diff --git a/advisories/github-reviewed/2025/01/GHSA-4g52-pq8j-6qv5/GHSA-4g52-pq8j-6qv5.json b/advisories/github-reviewed/2025/01/GHSA-4g52-pq8j-6qv5/GHSA-4g52-pq8j-6qv5.json index 8cb62421d4e..14e17f2b647 100644 --- a/advisories/github-reviewed/2025/01/GHSA-4g52-pq8j-6qv5/GHSA-4g52-pq8j-6qv5.json +++ b/advisories/github-reviewed/2025/01/GHSA-4g52-pq8j-6qv5/GHSA-4g52-pq8j-6qv5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4g52-pq8j-6qv5", - "modified": "2025-01-14T15:40:07Z", + "modified": "2025-01-14T22:01:25Z", "published": "2025-01-14T15:40:07Z", "aliases": [ "CVE-2024-55921" @@ -109,6 +109,10 @@ "type": "WEB", "url": "https://github.com/TYPO3/typo3/security/advisories/GHSA-4g52-pq8j-6qv5" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55921" + }, { "type": "WEB", "url": "https://github.com/TYPO3-CMS/extensionmanager/commit/a5a58626dcb2af0c31bc6aec068e3d24e789b9e8" @@ -130,6 +134,6 @@ "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2025-01-14T15:40:07Z", - "nvd_published_at": null + "nvd_published_at": "2025-01-14T20:15:29Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-5wjw-h8x5-v65m/GHSA-5wjw-h8x5-v65m.json b/advisories/github-reviewed/2025/01/GHSA-5wjw-h8x5-v65m/GHSA-5wjw-h8x5-v65m.json similarity index 63% rename from advisories/unreviewed/2025/01/GHSA-5wjw-h8x5-v65m/GHSA-5wjw-h8x5-v65m.json rename to advisories/github-reviewed/2025/01/GHSA-5wjw-h8x5-v65m/GHSA-5wjw-h8x5-v65m.json index 382b5c5d0c6..ad26864c722 100644 --- a/advisories/unreviewed/2025/01/GHSA-5wjw-h8x5-v65m/GHSA-5wjw-h8x5-v65m.json +++ b/advisories/github-reviewed/2025/01/GHSA-5wjw-h8x5-v65m/GHSA-5wjw-h8x5-v65m.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-5wjw-h8x5-v65m", - "modified": "2025-01-14T18:32:06Z", + "modified": "2025-01-14T22:02:40Z", "published": "2025-01-14T18:32:06Z", "aliases": [ "CVE-2025-23366" ], + "summary": " Wildfly HAL Console Cross-Site Scripting", "details": "A flaw was found in the HAL Console in the Wildfly component, which does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output used as a web page that is served to other users. The attacker must be authenticated as a user that belongs to management groups “SuperUser”, “Admin”, or “Maintainer”.", "severity": [ { @@ -13,7 +14,27 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N" } ], - "affected": [], + "affected": [ + { + "package": { + "ecosystem": "Maven", + "name": "org.jboss.hal:hal-console" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "last_affected": "3.7.7.Final" + } + ] + } + ] + } + ], "references": [ { "type": "ADVISORY", @@ -26,6 +47,10 @@ { "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2337619" + }, + { + "type": "PACKAGE", + "url": "https://github.com/hal/console" } ], "database_specific": { @@ -33,8 +58,8 @@ "CWE-79" ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2025-01-14T22:02:40Z", "nvd_published_at": "2025-01-14T18:16:06Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2025/01/GHSA-6w4x-gcx3-8p7v/GHSA-6w4x-gcx3-8p7v.json b/advisories/github-reviewed/2025/01/GHSA-6w4x-gcx3-8p7v/GHSA-6w4x-gcx3-8p7v.json index b8d2872e1cd..267fc2128c6 100644 --- a/advisories/github-reviewed/2025/01/GHSA-6w4x-gcx3-8p7v/GHSA-6w4x-gcx3-8p7v.json +++ b/advisories/github-reviewed/2025/01/GHSA-6w4x-gcx3-8p7v/GHSA-6w4x-gcx3-8p7v.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6w4x-gcx3-8p7v", - "modified": "2025-01-14T15:25:04Z", + "modified": "2025-01-14T22:01:06Z", "published": "2025-01-14T15:25:04Z", "aliases": [ "CVE-2024-55894" @@ -109,6 +109,10 @@ "type": "WEB", "url": "https://github.com/TYPO3/typo3/security/advisories/GHSA-6w4x-gcx3-8p7v" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55894" + }, { "type": "WEB", "url": "https://github.com/TYPO3-CMS/beuser/commit/1bb317cb2bc0b2f6ba4f758a088f060b36c67f9d" @@ -130,6 +134,6 @@ "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2025-01-14T15:25:04Z", - "nvd_published_at": null + "nvd_published_at": "2025-01-14T20:15:29Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2025/01/GHSA-7835-fcv3-g256/GHSA-7835-fcv3-g256.json b/advisories/github-reviewed/2025/01/GHSA-7835-fcv3-g256/GHSA-7835-fcv3-g256.json index c9e55740ca4..6594a3d0876 100644 --- a/advisories/github-reviewed/2025/01/GHSA-7835-fcv3-g256/GHSA-7835-fcv3-g256.json +++ b/advisories/github-reviewed/2025/01/GHSA-7835-fcv3-g256/GHSA-7835-fcv3-g256.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7835-fcv3-g256", - "modified": "2025-01-14T15:42:12Z", + "modified": "2025-01-14T22:01:55Z", "published": "2025-01-14T15:42:12Z", "aliases": [ "CVE-2024-55924" @@ -43,6 +43,10 @@ "type": "WEB", "url": "https://github.com/TYPO3/typo3/security/advisories/GHSA-7835-fcv3-g256" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55924" + }, { "type": "PACKAGE", "url": "https://github.com/TYPO3-CMS/scheduler" @@ -60,6 +64,6 @@ "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2025-01-14T15:42:12Z", - "nvd_published_at": null + "nvd_published_at": "2025-01-14T20:15:30Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2025/01/GHSA-7r5q-4qgx-v545/GHSA-7r5q-4qgx-v545.json b/advisories/github-reviewed/2025/01/GHSA-7r5q-4qgx-v545/GHSA-7r5q-4qgx-v545.json index 28862929651..ab30519069f 100644 --- a/advisories/github-reviewed/2025/01/GHSA-7r5q-4qgx-v545/GHSA-7r5q-4qgx-v545.json +++ b/advisories/github-reviewed/2025/01/GHSA-7r5q-4qgx-v545/GHSA-7r5q-4qgx-v545.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7r5q-4qgx-v545", - "modified": "2025-01-14T15:40:59Z", + "modified": "2025-01-14T22:01:47Z", "published": "2025-01-14T15:40:59Z", "aliases": [ "CVE-2024-55923" @@ -109,6 +109,10 @@ "type": "WEB", "url": "https://github.com/TYPO3/typo3/security/advisories/GHSA-7r5q-4qgx-v545" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55923" + }, { "type": "WEB", "url": "https://github.com/TYPO3-CMS/indexed_search/commit/cfda3f1edeea3c50034bce5c25393e297408c2b4" @@ -130,6 +134,6 @@ "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2025-01-14T15:40:59Z", - "nvd_published_at": null + "nvd_published_at": "2025-01-14T20:15:30Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2025/01/GHSA-8mv3-37rc-pvxj/GHSA-8mv3-37rc-pvxj.json b/advisories/github-reviewed/2025/01/GHSA-8mv3-37rc-pvxj/GHSA-8mv3-37rc-pvxj.json index 0b3b0c56f4e..f89f593877e 100644 --- a/advisories/github-reviewed/2025/01/GHSA-8mv3-37rc-pvxj/GHSA-8mv3-37rc-pvxj.json +++ b/advisories/github-reviewed/2025/01/GHSA-8mv3-37rc-pvxj/GHSA-8mv3-37rc-pvxj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8mv3-37rc-pvxj", - "modified": "2025-01-14T15:42:50Z", + "modified": "2025-01-14T22:02:04Z", "published": "2025-01-14T15:42:50Z", "aliases": [ "CVE-2024-55945" @@ -43,6 +43,10 @@ "type": "WEB", "url": "https://github.com/TYPO3/typo3/security/advisories/GHSA-8mv3-37rc-pvxj" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55945" + }, { "type": "PACKAGE", "url": "https://github.com/TYPO3-CMS/lowlevel" @@ -60,6 +64,6 @@ "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2025-01-14T15:42:50Z", - "nvd_published_at": null + "nvd_published_at": "2025-01-14T20:15:30Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2025/01/GHSA-j2jg-fq62-7c3h/GHSA-j2jg-fq62-7c3h.json b/advisories/github-reviewed/2025/01/GHSA-j2jg-fq62-7c3h/GHSA-j2jg-fq62-7c3h.json index a1edf896ec0..52921a8de03 100644 --- a/advisories/github-reviewed/2025/01/GHSA-j2jg-fq62-7c3h/GHSA-j2jg-fq62-7c3h.json +++ b/advisories/github-reviewed/2025/01/GHSA-j2jg-fq62-7c3h/GHSA-j2jg-fq62-7c3h.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j2jg-fq62-7c3h", - "modified": "2025-01-14T17:16:53Z", + "modified": "2025-01-14T22:02:17Z", "published": "2025-01-14T16:32:22Z", "aliases": [ "CVE-2025-23042" @@ -40,6 +40,10 @@ "type": "WEB", "url": "https://github.com/gradio-app/gradio/security/advisories/GHSA-j2jg-fq62-7c3h" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23042" + }, { "type": "WEB", "url": "https://github.com/gradio-app/gradio/commit/6b63fdec441b5c9bf910f910a2505d8defbb6bf8" @@ -55,11 +59,12 @@ ], "database_specific": { "cwe_ids": [ - "CWE-178" + "CWE-178", + "CWE-285" ], "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2025-01-14T16:32:22Z", - "nvd_published_at": null + "nvd_published_at": "2025-01-14T19:15:44Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2025/01/GHSA-qwx7-39pw-2mhr/GHSA-qwx7-39pw-2mhr.json b/advisories/github-reviewed/2025/01/GHSA-qwx7-39pw-2mhr/GHSA-qwx7-39pw-2mhr.json index a272d893d06..1eefd48a9ef 100644 --- a/advisories/github-reviewed/2025/01/GHSA-qwx7-39pw-2mhr/GHSA-qwx7-39pw-2mhr.json +++ b/advisories/github-reviewed/2025/01/GHSA-qwx7-39pw-2mhr/GHSA-qwx7-39pw-2mhr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qwx7-39pw-2mhr", - "modified": "2025-01-14T15:25:45Z", + "modified": "2025-01-14T22:01:15Z", "published": "2025-01-14T15:25:45Z", "aliases": [ "CVE-2024-55920" @@ -109,6 +109,10 @@ "type": "WEB", "url": "https://github.com/TYPO3/typo3/security/advisories/GHSA-qwx7-39pw-2mhr" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55920" + }, { "type": "WEB", "url": "https://github.com/TYPO3-CMS/dashboard/commit/c2e5dbdda87387ad9ee2ff8ca986d41dd9424875" @@ -130,6 +134,6 @@ "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2025-01-14T15:25:45Z", - "nvd_published_at": null + "nvd_published_at": "2025-01-14T20:15:29Z" } } \ No newline at end of file diff --git a/advisories/github-reviewed/2025/01/GHSA-ww7h-g2qf-7xv6/GHSA-ww7h-g2qf-7xv6.json b/advisories/github-reviewed/2025/01/GHSA-ww7h-g2qf-7xv6/GHSA-ww7h-g2qf-7xv6.json index eb0b52f44e3..91e20f11f14 100644 --- a/advisories/github-reviewed/2025/01/GHSA-ww7h-g2qf-7xv6/GHSA-ww7h-g2qf-7xv6.json +++ b/advisories/github-reviewed/2025/01/GHSA-ww7h-g2qf-7xv6/GHSA-ww7h-g2qf-7xv6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-ww7h-g2qf-7xv6", - "modified": "2025-01-14T15:40:37Z", + "modified": "2025-01-14T22:01:38Z", "published": "2025-01-14T15:40:37Z", "aliases": [ "CVE-2024-55922" @@ -109,6 +109,10 @@ "type": "WEB", "url": "https://github.com/TYPO3/typo3/security/advisories/GHSA-ww7h-g2qf-7xv6" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55922" + }, { "type": "WEB", "url": "https://github.com/TYPO3-CMS/form/commit/93327743f5dfd31c44898ce16e3e004e05f8ba5f" @@ -130,6 +134,6 @@ "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2025-01-14T15:40:37Z", - "nvd_published_at": null + "nvd_published_at": "2025-01-14T20:15:30Z" } } \ No newline at end of file