From a260c64cf5684ebc5f6073dfcc234fd8f39f2908 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 20 Feb 2025 00:33:30 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-9749-2mfq-hv49.json | 3 +- .../GHSA-xxch-mf4j-qcvj.json | 14 +++++++- .../GHSA-xh5q-pch5-g3xq.json | 6 +++- .../GHSA-268p-8m6q-3rq7.json | 11 ++++-- .../GHSA-298w-pg84-p7jw.json | 36 +++++++++++++++++++ .../GHSA-4g7p-889h-qvww.json | 36 +++++++++++++++++++ .../GHSA-572j-cqp5-7xrw.json | 33 +++++++++++++++++ .../GHSA-5f3r-pg69-63xp.json | 29 +++++++++++++++ .../GHSA-5r39-9h33-q5xr.json | 36 +++++++++++++++++++ .../GHSA-767x-vx85-f9jj.json | 36 +++++++++++++++++++ .../GHSA-7qgp-q3fg-4c39.json | 15 +++++--- .../GHSA-977c-3xvh-wwgh.json | 36 +++++++++++++++++++ .../GHSA-9pxm-pjxv-2f62.json | 25 +++++++++++++ .../GHSA-9wj2-6hv9-fwwp.json | 36 +++++++++++++++++++ .../GHSA-cc77-xm2j-7rm6.json | 11 ++++-- .../GHSA-cv3f-w5gj-ccpf.json | 29 +++++++++++++++ .../GHSA-fx4j-9fqf-p9p2.json | 36 +++++++++++++++++++ .../GHSA-h4wq-hxvv-x8qq.json | 36 +++++++++++++++++++ .../GHSA-hcqg-278r-c3pp.json | 15 +++++--- .../GHSA-hwqj-cjw9-27x8.json | 29 +++++++++++++++ .../GHSA-m4p3-9x42-5p6v.json | 11 ++++-- .../GHSA-p4xp-95h3-7gxv.json | 29 +++++++++++++++ .../GHSA-p87j-c6xv-g28x.json | 11 ++++-- .../GHSA-pf5r-3jm5-9v36.json | 29 +++++++++++++++ .../GHSA-pxjr-976r-24r6.json | 36 +++++++++++++++++++ .../GHSA-qfm9-r3p9-8hcp.json | 36 +++++++++++++++++++ .../GHSA-r5c8-8xvg-qm37.json | 36 +++++++++++++++++++ .../GHSA-v8rq-3rvq-8hjc.json | 36 +++++++++++++++++++ .../GHSA-vp3x-fq4p-vf29.json | 36 +++++++++++++++++++ .../GHSA-vxpp-m9vw-rjcx.json | 6 +++- .../GHSA-wmcv-pj3g-38rp.json | 2 +- .../GHSA-wr4v-2x2x-cprg.json | 29 +++++++++++++++ 32 files changed, 780 insertions(+), 25 deletions(-) create mode 100644 advisories/unreviewed/2025/02/GHSA-298w-pg84-p7jw/GHSA-298w-pg84-p7jw.json create mode 100644 advisories/unreviewed/2025/02/GHSA-4g7p-889h-qvww/GHSA-4g7p-889h-qvww.json create mode 100644 advisories/unreviewed/2025/02/GHSA-572j-cqp5-7xrw/GHSA-572j-cqp5-7xrw.json create mode 100644 advisories/unreviewed/2025/02/GHSA-5f3r-pg69-63xp/GHSA-5f3r-pg69-63xp.json create mode 100644 advisories/unreviewed/2025/02/GHSA-5r39-9h33-q5xr/GHSA-5r39-9h33-q5xr.json create mode 100644 advisories/unreviewed/2025/02/GHSA-767x-vx85-f9jj/GHSA-767x-vx85-f9jj.json create mode 100644 advisories/unreviewed/2025/02/GHSA-977c-3xvh-wwgh/GHSA-977c-3xvh-wwgh.json create mode 100644 advisories/unreviewed/2025/02/GHSA-9pxm-pjxv-2f62/GHSA-9pxm-pjxv-2f62.json create mode 100644 advisories/unreviewed/2025/02/GHSA-9wj2-6hv9-fwwp/GHSA-9wj2-6hv9-fwwp.json create mode 100644 advisories/unreviewed/2025/02/GHSA-cv3f-w5gj-ccpf/GHSA-cv3f-w5gj-ccpf.json create mode 100644 advisories/unreviewed/2025/02/GHSA-fx4j-9fqf-p9p2/GHSA-fx4j-9fqf-p9p2.json create mode 100644 advisories/unreviewed/2025/02/GHSA-h4wq-hxvv-x8qq/GHSA-h4wq-hxvv-x8qq.json create mode 100644 advisories/unreviewed/2025/02/GHSA-hwqj-cjw9-27x8/GHSA-hwqj-cjw9-27x8.json create mode 100644 advisories/unreviewed/2025/02/GHSA-p4xp-95h3-7gxv/GHSA-p4xp-95h3-7gxv.json create mode 100644 advisories/unreviewed/2025/02/GHSA-pf5r-3jm5-9v36/GHSA-pf5r-3jm5-9v36.json create mode 100644 advisories/unreviewed/2025/02/GHSA-pxjr-976r-24r6/GHSA-pxjr-976r-24r6.json create mode 100644 advisories/unreviewed/2025/02/GHSA-qfm9-r3p9-8hcp/GHSA-qfm9-r3p9-8hcp.json create mode 100644 advisories/unreviewed/2025/02/GHSA-r5c8-8xvg-qm37/GHSA-r5c8-8xvg-qm37.json create mode 100644 advisories/unreviewed/2025/02/GHSA-v8rq-3rvq-8hjc/GHSA-v8rq-3rvq-8hjc.json create mode 100644 advisories/unreviewed/2025/02/GHSA-vp3x-fq4p-vf29/GHSA-vp3x-fq4p-vf29.json create mode 100644 advisories/unreviewed/2025/02/GHSA-wr4v-2x2x-cprg/GHSA-wr4v-2x2x-cprg.json diff --git a/advisories/unreviewed/2023/03/GHSA-9749-2mfq-hv49/GHSA-9749-2mfq-hv49.json b/advisories/unreviewed/2023/03/GHSA-9749-2mfq-hv49/GHSA-9749-2mfq-hv49.json index 4658c3e1763..346be1f90b5 100644 --- a/advisories/unreviewed/2023/03/GHSA-9749-2mfq-hv49/GHSA-9749-2mfq-hv49.json +++ b/advisories/unreviewed/2023/03/GHSA-9749-2mfq-hv49/GHSA-9749-2mfq-hv49.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-347" + "CWE-347", + "CWE-494" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/03/GHSA-xxch-mf4j-qcvj/GHSA-xxch-mf4j-qcvj.json b/advisories/unreviewed/2023/03/GHSA-xxch-mf4j-qcvj/GHSA-xxch-mf4j-qcvj.json index e1aedc27ab3..124955d7a8d 100644 --- a/advisories/unreviewed/2023/03/GHSA-xxch-mf4j-qcvj/GHSA-xxch-mf4j-qcvj.json +++ b/advisories/unreviewed/2023/03/GHSA-xxch-mf4j-qcvj/GHSA-xxch-mf4j-qcvj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xxch-mf4j-qcvj", - "modified": "2023-03-31T15:30:19Z", + "modified": "2025-02-20T00:32:02Z", "published": "2023-03-24T06:30:16Z", "aliases": [ "CVE-2023-28686" @@ -23,6 +23,18 @@ "type": "WEB", "url": "https://dino.im/security/cve-2023-28686" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BQLCEUZS5GPHUQMS7C6W2NS3PHYUFHYF" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GOH6NYTLPM52MDIR2IRVUR3REDVWZV6N" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IIWXAK656EHSRIRUHLPBE3AX2I4TMH7M" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BQLCEUZS5GPHUQMS7C6W2NS3PHYUFHYF" diff --git a/advisories/unreviewed/2025/01/GHSA-xh5q-pch5-g3xq/GHSA-xh5q-pch5-g3xq.json b/advisories/unreviewed/2025/01/GHSA-xh5q-pch5-g3xq/GHSA-xh5q-pch5-g3xq.json index ea57e1f28c3..655ffa7e442 100644 --- a/advisories/unreviewed/2025/01/GHSA-xh5q-pch5-g3xq/GHSA-xh5q-pch5-g3xq.json +++ b/advisories/unreviewed/2025/01/GHSA-xh5q-pch5-g3xq/GHSA-xh5q-pch5-g3xq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xh5q-pch5-g3xq", - "modified": "2025-02-13T03:30:43Z", + "modified": "2025-02-20T00:32:02Z", "published": "2025-01-14T18:32:00Z", "aliases": [ "CVE-2024-12085" @@ -31,6 +31,10 @@ "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-12085" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:1451" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:1242" diff --git a/advisories/unreviewed/2025/02/GHSA-268p-8m6q-3rq7/GHSA-268p-8m6q-3rq7.json b/advisories/unreviewed/2025/02/GHSA-268p-8m6q-3rq7/GHSA-268p-8m6q-3rq7.json index dc506d338c0..1aaaa4e4f93 100644 --- a/advisories/unreviewed/2025/02/GHSA-268p-8m6q-3rq7/GHSA-268p-8m6q-3rq7.json +++ b/advisories/unreviewed/2025/02/GHSA-268p-8m6q-3rq7/GHSA-268p-8m6q-3rq7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-268p-8m6q-3rq7", - "modified": "2025-02-13T06:31:43Z", + "modified": "2025-02-20T00:32:02Z", "published": "2025-02-13T06:31:43Z", "aliases": [ "CVE-2024-13121" ], "details": "The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.15.20 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-13T06:15:21Z" diff --git a/advisories/unreviewed/2025/02/GHSA-298w-pg84-p7jw/GHSA-298w-pg84-p7jw.json b/advisories/unreviewed/2025/02/GHSA-298w-pg84-p7jw/GHSA-298w-pg84-p7jw.json new file mode 100644 index 00000000000..a2a6e693116 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-298w-pg84-p7jw/GHSA-298w-pg84-p7jw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-298w-pg84-p7jw", + "modified": "2025-02-20T00:32:05Z", + "published": "2025-02-20T00:32:05Z", + "aliases": [ + "CVE-2024-37361" + ], + "details": "The application deserializes untrusted data without sufficiently verifying that the resulting data will be valid. (CWE-502)\n\n\n\n \n\n\n\nHitachi Vantara Pentaho Business Analytics Server versions before 10.2.0.0 and 9.3.0.9, including 8.3.x, deserialize untrusted JSON data without constraining the parser to approved classes and methods.\n\n\n\n \n\n\n\nWhen developers place no restrictions on \"gadget chains,\" or series of instances and method invocations that can self-execute during the deserialization process (i.e., before the object is returned to the caller), it is sometimes possible for attackers to leverage them to perform unauthorized actions.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37361" + }, + { + "type": "WEB", + "url": "https://support.pentaho.com/hc/en-us/articles/34298351866893--Resolved-Hitachi-Vantara-Pentaho-Business-Analytics-Server-Improper-Neutralization-of-Input-During-Web-Page-Generation-Cross-site-Scripting-Versions-before-10-2-0-0-and-9-3-0-9-including-8-3-x-Impacted-CVE-2024-37360" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T00:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-4g7p-889h-qvww/GHSA-4g7p-889h-qvww.json b/advisories/unreviewed/2025/02/GHSA-4g7p-889h-qvww/GHSA-4g7p-889h-qvww.json new file mode 100644 index 00000000000..9e4acb87c9a --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-4g7p-889h-qvww/GHSA-4g7p-889h-qvww.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4g7p-889h-qvww", + "modified": "2025-02-20T00:32:05Z", + "published": "2025-02-20T00:32:05Z", + "aliases": [ + "CVE-2024-12284" + ], + "details": "Authenticated privilege escalation in NetScaler Console and NetScaler Agent allows.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12284" + }, + { + "type": "WEB", + "url": "https://support.citrix.com/s/article/CTX692579-netscaler-console-and-netscaler-agent-security-bulletin-for-cve202412284?language=en_US" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T00:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-572j-cqp5-7xrw/GHSA-572j-cqp5-7xrw.json b/advisories/unreviewed/2025/02/GHSA-572j-cqp5-7xrw/GHSA-572j-cqp5-7xrw.json new file mode 100644 index 00000000000..6fe23e0e44b --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-572j-cqp5-7xrw/GHSA-572j-cqp5-7xrw.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-572j-cqp5-7xrw", + "modified": "2025-02-20T00:32:03Z", + "published": "2025-02-20T00:32:03Z", + "aliases": [ + "CVE-2023-51305" + ], + "details": "PHPJabbers Car Park Booking System v3.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the \"name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key\" parameters.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-51305" + }, + { + "type": "WEB", + "url": "https://packetstorm.news/files/id/176491" + }, + { + "type": "WEB", + "url": "https://www.phpjabbers.com/car-park-booking/#sectionDemo" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-19T23:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-5f3r-pg69-63xp/GHSA-5f3r-pg69-63xp.json b/advisories/unreviewed/2025/02/GHSA-5f3r-pg69-63xp/GHSA-5f3r-pg69-63xp.json new file mode 100644 index 00000000000..ecbaa6c49e6 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-5f3r-pg69-63xp/GHSA-5f3r-pg69-63xp.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5f3r-pg69-63xp", + "modified": "2025-02-20T00:32:04Z", + "published": "2025-02-20T00:32:04Z", + "aliases": [ + "CVE-2025-25945" + ], + "details": "An issue in Bento4 v1.6.0-641 allows an attacker to obtain sensitive information via the the Mp4Fragment.cpp and in AP4_DescriptorFactory::CreateDescriptorFromStream at Ap4DescriptorFactory.cpp.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25945" + }, + { + "type": "WEB", + "url": "https://github.com/axiomatic-systems/Bento4/issues/993" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-19T23:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-5r39-9h33-q5xr/GHSA-5r39-9h33-q5xr.json b/advisories/unreviewed/2025/02/GHSA-5r39-9h33-q5xr/GHSA-5r39-9h33-q5xr.json new file mode 100644 index 00000000000..cd07ac3c5ad --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-5r39-9h33-q5xr/GHSA-5r39-9h33-q5xr.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5r39-9h33-q5xr", + "modified": "2025-02-20T00:32:05Z", + "published": "2025-02-20T00:32:05Z", + "aliases": [ + "CVE-2024-6696" + ], + "details": "The product implements access controls via a policy or other feature with the intention to disable or restrict accesses (reads and/or writes) to assets in a system from untrusted agents. However, implemented access controls lack required granularity, which renders the control policy too broad because it allows accesses from unauthorized agents to the security-sensitive assets. (CWE-1220) \n\n\n\n\n\n\nHitachi Vantara Pentaho Business Analytics Server versions before 10.2.0.0 and 9.3.0.9, including 8.3.x, do not correctly perform an authorization check in the user console trash content\n\n\n\n\n\n\n An attacker exploits a weakness in the configuration of access controls and is able to bypass the intended protection that these measures guard against and thereby obtain unauthorized access to the system or network.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6696" + }, + { + "type": "WEB", + "url": "https://support.pentaho.com/hc/en-us/articles/34296877157517--Resolved-Hitachi-Vantara-Pentaho-Business-Analytics-Server-Insufficient-Granularity-of-Access-Control-Versions-before-10-2-0-0-and-9-3-0-9-including-8-3-x-Impacted-CVE-2024-6696" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1220" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T00:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-767x-vx85-f9jj/GHSA-767x-vx85-f9jj.json b/advisories/unreviewed/2025/02/GHSA-767x-vx85-f9jj/GHSA-767x-vx85-f9jj.json new file mode 100644 index 00000000000..e6a729fe3e9 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-767x-vx85-f9jj/GHSA-767x-vx85-f9jj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-767x-vx85-f9jj", + "modified": "2025-02-20T00:32:03Z", + "published": "2025-02-20T00:32:03Z", + "aliases": [ + "CVE-2024-5705" + ], + "details": "The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions. (CWE-863) \n\n\n\n \n\n\n\n \n\n\n\nHitachi Vantara Pentaho Business Analytics Server versions before 10.2.0.0 and 9.3.0.9, including 8.3.x, have modules enabled by default that allow execution of system level processes. \n\n\n\n \n\n\n\n\n\n\n\n\nWhen access control checks are incorrectly applied, users can access data or perform actions that they should not be allowed to perform. This can lead to a wide range of problems, including information exposures and denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5705" + }, + { + "type": "WEB", + "url": "https://support.pentaho.com/hc/en-us/articles/34296615099405--Resolved-Hitachi-Vantara-Pentaho-Business-Analytics-Server-Incorrect-Authorization-Versions-before-10-2-0-0-and-9-3-0-9-including-8-3-x-Impacted-CVE-2024-5705" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-19T23:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-7qgp-q3fg-4c39/GHSA-7qgp-q3fg-4c39.json b/advisories/unreviewed/2025/02/GHSA-7qgp-q3fg-4c39/GHSA-7qgp-q3fg-4c39.json index 8890a90b6b5..2f83cef79c1 100644 --- a/advisories/unreviewed/2025/02/GHSA-7qgp-q3fg-4c39/GHSA-7qgp-q3fg-4c39.json +++ b/advisories/unreviewed/2025/02/GHSA-7qgp-q3fg-4c39/GHSA-7qgp-q3fg-4c39.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7qgp-q3fg-4c39", - "modified": "2025-02-19T00:31:19Z", + "modified": "2025-02-20T00:32:03Z", "published": "2025-02-19T00:31:19Z", "aliases": [ "CVE-2025-22920" ], "details": "A heap buffer overflow vulnerability in FFmpeg before commit 4bf784c allows attackers to trigger a memory corruption via supplying a crafted media file in avformat when processing tile grid group streams. This can lead to a Denial of Service (DoS).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-122" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-18T23:15:10Z" diff --git a/advisories/unreviewed/2025/02/GHSA-977c-3xvh-wwgh/GHSA-977c-3xvh-wwgh.json b/advisories/unreviewed/2025/02/GHSA-977c-3xvh-wwgh/GHSA-977c-3xvh-wwgh.json new file mode 100644 index 00000000000..07ca385e89e --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-977c-3xvh-wwgh/GHSA-977c-3xvh-wwgh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-977c-3xvh-wwgh", + "modified": "2025-02-20T00:32:04Z", + "published": "2025-02-20T00:32:04Z", + "aliases": [ + "CVE-2024-5706" + ], + "details": "The product receives input from an upstream component, but it does not restrict or incorrectly restricts the input before it is used as an identifier for a resource that may be outside the intended sphere of control. (CWE-99) \n\n\n\n\n\n\nHitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.0 and 9.3.0.9, including 8.3.x, do not restrict JNDI identifiers during the creation of Community Dashboards, allowing control of system-level data sources. \n\n\n\n\n\n\n\nAn attacker could gain access to or modify sensitive data or system resources. This could allow access to protected files or directories including configuration files and files containing sensitive information, which can lead to remote code execution by unauthorized users.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5706" + }, + { + "type": "WEB", + "url": "https://support.pentaho.com/hc/en-us/articles/34296195570189--Resolved-Hitachi-Vantara-Pentaho-Data-Integration-Analytics-Improper-Control-of-Resource-Identifiers-Resource-Injection-Versions-before-10-2-0-0-and-9-3-0-9-including-8-3-x-Impacted-CVE-2024-5706" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-99" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-19T23:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-9pxm-pjxv-2f62/GHSA-9pxm-pjxv-2f62.json b/advisories/unreviewed/2025/02/GHSA-9pxm-pjxv-2f62/GHSA-9pxm-pjxv-2f62.json new file mode 100644 index 00000000000..e0d156a9d8e --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-9pxm-pjxv-2f62/GHSA-9pxm-pjxv-2f62.json @@ -0,0 +1,25 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9pxm-pjxv-2f62", + "modified": "2025-02-20T00:32:03Z", + "published": "2025-02-20T00:32:03Z", + "aliases": [ + "CVE-2024-10339" + ], + "details": "Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-10339" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-19T23:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-9wj2-6hv9-fwwp/GHSA-9wj2-6hv9-fwwp.json b/advisories/unreviewed/2025/02/GHSA-9wj2-6hv9-fwwp/GHSA-9wj2-6hv9-fwwp.json new file mode 100644 index 00000000000..612aa21279c --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-9wj2-6hv9-fwwp/GHSA-9wj2-6hv9-fwwp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9wj2-6hv9-fwwp", + "modified": "2025-02-20T00:32:05Z", + "published": "2025-02-20T00:32:05Z", + "aliases": [ + "CVE-2025-0112" + ], + "details": "A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with Windows non-administrative privileges to disable the agent. This vulnerability can also be leveraged by malware to disable the Cortex XDR agent and then perform malicious activity.", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:D/RE:X/U:Amber" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0112" + }, + { + "type": "WEB", + "url": "https://security.paloaltonetworks.com/CVE-2025-0112" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-754" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T00:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-cc77-xm2j-7rm6/GHSA-cc77-xm2j-7rm6.json b/advisories/unreviewed/2025/02/GHSA-cc77-xm2j-7rm6/GHSA-cc77-xm2j-7rm6.json index 6a55cabd4d3..1af94993c09 100644 --- a/advisories/unreviewed/2025/02/GHSA-cc77-xm2j-7rm6/GHSA-cc77-xm2j-7rm6.json +++ b/advisories/unreviewed/2025/02/GHSA-cc77-xm2j-7rm6/GHSA-cc77-xm2j-7rm6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-cc77-xm2j-7rm6", - "modified": "2025-02-13T06:31:43Z", + "modified": "2025-02-20T00:32:02Z", "published": "2025-02-13T06:31:43Z", "aliases": [ "CVE-2025-0692" ], "details": "The Simple Video Management System WordPress plugin through 1.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-13T06:15:21Z" diff --git a/advisories/unreviewed/2025/02/GHSA-cv3f-w5gj-ccpf/GHSA-cv3f-w5gj-ccpf.json b/advisories/unreviewed/2025/02/GHSA-cv3f-w5gj-ccpf/GHSA-cv3f-w5gj-ccpf.json new file mode 100644 index 00000000000..be3043aebf4 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-cv3f-w5gj-ccpf/GHSA-cv3f-w5gj-ccpf.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cv3f-w5gj-ccpf", + "modified": "2025-02-20T00:32:04Z", + "published": "2025-02-20T00:32:04Z", + "aliases": [ + "CVE-2025-25943" + ], + "details": "Buffer Overflow vulnerability in Bento4 v.1.6.0-641 allows a local attacker to execute arbitrary code via the AP4_Stz2Atom::AP4_Stz2Atom component located in Ap4Stz2Atom.cpp.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25943" + }, + { + "type": "WEB", + "url": "https://github.com/axiomatic-systems/Bento4/issues/993" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-19T23:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-fx4j-9fqf-p9p2/GHSA-fx4j-9fqf-p9p2.json b/advisories/unreviewed/2025/02/GHSA-fx4j-9fqf-p9p2/GHSA-fx4j-9fqf-p9p2.json new file mode 100644 index 00000000000..a103d095509 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-fx4j-9fqf-p9p2/GHSA-fx4j-9fqf-p9p2.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fx4j-9fqf-p9p2", + "modified": "2025-02-20T00:32:04Z", + "published": "2025-02-20T00:32:04Z", + "aliases": [ + "CVE-2025-21355" + ], + "details": "Missing Authentication for Critical Function in Microsoft Bing allows an unauthorized attacker to execute code over a network", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21355" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21355" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-19T23:15:12Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-h4wq-hxvv-x8qq/GHSA-h4wq-hxvv-x8qq.json b/advisories/unreviewed/2025/02/GHSA-h4wq-hxvv-x8qq/GHSA-h4wq-hxvv-x8qq.json new file mode 100644 index 00000000000..6f38128481d --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-h4wq-hxvv-x8qq/GHSA-h4wq-hxvv-x8qq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h4wq-hxvv-x8qq", + "modified": "2025-02-20T00:32:03Z", + "published": "2025-02-20T00:32:03Z", + "aliases": [ + "CVE-2024-37360" + ], + "details": "Hitachi Vantara Pentaho Business Analytics Server - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') \n\n\n\n \n\n\n\nThe software does not neutralize or incorrectly neutralize user-controllable input before it is placed in output that is used as a web page that is served to other users. (CWE-79)\n\n\n\n \n\n\n\nHitachi Vantara Pentaho Business Analytics Server prior to versions 10.2.0.0 and 9.3.0.9, including 8.3.x, allow a malicious URL to inject content into the Analyzer plugin interface.\n\n\n\n \n\n\n\n\nOnce the malicious script is injected, the attacker can perform a variety of malicious activities. The attacker could transfer private information, such as cookies that may include session information, from the victim's machine to the attacker. The attacker could send malicious requests to a web site on behalf of the victim, which could be especially dangerous to the site if the victim has administrator privileges to manage that site.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37360" + }, + { + "type": "WEB", + "url": "https://support.pentaho.com/hc/en-us/articles/34298351866893--Resolved-Hitachi-Vantara-Pentaho-Business-Analytics-Server-Improper-Neutralization-of-Input-During-Web-Page-Generation-Cross-site-Scripting-CVE-2024-37360" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-19T23:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-hcqg-278r-c3pp/GHSA-hcqg-278r-c3pp.json b/advisories/unreviewed/2025/02/GHSA-hcqg-278r-c3pp/GHSA-hcqg-278r-c3pp.json index 0a7f5cf43b2..e504b883a9b 100644 --- a/advisories/unreviewed/2025/02/GHSA-hcqg-278r-c3pp/GHSA-hcqg-278r-c3pp.json +++ b/advisories/unreviewed/2025/02/GHSA-hcqg-278r-c3pp/GHSA-hcqg-278r-c3pp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hcqg-278r-c3pp", - "modified": "2025-02-19T00:31:19Z", + "modified": "2025-02-20T00:32:03Z", "published": "2025-02-19T00:31:19Z", "aliases": [ "CVE-2025-22919" ], "details": "A reachable assertion in FFmpeg git-master commit N-113007-g8d24a28d06 allows attackers to cause a Denial of Service (DoS) via opening a crafted AAC file.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-617" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-18T23:15:10Z" diff --git a/advisories/unreviewed/2025/02/GHSA-hwqj-cjw9-27x8/GHSA-hwqj-cjw9-27x8.json b/advisories/unreviewed/2025/02/GHSA-hwqj-cjw9-27x8/GHSA-hwqj-cjw9-27x8.json new file mode 100644 index 00000000000..a84a65d766b --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-hwqj-cjw9-27x8/GHSA-hwqj-cjw9-27x8.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hwqj-cjw9-27x8", + "modified": "2025-02-20T00:32:05Z", + "published": "2025-02-20T00:32:05Z", + "aliases": [ + "CVE-2025-25947" + ], + "details": "An issue in Bento4 v1.6.0-641 allows an attacker to trigger a segmentation fault via Ap4Atom.cpp, specifically in AP4_AtomParent::RemoveChild, during the execution of mp4encrypt with a specially crafted MP4 input file.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25947" + }, + { + "type": "WEB", + "url": "https://github.com/axiomatic-systems/Bento4/issues/994" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-19T23:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-m4p3-9x42-5p6v/GHSA-m4p3-9x42-5p6v.json b/advisories/unreviewed/2025/02/GHSA-m4p3-9x42-5p6v/GHSA-m4p3-9x42-5p6v.json index 7dac2b3e9c4..577fee88db8 100644 --- a/advisories/unreviewed/2025/02/GHSA-m4p3-9x42-5p6v/GHSA-m4p3-9x42-5p6v.json +++ b/advisories/unreviewed/2025/02/GHSA-m4p3-9x42-5p6v/GHSA-m4p3-9x42-5p6v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-m4p3-9x42-5p6v", - "modified": "2025-02-13T06:31:43Z", + "modified": "2025-02-20T00:32:02Z", "published": "2025-02-13T06:31:43Z", "aliases": [ "CVE-2024-13125" ], "details": "The Everest Forms WordPress plugin before 3.0.8.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-13T06:15:21Z" diff --git a/advisories/unreviewed/2025/02/GHSA-p4xp-95h3-7gxv/GHSA-p4xp-95h3-7gxv.json b/advisories/unreviewed/2025/02/GHSA-p4xp-95h3-7gxv/GHSA-p4xp-95h3-7gxv.json new file mode 100644 index 00000000000..c8703a8bfa6 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-p4xp-95h3-7gxv/GHSA-p4xp-95h3-7gxv.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p4xp-95h3-7gxv", + "modified": "2025-02-20T00:32:05Z", + "published": "2025-02-20T00:32:05Z", + "aliases": [ + "CVE-2025-25946" + ], + "details": "An issue in Bento4 v1.6.0-641 allows an attacker to cause a memory leak via Ap4Marlin.cpp and Ap4Processor.cpp, specifically in AP4_MarlinIpmpEncryptingProcessor::Initialize and AP4_Processor::Process, during the execution of mp4encrypt with a specially crafted MP4 input file.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25946" + }, + { + "type": "WEB", + "url": "https://github.com/axiomatic-systems/Bento4/issues/994" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-19T23:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-p87j-c6xv-g28x/GHSA-p87j-c6xv-g28x.json b/advisories/unreviewed/2025/02/GHSA-p87j-c6xv-g28x/GHSA-p87j-c6xv-g28x.json index 52d7edda128..1f97df62730 100644 --- a/advisories/unreviewed/2025/02/GHSA-p87j-c6xv-g28x/GHSA-p87j-c6xv-g28x.json +++ b/advisories/unreviewed/2025/02/GHSA-p87j-c6xv-g28x/GHSA-p87j-c6xv-g28x.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-p87j-c6xv-g28x", - "modified": "2025-02-11T18:31:43Z", + "modified": "2025-02-20T00:32:02Z", "published": "2025-02-11T18:31:43Z", "aliases": [ "CVE-2025-26494" ], "details": "Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server allows Authentication Bypass.This issue affects Tableau Server: from 2023.3 through 2023.3.5.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-918" ], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-11T18:15:47Z" diff --git a/advisories/unreviewed/2025/02/GHSA-pf5r-3jm5-9v36/GHSA-pf5r-3jm5-9v36.json b/advisories/unreviewed/2025/02/GHSA-pf5r-3jm5-9v36/GHSA-pf5r-3jm5-9v36.json new file mode 100644 index 00000000000..d5ec75c961d --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-pf5r-3jm5-9v36/GHSA-pf5r-3jm5-9v36.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pf5r-3jm5-9v36", + "modified": "2025-02-20T00:32:04Z", + "published": "2025-02-20T00:32:04Z", + "aliases": [ + "CVE-2025-25944" + ], + "details": "Buffer Overflow vulnerability in Bento4 v.1.6.0-641 allows a local attacker to execute arbitrary code via the Ap4RtpAtom.cpp, specifically in AP4_RtpAtom::AP4_RtpAtom, during the execution of mp4fragment with a crafted MP4 input file.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25944" + }, + { + "type": "WEB", + "url": "https://github.com/axiomatic-systems/Bento4/issues/993" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-19T23:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-pxjr-976r-24r6/GHSA-pxjr-976r-24r6.json b/advisories/unreviewed/2025/02/GHSA-pxjr-976r-24r6/GHSA-pxjr-976r-24r6.json new file mode 100644 index 00000000000..17a3eba8423 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-pxjr-976r-24r6/GHSA-pxjr-976r-24r6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pxjr-976r-24r6", + "modified": "2025-02-20T00:32:04Z", + "published": "2025-02-20T00:32:04Z", + "aliases": [ + "CVE-2025-24989" + ], + "details": "An improper access control vulnerability in Power Pages allows an unauthorized attacker to elevate privileges over a network potentially bypassing the user registration control.\nThis vulnerability has already been mitigated in the service and all affected cusomters have been notified. This update addressed the registration control bypass. Affected customers have been given instructions on reviewing their sites for potential exploitation and clean up methods. If you've not been notified this vulnerability does not affect you.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24989" + }, + { + "type": "WEB", + "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-24989" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-19T23:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-qfm9-r3p9-8hcp/GHSA-qfm9-r3p9-8hcp.json b/advisories/unreviewed/2025/02/GHSA-qfm9-r3p9-8hcp/GHSA-qfm9-r3p9-8hcp.json new file mode 100644 index 00000000000..5e0378947ed --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-qfm9-r3p9-8hcp/GHSA-qfm9-r3p9-8hcp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qfm9-r3p9-8hcp", + "modified": "2025-02-20T00:32:03Z", + "published": "2025-02-20T00:32:03Z", + "aliases": [ + "CVE-2024-37359" + ], + "details": "The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination. (CWE-918) \n\n\n\n \n\n\n\nHitachi Vantara Pentaho Business Analytics Server versions before 10.2.0.0 and 9.3.0.9, including 8.3.x, do not validate the Host header of incoming HTTP/HTTPS requests.\n\n\n\n \n\n\n\nBy providing URLs to unexpected hosts or ports, attackers can make it appear that the server is sending the request, possibly bypassing access controls such as firewalls that prevent the attackers from accessing the URLs directly. The server can be used as a proxy to conduct port scanning of hosts in internal networks, use other URLs such as that can access documents on the system (using file://), or use other protocols such as gopher:// or tftp://, which may provide greater control over the contents of requests.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37359" + }, + { + "type": "WEB", + "url": "https://support.pentaho.com/hc/en-us/articles/34296789835917--Resolved-Hitachi-Vantara-Pentaho-Business-Analytics-Server-Server-Side-Request-Forgery-Versions-before-10-2-0-0-and-9-3-0-9-including-8-3-x-Impacted-CVE-2024-37359" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-19T23:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-r5c8-8xvg-qm37/GHSA-r5c8-8xvg-qm37.json b/advisories/unreviewed/2025/02/GHSA-r5c8-8xvg-qm37/GHSA-r5c8-8xvg-qm37.json new file mode 100644 index 00000000000..cea9b9b66d7 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-r5c8-8xvg-qm37/GHSA-r5c8-8xvg-qm37.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r5c8-8xvg-qm37", + "modified": "2025-02-20T00:32:05Z", + "published": "2025-02-20T00:32:05Z", + "aliases": [ + "CVE-2024-37362" + ], + "details": "The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval. (CWE-522) \n\n\n\n \n\n\n\nHitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.0 and 9.3.0.8, including 8.3.x, discloses database passwords when saving connections to RedShift.\n\n\n\n \n\n\n\nProducts must not disclose sensitive information without cause. Disclosure of sensitive information can lead to further exploitation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37362" + }, + { + "type": "WEB", + "url": "https://support.pentaho.com/hc/en-us/articles/34296552220941--Resolved-Hitachi-Vantara-Pentaho-Data-Integration-Analytics-Insufficiently-Protected-Credentials-Versions-before-10-2-0-0-and-9-3-0-8-including-8-3-x-Impacted-CVE-2024-37362" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-522" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T00:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-v8rq-3rvq-8hjc/GHSA-v8rq-3rvq-8hjc.json b/advisories/unreviewed/2025/02/GHSA-v8rq-3rvq-8hjc/GHSA-v8rq-3rvq-8hjc.json new file mode 100644 index 00000000000..a3f0022f740 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-v8rq-3rvq-8hjc/GHSA-v8rq-3rvq-8hjc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v8rq-3rvq-8hjc", + "modified": "2025-02-20T00:32:05Z", + "published": "2025-02-20T00:32:05Z", + "aliases": [ + "CVE-2024-37363" + ], + "details": "The product does not perform an authorization check when an actor attempts to access a resource or perform an action. (CWE-862)\n\n\n\n\n\n\n Hitachi Vantara Pentaho Business Analytics Server versions before 10.2.0.0 and 9.3.0.8, including 8.3.x, do not correctly perform an authorization check in the data source management service.\n\n\n\n\n\n\n\n\nWhen access control checks are incorrectly applied, users can access data or perform actions that they should not be allowed to perform. This can lead to a wide range of problems, including information exposures and denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37363" + }, + { + "type": "WEB", + "url": "https://support.pentaho.com/hc/en-us/articles/34296230504589--Resolved-Hitachi-Vantara-Pentaho-Business-Analytics-Server-Incorrect-Authorization-Versions-before-10-2-0-0-and-9-3-0-8-including-8-3-x-Impacted-CVE-2024-37363" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T00:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-vp3x-fq4p-vf29/GHSA-vp3x-fq4p-vf29.json b/advisories/unreviewed/2025/02/GHSA-vp3x-fq4p-vf29/GHSA-vp3x-fq4p-vf29.json new file mode 100644 index 00000000000..3a97c2081b1 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-vp3x-fq4p-vf29/GHSA-vp3x-fq4p-vf29.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vp3x-fq4p-vf29", + "modified": "2025-02-20T00:32:06Z", + "published": "2025-02-20T00:32:05Z", + "aliases": [ + "CVE-2024-6697" + ], + "details": "The product does not handle or incorrectly handles when it has insufficient privileges to access resources or functionality as specified by their permissions. This may cause it to follow unexpected code paths that may leave the product in an invalid state. (CWE-280)\n\n\n\n \n\n\n\nHitachi Vantara Pentaho Business Analytics Server versions before 10.2.0.0 and 9.3.0.9, including 8.3.x, do not handle invalid and missing permissions correctly, resulting in a denial of service.\n\n\n\n \n\n\n\nAn adversary leverages a legitimate capability of an application in such a way as to achieve a negative technical impact.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6697" + }, + { + "type": "WEB", + "url": "https://support.pentaho.com/hc/en-us/articles/34296654642701--Resolved-Hitachi-Vantara-Pentaho-Business-Analytics-Server-Improper-Handling-of-Insufficient-Permissions-or-Privileges-Versions-before-10-2-0-0-and-9-3-0-9-including-8-3-x-Impacted-CVE-2024-6697" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-280" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-20T00:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-vxpp-m9vw-rjcx/GHSA-vxpp-m9vw-rjcx.json b/advisories/unreviewed/2025/02/GHSA-vxpp-m9vw-rjcx/GHSA-vxpp-m9vw-rjcx.json index cf41fefe118..c03f6fe25d6 100644 --- a/advisories/unreviewed/2025/02/GHSA-vxpp-m9vw-rjcx/GHSA-vxpp-m9vw-rjcx.json +++ b/advisories/unreviewed/2025/02/GHSA-vxpp-m9vw-rjcx/GHSA-vxpp-m9vw-rjcx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vxpp-m9vw-rjcx", - "modified": "2025-02-03T18:30:43Z", + "modified": "2025-02-20T00:32:02Z", "published": "2025-02-03T18:30:43Z", "aliases": [ "CVE-2024-54840" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://docs.cyberark.com/pam-self-hosted/latest/en/content/release%20notes/rn-whatsnew14-4.htm#Securitybugfixes" + }, + { + "type": "WEB", + "url": "https://gist.github.com/Hurdano/8244855ef8ec364fd98a2693de6e30c5" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/02/GHSA-wmcv-pj3g-38rp/GHSA-wmcv-pj3g-38rp.json b/advisories/unreviewed/2025/02/GHSA-wmcv-pj3g-38rp/GHSA-wmcv-pj3g-38rp.json index cc7e4f48288..de990297597 100644 --- a/advisories/unreviewed/2025/02/GHSA-wmcv-pj3g-38rp/GHSA-wmcv-pj3g-38rp.json +++ b/advisories/unreviewed/2025/02/GHSA-wmcv-pj3g-38rp/GHSA-wmcv-pj3g-38rp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wmcv-pj3g-38rp", - "modified": "2025-02-12T21:31:54Z", + "modified": "2025-02-20T00:32:02Z", "published": "2025-02-12T21:31:54Z", "aliases": [ "CVE-2025-0111" diff --git a/advisories/unreviewed/2025/02/GHSA-wr4v-2x2x-cprg/GHSA-wr4v-2x2x-cprg.json b/advisories/unreviewed/2025/02/GHSA-wr4v-2x2x-cprg/GHSA-wr4v-2x2x-cprg.json new file mode 100644 index 00000000000..5a862a6e4ed --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-wr4v-2x2x-cprg/GHSA-wr4v-2x2x-cprg.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wr4v-2x2x-cprg", + "modified": "2025-02-20T00:32:04Z", + "published": "2025-02-20T00:32:04Z", + "aliases": [ + "CVE-2025-25942" + ], + "details": "An issue in Bento4 v1.6.0-641 allows an attacker to obtain sensitive information via the the mp4fragment tool when processing invalid files. Specifically, memory allocated in SampleArray::SampleArray in Mp4Fragment.cpp is not properly released.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25942" + }, + { + "type": "WEB", + "url": "https://github.com/axiomatic-systems/Bento4/issues/993" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-19T23:15:15Z" + } +} \ No newline at end of file