Publish Advisories

GHSA-5gp5-vxj6-4257
GHSA-hm7p-r324-hhf3
GHSA-52jx-g6m5-h735
GHSA-mf24-chxh-hmvj
GHSA-wf6c-hrhf-86cw
This commit is contained in:
advisory-database[bot]
2025-03-06 21:38:03 +00:00
parent 53708f237d
commit cc7b6af2d2
5 changed files with 32 additions and 10 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5gp5-vxj6-4257",
"modified": "2024-11-22T17:55:04Z",
"modified": "2025-03-06T21:36:21Z",
"published": "2023-03-07T00:30:24Z",
"aliases": [
"CVE-2022-4134"
@@ -1,14 +1,19 @@
{
"schema_version": "1.4.0",
"id": "GHSA-hm7p-r324-hhf3",
"modified": "2023-03-06T21:20:42Z",
"modified": "2025-03-06T21:36:12Z",
"published": "2023-03-03T06:30:17Z",
"aliases": [
"CVE-2023-27560"
],
"summary": "phpseclib Infinite Loop vulnerability",
"details": "Math/PrimeField.php in phpseclib has an infinite loop with composite primefields. This vulnerability was introduced in version 3.0.0, and has been patched in 3.0.19. The CVE for this issue originally identified the the vulnerable version as 2.x, however, the vulnerable functionality was not introduced until version 3.",
"severity": [],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
}
],
"affected": [
{
"package": {
@@ -60,7 +65,7 @@
"cwe_ids": [
"CWE-835"
],
"severity": "MODERATE",
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2023-03-03T23:01:05Z",
"nvd_published_at": "2023-03-03T06:15:00Z"
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-52jx-g6m5-h735",
"modified": "2025-03-06T19:12:27Z",
"modified": "2025-03-06T21:36:50Z",
"published": "2025-03-06T19:12:27Z",
"aliases": [
"CVE-2025-27509"
@@ -97,6 +97,10 @@
"type": "WEB",
"url": "https://github.com/fleetdm/fleet/security/advisories/GHSA-52jx-g6m5-h735"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27509"
},
{
"type": "WEB",
"url": "https://github.com/fleetdm/fleet/commit/718c95e47ad010ad6b8ceb3f3460e921fbfc53bb"
@@ -112,11 +116,12 @@
],
"database_specific": {
"cwe_ids": [
"CWE-285",
"CWE-74"
],
"severity": "CRITICAL",
"github_reviewed": true,
"github_reviewed_at": "2025-03-06T19:12:27Z",
"nvd_published_at": null
"nvd_published_at": "2025-03-06T19:15:27Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mf24-chxh-hmvj",
"modified": "2025-03-06T19:11:39Z",
"modified": "2025-03-06T21:36:34Z",
"published": "2025-03-06T19:11:39Z",
"aliases": [
"CVE-2025-25294"
@@ -59,6 +59,10 @@
"type": "WEB",
"url": "https://github.com/envoyproxy/gateway/security/advisories/GHSA-mf24-chxh-hmvj"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25294"
},
{
"type": "WEB",
"url": "https://github.com/envoyproxy/gateway/commit/041d474a70d5921e5d65e6e14ea60e14dac70b01"
@@ -67,6 +71,10 @@
"type": "WEB",
"url": "https://github.com/envoyproxy/gateway/commit/358bed50dcb7b32f39a2edb252fb1399c7fc65dc"
},
{
"type": "WEB",
"url": "https://github.com/envoyproxy/gateway/commit/8f48f5199cf1bbb9a8ac0695c5171bfef6c9198a"
},
{
"type": "PACKAGE",
"url": "https://github.com/envoyproxy/gateway"
@@ -87,6 +95,6 @@
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2025-03-06T19:11:39Z",
"nvd_published_at": null
"nvd_published_at": "2025-03-06T19:15:27Z"
}
}
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wf6c-hrhf-86cw",
"modified": "2025-03-06T18:52:17Z",
"modified": "2025-03-06T21:36:42Z",
"published": "2025-03-06T18:52:17Z",
"aliases": [
"CVE-2025-27506"
@@ -40,6 +40,10 @@
"type": "WEB",
"url": "https://github.com/nocodb/nocodb/security/advisories/GHSA-wf6c-hrhf-86cw"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27506"
},
{
"type": "WEB",
"url": "https://github.com/nocodb/nocodb/commit/ea821edb133e621e26183ae65c8ff9ee5d6f2723"
@@ -64,6 +68,6 @@
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2025-03-06T18:52:17Z",
"nvd_published_at": null
"nvd_published_at": "2025-03-06T19:15:27Z"
}
}