diff --git a/advisories/unreviewed/2025/04/GHSA-p999-j4hq-pmj3/GHSA-p999-j4hq-pmj3.json b/advisories/unreviewed/2025/04/GHSA-p999-j4hq-pmj3/GHSA-p999-j4hq-pmj3.json new file mode 100644 index 00000000000..909f196bb93 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-p999-j4hq-pmj3/GHSA-p999-j4hq-pmj3.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p999-j4hq-pmj3", + "modified": "2025-04-09T00:30:27Z", + "published": "2025-04-09T00:30:27Z", + "aliases": [ + "CVE-2025-25013" + ], + "details": "Improper restriction of environment variables in Elastic Defend can lead to exposure of sensitive information such as API keys and tokens via automatic transmission of unfiltered environment variables to the stack.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25013" + }, + { + "type": "WEB", + "url": "https://discuss.elastic.co/t/elastic-defend-8-17-3-security-update-esa-2025-05/376921" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-08T23:15:45Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vv22-vwq7-hqwj/GHSA-vv22-vwq7-hqwj.json b/advisories/unreviewed/2025/04/GHSA-vv22-vwq7-hqwj/GHSA-vv22-vwq7-hqwj.json index 8e51a184134..da5f59b6a57 100644 --- a/advisories/unreviewed/2025/04/GHSA-vv22-vwq7-hqwj/GHSA-vv22-vwq7-hqwj.json +++ b/advisories/unreviewed/2025/04/GHSA-vv22-vwq7-hqwj/GHSA-vv22-vwq7-hqwj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vv22-vwq7-hqwj", - "modified": "2025-04-08T00:30:26Z", + "modified": "2025-04-09T00:30:27Z", "published": "2025-04-08T00:30:26Z", "aliases": [ "CVE-2025-0942"