diff --git a/advisories/unreviewed/2022/02/GHSA-c547-2659-q37g/GHSA-c547-2659-q37g.json b/advisories/unreviewed/2022/02/GHSA-c547-2659-q37g/GHSA-c547-2659-q37g.json index 06ef59ccd79..4a0abcb17e2 100644 --- a/advisories/unreviewed/2022/02/GHSA-c547-2659-q37g/GHSA-c547-2659-q37g.json +++ b/advisories/unreviewed/2022/02/GHSA-c547-2659-q37g/GHSA-c547-2659-q37g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c547-2659-q37g", - "modified": "2022-03-23T00:01:07Z", + "modified": "2025-05-01T18:31:41Z", "published": "2022-02-08T00:00:56Z", "aliases": [ "CVE-2021-44790" @@ -21,51 +21,7 @@ }, { "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BFSWOH4X77CV7AH7C4RMHUBDWKQDL4YH" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RGWILBORT67SHMSLYSQZG2NMXGCMPUZO" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X73C35MMMZGBVPQQCH7LQZUMYZNQA5FO" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Z7H26WJ6TPKNWV3QKY4BHKUKQVUTZJTD" - }, - { - "type": "WEB", - "url": "https://security.gentoo.org/glsa/202208-20" - }, - { - "type": "WEB", - "url": "https://security.netapp.com/advisory/ntap-20211224-0001" - }, - { - "type": "WEB", - "url": "https://support.apple.com/kb/HT213255" - }, - { - "type": "WEB", - "url": "https://support.apple.com/kb/HT213256" - }, - { - "type": "WEB", - "url": "https://support.apple.com/kb/HT213257" - }, - { - "type": "WEB", - "url": "https://www.debian.org/security/2022/dsa-5035" - }, - { - "type": "WEB", - "url": "https://www.oracle.com/security-alerts/cpuapr2022.html" - }, - { - "type": "WEB", - "url": "https://www.oracle.com/security-alerts/cpujan2022.html" + "url": "https://www.tenable.com/security/tns-2022-03" }, { "type": "WEB", @@ -73,7 +29,67 @@ }, { "type": "WEB", - "url": "https://www.tenable.com/security/tns-2022-03" + "url": "https://www.oracle.com/security-alerts/cpujan2022.html" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuapr2022.html" + }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2022/dsa-5035" + }, + { + "type": "WEB", + "url": "https://support.apple.com/kb/HT213257" + }, + { + "type": "WEB", + "url": "https://support.apple.com/kb/HT213256" + }, + { + "type": "WEB", + "url": "https://support.apple.com/kb/HT213255" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20211224-0001" + }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202208-20" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Z7H26WJ6TPKNWV3QKY4BHKUKQVUTZJTD" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X73C35MMMZGBVPQQCH7LQZUMYZNQA5FO" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RGWILBORT67SHMSLYSQZG2NMXGCMPUZO" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BFSWOH4X77CV7AH7C4RMHUBDWKQDL4YH" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z7H26WJ6TPKNWV3QKY4BHKUKQVUTZJTD" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X73C35MMMZGBVPQQCH7LQZUMYZNQA5FO" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RGWILBORT67SHMSLYSQZG2NMXGCMPUZO" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BFSWOH4X77CV7AH7C4RMHUBDWKQDL4YH" }, { "type": "WEB", diff --git a/advisories/unreviewed/2022/03/GHSA-778r-vp3x-2f8c/GHSA-778r-vp3x-2f8c.json b/advisories/unreviewed/2022/03/GHSA-778r-vp3x-2f8c/GHSA-778r-vp3x-2f8c.json index ddd456d0713..f6848d45244 100644 --- a/advisories/unreviewed/2022/03/GHSA-778r-vp3x-2f8c/GHSA-778r-vp3x-2f8c.json +++ b/advisories/unreviewed/2022/03/GHSA-778r-vp3x-2f8c/GHSA-778r-vp3x-2f8c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-778r-vp3x-2f8c", - "modified": "2022-03-19T00:01:10Z", + "modified": "2025-05-01T18:31:41Z", "published": "2022-03-15T00:01:02Z", "aliases": [ "CVE-2022-23943" @@ -27,6 +27,18 @@ "type": "WEB", "url": "https://lists.debian.org/debian-lts-announce/2022/03/msg00033.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RGWILBORT67SHMSLYSQZG2NMXGCMPUZO" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X73C35MMMZGBVPQQCH7LQZUMYZNQA5FO" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z7H26WJ6TPKNWV3QKY4BHKUKQVUTZJTD" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RGWILBORT67SHMSLYSQZG2NMXGCMPUZO" @@ -66,6 +78,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-190", "CWE-787" ], "severity": "CRITICAL", diff --git a/advisories/unreviewed/2022/05/GHSA-89mq-r3q6-9q3q/GHSA-89mq-r3q6-9q3q.json b/advisories/unreviewed/2022/05/GHSA-89mq-r3q6-9q3q/GHSA-89mq-r3q6-9q3q.json index 93277dbda78..159be05d15f 100644 --- a/advisories/unreviewed/2022/05/GHSA-89mq-r3q6-9q3q/GHSA-89mq-r3q6-9q3q.json +++ b/advisories/unreviewed/2022/05/GHSA-89mq-r3q6-9q3q/GHSA-89mq-r3q6-9q3q.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-89mq-r3q6-9q3q", - "modified": "2022-05-24T17:25:02Z", + "modified": "2025-05-01T18:31:41Z", "published": "2022-05-24T17:25:02Z", "aliases": [ "CVE-2020-11993" ], "details": "Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic edge patterns, logging statements were made on the wrong connection, causing concurrent use of memory pools. Configuring the LogLevel of mod_http2 above \"info\" will mitigate this vulnerability for unpatched servers.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -16,47 +21,7 @@ }, { "type": "WEB", - "url": "https://www.oracle.com/security-alerts/cpuoct2020.html" - }, - { - "type": "WEB", - "url": "https://www.oracle.com/security-alerts/cpujan2021.html" - }, - { - "type": "WEB", - "url": "https://www.debian.org/security/2020/dsa-4757" - }, - { - "type": "WEB", - "url": "https://usn.ubuntu.com/4458-1" - }, - { - "type": "WEB", - "url": "https://security.netapp.com/advisory/ntap-20200814-0005" - }, - { - "type": "WEB", - "url": "https://security.gentoo.org/glsa/202008-04" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ITVFDBVM6E3JF3O7RYLRPRCH3RDRHJJY" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4NKWG2EXAQQB6LMLATKZ7KLSRGCSHVAN" - }, - { - "type": "WEB", - "url": "https://lists.apache.org/thread.html/rf71eb428714374a6f9ad68952e23611ec7807b029fd6a1b4f5f732d9@%3Ccvs.httpd.apache.org%3E" - }, - { - "type": "WEB", - "url": "https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9@%3Ccvs.httpd.apache.org%3E" - }, - { - "type": "WEB", - "url": "https://lists.apache.org/thread.html/rdf3e5d0a5f5c3d90d6013bccc6c4d5af59cf1f8c8dea5d9a283d13ce@%3Ccvs.httpd.apache.org%3E" + "url": "https://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3E" }, { "type": "WEB", @@ -64,35 +29,75 @@ }, { "type": "WEB", - "url": "https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920@%3Ccvs.httpd.apache.org%3E" + "url": "https://lists.apache.org/thread.html/rdf3e5d0a5f5c3d90d6013bccc6c4d5af59cf1f8c8dea5d9a283d13ce%40%3Ccvs.httpd.apache.org%3E" }, { "type": "WEB", - "url": "https://lists.apache.org/thread.html/r9e9f1a7609760f0f80562eaaec2aa3c32d525c3e0fca98b475240c71@%3Cdev.httpd.apache.org%3E" + "url": "https://lists.apache.org/thread.html/rdf3e5d0a5f5c3d90d6013bccc6c4d5af59cf1f8c8dea5d9a283d13ce@%3Ccvs.httpd.apache.org%3E" }, { "type": "WEB", - "url": "https://lists.apache.org/thread.html/r76142b8c5119df2178be7c2dba88fde552eedeec37ea993dfce68d1d@%3Ccvs.httpd.apache.org%3E" + "url": "https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E" }, { "type": "WEB", - "url": "https://lists.apache.org/thread.html/r623de9b2b2433a87f3f3a15900419fc9c00c77b26936dfea4060f672@%3Cdev.httpd.apache.org%3E" + "url": "https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9@%3Ccvs.httpd.apache.org%3E" }, { "type": "WEB", - "url": "https://lists.apache.org/thread.html/r5debe8f82728a00a4a68bc904dd6c35423bdfc8d601cfb4579f38bf1@%3Cdev.httpd.apache.org%3E" + "url": "https://lists.apache.org/thread.html/rf71eb428714374a6f9ad68952e23611ec7807b029fd6a1b4f5f732d9%40%3Ccvs.httpd.apache.org%3E" }, { "type": "WEB", - "url": "https://lists.apache.org/thread.html/r3c5c3104813c1c5508b55564b66546933079250a46ce50eee90b2e36@%3Ccvs.httpd.apache.org%3E" + "url": "https://lists.apache.org/thread.html/rf71eb428714374a6f9ad68952e23611ec7807b029fd6a1b4f5f732d9@%3Ccvs.httpd.apache.org%3E" }, { "type": "WEB", - "url": "https://lists.apache.org/thread.html/r2c6083f6a2027914a0f5b54e2a1f4fa98c03f8693b58460911818255@%3Ccvs.httpd.apache.org%3E" + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4NKWG2EXAQQB6LMLATKZ7KLSRGCSHVAN" }, { "type": "WEB", - "url": "https://lists.apache.org/thread.html/r09bb998baee74a2c316446bd1a41ae7f8d7049d09d9ff991471e8775@%3Ccvs.httpd.apache.org%3E" + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ITVFDBVM6E3JF3O7RYLRPRCH3RDRHJJY" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4NKWG2EXAQQB6LMLATKZ7KLSRGCSHVAN" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ITVFDBVM6E3JF3O7RYLRPRCH3RDRHJJY" + }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202008-04" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20200814-0005" + }, + { + "type": "WEB", + "url": "https://usn.ubuntu.com/4458-1" + }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2020/dsa-4757" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujan2021.html" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuoct2020.html" + }, + { + "type": "WEB", + "url": "https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2020-11993" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r06f0d87ebb6d59ed8379633f36f72f5b1f79cadfda72ede0830b42cf%40%3Ccvs.httpd.apache.org%3E" }, { "type": "WEB", @@ -100,7 +105,67 @@ }, { "type": "WEB", - "url": "https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2020-11993" + "url": "https://lists.apache.org/thread.html/r09bb998baee74a2c316446bd1a41ae7f8d7049d09d9ff991471e8775%40%3Ccvs.httpd.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r09bb998baee74a2c316446bd1a41ae7f8d7049d09d9ff991471e8775@%3Ccvs.httpd.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r2c6083f6a2027914a0f5b54e2a1f4fa98c03f8693b58460911818255%40%3Ccvs.httpd.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r2c6083f6a2027914a0f5b54e2a1f4fa98c03f8693b58460911818255@%3Ccvs.httpd.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r3c5c3104813c1c5508b55564b66546933079250a46ce50eee90b2e36%40%3Ccvs.httpd.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r3c5c3104813c1c5508b55564b66546933079250a46ce50eee90b2e36@%3Ccvs.httpd.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r5debe8f82728a00a4a68bc904dd6c35423bdfc8d601cfb4579f38bf1%40%3Cdev.httpd.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r5debe8f82728a00a4a68bc904dd6c35423bdfc8d601cfb4579f38bf1@%3Cdev.httpd.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r623de9b2b2433a87f3f3a15900419fc9c00c77b26936dfea4060f672%40%3Cdev.httpd.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r623de9b2b2433a87f3f3a15900419fc9c00c77b26936dfea4060f672@%3Cdev.httpd.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r76142b8c5119df2178be7c2dba88fde552eedeec37ea993dfce68d1d%40%3Ccvs.httpd.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r76142b8c5119df2178be7c2dba88fde552eedeec37ea993dfce68d1d@%3Ccvs.httpd.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r9e9f1a7609760f0f80562eaaec2aa3c32d525c3e0fca98b475240c71%40%3Cdev.httpd.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r9e9f1a7609760f0f80562eaaec2aa3c32d525c3e0fca98b475240c71@%3Cdev.httpd.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920@%3Ccvs.httpd.apache.org%3E" }, { "type": "WEB", diff --git a/advisories/unreviewed/2022/05/GHSA-f4wr-wvqf-r2q5/GHSA-f4wr-wvqf-r2q5.json b/advisories/unreviewed/2022/05/GHSA-f4wr-wvqf-r2q5/GHSA-f4wr-wvqf-r2q5.json index 2c9e6486498..bcb9b02686f 100644 --- a/advisories/unreviewed/2022/05/GHSA-f4wr-wvqf-r2q5/GHSA-f4wr-wvqf-r2q5.json +++ b/advisories/unreviewed/2022/05/GHSA-f4wr-wvqf-r2q5/GHSA-f4wr-wvqf-r2q5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-f4wr-wvqf-r2q5", - "modified": "2022-05-24T19:14:50Z", + "modified": "2025-05-01T18:31:41Z", "published": "2022-05-24T19:14:50Z", "aliases": [ "CVE-2021-36160" @@ -21,51 +21,11 @@ }, { "type": "WEB", - "url": "https://www.oracle.com/security-alerts/cpujan2022.html" + "url": "https://lists.apache.org/thread.html/r2eb200ac1340f69aa22af61ab34780c531d110437910cb9c0ece3b37%40%3Cbugs.httpd.apache.org%3E" }, { "type": "WEB", - "url": "https://www.oracle.com/security-alerts/cpuapr2022.html" - }, - { - "type": "WEB", - "url": "https://www.debian.org/security/2021/dsa-4982" - }, - { - "type": "WEB", - "url": "https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-httpd-2.4.49-VWL69sWQ" - }, - { - "type": "WEB", - "url": "https://security.netapp.com/advisory/ntap-20211008-0004" - }, - { - "type": "WEB", - "url": "https://security.gentoo.org/glsa/202208-20" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZNCYSR3BXT36FFF4XTCPL3HDQK4VP45R" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SPBR6WUYBJNACHKE65SPL7TJOHX7RHWD" - }, - { - "type": "WEB", - "url": "https://lists.debian.org/debian-lts-announce/2021/10/msg00016.html" - }, - { - "type": "WEB", - "url": "https://lists.debian.org/debian-lts-announce/2021/09/msg00016.html" - }, - { - "type": "WEB", - "url": "https://lists.apache.org/thread.html/ree7519d71415ecdd170ff1889cab552d71758d2ba2904a17ded21a70@%3Ccvs.httpd.apache.org%3E" - }, - { - "type": "WEB", - "url": "https://lists.apache.org/thread.html/re4162adc051c1a0a79e7a24093f3776373e8733abaff57253fef341d@%3Ccvs.httpd.apache.org%3E" + "url": "https://lists.apache.org/thread.html/rb2341c8786d0f9924f5b666e82d8d170b4804f50a523d750551bef1a%40%3Cbugs.httpd.apache.org%3E" }, { "type": "WEB", @@ -73,35 +33,75 @@ }, { "type": "WEB", - "url": "https://lists.apache.org/thread.html/ra87a69d0703d09dc52b86e32b08f8d7327af10acdd5f577a4e82596a@%3Cbugs.httpd.apache.org%3E" + "url": "https://lists.apache.org/thread.html/re4162adc051c1a0a79e7a24093f3776373e8733abaff57253fef341d%40%3Ccvs.httpd.apache.org%3E" }, { "type": "WEB", - "url": "https://lists.apache.org/thread.html/ra1c05a392587bfe34383dffe1213edc425de8d4afc25b7cefab3e781@%3Cbugs.httpd.apache.org%3E" + "url": "https://lists.apache.org/thread.html/re4162adc051c1a0a79e7a24093f3776373e8733abaff57253fef341d@%3Ccvs.httpd.apache.org%3E" }, { "type": "WEB", - "url": "https://lists.apache.org/thread.html/r94a61a1517133a19dcf40016e87454ea86e355d06a0cec4c778530f3@%3Cbugs.httpd.apache.org%3E" + "url": "https://lists.apache.org/thread.html/ree7519d71415ecdd170ff1889cab552d71758d2ba2904a17ded21a70%40%3Ccvs.httpd.apache.org%3E" }, { "type": "WEB", - "url": "https://lists.apache.org/thread.html/r82c077663f9759c7df5a6656f925b3ee4f55fcd33c889ba7cd687029@%3Cusers.httpd.apache.org%3E" + "url": "https://lists.apache.org/thread.html/ree7519d71415ecdd170ff1889cab552d71758d2ba2904a17ded21a70@%3Ccvs.httpd.apache.org%3E" }, { "type": "WEB", - "url": "https://lists.apache.org/thread.html/r82838efc5fa6fc4c73986399c9b71573589f78b31846aff5bd9b1697@%3Cusers.httpd.apache.org%3E" + "url": "https://lists.debian.org/debian-lts-announce/2021/09/msg00016.html" }, { "type": "WEB", - "url": "https://lists.apache.org/thread.html/r7f2746e916ed370239bc1a1025e5ebbf345f79df9ea0ea39e44acfbb@%3Cbugs.httpd.apache.org%3E" + "url": "https://lists.debian.org/debian-lts-announce/2021/10/msg00016.html" }, { "type": "WEB", - "url": "https://lists.apache.org/thread.html/r73260f6ba9fb52e43d860905fc90462ba5a814afda2d011f32bbd41c@%3Cbugs.httpd.apache.org%3E" + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SPBR6WUYBJNACHKE65SPL7TJOHX7RHWD" }, { "type": "WEB", - "url": "https://lists.apache.org/thread.html/r61fdbfc26ab170f4e6492ef3bd5197c20b862ce156e9d5a54d4b899c@%3Cusers.httpd.apache.org%3E" + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZNCYSR3BXT36FFF4XTCPL3HDQK4VP45R" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SPBR6WUYBJNACHKE65SPL7TJOHX7RHWD" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZNCYSR3BXT36FFF4XTCPL3HDQK4VP45R" + }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202208-20" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20211008-0004" + }, + { + "type": "WEB", + "url": "https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-httpd-2.4.49-VWL69sWQ" + }, + { + "type": "WEB", + "url": "https://www.debian.org/security/2021/dsa-4982" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpuapr2022.html" + }, + { + "type": "WEB", + "url": "https://www.oracle.com/security-alerts/cpujan2022.html" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r2eb200ac1340f69aa22af61ab34780c531d110437910cb9c0ece3b37@%3Cbugs.httpd.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r3925e167d5eb1c75def3750c155d753064e1d34a143028bb32910432%40%3Cusers.httpd.apache.org%3E" }, { "type": "WEB", @@ -109,7 +109,67 @@ }, { "type": "WEB", - "url": "https://lists.apache.org/thread.html/r2eb200ac1340f69aa22af61ab34780c531d110437910cb9c0ece3b37@%3Cbugs.httpd.apache.org%3E" + "url": "https://lists.apache.org/thread.html/r61fdbfc26ab170f4e6492ef3bd5197c20b862ce156e9d5a54d4b899c%40%3Cusers.httpd.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r61fdbfc26ab170f4e6492ef3bd5197c20b862ce156e9d5a54d4b899c@%3Cusers.httpd.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r73260f6ba9fb52e43d860905fc90462ba5a814afda2d011f32bbd41c%40%3Cbugs.httpd.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r73260f6ba9fb52e43d860905fc90462ba5a814afda2d011f32bbd41c@%3Cbugs.httpd.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r7f2746e916ed370239bc1a1025e5ebbf345f79df9ea0ea39e44acfbb%40%3Cbugs.httpd.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r7f2746e916ed370239bc1a1025e5ebbf345f79df9ea0ea39e44acfbb@%3Cbugs.httpd.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r82838efc5fa6fc4c73986399c9b71573589f78b31846aff5bd9b1697%40%3Cusers.httpd.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r82838efc5fa6fc4c73986399c9b71573589f78b31846aff5bd9b1697@%3Cusers.httpd.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r82c077663f9759c7df5a6656f925b3ee4f55fcd33c889ba7cd687029%40%3Cusers.httpd.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r82c077663f9759c7df5a6656f925b3ee4f55fcd33c889ba7cd687029@%3Cusers.httpd.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r94a61a1517133a19dcf40016e87454ea86e355d06a0cec4c778530f3%40%3Cbugs.httpd.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r94a61a1517133a19dcf40016e87454ea86e355d06a0cec4c778530f3@%3Cbugs.httpd.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/ra1c05a392587bfe34383dffe1213edc425de8d4afc25b7cefab3e781%40%3Cbugs.httpd.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/ra1c05a392587bfe34383dffe1213edc425de8d4afc25b7cefab3e781@%3Cbugs.httpd.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/ra87a69d0703d09dc52b86e32b08f8d7327af10acdd5f577a4e82596a%40%3Cbugs.httpd.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/ra87a69d0703d09dc52b86e32b08f8d7327af10acdd5f577a4e82596a@%3Cbugs.httpd.apache.org%3E" }, { "type": "WEB", diff --git a/advisories/unreviewed/2022/05/GHSA-p59c-pqfv-4fwc/GHSA-p59c-pqfv-4fwc.json b/advisories/unreviewed/2022/05/GHSA-p59c-pqfv-4fwc/GHSA-p59c-pqfv-4fwc.json index 66660166749..415f1ec4081 100644 --- a/advisories/unreviewed/2022/05/GHSA-p59c-pqfv-4fwc/GHSA-p59c-pqfv-4fwc.json +++ b/advisories/unreviewed/2022/05/GHSA-p59c-pqfv-4fwc/GHSA-p59c-pqfv-4fwc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p59c-pqfv-4fwc", - "modified": "2022-05-24T19:14:50Z", + "modified": "2025-05-01T18:31:41Z", "published": "2022-05-24T19:14:50Z", "aliases": [ "CVE-2021-39275" @@ -21,55 +21,7 @@ }, { "type": "WEB", - "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-685781.pdf" - }, - { - "type": "WEB", - "url": "https://httpd.apache.org/security/vulnerabilities_24.html" - }, - { - "type": "WEB", - "url": "https://lists.apache.org/thread.html/r3925e167d5eb1c75def3750c155d753064e1d34a143028bb32910432@%3Cusers.httpd.apache.org%3E" - }, - { - "type": "WEB", - "url": "https://lists.apache.org/thread.html/r61fdbfc26ab170f4e6492ef3bd5197c20b862ce156e9d5a54d4b899c@%3Cusers.httpd.apache.org%3E" - }, - { - "type": "WEB", - "url": "https://lists.apache.org/thread.html/r82838efc5fa6fc4c73986399c9b71573589f78b31846aff5bd9b1697@%3Cusers.httpd.apache.org%3E" - }, - { - "type": "WEB", - "url": "https://lists.apache.org/thread.html/r82c077663f9759c7df5a6656f925b3ee4f55fcd33c889ba7cd687029@%3Cusers.httpd.apache.org%3E" - }, - { - "type": "WEB", - "url": "https://lists.debian.org/debian-lts-announce/2021/10/msg00001.html" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SPBR6WUYBJNACHKE65SPL7TJOHX7RHWD" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZNCYSR3BXT36FFF4XTCPL3HDQK4VP45R" - }, - { - "type": "WEB", - "url": "https://security.gentoo.org/glsa/202208-20" - }, - { - "type": "WEB", - "url": "https://security.netapp.com/advisory/ntap-20211008-0004" - }, - { - "type": "WEB", - "url": "https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-httpd-2.4.49-VWL69sWQ" - }, - { - "type": "WEB", - "url": "https://www.debian.org/security/2021/dsa-4982" + "url": "https://www.oracle.com/security-alerts/cpujan2022.html" }, { "type": "WEB", @@ -77,7 +29,79 @@ }, { "type": "WEB", - "url": "https://www.oracle.com/security-alerts/cpujan2022.html" + "url": "https://www.debian.org/security/2021/dsa-4982" + }, + { + "type": "WEB", + "url": "https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-httpd-2.4.49-VWL69sWQ" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20211008-0004" + }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202208-20" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZNCYSR3BXT36FFF4XTCPL3HDQK4VP45R" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SPBR6WUYBJNACHKE65SPL7TJOHX7RHWD" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZNCYSR3BXT36FFF4XTCPL3HDQK4VP45R" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SPBR6WUYBJNACHKE65SPL7TJOHX7RHWD" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2021/10/msg00001.html" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r82c077663f9759c7df5a6656f925b3ee4f55fcd33c889ba7cd687029@%3Cusers.httpd.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r82c077663f9759c7df5a6656f925b3ee4f55fcd33c889ba7cd687029%40%3Cusers.httpd.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r82838efc5fa6fc4c73986399c9b71573589f78b31846aff5bd9b1697@%3Cusers.httpd.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r82838efc5fa6fc4c73986399c9b71573589f78b31846aff5bd9b1697%40%3Cusers.httpd.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r61fdbfc26ab170f4e6492ef3bd5197c20b862ce156e9d5a54d4b899c@%3Cusers.httpd.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r61fdbfc26ab170f4e6492ef3bd5197c20b862ce156e9d5a54d4b899c%40%3Cusers.httpd.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r3925e167d5eb1c75def3750c155d753064e1d34a143028bb32910432@%3Cusers.httpd.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/r3925e167d5eb1c75def3750c155d753064e1d34a143028bb32910432%40%3Cusers.httpd.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://httpd.apache.org/security/vulnerabilities_24.html" + }, + { + "type": "WEB", + "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-685781.pdf" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/05/GHSA-p9fg-6rr5-38xc/GHSA-p9fg-6rr5-38xc.json b/advisories/unreviewed/2022/05/GHSA-p9fg-6rr5-38xc/GHSA-p9fg-6rr5-38xc.json index 84ba6f5fcaa..78cd82325ca 100644 --- a/advisories/unreviewed/2022/05/GHSA-p9fg-6rr5-38xc/GHSA-p9fg-6rr5-38xc.json +++ b/advisories/unreviewed/2022/05/GHSA-p9fg-6rr5-38xc/GHSA-p9fg-6rr5-38xc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p9fg-6rr5-38xc", - "modified": "2022-05-24T19:11:19Z", + "modified": "2025-05-01T18:31:40Z", "published": "2022-05-24T19:11:19Z", "aliases": [ "CVE-2021-33193" @@ -25,43 +25,7 @@ }, { "type": "WEB", - "url": "https://lists.apache.org/thread.html/re4162adc051c1a0a79e7a24093f3776373e8733abaff57253fef341d@%3Ccvs.httpd.apache.org%3E" - }, - { - "type": "WEB", - "url": "https://lists.apache.org/thread.html/ree7519d71415ecdd170ff1889cab552d71758d2ba2904a17ded21a70@%3Ccvs.httpd.apache.org%3E" - }, - { - "type": "WEB", - "url": "https://lists.debian.org/debian-lts-announce/2023/03/msg00002.html" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DSM6UWQICBJ2TU727RENU3HBKEAFLT6T" - }, - { - "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EUVJVRJRBW5QVX4OY3NOHZDQ3B3YOTSG" - }, - { - "type": "WEB", - "url": "https://portswigger.net/research/http2" - }, - { - "type": "WEB", - "url": "https://security.gentoo.org/glsa/202208-20" - }, - { - "type": "WEB", - "url": "https://security.netapp.com/advisory/ntap-20210917-0004" - }, - { - "type": "WEB", - "url": "https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-httpd-2.4.49-VWL69sWQ" - }, - { - "type": "WEB", - "url": "https://www.oracle.com/security-alerts/cpuapr2022.html" + "url": "https://www.tenable.com/security/tns-2021-17" }, { "type": "WEB", @@ -69,7 +33,59 @@ }, { "type": "WEB", - "url": "https://www.tenable.com/security/tns-2021-17" + "url": "https://www.oracle.com/security-alerts/cpuapr2022.html" + }, + { + "type": "WEB", + "url": "https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-httpd-2.4.49-VWL69sWQ" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20210917-0004" + }, + { + "type": "WEB", + "url": "https://security.gentoo.org/glsa/202208-20" + }, + { + "type": "WEB", + "url": "https://portswigger.net/research/http2" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/EUVJVRJRBW5QVX4OY3NOHZDQ3B3YOTSG" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DSM6UWQICBJ2TU727RENU3HBKEAFLT6T" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EUVJVRJRBW5QVX4OY3NOHZDQ3B3YOTSG" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DSM6UWQICBJ2TU727RENU3HBKEAFLT6T" + }, + { + "type": "WEB", + "url": "https://lists.debian.org/debian-lts-announce/2023/03/msg00002.html" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/ree7519d71415ecdd170ff1889cab552d71758d2ba2904a17ded21a70@%3Ccvs.httpd.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/ree7519d71415ecdd170ff1889cab552d71758d2ba2904a17ded21a70%40%3Ccvs.httpd.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/re4162adc051c1a0a79e7a24093f3776373e8733abaff57253fef341d@%3Ccvs.httpd.apache.org%3E" + }, + { + "type": "WEB", + "url": "https://lists.apache.org/thread.html/re4162adc051c1a0a79e7a24093f3776373e8733abaff57253fef341d%40%3Ccvs.httpd.apache.org%3E" } ], "database_specific": { diff --git a/advisories/unreviewed/2022/06/GHSA-4hj9-gjv4-4363/GHSA-4hj9-gjv4-4363.json b/advisories/unreviewed/2022/06/GHSA-4hj9-gjv4-4363/GHSA-4hj9-gjv4-4363.json index 7625e0ed78e..75fc4ecb297 100644 --- a/advisories/unreviewed/2022/06/GHSA-4hj9-gjv4-4363/GHSA-4hj9-gjv4-4363.json +++ b/advisories/unreviewed/2022/06/GHSA-4hj9-gjv4-4363/GHSA-4hj9-gjv4-4363.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4hj9-gjv4-4363", - "modified": "2022-06-17T00:01:28Z", + "modified": "2025-05-01T18:31:42Z", "published": "2022-06-10T00:00:55Z", "aliases": [ "CVE-2022-28615" @@ -23,6 +23,14 @@ "type": "WEB", "url": "https://httpd.apache.org/security/vulnerabilities_24.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7QUGG2QZWHTITMABFLVXA4DNYUOTPWYQ" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YPY2BLEVJWFH34AX77ZJPLD2OOBYR6ND" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7QUGG2QZWHTITMABFLVXA4DNYUOTPWYQ" diff --git a/advisories/unreviewed/2022/06/GHSA-4xc6-mgv4-5v44/GHSA-4xc6-mgv4-5v44.json b/advisories/unreviewed/2022/06/GHSA-4xc6-mgv4-5v44/GHSA-4xc6-mgv4-5v44.json index cfe3308821f..ffadd2f8d2a 100644 --- a/advisories/unreviewed/2022/06/GHSA-4xc6-mgv4-5v44/GHSA-4xc6-mgv4-5v44.json +++ b/advisories/unreviewed/2022/06/GHSA-4xc6-mgv4-5v44/GHSA-4xc6-mgv4-5v44.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4xc6-mgv4-5v44", - "modified": "2022-06-18T00:00:20Z", + "modified": "2025-05-01T18:31:42Z", "published": "2022-06-10T00:00:55Z", "aliases": [ "CVE-2022-31813" @@ -23,6 +23,14 @@ "type": "WEB", "url": "https://httpd.apache.org/security/vulnerabilities_24.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7QUGG2QZWHTITMABFLVXA4DNYUOTPWYQ" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YPY2BLEVJWFH34AX77ZJPLD2OOBYR6ND" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7QUGG2QZWHTITMABFLVXA4DNYUOTPWYQ" @@ -46,7 +54,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-345" + "CWE-345", + "CWE-348" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/06/GHSA-gvrr-g8v5-hjqr/GHSA-gvrr-g8v5-hjqr.json b/advisories/unreviewed/2022/06/GHSA-gvrr-g8v5-hjqr/GHSA-gvrr-g8v5-hjqr.json index b0456cb3ec9..290a1243f34 100644 --- a/advisories/unreviewed/2022/06/GHSA-gvrr-g8v5-hjqr/GHSA-gvrr-g8v5-hjqr.json +++ b/advisories/unreviewed/2022/06/GHSA-gvrr-g8v5-hjqr/GHSA-gvrr-g8v5-hjqr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gvrr-g8v5-hjqr", - "modified": "2022-06-18T00:00:20Z", + "modified": "2025-05-01T18:31:42Z", "published": "2022-06-10T00:00:55Z", "aliases": [ "CVE-2022-30556" @@ -23,6 +23,14 @@ "type": "WEB", "url": "https://httpd.apache.org/security/vulnerabilities_24.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7QUGG2QZWHTITMABFLVXA4DNYUOTPWYQ" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YPY2BLEVJWFH34AX77ZJPLD2OOBYR6ND" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7QUGG2QZWHTITMABFLVXA4DNYUOTPWYQ" diff --git a/advisories/unreviewed/2022/06/GHSA-gx9q-f765-xrgg/GHSA-gx9q-f765-xrgg.json b/advisories/unreviewed/2022/06/GHSA-gx9q-f765-xrgg/GHSA-gx9q-f765-xrgg.json index daba2d9a2b0..d8beda7b409 100644 --- a/advisories/unreviewed/2022/06/GHSA-gx9q-f765-xrgg/GHSA-gx9q-f765-xrgg.json +++ b/advisories/unreviewed/2022/06/GHSA-gx9q-f765-xrgg/GHSA-gx9q-f765-xrgg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gx9q-f765-xrgg", - "modified": "2022-06-17T00:01:27Z", + "modified": "2025-05-01T18:31:41Z", "published": "2022-06-10T00:00:55Z", "aliases": [ "CVE-2022-26377" @@ -23,6 +23,14 @@ "type": "WEB", "url": "https://httpd.apache.org/security/vulnerabilities_24.html" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7QUGG2QZWHTITMABFLVXA4DNYUOTPWYQ" + }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YPY2BLEVJWFH34AX77ZJPLD2OOBYR6ND" + }, { "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7QUGG2QZWHTITMABFLVXA4DNYUOTPWYQ" diff --git a/advisories/unreviewed/2022/11/GHSA-5m37-wwv9-vm8g/GHSA-5m37-wwv9-vm8g.json b/advisories/unreviewed/2022/11/GHSA-5m37-wwv9-vm8g/GHSA-5m37-wwv9-vm8g.json index 47e69ff01d3..749f5f78910 100644 --- a/advisories/unreviewed/2022/11/GHSA-5m37-wwv9-vm8g/GHSA-5m37-wwv9-vm8g.json +++ b/advisories/unreviewed/2022/11/GHSA-5m37-wwv9-vm8g/GHSA-5m37-wwv9-vm8g.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-284" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-72h9-mpvp-p445/GHSA-72h9-mpvp-p445.json b/advisories/unreviewed/2022/11/GHSA-72h9-mpvp-p445/GHSA-72h9-mpvp-p445.json index 47c21d1ba6a..5aa495cf5ba 100644 --- a/advisories/unreviewed/2022/11/GHSA-72h9-mpvp-p445/GHSA-72h9-mpvp-p445.json +++ b/advisories/unreviewed/2022/11/GHSA-72h9-mpvp-p445/GHSA-72h9-mpvp-p445.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-276" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-8vrc-m2h5-hwr9/GHSA-8vrc-m2h5-hwr9.json b/advisories/unreviewed/2022/11/GHSA-8vrc-m2h5-hwr9/GHSA-8vrc-m2h5-hwr9.json index 2ba798e5981..896f3101abb 100644 --- a/advisories/unreviewed/2022/11/GHSA-8vrc-m2h5-hwr9/GHSA-8vrc-m2h5-hwr9.json +++ b/advisories/unreviewed/2022/11/GHSA-8vrc-m2h5-hwr9/GHSA-8vrc-m2h5-hwr9.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-276" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-9672-4fh3-mcfg/GHSA-9672-4fh3-mcfg.json b/advisories/unreviewed/2022/11/GHSA-9672-4fh3-mcfg/GHSA-9672-4fh3-mcfg.json index 031f5946f80..c89e60955a3 100644 --- a/advisories/unreviewed/2022/11/GHSA-9672-4fh3-mcfg/GHSA-9672-4fh3-mcfg.json +++ b/advisories/unreviewed/2022/11/GHSA-9672-4fh3-mcfg/GHSA-9672-4fh3-mcfg.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-639", "CWE-863" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2022/11/GHSA-pppm-qqpf-jj26/GHSA-pppm-qqpf-jj26.json b/advisories/unreviewed/2022/11/GHSA-pppm-qqpf-jj26/GHSA-pppm-qqpf-jj26.json index 50b128436e7..7726830e9f9 100644 --- a/advisories/unreviewed/2022/11/GHSA-pppm-qqpf-jj26/GHSA-pppm-qqpf-jj26.json +++ b/advisories/unreviewed/2022/11/GHSA-pppm-qqpf-jj26/GHSA-pppm-qqpf-jj26.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-276" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-q4vj-h3gm-jx5h/GHSA-q4vj-h3gm-jx5h.json b/advisories/unreviewed/2022/11/GHSA-q4vj-h3gm-jx5h/GHSA-q4vj-h3gm-jx5h.json index 71d279d07d3..78c0e8b7c31 100644 --- a/advisories/unreviewed/2022/11/GHSA-q4vj-h3gm-jx5h/GHSA-q4vj-h3gm-jx5h.json +++ b/advisories/unreviewed/2022/11/GHSA-q4vj-h3gm-jx5h/GHSA-q4vj-h3gm-jx5h.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-400" + "CWE-400", + "CWE-754" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/11/GHSA-r77h-h23j-fv39/GHSA-r77h-h23j-fv39.json b/advisories/unreviewed/2022/11/GHSA-r77h-h23j-fv39/GHSA-r77h-h23j-fv39.json index b0c76016a4f..ac6eea68afb 100644 --- a/advisories/unreviewed/2022/11/GHSA-r77h-h23j-fv39/GHSA-r77h-h23j-fv39.json +++ b/advisories/unreviewed/2022/11/GHSA-r77h-h23j-fv39/GHSA-r77h-h23j-fv39.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-276" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2022/11/GHSA-xj28-8c9f-6cgg/GHSA-xj28-8c9f-6cgg.json b/advisories/unreviewed/2022/11/GHSA-xj28-8c9f-6cgg/GHSA-xj28-8c9f-6cgg.json index a763fdffd9b..439dc62c935 100644 --- a/advisories/unreviewed/2022/11/GHSA-xj28-8c9f-6cgg/GHSA-xj28-8c9f-6cgg.json +++ b/advisories/unreviewed/2022/11/GHSA-xj28-8c9f-6cgg/GHSA-xj28-8c9f-6cgg.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xj28-8c9f-6cgg", - "modified": "2022-11-10T19:01:11Z", + "modified": "2025-05-01T18:31:44Z", "published": "2022-11-10T12:01:16Z", "aliases": [ "CVE-2022-44547" diff --git a/advisories/unreviewed/2022/11/GHSA-xm24-7c3w-pfc7/GHSA-xm24-7c3w-pfc7.json b/advisories/unreviewed/2022/11/GHSA-xm24-7c3w-pfc7/GHSA-xm24-7c3w-pfc7.json index d808b198b76..bb5222995b2 100644 --- a/advisories/unreviewed/2022/11/GHSA-xm24-7c3w-pfc7/GHSA-xm24-7c3w-pfc7.json +++ b/advisories/unreviewed/2022/11/GHSA-xm24-7c3w-pfc7/GHSA-xm24-7c3w-pfc7.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-754" + "CWE-754", + "CWE-755" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/05/GHSA-22jc-frmh-h993/GHSA-22jc-frmh-h993.json b/advisories/unreviewed/2025/05/GHSA-22jc-frmh-h993/GHSA-22jc-frmh-h993.json new file mode 100644 index 00000000000..6937443bc5c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-22jc-frmh-h993/GHSA-22jc-frmh-h993.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-22jc-frmh-h993", + "modified": "2025-05-01T18:31:47Z", + "published": "2025-05-01T18:31:47Z", + "aliases": [ + "CVE-2025-44845" + ], + "details": "TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the NTPSyncWithHost function via the hostTime parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44845" + }, + { + "type": "WEB", + "url": "https://github.com/Summermu/VulnForIoT/tree/main/Totolink_CA600-PoE/NTPSyncWithHost/readme.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T17:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-2fc6-6f56-6w7m/GHSA-2fc6-6f56-6w7m.json b/advisories/unreviewed/2025/05/GHSA-2fc6-6f56-6w7m/GHSA-2fc6-6f56-6w7m.json new file mode 100644 index 00000000000..cfa0d0c2390 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-2fc6-6f56-6w7m/GHSA-2fc6-6f56-6w7m.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2fc6-6f56-6w7m", + "modified": "2025-05-01T18:31:48Z", + "published": "2025-05-01T18:31:48Z", + "aliases": [ + "CVE-2025-4173" + ], + "details": "A vulnerability classified as critical was found in SourceCodester Online Eyewear Shop 1.0. Affected by this vulnerability is the function delete_cart of the file /oews/classes/Master.php?f=delete_cart. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4173" + }, + { + "type": "WEB", + "url": "https://github.com/huashuocc/cve/blob/main/sql.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.306793" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.306793" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.561737" + }, + { + "type": "WEB", + "url": "https://www.sourcecodester.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T17:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4pqf-x898-75w7/GHSA-4pqf-x898-75w7.json b/advisories/unreviewed/2025/05/GHSA-4pqf-x898-75w7/GHSA-4pqf-x898-75w7.json new file mode 100644 index 00000000000..8ff95dfaaf3 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4pqf-x898-75w7/GHSA-4pqf-x898-75w7.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4pqf-x898-75w7", + "modified": "2025-05-01T18:31:47Z", + "published": "2025-05-01T18:31:47Z", + "aliases": [ + "CVE-2025-44842" + ], + "details": "TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the msg_process function via the Port parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44842" + }, + { + "type": "WEB", + "url": "https://github.com/Summermu/VulnForIoT/tree/main/Totolink_CA600-PoE/msg_process_Port/readme.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T17:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-5c44-2p98-m32j/GHSA-5c44-2p98-m32j.json b/advisories/unreviewed/2025/05/GHSA-5c44-2p98-m32j/GHSA-5c44-2p98-m32j.json new file mode 100644 index 00000000000..1f71ef97dd8 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-5c44-2p98-m32j/GHSA-5c44-2p98-m32j.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-5c44-2p98-m32j", + "modified": "2025-05-01T18:31:46Z", + "published": "2025-05-01T18:31:46Z", + "aliases": [ + "CVE-2025-44840" + ], + "details": "TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the CloudSrvUserdataVersionCheck function via the svn parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44840" + }, + { + "type": "WEB", + "url": "https://github.com/Summermu/VulnForIoT/tree/main/Totolink_CA600-PoE/CloudSrvUserdataVersionCheck_svn/readme.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T17:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-7p7x-m4v3-7289/GHSA-7p7x-m4v3-7289.json b/advisories/unreviewed/2025/05/GHSA-7p7x-m4v3-7289/GHSA-7p7x-m4v3-7289.json new file mode 100644 index 00000000000..4ef972081a1 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-7p7x-m4v3-7289/GHSA-7p7x-m4v3-7289.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7p7x-m4v3-7289", + "modified": "2025-05-01T18:31:48Z", + "published": "2025-05-01T18:31:48Z", + "aliases": [ + "CVE-2025-44848" + ], + "details": "TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the msg_process function via the Url parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44848" + }, + { + "type": "WEB", + "url": "https://github.com/Summermu/VulnForIoT/tree/main/Totolink_CA600-PoE/msg_process_Url/readme.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T17:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-87vc-frqr-mh5v/GHSA-87vc-frqr-mh5v.json b/advisories/unreviewed/2025/05/GHSA-87vc-frqr-mh5v/GHSA-87vc-frqr-mh5v.json new file mode 100644 index 00000000000..4d4c118ee60 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-87vc-frqr-mh5v/GHSA-87vc-frqr-mh5v.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-87vc-frqr-mh5v", + "modified": "2025-05-01T18:31:47Z", + "published": "2025-05-01T18:31:47Z", + "aliases": [ + "CVE-2025-44844" + ], + "details": "TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the setUpgradeFW function via the FileName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44844" + }, + { + "type": "WEB", + "url": "https://github.com/Summermu/VulnForIoT/tree/main/Totolink_CA600-PoE/setUpgradeFW/readme.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T17:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hfpw-2f26-vgxr/GHSA-hfpw-2f26-vgxr.json b/advisories/unreviewed/2025/05/GHSA-hfpw-2f26-vgxr/GHSA-hfpw-2f26-vgxr.json new file mode 100644 index 00000000000..5a6c527ead2 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hfpw-2f26-vgxr/GHSA-hfpw-2f26-vgxr.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hfpw-2f26-vgxr", + "modified": "2025-05-01T18:31:46Z", + "published": "2025-05-01T18:31:46Z", + "aliases": [ + "CVE-2025-44841" + ], + "details": "TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the CloudSrvUserdataVersionCheck function via the version parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44841" + }, + { + "type": "WEB", + "url": "https://github.com/Summermu/VulnForIoT/tree/main/Totolink_CA600-PoE/CloudSrvUserdataVersionCheck_version/readme.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T17:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hx3p-h798-3rh6/GHSA-hx3p-h798-3rh6.json b/advisories/unreviewed/2025/05/GHSA-hx3p-h798-3rh6/GHSA-hx3p-h798-3rh6.json new file mode 100644 index 00000000000..b8c225a5cbe --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hx3p-h798-3rh6/GHSA-hx3p-h798-3rh6.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hx3p-h798-3rh6", + "modified": "2025-05-01T18:31:47Z", + "published": "2025-05-01T18:31:47Z", + "aliases": [ + "CVE-2025-44846" + ], + "details": "TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the recvUpgradeNewFw function via the fwUrl parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44846" + }, + { + "type": "WEB", + "url": "https://github.com/Summermu/VulnForIoT/tree/main/Totolink_CA600-PoE/recvUpgradeNewFw/readme.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T17:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rg65-rpmg-wff5/GHSA-rg65-rpmg-wff5.json b/advisories/unreviewed/2025/05/GHSA-rg65-rpmg-wff5/GHSA-rg65-rpmg-wff5.json new file mode 100644 index 00000000000..569243c5f08 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-rg65-rpmg-wff5/GHSA-rg65-rpmg-wff5.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rg65-rpmg-wff5", + "modified": "2025-05-01T18:31:47Z", + "published": "2025-05-01T18:31:47Z", + "aliases": [ + "CVE-2025-44847" + ], + "details": "TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the setWebWlanIdx function via the webWlanIdx parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44847" + }, + { + "type": "WEB", + "url": "https://github.com/Summermu/VulnForIoT/tree/main/Totolink_CA600-PoE/setWebWlanIdx/readme.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T17:15:51Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-x2f7-mww2-v4hq/GHSA-x2f7-mww2-v4hq.json b/advisories/unreviewed/2025/05/GHSA-x2f7-mww2-v4hq/GHSA-x2f7-mww2-v4hq.json new file mode 100644 index 00000000000..121be938f7e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-x2f7-mww2-v4hq/GHSA-x2f7-mww2-v4hq.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x2f7-mww2-v4hq", + "modified": "2025-05-01T18:31:46Z", + "published": "2025-05-01T18:31:46Z", + "aliases": [ + "CVE-2025-44839" + ], + "details": "TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the CloudSrvUserdataVersionCheck function via the magicid parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44839" + }, + { + "type": "WEB", + "url": "https://github.com/Summermu/VulnForIoT/tree/main/Totolink_CA600-PoE/CloudSrvUserdataVersionCheck_magicid/readme.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T17:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-xjhg-m88j-hqrc/GHSA-xjhg-m88j-hqrc.json b/advisories/unreviewed/2025/05/GHSA-xjhg-m88j-hqrc/GHSA-xjhg-m88j-hqrc.json new file mode 100644 index 00000000000..8216bbc3ec7 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-xjhg-m88j-hqrc/GHSA-xjhg-m88j-hqrc.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xjhg-m88j-hqrc", + "modified": "2025-05-01T18:31:47Z", + "published": "2025-05-01T18:31:47Z", + "aliases": [ + "CVE-2025-44843" + ], + "details": "TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the CloudSrvUserdataVersionCheck function via the url parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44843" + }, + { + "type": "WEB", + "url": "https://github.com/Summermu/VulnForIoT/tree/main/Totolink_CA600-PoE/CloudSrvUserdataVersionCheck_url/readme.md" + }, + { + "type": "WEB", + "url": "https://www.totolink.net" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T17:15:50Z" + } +} \ No newline at end of file