From 8cba40cb840832b4c3eefe6e6a839c308a9d9637 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 28 Feb 2025 02:46:54 +0000 Subject: [PATCH] Publish Advisories GHSA-469f-wf4f-3jjv GHSA-6w27-c66f-gvhq GHSA-7jmr-43qj-pw47 GHSA-82p4-55gj-956p GHSA-ghpr-6qhr-rpp8 GHSA-469f-wf4f-3jjv GHSA-6w27-c66f-gvhq GHSA-7jmr-43qj-pw47 GHSA-82p4-55gj-956p GHSA-ghpr-6qhr-rpp8 --- .../GHSA-469f-wf4f-3jjv.json | 182 ++++++++++++++++++ .../GHSA-6w27-c66f-gvhq.json | 182 ++++++++++++++++++ .../GHSA-7jmr-43qj-pw47.json | 182 ++++++++++++++++++ .../GHSA-82p4-55gj-956p.json | 182 ++++++++++++++++++ .../GHSA-ghpr-6qhr-rpp8.json | 182 ++++++++++++++++++ .../GHSA-469f-wf4f-3jjv.json | 36 ---- .../GHSA-6w27-c66f-gvhq.json | 36 ---- .../GHSA-7jmr-43qj-pw47.json | 36 ---- .../GHSA-82p4-55gj-956p.json | 36 ---- .../GHSA-ghpr-6qhr-rpp8.json | 36 ---- 10 files changed, 910 insertions(+), 180 deletions(-) create mode 100644 advisories/github-reviewed/2025/02/GHSA-469f-wf4f-3jjv/GHSA-469f-wf4f-3jjv.json create mode 100644 advisories/github-reviewed/2025/02/GHSA-6w27-c66f-gvhq/GHSA-6w27-c66f-gvhq.json create mode 100644 advisories/github-reviewed/2025/02/GHSA-7jmr-43qj-pw47/GHSA-7jmr-43qj-pw47.json create mode 100644 advisories/github-reviewed/2025/02/GHSA-82p4-55gj-956p/GHSA-82p4-55gj-956p.json create mode 100644 advisories/github-reviewed/2025/02/GHSA-ghpr-6qhr-rpp8/GHSA-ghpr-6qhr-rpp8.json delete mode 100644 advisories/unreviewed/2025/02/GHSA-469f-wf4f-3jjv/GHSA-469f-wf4f-3jjv.json delete mode 100644 advisories/unreviewed/2025/02/GHSA-6w27-c66f-gvhq/GHSA-6w27-c66f-gvhq.json delete mode 100644 advisories/unreviewed/2025/02/GHSA-7jmr-43qj-pw47/GHSA-7jmr-43qj-pw47.json delete mode 100644 advisories/unreviewed/2025/02/GHSA-82p4-55gj-956p/GHSA-82p4-55gj-956p.json delete mode 100644 advisories/unreviewed/2025/02/GHSA-ghpr-6qhr-rpp8/GHSA-ghpr-6qhr-rpp8.json diff --git a/advisories/github-reviewed/2025/02/GHSA-469f-wf4f-3jjv/GHSA-469f-wf4f-3jjv.json b/advisories/github-reviewed/2025/02/GHSA-469f-wf4f-3jjv/GHSA-469f-wf4f-3jjv.json new file mode 100644 index 00000000000..ec6d5250d0b --- /dev/null +++ b/advisories/github-reviewed/2025/02/GHSA-469f-wf4f-3jjv/GHSA-469f-wf4f-3jjv.json @@ -0,0 +1,182 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-469f-wf4f-3jjv", + "modified": "2025-02-28T02:46:17Z", + "published": "2025-02-11T18:31:42Z", + "aliases": [ + "CVE-2025-24437" + ], + "summary": "Magento Improper Access Control vulnerability", + "details": "Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in privilege escalation. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain elevated privileges. Exploitation of this issue does not require user interaction.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.4.7-beta1" + }, + { + "fixed": "2.4.7-p4" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.4.6-p1" + }, + { + "fixed": "2.4.6-p9" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.4.5-p1" + }, + { + "fixed": "2.4.5-p11" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.4.4-p12" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "versions": [ + "2.4.7" + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "versions": [ + "2.4.6" + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "versions": [ + "2.4.5" + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "versions": [ + "2.4.4" + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "versions": [ + "2.4.8-beta1" + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/project-community-edition" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "2.0.2" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24437" + }, + { + "type": "PACKAGE", + "url": "https://github.com/magento/magento2" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/magento/apsb25-08.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2025-02-28T02:46:17Z", + "nvd_published_at": "2025-02-11T18:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2025/02/GHSA-6w27-c66f-gvhq/GHSA-6w27-c66f-gvhq.json b/advisories/github-reviewed/2025/02/GHSA-6w27-c66f-gvhq/GHSA-6w27-c66f-gvhq.json new file mode 100644 index 00000000000..2737b3194f3 --- /dev/null +++ b/advisories/github-reviewed/2025/02/GHSA-6w27-c66f-gvhq/GHSA-6w27-c66f-gvhq.json @@ -0,0 +1,182 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6w27-c66f-gvhq", + "modified": "2025-02-28T02:44:46Z", + "published": "2025-02-11T18:31:42Z", + "aliases": [ + "CVE-2025-24430" + ], + "summary": "Magento Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability", + "details": "Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could result in a security feature bypass. An attacker could exploit this race condition to alter a condition after it has been checked but before it is used, potentially bypassing security mechanisms. Exploitation of this issue requires user interaction.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.4.7-beta1" + }, + { + "fixed": "2.4.7-p4" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.4.6-p1" + }, + { + "fixed": "2.4.6-p9" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.4.5-p1" + }, + { + "fixed": "2.4.5-p11" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.4.4-p12" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "versions": [ + "2.4.7" + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "versions": [ + "2.4.6" + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "versions": [ + "2.4.5" + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "versions": [ + "2.4.4" + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "versions": [ + "2.4.8-beta1" + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/project-community-edition" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "2.0.2" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24430" + }, + { + "type": "PACKAGE", + "url": "https://github.com/magento/magento2" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/magento/apsb25-08.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-367" + ], + "severity": "LOW", + "github_reviewed": true, + "github_reviewed_at": "2025-02-28T02:44:46Z", + "nvd_published_at": "2025-02-11T18:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2025/02/GHSA-7jmr-43qj-pw47/GHSA-7jmr-43qj-pw47.json b/advisories/github-reviewed/2025/02/GHSA-7jmr-43qj-pw47/GHSA-7jmr-43qj-pw47.json new file mode 100644 index 00000000000..906f78ba613 --- /dev/null +++ b/advisories/github-reviewed/2025/02/GHSA-7jmr-43qj-pw47/GHSA-7jmr-43qj-pw47.json @@ -0,0 +1,182 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7jmr-43qj-pw47", + "modified": "2025-02-28T02:45:02Z", + "published": "2025-02-11T18:31:42Z", + "aliases": [ + "CVE-2025-24432" + ], + "summary": "Magento Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability", + "details": "Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could result in a security feature bypass. An attacker could exploit this race condition to alter a condition after it has been checked but before it is used, potentially bypassing security mechanisms. Exploitation of this issue requires user interaction.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.4.7-beta1" + }, + { + "fixed": "2.4.7-p4" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.4.6-p1" + }, + { + "fixed": "2.4.6-p9" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.4.5-p1" + }, + { + "fixed": "2.4.5-p11" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.4.4-p12" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "versions": [ + "2.4.7" + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "versions": [ + "2.4.6" + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "versions": [ + "2.4.5" + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "versions": [ + "2.4.4" + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "versions": [ + "2.4.8-beta1" + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/project-community-edition" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "2.0.2" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24432" + }, + { + "type": "PACKAGE", + "url": "https://github.com/magento/magento2" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/magento/apsb25-08.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-367" + ], + "severity": "LOW", + "github_reviewed": true, + "github_reviewed_at": "2025-02-28T02:45:01Z", + "nvd_published_at": "2025-02-11T18:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2025/02/GHSA-82p4-55gj-956p/GHSA-82p4-55gj-956p.json b/advisories/github-reviewed/2025/02/GHSA-82p4-55gj-956p/GHSA-82p4-55gj-956p.json new file mode 100644 index 00000000000..53255769388 --- /dev/null +++ b/advisories/github-reviewed/2025/02/GHSA-82p4-55gj-956p/GHSA-82p4-55gj-956p.json @@ -0,0 +1,182 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-82p4-55gj-956p", + "modified": "2025-02-28T02:45:59Z", + "published": "2025-02-11T18:31:42Z", + "aliases": [ + "CVE-2025-24435" + ], + "summary": "Magento Improper Access Control vulnerability", + "details": "Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in Privilege escalation. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized access to modify limited fields. Exploitation of this issue does not require user interaction.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.4.7-beta1" + }, + { + "fixed": "2.4.7-p4" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.4.6-p1" + }, + { + "fixed": "2.4.6-p9" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.4.4-p12" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "versions": [ + "2.4.7" + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "versions": [ + "2.4.6" + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.4.5-p1" + }, + { + "fixed": "2.4.5-p11" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "versions": [ + "2.4.5" + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "versions": [ + "2.4.4" + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "versions": [ + "2.4.8-beta1" + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/project-community-edition" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "2.0.2" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24435" + }, + { + "type": "PACKAGE", + "url": "https://github.com/magento/magento2" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/magento/apsb25-08.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2025-02-28T02:45:59Z", + "nvd_published_at": "2025-02-11T18:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2025/02/GHSA-ghpr-6qhr-rpp8/GHSA-ghpr-6qhr-rpp8.json b/advisories/github-reviewed/2025/02/GHSA-ghpr-6qhr-rpp8/GHSA-ghpr-6qhr-rpp8.json new file mode 100644 index 00000000000..b3b5a4a6b5a --- /dev/null +++ b/advisories/github-reviewed/2025/02/GHSA-ghpr-6qhr-rpp8/GHSA-ghpr-6qhr-rpp8.json @@ -0,0 +1,182 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ghpr-6qhr-rpp8", + "modified": "2025-02-28T02:45:26Z", + "published": "2025-02-11T18:31:42Z", + "aliases": [ + "CVE-2025-24436" + ], + "summary": "Magento Improper Access Control vulnerability", + "details": "Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in Privilege escalation. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue does not require user interaction.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.4.7-beta1" + }, + { + "fixed": "2.4.7-p4" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.4.6-p1" + }, + { + "fixed": "2.4.6-p9" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.4.5-p1" + }, + { + "fixed": "2.4.5-p11" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.4.4-p12" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "versions": [ + "2.4.7" + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "versions": [ + "2.4.6" + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "versions": [ + "2.4.5" + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "versions": [ + "2.4.4" + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/community-edition" + }, + "versions": [ + "2.4.8-beta1" + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "magento/project-community-edition" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "2.0.2" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24436" + }, + { + "type": "PACKAGE", + "url": "https://github.com/magento/magento2" + }, + { + "type": "WEB", + "url": "https://helpx.adobe.com/security/products/magento/apsb25-08.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2025-02-28T02:45:25Z", + "nvd_published_at": "2025-02-11T18:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-469f-wf4f-3jjv/GHSA-469f-wf4f-3jjv.json b/advisories/unreviewed/2025/02/GHSA-469f-wf4f-3jjv/GHSA-469f-wf4f-3jjv.json deleted file mode 100644 index 898bd9a9501..00000000000 --- a/advisories/unreviewed/2025/02/GHSA-469f-wf4f-3jjv/GHSA-469f-wf4f-3jjv.json +++ /dev/null @@ -1,36 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-469f-wf4f-3jjv", - "modified": "2025-02-11T18:31:42Z", - "published": "2025-02-11T18:31:42Z", - "aliases": [ - "CVE-2025-24437" - ], - "details": "Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in privilege escalation. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain elevated privileges. Exploitation of this issue does not require user interaction.", - "severity": [ - { - "type": "CVSS_V3", - "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" - } - ], - "affected": [], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24437" - }, - { - "type": "WEB", - "url": "https://helpx.adobe.com/security/products/magento/apsb25-08.html" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-284" - ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2025-02-11T18:15:46Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-6w27-c66f-gvhq/GHSA-6w27-c66f-gvhq.json b/advisories/unreviewed/2025/02/GHSA-6w27-c66f-gvhq/GHSA-6w27-c66f-gvhq.json deleted file mode 100644 index 965f10f3096..00000000000 --- a/advisories/unreviewed/2025/02/GHSA-6w27-c66f-gvhq/GHSA-6w27-c66f-gvhq.json +++ /dev/null @@ -1,36 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-6w27-c66f-gvhq", - "modified": "2025-02-11T18:31:42Z", - "published": "2025-02-11T18:31:42Z", - "aliases": [ - "CVE-2025-24430" - ], - "details": "Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could result in a security feature bypass. An attacker could exploit this race condition to alter a condition after it has been checked but before it is used, potentially bypassing security mechanisms. Exploitation of this issue requires user interaction.", - "severity": [ - { - "type": "CVSS_V3", - "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N" - } - ], - "affected": [], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24430" - }, - { - "type": "WEB", - "url": "https://helpx.adobe.com/security/products/magento/apsb25-08.html" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-367" - ], - "severity": "LOW", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2025-02-11T18:15:45Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-7jmr-43qj-pw47/GHSA-7jmr-43qj-pw47.json b/advisories/unreviewed/2025/02/GHSA-7jmr-43qj-pw47/GHSA-7jmr-43qj-pw47.json deleted file mode 100644 index 003e8d9c6f6..00000000000 --- a/advisories/unreviewed/2025/02/GHSA-7jmr-43qj-pw47/GHSA-7jmr-43qj-pw47.json +++ /dev/null @@ -1,36 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-7jmr-43qj-pw47", - "modified": "2025-02-11T18:31:42Z", - "published": "2025-02-11T18:31:42Z", - "aliases": [ - "CVE-2025-24432" - ], - "details": "Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could result in a security feature bypass. An attacker could exploit this race condition to alter a condition after it has been checked but before it is used, potentially bypassing security mechanisms. Exploitation of this issue requires user interaction.", - "severity": [ - { - "type": "CVSS_V3", - "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N" - } - ], - "affected": [], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24432" - }, - { - "type": "WEB", - "url": "https://helpx.adobe.com/security/products/magento/apsb25-08.html" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-367" - ], - "severity": "LOW", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2025-02-11T18:15:45Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-82p4-55gj-956p/GHSA-82p4-55gj-956p.json b/advisories/unreviewed/2025/02/GHSA-82p4-55gj-956p/GHSA-82p4-55gj-956p.json deleted file mode 100644 index dcefecab4fc..00000000000 --- a/advisories/unreviewed/2025/02/GHSA-82p4-55gj-956p/GHSA-82p4-55gj-956p.json +++ /dev/null @@ -1,36 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-82p4-55gj-956p", - "modified": "2025-02-11T18:31:42Z", - "published": "2025-02-11T18:31:42Z", - "aliases": [ - "CVE-2025-24435" - ], - "details": "Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in Privilege escalation. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized access to modify limited fields. Exploitation of this issue does not require user interaction.", - "severity": [ - { - "type": "CVSS_V3", - "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" - } - ], - "affected": [], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24435" - }, - { - "type": "WEB", - "url": "https://helpx.adobe.com/security/products/magento/apsb25-08.html" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-284" - ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2025-02-11T18:15:46Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-ghpr-6qhr-rpp8/GHSA-ghpr-6qhr-rpp8.json b/advisories/unreviewed/2025/02/GHSA-ghpr-6qhr-rpp8/GHSA-ghpr-6qhr-rpp8.json deleted file mode 100644 index 8c9c5c0b74e..00000000000 --- a/advisories/unreviewed/2025/02/GHSA-ghpr-6qhr-rpp8/GHSA-ghpr-6qhr-rpp8.json +++ /dev/null @@ -1,36 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-ghpr-6qhr-rpp8", - "modified": "2025-02-11T18:31:42Z", - "published": "2025-02-11T18:31:42Z", - "aliases": [ - "CVE-2025-24436" - ], - "details": "Adobe Commerce versions 2.4.7-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Improper Access Control vulnerability that could result in Privilege escalation. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized access. Exploitation of this issue does not require user interaction.", - "severity": [ - { - "type": "CVSS_V3", - "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" - } - ], - "affected": [], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24436" - }, - { - "type": "WEB", - "url": "https://helpx.adobe.com/security/products/magento/apsb25-08.html" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-284" - ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2025-02-11T18:15:46Z" - } -} \ No newline at end of file