Publish Advisories

GHSA-4xpw-6594-8f5m
GHSA-37m8-vrcv-2x3f
GHSA-6f6h-2hc4-8gjc
GHSA-794f-v4rm-x7r5
GHSA-fvp7-w3vq-22p7
GHSA-g2vc-w9mc-h6ch
GHSA-mmfm-hc46-3944
GHSA-qgfc-q68c-8fgx
This commit is contained in:
advisory-database[bot]
2025-04-25 03:32:14 +00:00
parent 8727e824c5
commit b5b537849b
8 changed files with 243 additions and 3 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-4xpw-6594-8f5m",
"modified": "2025-04-13T06:30:33Z",
"modified": "2025-04-25T03:30:33Z",
"published": "2025-01-22T15:32:34Z",
"aliases": [
"CVE-2025-0395"
@@ -50,6 +50,10 @@
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2025/04/13/1"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2025/04/24/7"
}
],
"database_specific": {
@@ -0,0 +1,48 @@
{
"schema_version": "1.4.0",
"id": "GHSA-37m8-vrcv-2x3f",
"modified": "2025-04-25T03:30:34Z",
"published": "2025-04-25T03:30:34Z",
"aliases": [
"CVE-2025-46545"
],
"details": "In Sherpa Orchestrator 141851, the functionality for adding or updating licenses allows for stored XSS attacks by an administrator through the name parameter. The XSS payload can execute when the license expires.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46545"
},
{
"type": "WEB",
"url": "https://deiteriy.com"
},
{
"type": "WEB",
"url": "https://gist.github.com/ArtemBrylev/5a0c76285d5fa9daf4ec753034185de7"
},
{
"type": "WEB",
"url": "https://sherparpa.com"
},
{
"type": "WEB",
"url": "https://twitter.com/ArtyomBrylev"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-25T03:15:20Z"
}
}
@@ -0,0 +1,48 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6f6h-2hc4-8gjc",
"modified": "2025-04-25T03:30:34Z",
"published": "2025-04-25T03:30:34Z",
"aliases": [
"CVE-2025-46544"
],
"details": "In Sherpa Orchestrator 141851, a low-privileged user can elevate their privileges by creating new users and roles.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46544"
},
{
"type": "WEB",
"url": "https://deiteriy.com"
},
{
"type": "WEB",
"url": "https://gist.github.com/ArtemBrylev/a258f920a6556470951c9a483fcf194a"
},
{
"type": "WEB",
"url": "https://sherparpa.com"
},
{
"type": "WEB",
"url": "https://twitter.com/ArtyomBrylev"
}
],
"database_specific": {
"cwe_ids": [
"CWE-863"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-25T03:15:19Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-794f-v4rm-x7r5",
"modified": "2025-04-24T21:31:47Z",
"modified": "2025-04-25T03:30:33Z",
"published": "2025-04-11T09:30:24Z",
"aliases": [
"CVE-2025-3512"
@@ -34,6 +34,10 @@
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2025/04/24/6"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2025/04/25/1"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fvp7-w3vq-22p7",
"modified": "2025-04-23T21:30:35Z",
"modified": "2025-04-25T03:30:33Z",
"published": "2025-04-23T18:31:00Z",
"aliases": [
"CVE-2025-3900"
@@ -19,6 +19,10 @@
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3900"
},
{
"type": "WEB",
"url": "https://backdropcms.org/security/backdrop-sa-contrib-2025-012"
},
{
"type": "WEB",
"url": "https://www.drupal.org/sa-contrib-2025-041"
@@ -0,0 +1,48 @@
{
"schema_version": "1.4.0",
"id": "GHSA-g2vc-w9mc-h6ch",
"modified": "2025-04-25T03:30:34Z",
"published": "2025-04-25T03:30:34Z",
"aliases": [
"CVE-2025-46547"
],
"details": "In Sherpa Orchestrator 141851, the web application lacks protection against CSRF attacks, with resultant effects of an attacker conducting XSS attacks, adding a new user or role, or exploiting a SQL injection issue.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46547"
},
{
"type": "WEB",
"url": "https://deiteriy.com"
},
{
"type": "WEB",
"url": "https://gist.github.com/ArtemBrylev/9af206c46d7505db03ad6fcd9fc46f7f"
},
{
"type": "WEB",
"url": "https://sherparpa.com"
},
{
"type": "WEB",
"url": "https://twitter.com/ArtyomBrylev"
}
],
"database_specific": {
"cwe_ids": [
"CWE-352"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-25T03:15:20Z"
}
}
@@ -0,0 +1,48 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mmfm-hc46-3944",
"modified": "2025-04-25T03:30:34Z",
"published": "2025-04-25T03:30:34Z",
"aliases": [
"CVE-2025-46546"
],
"details": "In Sherpa Orchestrator 141851, multiple time-based blind SQL injections can be performed by an authenticated user. This affects api/gui/asset/list, /api/gui/files/export/csv/, /api/gui/files/list, /api/gui/process/export/csv, /api/gui/process/export/xlsx, /api/gui/process/listAll, /api/gui/processVersion/export/csv/, /api/gui/processVersion/export/xlsx/, /api/gui/processVersion/list/, /api/gui/robot/list/, /api/gui/task/export/csv/, /api/gui/task/export/xlsx/, and /api/gui/task/list/.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46546"
},
{
"type": "WEB",
"url": "https://deiteriy.com"
},
{
"type": "WEB",
"url": "https://gist.github.com/ArtemBrylev/59b4c0825a988f39a58b79e4e8d2f378"
},
{
"type": "WEB",
"url": "https://sherparpa.com"
},
{
"type": "WEB",
"url": "https://twitter.com/ArtyomBrylev"
}
],
"database_specific": {
"cwe_ids": [
"CWE-89"
],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-25T03:15:20Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qgfc-q68c-8fgx",
"modified": "2025-04-25T03:30:34Z",
"published": "2025-04-25T03:30:34Z",
"aliases": [
"CVE-2025-46595"
],
"details": "An XSS issue was discovered in the Flag module before 1.x-3.6.2 for Backdrop CMS. Flag is a module that allows flags to be added to nodes, comments, users, and any other type of entity. It doesn't verify flag links before performing the flag action, or verify that the response returned was provided by the flag module. This can allow crafted HTML to result in Cross Site Scripting. This is mitigated by the fact that an attacker must have a role with permission to create links on the website, for example: create or edit comments or content with a filtered text format.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46595"
},
{
"type": "WEB",
"url": "https://backdropcms.org/security/backdrop-sa-contrib-2025-011"
}
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-25T03:15:20Z"
}
}