diff --git a/advisories/unreviewed/2025/04/GHSA-26mg-p594-q328/GHSA-26mg-p594-q328.json b/advisories/unreviewed/2025/04/GHSA-26mg-p594-q328/GHSA-26mg-p594-q328.json new file mode 100644 index 00000000000..8f97a829795 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-26mg-p594-q328/GHSA-26mg-p594-q328.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-26mg-p594-q328", + "modified": "2025-04-10T03:31:32Z", + "published": "2025-04-10T03:31:32Z", + "aliases": [ + "CVE-2025-32728" + ], + "details": "In sshd in OpenSSH before 10.0, the DisableForwarding directive does not adhere to the documentation stating that it disables X11 and agent forwarding.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32728" + }, + { + "type": "WEB", + "url": "https://github.com/openssh/openssh-portable/commit/fc86875e6acb36401dfc1dfb6b628a9d1460f367" + }, + { + "type": "WEB", + "url": "https://ftp.openbsd.org/pub/OpenBSD/patches/7.6/common/013_ssh.patch.sig" + }, + { + "type": "WEB", + "url": "https://lists.mindrot.org/pipermail/openssh-unix-dev/2025-April/041879.html" + }, + { + "type": "WEB", + "url": "https://www.openssh.com/txt/release-10.0" + }, + { + "type": "WEB", + "url": "https://www.openssh.com/txt/release-7.4" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-440" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T02:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5537-v9p2-j3p7/GHSA-5537-v9p2-j3p7.json b/advisories/unreviewed/2025/04/GHSA-5537-v9p2-j3p7/GHSA-5537-v9p2-j3p7.json new file mode 100644 index 00000000000..13950f33252 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5537-v9p2-j3p7/GHSA-5537-v9p2-j3p7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5537-v9p2-j3p7", + "modified": "2025-04-10T03:31:32Z", + "published": "2025-04-10T03:31:32Z", + "aliases": [ + "CVE-2025-29989" + ], + "details": "Dell Client Platform BIOS contains a Security Version Number Mutable to Older Versions vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to BIOS upgrade denial.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29989" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000250131/dsa-2025-016" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1328" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T02:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-ggwg-cmwp-46r5/GHSA-ggwg-cmwp-46r5.json b/advisories/unreviewed/2025/04/GHSA-ggwg-cmwp-46r5/GHSA-ggwg-cmwp-46r5.json new file mode 100644 index 00000000000..b6b050185ae --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-ggwg-cmwp-46r5/GHSA-ggwg-cmwp-46r5.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ggwg-cmwp-46r5", + "modified": "2025-04-10T03:31:32Z", + "published": "2025-04-10T03:31:32Z", + "aliases": [ + "CVE-2024-58136" + ], + "details": "Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-58136" + }, + { + "type": "WEB", + "url": "https://github.com/yiisoft/yii2/pull/20232" + }, + { + "type": "WEB", + "url": "https://github.com/yiisoft/yii2/pull/20232#issuecomment-2252459709" + }, + { + "type": "WEB", + "url": "https://github.com/yiisoft/yii2/commit/40fe496eda529fd1d933b56a1022ec32d3cd0b12" + }, + { + "type": "WEB", + "url": "https://github.com/yiisoft/yii2/compare/2.0.51...2.0.52" + }, + { + "type": "WEB", + "url": "https://www.yiiframework.com/news/709/please-upgrade-to-yii-2-0-52" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-424" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T03:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-gphh-hmhf-jgcw/GHSA-gphh-hmhf-jgcw.json b/advisories/unreviewed/2025/04/GHSA-gphh-hmhf-jgcw/GHSA-gphh-hmhf-jgcw.json new file mode 100644 index 00000000000..952c4fc0f54 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-gphh-hmhf-jgcw/GHSA-gphh-hmhf-jgcw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gphh-hmhf-jgcw", + "modified": "2025-04-10T03:31:32Z", + "published": "2025-04-10T03:31:32Z", + "aliases": [ + "CVE-2025-22471" + ], + "details": "Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.1, contains an integer overflow or wraparound vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22471" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000300860/dsa-2025-119-security-update-for-dell-powerscale-onefs-for-multiple-security-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-190" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T03:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-m436-48r8-qqpq/GHSA-m436-48r8-qqpq.json b/advisories/unreviewed/2025/04/GHSA-m436-48r8-qqpq/GHSA-m436-48r8-qqpq.json new file mode 100644 index 00000000000..0239c4ada67 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-m436-48r8-qqpq/GHSA-m436-48r8-qqpq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m436-48r8-qqpq", + "modified": "2025-04-10T03:31:32Z", + "published": "2025-04-10T03:31:32Z", + "aliases": [ + "CVE-2025-26330" + ], + "details": "Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.1, contains an incorrect authorization vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability to access the cluster with previous privileges of a disabled user account.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26330" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000300860/dsa-2025-119-security-update-for-dell-powerscale-onefs-for-multiple-security-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T03:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-m77q-7jww-hhf9/GHSA-m77q-7jww-hhf9.json b/advisories/unreviewed/2025/04/GHSA-m77q-7jww-hhf9/GHSA-m77q-7jww-hhf9.json new file mode 100644 index 00000000000..2c4289b181f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-m77q-7jww-hhf9/GHSA-m77q-7jww-hhf9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m77q-7jww-hhf9", + "modified": "2025-04-10T03:31:32Z", + "published": "2025-04-10T03:31:32Z", + "aliases": [ + "CVE-2025-27690" + ], + "details": "Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.1.0, contains a use of default password vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to the takeover of a high privileged user account.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27690" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000300860/dsa-2025-119-security-update-for-dell-powerscale-onefs-for-multiple-security-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1393" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T03:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-p7f2-4vp4-pjr6/GHSA-p7f2-4vp4-pjr6.json b/advisories/unreviewed/2025/04/GHSA-p7f2-4vp4-pjr6/GHSA-p7f2-4vp4-pjr6.json new file mode 100644 index 00000000000..df82799d22f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-p7f2-4vp4-pjr6/GHSA-p7f2-4vp4-pjr6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p7f2-4vp4-pjr6", + "modified": "2025-04-10T03:31:32Z", + "published": "2025-04-10T03:31:32Z", + "aliases": [ + "CVE-2025-26479" + ], + "details": "Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.0, contains an out-of-bounds write vulnerability. An attacker could potentially exploit this vulnerability in NFS workflows, leading to data integrity issues.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26479" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000300860/dsa-2025-119-security-update-for-dell-powerscale-onefs-for-multiple-security-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T03:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-ppxp-2q6f-m9hh/GHSA-ppxp-2q6f-m9hh.json b/advisories/unreviewed/2025/04/GHSA-ppxp-2q6f-m9hh/GHSA-ppxp-2q6f-m9hh.json new file mode 100644 index 00000000000..7fa8357a400 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-ppxp-2q6f-m9hh/GHSA-ppxp-2q6f-m9hh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ppxp-2q6f-m9hh", + "modified": "2025-04-10T03:31:32Z", + "published": "2025-04-10T03:31:32Z", + "aliases": [ + "CVE-2025-23378" + ], + "details": "Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.0, contains an exposure of information through directory listing vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23378" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000300860/dsa-2025-119-security-update-for-dell-powerscale-onefs-for-multiple-security-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-548" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T03:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-pqrf-m72x-vgx9/GHSA-pqrf-m72x-vgx9.json b/advisories/unreviewed/2025/04/GHSA-pqrf-m72x-vgx9/GHSA-pqrf-m72x-vgx9.json new file mode 100644 index 00000000000..0fcbeb2fd4a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-pqrf-m72x-vgx9/GHSA-pqrf-m72x-vgx9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pqrf-m72x-vgx9", + "modified": "2025-04-10T03:31:32Z", + "published": "2025-04-10T03:31:32Z", + "aliases": [ + "CVE-2025-26480" + ], + "details": "Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.0.0, contains an uncontrolled resource consumption vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26480" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000300860/dsa-2025-119-security-update-for-dell-powerscale-onefs-for-multiple-security-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-770" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T03:15:19Z" + } +} \ No newline at end of file