From 987f3cbbdef2e0a69e1c6fbe08f8e784de28a48b Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 21 Apr 2025 18:33:27 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-5h3p-5xx6-mh88.json | 4 +- .../GHSA-cjwx-h5pw-chvg.json | 14 ++++++- .../GHSA-mgh2-3cf4-78r5.json | 4 +- .../GHSA-rjj4-r4wr-cjq8.json | 14 ++++++- .../GHSA-248j-xg68-6w85.json | 10 ++++- .../GHSA-2675-54p5-24ww.json | 4 +- .../GHSA-4hf4-g256-gxvm.json | 7 +++- .../GHSA-62ff-q4g6-fj3j.json | 3 +- .../GHSA-6385-g25r-xp83.json | 3 +- .../GHSA-cj65-9hr7-j38f.json | 4 +- .../GHSA-f52r-6pr7-vmv3.json | 4 +- .../GHSA-h72x-r663-chxx.json | 4 +- .../GHSA-j58x-47c8-gq4h.json | 4 +- .../GHSA-m5c8-qvmj-6h85.json | 4 +- .../GHSA-qg7p-gqjj-g2r8.json | 4 +- .../GHSA-rg9c-336x-3rq5.json | 4 +- .../GHSA-wrh9-jf24-cgwp.json | 4 +- .../GHSA-xh54-7xjp-2239.json | 1 + .../GHSA-vjhq-xqvq-7gh3.json | 1 + .../GHSA-8p2p-qc6p-2hr2.json | 4 +- .../GHSA-2823-wfgm-j3hr.json | 33 +++++++++++++++ .../GHSA-3ph3-5vg6-324h.json | 6 ++- .../GHSA-4528-h42g-x3c7.json | 29 ++++++++++++++ .../GHSA-5fjr-xr2p-8c46.json | 33 +++++++++++++++ .../GHSA-5vf8-pp4v-ccv9.json | 15 +++++-- .../GHSA-743f-hxpg-f2rj.json | 40 +++++++++++++++++++ .../GHSA-87v4-c5h4-88xg.json | 33 +++++++++++++++ .../GHSA-8rrr-w669-26rg.json | 15 +++++-- .../GHSA-f8h6-w72c-c28q.json | 36 +++++++++++++++++ .../GHSA-j6gw-77pg-859q.json | 36 +++++++++++++++++ .../GHSA-mh2f-2hrx-5245.json | 36 +++++++++++++++++ .../GHSA-pmgr-28ph-jhmm.json | 15 +++++-- .../GHSA-q332-7cfx-q6r5.json | 40 +++++++++++++++++++ .../GHSA-rfhg-52gw-r6hv.json | 33 +++++++++++++++ .../GHSA-v4fw-ww7x-63fp.json | 33 +++++++++++++++ .../GHSA-xw3g-f28m-3q7j.json | 15 +++++-- 36 files changed, 513 insertions(+), 36 deletions(-) create mode 100644 advisories/unreviewed/2025/04/GHSA-2823-wfgm-j3hr/GHSA-2823-wfgm-j3hr.json create mode 100644 advisories/unreviewed/2025/04/GHSA-4528-h42g-x3c7/GHSA-4528-h42g-x3c7.json create mode 100644 advisories/unreviewed/2025/04/GHSA-5fjr-xr2p-8c46/GHSA-5fjr-xr2p-8c46.json create mode 100644 advisories/unreviewed/2025/04/GHSA-743f-hxpg-f2rj/GHSA-743f-hxpg-f2rj.json create mode 100644 advisories/unreviewed/2025/04/GHSA-87v4-c5h4-88xg/GHSA-87v4-c5h4-88xg.json create mode 100644 advisories/unreviewed/2025/04/GHSA-f8h6-w72c-c28q/GHSA-f8h6-w72c-c28q.json create mode 100644 advisories/unreviewed/2025/04/GHSA-j6gw-77pg-859q/GHSA-j6gw-77pg-859q.json create mode 100644 advisories/unreviewed/2025/04/GHSA-mh2f-2hrx-5245/GHSA-mh2f-2hrx-5245.json create mode 100644 advisories/unreviewed/2025/04/GHSA-q332-7cfx-q6r5/GHSA-q332-7cfx-q6r5.json create mode 100644 advisories/unreviewed/2025/04/GHSA-rfhg-52gw-r6hv/GHSA-rfhg-52gw-r6hv.json create mode 100644 advisories/unreviewed/2025/04/GHSA-v4fw-ww7x-63fp/GHSA-v4fw-ww7x-63fp.json diff --git a/advisories/unreviewed/2022/11/GHSA-5h3p-5xx6-mh88/GHSA-5h3p-5xx6-mh88.json b/advisories/unreviewed/2022/11/GHSA-5h3p-5xx6-mh88/GHSA-5h3p-5xx6-mh88.json index 39088ddf8c0..0f39701ca18 100644 --- a/advisories/unreviewed/2022/11/GHSA-5h3p-5xx6-mh88/GHSA-5h3p-5xx6-mh88.json +++ b/advisories/unreviewed/2022/11/GHSA-5h3p-5xx6-mh88/GHSA-5h3p-5xx6-mh88.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-cjwx-h5pw-chvg/GHSA-cjwx-h5pw-chvg.json b/advisories/unreviewed/2022/11/GHSA-cjwx-h5pw-chvg/GHSA-cjwx-h5pw-chvg.json index 1ff6f903f15..451c78c3b3a 100644 --- a/advisories/unreviewed/2022/11/GHSA-cjwx-h5pw-chvg/GHSA-cjwx-h5pw-chvg.json +++ b/advisories/unreviewed/2022/11/GHSA-cjwx-h5pw-chvg/GHSA-cjwx-h5pw-chvg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cjwx-h5pw-chvg", - "modified": "2022-11-03T19:00:28Z", + "modified": "2025-04-21T18:32:07Z", "published": "2022-11-02T12:00:44Z", "aliases": [ "CVE-2022-42824" @@ -23,6 +23,18 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2022/11/msg00010.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5LF4LYP725XZ7RWOPFUV6DGPN4Q5DUU4" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AQKLEGJK3LHAKUQOLBHNR2DI3IUGLLTY" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JOFKX6BUEJFECSVFV6P5INQCOYQBB4NZ" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5LF4LYP725XZ7RWOPFUV6DGPN4Q5DUU4" diff --git a/advisories/unreviewed/2022/11/GHSA-mgh2-3cf4-78r5/GHSA-mgh2-3cf4-78r5.json b/advisories/unreviewed/2022/11/GHSA-mgh2-3cf4-78r5/GHSA-mgh2-3cf4-78r5.json index e799e44d5f2..ae336a4c0fa 100644 --- a/advisories/unreviewed/2022/11/GHSA-mgh2-3cf4-78r5/GHSA-mgh2-3cf4-78r5.json +++ b/advisories/unreviewed/2022/11/GHSA-mgh2-3cf4-78r5/GHSA-mgh2-3cf4-78r5.json @@ -45,7 +45,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-266" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-rjj4-r4wr-cjq8/GHSA-rjj4-r4wr-cjq8.json b/advisories/unreviewed/2022/11/GHSA-rjj4-r4wr-cjq8/GHSA-rjj4-r4wr-cjq8.json index 5fbdad40915..91bbd8389f4 100644 --- a/advisories/unreviewed/2022/11/GHSA-rjj4-r4wr-cjq8/GHSA-rjj4-r4wr-cjq8.json +++ b/advisories/unreviewed/2022/11/GHSA-rjj4-r4wr-cjq8/GHSA-rjj4-r4wr-cjq8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-rjj4-r4wr-cjq8", - "modified": "2022-11-03T19:00:29Z", + "modified": "2025-04-21T18:32:06Z", "published": "2022-11-02T12:00:44Z", "aliases": [ "CVE-2022-42823" @@ -23,6 +23,18 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2022/11/msg00010.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5LF4LYP725XZ7RWOPFUV6DGPN4Q5DUU4" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AQKLEGJK3LHAKUQOLBHNR2DI3IUGLLTY" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JOFKX6BUEJFECSVFV6P5INQCOYQBB4NZ" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5LF4LYP725XZ7RWOPFUV6DGPN4Q5DUU4" diff --git a/advisories/unreviewed/2022/12/GHSA-248j-xg68-6w85/GHSA-248j-xg68-6w85.json b/advisories/unreviewed/2022/12/GHSA-248j-xg68-6w85/GHSA-248j-xg68-6w85.json index a7677e97dec..8b09ad8140c 100644 --- a/advisories/unreviewed/2022/12/GHSA-248j-xg68-6w85/GHSA-248j-xg68-6w85.json +++ b/advisories/unreviewed/2022/12/GHSA-248j-xg68-6w85/GHSA-248j-xg68-6w85.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-248j-xg68-6w85", - "modified": "2022-12-19T21:30:28Z", + "modified": "2025-04-21T18:32:07Z", "published": "2022-12-15T21:30:29Z", "aliases": [ "CVE-2022-42842" @@ -62,10 +62,16 @@ { "type": "WEB", "url": "http://seclists.org/fulldisclosure/2022/Dec/26" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2022/Dec/27" } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-2675-54p5-24ww/GHSA-2675-54p5-24ww.json b/advisories/unreviewed/2022/12/GHSA-2675-54p5-24ww/GHSA-2675-54p5-24ww.json index 23eeac3538d..d55f92f2b6b 100644 --- a/advisories/unreviewed/2022/12/GHSA-2675-54p5-24ww/GHSA-2675-54p5-24ww.json +++ b/advisories/unreviewed/2022/12/GHSA-2675-54p5-24ww/GHSA-2675-54p5-24ww.json @@ -41,7 +41,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-693" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-4hf4-g256-gxvm/GHSA-4hf4-g256-gxvm.json b/advisories/unreviewed/2022/12/GHSA-4hf4-g256-gxvm/GHSA-4hf4-g256-gxvm.json index 77fa719b3f4..9702a98b4e0 100644 --- a/advisories/unreviewed/2022/12/GHSA-4hf4-g256-gxvm/GHSA-4hf4-g256-gxvm.json +++ b/advisories/unreviewed/2022/12/GHSA-4hf4-g256-gxvm/GHSA-4hf4-g256-gxvm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4hf4-g256-gxvm", - "modified": "2022-12-19T21:30:28Z", + "modified": "2025-04-21T18:32:07Z", "published": "2022-12-15T21:30:29Z", "aliases": [ "CVE-2022-42843" @@ -46,10 +46,15 @@ { "type": "WEB", "url": "http://seclists.org/fulldisclosure/2022/Dec/26" + }, + { + "type": "WEB", + "url": "http://seclists.org/fulldisclosure/2022/Dec/27" } ], "database_specific": { "cwe_ids": [ + "CWE-200", "CWE-668" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/12/GHSA-62ff-q4g6-fj3j/GHSA-62ff-q4g6-fj3j.json b/advisories/unreviewed/2022/12/GHSA-62ff-q4g6-fj3j/GHSA-62ff-q4g6-fj3j.json index bb5a9c33396..79096e28bcf 100644 --- a/advisories/unreviewed/2022/12/GHSA-62ff-q4g6-fj3j/GHSA-62ff-q4g6-fj3j.json +++ b/advisories/unreviewed/2022/12/GHSA-62ff-q4g6-fj3j/GHSA-62ff-q4g6-fj3j.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/12/GHSA-6385-g25r-xp83/GHSA-6385-g25r-xp83.json b/advisories/unreviewed/2022/12/GHSA-6385-g25r-xp83/GHSA-6385-g25r-xp83.json index 9fdd651a9f0..aa999a82ffe 100644 --- a/advisories/unreviewed/2022/12/GHSA-6385-g25r-xp83/GHSA-6385-g25r-xp83.json +++ b/advisories/unreviewed/2022/12/GHSA-6385-g25r-xp83/GHSA-6385-g25r-xp83.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/12/GHSA-cj65-9hr7-j38f/GHSA-cj65-9hr7-j38f.json b/advisories/unreviewed/2022/12/GHSA-cj65-9hr7-j38f/GHSA-cj65-9hr7-j38f.json index 381b444ebb2..82a5f877a18 100644 --- a/advisories/unreviewed/2022/12/GHSA-cj65-9hr7-j38f/GHSA-cj65-9hr7-j38f.json +++ b/advisories/unreviewed/2022/12/GHSA-cj65-9hr7-j38f/GHSA-cj65-9hr7-j38f.json @@ -61,7 +61,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-f52r-6pr7-vmv3/GHSA-f52r-6pr7-vmv3.json b/advisories/unreviewed/2022/12/GHSA-f52r-6pr7-vmv3/GHSA-f52r-6pr7-vmv3.json index 2d7b2337f38..50ba711a2fd 100644 --- a/advisories/unreviewed/2022/12/GHSA-f52r-6pr7-vmv3/GHSA-f52r-6pr7-vmv3.json +++ b/advisories/unreviewed/2022/12/GHSA-f52r-6pr7-vmv3/GHSA-f52r-6pr7-vmv3.json @@ -45,7 +45,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-125" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-h72x-r663-chxx/GHSA-h72x-r663-chxx.json b/advisories/unreviewed/2022/12/GHSA-h72x-r663-chxx/GHSA-h72x-r663-chxx.json index 87d044285e6..73f8cd5f13b 100644 --- a/advisories/unreviewed/2022/12/GHSA-h72x-r663-chxx/GHSA-h72x-r663-chxx.json +++ b/advisories/unreviewed/2022/12/GHSA-h72x-r663-chxx/GHSA-h72x-r663-chxx.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-125" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-j58x-47c8-gq4h/GHSA-j58x-47c8-gq4h.json b/advisories/unreviewed/2022/12/GHSA-j58x-47c8-gq4h/GHSA-j58x-47c8-gq4h.json index 8b651d4f8c6..f1a746edaaa 100644 --- a/advisories/unreviewed/2022/12/GHSA-j58x-47c8-gq4h/GHSA-j58x-47c8-gq4h.json +++ b/advisories/unreviewed/2022/12/GHSA-j58x-47c8-gq4h/GHSA-j58x-47c8-gq4h.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-119" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-m5c8-qvmj-6h85/GHSA-m5c8-qvmj-6h85.json b/advisories/unreviewed/2022/12/GHSA-m5c8-qvmj-6h85/GHSA-m5c8-qvmj-6h85.json index 87fd7665e58..3a0f1ad02d5 100644 --- a/advisories/unreviewed/2022/12/GHSA-m5c8-qvmj-6h85/GHSA-m5c8-qvmj-6h85.json +++ b/advisories/unreviewed/2022/12/GHSA-m5c8-qvmj-6h85/GHSA-m5c8-qvmj-6h85.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-qg7p-gqjj-g2r8/GHSA-qg7p-gqjj-g2r8.json b/advisories/unreviewed/2022/12/GHSA-qg7p-gqjj-g2r8/GHSA-qg7p-gqjj-g2r8.json index 7ca75060878..049713ed879 100644 --- a/advisories/unreviewed/2022/12/GHSA-qg7p-gqjj-g2r8/GHSA-qg7p-gqjj-g2r8.json +++ b/advisories/unreviewed/2022/12/GHSA-qg7p-gqjj-g2r8/GHSA-qg7p-gqjj-g2r8.json @@ -57,7 +57,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-20" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-rg9c-336x-3rq5/GHSA-rg9c-336x-3rq5.json b/advisories/unreviewed/2022/12/GHSA-rg9c-336x-3rq5/GHSA-rg9c-336x-3rq5.json index 9828aaa78b0..3ac7808812d 100644 --- a/advisories/unreviewed/2022/12/GHSA-rg9c-336x-3rq5/GHSA-rg9c-336x-3rq5.json +++ b/advisories/unreviewed/2022/12/GHSA-rg9c-336x-3rq5/GHSA-rg9c-336x-3rq5.json @@ -69,7 +69,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-269" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-wrh9-jf24-cgwp/GHSA-wrh9-jf24-cgwp.json b/advisories/unreviewed/2022/12/GHSA-wrh9-jf24-cgwp/GHSA-wrh9-jf24-cgwp.json index 057146a0c74..33436c60616 100644 --- a/advisories/unreviewed/2022/12/GHSA-wrh9-jf24-cgwp/GHSA-wrh9-jf24-cgwp.json +++ b/advisories/unreviewed/2022/12/GHSA-wrh9-jf24-cgwp/GHSA-wrh9-jf24-cgwp.json @@ -53,7 +53,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-xh54-7xjp-2239/GHSA-xh54-7xjp-2239.json b/advisories/unreviewed/2022/12/GHSA-xh54-7xjp-2239/GHSA-xh54-7xjp-2239.json index 08746ac4a70..779ab9d99dd 100644 --- a/advisories/unreviewed/2022/12/GHSA-xh54-7xjp-2239/GHSA-xh54-7xjp-2239.json +++ b/advisories/unreviewed/2022/12/GHSA-xh54-7xjp-2239/GHSA-xh54-7xjp-2239.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-284", "CWE-863" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/12/GHSA-vjhq-xqvq-7gh3/GHSA-vjhq-xqvq-7gh3.json b/advisories/unreviewed/2024/12/GHSA-vjhq-xqvq-7gh3/GHSA-vjhq-xqvq-7gh3.json index a2d18b4769c..efeaec1da9e 100644 --- a/advisories/unreviewed/2024/12/GHSA-vjhq-xqvq-7gh3/GHSA-vjhq-xqvq-7gh3.json +++ b/advisories/unreviewed/2024/12/GHSA-vjhq-xqvq-7gh3/GHSA-vjhq-xqvq-7gh3.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-79", "CWE-80" ], "severity": "LOW", diff --git a/advisories/unreviewed/2025/01/GHSA-8p2p-qc6p-2hr2/GHSA-8p2p-qc6p-2hr2.json b/advisories/unreviewed/2025/01/GHSA-8p2p-qc6p-2hr2/GHSA-8p2p-qc6p-2hr2.json index 9a5672759c3..adc6f01da1c 100644 --- a/advisories/unreviewed/2025/01/GHSA-8p2p-qc6p-2hr2/GHSA-8p2p-qc6p-2hr2.json +++ b/advisories/unreviewed/2025/01/GHSA-8p2p-qc6p-2hr2/GHSA-8p2p-qc6p-2hr2.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-2823-wfgm-j3hr/GHSA-2823-wfgm-j3hr.json b/advisories/unreviewed/2025/04/GHSA-2823-wfgm-j3hr/GHSA-2823-wfgm-j3hr.json new file mode 100644 index 00000000000..d67c92db84a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2823-wfgm-j3hr/GHSA-2823-wfgm-j3hr.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2823-wfgm-j3hr", + "modified": "2025-04-21T18:32:09Z", + "published": "2025-04-21T18:32:09Z", + "aliases": [ + "CVE-2025-29446" + ], + "details": "open-webui v0.5.16 is vulnerable to SSRF in routers/ollama.py in function verify_connection.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29446" + }, + { + "type": "WEB", + "url": "https://github.com/jcxj/jcxj/blob/master/source/_posts/open-webui-ssrf%E6%BC%8F%E6%B4%9E.md" + }, + { + "type": "WEB", + "url": "https://github.com/l1uyi/cve-list/blob/main/cve-list/open-webui-ssrf.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-21T17:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-3ph3-5vg6-324h/GHSA-3ph3-5vg6-324h.json b/advisories/unreviewed/2025/04/GHSA-3ph3-5vg6-324h/GHSA-3ph3-5vg6-324h.json index 210bea02a3b..5b7a4051c30 100644 --- a/advisories/unreviewed/2025/04/GHSA-3ph3-5vg6-324h/GHSA-3ph3-5vg6-324h.json +++ b/advisories/unreviewed/2025/04/GHSA-3ph3-5vg6-324h/GHSA-3ph3-5vg6-324h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3ph3-5vg6-324h", - "modified": "2025-04-21T15:31:23Z", + "modified": "2025-04-21T18:32:08Z", "published": "2025-04-21T15:31:23Z", "aliases": [ "CVE-2025-32408" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://bookstack.soffid.com/books/security-advisories/page/cve-2024-39669" + }, + { + "type": "WEB", + "url": "https://bookstack.soffid.com/books/security-advisories/page/cve-2025-32408" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/04/GHSA-4528-h42g-x3c7/GHSA-4528-h42g-x3c7.json b/advisories/unreviewed/2025/04/GHSA-4528-h42g-x3c7/GHSA-4528-h42g-x3c7.json new file mode 100644 index 00000000000..498531120bd --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-4528-h42g-x3c7/GHSA-4528-h42g-x3c7.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4528-h42g-x3c7", + "modified": "2025-04-21T18:32:09Z", + "published": "2025-04-21T18:32:09Z", + "aliases": [ + "CVE-2025-27086" + ], + "details": "Vulnerability in Hewlett Packard Enterprise HPE Performance Cluster Manager (HPCM).This issue affects HPE Performance Cluster Manager (HPCM): through 1.12.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27086" + }, + { + "type": "WEB", + "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbcr04842en_us&docLocale=en_US" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-21T18:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5fjr-xr2p-8c46/GHSA-5fjr-xr2p-8c46.json b/advisories/unreviewed/2025/04/GHSA-5fjr-xr2p-8c46/GHSA-5fjr-xr2p-8c46.json new file mode 100644 index 00000000000..b472e202f75 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5fjr-xr2p-8c46/GHSA-5fjr-xr2p-8c46.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5fjr-xr2p-8c46", + "modified": "2025-04-21T18:32:09Z", + "published": "2025-04-21T18:32:09Z", + "aliases": [ + "CVE-2025-28099" + ], + "details": "opencms V2.3 is vulnerable to Arbitrary file read in src/main/webapp/view/admin/document/dataPage.jsp,", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28099" + }, + { + "type": "WEB", + "url": "https://gist.github.com/kaoniniang2/e159346725f50d6c44c82214970f02b8" + }, + { + "type": "WEB", + "url": "https://gitee.com/fumiao/opencms/issues/IBLJLM" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-21T17:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5vf8-pp4v-ccv9/GHSA-5vf8-pp4v-ccv9.json b/advisories/unreviewed/2025/04/GHSA-5vf8-pp4v-ccv9/GHSA-5vf8-pp4v-ccv9.json index 76d7b40d92d..3f23154a60a 100644 --- a/advisories/unreviewed/2025/04/GHSA-5vf8-pp4v-ccv9/GHSA-5vf8-pp4v-ccv9.json +++ b/advisories/unreviewed/2025/04/GHSA-5vf8-pp4v-ccv9/GHSA-5vf8-pp4v-ccv9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5vf8-pp4v-ccv9", - "modified": "2025-04-18T00:30:43Z", + "modified": "2025-04-21T18:32:08Z", "published": "2025-04-18T00:30:43Z", "aliases": [ "CVE-2025-29453" ], "details": "An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the my-contacts-settings component.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-17T22:15:14Z" diff --git a/advisories/unreviewed/2025/04/GHSA-743f-hxpg-f2rj/GHSA-743f-hxpg-f2rj.json b/advisories/unreviewed/2025/04/GHSA-743f-hxpg-f2rj/GHSA-743f-hxpg-f2rj.json new file mode 100644 index 00000000000..d582a184755 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-743f-hxpg-f2rj/GHSA-743f-hxpg-f2rj.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-743f-hxpg-f2rj", + "modified": "2025-04-21T18:32:09Z", + "published": "2025-04-21T18:32:09Z", + "aliases": [ + "CVE-2025-28102" + ], + "details": "A cross-site scripting (XSS) vulnerability in flaskBlog v2.6.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the postContent parameter at /createpost.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28102" + }, + { + "type": "WEB", + "url": "https://github.com/DogukanUrker/flaskBlog/issues/130" + }, + { + "type": "WEB", + "url": "https://gist.github.com/coleak2021/edbd6e0766227ee96a7a4601e50773eb" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-21T17:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-87v4-c5h4-88xg/GHSA-87v4-c5h4-88xg.json b/advisories/unreviewed/2025/04/GHSA-87v4-c5h4-88xg/GHSA-87v4-c5h4-88xg.json new file mode 100644 index 00000000000..a349358ea9c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-87v4-c5h4-88xg/GHSA-87v4-c5h4-88xg.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-87v4-c5h4-88xg", + "modified": "2025-04-21T18:32:09Z", + "published": "2025-04-21T18:32:09Z", + "aliases": [ + "CVE-2025-28103" + ], + "details": "Incorrect access control in laskBlog v2.6.1 allows attackers to arbitrarily delete user accounts via a crafted request.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28103" + }, + { + "type": "WEB", + "url": "https://github.com/DogukanUrker/flaskBlog/issues/130" + }, + { + "type": "WEB", + "url": "https://gist.github.com/coleak2021/77895b7a7b335ae17eb57390f4a94917" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-21T18:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8rrr-w669-26rg/GHSA-8rrr-w669-26rg.json b/advisories/unreviewed/2025/04/GHSA-8rrr-w669-26rg/GHSA-8rrr-w669-26rg.json index 96266ea71de..ddbffa46d82 100644 --- a/advisories/unreviewed/2025/04/GHSA-8rrr-w669-26rg/GHSA-8rrr-w669-26rg.json +++ b/advisories/unreviewed/2025/04/GHSA-8rrr-w669-26rg/GHSA-8rrr-w669-26rg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8rrr-w669-26rg", - "modified": "2025-04-17T21:31:05Z", + "modified": "2025-04-21T18:32:08Z", "published": "2025-04-17T21:31:05Z", "aliases": [ "CVE-2025-29454" ], "details": "An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the Upload function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-17T21:15:50Z" diff --git a/advisories/unreviewed/2025/04/GHSA-f8h6-w72c-c28q/GHSA-f8h6-w72c-c28q.json b/advisories/unreviewed/2025/04/GHSA-f8h6-w72c-c28q/GHSA-f8h6-w72c-c28q.json new file mode 100644 index 00000000000..c2973565afc --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-f8h6-w72c-c28q/GHSA-f8h6-w72c-c28q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f8h6-w72c-c28q", + "modified": "2025-04-21T18:32:09Z", + "published": "2025-04-21T18:32:09Z", + "aliases": [ + "CVE-2025-23174" + ], + "details": "CWE-200: Exposure of Sensitive Information to an Unauthorized Actor", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23174" + }, + { + "type": "WEB", + "url": "https://www.gov.il/en/departments/dynamiccollectors/cve_advisories_listing?skip=0" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-21T17:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-j6gw-77pg-859q/GHSA-j6gw-77pg-859q.json b/advisories/unreviewed/2025/04/GHSA-j6gw-77pg-859q/GHSA-j6gw-77pg-859q.json new file mode 100644 index 00000000000..32909d39ba1 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-j6gw-77pg-859q/GHSA-j6gw-77pg-859q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j6gw-77pg-859q", + "modified": "2025-04-21T18:32:09Z", + "published": "2025-04-21T18:32:09Z", + "aliases": [ + "CVE-2025-43922" + ], + "details": "The FileWave Windows client before 16.0.0, in some non-default configurations, allows an unprivileged local user to escalate privileges to SYSTEM.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-43922" + }, + { + "type": "WEB", + "url": "https://kb.filewave.com/books/downloads/page/filewave-version-1603" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-21T16:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-mh2f-2hrx-5245/GHSA-mh2f-2hrx-5245.json b/advisories/unreviewed/2025/04/GHSA-mh2f-2hrx-5245/GHSA-mh2f-2hrx-5245.json new file mode 100644 index 00000000000..3431cc9f466 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-mh2f-2hrx-5245/GHSA-mh2f-2hrx-5245.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mh2f-2hrx-5245", + "modified": "2025-04-21T18:32:08Z", + "published": "2025-04-21T18:32:08Z", + "aliases": [ + "CVE-2024-12543" + ], + "details": "User Enumeration and Data Integrity in Barcode functionality in OpenText Content Management versions 24.3-25.1on Windows and Linux allows a malicous authenticated attacker to potentially alter barcode attributes.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12543" + }, + { + "type": "WEB", + "url": "https://support.opentext.com/csm?id=ot_kb_unauthenticated&sysparm_article=KB0839119" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-841" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-21T16:15:53Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-pmgr-28ph-jhmm/GHSA-pmgr-28ph-jhmm.json b/advisories/unreviewed/2025/04/GHSA-pmgr-28ph-jhmm/GHSA-pmgr-28ph-jhmm.json index 2f17e94910b..714da7dd017 100644 --- a/advisories/unreviewed/2025/04/GHSA-pmgr-28ph-jhmm/GHSA-pmgr-28ph-jhmm.json +++ b/advisories/unreviewed/2025/04/GHSA-pmgr-28ph-jhmm/GHSA-pmgr-28ph-jhmm.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-pmgr-28ph-jhmm", - "modified": "2025-04-18T00:30:43Z", + "modified": "2025-04-21T18:32:08Z", "published": "2025-04-18T00:30:43Z", "aliases": [ "CVE-2025-29456" ], "details": "An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the create Notes function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-17T22:15:15Z" diff --git a/advisories/unreviewed/2025/04/GHSA-q332-7cfx-q6r5/GHSA-q332-7cfx-q6r5.json b/advisories/unreviewed/2025/04/GHSA-q332-7cfx-q6r5/GHSA-q332-7cfx-q6r5.json new file mode 100644 index 00000000000..04f9d4e926e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-q332-7cfx-q6r5/GHSA-q332-7cfx-q6r5.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q332-7cfx-q6r5", + "modified": "2025-04-21T18:32:09Z", + "published": "2025-04-21T18:32:08Z", + "aliases": [ + "CVE-2025-28367" + ], + "details": "mojoPortal <=2.9.0.1 is vulnerable to Directory Traversal via BetterImageGallery API Controller - ImageHandler Action. An attacker can exploit this vulnerability to access the Web.Config file and obtain the MachineKey.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28367" + }, + { + "type": "WEB", + "url": "https://github.com/i7MEDIA/mojoportal" + }, + { + "type": "WEB", + "url": "https://www.0xlanks.me/blog/cve-2025-28367-advisory" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-21T16:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-rfhg-52gw-r6hv/GHSA-rfhg-52gw-r6hv.json b/advisories/unreviewed/2025/04/GHSA-rfhg-52gw-r6hv/GHSA-rfhg-52gw-r6hv.json new file mode 100644 index 00000000000..b34a58c14c6 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-rfhg-52gw-r6hv/GHSA-rfhg-52gw-r6hv.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rfhg-52gw-r6hv", + "modified": "2025-04-21T18:32:09Z", + "published": "2025-04-21T18:32:09Z", + "aliases": [ + "CVE-2025-28104" + ], + "details": "Incorrect access control in laskBlog v2.6.1 allows attackers to access all usernames via a crafted input.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-28104" + }, + { + "type": "WEB", + "url": "https://github.com/DogukanUrker/flaskBlog/issues/130" + }, + { + "type": "WEB", + "url": "https://gist.github.com/coleak2021/d5fea0f7d32a2de38130da089f4fb735" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-21T18:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-v4fw-ww7x-63fp/GHSA-v4fw-ww7x-63fp.json b/advisories/unreviewed/2025/04/GHSA-v4fw-ww7x-63fp/GHSA-v4fw-ww7x-63fp.json new file mode 100644 index 00000000000..cc2b9d12ff7 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-v4fw-ww7x-63fp/GHSA-v4fw-ww7x-63fp.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v4fw-ww7x-63fp", + "modified": "2025-04-21T18:32:09Z", + "published": "2025-04-21T18:32:09Z", + "aliases": [ + "CVE-2024-57394" + ], + "details": "The quarantine - restore function in Qi-ANXIN Tianqing Endpoint Security Management System v10.0 allows user to restore a malicious file to an arbitrary file path. Attackers can write malicious DLL to system path and perform privilege escalation by leveraging Windows DLL hijacking vulnerabilities.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57394" + }, + { + "type": "WEB", + "url": "https://en.qianxin.com/product/detail/165" + }, + { + "type": "WEB", + "url": "https://github.com/cwjchoi01/CVE-2024-57394" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-21T18:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-xw3g-f28m-3q7j/GHSA-xw3g-f28m-3q7j.json b/advisories/unreviewed/2025/04/GHSA-xw3g-f28m-3q7j/GHSA-xw3g-f28m-3q7j.json index ecc20720b24..ca737feb84c 100644 --- a/advisories/unreviewed/2025/04/GHSA-xw3g-f28m-3q7j/GHSA-xw3g-f28m-3q7j.json +++ b/advisories/unreviewed/2025/04/GHSA-xw3g-f28m-3q7j/GHSA-xw3g-f28m-3q7j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xw3g-f28m-3q7j", - "modified": "2025-04-17T21:31:05Z", + "modified": "2025-04-21T18:32:08Z", "published": "2025-04-17T21:31:05Z", "aliases": [ "CVE-2025-29455" ], "details": "An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive information via the Travel Ideas\" function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-17T21:15:50Z"