From b0e6bcfcbf3148ac9c5d4507e8b6327135b17184 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 30 May 2025 06:32:00 +0000 Subject: [PATCH] Publish Advisories GHSA-4q97-mrgv-92q2 GHSA-66gv-x64x-x377 GHSA-6j2q-c73v-97c5 GHSA-77wp-p4v3-xgj7 GHSA-8w6q-4mh2-p2gh GHSA-9r89-rh23-vf6r GHSA-qj62-4grm-wg6v --- .../GHSA-4q97-mrgv-92q2.json | 29 +++++++++++ .../GHSA-66gv-x64x-x377.json | 48 +++++++++++++++++++ .../GHSA-6j2q-c73v-97c5.json | 34 +++++++++++++ .../GHSA-77wp-p4v3-xgj7.json | 29 +++++++++++ .../GHSA-8w6q-4mh2-p2gh.json | 29 +++++++++++ .../GHSA-9r89-rh23-vf6r.json | 29 +++++++++++ .../GHSA-qj62-4grm-wg6v.json | 40 ++++++++++++++++ 7 files changed, 238 insertions(+) create mode 100644 advisories/unreviewed/2025/05/GHSA-4q97-mrgv-92q2/GHSA-4q97-mrgv-92q2.json create mode 100644 advisories/unreviewed/2025/05/GHSA-66gv-x64x-x377/GHSA-66gv-x64x-x377.json create mode 100644 advisories/unreviewed/2025/05/GHSA-6j2q-c73v-97c5/GHSA-6j2q-c73v-97c5.json create mode 100644 advisories/unreviewed/2025/05/GHSA-77wp-p4v3-xgj7/GHSA-77wp-p4v3-xgj7.json create mode 100644 advisories/unreviewed/2025/05/GHSA-8w6q-4mh2-p2gh/GHSA-8w6q-4mh2-p2gh.json create mode 100644 advisories/unreviewed/2025/05/GHSA-9r89-rh23-vf6r/GHSA-9r89-rh23-vf6r.json create mode 100644 advisories/unreviewed/2025/05/GHSA-qj62-4grm-wg6v/GHSA-qj62-4grm-wg6v.json diff --git a/advisories/unreviewed/2025/05/GHSA-4q97-mrgv-92q2/GHSA-4q97-mrgv-92q2.json b/advisories/unreviewed/2025/05/GHSA-4q97-mrgv-92q2/GHSA-4q97-mrgv-92q2.json new file mode 100644 index 00000000000..ce88fb7d3d6 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4q97-mrgv-92q2/GHSA-4q97-mrgv-92q2.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4q97-mrgv-92q2", + "modified": "2025-05-30T06:30:24Z", + "published": "2025-05-30T06:30:24Z", + "aliases": [ + "CVE-2025-44906" + ], + "details": "jhead v3.08 was discovered to contain a heap-use-after-free via the ProcessFile function at jhead.c.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44906" + }, + { + "type": "WEB", + "url": "https://github.com/madao123123/crash_report/blob/main/jhead/jhead.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-30T04:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-66gv-x64x-x377/GHSA-66gv-x64x-x377.json b/advisories/unreviewed/2025/05/GHSA-66gv-x64x-x377/GHSA-66gv-x64x-x377.json new file mode 100644 index 00000000000..fe3dbd2f7cc --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-66gv-x64x-x377/GHSA-66gv-x64x-x377.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-66gv-x64x-x377", + "modified": "2025-05-30T06:30:25Z", + "published": "2025-05-30T06:30:25Z", + "aliases": [ + "CVE-2025-5259" + ], + "details": "The Minimal Share Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’ parameter in all versions up to, and including, 1.7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5259" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/minimal-share-buttons/trunk/inc/class-minimal-share-buttons.php#L67" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3302704%40minimal-share-buttons&old=3074272%40minimal-share-buttons&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/minimal-share-buttons/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/7ac2ac7a-4cb5-4051-bec7-a22693c50915?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-30T06:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-6j2q-c73v-97c5/GHSA-6j2q-c73v-97c5.json b/advisories/unreviewed/2025/05/GHSA-6j2q-c73v-97c5/GHSA-6j2q-c73v-97c5.json new file mode 100644 index 00000000000..cef786e4fbb --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-6j2q-c73v-97c5/GHSA-6j2q-c73v-97c5.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6j2q-c73v-97c5", + "modified": "2025-05-30T06:30:25Z", + "published": "2025-05-30T06:30:25Z", + "aliases": [ + "CVE-2025-41235" + ], + "details": "Spring Cloud Gateway Server forwards the X-Forwarded-For and Forwarded headers from untrusted proxies.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-41235" + }, + { + "type": "WEB", + "url": "https://spring.io/security/cve-2025-41235" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-30T06:15:26Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-77wp-p4v3-xgj7/GHSA-77wp-p4v3-xgj7.json b/advisories/unreviewed/2025/05/GHSA-77wp-p4v3-xgj7/GHSA-77wp-p4v3-xgj7.json new file mode 100644 index 00000000000..052ccfcf024 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-77wp-p4v3-xgj7/GHSA-77wp-p4v3-xgj7.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-77wp-p4v3-xgj7", + "modified": "2025-05-30T06:30:24Z", + "published": "2025-05-30T06:30:24Z", + "aliases": [ + "CVE-2025-44904" + ], + "details": "hdf5 v1.14.6 was discovered to contain a heap buffer overflow via the H5VM_memcpyvv function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44904" + }, + { + "type": "WEB", + "url": "https://github.com/madao123123/crash_report/blob/main/hdf5_poc/hdf5_poc1.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-30T04:15:32Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8w6q-4mh2-p2gh/GHSA-8w6q-4mh2-p2gh.json b/advisories/unreviewed/2025/05/GHSA-8w6q-4mh2-p2gh/GHSA-8w6q-4mh2-p2gh.json new file mode 100644 index 00000000000..8f4454f0cf5 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8w6q-4mh2-p2gh/GHSA-8w6q-4mh2-p2gh.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8w6q-4mh2-p2gh", + "modified": "2025-05-30T06:30:25Z", + "published": "2025-05-30T06:30:25Z", + "aliases": [ + "CVE-2025-4429" + ], + "details": "The Gearside Developer Dashboard WordPress plugin through 1.0.72 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4429" + }, + { + "type": "WEB", + "url": "https://wpscan.com/vulnerability/a487f5c9-7db6-4427-8d95-17acbfd49fd2" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-30T06:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9r89-rh23-vf6r/GHSA-9r89-rh23-vf6r.json b/advisories/unreviewed/2025/05/GHSA-9r89-rh23-vf6r/GHSA-9r89-rh23-vf6r.json new file mode 100644 index 00000000000..3621aa95a99 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9r89-rh23-vf6r/GHSA-9r89-rh23-vf6r.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9r89-rh23-vf6r", + "modified": "2025-05-30T06:30:24Z", + "published": "2025-05-30T06:30:24Z", + "aliases": [ + "CVE-2025-44905" + ], + "details": "hdf5 v1.14.6 was discovered to contain a heap buffer overflow via the H5Z__filter_scaleoffset function.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44905" + }, + { + "type": "WEB", + "url": "https://github.com/madao123123/crash_report/blob/main/hdf5_poc/hdf5_poc5.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-30T04:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-qj62-4grm-wg6v/GHSA-qj62-4grm-wg6v.json b/advisories/unreviewed/2025/05/GHSA-qj62-4grm-wg6v/GHSA-qj62-4grm-wg6v.json new file mode 100644 index 00000000000..5afc9d6d126 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-qj62-4grm-wg6v/GHSA-qj62-4grm-wg6v.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qj62-4grm-wg6v", + "modified": "2025-05-30T06:30:25Z", + "published": "2025-05-30T06:30:25Z", + "aliases": [ + "CVE-2025-4659" + ], + "details": "The Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.4.4. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4659" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3299864" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/a99456c4-c828-4dc9-9375-8981eafbeb15?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-30T06:15:28Z" + } +} \ No newline at end of file