From 948eb0caf81c08b1224600448f2eb19a389955d4 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Sat, 1 Mar 2025 12:32:06 +0000 Subject: [PATCH] Publish Advisories GHSA-277c-h7c7-c26c GHSA-2vpg-f68p-chgv GHSA-8jxw-vxhj-q8p7 GHSA-mc5g-26q7-84px --- .../GHSA-277c-h7c7-c26c.json | 60 +++++++++++++++++++ .../GHSA-2vpg-f68p-chgv.json | 48 +++++++++++++++ .../GHSA-8jxw-vxhj-q8p7.json | 52 ++++++++++++++++ .../GHSA-mc5g-26q7-84px.json | 40 +++++++++++++ 4 files changed, 200 insertions(+) create mode 100644 advisories/unreviewed/2025/03/GHSA-277c-h7c7-c26c/GHSA-277c-h7c7-c26c.json create mode 100644 advisories/unreviewed/2025/03/GHSA-2vpg-f68p-chgv/GHSA-2vpg-f68p-chgv.json create mode 100644 advisories/unreviewed/2025/03/GHSA-8jxw-vxhj-q8p7/GHSA-8jxw-vxhj-q8p7.json create mode 100644 advisories/unreviewed/2025/03/GHSA-mc5g-26q7-84px/GHSA-mc5g-26q7-84px.json diff --git a/advisories/unreviewed/2025/03/GHSA-277c-h7c7-c26c/GHSA-277c-h7c7-c26c.json b/advisories/unreviewed/2025/03/GHSA-277c-h7c7-c26c/GHSA-277c-h7c7-c26c.json new file mode 100644 index 00000000000..5f585d95e63 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-277c-h7c7-c26c/GHSA-277c-h7c7-c26c.json @@ -0,0 +1,60 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-277c-h7c7-c26c", + "modified": "2025-03-01T12:30:35Z", + "published": "2025-03-01T12:30:34Z", + "aliases": [ + "CVE-2025-1786" + ], + "details": "A vulnerability was found in rizinorg rizin up to 0.7.4. It has been rated as critical. This issue affects the function msf_stream_directory_free in the library /librz/bin/pdb/pdb.c. The manipulation of the argument -P leads to buffer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. Upgrading to version 0.8.0 is able to address this issue. It is recommended to upgrade the affected component.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1786" + }, + { + "type": "WEB", + "url": "https://github.com/rizinorg/rizin/issues/4893" + }, + { + "type": "WEB", + "url": "https://github.com/rizinorg/rizin/milestone/18" + }, + { + "type": "WEB", + "url": "https://github.com/user-attachments/files/18765730/rz-bin-6fb50-poc.zip" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.298007" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.298007" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.502317" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-01T10:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-2vpg-f68p-chgv/GHSA-2vpg-f68p-chgv.json b/advisories/unreviewed/2025/03/GHSA-2vpg-f68p-chgv/GHSA-2vpg-f68p-chgv.json new file mode 100644 index 00000000000..0ec08f053c0 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-2vpg-f68p-chgv/GHSA-2vpg-f68p-chgv.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2vpg-f68p-chgv", + "modified": "2025-03-01T12:30:34Z", + "published": "2025-03-01T12:30:34Z", + "aliases": [ + "CVE-2024-13546" + ], + "details": "The GenerateBlocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.9.1 via the 'get_image_description' function. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including the content of private, draft, and scheduled posts and pages.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13546" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/generateblocks/trunk/includes/class-dynamic-content.php#L1047" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/generateblocks/trunk/includes/class-dynamic-content.php#L1054" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3239461" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/4f6f2a8c-ecd9-482c-a32e-0c3d7a7e4ec4?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-01T10:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-8jxw-vxhj-q8p7/GHSA-8jxw-vxhj-q8p7.json b/advisories/unreviewed/2025/03/GHSA-8jxw-vxhj-q8p7/GHSA-8jxw-vxhj-q8p7.json new file mode 100644 index 00000000000..aa927a07bc3 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-8jxw-vxhj-q8p7/GHSA-8jxw-vxhj-q8p7.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8jxw-vxhj-q8p7", + "modified": "2025-03-01T12:30:35Z", + "published": "2025-03-01T12:30:35Z", + "aliases": [ + "CVE-2025-1404" + ], + "details": "The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ays_sccp_reports_user_search() function in all versions up to, and including, 4.4.7. This makes it possible for unauthenticated attackers to retrieve a list of registered user emails.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1404" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/secure-copy-content-protection/tags/4.4.6/admin/class-secure-copy-content-protection-admin.php#L943" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/secure-copy-content-protection/tags/4.4.6/admin/js/secure-copy-content-protection-admin.js" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3246301" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/secure-copy-content-protection/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/7363b5de-db30-4b35-b701-5c8f2835ec6c?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-01T12:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-mc5g-26q7-84px/GHSA-mc5g-26q7-84px.json b/advisories/unreviewed/2025/03/GHSA-mc5g-26q7-84px/GHSA-mc5g-26q7-84px.json new file mode 100644 index 00000000000..0b6668ca040 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-mc5g-26q7-84px/GHSA-mc5g-26q7-84px.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mc5g-26q7-84px", + "modified": "2025-03-01T12:30:35Z", + "published": "2025-03-01T12:30:35Z", + "aliases": [ + "CVE-2024-13833" + ], + "details": "The Album Gallery – WordPress Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.6.3 via deserialization of untrusted input from gallery meta. This makes it possible for authenticated attackers, with Editor-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13833" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3246291/new-album-gallery" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/cc7075a6-5609-42ab-a4cb-9d33686c7de0?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-01T12:15:33Z" + } +} \ No newline at end of file