From 8ea485b7b643edb7e31ba2d9336440e54c56ee67 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 30 May 2025 21:32:35 +0000 Subject: [PATCH] Publish Advisories GHSA-3gf2-723m-w3fv GHSA-3498-94v2-7qqw GHSA-3797-gmjf-45gm GHSA-p3v7-wjmc-7fh8 GHSA-w829-6hpw-frjf GHSA-cfmr-vrgj-vqwv GHSA-2vq2-xc55-3j5m GHSA-4hjv-8mmr-jxwv GHSA-7cv2-wjgm-j7rm GHSA-3ff9-v8g6-rg9q GHSA-5gc6-2564-mq66 GHSA-7m65-wj64-957x GHSA-8prh-632c-4gfj GHSA-c8vj-q55w-r7h8 GHSA-mhg6-w3h6-f286 GHSA-mj3f-8797-c7r5 GHSA-p64m-3pg6-g8pq GHSA-w3vc-hpm9-2h9q GHSA-wxg6-4cwm-4rjf GHSA-x3mr-mm28-qg7m --- .../GHSA-3gf2-723m-w3fv.json | 13 ++- .../GHSA-3498-94v2-7qqw.json | 10 +- .../GHSA-3797-gmjf-45gm.json | 98 +++++++++++-------- .../GHSA-p3v7-wjmc-7fh8.json | 14 ++- .../GHSA-w829-6hpw-frjf.json | 30 ++++-- .../GHSA-cfmr-vrgj-vqwv.json | 1 + .../GHSA-2vq2-xc55-3j5m.json | 82 ++++++++++------ .../GHSA-4hjv-8mmr-jxwv.json | 2 +- .../GHSA-7cv2-wjgm-j7rm.json | 2 +- .../GHSA-3ff9-v8g6-rg9q.json | 56 +++++++++++ .../GHSA-5gc6-2564-mq66.json | 56 +++++++++++ .../GHSA-7m65-wj64-957x.json | 40 ++++++++ .../GHSA-8prh-632c-4gfj.json | 40 ++++++++ .../GHSA-c8vj-q55w-r7h8.json | 56 +++++++++++ .../GHSA-mhg6-w3h6-f286.json | 56 +++++++++++ .../GHSA-mj3f-8797-c7r5.json | 40 ++++++++ .../GHSA-p64m-3pg6-g8pq.json | 56 +++++++++++ .../GHSA-w3vc-hpm9-2h9q.json | 15 ++- .../GHSA-wxg6-4cwm-4rjf.json | 15 ++- .../GHSA-x3mr-mm28-qg7m.json | 40 ++++++++ 20 files changed, 625 insertions(+), 97 deletions(-) create mode 100644 advisories/unreviewed/2025/05/GHSA-3ff9-v8g6-rg9q/GHSA-3ff9-v8g6-rg9q.json create mode 100644 advisories/unreviewed/2025/05/GHSA-5gc6-2564-mq66/GHSA-5gc6-2564-mq66.json create mode 100644 advisories/unreviewed/2025/05/GHSA-7m65-wj64-957x/GHSA-7m65-wj64-957x.json create mode 100644 advisories/unreviewed/2025/05/GHSA-8prh-632c-4gfj/GHSA-8prh-632c-4gfj.json create mode 100644 advisories/unreviewed/2025/05/GHSA-c8vj-q55w-r7h8/GHSA-c8vj-q55w-r7h8.json create mode 100644 advisories/unreviewed/2025/05/GHSA-mhg6-w3h6-f286/GHSA-mhg6-w3h6-f286.json create mode 100644 advisories/unreviewed/2025/05/GHSA-mj3f-8797-c7r5/GHSA-mj3f-8797-c7r5.json create mode 100644 advisories/unreviewed/2025/05/GHSA-p64m-3pg6-g8pq/GHSA-p64m-3pg6-g8pq.json create mode 100644 advisories/unreviewed/2025/05/GHSA-x3mr-mm28-qg7m/GHSA-x3mr-mm28-qg7m.json diff --git a/advisories/unreviewed/2022/02/GHSA-3gf2-723m-w3fv/GHSA-3gf2-723m-w3fv.json b/advisories/unreviewed/2022/02/GHSA-3gf2-723m-w3fv/GHSA-3gf2-723m-w3fv.json index 4d8cedb4117..b3658d96648 100644 --- a/advisories/unreviewed/2022/02/GHSA-3gf2-723m-w3fv/GHSA-3gf2-723m-w3fv.json +++ b/advisories/unreviewed/2022/02/GHSA-3gf2-723m-w3fv/GHSA-3gf2-723m-w3fv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3gf2-723m-w3fv", - "modified": "2022-03-17T00:05:31Z", + "modified": "2025-05-30T21:30:52Z", "published": "2022-02-19T00:01:37Z", "aliases": [ "CVE-2022-25313" @@ -31,6 +31,14 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2022/03/msg00007.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3UFRBA3UQVIQKXTBUQXDWQOVWNBKLERU" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y27XO3JMKAOMQZVPS3B4MJGEAHCZF5OM" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3UFRBA3UQVIQKXTBUQXDWQOVWNBKLERU" @@ -62,7 +70,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-400" + "CWE-400", + "CWE-674" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-3498-94v2-7qqw/GHSA-3498-94v2-7qqw.json b/advisories/unreviewed/2022/05/GHSA-3498-94v2-7qqw/GHSA-3498-94v2-7qqw.json index 4b6cc62fe2b..8fbcaec9eff 100644 --- a/advisories/unreviewed/2022/05/GHSA-3498-94v2-7qqw/GHSA-3498-94v2-7qqw.json +++ b/advisories/unreviewed/2022/05/GHSA-3498-94v2-7qqw/GHSA-3498-94v2-7qqw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3498-94v2-7qqw", - "modified": "2022-05-24T16:56:44Z", + "modified": "2025-05-30T21:30:52Z", "published": "2022-05-24T16:56:44Z", "aliases": [ "CVE-2019-5094" @@ -23,6 +23,14 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2019/09/msg00029.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2AKETJ6BREDUHRWQTV35SPGG5C6H7KSI" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6DOBCYQKCTTWXBLMUPJ5TX3FY7JNCOKY" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2AKETJ6BREDUHRWQTV35SPGG5C6H7KSI" diff --git a/advisories/unreviewed/2022/05/GHSA-3797-gmjf-45gm/GHSA-3797-gmjf-45gm.json b/advisories/unreviewed/2022/05/GHSA-3797-gmjf-45gm/GHSA-3797-gmjf-45gm.json index 9acdd81dcf5..443aa494d42 100644 --- a/advisories/unreviewed/2022/05/GHSA-3797-gmjf-45gm/GHSA-3797-gmjf-45gm.json +++ b/advisories/unreviewed/2022/05/GHSA-3797-gmjf-45gm/GHSA-3797-gmjf-45gm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3797-gmjf-45gm", - "modified": "2022-09-14T00:00:52Z", + "modified": "2025-05-30T21:30:52Z", "published": "2022-05-24T17:17:32Z", "aliases": [ "CVE-2020-12762" @@ -29,47 +29,7 @@ }, { "type": "WEB", - "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-637483.pdf" - }, - { - "type": "WEB", - "url": "https://lists.debian.org/debian-lts-announce/2020/05/msg00032.html" - }, - { - "type": "WEB", - "url": "https://lists.debian.org/debian-lts-announce/2020/05/msg00034.html" - }, - { - "type": "WEB", - "url": "https://lists.debian.org/debian-lts-announce/2020/07/msg00031.html" - }, - { - "type": "WEB", - "url": "https://lists.debian.org/debian-lts-announce/2023/06/msg00023.html" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CBR36IXYBHITAZFB5PFBJTED22WO5ONB" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CQQRRGBQCAWNCCJ2HN3W5SSCZ4QGMXQI" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/W226TSCJBEOXDUFVKNWNH7ETG7AR6MCS" - }, - { - "type": "WEB", - "url": "https://security.gentoo.org/glsa/202006-13" - }, - { - "type": "WEB", - "url": "https://security.netapp.com/advisory/ntap-20210521-0001" - }, - { - "type": "WEB", - "url": "https://usn.ubuntu.com/4360-1" + "url": "https://www.debian.org/security/2020/dsa-4741" }, { "type": "WEB", @@ -77,7 +37,59 @@ }, { "type": "WEB", - "url": "https://www.debian.org/security/2020/dsa-4741" + "url": "https://usn.ubuntu.com/4360-1" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20210521-0001" + }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202006-13" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/W226TSCJBEOXDUFVKNWNH7ETG7AR6MCS" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CQQRRGBQCAWNCCJ2HN3W5SSCZ4QGMXQI" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CBR36IXYBHITAZFB5PFBJTED22WO5ONB" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W226TSCJBEOXDUFVKNWNH7ETG7AR6MCS" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CQQRRGBQCAWNCCJ2HN3W5SSCZ4QGMXQI" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CBR36IXYBHITAZFB5PFBJTED22WO5ONB" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2023/06/msg00023.html" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2020/07/msg00031.html" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2020/05/msg00034.html" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2020/05/msg00032.html" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-637483.pdf" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/05/GHSA-p3v7-wjmc-7fh8/GHSA-p3v7-wjmc-7fh8.json b/advisories/unreviewed/2022/05/GHSA-p3v7-wjmc-7fh8/GHSA-p3v7-wjmc-7fh8.json index f037709b2f8..6698db99072 100644 --- a/advisories/unreviewed/2022/05/GHSA-p3v7-wjmc-7fh8/GHSA-p3v7-wjmc-7fh8.json +++ b/advisories/unreviewed/2022/05/GHSA-p3v7-wjmc-7fh8/GHSA-p3v7-wjmc-7fh8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p3v7-wjmc-7fh8", - "modified": "2022-07-26T00:00:47Z", + "modified": "2025-05-30T21:30:52Z", "published": "2022-05-24T19:10:56Z", "aliases": [ "CVE-2021-38604" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://blog.tuxcare.com/cve/tuxcare-team-identifies-cve-2021-38604-a-new-vulnerability-in-glibc" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GYEXYM37RCJWJ6B5KQUYQI4NZBDDYSXP" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GYEXYM37RCJWJ6B5KQUYQI4NZBDDYSXP" @@ -39,6 +43,14 @@ "type": "WEB", "url": "https://sourceware.org/bugzilla/show_bug.cgi?id=28213" }, + { + "type": "WEB", + "url": "https://sourceware.org/git/?p=glibc.git%3Ba=commit%3Bh=4cc79c217744743077bf7a0ec5e0a4318f1e6641" + }, + { + "type": "WEB", + "url": "https://sourceware.org/git/?p=glibc.git%3Ba=commit%3Bh=b805aebd42364fe696e417808a700fdb9800c9e8" + }, { "type": "WEB", "url": "https://sourceware.org/git/?p=glibc.git;a=commit;h=4cc79c217744743077bf7a0ec5e0a4318f1e6641" diff --git a/advisories/unreviewed/2022/05/GHSA-w829-6hpw-frjf/GHSA-w829-6hpw-frjf.json b/advisories/unreviewed/2022/05/GHSA-w829-6hpw-frjf/GHSA-w829-6hpw-frjf.json index e780e708ee2..6316fa215ea 100644 --- a/advisories/unreviewed/2022/05/GHSA-w829-6hpw-frjf/GHSA-w829-6hpw-frjf.json +++ b/advisories/unreviewed/2022/05/GHSA-w829-6hpw-frjf/GHSA-w829-6hpw-frjf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w829-6hpw-frjf", - "modified": "2022-07-29T00:00:49Z", + "modified": "2025-05-30T21:30:53Z", "published": "2022-05-24T16:55:26Z", "aliases": [ "CVE-2019-15903" @@ -35,6 +35,14 @@ "type": "WEB", "url": "https://github.com/libexpat/libexpat/commit/c20b758c332d9a13afbbb276d30db1d183a85d43" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2019:3210" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20190926-0004" + }, { "type": "WEB", "url": "https://support.apple.com/kb/HT210785" @@ -107,10 +115,6 @@ "type": "WEB", "url": "https://www.tenable.com/security/tns-2021-11" }, - { - "type": "WEB", - "url": "https://access.redhat.com/errata/RHSA-2019:3210" - }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2019:3237" @@ -127,6 +131,18 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2019/11/msg00017.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A4TZKPJFTURRLXIGLB34WVKQ5HGY6JJA" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BDUTI5TVQWIGGQXPEVI4T2ENHFSBMIBP" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/S26LGXXQ7YF2BP3RGOWELBFKM6BHF6UG" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/A4TZKPJFTURRLXIGLB34WVKQ5HGY6JJA" @@ -175,10 +191,6 @@ "type": "WEB", "url": "https://security.gentoo.org/glsa/201911-08" }, - { - "type": "WEB", - "url": "https://security.netapp.com/advisory/ntap-20190926-0004" - }, { "type": "WEB", "url": "http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00080.html" diff --git a/advisories/unreviewed/2022/08/GHSA-cfmr-vrgj-vqwv/GHSA-cfmr-vrgj-vqwv.json b/advisories/unreviewed/2022/08/GHSA-cfmr-vrgj-vqwv/GHSA-cfmr-vrgj-vqwv.json index 7d5ddc792d2..275f372a79d 100644 --- a/advisories/unreviewed/2022/08/GHSA-cfmr-vrgj-vqwv/GHSA-cfmr-vrgj-vqwv.json +++ b/advisories/unreviewed/2022/08/GHSA-cfmr-vrgj-vqwv/GHSA-cfmr-vrgj-vqwv.json @@ -150,6 +150,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-120", "CWE-787" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2022/09/GHSA-2vq2-xc55-3j5m/GHSA-2vq2-xc55-3j5m.json b/advisories/unreviewed/2022/09/GHSA-2vq2-xc55-3j5m/GHSA-2vq2-xc55-3j5m.json index af5f2a71217..3b9a7894746 100644 --- a/advisories/unreviewed/2022/09/GHSA-2vq2-xc55-3j5m/GHSA-2vq2-xc55-3j5m.json +++ b/advisories/unreviewed/2022/09/GHSA-2vq2-xc55-3j5m/GHSA-2vq2-xc55-3j5m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2vq2-xc55-3j5m", - "modified": "2022-09-17T00:00:42Z", + "modified": "2025-05-30T21:30:54Z", "published": "2022-09-15T00:00:25Z", "aliases": [ "CVE-2022-40674" @@ -29,35 +29,7 @@ }, { "type": "WEB", - "url": "https://lists.debian.org/debian-lts-announce/2022/09/msg00029.html" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GSVZN3IJ6OCPSJL7AEX3ZHSHAHFOGESK" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/J2IGJNHFV53PYST7VQV3T4NHVYAMXA36" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LQB6FJAM5YQ35SF5B2MN25Y2FX56EOEZ" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WE2ZKEPGFCZ7R6DRVH3K6RBJPT42ZBEG" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XCGBVQQ47URGJAZWHCISHDWF6QBTV2LE" - }, - { - "type": "WEB", - "url": "https://security.gentoo.org/glsa/202209-24" - }, - { - "type": "WEB", - "url": "https://security.gentoo.org/glsa/202211-06" + "url": "https://www.debian.org/security/2022/dsa-5236" }, { "type": "WEB", @@ -65,7 +37,55 @@ }, { "type": "WEB", - "url": "https://www.debian.org/security/2022/dsa-5236" + "url": "https://security.gentoo.org/glsa/202211-06" + }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202209-24" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XCGBVQQ47URGJAZWHCISHDWF6QBTV2LE" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WE2ZKEPGFCZ7R6DRVH3K6RBJPT42ZBEG" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LQB6FJAM5YQ35SF5B2MN25Y2FX56EOEZ" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/J2IGJNHFV53PYST7VQV3T4NHVYAMXA36" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GSVZN3IJ6OCPSJL7AEX3ZHSHAHFOGESK" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XCGBVQQ47URGJAZWHCISHDWF6QBTV2LE" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WE2ZKEPGFCZ7R6DRVH3K6RBJPT42ZBEG" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LQB6FJAM5YQ35SF5B2MN25Y2FX56EOEZ" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/J2IGJNHFV53PYST7VQV3T4NHVYAMXA36" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GSVZN3IJ6OCPSJL7AEX3ZHSHAHFOGESK" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2022/09/msg00029.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/10/GHSA-4hjv-8mmr-jxwv/GHSA-4hjv-8mmr-jxwv.json b/advisories/unreviewed/2022/10/GHSA-4hjv-8mmr-jxwv/GHSA-4hjv-8mmr-jxwv.json index 4d49556dde3..e0a2be1fd76 100644 --- a/advisories/unreviewed/2022/10/GHSA-4hjv-8mmr-jxwv/GHSA-4hjv-8mmr-jxwv.json +++ b/advisories/unreviewed/2022/10/GHSA-4hjv-8mmr-jxwv/GHSA-4hjv-8mmr-jxwv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4hjv-8mmr-jxwv", - "modified": "2022-10-24T19:00:20Z", + "modified": "2025-05-30T21:30:54Z", "published": "2022-10-24T19:00:20Z", "aliases": [ "CVE-2022-43680" diff --git a/advisories/unreviewed/2023/04/GHSA-7cv2-wjgm-j7rm/GHSA-7cv2-wjgm-j7rm.json b/advisories/unreviewed/2023/04/GHSA-7cv2-wjgm-j7rm/GHSA-7cv2-wjgm-j7rm.json index 322858c3c24..75a000a85e4 100644 --- a/advisories/unreviewed/2023/04/GHSA-7cv2-wjgm-j7rm/GHSA-7cv2-wjgm-j7rm.json +++ b/advisories/unreviewed/2023/04/GHSA-7cv2-wjgm-j7rm/GHSA-7cv2-wjgm-j7rm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7cv2-wjgm-j7rm", - "modified": "2024-02-01T18:31:06Z", + "modified": "2025-05-30T21:30:55Z", "published": "2023-04-24T21:30:30Z", "aliases": [ "CVE-2023-28484" diff --git a/advisories/unreviewed/2025/05/GHSA-3ff9-v8g6-rg9q/GHSA-3ff9-v8g6-rg9q.json b/advisories/unreviewed/2025/05/GHSA-3ff9-v8g6-rg9q/GHSA-3ff9-v8g6-rg9q.json new file mode 100644 index 00000000000..7bd7bfcd966 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-3ff9-v8g6-rg9q/GHSA-3ff9-v8g6-rg9q.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3ff9-v8g6-rg9q", + "modified": "2025-05-30T21:30:58Z", + "published": "2025-05-30T21:30:58Z", + "aliases": [ + "CVE-2025-5363" + ], + "details": "A vulnerability has been found in Campcodes Online Hospital Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /doctor/index.php. The manipulation of the argument Username leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5363" + }, + { + "type": "WEB", + "url": "https://github.com/yuanchaoxxxxx/CVE/issues/3" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.310657" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.310657" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.586698" + }, + { + "type": "WEB", + "url": "https://www.campcodes.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-30T21:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-5gc6-2564-mq66/GHSA-5gc6-2564-mq66.json b/advisories/unreviewed/2025/05/GHSA-5gc6-2564-mq66/GHSA-5gc6-2564-mq66.json new file mode 100644 index 00000000000..9ce86dd0c38 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5gc6-2564-mq66/GHSA-5gc6-2564-mq66.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5gc6-2564-mq66", + "modified": "2025-05-30T21:30:58Z", + "published": "2025-05-30T21:30:58Z", + "aliases": [ + "CVE-2025-5362" + ], + "details": "A vulnerability, which was classified as critical, was found in Campcodes Online Hospital Management System 1.0. Affected is an unknown function of the file /admin/doctor-specilization.php. The manipulation of the argument doctorspecilization leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5362" + }, + { + "type": "WEB", + "url": "https://github.com/ASantsSec/CVE/issues/10" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.310656" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.310656" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.586596" + }, + { + "type": "WEB", + "url": "https://www.campcodes.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-30T21:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7m65-wj64-957x/GHSA-7m65-wj64-957x.json b/advisories/unreviewed/2025/05/GHSA-7m65-wj64-957x/GHSA-7m65-wj64-957x.json new file mode 100644 index 00000000000..b28ffe3b63b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7m65-wj64-957x/GHSA-7m65-wj64-957x.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7m65-wj64-957x", + "modified": "2025-05-30T21:30:57Z", + "published": "2025-05-30T21:30:57Z", + "aliases": [ + "CVE-2025-2501" + ], + "details": "An untrusted search path vulnerability was reported in Lenovo PC Manager that could allow a local attacker to elevate privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2501" + }, + { + "type": "WEB", + "url": "https://iknow.lenovo.com.cn/detail/428586" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-426" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-30T20:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8prh-632c-4gfj/GHSA-8prh-632c-4gfj.json b/advisories/unreviewed/2025/05/GHSA-8prh-632c-4gfj/GHSA-8prh-632c-4gfj.json new file mode 100644 index 00000000000..309611273fc --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8prh-632c-4gfj/GHSA-8prh-632c-4gfj.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8prh-632c-4gfj", + "modified": "2025-05-30T21:30:58Z", + "published": "2025-05-30T21:30:57Z", + "aliases": [ + "CVE-2025-2503" + ], + "details": "An improper permission handling vulnerability was reported in Lenovo PC Manager that could allow a local attacker to perform arbitrary file deletions as an elevated user.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2503" + }, + { + "type": "WEB", + "url": "https://iknow.lenovo.com.cn/detail/428586" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-280" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-30T20:15:42Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-c8vj-q55w-r7h8/GHSA-c8vj-q55w-r7h8.json b/advisories/unreviewed/2025/05/GHSA-c8vj-q55w-r7h8/GHSA-c8vj-q55w-r7h8.json new file mode 100644 index 00000000000..f8660d215de --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-c8vj-q55w-r7h8/GHSA-c8vj-q55w-r7h8.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c8vj-q55w-r7h8", + "modified": "2025-05-30T21:30:57Z", + "published": "2025-05-30T21:30:57Z", + "aliases": [ + "CVE-2025-5359" + ], + "details": "A vulnerability classified as critical has been found in Campcodes Online Hospital Management System 1.0. This affects an unknown part of the file /appointment-history.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5359" + }, + { + "type": "WEB", + "url": "https://github.com/ASantsSec/CVE/issues/7" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.310653" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.310653" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.586590" + }, + { + "type": "WEB", + "url": "https://www.campcodes.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-30T19:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-mhg6-w3h6-f286/GHSA-mhg6-w3h6-f286.json b/advisories/unreviewed/2025/05/GHSA-mhg6-w3h6-f286/GHSA-mhg6-w3h6-f286.json new file mode 100644 index 00000000000..caef246af5b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-mhg6-w3h6-f286/GHSA-mhg6-w3h6-f286.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mhg6-w3h6-f286", + "modified": "2025-05-30T21:30:58Z", + "published": "2025-05-30T21:30:58Z", + "aliases": [ + "CVE-2025-5360" + ], + "details": "A vulnerability classified as critical was found in Campcodes Online Hospital Management System 1.0. This vulnerability affects unknown code of the file /book-appointment.php. The manipulation of the argument doctor leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5360" + }, + { + "type": "WEB", + "url": "https://github.com/ASantsSec/CVE/issues/8" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.310654" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.310654" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.586591" + }, + { + "type": "WEB", + "url": "https://www.campcodes.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-30T20:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-mj3f-8797-c7r5/GHSA-mj3f-8797-c7r5.json b/advisories/unreviewed/2025/05/GHSA-mj3f-8797-c7r5/GHSA-mj3f-8797-c7r5.json new file mode 100644 index 00000000000..b12f6d2e0e4 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-mj3f-8797-c7r5/GHSA-mj3f-8797-c7r5.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mj3f-8797-c7r5", + "modified": "2025-05-30T21:30:57Z", + "published": "2025-05-30T21:30:57Z", + "aliases": [ + "CVE-2025-1479" + ], + "details": "An open debug interface was reported in the Legion Space software included on certain Legion devices that could allow a local attacker to execute arbitrary code.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1479" + }, + { + "type": "WEB", + "url": "https://support.lenovo.com/us/en/product_security/LEN-186929" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-489" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-30T20:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-p64m-3pg6-g8pq/GHSA-p64m-3pg6-g8pq.json b/advisories/unreviewed/2025/05/GHSA-p64m-3pg6-g8pq/GHSA-p64m-3pg6-g8pq.json new file mode 100644 index 00000000000..62925d472e1 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-p64m-3pg6-g8pq/GHSA-p64m-3pg6-g8pq.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p64m-3pg6-g8pq", + "modified": "2025-05-30T21:30:58Z", + "published": "2025-05-30T21:30:58Z", + "aliases": [ + "CVE-2025-5361" + ], + "details": "A vulnerability, which was classified as critical, has been found in Campcodes Online Hospital Management System 1.0. This issue affects some unknown processing of the file /contact.php. The manipulation of the argument fullname leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5361" + }, + { + "type": "WEB", + "url": "https://github.com/ASantsSec/CVE/issues/9" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.310655" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.310655" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.586592" + }, + { + "type": "WEB", + "url": "https://www.campcodes.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-30T20:15:44Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-w3vc-hpm9-2h9q/GHSA-w3vc-hpm9-2h9q.json b/advisories/unreviewed/2025/05/GHSA-w3vc-hpm9-2h9q/GHSA-w3vc-hpm9-2h9q.json index 5859d099d41..edc9b7ed5af 100644 --- a/advisories/unreviewed/2025/05/GHSA-w3vc-hpm9-2h9q/GHSA-w3vc-hpm9-2h9q.json +++ b/advisories/unreviewed/2025/05/GHSA-w3vc-hpm9-2h9q/GHSA-w3vc-hpm9-2h9q.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w3vc-hpm9-2h9q", - "modified": "2025-05-28T18:33:29Z", + "modified": "2025-05-30T21:30:56Z", "published": "2025-05-28T18:33:29Z", "aliases": [ "CVE-2024-57338" ], "details": "An arbitrary file upload vulnerability in M2Soft CROWNIX Report & ERS v5.x to v5.5.14.1070, v7.x to v7.4.3.960, and v8.x to v8.2.0.345 allows attackers to execute arbitrary code via supplying a crafted file.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-28T18:15:25Z" diff --git a/advisories/unreviewed/2025/05/GHSA-wxg6-4cwm-4rjf/GHSA-wxg6-4cwm-4rjf.json b/advisories/unreviewed/2025/05/GHSA-wxg6-4cwm-4rjf/GHSA-wxg6-4cwm-4rjf.json index e5355232c76..98c12526088 100644 --- a/advisories/unreviewed/2025/05/GHSA-wxg6-4cwm-4rjf/GHSA-wxg6-4cwm-4rjf.json +++ b/advisories/unreviewed/2025/05/GHSA-wxg6-4cwm-4rjf/GHSA-wxg6-4cwm-4rjf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wxg6-4cwm-4rjf", - "modified": "2025-05-28T18:33:29Z", + "modified": "2025-05-30T21:30:55Z", "published": "2025-05-28T18:33:29Z", "aliases": [ "CVE-2024-57337" ], "details": "An arbitrary file upload vulnerability in the opcode 500 functionality of M2Soft CROWNIX Report & ERS v5.x to v5.5.14.1070, v7.x to v7.4.3.960, and v8.x to v8.2.0.345 allows attackers to execute arbitrary code via supplying a crafted file.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-28T18:15:25Z" diff --git a/advisories/unreviewed/2025/05/GHSA-x3mr-mm28-qg7m/GHSA-x3mr-mm28-qg7m.json b/advisories/unreviewed/2025/05/GHSA-x3mr-mm28-qg7m/GHSA-x3mr-mm28-qg7m.json new file mode 100644 index 00000000000..ecae54efd37 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-x3mr-mm28-qg7m/GHSA-x3mr-mm28-qg7m.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x3mr-mm28-qg7m", + "modified": "2025-05-30T21:30:57Z", + "published": "2025-05-30T21:30:57Z", + "aliases": [ + "CVE-2025-2502" + ], + "details": "An improper default permissions vulnerability was reported in Lenovo PC Manager that could allow a local attacker to elevate privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2502" + }, + { + "type": "WEB", + "url": "https://iknow.lenovo.com.cn/detail/428586" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-276" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-30T20:15:42Z" + } +} \ No newline at end of file