From c50fa0a286bb51429bc0d088524861a54ccd05a6 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 2 May 2025 21:32:14 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-2qrf-m8qr-6w35.json | 3 +- .../GHSA-69v3-ccqq-ggg3.json | 4 +- .../GHSA-gq8w-3h98-m48x.json | 2 +- .../GHSA-h6wv-v27f-f93r.json | 2 +- .../GHSA-hrxf-3584-q6p6.json | 114 ++++++++++++------ .../GHSA-jw33-72hm-ggg2.json | 14 ++- .../GHSA-m238-3frq-24mf.json | 4 +- .../GHSA-rpr6-4jj7-qxhw.json | 4 +- .../GHSA-rxpv-r2wj-5vx3.json | 4 +- .../GHSA-wgmx-m8v4-7pmv.json | 4 +- .../GHSA-x372-9xvw-hg7r.json | 1 + .../GHSA-x7v7-6r3p-jhgv.json | 4 +- .../GHSA-3x8r-xvj6-wr9x.json | 4 +- .../GHSA-7724-hcxw-879r.json | 4 +- .../GHSA-fv7v-mj99-qpwm.json | 3 +- .../GHSA-gx45-4v3f-xmjv.json | 4 +- .../GHSA-hc32-26fg-wr69.json | 3 +- .../GHSA-pxcm-w3r6-w362.json | 1 + .../GHSA-qcq5-ww8j-m4m7.json | 3 +- .../GHSA-qxgq-6j8m-j2xm.json | 1 + .../GHSA-qxpj-x283-2f27.json | 3 +- .../GHSA-vpxm-346x-6362.json | 4 +- .../GHSA-ghvx-5v39-7hv5.json | 4 +- .../GHSA-5pxx-cc47-2282.json | 6 +- .../GHSA-785g-r934-c877.json | 56 +++++++++ .../GHSA-8h3j-f7jx-h7fq.json | 40 ++++++ .../GHSA-9qf4-cccj-922q.json | 52 ++++++++ .../GHSA-h3vp-qwmx-5j25.json | 44 +++++++ .../GHSA-m6jr-jq3q-3pp7.json | 56 +++++++++ .../GHSA-v2p5-q653-9j99.json | 40 ++++++ 30 files changed, 427 insertions(+), 61 deletions(-) create mode 100644 advisories/unreviewed/2025/05/GHSA-785g-r934-c877/GHSA-785g-r934-c877.json create mode 100644 advisories/unreviewed/2025/05/GHSA-8h3j-f7jx-h7fq/GHSA-8h3j-f7jx-h7fq.json create mode 100644 advisories/unreviewed/2025/05/GHSA-9qf4-cccj-922q/GHSA-9qf4-cccj-922q.json create mode 100644 advisories/unreviewed/2025/05/GHSA-h3vp-qwmx-5j25/GHSA-h3vp-qwmx-5j25.json create mode 100644 advisories/unreviewed/2025/05/GHSA-m6jr-jq3q-3pp7/GHSA-m6jr-jq3q-3pp7.json create mode 100644 advisories/unreviewed/2025/05/GHSA-v2p5-q653-9j99/GHSA-v2p5-q653-9j99.json diff --git a/advisories/unreviewed/2022/11/GHSA-2qrf-m8qr-6w35/GHSA-2qrf-m8qr-6w35.json b/advisories/unreviewed/2022/11/GHSA-2qrf-m8qr-6w35/GHSA-2qrf-m8qr-6w35.json index 53cb0ec7721..d1a54bb6ab0 100644 --- a/advisories/unreviewed/2022/11/GHSA-2qrf-m8qr-6w35/GHSA-2qrf-m8qr-6w35.json +++ b/advisories/unreviewed/2022/11/GHSA-2qrf-m8qr-6w35/GHSA-2qrf-m8qr-6w35.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/11/GHSA-69v3-ccqq-ggg3/GHSA-69v3-ccqq-ggg3.json b/advisories/unreviewed/2022/11/GHSA-69v3-ccqq-ggg3/GHSA-69v3-ccqq-ggg3.json index acbe1af7076..2f23804a467 100644 --- a/advisories/unreviewed/2022/11/GHSA-69v3-ccqq-ggg3/GHSA-69v3-ccqq-ggg3.json +++ b/advisories/unreviewed/2022/11/GHSA-69v3-ccqq-ggg3/GHSA-69v3-ccqq-ggg3.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-250" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-gq8w-3h98-m48x/GHSA-gq8w-3h98-m48x.json b/advisories/unreviewed/2022/11/GHSA-gq8w-3h98-m48x/GHSA-gq8w-3h98-m48x.json index 3e63cd7ad70..a313914128e 100644 --- a/advisories/unreviewed/2022/11/GHSA-gq8w-3h98-m48x/GHSA-gq8w-3h98-m48x.json +++ b/advisories/unreviewed/2022/11/GHSA-gq8w-3h98-m48x/GHSA-gq8w-3h98-m48x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gq8w-3h98-m48x", - "modified": "2022-11-05T12:00:20Z", + "modified": "2025-05-02T21:30:36Z", "published": "2022-11-04T12:00:25Z", "aliases": [ "CVE-2022-40276" diff --git a/advisories/unreviewed/2022/11/GHSA-h6wv-v27f-f93r/GHSA-h6wv-v27f-f93r.json b/advisories/unreviewed/2022/11/GHSA-h6wv-v27f-f93r/GHSA-h6wv-v27f-f93r.json index 05434a1ecc7..433a43506c1 100644 --- a/advisories/unreviewed/2022/11/GHSA-h6wv-v27f-f93r/GHSA-h6wv-v27f-f93r.json +++ b/advisories/unreviewed/2022/11/GHSA-h6wv-v27f-f93r/GHSA-h6wv-v27f-f93r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h6wv-v27f-f93r", - "modified": "2023-01-20T21:30:31Z", + "modified": "2025-05-02T21:30:38Z", "published": "2022-11-07T12:00:35Z", "aliases": [ "CVE-2022-42905" diff --git a/advisories/unreviewed/2022/11/GHSA-hrxf-3584-q6p6/GHSA-hrxf-3584-q6p6.json b/advisories/unreviewed/2022/11/GHSA-hrxf-3584-q6p6/GHSA-hrxf-3584-q6p6.json index a14bb25198d..38223a98b96 100644 --- a/advisories/unreviewed/2022/11/GHSA-hrxf-3584-q6p6/GHSA-hrxf-3584-q6p6.json +++ b/advisories/unreviewed/2022/11/GHSA-hrxf-3584-q6p6/GHSA-hrxf-3584-q6p6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hrxf-3584-q6p6", - "modified": "2022-11-08T19:00:24Z", + "modified": "2025-05-02T21:30:38Z", "published": "2022-11-07T12:00:35Z", "aliases": [ "CVE-2022-42919" @@ -29,43 +29,7 @@ }, { "type": "WEB", - "url": "https://github.com/python/cpython/compare/v3.10.8...v3.10.9" - }, - { - "type": "WEB", - "url": "https://github.com/python/cpython/compare/v3.9.15...v3.9.16" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FKGCQPIVHEAIJ77R3RSNSQWYBUDVWDKU" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/P2LHWWEI5OBQ6RELULMVU6KMDYG4WZXH" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PI5DYIED6U26BGX5IRZWNCP6TY4M2ZGZ" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QLUGZSEAO3MBWGKCUSMKQIRYJZKJCIOB" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/R6KGIRHSENZ4QAB234Z36HVIDTRJ3MFI" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RDK3ZZBRYFO47ET3N4BNTKVXN47U6ICY" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VCRKBB5Y5EWTJUNC7LK665WO64DDXSTN" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XX6LLAXGZVZ327REY6MDZRMMP47LJ53P" + "url": "https://security.netapp.com/advisory/ntap-20221209-0006" }, { "type": "WEB", @@ -73,11 +37,81 @@ }, { "type": "WEB", - "url": "https://security.netapp.com/advisory/ntap-20221209-0006" + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XX6LLAXGZVZ327REY6MDZRMMP47LJ53P" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VCRKBB5Y5EWTJUNC7LK665WO64DDXSTN" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RDK3ZZBRYFO47ET3N4BNTKVXN47U6ICY" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/R6KGIRHSENZ4QAB234Z36HVIDTRJ3MFI" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QLUGZSEAO3MBWGKCUSMKQIRYJZKJCIOB" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PI5DYIED6U26BGX5IRZWNCP6TY4M2ZGZ" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/P2LHWWEI5OBQ6RELULMVU6KMDYG4WZXH" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FKGCQPIVHEAIJ77R3RSNSQWYBUDVWDKU" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XX6LLAXGZVZ327REY6MDZRMMP47LJ53P" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VCRKBB5Y5EWTJUNC7LK665WO64DDXSTN" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RDK3ZZBRYFO47ET3N4BNTKVXN47U6ICY" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/R6KGIRHSENZ4QAB234Z36HVIDTRJ3MFI" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QLUGZSEAO3MBWGKCUSMKQIRYJZKJCIOB" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PI5DYIED6U26BGX5IRZWNCP6TY4M2ZGZ" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/P2LHWWEI5OBQ6RELULMVU6KMDYG4WZXH" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FKGCQPIVHEAIJ77R3RSNSQWYBUDVWDKU" + }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/compare/v3.9.15...v3.9.16" + }, + { + "type": "WEB", + "url": "https://github.com/python/cpython/compare/v3.10.8...v3.10.9" } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-502" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-jw33-72hm-ggg2/GHSA-jw33-72hm-ggg2.json b/advisories/unreviewed/2022/11/GHSA-jw33-72hm-ggg2/GHSA-jw33-72hm-ggg2.json index 85c3f1652f1..eaf27832ba5 100644 --- a/advisories/unreviewed/2022/11/GHSA-jw33-72hm-ggg2/GHSA-jw33-72hm-ggg2.json +++ b/advisories/unreviewed/2022/11/GHSA-jw33-72hm-ggg2/GHSA-jw33-72hm-ggg2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jw33-72hm-ggg2", - "modified": "2022-11-04T19:01:10Z", + "modified": "2025-05-02T21:30:35Z", "published": "2022-11-03T12:00:26Z", "aliases": [ "CVE-2022-44638" @@ -27,6 +27,18 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2022/11/msg00008.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AJ5VY2VYXE4WTRGQ6LMGLF6FV3SY37YE" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BY4OPSIB33ETNUXZY2UPZ4NGQ3OKDY4D" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IUJ2BULJTZ2BMSKQHB6US674P55UCWWS" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AJ5VY2VYXE4WTRGQ6LMGLF6FV3SY37YE" diff --git a/advisories/unreviewed/2022/11/GHSA-m238-3frq-24mf/GHSA-m238-3frq-24mf.json b/advisories/unreviewed/2022/11/GHSA-m238-3frq-24mf/GHSA-m238-3frq-24mf.json index 6091e23c31e..d0a6bf4a78d 100644 --- a/advisories/unreviewed/2022/11/GHSA-m238-3frq-24mf/GHSA-m238-3frq-24mf.json +++ b/advisories/unreviewed/2022/11/GHSA-m238-3frq-24mf/GHSA-m238-3frq-24mf.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-rpr6-4jj7-qxhw/GHSA-rpr6-4jj7-qxhw.json b/advisories/unreviewed/2022/11/GHSA-rpr6-4jj7-qxhw/GHSA-rpr6-4jj7-qxhw.json index 80f0390910d..46a03b50454 100644 --- a/advisories/unreviewed/2022/11/GHSA-rpr6-4jj7-qxhw/GHSA-rpr6-4jj7-qxhw.json +++ b/advisories/unreviewed/2022/11/GHSA-rpr6-4jj7-qxhw/GHSA-rpr6-4jj7-qxhw.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-703" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-rxpv-r2wj-5vx3/GHSA-rxpv-r2wj-5vx3.json b/advisories/unreviewed/2022/11/GHSA-rxpv-r2wj-5vx3/GHSA-rxpv-r2wj-5vx3.json index 6095239a3eb..bc27a2550df 100644 --- a/advisories/unreviewed/2022/11/GHSA-rxpv-r2wj-5vx3/GHSA-rxpv-r2wj-5vx3.json +++ b/advisories/unreviewed/2022/11/GHSA-rxpv-r2wj-5vx3/GHSA-rxpv-r2wj-5vx3.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-wgmx-m8v4-7pmv/GHSA-wgmx-m8v4-7pmv.json b/advisories/unreviewed/2022/11/GHSA-wgmx-m8v4-7pmv/GHSA-wgmx-m8v4-7pmv.json index bb7af8c182a..cefffe21f26 100644 --- a/advisories/unreviewed/2022/11/GHSA-wgmx-m8v4-7pmv/GHSA-wgmx-m8v4-7pmv.json +++ b/advisories/unreviewed/2022/11/GHSA-wgmx-m8v4-7pmv/GHSA-wgmx-m8v4-7pmv.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-x372-9xvw-hg7r/GHSA-x372-9xvw-hg7r.json b/advisories/unreviewed/2022/11/GHSA-x372-9xvw-hg7r/GHSA-x372-9xvw-hg7r.json index a71aab73790..3cc067d1205 100644 --- a/advisories/unreviewed/2022/11/GHSA-x372-9xvw-hg7r/GHSA-x372-9xvw-hg7r.json +++ b/advisories/unreviewed/2022/11/GHSA-x372-9xvw-hg7r/GHSA-x372-9xvw-hg7r.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-78", "CWE-79" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/11/GHSA-x7v7-6r3p-jhgv/GHSA-x7v7-6r3p-jhgv.json b/advisories/unreviewed/2022/11/GHSA-x7v7-6r3p-jhgv/GHSA-x7v7-6r3p-jhgv.json index a866a3c3ece..a5a6a830d78 100644 --- a/advisories/unreviewed/2022/11/GHSA-x7v7-6r3p-jhgv/GHSA-x7v7-6r3p-jhgv.json +++ b/advisories/unreviewed/2022/11/GHSA-x7v7-6r3p-jhgv/GHSA-x7v7-6r3p-jhgv.json @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-451" + ], "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-3x8r-xvj6-wr9x/GHSA-3x8r-xvj6-wr9x.json b/advisories/unreviewed/2022/12/GHSA-3x8r-xvj6-wr9x/GHSA-3x8r-xvj6-wr9x.json index d6af80de54f..e30effa7eae 100644 --- a/advisories/unreviewed/2022/12/GHSA-3x8r-xvj6-wr9x/GHSA-3x8r-xvj6-wr9x.json +++ b/advisories/unreviewed/2022/12/GHSA-3x8r-xvj6-wr9x/GHSA-3x8r-xvj6-wr9x.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-494" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-7724-hcxw-879r/GHSA-7724-hcxw-879r.json b/advisories/unreviewed/2022/12/GHSA-7724-hcxw-879r/GHSA-7724-hcxw-879r.json index 396150d3557..6eb7e28e7c3 100644 --- a/advisories/unreviewed/2022/12/GHSA-7724-hcxw-879r/GHSA-7724-hcxw-879r.json +++ b/advisories/unreviewed/2022/12/GHSA-7724-hcxw-879r/GHSA-7724-hcxw-879r.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-fv7v-mj99-qpwm/GHSA-fv7v-mj99-qpwm.json b/advisories/unreviewed/2022/12/GHSA-fv7v-mj99-qpwm/GHSA-fv7v-mj99-qpwm.json index 4da38ed7b45..df71bbde2a6 100644 --- a/advisories/unreviewed/2022/12/GHSA-fv7v-mj99-qpwm/GHSA-fv7v-mj99-qpwm.json +++ b/advisories/unreviewed/2022/12/GHSA-fv7v-mj99-qpwm/GHSA-fv7v-mj99-qpwm.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/12/GHSA-gx45-4v3f-xmjv/GHSA-gx45-4v3f-xmjv.json b/advisories/unreviewed/2022/12/GHSA-gx45-4v3f-xmjv/GHSA-gx45-4v3f-xmjv.json index f4fd1e859fb..f7d9c1cdc69 100644 --- a/advisories/unreviewed/2022/12/GHSA-gx45-4v3f-xmjv/GHSA-gx45-4v3f-xmjv.json +++ b/advisories/unreviewed/2022/12/GHSA-gx45-4v3f-xmjv/GHSA-gx45-4v3f-xmjv.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-200" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/12/GHSA-hc32-26fg-wr69/GHSA-hc32-26fg-wr69.json b/advisories/unreviewed/2022/12/GHSA-hc32-26fg-wr69/GHSA-hc32-26fg-wr69.json index 9790700264b..f52a207db5d 100644 --- a/advisories/unreviewed/2022/12/GHSA-hc32-26fg-wr69/GHSA-hc32-26fg-wr69.json +++ b/advisories/unreviewed/2022/12/GHSA-hc32-26fg-wr69/GHSA-hc32-26fg-wr69.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/12/GHSA-pxcm-w3r6-w362/GHSA-pxcm-w3r6-w362.json b/advisories/unreviewed/2022/12/GHSA-pxcm-w3r6-w362/GHSA-pxcm-w3r6-w362.json index 1d7add35827..2c5ccc41224 100644 --- a/advisories/unreviewed/2022/12/GHSA-pxcm-w3r6-w362/GHSA-pxcm-w3r6-w362.json +++ b/advisories/unreviewed/2022/12/GHSA-pxcm-w3r6-w362/GHSA-pxcm-w3r6-w362.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-123", "CWE-94" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/12/GHSA-qcq5-ww8j-m4m7/GHSA-qcq5-ww8j-m4m7.json b/advisories/unreviewed/2022/12/GHSA-qcq5-ww8j-m4m7/GHSA-qcq5-ww8j-m4m7.json index 00b5f1b9401..99ef3084467 100644 --- a/advisories/unreviewed/2022/12/GHSA-qcq5-ww8j-m4m7/GHSA-qcq5-ww8j-m4m7.json +++ b/advisories/unreviewed/2022/12/GHSA-qcq5-ww8j-m4m7/GHSA-qcq5-ww8j-m4m7.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/12/GHSA-qxgq-6j8m-j2xm/GHSA-qxgq-6j8m-j2xm.json b/advisories/unreviewed/2022/12/GHSA-qxgq-6j8m-j2xm/GHSA-qxgq-6j8m-j2xm.json index 6cc212bbe54..2cfa9f3e56c 100644 --- a/advisories/unreviewed/2022/12/GHSA-qxgq-6j8m-j2xm/GHSA-qxgq-6j8m-j2xm.json +++ b/advisories/unreviewed/2022/12/GHSA-qxgq-6j8m-j2xm/GHSA-qxgq-6j8m-j2xm.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1236", "CWE-94" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2022/12/GHSA-qxpj-x283-2f27/GHSA-qxpj-x283-2f27.json b/advisories/unreviewed/2022/12/GHSA-qxpj-x283-2f27/GHSA-qxpj-x283-2f27.json index 60aff092227..e2b50a33de2 100644 --- a/advisories/unreviewed/2022/12/GHSA-qxpj-x283-2f27/GHSA-qxpj-x283-2f27.json +++ b/advisories/unreviewed/2022/12/GHSA-qxpj-x283-2f27/GHSA-qxpj-x283-2f27.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/12/GHSA-vpxm-346x-6362/GHSA-vpxm-346x-6362.json b/advisories/unreviewed/2022/12/GHSA-vpxm-346x-6362/GHSA-vpxm-346x-6362.json index 2b4c2137b9e..96a9410b12c 100644 --- a/advisories/unreviewed/2022/12/GHSA-vpxm-346x-6362/GHSA-vpxm-346x-6362.json +++ b/advisories/unreviewed/2022/12/GHSA-vpxm-346x-6362/GHSA-vpxm-346x-6362.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-400" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/10/GHSA-ghvx-5v39-7hv5/GHSA-ghvx-5v39-7hv5.json b/advisories/unreviewed/2023/10/GHSA-ghvx-5v39-7hv5/GHSA-ghvx-5v39-7hv5.json index 1cd2666c974..a6f37c3fe82 100644 --- a/advisories/unreviewed/2023/10/GHSA-ghvx-5v39-7hv5/GHSA-ghvx-5v39-7hv5.json +++ b/advisories/unreviewed/2023/10/GHSA-ghvx-5v39-7hv5/GHSA-ghvx-5v39-7hv5.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-ghvx-5v39-7hv5", - "modified": "2024-04-04T08:49:21Z", + "modified": "2025-05-02T21:30:41Z", "published": "2023-10-20T06:30:19Z", "aliases": [ "CVE-2023-34051" ], - "details": "VMware Aria Operations for Logs contains an authentication bypass vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution.\n", + "details": "VMware Aria Operations for Logs contains an authentication bypass vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2025/05/GHSA-5pxx-cc47-2282/GHSA-5pxx-cc47-2282.json b/advisories/unreviewed/2025/05/GHSA-5pxx-cc47-2282/GHSA-5pxx-cc47-2282.json index 22b2ed88899..c6f46fbaebb 100644 --- a/advisories/unreviewed/2025/05/GHSA-5pxx-cc47-2282/GHSA-5pxx-cc47-2282.json +++ b/advisories/unreviewed/2025/05/GHSA-5pxx-cc47-2282/GHSA-5pxx-cc47-2282.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5pxx-cc47-2282", - "modified": "2025-05-02T03:30:34Z", + "modified": "2025-05-02T21:30:42Z", "published": "2025-05-01T09:32:27Z", "aliases": [ "CVE-2025-47153" @@ -38,6 +38,10 @@ { "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00003.html" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/05/02/2" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/05/GHSA-785g-r934-c877/GHSA-785g-r934-c877.json b/advisories/unreviewed/2025/05/GHSA-785g-r934-c877/GHSA-785g-r934-c877.json new file mode 100644 index 00000000000..03457b1e59f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-785g-r934-c877/GHSA-785g-r934-c877.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-785g-r934-c877", + "modified": "2025-05-02T21:30:43Z", + "published": "2025-05-02T21:30:43Z", + "aliases": [ + "CVE-2025-4215" + ], + "details": "A vulnerability was found in gorhill uBlock Origin up to 1.63.3b16. It has been classified as problematic. Affected is the function currentStateChanged of the file src/js/1p-filters.js of the component UI. The manipulation leads to inefficient regular expression complexity. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 1.63.3b17 is able to address this issue. The patch is identified as eaedaf5b10d2f7857c6b77fbf7d4a80681d4d46c. It is recommended to upgrade the affected component.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4215" + }, + { + "type": "WEB", + "url": "https://github.com/gorhill/uBlock/commit/eaedaf5b10d2f7857c6b77fbf7d4a80681d4d46c" + }, + { + "type": "WEB", + "url": "https://github.com/gorhill/uBlock/releases/tag/1.63.3b17" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.307194" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.307194" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.562301" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-02T21:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8h3j-f7jx-h7fq/GHSA-8h3j-f7jx-h7fq.json b/advisories/unreviewed/2025/05/GHSA-8h3j-f7jx-h7fq/GHSA-8h3j-f7jx-h7fq.json new file mode 100644 index 00000000000..30882da54e2 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8h3j-f7jx-h7fq/GHSA-8h3j-f7jx-h7fq.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8h3j-f7jx-h7fq", + "modified": "2025-05-02T21:30:43Z", + "published": "2025-05-02T21:30:43Z", + "aliases": [ + "CVE-2025-0782" + ], + "details": "A vulnerability in the S3 bucket configuration for h2oai/h2o-3 allows public write access to the 'h2o-release' bucket. This issue affects all versions and could enable an attacker to overwrite any file in the bucket. As users download binary files such as JARs from this bucket, this vulnerability could lead to remote code execution (RCE) on any user who uses the application. Additionally, an attacker could modify the documentation to include malicious download links.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0782" + }, + { + "type": "WEB", + "url": "https://github.com/h2oai/h2o-3/commit/6740655b70cef40ec67d952bee2d23f7d33c7419" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/4587cec7-8bc5-48ab-8614-105d41c99151" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-862" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-02T21:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9qf4-cccj-922q/GHSA-9qf4-cccj-922q.json b/advisories/unreviewed/2025/05/GHSA-9qf4-cccj-922q/GHSA-9qf4-cccj-922q.json new file mode 100644 index 00000000000..870d4542d66 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9qf4-cccj-922q/GHSA-9qf4-cccj-922q.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9qf4-cccj-922q", + "modified": "2025-05-02T21:30:43Z", + "published": "2025-05-02T21:30:43Z", + "aliases": [ + "CVE-2025-4214" + ], + "details": "A vulnerability was found in PHPGuruku Online DJ Booking Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/booking-bwdates-reports-details.php. The manipulation of the argument fromdate leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4214" + }, + { + "type": "WEB", + "url": "https://github.com/LoovvvE18/CVE/issues/2" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.307193" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.307193" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.562295" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-02T20:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-h3vp-qwmx-5j25/GHSA-h3vp-qwmx-5j25.json b/advisories/unreviewed/2025/05/GHSA-h3vp-qwmx-5j25/GHSA-h3vp-qwmx-5j25.json new file mode 100644 index 00000000000..a03e84837b2 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-h3vp-qwmx-5j25/GHSA-h3vp-qwmx-5j25.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h3vp-qwmx-5j25", + "modified": "2025-05-02T21:30:43Z", + "published": "2025-05-02T21:30:43Z", + "aliases": [ + "CVE-2025-47226" + ], + "details": "Grokability Snipe-IT before 8.1.0 has incorrect authorization for accessing asset information.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47226" + }, + { + "type": "WEB", + "url": "https://github.com/grokability/snipe-it/pull/16672" + }, + { + "type": "WEB", + "url": "https://github.com/grokability/snipe-it/compare/v8.0.4...v8.1.0" + }, + { + "type": "WEB", + "url": "https://github.com/grokability/snipe-it/releases/tag/v8.1.0" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-425" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-02T21:15:23Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-m6jr-jq3q-3pp7/GHSA-m6jr-jq3q-3pp7.json b/advisories/unreviewed/2025/05/GHSA-m6jr-jq3q-3pp7/GHSA-m6jr-jq3q-3pp7.json new file mode 100644 index 00000000000..3a46d4ce805 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-m6jr-jq3q-3pp7/GHSA-m6jr-jq3q-3pp7.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m6jr-jq3q-3pp7", + "modified": "2025-05-02T21:30:43Z", + "published": "2025-05-02T21:30:43Z", + "aliases": [ + "CVE-2025-4218" + ], + "details": "A vulnerability was found in handrew browserpilot up to 0.2.51. It has been declared as critical. Affected by this vulnerability is the function GPTSeleniumAgent of the file browserpilot/browserpilot/agents/gpt_selenium_agent.py. The manipulation of the argument instructions leads to code injection. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4218" + }, + { + "type": "WEB", + "url": "https://github.com/handrew/browserpilot/issues/20" + }, + { + "type": "WEB", + "url": "https://github.com/handrew/browserpilot/issues/20#issue-2999815850" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.307195" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.307195" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.562383" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-02T21:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-v2p5-q653-9j99/GHSA-v2p5-q653-9j99.json b/advisories/unreviewed/2025/05/GHSA-v2p5-q653-9j99/GHSA-v2p5-q653-9j99.json new file mode 100644 index 00000000000..038c613db53 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-v2p5-q653-9j99/GHSA-v2p5-q653-9j99.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v2p5-q653-9j99", + "modified": "2025-05-02T21:30:43Z", + "published": "2025-05-02T21:30:43Z", + "aliases": [ + "CVE-2024-58253" + ], + "details": "In the obfstr crate before 0.4.4 for Rust, the obfstr! argument type is not restricted to string slices, leading to invalid UTF-8 conversion that produces an invalid value.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-58253" + }, + { + "type": "WEB", + "url": "https://github.com/CasualX/obfstr/issues/60" + }, + { + "type": "WEB", + "url": "https://github.com/CasualX/obfstr/compare/v0.4.3...v0.4.4" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-843" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-02T20:15:19Z" + } +} \ No newline at end of file