From 9204d12a9d84e8048094102a5609296f6b7270d2 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 8 Jan 2025 15:32:34 +0000 Subject: [PATCH] Publish Advisories GHSA-v9pp-h525-vwm9 GHSA-8xr9-89pc-8wcx GHSA-c274-3m34-wwp8 GHSA-868q-j7qx-m3gf GHSA-pvhv-2w8w-pf3x GHSA-pxw4-6qw4-jp6w GHSA-vf7h-r8hg-75jj GHSA-vpj9-v2pp-24wp GHSA-x9mq-h652-rw6x GHSA-24v2-mrj2-4wpc GHSA-3wv8-q6g7-7frh GHSA-5wmg-fqv9-w9qf GHSA-7x7r-gpvw-q53f GHSA-9w8w-fgjg-w972 GHSA-c286-9hvr-9fmm GHSA-fh3v-99xx-v7cw GHSA-fv2q-p9cw-m9w5 GHSA-h6vm-3gjm-rw54 GHSA-mjf9-4pcv-vfg7 GHSA-vh28-f7wh-hg42 GHSA-vw56-cch3-67cp GHSA-wgc3-34qh-3h44 --- .../GHSA-v9pp-h525-vwm9/GHSA-v9pp-h525-vwm9.json | 2 +- .../GHSA-8xr9-89pc-8wcx/GHSA-8xr9-89pc-8wcx.json | 3 ++- .../GHSA-c274-3m34-wwp8/GHSA-c274-3m34-wwp8.json | 1 + .../GHSA-868q-j7qx-m3gf/GHSA-868q-j7qx-m3gf.json | 1 + .../GHSA-pvhv-2w8w-pf3x/GHSA-pvhv-2w8w-pf3x.json | 1 + .../GHSA-pxw4-6qw4-jp6w/GHSA-pxw4-6qw4-jp6w.json | 1 + .../GHSA-vf7h-r8hg-75jj/GHSA-vf7h-r8hg-75jj.json | 6 +++++- .../GHSA-vpj9-v2pp-24wp/GHSA-vpj9-v2pp-24wp.json | 1 + .../GHSA-x9mq-h652-rw6x/GHSA-x9mq-h652-rw6x.json | 1 + .../GHSA-24v2-mrj2-4wpc/GHSA-24v2-mrj2-4wpc.json | 11 ++++++++--- .../GHSA-3wv8-q6g7-7frh/GHSA-3wv8-q6g7-7frh.json | 15 +++++++++++---- .../GHSA-5wmg-fqv9-w9qf/GHSA-5wmg-fqv9-w9qf.json | 11 ++++++++--- .../GHSA-7x7r-gpvw-q53f/GHSA-7x7r-gpvw-q53f.json | 15 +++++++++++---- .../GHSA-9w8w-fgjg-w972/GHSA-9w8w-fgjg-w972.json | 15 +++++++++++---- .../GHSA-c286-9hvr-9fmm/GHSA-c286-9hvr-9fmm.json | 6 +++++- .../GHSA-fh3v-99xx-v7cw/GHSA-fh3v-99xx-v7cw.json | 6 +++++- .../GHSA-fv2q-p9cw-m9w5/GHSA-fv2q-p9cw-m9w5.json | 15 +++++++++++---- .../GHSA-h6vm-3gjm-rw54/GHSA-h6vm-3gjm-rw54.json | 11 ++++++++--- .../GHSA-mjf9-4pcv-vfg7/GHSA-mjf9-4pcv-vfg7.json | 11 ++++++++--- .../GHSA-vh28-f7wh-hg42/GHSA-vh28-f7wh-hg42.json | 15 +++++++++++---- .../GHSA-vw56-cch3-67cp/GHSA-vw56-cch3-67cp.json | 6 +++++- .../GHSA-wgc3-34qh-3h44/GHSA-wgc3-34qh-3h44.json | 6 ++++-- 22 files changed, 120 insertions(+), 40 deletions(-) diff --git a/advisories/unreviewed/2023/06/GHSA-v9pp-h525-vwm9/GHSA-v9pp-h525-vwm9.json b/advisories/unreviewed/2023/06/GHSA-v9pp-h525-vwm9/GHSA-v9pp-h525-vwm9.json index 3fb3fb2ad81..6b87b6a5bca 100644 --- a/advisories/unreviewed/2023/06/GHSA-v9pp-h525-vwm9/GHSA-v9pp-h525-vwm9.json +++ b/advisories/unreviewed/2023/06/GHSA-v9pp-h525-vwm9/GHSA-v9pp-h525-vwm9.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v9pp-h525-vwm9", - "modified": "2023-11-25T12:30:22Z", + "modified": "2025-01-08T15:31:06Z", "published": "2023-06-07T21:30:18Z", "aliases": [ "CVE-2023-33863" diff --git a/advisories/unreviewed/2024/04/GHSA-8xr9-89pc-8wcx/GHSA-8xr9-89pc-8wcx.json b/advisories/unreviewed/2024/04/GHSA-8xr9-89pc-8wcx/GHSA-8xr9-89pc-8wcx.json index efa03e4182c..9f18a01c79b 100644 --- a/advisories/unreviewed/2024/04/GHSA-8xr9-89pc-8wcx/GHSA-8xr9-89pc-8wcx.json +++ b/advisories/unreviewed/2024/04/GHSA-8xr9-89pc-8wcx/GHSA-8xr9-89pc-8wcx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8xr9-89pc-8wcx", - "modified": "2024-04-20T00:31:52Z", + "modified": "2025-01-08T15:31:06Z", "published": "2024-04-04T18:30:33Z", "aliases": [ "CVE-2024-25690" @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-79", "CWE-80" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/04/GHSA-c274-3m34-wwp8/GHSA-c274-3m34-wwp8.json b/advisories/unreviewed/2024/04/GHSA-c274-3m34-wwp8/GHSA-c274-3m34-wwp8.json index 4f814342ba3..47d7bffec5a 100644 --- a/advisories/unreviewed/2024/04/GHSA-c274-3m34-wwp8/GHSA-c274-3m34-wwp8.json +++ b/advisories/unreviewed/2024/04/GHSA-c274-3m34-wwp8/GHSA-c274-3m34-wwp8.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-203", "CWE-416" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/12/GHSA-868q-j7qx-m3gf/GHSA-868q-j7qx-m3gf.json b/advisories/unreviewed/2024/12/GHSA-868q-j7qx-m3gf/GHSA-868q-j7qx-m3gf.json index 49aaab94cff..bc7d1c84496 100644 --- a/advisories/unreviewed/2024/12/GHSA-868q-j7qx-m3gf/GHSA-868q-j7qx-m3gf.json +++ b/advisories/unreviewed/2024/12/GHSA-868q-j7qx-m3gf/GHSA-868q-j7qx-m3gf.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-362", "CWE-416" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/12/GHSA-pvhv-2w8w-pf3x/GHSA-pvhv-2w8w-pf3x.json b/advisories/unreviewed/2024/12/GHSA-pvhv-2w8w-pf3x/GHSA-pvhv-2w8w-pf3x.json index 45e7ed5c6c3..f2c222d2d15 100644 --- a/advisories/unreviewed/2024/12/GHSA-pvhv-2w8w-pf3x/GHSA-pvhv-2w8w-pf3x.json +++ b/advisories/unreviewed/2024/12/GHSA-pvhv-2w8w-pf3x/GHSA-pvhv-2w8w-pf3x.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-362", "CWE-416" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/12/GHSA-pxw4-6qw4-jp6w/GHSA-pxw4-6qw4-jp6w.json b/advisories/unreviewed/2024/12/GHSA-pxw4-6qw4-jp6w/GHSA-pxw4-6qw4-jp6w.json index bf4cb3674d6..e0755498865 100644 --- a/advisories/unreviewed/2024/12/GHSA-pxw4-6qw4-jp6w/GHSA-pxw4-6qw4-jp6w.json +++ b/advisories/unreviewed/2024/12/GHSA-pxw4-6qw4-jp6w/GHSA-pxw4-6qw4-jp6w.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-362", "CWE-415" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/12/GHSA-vf7h-r8hg-75jj/GHSA-vf7h-r8hg-75jj.json b/advisories/unreviewed/2024/12/GHSA-vf7h-r8hg-75jj/GHSA-vf7h-r8hg-75jj.json index 4b8b75c67c5..b7559a4b42a 100644 --- a/advisories/unreviewed/2024/12/GHSA-vf7h-r8hg-75jj/GHSA-vf7h-r8hg-75jj.json +++ b/advisories/unreviewed/2024/12/GHSA-vf7h-r8hg-75jj/GHSA-vf7h-r8hg-75jj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vf7h-r8hg-75jj", - "modified": "2025-01-06T18:31:01Z", + "modified": "2025-01-08T15:31:09Z", "published": "2024-12-31T12:30:44Z", "aliases": [ "CVE-2024-12105" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://www.progress.com/network-monitoring" + }, + { + "type": "WEB", + "url": "https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2089" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/12/GHSA-vpj9-v2pp-24wp/GHSA-vpj9-v2pp-24wp.json b/advisories/unreviewed/2024/12/GHSA-vpj9-v2pp-24wp/GHSA-vpj9-v2pp-24wp.json index 33fc3dc4757..d55d8b8ca55 100644 --- a/advisories/unreviewed/2024/12/GHSA-vpj9-v2pp-24wp/GHSA-vpj9-v2pp-24wp.json +++ b/advisories/unreviewed/2024/12/GHSA-vpj9-v2pp-24wp/GHSA-vpj9-v2pp-24wp.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-362", "CWE-416" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/12/GHSA-x9mq-h652-rw6x/GHSA-x9mq-h652-rw6x.json b/advisories/unreviewed/2024/12/GHSA-x9mq-h652-rw6x/GHSA-x9mq-h652-rw6x.json index 172b863e7cd..0dc48bb2904 100644 --- a/advisories/unreviewed/2024/12/GHSA-x9mq-h652-rw6x/GHSA-x9mq-h652-rw6x.json +++ b/advisories/unreviewed/2024/12/GHSA-x9mq-h652-rw6x/GHSA-x9mq-h652-rw6x.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-362", "CWE-59" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2025/01/GHSA-24v2-mrj2-4wpc/GHSA-24v2-mrj2-4wpc.json b/advisories/unreviewed/2025/01/GHSA-24v2-mrj2-4wpc/GHSA-24v2-mrj2-4wpc.json index ea2194e6eea..5790bba065c 100644 --- a/advisories/unreviewed/2025/01/GHSA-24v2-mrj2-4wpc/GHSA-24v2-mrj2-4wpc.json +++ b/advisories/unreviewed/2025/01/GHSA-24v2-mrj2-4wpc/GHSA-24v2-mrj2-4wpc.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-24v2-mrj2-4wpc", - "modified": "2025-01-07T18:30:50Z", + "modified": "2025-01-08T15:31:09Z", "published": "2025-01-07T18:30:50Z", "aliases": [ "CVE-2025-0247" ], "details": "Memory safety bugs present in Firefox 133 and Thunderbird 133. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 134.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -25,7 +30,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-07T16:15:39Z" diff --git a/advisories/unreviewed/2025/01/GHSA-3wv8-q6g7-7frh/GHSA-3wv8-q6g7-7frh.json b/advisories/unreviewed/2025/01/GHSA-3wv8-q6g7-7frh/GHSA-3wv8-q6g7-7frh.json index 3c56aed1090..5a5909808dd 100644 --- a/advisories/unreviewed/2025/01/GHSA-3wv8-q6g7-7frh/GHSA-3wv8-q6g7-7frh.json +++ b/advisories/unreviewed/2025/01/GHSA-3wv8-q6g7-7frh/GHSA-3wv8-q6g7-7frh.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3wv8-q6g7-7frh", - "modified": "2025-01-07T21:30:55Z", + "modified": "2025-01-08T15:31:10Z", "published": "2025-01-07T21:30:55Z", "aliases": [ "CVE-2022-41572" ], "details": "An issue was discovered in EyesOfNetwork (EON) through 5.3.11. Privilege escalation can be accomplished on the server because nmap can be run as root. The attacker achieves total control over the server.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-276" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-07T20:15:27Z" diff --git a/advisories/unreviewed/2025/01/GHSA-5wmg-fqv9-w9qf/GHSA-5wmg-fqv9-w9qf.json b/advisories/unreviewed/2025/01/GHSA-5wmg-fqv9-w9qf/GHSA-5wmg-fqv9-w9qf.json index 00543fc13b0..0401f7c9ef5 100644 --- a/advisories/unreviewed/2025/01/GHSA-5wmg-fqv9-w9qf/GHSA-5wmg-fqv9-w9qf.json +++ b/advisories/unreviewed/2025/01/GHSA-5wmg-fqv9-w9qf/GHSA-5wmg-fqv9-w9qf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5wmg-fqv9-w9qf", - "modified": "2025-01-07T18:30:52Z", + "modified": "2025-01-08T15:31:09Z", "published": "2025-01-07T18:30:51Z", "aliases": [ "CVE-2024-40748" ], "details": "Lack of output escaping in the id attribute of menu lists.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-79" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-07T17:15:23Z" diff --git a/advisories/unreviewed/2025/01/GHSA-7x7r-gpvw-q53f/GHSA-7x7r-gpvw-q53f.json b/advisories/unreviewed/2025/01/GHSA-7x7r-gpvw-q53f/GHSA-7x7r-gpvw-q53f.json index 3c610996ff4..692ae2d43f0 100644 --- a/advisories/unreviewed/2025/01/GHSA-7x7r-gpvw-q53f/GHSA-7x7r-gpvw-q53f.json +++ b/advisories/unreviewed/2025/01/GHSA-7x7r-gpvw-q53f/GHSA-7x7r-gpvw-q53f.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7x7r-gpvw-q53f", - "modified": "2025-01-07T21:30:55Z", + "modified": "2025-01-08T15:31:10Z", "published": "2025-01-07T21:30:55Z", "aliases": [ "CVE-2024-55218" ], "details": "IceWarp Server 10.2.1 is vulnerable to Cross Site Scripting (XSS) via the meta parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-07T20:15:30Z" diff --git a/advisories/unreviewed/2025/01/GHSA-9w8w-fgjg-w972/GHSA-9w8w-fgjg-w972.json b/advisories/unreviewed/2025/01/GHSA-9w8w-fgjg-w972/GHSA-9w8w-fgjg-w972.json index 3989c96388b..28cfa25dc6b 100644 --- a/advisories/unreviewed/2025/01/GHSA-9w8w-fgjg-w972/GHSA-9w8w-fgjg-w972.json +++ b/advisories/unreviewed/2025/01/GHSA-9w8w-fgjg-w972/GHSA-9w8w-fgjg-w972.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9w8w-fgjg-w972", - "modified": "2025-01-07T21:30:55Z", + "modified": "2025-01-08T15:31:10Z", "published": "2025-01-07T21:30:55Z", "aliases": [ "CVE-2024-54819" ], "details": "I, Librarian before and including 5.11.1 is vulnerable to Server-Side Request Forgery (SSRF) due to improper input validation in classes/security/validation.php", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-918" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-07T20:15:30Z" diff --git a/advisories/unreviewed/2025/01/GHSA-c286-9hvr-9fmm/GHSA-c286-9hvr-9fmm.json b/advisories/unreviewed/2025/01/GHSA-c286-9hvr-9fmm/GHSA-c286-9hvr-9fmm.json index c9e8b7967ba..4a4acb92711 100644 --- a/advisories/unreviewed/2025/01/GHSA-c286-9hvr-9fmm/GHSA-c286-9hvr-9fmm.json +++ b/advisories/unreviewed/2025/01/GHSA-c286-9hvr-9fmm/GHSA-c286-9hvr-9fmm.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-c286-9hvr-9fmm", - "modified": "2025-01-08T09:30:38Z", + "modified": "2025-01-08T15:31:11Z", "published": "2025-01-08T09:30:38Z", "aliases": [ "CVE-2024-13173" ], "details": "The health module has insufficient restrictions on loading URLs, which may lead to some information leakage.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2025/01/GHSA-fh3v-99xx-v7cw/GHSA-fh3v-99xx-v7cw.json b/advisories/unreviewed/2025/01/GHSA-fh3v-99xx-v7cw/GHSA-fh3v-99xx-v7cw.json index 8f7ae9a6f3b..3cd08e730e5 100644 --- a/advisories/unreviewed/2025/01/GHSA-fh3v-99xx-v7cw/GHSA-fh3v-99xx-v7cw.json +++ b/advisories/unreviewed/2025/01/GHSA-fh3v-99xx-v7cw/GHSA-fh3v-99xx-v7cw.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-fh3v-99xx-v7cw", - "modified": "2025-01-08T09:30:38Z", + "modified": "2025-01-08T15:31:11Z", "published": "2025-01-08T09:30:38Z", "aliases": [ "CVE-2024-13186" ], "details": "The MinigameCenter module has insufficient restrictions on loading URLs, which may lead to some information leakage.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2025/01/GHSA-fv2q-p9cw-m9w5/GHSA-fv2q-p9cw-m9w5.json b/advisories/unreviewed/2025/01/GHSA-fv2q-p9cw-m9w5/GHSA-fv2q-p9cw-m9w5.json index 7b817afebe5..dc71ae9024e 100644 --- a/advisories/unreviewed/2025/01/GHSA-fv2q-p9cw-m9w5/GHSA-fv2q-p9cw-m9w5.json +++ b/advisories/unreviewed/2025/01/GHSA-fv2q-p9cw-m9w5/GHSA-fv2q-p9cw-m9w5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fv2q-p9cw-m9w5", - "modified": "2025-01-07T21:30:55Z", + "modified": "2025-01-08T15:31:10Z", "published": "2025-01-07T21:30:55Z", "aliases": [ "CVE-2024-35532" ], "details": "An XML External Entity (XXE) injection vulnerability in Intersec Geosafe-ea 2022.12, 2022.13, and 2022.14 allows attackers to perform arbitrary file reading under the privileges of the running process, make SSRF requests, or cause a Denial of Service (DoS) via unspecified vectors.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-125" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-07T20:15:29Z" diff --git a/advisories/unreviewed/2025/01/GHSA-h6vm-3gjm-rw54/GHSA-h6vm-3gjm-rw54.json b/advisories/unreviewed/2025/01/GHSA-h6vm-3gjm-rw54/GHSA-h6vm-3gjm-rw54.json index 78957f4eff9..8a71b6fe8b1 100644 --- a/advisories/unreviewed/2025/01/GHSA-h6vm-3gjm-rw54/GHSA-h6vm-3gjm-rw54.json +++ b/advisories/unreviewed/2025/01/GHSA-h6vm-3gjm-rw54/GHSA-h6vm-3gjm-rw54.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-h6vm-3gjm-rw54", - "modified": "2025-01-07T18:30:52Z", + "modified": "2025-01-08T15:31:09Z", "published": "2025-01-07T18:30:52Z", "aliases": [ "CVE-2024-40749" ], "details": "Improper Access Controls allows access to protected views.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-284" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-07T17:15:23Z" diff --git a/advisories/unreviewed/2025/01/GHSA-mjf9-4pcv-vfg7/GHSA-mjf9-4pcv-vfg7.json b/advisories/unreviewed/2025/01/GHSA-mjf9-4pcv-vfg7/GHSA-mjf9-4pcv-vfg7.json index c9dfa6e520d..63db2dc7edb 100644 --- a/advisories/unreviewed/2025/01/GHSA-mjf9-4pcv-vfg7/GHSA-mjf9-4pcv-vfg7.json +++ b/advisories/unreviewed/2025/01/GHSA-mjf9-4pcv-vfg7/GHSA-mjf9-4pcv-vfg7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-mjf9-4pcv-vfg7", - "modified": "2025-01-08T09:30:39Z", + "modified": "2025-01-08T15:31:11Z", "published": "2025-01-08T09:30:39Z", "aliases": [ "CVE-2024-54676" ], "details": "Vendor: The Apache Software Foundation\n\nVersions Affected: Apache OpenMeetings from 2.1.0 before 8.0.0\n\nDescription: Default clustering instructions at https://openmeetings.apache.org/Clustering.html  doesn't specify white/black lists for OpenJPA this leads to possible deserialisation of untrusted data.\nUsers are recommended to upgrade to version 8.0.0 and update their startup scripts to include the relevant 'openjpa.serialization.class.blacklist' and 'openjpa.serialization.class.whitelist' configurations as shown in the documentation.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -27,7 +32,7 @@ "cwe_ids": [ "CWE-502" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-08T09:15:07Z" diff --git a/advisories/unreviewed/2025/01/GHSA-vh28-f7wh-hg42/GHSA-vh28-f7wh-hg42.json b/advisories/unreviewed/2025/01/GHSA-vh28-f7wh-hg42/GHSA-vh28-f7wh-hg42.json index 7731011a670..b2b4569f779 100644 --- a/advisories/unreviewed/2025/01/GHSA-vh28-f7wh-hg42/GHSA-vh28-f7wh-hg42.json +++ b/advisories/unreviewed/2025/01/GHSA-vh28-f7wh-hg42/GHSA-vh28-f7wh-hg42.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vh28-f7wh-hg42", - "modified": "2025-01-07T21:30:55Z", + "modified": "2025-01-08T15:31:10Z", "published": "2025-01-07T21:30:55Z", "aliases": [ "CVE-2022-41573" ], "details": "An issue was discovered in Ovidentia 8.3. The file upload feature does not prevent the uploading of executable files. A user can upload a .png file containing PHP code and then rename it to have the .php extension. It will then be accessible at an images/common/ URI for remote code execution.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-07T20:15:28Z" diff --git a/advisories/unreviewed/2025/01/GHSA-vw56-cch3-67cp/GHSA-vw56-cch3-67cp.json b/advisories/unreviewed/2025/01/GHSA-vw56-cch3-67cp/GHSA-vw56-cch3-67cp.json index 4e4236f5ae4..7f89051518a 100644 --- a/advisories/unreviewed/2025/01/GHSA-vw56-cch3-67cp/GHSA-vw56-cch3-67cp.json +++ b/advisories/unreviewed/2025/01/GHSA-vw56-cch3-67cp/GHSA-vw56-cch3-67cp.json @@ -1,13 +1,17 @@ { "schema_version": "1.4.0", "id": "GHSA-vw56-cch3-67cp", - "modified": "2025-01-08T09:30:38Z", + "modified": "2025-01-08T15:31:11Z", "published": "2025-01-08T09:30:38Z", "aliases": [ "CVE-2024-13185" ], "details": "The MinigameCenter module has insufficient restrictions on loading URLs, which may lead to some information leakage.", "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, { "type": "CVSS_V4", "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" diff --git a/advisories/unreviewed/2025/01/GHSA-wgc3-34qh-3h44/GHSA-wgc3-34qh-3h44.json b/advisories/unreviewed/2025/01/GHSA-wgc3-34qh-3h44/GHSA-wgc3-34qh-3h44.json index 46a2bbe19ec..f695750c93e 100644 --- a/advisories/unreviewed/2025/01/GHSA-wgc3-34qh-3h44/GHSA-wgc3-34qh-3h44.json +++ b/advisories/unreviewed/2025/01/GHSA-wgc3-34qh-3h44/GHSA-wgc3-34qh-3h44.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wgc3-34qh-3h44", - "modified": "2025-01-08T09:30:38Z", + "modified": "2025-01-08T15:31:11Z", "published": "2025-01-08T09:30:38Z", "aliases": [ "CVE-2025-22215" @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-918" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null,