diff --git a/advisories/unreviewed/2024/07/GHSA-jfh3-2j6g-58qv/GHSA-jfh3-2j6g-58qv.json b/advisories/unreviewed/2024/07/GHSA-jfh3-2j6g-58qv/GHSA-jfh3-2j6g-58qv.json index 1ef2bc2f1d1..ca8157a9395 100644 --- a/advisories/unreviewed/2024/07/GHSA-jfh3-2j6g-58qv/GHSA-jfh3-2j6g-58qv.json +++ b/advisories/unreviewed/2024/07/GHSA-jfh3-2j6g-58qv/GHSA-jfh3-2j6g-58qv.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-125" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-3w84-2h42-qpcw/GHSA-3w84-2h42-qpcw.json b/advisories/unreviewed/2025/01/GHSA-3w84-2h42-qpcw/GHSA-3w84-2h42-qpcw.json index ae1bce078e8..4f24712451f 100644 --- a/advisories/unreviewed/2025/01/GHSA-3w84-2h42-qpcw/GHSA-3w84-2h42-qpcw.json +++ b/advisories/unreviewed/2025/01/GHSA-3w84-2h42-qpcw/GHSA-3w84-2h42-qpcw.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-200", "CWE-862" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2025/03/GHSA-mrrh-fwg8-r2c3/GHSA-mrrh-fwg8-r2c3.json b/advisories/unreviewed/2025/03/GHSA-mrrh-fwg8-r2c3/GHSA-mrrh-fwg8-r2c3.json index c3790f74190..2df78bfbee7 100644 --- a/advisories/unreviewed/2025/03/GHSA-mrrh-fwg8-r2c3/GHSA-mrrh-fwg8-r2c3.json +++ b/advisories/unreviewed/2025/03/GHSA-mrrh-fwg8-r2c3/GHSA-mrrh-fwg8-r2c3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mrrh-fwg8-r2c3", - "modified": "2025-03-15T06:30:34Z", + "modified": "2025-03-15T15:33:41Z", "published": "2025-03-15T06:30:34Z", "aliases": [ "CVE-2025-30066" @@ -23,10 +23,22 @@ "type": "WEB", "url": "https://github.com/tj-actions/changed-files/issues/2463" }, + { + "type": "WEB", + "url": "https://github.com/chains-project/maven-lockfile/pull/1111" + }, + { + "type": "WEB", + "url": "https://github.com/rackerlabs/genestack/pull/903" + }, { "type": "WEB", "url": "https://github.com/github/docs/blob/962a1c8dccb8c0f66548b324e5b921b5e4fbc3d6/content/actions/security-for-github-actions/security-guides/security-hardening-for-github-actions.md?plain=1#L191-L193" }, + { + "type": "WEB", + "url": "https://news.ycombinator.com/item?id=43367987" + }, { "type": "WEB", "url": "https://news.ycombinator.com/item?id=43368870" @@ -35,6 +47,10 @@ "type": "WEB", "url": "https://semgrep.dev/blog/2025/popular-github-action-tj-actionschanged-files-is-compromised" }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20250315060250/https://github.com/tj-actions/changed-files/issues/2463" + }, { "type": "WEB", "url": "https://www.stepsecurity.io/blog/harden-runner-detection-tj-actions-changed-files-action-is-compromised" diff --git a/advisories/unreviewed/2025/03/GHSA-qc7f-pxqv-xfrh/GHSA-qc7f-pxqv-xfrh.json b/advisories/unreviewed/2025/03/GHSA-qc7f-pxqv-xfrh/GHSA-qc7f-pxqv-xfrh.json new file mode 100644 index 00000000000..b0e5c7c29b2 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-qc7f-pxqv-xfrh/GHSA-qc7f-pxqv-xfrh.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qc7f-pxqv-xfrh", + "modified": "2025-03-15T15:33:41Z", + "published": "2025-03-15T15:33:41Z", + "aliases": [ + "CVE-2025-2322" + ], + "details": "A vulnerability was found in 274056675 springboot-openai-chatgpt e84f6f5. It has been classified as critical. This affects an unknown part of the file /chatgpt-boot/src/main/java/org/springblade/modules/mjkj/controller/OpenController.java. The manipulation leads to hard-coded credentials. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2322" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.299751" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.299751" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.505694" + }, + { + "type": "WEB", + "url": "https://www.cnblogs.com/aibot/p/18732299" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-259" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-15T14:15:28Z" + } +} \ No newline at end of file