Publish Advisories

GHSA-v9pp-h525-vwm9
GHSA-8xr9-89pc-8wcx
GHSA-c274-3m34-wwp8
GHSA-868q-j7qx-m3gf
GHSA-pvhv-2w8w-pf3x
GHSA-pxw4-6qw4-jp6w
GHSA-vf7h-r8hg-75jj
GHSA-vpj9-v2pp-24wp
GHSA-x9mq-h652-rw6x
GHSA-24v2-mrj2-4wpc
GHSA-3wv8-q6g7-7frh
GHSA-5wmg-fqv9-w9qf
GHSA-7x7r-gpvw-q53f
GHSA-9w8w-fgjg-w972
GHSA-c286-9hvr-9fmm
GHSA-fh3v-99xx-v7cw
GHSA-fv2q-p9cw-m9w5
GHSA-h6vm-3gjm-rw54
GHSA-mjf9-4pcv-vfg7
GHSA-vh28-f7wh-hg42
GHSA-vw56-cch3-67cp
GHSA-wgc3-34qh-3h44
This commit is contained in:
advisory-database[bot]
2025-01-08 15:32:34 +00:00
parent 3285b3d56b
commit 9204d12a9d
22 changed files with 120 additions and 40 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v9pp-h525-vwm9",
"modified": "2023-11-25T12:30:22Z",
"modified": "2025-01-08T15:31:06Z",
"published": "2023-06-07T21:30:18Z",
"aliases": [
"CVE-2023-33863"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-8xr9-89pc-8wcx",
"modified": "2024-04-20T00:31:52Z",
"modified": "2025-01-08T15:31:06Z",
"published": "2024-04-04T18:30:33Z",
"aliases": [
"CVE-2024-25690"
@@ -30,6 +30,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-79",
"CWE-80"
],
"severity": "MODERATE",
@@ -26,6 +26,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-203",
"CWE-416"
],
"severity": "HIGH",
@@ -26,6 +26,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-362",
"CWE-416"
],
"severity": "HIGH",
@@ -26,6 +26,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-362",
"CWE-416"
],
"severity": "HIGH",
@@ -26,6 +26,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-362",
"CWE-415"
],
"severity": "HIGH",
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vf7h-r8hg-75jj",
"modified": "2025-01-06T18:31:01Z",
"modified": "2025-01-08T15:31:09Z",
"published": "2024-12-31T12:30:44Z",
"aliases": [
"CVE-2024-12105"
@@ -22,6 +22,10 @@
{
"type": "WEB",
"url": "https://www.progress.com/network-monitoring"
},
{
"type": "WEB",
"url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2089"
}
],
"database_specific": {
@@ -26,6 +26,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-362",
"CWE-416"
],
"severity": "HIGH",
@@ -26,6 +26,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-362",
"CWE-59"
],
"severity": "HIGH",
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-24v2-mrj2-4wpc",
"modified": "2025-01-07T18:30:50Z",
"modified": "2025-01-08T15:31:09Z",
"published": "2025-01-07T18:30:50Z",
"aliases": [
"CVE-2025-0247"
],
"details": "Memory safety bugs present in Firefox 133 and Thunderbird 133. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 134.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -25,7 +30,7 @@
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-07T16:15:39Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3wv8-q6g7-7frh",
"modified": "2025-01-07T21:30:55Z",
"modified": "2025-01-08T15:31:10Z",
"published": "2025-01-07T21:30:55Z",
"aliases": [
"CVE-2022-41572"
],
"details": "An issue was discovered in EyesOfNetwork (EON) through 5.3.11. Privilege escalation can be accomplished on the server because nmap can be run as root. The attacker achieves total control over the server.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-276"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-07T20:15:27Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5wmg-fqv9-w9qf",
"modified": "2025-01-07T18:30:52Z",
"modified": "2025-01-08T15:31:09Z",
"published": "2025-01-07T18:30:51Z",
"aliases": [
"CVE-2024-40748"
],
"details": "Lack of output escaping in the id attribute of menu lists.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [],
"references": [
{
@@ -23,7 +28,7 @@
"cwe_ids": [
"CWE-79"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-07T17:15:23Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7x7r-gpvw-q53f",
"modified": "2025-01-07T21:30:55Z",
"modified": "2025-01-08T15:31:10Z",
"published": "2025-01-07T21:30:55Z",
"aliases": [
"CVE-2024-55218"
],
"details": "IceWarp Server 10.2.1 is vulnerable to Cross Site Scripting (XSS) via the meta parameter.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-07T20:15:30Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9w8w-fgjg-w972",
"modified": "2025-01-07T21:30:55Z",
"modified": "2025-01-08T15:31:10Z",
"published": "2025-01-07T21:30:55Z",
"aliases": [
"CVE-2024-54819"
],
"details": "I, Librarian before and including 5.11.1 is vulnerable to Server-Side Request Forgery (SSRF) due to improper input validation in classes/security/validation.php",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"
}
],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-918"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-07T20:15:30Z"
@@ -1,13 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-c286-9hvr-9fmm",
"modified": "2025-01-08T09:30:38Z",
"modified": "2025-01-08T15:31:11Z",
"published": "2025-01-08T09:30:38Z",
"aliases": [
"CVE-2024-13173"
],
"details": "The health module has insufficient restrictions on loading URLs, which may lead to some information leakage.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
@@ -1,13 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fh3v-99xx-v7cw",
"modified": "2025-01-08T09:30:38Z",
"modified": "2025-01-08T15:31:11Z",
"published": "2025-01-08T09:30:38Z",
"aliases": [
"CVE-2024-13186"
],
"details": "The MinigameCenter module has insufficient restrictions on loading URLs, which may lead to some information leakage.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fv2q-p9cw-m9w5",
"modified": "2025-01-07T21:30:55Z",
"modified": "2025-01-08T15:31:10Z",
"published": "2025-01-07T21:30:55Z",
"aliases": [
"CVE-2024-35532"
],
"details": "An XML External Entity (XXE) injection vulnerability in Intersec Geosafe-ea 2022.12, 2022.13, and 2022.14 allows attackers to perform arbitrary file reading under the privileges of the running process, make SSRF requests, or cause a Denial of Service (DoS) via unspecified vectors.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"
}
],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-125"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-07T20:15:29Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h6vm-3gjm-rw54",
"modified": "2025-01-07T18:30:52Z",
"modified": "2025-01-08T15:31:09Z",
"published": "2025-01-07T18:30:52Z",
"aliases": [
"CVE-2024-40749"
],
"details": "Improper Access Controls allows access to protected views.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
}
],
"affected": [],
"references": [
{
@@ -23,7 +28,7 @@
"cwe_ids": [
"CWE-284"
],
"severity": null,
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-07T17:15:23Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mjf9-4pcv-vfg7",
"modified": "2025-01-08T09:30:39Z",
"modified": "2025-01-08T15:31:11Z",
"published": "2025-01-08T09:30:39Z",
"aliases": [
"CVE-2024-54676"
],
"details": "Vendor: The Apache Software Foundation\n\nVersions Affected: Apache OpenMeetings from 2.1.0 before 8.0.0\n\nDescription: Default clustering instructions at https://openmeetings.apache.org/Clustering.html  doesn't specify white/black lists for OpenJPA this leads to possible deserialisation of untrusted data.\nUsers are recommended to upgrade to version 8.0.0 and update their startup scripts to include the relevant 'openjpa.serialization.class.blacklist' and 'openjpa.serialization.class.whitelist' configurations as shown in the documentation.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -27,7 +32,7 @@
"cwe_ids": [
"CWE-502"
],
"severity": null,
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-08T09:15:07Z"
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-vh28-f7wh-hg42",
"modified": "2025-01-07T21:30:55Z",
"modified": "2025-01-08T15:31:10Z",
"published": "2025-01-07T21:30:55Z",
"aliases": [
"CVE-2022-41573"
],
"details": "An issue was discovered in Ovidentia 8.3. The file upload feature does not prevent the uploading of executable files. A user can upload a .png file containing PHP code and then rename it to have the .php extension. It will then be accessible at an images/common/ URI for remote code execution.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
"cwe_ids": [],
"severity": null,
"cwe_ids": [
"CWE-434"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-07T20:15:28Z"

Some files were not shown because too many files have changed in this diff Show More