From b87c9d795bab5ec0eaa1146396891a908b554fa0 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 10 Apr 2025 03:33:01 +0000 Subject: [PATCH] Publish Advisories GHSA-26mg-p594-q328 GHSA-5537-v9p2-j3p7 GHSA-ggwg-cmwp-46r5 GHSA-gphh-hmhf-jgcw GHSA-m436-48r8-qqpq GHSA-m77q-7jww-hhf9 GHSA-p7f2-4vp4-pjr6 GHSA-ppxp-2q6f-m9hh GHSA-pqrf-m72x-vgx9 --- .../GHSA-26mg-p594-q328.json | 52 +++++++++++++++++++ .../GHSA-5537-v9p2-j3p7.json | 36 +++++++++++++ .../GHSA-ggwg-cmwp-46r5.json | 52 +++++++++++++++++++ .../GHSA-gphh-hmhf-jgcw.json | 36 +++++++++++++ .../GHSA-m436-48r8-qqpq.json | 36 +++++++++++++ .../GHSA-m77q-7jww-hhf9.json | 36 +++++++++++++ .../GHSA-p7f2-4vp4-pjr6.json | 36 +++++++++++++ .../GHSA-ppxp-2q6f-m9hh.json | 36 +++++++++++++ .../GHSA-pqrf-m72x-vgx9.json | 36 +++++++++++++ 9 files changed, 356 insertions(+) create mode 100644 advisories/unreviewed/2025/04/GHSA-26mg-p594-q328/GHSA-26mg-p594-q328.json create mode 100644 advisories/unreviewed/2025/04/GHSA-5537-v9p2-j3p7/GHSA-5537-v9p2-j3p7.json create mode 100644 advisories/unreviewed/2025/04/GHSA-ggwg-cmwp-46r5/GHSA-ggwg-cmwp-46r5.json create mode 100644 advisories/unreviewed/2025/04/GHSA-gphh-hmhf-jgcw/GHSA-gphh-hmhf-jgcw.json create mode 100644 advisories/unreviewed/2025/04/GHSA-m436-48r8-qqpq/GHSA-m436-48r8-qqpq.json create mode 100644 advisories/unreviewed/2025/04/GHSA-m77q-7jww-hhf9/GHSA-m77q-7jww-hhf9.json create mode 100644 advisories/unreviewed/2025/04/GHSA-p7f2-4vp4-pjr6/GHSA-p7f2-4vp4-pjr6.json create mode 100644 advisories/unreviewed/2025/04/GHSA-ppxp-2q6f-m9hh/GHSA-ppxp-2q6f-m9hh.json create mode 100644 advisories/unreviewed/2025/04/GHSA-pqrf-m72x-vgx9/GHSA-pqrf-m72x-vgx9.json diff --git a/advisories/unreviewed/2025/04/GHSA-26mg-p594-q328/GHSA-26mg-p594-q328.json b/advisories/unreviewed/2025/04/GHSA-26mg-p594-q328/GHSA-26mg-p594-q328.json new file mode 100644 index 00000000000..8f97a829795 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-26mg-p594-q328/GHSA-26mg-p594-q328.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-26mg-p594-q328", + "modified": "2025-04-10T03:31:32Z", + "published": "2025-04-10T03:31:32Z", + "aliases": [ + "CVE-2025-32728" + ], + "details": "In sshd in OpenSSH before 10.0, the DisableForwarding directive does not adhere to the documentation stating that it disables X11 and agent forwarding.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32728" + }, + { + "type": "WEB", + "url": "https://github.com/openssh/openssh-portable/commit/fc86875e6acb36401dfc1dfb6b628a9d1460f367" + }, + { + "type": "WEB", + "url": "https://ftp.openbsd.org/pub/OpenBSD/patches/7.6/common/013_ssh.patch.sig" + }, + { + "type": "WEB", + "url": "https://lists.mindrot.org/pipermail/openssh-unix-dev/2025-April/041879.html" + }, + { + "type": "WEB", + "url": "https://www.openssh.com/txt/release-10.0" + }, + { + "type": "WEB", + "url": "https://www.openssh.com/txt/release-7.4" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-440" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T02:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5537-v9p2-j3p7/GHSA-5537-v9p2-j3p7.json b/advisories/unreviewed/2025/04/GHSA-5537-v9p2-j3p7/GHSA-5537-v9p2-j3p7.json new file mode 100644 index 00000000000..13950f33252 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5537-v9p2-j3p7/GHSA-5537-v9p2-j3p7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5537-v9p2-j3p7", + "modified": "2025-04-10T03:31:32Z", + "published": "2025-04-10T03:31:32Z", + "aliases": [ + "CVE-2025-29989" + ], + "details": "Dell Client Platform BIOS contains a Security Version Number Mutable to Older Versions vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to BIOS upgrade denial.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-29989" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000250131/dsa-2025-016" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1328" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T02:15:30Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-ggwg-cmwp-46r5/GHSA-ggwg-cmwp-46r5.json b/advisories/unreviewed/2025/04/GHSA-ggwg-cmwp-46r5/GHSA-ggwg-cmwp-46r5.json new file mode 100644 index 00000000000..b6b050185ae --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-ggwg-cmwp-46r5/GHSA-ggwg-cmwp-46r5.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ggwg-cmwp-46r5", + "modified": "2025-04-10T03:31:32Z", + "published": "2025-04-10T03:31:32Z", + "aliases": [ + "CVE-2024-58136" + ], + "details": "Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-58136" + }, + { + "type": "WEB", + "url": "https://github.com/yiisoft/yii2/pull/20232" + }, + { + "type": "WEB", + "url": "https://github.com/yiisoft/yii2/pull/20232#issuecomment-2252459709" + }, + { + "type": "WEB", + "url": "https://github.com/yiisoft/yii2/commit/40fe496eda529fd1d933b56a1022ec32d3cd0b12" + }, + { + "type": "WEB", + "url": "https://github.com/yiisoft/yii2/compare/2.0.51...2.0.52" + }, + { + "type": "WEB", + "url": "https://www.yiiframework.com/news/709/please-upgrade-to-yii-2-0-52" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-424" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T03:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-gphh-hmhf-jgcw/GHSA-gphh-hmhf-jgcw.json b/advisories/unreviewed/2025/04/GHSA-gphh-hmhf-jgcw/GHSA-gphh-hmhf-jgcw.json new file mode 100644 index 00000000000..952c4fc0f54 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-gphh-hmhf-jgcw/GHSA-gphh-hmhf-jgcw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gphh-hmhf-jgcw", + "modified": "2025-04-10T03:31:32Z", + "published": "2025-04-10T03:31:32Z", + "aliases": [ + "CVE-2025-22471" + ], + "details": "Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.1, contains an integer overflow or wraparound vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-22471" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000300860/dsa-2025-119-security-update-for-dell-powerscale-onefs-for-multiple-security-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-190" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T03:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-m436-48r8-qqpq/GHSA-m436-48r8-qqpq.json b/advisories/unreviewed/2025/04/GHSA-m436-48r8-qqpq/GHSA-m436-48r8-qqpq.json new file mode 100644 index 00000000000..0239c4ada67 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-m436-48r8-qqpq/GHSA-m436-48r8-qqpq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m436-48r8-qqpq", + "modified": "2025-04-10T03:31:32Z", + "published": "2025-04-10T03:31:32Z", + "aliases": [ + "CVE-2025-26330" + ], + "details": "Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.1, contains an incorrect authorization vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability to access the cluster with previous privileges of a disabled user account.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26330" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000300860/dsa-2025-119-security-update-for-dell-powerscale-onefs-for-multiple-security-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T03:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-m77q-7jww-hhf9/GHSA-m77q-7jww-hhf9.json b/advisories/unreviewed/2025/04/GHSA-m77q-7jww-hhf9/GHSA-m77q-7jww-hhf9.json new file mode 100644 index 00000000000..2c4289b181f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-m77q-7jww-hhf9/GHSA-m77q-7jww-hhf9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m77q-7jww-hhf9", + "modified": "2025-04-10T03:31:32Z", + "published": "2025-04-10T03:31:32Z", + "aliases": [ + "CVE-2025-27690" + ], + "details": "Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.1.0, contains a use of default password vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to the takeover of a high privileged user account.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27690" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000300860/dsa-2025-119-security-update-for-dell-powerscale-onefs-for-multiple-security-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1393" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T03:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-p7f2-4vp4-pjr6/GHSA-p7f2-4vp4-pjr6.json b/advisories/unreviewed/2025/04/GHSA-p7f2-4vp4-pjr6/GHSA-p7f2-4vp4-pjr6.json new file mode 100644 index 00000000000..df82799d22f --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-p7f2-4vp4-pjr6/GHSA-p7f2-4vp4-pjr6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p7f2-4vp4-pjr6", + "modified": "2025-04-10T03:31:32Z", + "published": "2025-04-10T03:31:32Z", + "aliases": [ + "CVE-2025-26479" + ], + "details": "Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.0, contains an out-of-bounds write vulnerability. An attacker could potentially exploit this vulnerability in NFS workflows, leading to data integrity issues.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26479" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000300860/dsa-2025-119-security-update-for-dell-powerscale-onefs-for-multiple-security-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T03:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-ppxp-2q6f-m9hh/GHSA-ppxp-2q6f-m9hh.json b/advisories/unreviewed/2025/04/GHSA-ppxp-2q6f-m9hh/GHSA-ppxp-2q6f-m9hh.json new file mode 100644 index 00000000000..7fa8357a400 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-ppxp-2q6f-m9hh/GHSA-ppxp-2q6f-m9hh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ppxp-2q6f-m9hh", + "modified": "2025-04-10T03:31:32Z", + "published": "2025-04-10T03:31:32Z", + "aliases": [ + "CVE-2025-23378" + ], + "details": "Dell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.0, contains an exposure of information through directory listing vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information disclosure.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23378" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000300860/dsa-2025-119-security-update-for-dell-powerscale-onefs-for-multiple-security-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-548" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T03:15:18Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-pqrf-m72x-vgx9/GHSA-pqrf-m72x-vgx9.json b/advisories/unreviewed/2025/04/GHSA-pqrf-m72x-vgx9/GHSA-pqrf-m72x-vgx9.json new file mode 100644 index 00000000000..0fcbeb2fd4a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-pqrf-m72x-vgx9/GHSA-pqrf-m72x-vgx9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pqrf-m72x-vgx9", + "modified": "2025-04-10T03:31:32Z", + "published": "2025-04-10T03:31:32Z", + "aliases": [ + "CVE-2025-26480" + ], + "details": "Dell PowerScale OneFS, versions 9.5.0.0 through 9.10.0.0, contains an uncontrolled resource consumption vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26480" + }, + { + "type": "WEB", + "url": "https://www.dell.com/support/kbdoc/en-us/000300860/dsa-2025-119-security-update-for-dell-powerscale-onefs-for-multiple-security-vulnerabilities" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-770" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-10T03:15:19Z" + } +} \ No newline at end of file