Publish Advisories

GHSA-26mg-p594-q328
GHSA-5537-v9p2-j3p7
GHSA-ggwg-cmwp-46r5
GHSA-gphh-hmhf-jgcw
GHSA-m436-48r8-qqpq
GHSA-m77q-7jww-hhf9
GHSA-p7f2-4vp4-pjr6
GHSA-ppxp-2q6f-m9hh
GHSA-pqrf-m72x-vgx9
This commit is contained in:
advisory-database[bot]
2025-04-10 03:33:01 +00:00
parent 73d0227dd7
commit b87c9d795b
9 changed files with 356 additions and 0 deletions
@@ -0,0 +1,52 @@
{
"schema_version": "1.4.0",
"id": "GHSA-26mg-p594-q328",
"modified": "2025-04-10T03:31:32Z",
"published": "2025-04-10T03:31:32Z",
"aliases": [
"CVE-2025-32728"
],
"details": "In sshd in OpenSSH before 10.0, the DisableForwarding directive does not adhere to the documentation stating that it disables X11 and agent forwarding.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32728"
},
{
"type": "WEB",
"url": "https://github.com/openssh/openssh-portable/commit/fc86875e6acb36401dfc1dfb6b628a9d1460f367"
},
{
"type": "WEB",
"url": "https://ftp.openbsd.org/pub/OpenBSD/patches/7.6/common/013_ssh.patch.sig"
},
{
"type": "WEB",
"url": "https://lists.mindrot.org/pipermail/openssh-unix-dev/2025-April/041879.html"
},
{
"type": "WEB",
"url": "https://www.openssh.com/txt/release-10.0"
},
{
"type": "WEB",
"url": "https://www.openssh.com/txt/release-7.4"
}
],
"database_specific": {
"cwe_ids": [
"CWE-440"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-10T02:15:30Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5537-v9p2-j3p7",
"modified": "2025-04-10T03:31:32Z",
"published": "2025-04-10T03:31:32Z",
"aliases": [
"CVE-2025-29989"
],
"details": "Dell Client Platform BIOS contains a Security Version Number Mutable to Older Versions vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to BIOS upgrade denial.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:L"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29989"
},
{
"type": "WEB",
"url": "https://www.dell.com/support/kbdoc/en-us/000250131/dsa-2025-016"
}
],
"database_specific": {
"cwe_ids": [
"CWE-1328"
],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-10T02:15:30Z"
}
}
@@ -0,0 +1,52 @@
{
"schema_version": "1.4.0",
"id": "GHSA-ggwg-cmwp-46r5",
"modified": "2025-04-10T03:31:32Z",
"published": "2025-04-10T03:31:32Z",
"aliases": [
"CVE-2024-58136"
],
"details": "Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-58136"
},
{
"type": "WEB",
"url": "https://github.com/yiisoft/yii2/pull/20232"
},
{
"type": "WEB",
"url": "https://github.com/yiisoft/yii2/pull/20232#issuecomment-2252459709"
},
{
"type": "WEB",
"url": "https://github.com/yiisoft/yii2/commit/40fe496eda529fd1d933b56a1022ec32d3cd0b12"
},
{
"type": "WEB",
"url": "https://github.com/yiisoft/yii2/compare/2.0.51...2.0.52"
},
{
"type": "WEB",
"url": "https://www.yiiframework.com/news/709/please-upgrade-to-yii-2-0-52"
}
],
"database_specific": {
"cwe_ids": [
"CWE-424"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-10T03:15:17Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gphh-hmhf-jgcw",
"modified": "2025-04-10T03:31:32Z",
"published": "2025-04-10T03:31:32Z",
"aliases": [
"CVE-2025-22471"
],
"details": "Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.1, contains an integer overflow or wraparound vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22471"
},
{
"type": "WEB",
"url": "https://www.dell.com/support/kbdoc/en-us/000300860/dsa-2025-119-security-update-for-dell-powerscale-onefs-for-multiple-security-vulnerabilities"
}
],
"database_specific": {
"cwe_ids": [
"CWE-190"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-10T03:15:18Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m436-48r8-qqpq",
"modified": "2025-04-10T03:31:32Z",
"published": "2025-04-10T03:31:32Z",
"aliases": [
"CVE-2025-26330"
],
"details": "Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.1, contains an incorrect authorization vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability to access the cluster with previous privileges of a disabled user account.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26330"
},
{
"type": "WEB",
"url": "https://www.dell.com/support/kbdoc/en-us/000300860/dsa-2025-119-security-update-for-dell-powerscale-onefs-for-multiple-security-vulnerabilities"
}
],
"database_specific": {
"cwe_ids": [
"CWE-863"
],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-10T03:15:18Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m77q-7jww-hhf9",
"modified": "2025-04-10T03:31:32Z",
"published": "2025-04-10T03:31:32Z",
"aliases": [
"CVE-2025-27690"
],
"details": "Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.1.0, contains a use of default password vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to the takeover of a high privileged user account.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27690"
},
{
"type": "WEB",
"url": "https://www.dell.com/support/kbdoc/en-us/000300860/dsa-2025-119-security-update-for-dell-powerscale-onefs-for-multiple-security-vulnerabilities"
}
],
"database_specific": {
"cwe_ids": [
"CWE-1393"
],
"severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-10T03:15:19Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p7f2-4vp4-pjr6",
"modified": "2025-04-10T03:31:32Z",
"published": "2025-04-10T03:31:32Z",
"aliases": [
"CVE-2025-26479"
],
"details": "Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.0, contains an out-of-bounds write vulnerability. An attacker could potentially exploit this vulnerability in NFS workflows, leading to data integrity issues.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26479"
},
{
"type": "WEB",
"url": "https://www.dell.com/support/kbdoc/en-us/000300860/dsa-2025-119-security-update-for-dell-powerscale-onefs-for-multiple-security-vulnerabilities"
}
],
"database_specific": {
"cwe_ids": [
"CWE-787"
],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-10T03:15:18Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-ppxp-2q6f-m9hh",
"modified": "2025-04-10T03:31:32Z",
"published": "2025-04-10T03:31:32Z",
"aliases": [
"CVE-2025-23378"
],
"details": "Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.0, contains an exposure of information through directory listing vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23378"
},
{
"type": "WEB",
"url": "https://www.dell.com/support/kbdoc/en-us/000300860/dsa-2025-119-security-update-for-dell-powerscale-onefs-for-multiple-security-vulnerabilities"
}
],
"database_specific": {
"cwe_ids": [
"CWE-548"
],
"severity": "LOW",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-10T03:15:18Z"
}
}
@@ -0,0 +1,36 @@
{
"schema_version": "1.4.0",
"id": "GHSA-pqrf-m72x-vgx9",
"modified": "2025-04-10T03:31:32Z",
"published": "2025-04-10T03:31:32Z",
"aliases": [
"CVE-2025-26480"
],
"details": "Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.0.0, contains an uncontrolled resource consumption vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26480"
},
{
"type": "WEB",
"url": "https://www.dell.com/support/kbdoc/en-us/000300860/dsa-2025-119-security-update-for-dell-powerscale-onefs-for-multiple-security-vulnerabilities"
}
],
"database_specific": {
"cwe_ids": [
"CWE-770"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-04-10T03:15:19Z"
}
}