diff --git a/advisories/github-reviewed/2025/03/GHSA-4vc4-m8qh-g8jm/GHSA-4vc4-m8qh-g8jm.json b/advisories/github-reviewed/2025/03/GHSA-4vc4-m8qh-g8jm/GHSA-4vc4-m8qh-g8jm.json index 469f0c4f2e8..43c5ca7b9e4 100644 --- a/advisories/github-reviewed/2025/03/GHSA-4vc4-m8qh-g8jm/GHSA-4vc4-m8qh-g8jm.json +++ b/advisories/github-reviewed/2025/03/GHSA-4vc4-m8qh-g8jm/GHSA-4vc4-m8qh-g8jm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4vc4-m8qh-g8jm", - "modified": "2025-03-14T20:22:17Z", + "modified": "2025-03-16T21:34:33Z", "published": "2025-03-12T20:20:24Z", "aliases": [ "CVE-2025-25291" @@ -99,6 +99,10 @@ "type": "WEB", "url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/ruby-saml/CVE-2025-25291.yml" }, + { + "type": "WEB", + "url": "https://news.ycombinator.com/item?id=43374519" + }, { "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20250314-0010" diff --git a/advisories/github-reviewed/2025/03/GHSA-754f-8gm6-c4r2/GHSA-754f-8gm6-c4r2.json b/advisories/github-reviewed/2025/03/GHSA-754f-8gm6-c4r2/GHSA-754f-8gm6-c4r2.json index aa9fe4a4c28..18b15e4e44a 100644 --- a/advisories/github-reviewed/2025/03/GHSA-754f-8gm6-c4r2/GHSA-754f-8gm6-c4r2.json +++ b/advisories/github-reviewed/2025/03/GHSA-754f-8gm6-c4r2/GHSA-754f-8gm6-c4r2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-754f-8gm6-c4r2", - "modified": "2025-03-14T12:32:01Z", + "modified": "2025-03-16T21:34:37Z", "published": "2025-03-12T20:54:42Z", "aliases": [ "CVE-2025-25292" @@ -99,6 +99,10 @@ "type": "WEB", "url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/ruby-saml/CVE-2025-25292.yml" }, + { + "type": "WEB", + "url": "https://news.ycombinator.com/item?id=43374519" + }, { "type": "WEB", "url": "https://security.netapp.com/advisory/ntap-20250314-0009" diff --git a/advisories/github-reviewed/2025/03/GHSA-9p8x-f768-wp2g/GHSA-9p8x-f768-wp2g.json b/advisories/github-reviewed/2025/03/GHSA-9p8x-f768-wp2g/GHSA-9p8x-f768-wp2g.json index e5004cef096..e7575115dcf 100644 --- a/advisories/github-reviewed/2025/03/GHSA-9p8x-f768-wp2g/GHSA-9p8x-f768-wp2g.json +++ b/advisories/github-reviewed/2025/03/GHSA-9p8x-f768-wp2g/GHSA-9p8x-f768-wp2g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9p8x-f768-wp2g", - "modified": "2025-03-14T20:24:06Z", + "modified": "2025-03-16T21:34:47Z", "published": "2025-03-14T17:14:23Z", "aliases": [ "CVE-2025-29774" @@ -109,6 +109,10 @@ { "type": "WEB", "url": "https://github.com/node-saml/xml-crypto/releases/tag/v6.0.1" + }, + { + "type": "WEB", + "url": "https://workos.com/blog/samlstorm" } ], "database_specific": { diff --git a/advisories/github-reviewed/2025/03/GHSA-x3m8-899r-f7c3/GHSA-x3m8-899r-f7c3.json b/advisories/github-reviewed/2025/03/GHSA-x3m8-899r-f7c3/GHSA-x3m8-899r-f7c3.json index 0a332a5cc48..aef84ad78ef 100644 --- a/advisories/github-reviewed/2025/03/GHSA-x3m8-899r-f7c3/GHSA-x3m8-899r-f7c3.json +++ b/advisories/github-reviewed/2025/03/GHSA-x3m8-899r-f7c3/GHSA-x3m8-899r-f7c3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-x3m8-899r-f7c3", - "modified": "2025-03-14T20:23:56Z", + "modified": "2025-03-16T21:34:52Z", "published": "2025-03-14T17:16:47Z", "aliases": [ "CVE-2025-29775" @@ -109,6 +109,10 @@ { "type": "WEB", "url": "https://github.com/node-saml/xml-crypto/releases/tag/v6.0.1" + }, + { + "type": "WEB", + "url": "https://workos.com/blog/samlstorm" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/03/GHSA-68wh-6q5x-7wqc/GHSA-68wh-6q5x-7wqc.json b/advisories/unreviewed/2025/03/GHSA-68wh-6q5x-7wqc/GHSA-68wh-6q5x-7wqc.json new file mode 100644 index 00000000000..b2e9b59f8f3 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-68wh-6q5x-7wqc/GHSA-68wh-6q5x-7wqc.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-68wh-6q5x-7wqc", + "modified": "2025-03-16T21:35:03Z", + "published": "2025-03-16T21:35:03Z", + "aliases": [ + "CVE-2025-2346" + ], + "details": "A vulnerability has been found in IROAD Dash Cam X5 and Dash Cam X6 up to 20250308 and classified as problematic. This vulnerability affects unknown code of the component Domain Handler. The manipulation of the argument Domain Name leads to origin validation error. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2346" + }, + { + "type": "WEB", + "url": "https://github.com/geo-chen/IROAD?tab=readme-ov-file#finding-6-public-domain-used-for-internal-domain-name" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.299812" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.299812" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-345" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-16T20:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-9m29-x4p3-hvhr/GHSA-9m29-x4p3-hvhr.json b/advisories/unreviewed/2025/03/GHSA-9m29-x4p3-hvhr/GHSA-9m29-x4p3-hvhr.json new file mode 100644 index 00000000000..ee6a42f5a51 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-9m29-x4p3-hvhr/GHSA-9m29-x4p3-hvhr.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9m29-x4p3-hvhr", + "modified": "2025-03-16T21:35:03Z", + "published": "2025-03-16T21:35:03Z", + "aliases": [ + "CVE-2025-2347" + ], + "details": "A vulnerability was found in IROAD Dash Cam FX2 up to 20250308 and classified as problematic. This issue affects some unknown processing of the component Device Registration. The manipulation of the argument Password with the input qwertyuiop leads to use of default password. The attack needs to be done within the local network. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2347" + }, + { + "type": "WEB", + "url": "https://github.com/geo-chen/IROAD?tab=readme-ov-file#finding-7-bypass-of-device-pairingregistration-for-iroad-fx2" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.299813" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.299813" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1393" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-16T21:15:37Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-wh2j-q9xp-x425/GHSA-wh2j-q9xp-x425.json b/advisories/unreviewed/2025/03/GHSA-wh2j-q9xp-x425/GHSA-wh2j-q9xp-x425.json new file mode 100644 index 00000000000..720ba5847f6 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-wh2j-q9xp-x425/GHSA-wh2j-q9xp-x425.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wh2j-q9xp-x425", + "modified": "2025-03-16T21:35:03Z", + "published": "2025-03-16T21:35:03Z", + "aliases": [ + "CVE-2025-2345" + ], + "details": "A vulnerability, which was classified as very critical, was found in IROAD Dash Cam X5 and Dash Cam X6 up to 20250308. This affects an unknown part. The manipulation leads to improper authorization. It is possible to initiate the attack remotely. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2345" + }, + { + "type": "WEB", + "url": "https://github.com/geo-chen/IROAD/blob/main/README.md#finding-5-managing-settings-to-obtain-sensitive-data-and-sabotaging-car-battery" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.299811" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.299811" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.516883" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-16T19:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-x83r-m463-jfj9/GHSA-x83r-m463-jfj9.json b/advisories/unreviewed/2025/03/GHSA-x83r-m463-jfj9/GHSA-x83r-m463-jfj9.json new file mode 100644 index 00000000000..b2eed4d7ea6 --- /dev/null +++ b/advisories/unreviewed/2025/03/GHSA-x83r-m463-jfj9/GHSA-x83r-m463-jfj9.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x83r-m463-jfj9", + "modified": "2025-03-16T21:35:03Z", + "published": "2025-03-16T21:35:03Z", + "aliases": [ + "CVE-2025-2348" + ], + "details": "A vulnerability was found in IROAD Dash Cam FX2 up to 20250308. It has been classified as problematic. Affected is an unknown function of the file /mnt/extsd/event/ of the component HTTP/RTSP. The manipulation leads to information disclosure. The attack needs to be initiated within the local network. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2348" + }, + { + "type": "WEB", + "url": "https://github.com/geo-chen/IROAD?tab=readme-ov-file#finding-8-dumping-files-over-http-and-rtsp-without-authentication" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.299814" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.299814" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-03-16T21:15:37Z" + } +} \ No newline at end of file