From 9bffd9721a6769fea96c90918ad7b133198635d8 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 9 Apr 2025 20:15:31 +0000 Subject: [PATCH] Publish Advisories GHSA-4w26-8p97-f4jp GHSA-h33q-mhmp-8p67 GHSA-2hmp-5wqg-f24h GHSA-7q5r-7gvp-wc82 GHSA-w4rh-fgx7-q63m GHSA-w8jq-xcqf-f792 GHSA-3f7v-qx94-666m GHSA-7v4r-c989-xh26 --- .../02/GHSA-4w26-8p97-f4jp/GHSA-4w26-8p97-f4jp.json | 6 +++++- .../02/GHSA-h33q-mhmp-8p67/GHSA-h33q-mhmp-8p67.json | 6 +++++- .../03/GHSA-2hmp-5wqg-f24h/GHSA-2hmp-5wqg-f24h.json | 6 +++++- .../03/GHSA-7q5r-7gvp-wc82/GHSA-7q5r-7gvp-wc82.json | 6 +++++- .../03/GHSA-w4rh-fgx7-q63m/GHSA-w4rh-fgx7-q63m.json | 6 +++++- .../03/GHSA-w8jq-xcqf-f792/GHSA-w8jq-xcqf-f792.json | 6 +++++- .../04/GHSA-3f7v-qx94-666m/GHSA-3f7v-qx94-666m.json | 12 ++++++++++-- .../04/GHSA-7v4r-c989-xh26/GHSA-7v4r-c989-xh26.json | 8 ++++++-- 8 files changed, 46 insertions(+), 10 deletions(-) diff --git a/advisories/github-reviewed/2025/02/GHSA-4w26-8p97-f4jp/GHSA-4w26-8p97-f4jp.json b/advisories/github-reviewed/2025/02/GHSA-4w26-8p97-f4jp/GHSA-4w26-8p97-f4jp.json index ce116d089df..2a046c6bd48 100644 --- a/advisories/github-reviewed/2025/02/GHSA-4w26-8p97-f4jp/GHSA-4w26-8p97-f4jp.json +++ b/advisories/github-reviewed/2025/02/GHSA-4w26-8p97-f4jp/GHSA-4w26-8p97-f4jp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4w26-8p97-f4jp", - "modified": "2025-02-24T20:25:09Z", + "modified": "2025-04-09T20:14:00Z", "published": "2025-02-21T22:43:33Z", "aliases": [ "CVE-2025-27105" @@ -47,6 +47,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27105" }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/vyper/PYSEC-2025-31.yaml" + }, { "type": "PACKAGE", "url": "https://github.com/vyperlang/vyper" diff --git a/advisories/github-reviewed/2025/02/GHSA-h33q-mhmp-8p67/GHSA-h33q-mhmp-8p67.json b/advisories/github-reviewed/2025/02/GHSA-h33q-mhmp-8p67/GHSA-h33q-mhmp-8p67.json index 0372c269f8c..279db313112 100644 --- a/advisories/github-reviewed/2025/02/GHSA-h33q-mhmp-8p67/GHSA-h33q-mhmp-8p67.json +++ b/advisories/github-reviewed/2025/02/GHSA-h33q-mhmp-8p67/GHSA-h33q-mhmp-8p67.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h33q-mhmp-8p67", - "modified": "2025-02-24T20:26:22Z", + "modified": "2025-04-09T20:12:39Z", "published": "2025-02-21T22:43:36Z", "aliases": [ "CVE-2025-27104" @@ -51,6 +51,10 @@ "type": "WEB", "url": "https://github.com/vyperlang/vyper/pull/4488" }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/vyper/PYSEC-2025-30.yaml" + }, { "type": "PACKAGE", "url": "https://github.com/vyperlang/vyper" diff --git a/advisories/github-reviewed/2025/03/GHSA-2hmp-5wqg-f24h/GHSA-2hmp-5wqg-f24h.json b/advisories/github-reviewed/2025/03/GHSA-2hmp-5wqg-f24h/GHSA-2hmp-5wqg-f24h.json index d1bb9901af4..7f9c00e3caa 100644 --- a/advisories/github-reviewed/2025/03/GHSA-2hmp-5wqg-f24h/GHSA-2hmp-5wqg-f24h.json +++ b/advisories/github-reviewed/2025/03/GHSA-2hmp-5wqg-f24h/GHSA-2hmp-5wqg-f24h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2hmp-5wqg-f24h", - "modified": "2025-03-24T21:46:52Z", + "modified": "2025-04-09T20:13:47Z", "published": "2025-03-10T15:30:47Z", "aliases": [ "CVE-2025-1497" @@ -59,6 +59,10 @@ { "type": "PACKAGE", "url": "https://github.com/mljar/plotai" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/plotai/PYSEC-2025-22.yaml" } ], "database_specific": { diff --git a/advisories/github-reviewed/2025/03/GHSA-7q5r-7gvp-wc82/GHSA-7q5r-7gvp-wc82.json b/advisories/github-reviewed/2025/03/GHSA-7q5r-7gvp-wc82/GHSA-7q5r-7gvp-wc82.json index 5bb1b77bafa..d9b952dfb4a 100644 --- a/advisories/github-reviewed/2025/03/GHSA-7q5r-7gvp-wc82/GHSA-7q5r-7gvp-wc82.json +++ b/advisories/github-reviewed/2025/03/GHSA-7q5r-7gvp-wc82/GHSA-7q5r-7gvp-wc82.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7q5r-7gvp-wc82", - "modified": "2025-03-20T19:18:35Z", + "modified": "2025-04-09T20:13:35Z", "published": "2025-03-10T18:26:44Z", "aliases": [ "CVE-2025-1944" @@ -56,6 +56,10 @@ "type": "PACKAGE", "url": "https://github.com/mmaitre314/picklescan" }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/picklescan/PYSEC-2025-20.yaml" + }, { "type": "WEB", "url": "https://sites.google.com/sonatype.com/vulnerabilities/cve-2025-1944" diff --git a/advisories/github-reviewed/2025/03/GHSA-w4rh-fgx7-q63m/GHSA-w4rh-fgx7-q63m.json b/advisories/github-reviewed/2025/03/GHSA-w4rh-fgx7-q63m/GHSA-w4rh-fgx7-q63m.json index 882a109b6ff..56dc6fb0290 100644 --- a/advisories/github-reviewed/2025/03/GHSA-w4rh-fgx7-q63m/GHSA-w4rh-fgx7-q63m.json +++ b/advisories/github-reviewed/2025/03/GHSA-w4rh-fgx7-q63m/GHSA-w4rh-fgx7-q63m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w4rh-fgx7-q63m", - "modified": "2025-03-06T22:31:54Z", + "modified": "2025-04-09T20:12:59Z", "published": "2025-03-06T06:30:52Z", "aliases": [ "CVE-2025-1979" @@ -56,6 +56,10 @@ "type": "WEB", "url": "https://github.com/ray-project/ray/commit/64a2e4010522d60b90c389634f24df77b603d85d" }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/ray/PYSEC-2025-23.yaml" + }, { "type": "PACKAGE", "url": "https://github.com/ray-project/ray" diff --git a/advisories/github-reviewed/2025/03/GHSA-w8jq-xcqf-f792/GHSA-w8jq-xcqf-f792.json b/advisories/github-reviewed/2025/03/GHSA-w8jq-xcqf-f792/GHSA-w8jq-xcqf-f792.json index a9a58866d7c..53d8129affd 100644 --- a/advisories/github-reviewed/2025/03/GHSA-w8jq-xcqf-f792/GHSA-w8jq-xcqf-f792.json +++ b/advisories/github-reviewed/2025/03/GHSA-w8jq-xcqf-f792/GHSA-w8jq-xcqf-f792.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w8jq-xcqf-f792", - "modified": "2025-03-10T18:26:35Z", + "modified": "2025-04-09T20:13:19Z", "published": "2025-03-10T18:26:35Z", "aliases": [ "CVE-2025-1945" @@ -52,6 +52,10 @@ "type": "PACKAGE", "url": "https://github.com/mmaitre314/picklescan" }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/picklescan/PYSEC-2025-21.yaml" + }, { "type": "WEB", "url": "https://sites.google.com/sonatype.com/vulnerabilities/cve-2025-1945" diff --git a/advisories/github-reviewed/2025/04/GHSA-3f7v-qx94-666m/GHSA-3f7v-qx94-666m.json b/advisories/github-reviewed/2025/04/GHSA-3f7v-qx94-666m/GHSA-3f7v-qx94-666m.json index ff55e28650f..03f7ad87a51 100644 --- a/advisories/github-reviewed/2025/04/GHSA-3f7v-qx94-666m/GHSA-3f7v-qx94-666m.json +++ b/advisories/github-reviewed/2025/04/GHSA-3f7v-qx94-666m/GHSA-3f7v-qx94-666m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3f7v-qx94-666m", - "modified": "2025-04-09T12:58:28Z", + "modified": "2025-04-09T20:14:12Z", "published": "2025-04-09T12:58:28Z", "aliases": [ "CVE-2025-32372" @@ -40,6 +40,14 @@ "type": "WEB", "url": "https://github.com/dnnsoftware/Dnn.Platform/security/advisories/GHSA-3f7v-qx94-666m" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32372" + }, + { + "type": "WEB", + "url": "https://github.com/dnnsoftware/Dnn.Platform/commit/4721dd9eef846936d3b1a3676499e46968d15feb" + }, { "type": "PACKAGE", "url": "https://github.com/dnnsoftware/Dnn.Platform" @@ -52,6 +60,6 @@ "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2025-04-09T12:58:28Z", - "nvd_published_at": null + "nvd_published_at": "2025-04-09T16:15:25Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2025/04/GHSA-7v4r-c989-xh26/GHSA-7v4r-c989-xh26.json b/advisories/github-reviewed/2025/04/GHSA-7v4r-c989-xh26/GHSA-7v4r-c989-xh26.json index cd3c89fb217..e349de7ae3b 100644 --- a/advisories/github-reviewed/2025/04/GHSA-7v4r-c989-xh26/GHSA-7v4r-c989-xh26.json +++ b/advisories/github-reviewed/2025/04/GHSA-7v4r-c989-xh26/GHSA-7v4r-c989-xh26.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7v4r-c989-xh26", - "modified": "2025-04-09T12:59:45Z", + "modified": "2025-04-09T20:14:20Z", "published": "2025-04-09T12:59:45Z", "aliases": [ "CVE-2025-32375" @@ -40,6 +40,10 @@ "type": "WEB", "url": "https://github.com/bentoml/BentoML/security/advisories/GHSA-7v4r-c989-xh26" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32375" + }, { "type": "PACKAGE", "url": "https://github.com/bentoml/BentoML" @@ -52,6 +56,6 @@ "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2025-04-09T12:59:45Z", - "nvd_published_at": null + "nvd_published_at": "2025-04-09T16:15:25Z" } } \ No newline at end of file