From b1c45b4537447b56b16a8345bc0fd030b45ae083 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 5 Feb 2025 12:35:00 +0000 Subject: [PATCH] Publish Advisories GHSA-4rf9-gv7f-cc74 GHSA-4rw8-6238-r9gq GHSA-53g3-q2ww-hf74 GHSA-89fg-r5w5-hh2w GHSA-c42g-rmxf-64ch GHSA-cc57-hgv8-p56r GHSA-cgvr-gqfv-x5mj GHSA-f3j9-rq93-g9jv GHSA-gvg6-gvpx-66f6 GHSA-mjxq-9q7r-qmc7 GHSA-px4x-cjpp-hqv5 GHSA-rfm6-5393-x9wf GHSA-v3q6-3rrv-r75p GHSA-vvqh-cqpj-5537 GHSA-vxw5-rxj4-h92f --- .../GHSA-4rf9-gv7f-cc74.json | 40 ++++++++++++++ .../GHSA-4rw8-6238-r9gq.json | 53 +++++++++++++++++++ .../GHSA-53g3-q2ww-hf74.json | 36 +++++++++++++ .../GHSA-89fg-r5w5-hh2w.json | 40 ++++++++++++++ .../GHSA-c42g-rmxf-64ch.json | 37 +++++++++++++ .../GHSA-cc57-hgv8-p56r.json | 41 ++++++++++++++ .../GHSA-cgvr-gqfv-x5mj.json | 45 ++++++++++++++++ .../GHSA-f3j9-rq93-g9jv.json | 36 +++++++++++++ .../GHSA-gvg6-gvpx-66f6.json | 40 ++++++++++++++ .../GHSA-mjxq-9q7r-qmc7.json | 36 +++++++++++++ .../GHSA-px4x-cjpp-hqv5.json | 40 ++++++++++++++ .../GHSA-rfm6-5393-x9wf.json | 40 ++++++++++++++ .../GHSA-v3q6-3rrv-r75p.json | 36 +++++++++++++ .../GHSA-vvqh-cqpj-5537.json | 41 ++++++++++++++ .../GHSA-vxw5-rxj4-h92f.json | 40 ++++++++++++++ 15 files changed, 601 insertions(+) create mode 100644 advisories/unreviewed/2025/02/GHSA-4rf9-gv7f-cc74/GHSA-4rf9-gv7f-cc74.json create mode 100644 advisories/unreviewed/2025/02/GHSA-4rw8-6238-r9gq/GHSA-4rw8-6238-r9gq.json create mode 100644 advisories/unreviewed/2025/02/GHSA-53g3-q2ww-hf74/GHSA-53g3-q2ww-hf74.json create mode 100644 advisories/unreviewed/2025/02/GHSA-89fg-r5w5-hh2w/GHSA-89fg-r5w5-hh2w.json create mode 100644 advisories/unreviewed/2025/02/GHSA-c42g-rmxf-64ch/GHSA-c42g-rmxf-64ch.json create mode 100644 advisories/unreviewed/2025/02/GHSA-cc57-hgv8-p56r/GHSA-cc57-hgv8-p56r.json create mode 100644 advisories/unreviewed/2025/02/GHSA-cgvr-gqfv-x5mj/GHSA-cgvr-gqfv-x5mj.json create mode 100644 advisories/unreviewed/2025/02/GHSA-f3j9-rq93-g9jv/GHSA-f3j9-rq93-g9jv.json create mode 100644 advisories/unreviewed/2025/02/GHSA-gvg6-gvpx-66f6/GHSA-gvg6-gvpx-66f6.json create mode 100644 advisories/unreviewed/2025/02/GHSA-mjxq-9q7r-qmc7/GHSA-mjxq-9q7r-qmc7.json create mode 100644 advisories/unreviewed/2025/02/GHSA-px4x-cjpp-hqv5/GHSA-px4x-cjpp-hqv5.json create mode 100644 advisories/unreviewed/2025/02/GHSA-rfm6-5393-x9wf/GHSA-rfm6-5393-x9wf.json create mode 100644 advisories/unreviewed/2025/02/GHSA-v3q6-3rrv-r75p/GHSA-v3q6-3rrv-r75p.json create mode 100644 advisories/unreviewed/2025/02/GHSA-vvqh-cqpj-5537/GHSA-vvqh-cqpj-5537.json create mode 100644 advisories/unreviewed/2025/02/GHSA-vxw5-rxj4-h92f/GHSA-vxw5-rxj4-h92f.json diff --git a/advisories/unreviewed/2025/02/GHSA-4rf9-gv7f-cc74/GHSA-4rf9-gv7f-cc74.json b/advisories/unreviewed/2025/02/GHSA-4rf9-gv7f-cc74/GHSA-4rf9-gv7f-cc74.json new file mode 100644 index 00000000000..cbebbfe24ee --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-4rf9-gv7f-cc74/GHSA-4rf9-gv7f-cc74.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4rf9-gv7f-cc74", + "modified": "2025-02-05T12:33:07Z", + "published": "2025-02-05T12:33:07Z", + "aliases": [ + "CVE-2024-1539" + ], + "details": "An issue has been discovered in GitLab EE affecting all versions starting from 15.2 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. It was possible to disclose updates to issues to a banned group member using the API.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-1539" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2369988" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/442049" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-05T10:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-4rw8-6238-r9gq/GHSA-4rw8-6238-r9gq.json b/advisories/unreviewed/2025/02/GHSA-4rw8-6238-r9gq/GHSA-4rw8-6238-r9gq.json new file mode 100644 index 00000000000..17cfd789867 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-4rw8-6238-r9gq/GHSA-4rw8-6238-r9gq.json @@ -0,0 +1,53 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4rw8-6238-r9gq", + "modified": "2025-02-05T12:33:06Z", + "published": "2025-02-05T12:33:06Z", + "aliases": [ + "CVE-2023-52924" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: don't skip expired elements during walk\n\nThere is an asymmetry between commit/abort and preparation phase if the\nfollowing conditions are met:\n\n1. set is a verdict map (\"1.2.3.4 : jump foo\")\n2. timeouts are enabled\n\nIn this case, following sequence is problematic:\n\n1. element E in set S refers to chain C\n2. userspace requests removal of set S\n3. kernel does a set walk to decrement chain->use count for all elements\n from preparation phase\n4. kernel does another set walk to remove elements from the commit phase\n (or another walk to do a chain->use increment for all elements from\n abort phase)\n\nIf E has already expired in 1), it will be ignored during list walk, so its use count\nwon't have been changed.\n\nThen, when set is culled, ->destroy callback will zap the element via\nnf_tables_set_elem_destroy(), but this function is only safe for\nelements that have been deactivated earlier from the preparation phase:\nlack of earlier deactivate removes the element but leaks the chain use\ncount, which results in a WARN splat when the chain gets removed later,\nplus a leak of the nft_chain structure.\n\nUpdate pipapo_get() not to skip expired elements, otherwise flush\ncommand reports bogus ENOENT errors.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52924" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/1da4874d05da1526b11b82fc7f3c7ac38749ddf8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/24138933b97b055d486e8064b4a1721702442a9b" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/59dab3bf0b8fc08eb802721c0532f13dd89209b8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7c7e658a36f8b1522bd3586d8137e5f93a25ddc5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/94313a196b44184b5b52c1876da6a537701b425a" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/b15ea4017af82011dd55225ce77cce3d4dfc169c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bd156ce9553dcaf2d6ee2c825d1a5a1718e86524" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-05T10:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-53g3-q2ww-hf74/GHSA-53g3-q2ww-hf74.json b/advisories/unreviewed/2025/02/GHSA-53g3-q2ww-hf74/GHSA-53g3-q2ww-hf74.json new file mode 100644 index 00000000000..3a52f0e474f --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-53g3-q2ww-hf74/GHSA-53g3-q2ww-hf74.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-53g3-q2ww-hf74", + "modified": "2025-02-05T12:33:07Z", + "published": "2025-02-05T12:33:07Z", + "aliases": [ + "CVE-2024-52365" + ], + "details": "IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 \n\nis vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52365" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7182403" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-05T12:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-89fg-r5w5-hh2w/GHSA-89fg-r5w5-hh2w.json b/advisories/unreviewed/2025/02/GHSA-89fg-r5w5-hh2w/GHSA-89fg-r5w5-hh2w.json new file mode 100644 index 00000000000..3d59d7e4ae6 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-89fg-r5w5-hh2w/GHSA-89fg-r5w5-hh2w.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-89fg-r5w5-hh2w", + "modified": "2025-02-05T12:33:07Z", + "published": "2025-02-05T12:33:07Z", + "aliases": [ + "CVE-2024-5528" + ], + "details": "An issue was discovered in GitLab CE/EE affecting all versions prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2, which allows a subdomain takeover in GitLab Pages.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5528" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2523654" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/464558" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1023" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-05T11:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-c42g-rmxf-64ch/GHSA-c42g-rmxf-64ch.json b/advisories/unreviewed/2025/02/GHSA-c42g-rmxf-64ch/GHSA-c42g-rmxf-64ch.json new file mode 100644 index 00000000000..3f95b8d0975 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-c42g-rmxf-64ch/GHSA-c42g-rmxf-64ch.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c42g-rmxf-64ch", + "modified": "2025-02-05T12:33:07Z", + "published": "2025-02-05T12:33:07Z", + "aliases": [ + "CVE-2025-0167" + ], + "details": "When asked to use a `.netrc` file for credentials **and** to follow HTTP\nredirects, curl could leak the password used for the first host to the\nfollowed-to host under certain circumstances.\n\nThis flaw only manifests itself if the netrc file has a `default` entry that\nomits both login and password. A rare circumstance.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0167" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2917232" + }, + { + "type": "WEB", + "url": "https://curl.se/docs/CVE-2025-0167.html" + }, + { + "type": "WEB", + "url": "https://curl.se/docs/CVE-2025-0167.json" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-05T10:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-cc57-hgv8-p56r/GHSA-cc57-hgv8-p56r.json b/advisories/unreviewed/2025/02/GHSA-cc57-hgv8-p56r/GHSA-cc57-hgv8-p56r.json new file mode 100644 index 00000000000..37fdb727bb9 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-cc57-hgv8-p56r/GHSA-cc57-hgv8-p56r.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cc57-hgv8-p56r", + "modified": "2025-02-05T12:33:07Z", + "published": "2025-02-05T12:33:07Z", + "aliases": [ + "CVE-2025-0665" + ], + "details": "libcurl would wrongly close the same eventfd file descriptor twice when taking\ndown a connection channel after having completed a threaded name resolve.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0665" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2954286" + }, + { + "type": "WEB", + "url": "https://curl.se/docs/CVE-2025-0665.html" + }, + { + "type": "WEB", + "url": "https://curl.se/docs/CVE-2025-0665.json" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/02/05/2" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-05T10:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-cgvr-gqfv-x5mj/GHSA-cgvr-gqfv-x5mj.json b/advisories/unreviewed/2025/02/GHSA-cgvr-gqfv-x5mj/GHSA-cgvr-gqfv-x5mj.json new file mode 100644 index 00000000000..8c1678bece7 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-cgvr-gqfv-x5mj/GHSA-cgvr-gqfv-x5mj.json @@ -0,0 +1,45 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cgvr-gqfv-x5mj", + "modified": "2025-02-05T12:33:06Z", + "published": "2025-02-05T12:33:06Z", + "aliases": [ + "CVE-2023-52925" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: don't fail inserts if duplicate has expired\n\nnftables selftests fail:\nrun-tests.sh testcases/sets/0044interval_overlap_0\nExpected: 0-2 . 0-3, got:\nW: [FAILED] ./testcases/sets/0044interval_overlap_0: got 1\n\nInsertion must ignore duplicate but expired entries.\n\nMoreover, there is a strange asymmetry in nft_pipapo_activate:\n\nIt refetches the current element, whereas the other ->activate callbacks\n(bitmap, hash, rhash, rbtree) use elem->priv.\nSame for .remove: other set implementations take elem->priv,\nnft_pipapo_remove fetches elem->priv, then does a relookup,\nremove this.\n\nI suspect this was the reason for the change that prompted the\nremoval of the expired check in pipapo_get() in the first place,\nbut skipping exired elements there makes no sense to me, this helper\nis used for normal get requests, insertions (duplicate check)\nand deactivate callback.\n\nIn first two cases expired elements must be skipped.\n\nFor ->deactivate(), this gets called for DELSETELEM, so it\nseems to me that expired elements should be skipped as well, i.e.\ndelete request should fail with -ENOENT error.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-52925" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/156369a702c33ad5434a19c3a689bfb836d4e0b8" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/59ee68c437c562170265194a99698c805a686bb3" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/7845914f45f066497ac75b30c50dbc735e84e884" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/891ca5dfe3b718b441fc786014a7ba8f517da188" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/af78b0489e8898a8c9449ffc0fdd2e181916f0d4" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-05T10:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-f3j9-rq93-g9jv/GHSA-f3j9-rq93-g9jv.json b/advisories/unreviewed/2025/02/GHSA-f3j9-rq93-g9jv/GHSA-f3j9-rq93-g9jv.json new file mode 100644 index 00000000000..bd7df5eb182 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-f3j9-rq93-g9jv/GHSA-f3j9-rq93-g9jv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f3j9-rq93-g9jv", + "modified": "2025-02-05T12:33:07Z", + "published": "2025-02-05T12:33:07Z", + "aliases": [ + "CVE-2024-49352" + ], + "details": "IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49352" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7181480" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-611" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-05T11:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-gvg6-gvpx-66f6/GHSA-gvg6-gvpx-66f6.json b/advisories/unreviewed/2025/02/GHSA-gvg6-gvpx-66f6/GHSA-gvg6-gvpx-66f6.json new file mode 100644 index 00000000000..b7c187863fb --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-gvg6-gvpx-66f6/GHSA-gvg6-gvpx-66f6.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gvg6-gvpx-66f6", + "modified": "2025-02-05T12:33:06Z", + "published": "2025-02-05T12:33:06Z", + "aliases": [ + "CVE-2024-6356" + ], + "details": "An issue was discovered in GitLab EE affecting all versions starting from 16.0 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2, which allowed cross project access for Security policy bot.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6356" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2575051" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/469108" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-286" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-05T10:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-mjxq-9q7r-qmc7/GHSA-mjxq-9q7r-qmc7.json b/advisories/unreviewed/2025/02/GHSA-mjxq-9q7r-qmc7/GHSA-mjxq-9q7r-qmc7.json new file mode 100644 index 00000000000..7dc44c0e3fa --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-mjxq-9q7r-qmc7/GHSA-mjxq-9q7r-qmc7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mjxq-9q7r-qmc7", + "modified": "2025-02-05T12:33:07Z", + "published": "2025-02-05T12:33:07Z", + "aliases": [ + "CVE-2024-52364" + ], + "details": "IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52364" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7182403" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-05T12:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-px4x-cjpp-hqv5/GHSA-px4x-cjpp-hqv5.json b/advisories/unreviewed/2025/02/GHSA-px4x-cjpp-hqv5/GHSA-px4x-cjpp-hqv5.json new file mode 100644 index 00000000000..f2c670cb995 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-px4x-cjpp-hqv5/GHSA-px4x-cjpp-hqv5.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-px4x-cjpp-hqv5", + "modified": "2025-02-05T12:33:07Z", + "published": "2025-02-05T12:33:07Z", + "aliases": [ + "CVE-2024-3976" + ], + "details": "An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.0 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. It was possible to disclose via the UI the confidential issues title and description from a public project to unauthorised instance users.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-3976" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2470939" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/457140" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-05T12:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-rfm6-5393-x9wf/GHSA-rfm6-5393-x9wf.json b/advisories/unreviewed/2025/02/GHSA-rfm6-5393-x9wf/GHSA-rfm6-5393-x9wf.json new file mode 100644 index 00000000000..f158b68c8c7 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-rfm6-5393-x9wf/GHSA-rfm6-5393-x9wf.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rfm6-5393-x9wf", + "modified": "2025-02-05T12:33:07Z", + "published": "2025-02-05T12:33:07Z", + "aliases": [ + "CVE-2024-9631" + ], + "details": "An issue was discovered in GitLab CE/EE affecting all versions starting from 13.6 prior to 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4 prior to 17.4.2, where viewing diffs of MR with conflicts can be slow.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-9631" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2650086" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/480867" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-407" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-05T11:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-v3q6-3rrv-r75p/GHSA-v3q6-3rrv-r75p.json b/advisories/unreviewed/2025/02/GHSA-v3q6-3rrv-r75p/GHSA-v3q6-3rrv-r75p.json new file mode 100644 index 00000000000..45bb71902f7 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-v3q6-3rrv-r75p/GHSA-v3q6-3rrv-r75p.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v3q6-3rrv-r75p", + "modified": "2025-02-05T12:33:07Z", + "published": "2025-02-05T12:33:07Z", + "aliases": [ + "CVE-2024-49348" + ], + "details": "IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 \n\n\n\nallows restricting access to organizational data to valid contexts. The fact that tasks of type comment can be reassigned via API implicitly grants access to user queries in an unexpected context.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49348" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7182403" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-05T12:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-vvqh-cqpj-5537/GHSA-vvqh-cqpj-5537.json b/advisories/unreviewed/2025/02/GHSA-vvqh-cqpj-5537/GHSA-vvqh-cqpj-5537.json new file mode 100644 index 00000000000..2d385486ccd --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-vvqh-cqpj-5537/GHSA-vvqh-cqpj-5537.json @@ -0,0 +1,41 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vvqh-cqpj-5537", + "modified": "2025-02-05T12:33:07Z", + "published": "2025-02-05T12:33:07Z", + "aliases": [ + "CVE-2025-0725" + ], + "details": "When libcurl is asked to perform automatic gzip decompression of\ncontent-encoded HTTP responses with the `CURLOPT_ACCEPT_ENCODING` option,\n**using zlib 1.2.0.3 or older**, an attacker-controlled integer overflow would\nmake libcurl perform a buffer overflow.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0725" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2956023" + }, + { + "type": "WEB", + "url": "https://curl.se/docs/CVE-2025-0725.html" + }, + { + "type": "WEB", + "url": "https://curl.se/docs/CVE-2025-0725.json" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/02/05/3" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-05T10:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-vxw5-rxj4-h92f/GHSA-vxw5-rxj4-h92f.json b/advisories/unreviewed/2025/02/GHSA-vxw5-rxj4-h92f/GHSA-vxw5-rxj4-h92f.json new file mode 100644 index 00000000000..098503b2869 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-vxw5-rxj4-h92f/GHSA-vxw5-rxj4-h92f.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vxw5-rxj4-h92f", + "modified": "2025-02-05T12:33:07Z", + "published": "2025-02-05T12:33:06Z", + "aliases": [ + "CVE-2023-6386" + ], + "details": "A denial of service vulnerability was identified in GitLab CE/EE, affecting all versions from 15.11 prior to 16.6.7, 16.7 prior to 16.7.5 and 16.8 prior to 16.8.2 which allows an attacker to spike the GitLab instance resource usage resulting in service degradation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6386" + }, + { + "type": "WEB", + "url": "https://hackerone.com/reports/2261581" + }, + { + "type": "WEB", + "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/433147" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-770" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-05T10:15:22Z" + } +} \ No newline at end of file