diff --git a/advisories/github-reviewed/2025/04/GHSA-75v8-2h7p-7m2m/GHSA-75v8-2h7p-7m2m.json b/advisories/github-reviewed/2025/04/GHSA-75v8-2h7p-7m2m/GHSA-75v8-2h7p-7m2m.json index 917b66a2608..d41d07402bc 100644 --- a/advisories/github-reviewed/2025/04/GHSA-75v8-2h7p-7m2m/GHSA-75v8-2h7p-7m2m.json +++ b/advisories/github-reviewed/2025/04/GHSA-75v8-2h7p-7m2m/GHSA-75v8-2h7p-7m2m.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-75v8-2h7p-7m2m", - "modified": "2025-04-30T21:07:20Z", + "modified": "2025-05-27T18:49:20Z", "published": "2025-04-26T21:31:26Z", "aliases": [ "CVE-2025-46653" ], "summary": "Formidable relies on hexoid to prevent guessing of filenames for untrusted executable content", - "details": "Formidable (aka node-formidable) 2.1.0 through 3.x before 3.5.3 relies on hexoid to prevent guessing of filenames for untrusted executable content; however, hexoid is documented as not \"cryptographically secure.\" (Also, there is a scenario in which only the last two characters of a hexoid string need to be guessed, but this is not often relevant.) NOTE: this does not imply that, in a typical use case, attackers will be able to exploit any hexoid behavior to upload and execute their own content.", + "details": "Formidable (aka node-formidable) 2.x before 2.1.3 and 3.x before 3.5.3 relies on hexoid to prevent guessing of filenames for untrusted executable content; however, hexoid is documented as not \"cryptographically secure.\" (Also, there is a scenario in which only the last two characters of a hexoid string need to be guessed, but this is not often relevant.) NOTE: this does not imply that, in a typical use case, attackers will be able to exploit any hexoid behavior to upload and execute their own content.", "severity": [ { "type": "CVSS_V3", @@ -45,13 +45,13 @@ "events": [ { "introduced": "2.1.0" + }, + { + "fixed": "2.1.3" } ] } - ], - "database_specific": { - "last_known_affected_version_range": "< 2.1.3" - } + ] } ], "references": [ @@ -78,6 +78,14 @@ { "type": "WEB", "url": "https://github.com/zast-ai/vulnerability-reports/blob/main/formidable/file_upload/report.md" + }, + { + "type": "WEB", + "url": "https://www.npmjs.com/package/formidable/v/2.1.3" + }, + { + "type": "WEB", + "url": "https://www.npmjs.com/package/formidable/v/3.5.3" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/05/GHSA-cm3g-qm4h-xm6m/GHSA-cm3g-qm4h-xm6m.json b/advisories/github-reviewed/2025/05/GHSA-cm3g-qm4h-xm6m/GHSA-cm3g-qm4h-xm6m.json similarity index 58% rename from advisories/unreviewed/2025/05/GHSA-cm3g-qm4h-xm6m/GHSA-cm3g-qm4h-xm6m.json rename to advisories/github-reviewed/2025/05/GHSA-cm3g-qm4h-xm6m/GHSA-cm3g-qm4h-xm6m.json index c9d7067257f..0b17132bcbf 100644 --- a/advisories/unreviewed/2025/05/GHSA-cm3g-qm4h-xm6m/GHSA-cm3g-qm4h-xm6m.json +++ b/advisories/github-reviewed/2025/05/GHSA-cm3g-qm4h-xm6m/GHSA-cm3g-qm4h-xm6m.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-cm3g-qm4h-xm6m", - "modified": "2025-05-24T03:30:19Z", + "modified": "2025-05-27T18:52:08Z", "published": "2025-05-24T03:30:19Z", "aliases": [ "CVE-2025-48756" ], + "summary": "SCSIR has a Potential Unsound Issue in WriteSameCommand", "details": "In group_number in the scsir crate 0.2.0 for Rust, there can be an overflow because a hardware device may expect a small number of bits (e.g., 5 bits) for group number.", "severity": [ { @@ -13,7 +14,27 @@ "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L" } ], - "affected": [], + "affected": [ + { + "package": { + "ecosystem": "crates.io", + "name": "scsir" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "0.2.0" + } + ] + } + ] + } + ], "references": [ { "type": "ADVISORY", @@ -26,6 +47,10 @@ { "type": "WEB", "url": "https://crates.io/crates/scsir" + }, + { + "type": "PACKAGE", + "url": "https://github.com/maboroshinokiseki/scsir" } ], "database_specific": { @@ -33,8 +58,8 @@ "CWE-843" ], "severity": "LOW", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2025-05-27T18:52:08Z", "nvd_published_at": "2025-05-24T03:15:24Z" } } \ No newline at end of file