From da59c2b5dd6473fbbdb7c97fee67cd9398b6df58 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 29 Jan 2025 12:33:49 +0000 Subject: [PATCH] Publish Advisories GHSA-43vj-hhq4-8c72 GHSA-54pf-9qmv-m7pj GHSA-99jw-x78w-3hcm GHSA-cf2r-vpqc-55g6 GHSA-fcq5-wxxx-j73q GHSA-fh7x-2848-jmpf GHSA-h5x7-x73g-46v4 GHSA-m9g8-46v9-pjp2 GHSA-q8mj-2j9f-gw99 GHSA-qqmj-rrh7-547q GHSA-vhqh-w8vh-h8h6 GHSA-x26x-c8x5-v2rm GHSA-xh5q-pch5-g3xq GHSA-xq9p-h64g-x8mc --- .../GHSA-43vj-hhq4-8c72.json | 36 ++++++++ .../GHSA-54pf-9qmv-m7pj.json | 6 +- .../GHSA-99jw-x78w-3hcm.json | 6 +- .../GHSA-cf2r-vpqc-55g6.json | 36 ++++++++ .../GHSA-fcq5-wxxx-j73q.json | 92 +++++++++++++++++++ .../GHSA-fh7x-2848-jmpf.json | 15 ++- .../GHSA-h5x7-x73g-46v4.json | 48 ++++++++++ .../GHSA-m9g8-46v9-pjp2.json | 6 +- .../GHSA-q8mj-2j9f-gw99.json | 6 +- .../GHSA-qqmj-rrh7-547q.json | 6 +- .../GHSA-vhqh-w8vh-h8h6.json | 6 +- .../GHSA-x26x-c8x5-v2rm.json | 35 +++++++ .../GHSA-xh5q-pch5-g3xq.json | 6 +- .../GHSA-xq9p-h64g-x8mc.json | 6 +- 14 files changed, 298 insertions(+), 12 deletions(-) create mode 100644 advisories/unreviewed/2025/01/GHSA-43vj-hhq4-8c72/GHSA-43vj-hhq4-8c72.json create mode 100644 advisories/unreviewed/2025/01/GHSA-cf2r-vpqc-55g6/GHSA-cf2r-vpqc-55g6.json create mode 100644 advisories/unreviewed/2025/01/GHSA-fcq5-wxxx-j73q/GHSA-fcq5-wxxx-j73q.json create mode 100644 advisories/unreviewed/2025/01/GHSA-h5x7-x73g-46v4/GHSA-h5x7-x73g-46v4.json create mode 100644 advisories/unreviewed/2025/01/GHSA-x26x-c8x5-v2rm/GHSA-x26x-c8x5-v2rm.json diff --git a/advisories/unreviewed/2025/01/GHSA-43vj-hhq4-8c72/GHSA-43vj-hhq4-8c72.json b/advisories/unreviewed/2025/01/GHSA-43vj-hhq4-8c72/GHSA-43vj-hhq4-8c72.json new file mode 100644 index 00000000000..a7a32b27aab --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-43vj-hhq4-8c72/GHSA-43vj-hhq4-8c72.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-43vj-hhq4-8c72", + "modified": "2025-01-29T12:31:45Z", + "published": "2025-01-29T12:31:45Z", + "aliases": [ + "CVE-2024-41140" + ], + "details": "Zohocorp ManageEngine Applications Manager versions 174000 and prior are vulnerable to the incorrect authorization in the update user function.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41140" + }, + { + "type": "WEB", + "url": "https://www.manageengine.com/products/applications_manager/security-updates/security-updates-cve-2024-41140.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-863" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-29T12:15:28Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-54pf-9qmv-m7pj/GHSA-54pf-9qmv-m7pj.json b/advisories/unreviewed/2025/01/GHSA-54pf-9qmv-m7pj/GHSA-54pf-9qmv-m7pj.json index 6b08ce124a2..983c3798ae5 100644 --- a/advisories/unreviewed/2025/01/GHSA-54pf-9qmv-m7pj/GHSA-54pf-9qmv-m7pj.json +++ b/advisories/unreviewed/2025/01/GHSA-54pf-9qmv-m7pj/GHSA-54pf-9qmv-m7pj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-54pf-9qmv-m7pj", - "modified": "2025-01-23T18:31:20Z", + "modified": "2025-01-29T12:31:45Z", "published": "2025-01-23T18:31:20Z", "aliases": [ "CVE-2024-55925" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://securitydocs.business.xerox.com/wp-content/uploads/2025/01/Xerox-Security-Bulletin-XRX25-002-for-Xerox%C2%AE-Workplace-Suite%C2%AE.pdf" + }, + { + "type": "WEB", + "url": "https://securitydocs.business.xerox.com/wp-content/uploads/2025/01/Xerox-Security-Bulletin-XRX25-002-for-Xerox%C2%AE-WorkplaceSuite%C2%AE.pdf" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/01/GHSA-99jw-x78w-3hcm/GHSA-99jw-x78w-3hcm.json b/advisories/unreviewed/2025/01/GHSA-99jw-x78w-3hcm/GHSA-99jw-x78w-3hcm.json index d886ef78b1e..a58dbc2933c 100644 --- a/advisories/unreviewed/2025/01/GHSA-99jw-x78w-3hcm/GHSA-99jw-x78w-3hcm.json +++ b/advisories/unreviewed/2025/01/GHSA-99jw-x78w-3hcm/GHSA-99jw-x78w-3hcm.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-99jw-x78w-3hcm", - "modified": "2025-01-23T18:31:20Z", + "modified": "2025-01-29T12:31:45Z", "published": "2025-01-23T18:31:20Z", "aliases": [ "CVE-2024-55926" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://securitydocs.business.xerox.com/wp-content/uploads/2025/01/Xerox-Security-Bulletin-XRX25-002-for-Xerox%C2%AE-Workplace-Suite%C2%AE.pdf" + }, + { + "type": "WEB", + "url": "https://securitydocs.business.xerox.com/wp-content/uploads/2025/01/Xerox-Security-Bulletin-XRX25-002-for-Xerox%C2%AE-WorkplaceSuite%C2%AE.pdf" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/01/GHSA-cf2r-vpqc-55g6/GHSA-cf2r-vpqc-55g6.json b/advisories/unreviewed/2025/01/GHSA-cf2r-vpqc-55g6/GHSA-cf2r-vpqc-55g6.json new file mode 100644 index 00000000000..1b841a86a52 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-cf2r-vpqc-55g6/GHSA-cf2r-vpqc-55g6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cf2r-vpqc-55g6", + "modified": "2025-01-29T12:31:45Z", + "published": "2025-01-29T12:31:45Z", + "aliases": [ + "CVE-2025-0617" + ], + "details": "An attacker with access to an HX 10.0.0 and previous versions, may send specially-crafted data to the HX console. The malicious detection would then trigger file parsing containing exponential entity expansions in the consumer process thus causing a Denial of Service.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0617" + }, + { + "type": "WEB", + "url": "https://thrive.trellix.com/s/article/000014214" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-776" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-29T11:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-fcq5-wxxx-j73q/GHSA-fcq5-wxxx-j73q.json b/advisories/unreviewed/2025/01/GHSA-fcq5-wxxx-j73q/GHSA-fcq5-wxxx-j73q.json new file mode 100644 index 00000000000..e7daeafc41c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-fcq5-wxxx-j73q/GHSA-fcq5-wxxx-j73q.json @@ -0,0 +1,92 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fcq5-wxxx-j73q", + "modified": "2025-01-29T12:31:45Z", + "published": "2025-01-29T12:31:45Z", + "aliases": [ + "CVE-2025-0353" + ], + "details": "The Divi Torque Lite – Best Divi Addon, Extensions, Modules & Social Modules plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets in all versions up to, and including, 4.1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0353" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/addons-for-divi/trunk/includes/modules/divi-4/FlipBox/FlipBox.php#L1053" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/addons-for-divi/trunk/includes/modules/divi-4/GradientHeading/GradientHeading.php#L344" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/addons-for-divi/trunk/includes/modules/divi-4/ImageCarouselChild/ImageCarouselChild.php#L507" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/addons-for-divi/trunk/includes/modules/divi-4/InfoBox/InfoBox.php#L852" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/addons-for-divi/trunk/includes/modules/divi-4/InfoCard/InfoCard.php#L688" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/addons-for-divi/trunk/includes/modules/divi-4/InlineNotice/InlineNotice.php#L486" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/addons-for-divi/trunk/includes/modules/divi-4/LogoCarouselChild/LogoCarouselChild.php#L177" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/addons-for-divi/trunk/includes/modules/divi-4/LogoGridChild/LogoGridChild.php#L193" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/addons-for-divi/trunk/includes/modules/divi-4/Review/Review.php#L703" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/addons-for-divi/trunk/includes/modules/divi-4/ScrollImage/ScrollImage.php#L388" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/addons-for-divi/trunk/includes/modules/divi-4/Testimonial/Testimonial.php#L1147" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/addons-for-divi/trunk/includes/modules/divi-4/VideoModal/VideoModal.php#L593" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3230743" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/addons-for-divi/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/d5810757-1866-4788-809f-2c68e16a5156?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-29T12:15:29Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-fh7x-2848-jmpf/GHSA-fh7x-2848-jmpf.json b/advisories/unreviewed/2025/01/GHSA-fh7x-2848-jmpf/GHSA-fh7x-2848-jmpf.json index 829221c3cf9..2c7f30123ed 100644 --- a/advisories/unreviewed/2025/01/GHSA-fh7x-2848-jmpf/GHSA-fh7x-2848-jmpf.json +++ b/advisories/unreviewed/2025/01/GHSA-fh7x-2848-jmpf/GHSA-fh7x-2848-jmpf.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fh7x-2848-jmpf", - "modified": "2025-01-29T09:31:42Z", + "modified": "2025-01-29T12:31:45Z", "published": "2025-01-29T09:31:42Z", "aliases": [ "CVE-2024-57965" ], "details": "In axios before 1.7.8, lib/helpers/isURLSameOrigin.js does not use a URL object when determining an origin, and has a potentially unwanted setAttribute('href',href) call. NOTE: some parties feel that the code change only addresses a warning message from a SAST tool and does not fix a vulnerability.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-346" + ], + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-29T09:15:08Z" diff --git a/advisories/unreviewed/2025/01/GHSA-h5x7-x73g-46v4/GHSA-h5x7-x73g-46v4.json b/advisories/unreviewed/2025/01/GHSA-h5x7-x73g-46v4/GHSA-h5x7-x73g-46v4.json new file mode 100644 index 00000000000..5b0588d08cd --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-h5x7-x73g-46v4/GHSA-h5x7-x73g-46v4.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h5x7-x73g-46v4", + "modified": "2025-01-29T12:31:45Z", + "published": "2025-01-29T12:31:45Z", + "aliases": [ + "CVE-2024-13561" + ], + "details": "The Target Video Easy Publish plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's brid_override_yt shortcode in all versions up to, and including, 3.8.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13561" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/browser/brid-video-easy-publish/trunk/lib/BridShortcode.php#L412" + }, + { + "type": "WEB", + "url": "https://plugins.trac.wordpress.org/changeset/3226143" + }, + { + "type": "WEB", + "url": "https://wordpress.org/plugins/brid-video-easy-publish/#developers" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/cc67fbfa-d84c-45c3-bbb1-4557dc70a8c9?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-29T12:15:27Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-m9g8-46v9-pjp2/GHSA-m9g8-46v9-pjp2.json b/advisories/unreviewed/2025/01/GHSA-m9g8-46v9-pjp2/GHSA-m9g8-46v9-pjp2.json index 023dcf1a917..63cf5a31cd2 100644 --- a/advisories/unreviewed/2025/01/GHSA-m9g8-46v9-pjp2/GHSA-m9g8-46v9-pjp2.json +++ b/advisories/unreviewed/2025/01/GHSA-m9g8-46v9-pjp2/GHSA-m9g8-46v9-pjp2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m9g8-46v9-pjp2", - "modified": "2025-01-23T18:31:20Z", + "modified": "2025-01-29T12:31:45Z", "published": "2025-01-23T18:31:20Z", "aliases": [ "CVE-2024-55929" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://securitydocs.business.xerox.com/wp-content/uploads/2025/01/Xerox-Security-Bulletin-XRX25-002-for-Xerox%C2%AE-Workplace-Suite%C2%AE.pdf" + }, + { + "type": "WEB", + "url": "https://securitydocs.business.xerox.com/wp-content/uploads/2025/01/Xerox-Security-Bulletin-XRX25-002-for-Xerox%C2%AE-WorkplaceSuite%C2%AE.pdf" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/01/GHSA-q8mj-2j9f-gw99/GHSA-q8mj-2j9f-gw99.json b/advisories/unreviewed/2025/01/GHSA-q8mj-2j9f-gw99/GHSA-q8mj-2j9f-gw99.json index 7c460107f52..8b7861c8091 100644 --- a/advisories/unreviewed/2025/01/GHSA-q8mj-2j9f-gw99/GHSA-q8mj-2j9f-gw99.json +++ b/advisories/unreviewed/2025/01/GHSA-q8mj-2j9f-gw99/GHSA-q8mj-2j9f-gw99.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q8mj-2j9f-gw99", - "modified": "2025-01-23T18:31:20Z", + "modified": "2025-01-29T12:31:45Z", "published": "2025-01-23T18:31:20Z", "aliases": [ "CVE-2024-55927" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://securitydocs.business.xerox.com/wp-content/uploads/2025/01/Xerox-Security-Bulletin-XRX25-002-for-Xerox%C2%AE-Workplace-Suite%C2%AE.pdf" + }, + { + "type": "WEB", + "url": "https://securitydocs.business.xerox.com/wp-content/uploads/2025/01/Xerox-Security-Bulletin-XRX25-002-for-Xerox%C2%AE-WorkplaceSuite%C2%AE.pdf" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/01/GHSA-qqmj-rrh7-547q/GHSA-qqmj-rrh7-547q.json b/advisories/unreviewed/2025/01/GHSA-qqmj-rrh7-547q/GHSA-qqmj-rrh7-547q.json index 5e781f2bd1f..0a4ab796afb 100644 --- a/advisories/unreviewed/2025/01/GHSA-qqmj-rrh7-547q/GHSA-qqmj-rrh7-547q.json +++ b/advisories/unreviewed/2025/01/GHSA-qqmj-rrh7-547q/GHSA-qqmj-rrh7-547q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qqmj-rrh7-547q", - "modified": "2025-01-23T18:31:21Z", + "modified": "2025-01-29T12:31:45Z", "published": "2025-01-23T18:31:20Z", "aliases": [ "CVE-2024-55928" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://securitydocs.business.xerox.com/wp-content/uploads/2025/01/Xerox-Security-Bulletin-XRX25-002-for-Xerox%C2%AE-Workplace-Suite%C2%AE.pdf" + }, + { + "type": "WEB", + "url": "https://securitydocs.business.xerox.com/wp-content/uploads/2025/01/Xerox-Security-Bulletin-XRX25-002-for-Xerox%C2%AE-WorkplaceSuite%C2%AE.pdf" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/01/GHSA-vhqh-w8vh-h8h6/GHSA-vhqh-w8vh-h8h6.json b/advisories/unreviewed/2025/01/GHSA-vhqh-w8vh-h8h6/GHSA-vhqh-w8vh-h8h6.json index bf6fed3e532..1eeef8dacbf 100644 --- a/advisories/unreviewed/2025/01/GHSA-vhqh-w8vh-h8h6/GHSA-vhqh-w8vh-h8h6.json +++ b/advisories/unreviewed/2025/01/GHSA-vhqh-w8vh-h8h6/GHSA-vhqh-w8vh-h8h6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-vhqh-w8vh-h8h6", - "modified": "2025-01-27T12:31:11Z", + "modified": "2025-01-29T12:31:45Z", "published": "2025-01-27T12:31:11Z", "aliases": [ "CVE-2024-55931" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://securitydocs.business.xerox.com/wp-content/uploads/2025/01/Xerox-Security-Bulletin-XRX25-002-for-Xerox%C2%AE-Workplace-Suite%C2%AE.pdf" + }, + { + "type": "WEB", + "url": "https://securitydocs.business.xerox.com/wp-content/uploads/2025/01/Xerox-Security-Bulletin-XRX25-002-for-Xerox%C2%AE-WorkplaceSuite%C2%AE.pdf" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/01/GHSA-x26x-c8x5-v2rm/GHSA-x26x-c8x5-v2rm.json b/advisories/unreviewed/2025/01/GHSA-x26x-c8x5-v2rm/GHSA-x26x-c8x5-v2rm.json new file mode 100644 index 00000000000..dd05afe09cb --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-x26x-c8x5-v2rm/GHSA-x26x-c8x5-v2rm.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x26x-c8x5-v2rm", + "modified": "2025-01-29T12:31:45Z", + "published": "2025-01-29T12:31:45Z", + "aliases": [ + "CVE-2025-0762" + ], + "details": "Use after free in DevTools in Google Chrome prior to 132.0.6834.159 allowed a remote attacker to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: Medium)", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0762" + }, + { + "type": "WEB", + "url": "https://chromereleases.googleblog.com/2025/01/stable-channel-update-for-desktop_28.html" + }, + { + "type": "WEB", + "url": "https://issues.chromium.org/issues/384844003" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-29T11:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-xh5q-pch5-g3xq/GHSA-xh5q-pch5-g3xq.json b/advisories/unreviewed/2025/01/GHSA-xh5q-pch5-g3xq/GHSA-xh5q-pch5-g3xq.json index e2106083b28..18d033743fa 100644 --- a/advisories/unreviewed/2025/01/GHSA-xh5q-pch5-g3xq/GHSA-xh5q-pch5-g3xq.json +++ b/advisories/unreviewed/2025/01/GHSA-xh5q-pch5-g3xq/GHSA-xh5q-pch5-g3xq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xh5q-pch5-g3xq", - "modified": "2025-01-29T09:31:42Z", + "modified": "2025-01-29T12:31:45Z", "published": "2025-01-14T18:32:00Z", "aliases": [ "CVE-2024-12085" @@ -47,6 +47,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:0787" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:0790" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-12085" diff --git a/advisories/unreviewed/2025/01/GHSA-xq9p-h64g-x8mc/GHSA-xq9p-h64g-x8mc.json b/advisories/unreviewed/2025/01/GHSA-xq9p-h64g-x8mc/GHSA-xq9p-h64g-x8mc.json index 15f7fa0f8b6..5c73403a3de 100644 --- a/advisories/unreviewed/2025/01/GHSA-xq9p-h64g-x8mc/GHSA-xq9p-h64g-x8mc.json +++ b/advisories/unreviewed/2025/01/GHSA-xq9p-h64g-x8mc/GHSA-xq9p-h64g-x8mc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xq9p-h64g-x8mc", - "modified": "2025-01-23T18:31:20Z", + "modified": "2025-01-29T12:31:45Z", "published": "2025-01-23T18:31:20Z", "aliases": [ "CVE-2024-55930" @@ -22,6 +22,10 @@ { "type": "WEB", "url": "https://securitydocs.business.xerox.com/wp-content/uploads/2025/01/Xerox-Security-Bulletin-XRX25-002-for-Xerox%C2%AE-Workplace-Suite%C2%AE.pdf" + }, + { + "type": "WEB", + "url": "https://securitydocs.business.xerox.com/wp-content/uploads/2025/01/Xerox-Security-Bulletin-XRX25-002-for-Xerox%C2%AE-WorkplaceSuite%C2%AE.pdf" } ], "database_specific": {