/unreviewed/2022/12/GHSA-r8rm-jw25-4h55/GHSA-r8rm-jw25-4h55.json index e0614cb57f1..1a15fa8cf36 100644 --- a/advisories/unreviewed/2022/12/GHSA-r8rm-jw25-4h55/GHSA-r8rm-jw25-4h55.json +++ b/advisories/unreviewed/2022/12/GHSA-r8rm-jw25-4h55/GHSA-r8rm-jw25-4h55.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-284", "CWE-287" ], "severity": "LOW", diff --git a/advisories/unreviewed/2024/02/GHSA-h3qj-j9m5-8ffr/GHSA-h3qj-j9m5-8ffr.json b/advisories/unreviewed/2024/02/GHSA-h3qj-j9m5-8ffr/GHSA-h3qj-j9m5-8ffr.json index 8695b7a1eb6..752f888f8c7 100644 --- a/advisories/unreviewed/2024/02/GHSA-h3qj-j9m5-8ffr/GHSA-h3qj-j9m5-8ffr.json +++ b/advisories/unreviewed/2024/02/GHSA-h3qj-j9m5-8ffr/GHSA-h3qj-j9m5-8ffr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h3qj-j9m5-8ffr", - "modified": "2025-01-08T18:30:41Z", + "modified": "2025-04-12T00:30:26Z", "published": "2024-02-28T09:30:37Z", "aliases": [ "CVE-2021-47001" @@ -34,6 +34,10 @@ { "type": "WEB", "url": "https://git.kernel.org/stable/c/eddae8be7944096419c2ae29477a45f767d0fcd4" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250411-0001" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/03/GHSA-2cj9-wjmr-5w57/GHSA-2cj9-wjmr-5w57.json b/advisories/unreviewed/2024/03/GHSA-2cj9-wjmr-5w57/GHSA-2cj9-wjmr-5w57.json index 3a077d2cf97..fd607398735 100644 --- a/advisories/unreviewed/2024/03/GHSA-2cj9-wjmr-5w57/GHSA-2cj9-wjmr-5w57.json +++ b/advisories/unreviewed/2024/03/GHSA-2cj9-wjmr-5w57/GHSA-2cj9-wjmr-5w57.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2cj9-wjmr-5w57", - "modified": "2024-04-30T21:30:31Z", + "modified": "2025-04-12T00:30:26Z", "published": "2024-03-11T15:31:24Z", "aliases": [ "CVE-2024-1441" @@ -42,6 +42,10 @@ { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/E6MVZO5GXDB7RHY6MS3ZXES3HPK34P3A" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250411-0003" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/05/GHSA-q262-3hfr-f5q4/GHSA-q262-3hfr-f5q4.json b/advisories/unreviewed/2024/05/GHSA-q262-3hfr-f5q4/GHSA-q262-3hfr-f5q4.json index 4e161cb33cd..6144eb8ef84 100644 --- a/advisories/unreviewed/2024/05/GHSA-q262-3hfr-f5q4/GHSA-q262-3hfr-f5q4.json +++ b/advisories/unreviewed/2024/05/GHSA-q262-3hfr-f5q4/GHSA-q262-3hfr-f5q4.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q262-3hfr-f5q4", - "modified": "2024-07-24T00:31:17Z", + "modified": "2025-04-12T00:30:26Z", "published": "2024-05-08T03:30:37Z", "aliases": [ "CVE-2024-4418" @@ -46,6 +46,10 @@ { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Q4ZQBAJVHIZMCZNTRPUW3ZKXRKLXRQZU" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250411-0002" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/06/GHSA-xhf3-pp4q-gxh5/GHSA-xhf3-pp4q-gxh5.json b/advisories/unreviewed/2024/06/GHSA-xhf3-pp4q-gxh5/GHSA-xhf3-pp4q-gxh5.json index e94890accc8..92a8db59acf 100644 --- a/advisories/unreviewed/2024/06/GHSA-xhf3-pp4q-gxh5/GHSA-xhf3-pp4q-gxh5.json +++ b/advisories/unreviewed/2024/06/GHSA-xhf3-pp4q-gxh5/GHSA-xhf3-pp4q-gxh5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xhf3-pp4q-gxh5", - "modified": "2024-07-03T18:45:37Z", + "modified": "2025-04-12T00:30:26Z", "published": "2024-06-17T18:31:33Z", "aliases": [ "CVE-2024-0397" @@ -55,6 +55,10 @@ "type": "WEB", "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/BMAK5BCGKYWNJOACVUSLUF6SFGBIM4VP" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250411-0006" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2024/06/17/2" diff --git a/advisories/unreviewed/2024/11/GHSA-qxg5-mcmp-m3m9/GHSA-qxg5-mcmp-m3m9.json b/advisories/unreviewed/2024/11/GHSA-qxg5-mcmp-m3m9/GHSA-qxg5-mcmp-m3m9.json index e79986aa5b8..921336a19f4 100644 --- a/advisories/unreviewed/2024/11/GHSA-qxg5-mcmp-m3m9/GHSA-qxg5-mcmp-m3m9.json +++ b/advisories/unreviewed/2024/11/GHSA-qxg5-mcmp-m3m9/GHSA-qxg5-mcmp-m3m9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qxg5-mcmp-m3m9", - "modified": "2025-01-06T18:31:00Z", + "modified": "2025-04-12T00:30:26Z", "published": "2024-11-13T00:30:48Z", "aliases": [ "CVE-2024-11168" @@ -50,6 +50,10 @@ { "type": "WEB", "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/XPWB6XVZ5G5KGEI63M4AWLIEUF5BPH4T" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250411-0004" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/02/GHSA-6cwx-2fwm-4jvm/GHSA-6cwx-2fwm-4jvm.json b/advisories/unreviewed/2025/02/GHSA-6cwx-2fwm-4jvm/GHSA-6cwx-2fwm-4jvm.json index 318807ee53c..316a2c39181 100644 --- a/advisories/unreviewed/2025/02/GHSA-6cwx-2fwm-4jvm/GHSA-6cwx-2fwm-4jvm.json +++ b/advisories/unreviewed/2025/02/GHSA-6cwx-2fwm-4jvm/GHSA-6cwx-2fwm-4jvm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6cwx-2fwm-4jvm", - "modified": "2025-02-11T09:30:32Z", + "modified": "2025-04-12T00:30:26Z", "published": "2025-02-11T09:30:32Z", "aliases": [ "CVE-2025-1178" @@ -23,6 +23,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1178" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250411-0008" + }, { "type": "WEB", "url": "https://sourceware.org/bugzilla/attachment.cgi?id=15914" diff --git a/advisories/unreviewed/2025/02/GHSA-9373-29x4-fjwq/GHSA-9373-29x4-fjwq.json b/advisories/unreviewed/2025/02/GHSA-9373-29x4-fjwq/GHSA-9373-29x4-fjwq.json index 0d1858efda6..adfc35b1869 100644 --- a/advisories/unreviewed/2025/02/GHSA-9373-29x4-fjwq/GHSA-9373-29x4-fjwq.json +++ b/advisories/unreviewed/2025/02/GHSA-9373-29x4-fjwq/GHSA-9373-29x4-fjwq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9373-29x4-fjwq", - "modified": "2025-02-11T06:30:28Z", + "modified": "2025-04-12T00:30:26Z", "published": "2025-02-11T06:30:27Z", "aliases": [ "CVE-2025-1176" @@ -23,6 +23,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1176" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250411-0007" + }, { "type": "WEB", "url": "https://sourceware.org/bugzilla/attachment.cgi?id=15913" diff --git a/advisories/unreviewed/2025/04/GHSA-hcg3-q754-cr77/GHSA-hcg3-q754-cr77.json b/advisories/unreviewed/2025/04/GHSA-hcg3-q754-cr77/GHSA-hcg3-q754-cr77.json new file mode 100644 index 00000000000..775853deb40 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hcg3-q754-cr77/GHSA-hcg3-q754-cr77.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hcg3-q754-cr77", + "modified": "2025-04-12T00:30:26Z", + "published": "2025-04-12T00:30:26Z", + "aliases": [ + "CVE-2025-22869" + ], + "details": "SSH servers which implement file transfer protocols are vulnerable to a denial of service attack from clients which complete the key exchange slowly, or not at all, causing pending content to be read into memory, but never transmitted.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22869" + }, + { + "type": "WEB", + "url": "https://go.dev/cl/652135" + }, + { + "type": "WEB", + "url": "https://go.dev/issue/71931" + }, + { + "type": "WEB", + "url": "https://pkg.go.dev/vuln/GO-2025-3487" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250411-0010" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-770" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-26T08:14:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-hw2v-r646-wgxr/GHSA-hw2v-r646-wgxr.json b/advisories/unreviewed/2025/04/GHSA-hw2v-r646-wgxr/GHSA-hw2v-r646-wgxr.json new file mode 100644 index 00000000000..0c704f9793b --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-hw2v-r646-wgxr/GHSA-hw2v-r646-wgxr.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hw2v-r646-wgxr", + "modified": "2025-04-12T00:30:26Z", + "published": "2025-04-12T00:30:26Z", + "aliases": [ + "CVE-2025-0129" + ], + "details": "Prisma Access Browser: Inappropriate control behavior in Prisma Access Browser", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:U/V:D/RE:L/U:Amber" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0129" + }, + { + "type": "WEB", + "url": "https://security.paloaltonetworks.com/PAN-SA-2025-0008" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-11T23:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qrjv-gffj-m676/GHSA-qrjv-gffj-m676.json b/advisories/unreviewed/2025/04/GHSA-qrjv-gffj-m676/GHSA-qrjv-gffj-m676.json new file mode 100644 index 00000000000..912edcb90cf --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qrjv-gffj-m676/GHSA-qrjv-gffj-m676.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qrjv-gffj-m676", + "modified": "2025-04-12T00:30:26Z", + "published": "2025-04-12T00:30:26Z", + "aliases": [ + "CVE-2025-2269" + ], + "details": "The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘image_id’ parameter in all versions up to, and including, 1.8.34 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick an administrative user into performing an action such as clicking on a link.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2269" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/photo-gallery/tags/1.8.34/admin/views/Editimage.php#L39" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/ce261415-870c-4300-85e8-b15a02c7eec5?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-12T00:15:18Z" + } +} \ No newline at end of file