From b5b537849b012f5cf866675c9caa7e7292d22263 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 25 Apr 2025 03:32:14 +0000 Subject: [PATCH] Publish Advisories GHSA-4xpw-6594-8f5m GHSA-37m8-vrcv-2x3f GHSA-6f6h-2hc4-8gjc GHSA-794f-v4rm-x7r5 GHSA-fvp7-w3vq-22p7 GHSA-g2vc-w9mc-h6ch GHSA-mmfm-hc46-3944 GHSA-qgfc-q68c-8fgx --- .../GHSA-4xpw-6594-8f5m.json | 6 ++- .../GHSA-37m8-vrcv-2x3f.json | 48 +++++++++++++++++++ .../GHSA-6f6h-2hc4-8gjc.json | 48 +++++++++++++++++++ .../GHSA-794f-v4rm-x7r5.json | 6 ++- .../GHSA-fvp7-w3vq-22p7.json | 6 ++- .../GHSA-g2vc-w9mc-h6ch.json | 48 +++++++++++++++++++ .../GHSA-mmfm-hc46-3944.json | 48 +++++++++++++++++++ .../GHSA-qgfc-q68c-8fgx.json | 36 ++++++++++++++ 8 files changed, 243 insertions(+), 3 deletions(-) create mode 100644 advisories/unreviewed/2025/04/GHSA-37m8-vrcv-2x3f/GHSA-37m8-vrcv-2x3f.json create mode 100644 advisories/unreviewed/2025/04/GHSA-6f6h-2hc4-8gjc/GHSA-6f6h-2hc4-8gjc.json create mode 100644 advisories/unreviewed/2025/04/GHSA-g2vc-w9mc-h6ch/GHSA-g2vc-w9mc-h6ch.json create mode 100644 advisories/unreviewed/2025/04/GHSA-mmfm-hc46-3944/GHSA-mmfm-hc46-3944.json create mode 100644 advisories/unreviewed/2025/04/GHSA-qgfc-q68c-8fgx/GHSA-qgfc-q68c-8fgx.json diff --git a/advisories/unreviewed/2025/01/GHSA-4xpw-6594-8f5m/GHSA-4xpw-6594-8f5m.json b/advisories/unreviewed/2025/01/GHSA-4xpw-6594-8f5m/GHSA-4xpw-6594-8f5m.json index 2f5a328117b..58569669bca 100644 --- a/advisories/unreviewed/2025/01/GHSA-4xpw-6594-8f5m/GHSA-4xpw-6594-8f5m.json +++ b/advisories/unreviewed/2025/01/GHSA-4xpw-6594-8f5m/GHSA-4xpw-6594-8f5m.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4xpw-6594-8f5m", - "modified": "2025-04-13T06:30:33Z", + "modified": "2025-04-25T03:30:33Z", "published": "2025-01-22T15:32:34Z", "aliases": [ "CVE-2025-0395" @@ -50,6 +50,10 @@ { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2025/04/13/1" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/04/24/7" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/04/GHSA-37m8-vrcv-2x3f/GHSA-37m8-vrcv-2x3f.json b/advisories/unreviewed/2025/04/GHSA-37m8-vrcv-2x3f/GHSA-37m8-vrcv-2x3f.json new file mode 100644 index 00000000000..e0be9d07755 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-37m8-vrcv-2x3f/GHSA-37m8-vrcv-2x3f.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-37m8-vrcv-2x3f", + "modified": "2025-04-25T03:30:34Z", + "published": "2025-04-25T03:30:34Z", + "aliases": [ + "CVE-2025-46545" + ], + "details": "In Sherpa Orchestrator 141851, the functionality for adding or updating licenses allows for stored XSS attacks by an administrator through the name parameter. The XSS payload can execute when the license expires.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46545" + }, + { + "type": "WEB", + "url": "https://deiteriy.com" + }, + { + "type": "WEB", + "url": "https://gist.github.com/ArtemBrylev/5a0c76285d5fa9daf4ec753034185de7" + }, + { + "type": "WEB", + "url": "https://sherparpa.com" + }, + { + "type": "WEB", + "url": "https://twitter.com/ArtyomBrylev" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-25T03:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6f6h-2hc4-8gjc/GHSA-6f6h-2hc4-8gjc.json b/advisories/unreviewed/2025/04/GHSA-6f6h-2hc4-8gjc/GHSA-6f6h-2hc4-8gjc.json new file mode 100644 index 00000000000..fece9a072cb --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-6f6h-2hc4-8gjc/GHSA-6f6h-2hc4-8gjc.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6f6h-2hc4-8gjc", + "modified": "2025-04-25T03:30:34Z", + "published": "2025-04-25T03:30:34Z", + "aliases": [ + "CVE-2025-46544" + ], + "details": "In Sherpa Orchestrator 141851, a low-privileged user can elevate their privileges by creating new users and roles.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46544" + }, + { + "type": "WEB", + "url": "https://deiteriy.com" + }, + { + "type": "WEB", + "url": "https://gist.github.com/ArtemBrylev/a258f920a6556470951c9a483fcf194a" + }, + { + "type": "WEB", + "url": "https://sherparpa.com" + }, + { + "type": "WEB", + "url": "https://twitter.com/ArtyomBrylev" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-25T03:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-794f-v4rm-x7r5/GHSA-794f-v4rm-x7r5.json b/advisories/unreviewed/2025/04/GHSA-794f-v4rm-x7r5/GHSA-794f-v4rm-x7r5.json index f3568f56239..dffcb14fb43 100644 --- a/advisories/unreviewed/2025/04/GHSA-794f-v4rm-x7r5/GHSA-794f-v4rm-x7r5.json +++ b/advisories/unreviewed/2025/04/GHSA-794f-v4rm-x7r5/GHSA-794f-v4rm-x7r5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-794f-v4rm-x7r5", - "modified": "2025-04-24T21:31:47Z", + "modified": "2025-04-25T03:30:33Z", "published": "2025-04-11T09:30:24Z", "aliases": [ "CVE-2025-3512" @@ -34,6 +34,10 @@ { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2025/04/24/6" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/04/25/1" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/04/GHSA-fvp7-w3vq-22p7/GHSA-fvp7-w3vq-22p7.json b/advisories/unreviewed/2025/04/GHSA-fvp7-w3vq-22p7/GHSA-fvp7-w3vq-22p7.json index 0e13ca3340c..576ed78abfb 100644 --- a/advisories/unreviewed/2025/04/GHSA-fvp7-w3vq-22p7/GHSA-fvp7-w3vq-22p7.json +++ b/advisories/unreviewed/2025/04/GHSA-fvp7-w3vq-22p7/GHSA-fvp7-w3vq-22p7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fvp7-w3vq-22p7", - "modified": "2025-04-23T21:30:35Z", + "modified": "2025-04-25T03:30:33Z", "published": "2025-04-23T18:31:00Z", "aliases": [ "CVE-2025-3900" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3900" }, + { + "type": "WEB", + "url": "https://backdropcms.org/security/backdrop-sa-contrib-2025-012" + }, { "type": "WEB", "url": "https://www.drupal.org/sa-contrib-2025-041" diff --git a/advisories/unreviewed/2025/04/GHSA-g2vc-w9mc-h6ch/GHSA-g2vc-w9mc-h6ch.json b/advisories/unreviewed/2025/04/GHSA-g2vc-w9mc-h6ch/GHSA-g2vc-w9mc-h6ch.json new file mode 100644 index 00000000000..f96b22cb445 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-g2vc-w9mc-h6ch/GHSA-g2vc-w9mc-h6ch.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g2vc-w9mc-h6ch", + "modified": "2025-04-25T03:30:34Z", + "published": "2025-04-25T03:30:34Z", + "aliases": [ + "CVE-2025-46547" + ], + "details": "In Sherpa Orchestrator 141851, the web application lacks protection against CSRF attacks, with resultant effects of an attacker conducting XSS attacks, adding a new user or role, or exploiting a SQL injection issue.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46547" + }, + { + "type": "WEB", + "url": "https://deiteriy.com" + }, + { + "type": "WEB", + "url": "https://gist.github.com/ArtemBrylev/9af206c46d7505db03ad6fcd9fc46f7f" + }, + { + "type": "WEB", + "url": "https://sherparpa.com" + }, + { + "type": "WEB", + "url": "https://twitter.com/ArtyomBrylev" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-25T03:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-mmfm-hc46-3944/GHSA-mmfm-hc46-3944.json b/advisories/unreviewed/2025/04/GHSA-mmfm-hc46-3944/GHSA-mmfm-hc46-3944.json new file mode 100644 index 00000000000..82daa31181e --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-mmfm-hc46-3944/GHSA-mmfm-hc46-3944.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mmfm-hc46-3944", + "modified": "2025-04-25T03:30:34Z", + "published": "2025-04-25T03:30:34Z", + "aliases": [ + "CVE-2025-46546" + ], + "details": "In Sherpa Orchestrator 141851, multiple time-based blind SQL injections can be performed by an authenticated user. This affects api/gui/asset/list, /api/gui/files/export/csv/, /api/gui/files/list, /api/gui/process/export/csv, /api/gui/process/export/xlsx, /api/gui/process/listAll, /api/gui/processVersion/export/csv/, /api/gui/processVersion/export/xlsx/, /api/gui/processVersion/list/, /api/gui/robot/list/, /api/gui/task/export/csv/, /api/gui/task/export/xlsx/, and /api/gui/task/list/.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46546" + }, + { + "type": "WEB", + "url": "https://deiteriy.com" + }, + { + "type": "WEB", + "url": "https://gist.github.com/ArtemBrylev/59b4c0825a988f39a58b79e4e8d2f378" + }, + { + "type": "WEB", + "url": "https://sherparpa.com" + }, + { + "type": "WEB", + "url": "https://twitter.com/ArtyomBrylev" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-25T03:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-qgfc-q68c-8fgx/GHSA-qgfc-q68c-8fgx.json b/advisories/unreviewed/2025/04/GHSA-qgfc-q68c-8fgx/GHSA-qgfc-q68c-8fgx.json new file mode 100644 index 00000000000..92f914204c2 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-qgfc-q68c-8fgx/GHSA-qgfc-q68c-8fgx.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qgfc-q68c-8fgx", + "modified": "2025-04-25T03:30:34Z", + "published": "2025-04-25T03:30:34Z", + "aliases": [ + "CVE-2025-46595" + ], + "details": "An XSS issue was discovered in the Flag module before 1.x-3.6.2 for Backdrop CMS. Flag is a module that allows flags to be added to nodes, comments, users, and any other type of entity. It doesn't verify flag links before performing the flag action, or verify that the response returned was provided by the flag module. This can allow crafted HTML to result in Cross Site Scripting. This is mitigated by the fact that an attacker must have a role with permission to create links on the website, for example: create or edit comments or content with a filtered text format.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46595" + }, + { + "type": "WEB", + "url": "https://backdropcms.org/security/backdrop-sa-contrib-2025-011" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-25T03:15:20Z" + } +} \ No newline at end of file