diff --git a/advisories/github-reviewed/2025/01/GHSA-gvvw-rr8m-fj76/GHSA-gvvw-rr8m-fj76.json b/advisories/github-reviewed/2025/01/GHSA-gvvw-rr8m-fj76/GHSA-gvvw-rr8m-fj76.json new file mode 100644 index 00000000000..1bdb8eaaba4 --- /dev/null +++ b/advisories/github-reviewed/2025/01/GHSA-gvvw-rr8m-fj76/GHSA-gvvw-rr8m-fj76.json @@ -0,0 +1,38 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gvvw-rr8m-fj76", + "modified": "2025-01-27T12:30:28Z", + "published": "2025-01-27T12:30:28Z", + "aliases": [], + "summary": "uniapi version 1.0.7 contained an information harvesting script.", + "details": "uniapi version 1.0.7 introduces code that would execute on import of the module and download a script from a remote URL, and would then execute the downloaded script in a thread. The downloaded script would harvest system information and `POST` the information to another remote URL. This code was found in the PyPI release artifacts and was not present in the public GitHub repository.\n", + "severity": [], + "affected": [ + { + "package": { + "ecosystem": "PyPI", + "name": "uniapi" + }, + "versions": [ + "1.0.7" + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/uniapi/PYSEC-2025-2.yaml" + }, + { + "type": "WEB", + "url": "https://inspector.pypi.io/project/uniapi/1.0.7/packages/0f/40/c6e06c22bbc22ef45f40bf5a7711763fa08fec4d16b4718d86fd60970131/uniapi-1.0.7.tar.gz/uniapi-1.0.7/uniapi/__init__.py#line.11" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "HIGH", + "github_reviewed": true, + "github_reviewed_at": "2025-01-27T12:30:28Z", + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-59j2-vr29-mmmc/GHSA-59j2-vr29-mmmc.json b/advisories/unreviewed/2025/01/GHSA-59j2-vr29-mmmc/GHSA-59j2-vr29-mmmc.json new file mode 100644 index 00000000000..16bf230b0e6 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-59j2-vr29-mmmc/GHSA-59j2-vr29-mmmc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-59j2-vr29-mmmc", + "modified": "2025-01-27T12:31:11Z", + "published": "2025-01-27T12:31:11Z", + "aliases": [ + "CVE-2025-0695" + ], + "details": "An Allocation of Resources Without Limits or Throttling vulnerability in Cesanta Frozen versions less than 1.7 allows an attacker to induce a crash of the component embedding the library by supplying a maliciously crafted JSON as input.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0695" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-0695" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-770" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T11:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-j86m-4332-jm3w/GHSA-j86m-4332-jm3w.json b/advisories/unreviewed/2025/01/GHSA-j86m-4332-jm3w/GHSA-j86m-4332-jm3w.json new file mode 100644 index 00000000000..fb4711a89ea --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-j86m-4332-jm3w/GHSA-j86m-4332-jm3w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j86m-4332-jm3w", + "modified": "2025-01-27T12:31:11Z", + "published": "2025-01-27T12:31:11Z", + "aliases": [ + "CVE-2025-0696" + ], + "details": "A NULL Pointer Dereference vulnerability in Cesanta Frozen versions less than 1.7 allows an attacker to induce a crash of the component embedding the library by supplying a maliciously crafted JSON as input.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0696" + }, + { + "type": "WEB", + "url": "https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2025-0696" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T11:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-vhqh-w8vh-h8h6/GHSA-vhqh-w8vh-h8h6.json b/advisories/unreviewed/2025/01/GHSA-vhqh-w8vh-h8h6/GHSA-vhqh-w8vh-h8h6.json new file mode 100644 index 00000000000..bf6fed3e532 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-vhqh-w8vh-h8h6/GHSA-vhqh-w8vh-h8h6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vhqh-w8vh-h8h6", + "modified": "2025-01-27T12:31:11Z", + "published": "2025-01-27T12:31:11Z", + "aliases": [ + "CVE-2024-55931" + ], + "details": "Xerox Workplace Suite stores tokens in session storage, which may expose them to potential access if a user's session is compromised. \n\nThe patch for this vulnerability will be included in a future release of Workplace Suite, and customers will be notified through an update to the security bulletin.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55931" + }, + { + "type": "WEB", + "url": "https://securitydocs.business.xerox.com/wp-content/uploads/2025/01/Xerox-Security-Bulletin-XRX25-002-for-Xerox%C2%AE-Workplace-Suite%C2%AE.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-922" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-27T12:15:27Z" + } +} \ No newline at end of file