From ca2be615397f3da64357f820eb3b00358f8b65d8 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 1 Apr 2025 12:32:05 +0000 Subject: [PATCH] Publish Advisories GHSA-2g49-fr8w-j923 GHSA-2qjj-4522-pjgp GHSA-5ggp-wm87-2p6g GHSA-6jwp-4wvj-6597 GHSA-75j9-xw79-qxqv GHSA-77w4-3h74-q5hf GHSA-8jp9-435c-pj3q GHSA-v8j7-gw8h-m2j4 GHSA-vq4p-pchp-6g6v --- .../GHSA-2g49-fr8w-j923.json | 40 +++++++++++++++++ .../GHSA-2qjj-4522-pjgp.json | 44 +++++++++++++++++++ .../GHSA-5ggp-wm87-2p6g.json | 36 +++++++++++++++ .../GHSA-6jwp-4wvj-6597.json | 6 ++- .../GHSA-75j9-xw79-qxqv.json | 36 +++++++++++++++ .../GHSA-77w4-3h74-q5hf.json | 36 +++++++++++++++ .../GHSA-8jp9-435c-pj3q.json | 44 +++++++++++++++++++ .../GHSA-v8j7-gw8h-m2j4.json | 36 +++++++++++++++ .../GHSA-vq4p-pchp-6g6v.json | 39 ++++++++++++++++ 9 files changed, 316 insertions(+), 1 deletion(-) create mode 100644 advisories/unreviewed/2025/04/GHSA-2g49-fr8w-j923/GHSA-2g49-fr8w-j923.json create mode 100644 advisories/unreviewed/2025/04/GHSA-2qjj-4522-pjgp/GHSA-2qjj-4522-pjgp.json create mode 100644 advisories/unreviewed/2025/04/GHSA-5ggp-wm87-2p6g/GHSA-5ggp-wm87-2p6g.json create mode 100644 advisories/unreviewed/2025/04/GHSA-75j9-xw79-qxqv/GHSA-75j9-xw79-qxqv.json create mode 100644 advisories/unreviewed/2025/04/GHSA-77w4-3h74-q5hf/GHSA-77w4-3h74-q5hf.json create mode 100644 advisories/unreviewed/2025/04/GHSA-8jp9-435c-pj3q/GHSA-8jp9-435c-pj3q.json create mode 100644 advisories/unreviewed/2025/04/GHSA-v8j7-gw8h-m2j4/GHSA-v8j7-gw8h-m2j4.json create mode 100644 advisories/unreviewed/2025/04/GHSA-vq4p-pchp-6g6v/GHSA-vq4p-pchp-6g6v.json diff --git a/advisories/unreviewed/2025/04/GHSA-2g49-fr8w-j923/GHSA-2g49-fr8w-j923.json b/advisories/unreviewed/2025/04/GHSA-2g49-fr8w-j923/GHSA-2g49-fr8w-j923.json new file mode 100644 index 00000000000..7e3e316d0b2 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2g49-fr8w-j923/GHSA-2g49-fr8w-j923.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2g49-fr8w-j923", + "modified": "2025-04-01T12:30:34Z", + "published": "2025-04-01T12:30:34Z", + "aliases": [ + "CVE-2025-2237" + ], + "details": "The WP RealEstate plugin for WordPress, used by the Homeo theme, is vulnerable to authentication bypass in all versions up to, and including, 1.6.26. This is due to insufficient role restrictions in the 'process_register' function. This makes it possible for unauthenticated attackers to register an account with the Administrator role.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2237" + }, + { + "type": "WEB", + "url": "https://themeforest.net/item/homeo-real-estate-wordpress-theme/26372986#item-description__updates-history" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/f6f7bff6-3bc3-4572-97fd-a039d54ac0ff?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-269" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T12:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-2qjj-4522-pjgp/GHSA-2qjj-4522-pjgp.json b/advisories/unreviewed/2025/04/GHSA-2qjj-4522-pjgp/GHSA-2qjj-4522-pjgp.json new file mode 100644 index 00000000000..0435ff7a2a1 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-2qjj-4522-pjgp/GHSA-2qjj-4522-pjgp.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2qjj-4522-pjgp", + "modified": "2025-04-01T12:30:34Z", + "published": "2025-04-01T12:30:34Z", + "aliases": [ + "CVE-2024-13553" + ], + "details": "The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.7.9. This is due to the plugin using the Host header to determine if the plugin is in a playground environment. This makes it possible for unauthenticated attackers to spoof the Host header to make the OTP code \"1234\" and authenticate as any user, including administrators.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13553" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3227241%40sms-alert&new=3227241%40sms-alert&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3248017%40sms-alert&new=3248017%40sms-alert&sfp_email=&sfph_mail=" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/4e444a30-11c5-4219-b4fe-635084cbac3a?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-288" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T12:15:14Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-5ggp-wm87-2p6g/GHSA-5ggp-wm87-2p6g.json b/advisories/unreviewed/2025/04/GHSA-5ggp-wm87-2p6g/GHSA-5ggp-wm87-2p6g.json new file mode 100644 index 00000000000..0fdb72f07c0 --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-5ggp-wm87-2p6g/GHSA-5ggp-wm87-2p6g.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5ggp-wm87-2p6g", + "modified": "2025-04-01T12:30:35Z", + "published": "2025-04-01T12:30:35Z", + "aliases": [ + "CVE-2025-3083" + ], + "details": "Specifically crafted MongoDB wire protocol messages can cause mongos to crash during command validation. This can occur without using an authenticated connection. This issue affects MongoDB v5.0 versions prior to 5.0.31,  MongoDB v6.0 versions prior to 6.0.20 and MongoDB v7.0 versions prior to 7.0.16", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3083" + }, + { + "type": "WEB", + "url": "https://jira.mongodb.org/browse/SERVER-103152" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-248" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T12:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-6jwp-4wvj-6597/GHSA-6jwp-4wvj-6597.json b/advisories/unreviewed/2025/04/GHSA-6jwp-4wvj-6597/GHSA-6jwp-4wvj-6597.json index beaea014b78..6591ae938c6 100644 --- a/advisories/unreviewed/2025/04/GHSA-6jwp-4wvj-6597/GHSA-6jwp-4wvj-6597.json +++ b/advisories/unreviewed/2025/04/GHSA-6jwp-4wvj-6597/GHSA-6jwp-4wvj-6597.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6jwp-4wvj-6597", - "modified": "2025-04-01T09:30:20Z", + "modified": "2025-04-01T12:30:34Z", "published": "2025-04-01T09:30:20Z", "aliases": [ "CVE-2024-56325" @@ -17,6 +17,10 @@ { "type": "WEB", "url": "https://lists.apache.org/thread/ksf8qsndr1h66otkbjz2wrzsbw992r8v" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/03/27/8" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/04/GHSA-75j9-xw79-qxqv/GHSA-75j9-xw79-qxqv.json b/advisories/unreviewed/2025/04/GHSA-75j9-xw79-qxqv/GHSA-75j9-xw79-qxqv.json new file mode 100644 index 00000000000..3e501e9e19a --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-75j9-xw79-qxqv/GHSA-75j9-xw79-qxqv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-75j9-xw79-qxqv", + "modified": "2025-04-01T12:30:35Z", + "published": "2025-04-01T12:30:35Z", + "aliases": [ + "CVE-2025-3084" + ], + "details": "When run on commands with certain arguments set, explain may fail to validate these arguments before using them. This can lead to crashes in router servers. This affects MongoDB Server v5.0 prior to 5.0.31, MongoDB Server v6.0 prior to 6.0.20, MongoDB Server v7.0 prior to 7.0.16 and MongoDB Server v8.0 prior to 8.0.4", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3084" + }, + { + "type": "WEB", + "url": "https://jira.mongodb.org/browse/SERVER-103153" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-703" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T12:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-77w4-3h74-q5hf/GHSA-77w4-3h74-q5hf.json b/advisories/unreviewed/2025/04/GHSA-77w4-3h74-q5hf/GHSA-77w4-3h74-q5hf.json new file mode 100644 index 00000000000..274750efccc --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-77w4-3h74-q5hf/GHSA-77w4-3h74-q5hf.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-77w4-3h74-q5hf", + "modified": "2025-04-01T12:30:34Z", + "published": "2025-04-01T12:30:34Z", + "aliases": [ + "CVE-2025-3082" + ], + "details": "A user authorized to access a view may be able to alter the intended collation, allowing them to access to a different or unintended view of underlying data. This issue affects MongoDB Server v5.0 version prior to 5.0.31, MongoDB Server v6.0 version prior to 6.0.20, MongoDB Server v7.0 version prior to 7.0.14 and MongoDB Server v7.3 versions prior to 7.3.4.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3082" + }, + { + "type": "WEB", + "url": "https://jira.mongodb.org/browse/SERVER-103151" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T11:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-8jp9-435c-pj3q/GHSA-8jp9-435c-pj3q.json b/advisories/unreviewed/2025/04/GHSA-8jp9-435c-pj3q/GHSA-8jp9-435c-pj3q.json new file mode 100644 index 00000000000..76eaadb5d8c --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-8jp9-435c-pj3q/GHSA-8jp9-435c-pj3q.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8jp9-435c-pj3q", + "modified": "2025-04-01T12:30:34Z", + "published": "2025-04-01T12:30:34Z", + "aliases": [ + "CVE-2025-2906" + ], + "details": "The Contempo Real Estate Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 3.6.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2906" + }, + { + "type": "WEB", + "url": "https://contempothemes.com/changelog" + }, + { + "type": "WEB", + "url": "https://themeforest.net/item/wp-pro-real-estate-7-responsive-real-estate-wordpress-theme/12473778" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/39c651c3-a478-4f58-af51-fd73d2934bdf?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T12:15:15Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-v8j7-gw8h-m2j4/GHSA-v8j7-gw8h-m2j4.json b/advisories/unreviewed/2025/04/GHSA-v8j7-gw8h-m2j4/GHSA-v8j7-gw8h-m2j4.json new file mode 100644 index 00000000000..80521c962be --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-v8j7-gw8h-m2j4/GHSA-v8j7-gw8h-m2j4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v8j7-gw8h-m2j4", + "modified": "2025-04-01T12:30:35Z", + "published": "2025-04-01T12:30:35Z", + "aliases": [ + "CVE-2025-3085" + ], + "details": "A MongoDB server under specific conditions running on Linux with TLS and CRL revocation status checking enabled, fails to check the revocation status of the intermediate certificates in the peer's certificate chain. In cases of MONGODB-X509, which is not enabled by default, this may lead to improper authentication. This issue may also affect intra-cluster authentication. This issue affects MongoDB Server v5.0 versions prior to 5.0.31, MongoDB Server v6.0 versions prior to 6.0.20, MongoDB Server v7.0 versions prior to 7.0.16 and MongoDB Server v8.0 versions prior to 8.0.4.\nRequired Configuration : MongoDB Server must be running on Linux Operating Systems and CRL revocation status checking must be enabled", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3085" + }, + { + "type": "WEB", + "url": "https://jira.mongodb.org/browse/SERVER-95445" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-299" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T12:15:16Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/04/GHSA-vq4p-pchp-6g6v/GHSA-vq4p-pchp-6g6v.json b/advisories/unreviewed/2025/04/GHSA-vq4p-pchp-6g6v/GHSA-vq4p-pchp-6g6v.json new file mode 100644 index 00000000000..d75bacaa2fe --- /dev/null +++ b/advisories/unreviewed/2025/04/GHSA-vq4p-pchp-6g6v/GHSA-vq4p-pchp-6g6v.json @@ -0,0 +1,39 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vq4p-pchp-6g6v", + "modified": "2025-04-01T12:30:34Z", + "published": "2025-04-01T12:30:34Z", + "aliases": [ + "CVE-2025-30177" + ], + "details": "Bypass/Injection vulnerability in Apache Camel in Camel-Undertow component under particular conditions.\n\nThis issue affects Apache Camel: from 4.10.0 before 4.10.3, from 4.8.0 before 4.8.6.\n\nUsers are recommended to upgrade to version 4.10.3 for 4.10.x LTS and 4.8.6 for 4.8.x LTS.\n\nCamel undertow component is vulnerable to Camel message header injection, in particular the custom header filter strategy used by the component only filter the \"out\" direction, while it doesn't filter the \"in\" direction.\n\n\nThis allows an attacker to include Camel specific headers that for some Camel components can alter the behaviour such as the camel-bean component, or the camel-exec component.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30177" + }, + { + "type": "WEB", + "url": "https://camel.apache.org/security/CVE-2025-27636.html" + }, + { + "type": "WEB", + "url": "https://camel.apache.org/security/CVE-2025-29891.html" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread/dj79zdgw01j337lr9gvyy4sv8xfyw8py" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-164" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-04-01T12:15:15Z" + } +} \ No newline at end of file