mirror of
https://github.com/netbirdio/advisory-database.git
synced 2026-05-22 18:04:22 -07:00
Publish Advisories
GHSA-754f-8gm6-c4r2 GHSA-92rq-c8cf-prrq GHSA-27c6-7gh5-wmvg GHSA-6hcg-vqw2-35jw GHSA-5qjr-cj9f-phrx GHSA-74p9-4v44-wwx5 GHSA-4678-x95m-c2hf GHSA-98c3-q46g-62qh GHSA-cghv-p6j4-5ch6 GHSA-jrw2-pv6m-v2w5 GHSA-m727-97qg-jrmp GHSA-p844-gjc4-j9h6
This commit is contained in:
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-754f-8gm6-c4r2",
|
||||
"modified": "2025-03-13T21:43:02Z",
|
||||
"modified": "2025-03-14T12:32:01Z",
|
||||
"published": "2025-03-12T20:54:42Z",
|
||||
"aliases": [
|
||||
"CVE-2025-25292"
|
||||
@@ -98,6 +98,10 @@
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/ruby-saml/CVE-2025-25292.yml"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.netapp.com/advisory/ntap-20250314-0009"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-92rq-c8cf-prrq",
|
||||
"modified": "2025-03-13T21:42:28Z",
|
||||
"modified": "2025-03-14T12:32:01Z",
|
||||
"published": "2025-03-12T20:16:50Z",
|
||||
"aliases": [
|
||||
"CVE-2025-25293"
|
||||
@@ -98,6 +98,10 @@
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/ruby-saml/CVE-2025-25293.yml"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.netapp.com/advisory/ntap-20250314-0008"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-27c6-7gh5-wmvg",
|
||||
"modified": "2024-08-14T15:31:13Z",
|
||||
"modified": "2025-03-14T12:31:58Z",
|
||||
"published": "2024-08-14T15:31:13Z",
|
||||
"aliases": [
|
||||
"CVE-2023-49141"
|
||||
@@ -23,6 +23,10 @@
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-49141"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.netapp.com/advisory/ntap-20250314-0003"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01046.html"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-6hcg-vqw2-35jw",
|
||||
"modified": "2024-12-11T18:30:40Z",
|
||||
"modified": "2025-03-14T12:31:58Z",
|
||||
"published": "2024-12-05T21:31:52Z",
|
||||
"aliases": [
|
||||
"CVE-2024-53589"
|
||||
@@ -23,6 +23,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://bushido-sec.com/index.php/2024/12/05/binutils-objdump-tekhex-buffer-overflow"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.netapp.com/advisory/ntap-20250314-0006"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.gnu.org/software/binutils"
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-5qjr-cj9f-phrx",
|
||||
"modified": "2025-02-28T21:32:14Z",
|
||||
"modified": "2025-03-14T12:31:59Z",
|
||||
"published": "2025-01-31T18:31:08Z",
|
||||
"aliases": [
|
||||
"CVE-2025-0938"
|
||||
@@ -54,6 +54,10 @@
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://mail.python.org/archives/list/security-announce@python.org/thread/K4EUG6EKV6JYFIC24BASYOZS4M5XOQIB"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.netapp.com/advisory/ntap-20250314-0002"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-74p9-4v44-wwx5",
|
||||
"modified": "2025-02-14T21:31:04Z",
|
||||
"modified": "2025-03-14T12:31:59Z",
|
||||
"published": "2025-02-14T18:30:51Z",
|
||||
"aliases": [
|
||||
"CVE-2024-3220"
|
||||
@@ -23,6 +23,10 @@
|
||||
"type": "WEB",
|
||||
"url": "https://mail.python.org/archives/list/security-announce@python.org/thread/CDXW34ND2LSAOYAR5N6UNONP4ZBX4D6R"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://security.netapp.com/advisory/ntap-20250314-0001"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://www.openwall.com/lists/oss-security/2025/02/14/8"
|
||||
|
||||
@@ -0,0 +1,36 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-4678-x95m-c2hf",
|
||||
"modified": "2025-03-14T12:32:01Z",
|
||||
"published": "2025-03-14T12:32:01Z",
|
||||
"aliases": [
|
||||
"CVE-2024-26006"
|
||||
],
|
||||
"details": "An improper neutralization of input during web page Generation vulnerability [CWE-79] in FortiOS version 7.4.3 and below, version 7.2.7 and below, version 7.0.13 and below and FortiProxy version 7.4.3 and below, version 7.2.9 and below, version 7.0.16 and below web SSL VPN UI may allow a remote unauthenticated attacker to perform a Cross-Site Scripting attack via a malicious samba server.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-26006"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://fortiguard.fortinet.com/psirt/FG-IR-23-485"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-79"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-03-14T10:15:14Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,40 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-98c3-q46g-62qh",
|
||||
"modified": "2025-03-14T12:32:01Z",
|
||||
"published": "2025-03-14T12:32:01Z",
|
||||
"aliases": [
|
||||
"CVE-2024-13771"
|
||||
],
|
||||
"details": "The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.1.4. This is due to a lack of user validation before changing a password. This makes it possible for unauthenticated attackers to change the password of arbitrary users, including administrators, if the attacker knows the username of the victim.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13771"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/5ab2c74d-b83b-40ea-951c-83aeb76a7515?source=cve"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://localhost:1337/wp-content/themes/civi/includes/class-ajax.php#L715"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-288"
|
||||
],
|
||||
"severity": "CRITICAL",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-03-14T12:15:13Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,40 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-cghv-p6j4-5ch6",
|
||||
"modified": "2025-03-14T12:32:02Z",
|
||||
"published": "2025-03-14T12:32:02Z",
|
||||
"aliases": [
|
||||
"CVE-2025-2232"
|
||||
],
|
||||
"details": "The Realteo - Real Estate Plugin by Purethemes plugin for WordPress, used by the Findeo Theme, is vulnerable to authentication bypass in all versions up to, and including, 1.2.8. This is due to insufficient role restrictions in the 'do_register_user' function. This makes it possible for unauthenticated attackers to register an account with the Administrator role.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2232"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://docs.purethemes.net/findeo/knowledge-base/changelog-findeo"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/abe73ecd-1325-4d6d-8545-d27f6116ca43?source=cve"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-269"
|
||||
],
|
||||
"severity": "CRITICAL",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-03-14T12:15:14Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,44 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-jrw2-pv6m-v2w5",
|
||||
"modified": "2025-03-14T12:32:01Z",
|
||||
"published": "2025-03-14T12:32:01Z",
|
||||
"aliases": [
|
||||
"CVE-2024-13772"
|
||||
],
|
||||
"details": "The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.1.4. This is due to a lack of randomization of a password created during Single Sign-On via Google or Facebook. This makes it possible for unauthenticated attackers to change the password of arbitrary Candidate-level users if the attacker knows the username assigned to the victim during account creation.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"
|
||||
}
|
||||
],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13772"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/bf04f458-7900-4dd3-84fb-169b74db97ab?source=cve"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://localhost:1337/wp-content/themes/civi/includes/class-ajax.php#L567"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://localhost:1337/wp-content/themes/civi/includes/class-ajax.php#L739"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-288"
|
||||
],
|
||||
"severity": "MODERATE",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-03-14T12:15:13Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,40 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-m727-97qg-jrmp",
|
||||
"modified": "2025-03-14T12:32:02Z",
|
||||
"published": "2025-03-14T12:32:02Z",
|
||||
"aliases": [
|
||||
"CVE-2024-13773"
|
||||
],
|
||||
"details": "The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4 via hard-coded credentials. This makes it possible for unauthenticated attackers to extract sensitive data including LinkedIn client and secret keys.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
|
||||
}
|
||||
],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13773"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e3499182-7501-4fec-a7c6-b66ae47533cd?source=cve"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "http://localhost:1337/wp-content/themes/civi/includes/class-init.php#L36"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-321"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-03-14T12:15:14Z"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,40 @@
|
||||
{
|
||||
"schema_version": "1.4.0",
|
||||
"id": "GHSA-p844-gjc4-j9h6",
|
||||
"modified": "2025-03-14T12:32:01Z",
|
||||
"published": "2025-03-14T12:32:01Z",
|
||||
"aliases": [
|
||||
"CVE-2024-12810"
|
||||
],
|
||||
"details": "The JobCareer | Job Board Responsive WordPress Theme theme for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability checks on multiple functions in all versions up to, and including, 7.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files, generate backups, restore backups, update theme options, and reset theme options to default settings.",
|
||||
"severity": [
|
||||
{
|
||||
"type": "CVSS_V3",
|
||||
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
|
||||
}
|
||||
],
|
||||
"affected": [],
|
||||
"references": [
|
||||
{
|
||||
"type": "ADVISORY",
|
||||
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12810"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://themeforest.net/item/jobcareer-job-board-responsive-wordpress-theme/14221636"
|
||||
},
|
||||
{
|
||||
"type": "WEB",
|
||||
"url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/24889552-0db6-44e6-9b12-f31b5e92a42e?source=cve"
|
||||
}
|
||||
],
|
||||
"database_specific": {
|
||||
"cwe_ids": [
|
||||
"CWE-862"
|
||||
],
|
||||
"severity": "HIGH",
|
||||
"github_reviewed": false,
|
||||
"github_reviewed_at": null,
|
||||
"nvd_published_at": "2025-03-14T12:15:13Z"
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user