diff --git a/advisories/github-reviewed/2025/03/GHSA-66pp-5p9w-q87j/GHSA-66pp-5p9w-q87j.json b/advisories/github-reviewed/2025/03/GHSA-66pp-5p9w-q87j/GHSA-66pp-5p9w-q87j.json new file mode 100644 index 00000000000..7be280eb3dd --- /dev/null +++ b/advisories/github-reviewed/2025/03/GHSA-66pp-5p9w-q87j/GHSA-66pp-5p9w-q87j.json @@ -0,0 +1,73 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-66pp-5p9w-q87j", + "modified": "2025-03-26T14:54:22Z", + "published": "2025-03-26T14:54:22Z", + "aliases": [ + "CVE-2025-30222" + ], + "summary": "Shescape has potential environment variable exposure on Windows with CMD", + "details": "### Impact\n\nThis impact users of Shescape on Windows that explicitly configure `shell: 'cmd.exe'` or `shell: true` using any of `quote`/`quoteAll`/`escape`/`escapeAll`.\n\nAn attacker may be able to get read-only access to environment variables. Example:\n\n```javascript\nimport * as cp from \"node:child_process\";\nimport { Shescape } from \"shescape\";\n\n// 1. Prerequisites\nconst shescape = new Shescape({\n shell: \"cmd.exe\",\n // Or\n shell: true, // Only if the default shell is CMD\n});\n\n// 2. Payload\nconst payload = '\"%PATH%';\n\n// 3. Usage\nlet escapedPayload;\n\nescapedPayload = shescape.quote(payload);\n// Or\nescapedPayload = shescape.quoteAll([payload]);\n// Or\nescapedPayload = shescape.escape(payload);\n// Or\nescapedPayload = shescape.escapeAll([payload]);\n\n// And (example)\nconst result = cp.execSync(`echo Hello ${escapedPayload}`, options);\n\n// 4. Impact\nconsole.log(result.toString());\n// Outputs \"Hello\" followed by the contents of the PATH environment variable\n```\n\nFor Shescape prior to v2.0.0, the `options` object must have `shell: 'cmd.exe'` or `shell: undefined` and `interpolation: true`.\n\n\n### Patches\n\nThis bug has been patched in [v2.1.2](https://github.com/ericcornelissen/shescape/releases/tag/v2.1.2) which you can upgrade to now.\n\nIf you are already using v2 of Shescape, no further changes are required. If you are using v1 of Shescape, follow the [migration guide](https://github.com/ericcornelissen/shescape/blob/155b13b4141750203ce71249f1b0fdc638c7a0d0/docs/migration.md) to upgrade to v2. There is no plan to release a patch compatible with v1 of Shescape.\n\n\n### Workarounds\n\nAlternatively, users can remove all instances of % from user input before using Shescape.\n\n\n### References\n\n- Shescape Pull Request [#1916](https://github.com/ericcornelissen/shescape/pull/1916)\n- Shescape commit [0a81f1e](https://github.com/ericcornelissen/shescape/commit/0a81f1eb077bab8caae283a2490cd7be9af179c6)\n- Shescape release [v2.1.2](https://github.com/ericcornelissen/shescape/releases/tag/v2.1.2)\n\n\n### For more information\n\n- Comment on Pull Request [#1916](https://github.com/ericcornelissen/shescape/pull/1916)\n- Comment on commit [0a81f1e](https://github.com/ericcornelissen/shescape/commit/0a81f1eb077bab8caae283a2490cd7be9af179c6)\n- Open an issue at [https://github.com/ericcornelissen/shescape/issues](https://github.com/ericcornelissen/shescape/issues) (New issue > Question)", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U" + } + ], + "affected": [ + { + "package": { + "ecosystem": "npm", + "name": "shescape" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "1.7.2" + }, + { + "fixed": "2.1.2" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/ericcornelissen/shescape/security/advisories/GHSA-66pp-5p9w-q87j" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30222" + }, + { + "type": "WEB", + "url": "https://github.com/ericcornelissen/shescape/pull/1916" + }, + { + "type": "WEB", + "url": "https://github.com/ericcornelissen/shescape/commit/0a81f1eb077bab8caae283a2490cd7be9af179c6" + }, + { + "type": "PACKAGE", + "url": "https://github.com/ericcornelissen/shescape" + }, + { + "type": "WEB", + "url": "https://github.com/ericcornelissen/shescape/releases/tag/v2.1.2" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "LOW", + "github_reviewed": true, + "github_reviewed_at": "2025-03-26T14:54:22Z", + "nvd_published_at": "2025-03-25T23:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-7287-grhx-542x/GHSA-7287-grhx-542x.json b/advisories/github-reviewed/2025/03/GHSA-7287-grhx-542x/GHSA-7287-grhx-542x.json similarity index 64% rename from advisories/unreviewed/2025/03/GHSA-7287-grhx-542x/GHSA-7287-grhx-542x.json rename to advisories/github-reviewed/2025/03/GHSA-7287-grhx-542x/GHSA-7287-grhx-542x.json index 4fc1f4b120f..67d2576f346 100644 --- a/advisories/unreviewed/2025/03/GHSA-7287-grhx-542x/GHSA-7287-grhx-542x.json +++ b/advisories/github-reviewed/2025/03/GHSA-7287-grhx-542x/GHSA-7287-grhx-542x.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-7287-grhx-542x", - "modified": "2025-03-25T21:31:34Z", + "modified": "2025-03-26T14:53:15Z", "published": "2025-03-25T21:31:34Z", "aliases": [ "CVE-2025-30741" ], + "summary": "Pixelfed may allow unauthorized actor to view private posts and private users", "details": "Pixelfed before 0.12.5 allows anyone to follow private accounts and see private posts on other Fediverse servers. This affects users elsewhere in the Fediverse, if they otherwise have any followers from a Pixelfed instance.", "severity": [ { @@ -13,7 +14,27 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "pixelfed/pixelfed" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.12.5" + } + ] + } + ] + } + ], "references": [ { "type": "ADVISORY", @@ -23,6 +44,10 @@ "type": "WEB", "url": "https://fokus.cool/2025/03/25/pixelfed-vulnerability.html" }, + { + "type": "PACKAGE", + "url": "https://github.com/pixelfed/pixelfed" + }, { "type": "WEB", "url": "https://github.com/pixelfed/pixelfed/releases/tag/v0.12.5" @@ -41,8 +66,8 @@ "CWE-863" ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2025-03-26T14:53:15Z", "nvd_published_at": "2025-03-25T21:15:43Z" } } \ No newline at end of file