From da7f15cd50e5e935edee26b3bac341e25a55d2b6 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 14 May 2025 00:33:32 +0000 Subject: [PATCH] Publish Advisories GHSA-qxwh-7c22-mwpm GHSA-9hcv-xw76-m4h6 GHSA-5qxx-2mqf-3v7g GHSA-89g2-jrcc-p8r7 GHSA-hhmv-6rqc-qrc8 GHSA-cvpp-rmjx-5x2m GHSA-hwrg-xmjh-93xc GHSA-w443-5h3j-jqcp --- .../GHSA-qxwh-7c22-mwpm.json | 3 +- .../GHSA-9hcv-xw76-m4h6.json | 10 ++++- .../GHSA-5qxx-2mqf-3v7g.json | 6 ++- .../GHSA-89g2-jrcc-p8r7.json | 6 ++- .../GHSA-hhmv-6rqc-qrc8.json | 6 ++- .../GHSA-cvpp-rmjx-5x2m.json | 36 +++++++++++++++ .../GHSA-hwrg-xmjh-93xc.json | 10 ++++- .../GHSA-w443-5h3j-jqcp.json | 44 +++++++++++++++++++ 8 files changed, 115 insertions(+), 6 deletions(-) create mode 100644 advisories/unreviewed/2025/05/GHSA-cvpp-rmjx-5x2m/GHSA-cvpp-rmjx-5x2m.json create mode 100644 advisories/unreviewed/2025/05/GHSA-w443-5h3j-jqcp/GHSA-w443-5h3j-jqcp.json diff --git a/advisories/unreviewed/2025/01/GHSA-qxwh-7c22-mwpm/GHSA-qxwh-7c22-mwpm.json b/advisories/unreviewed/2025/01/GHSA-qxwh-7c22-mwpm/GHSA-qxwh-7c22-mwpm.json index eeae5c52075..c7456f239de 100644 --- a/advisories/unreviewed/2025/01/GHSA-qxwh-7c22-mwpm/GHSA-qxwh-7c22-mwpm.json +++ b/advisories/unreviewed/2025/01/GHSA-qxwh-7c22-mwpm/GHSA-qxwh-7c22-mwpm.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/03/GHSA-9hcv-xw76-m4h6/GHSA-9hcv-xw76-m4h6.json b/advisories/unreviewed/2025/03/GHSA-9hcv-xw76-m4h6/GHSA-9hcv-xw76-m4h6.json index 94f1105fc4f..e47d113bcfd 100644 --- a/advisories/unreviewed/2025/03/GHSA-9hcv-xw76-m4h6/GHSA-9hcv-xw76-m4h6.json +++ b/advisories/unreviewed/2025/03/GHSA-9hcv-xw76-m4h6/GHSA-9hcv-xw76-m4h6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9hcv-xw76-m4h6", - "modified": "2025-05-09T15:31:40Z", + "modified": "2025-05-14T00:32:21Z", "published": "2025-03-14T09:34:06Z", "aliases": [ "CVE-2024-8176" @@ -63,6 +63,14 @@ "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2024-8176" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:7512" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:7444" + }, { "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2025:4449" diff --git a/advisories/unreviewed/2025/04/GHSA-5qxx-2mqf-3v7g/GHSA-5qxx-2mqf-3v7g.json b/advisories/unreviewed/2025/04/GHSA-5qxx-2mqf-3v7g/GHSA-5qxx-2mqf-3v7g.json index 836d3d3eaf9..39565d59bd9 100644 --- a/advisories/unreviewed/2025/04/GHSA-5qxx-2mqf-3v7g/GHSA-5qxx-2mqf-3v7g.json +++ b/advisories/unreviewed/2025/04/GHSA-5qxx-2mqf-3v7g/GHSA-5qxx-2mqf-3v7g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5qxx-2mqf-3v7g", - "modified": "2025-04-03T04:41:19Z", + "modified": "2025-05-14T00:32:20Z", "published": "2025-04-03T04:41:19Z", "aliases": [ "CVE-2025-2784" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2784" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:7505" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-2784" diff --git a/advisories/unreviewed/2025/04/GHSA-89g2-jrcc-p8r7/GHSA-89g2-jrcc-p8r7.json b/advisories/unreviewed/2025/04/GHSA-89g2-jrcc-p8r7/GHSA-89g2-jrcc-p8r7.json index febc645a8c8..d424664f856 100644 --- a/advisories/unreviewed/2025/04/GHSA-89g2-jrcc-p8r7/GHSA-89g2-jrcc-p8r7.json +++ b/advisories/unreviewed/2025/04/GHSA-89g2-jrcc-p8r7/GHSA-89g2-jrcc-p8r7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-89g2-jrcc-p8r7", - "modified": "2025-04-14T15:31:59Z", + "modified": "2025-05-14T00:32:20Z", "published": "2025-04-14T15:31:59Z", "aliases": [ "CVE-2025-32914" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32914" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:7505" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-32914" diff --git a/advisories/unreviewed/2025/04/GHSA-hhmv-6rqc-qrc8/GHSA-hhmv-6rqc-qrc8.json b/advisories/unreviewed/2025/04/GHSA-hhmv-6rqc-qrc8/GHSA-hhmv-6rqc-qrc8.json index e6ddefdc452..d9b7f4a289c 100644 --- a/advisories/unreviewed/2025/04/GHSA-hhmv-6rqc-qrc8/GHSA-hhmv-6rqc-qrc8.json +++ b/advisories/unreviewed/2025/04/GHSA-hhmv-6rqc-qrc8/GHSA-hhmv-6rqc-qrc8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hhmv-6rqc-qrc8", - "modified": "2025-04-14T15:31:59Z", + "modified": "2025-05-14T00:32:20Z", "published": "2025-04-14T15:31:59Z", "aliases": [ "CVE-2025-32912" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32912" }, + { + "type": "WEB", + "url": "https://access.redhat.com/errata/RHSA-2025:7505" + }, { "type": "WEB", "url": "https://access.redhat.com/security/cve/CVE-2025-32912" diff --git a/advisories/unreviewed/2025/05/GHSA-cvpp-rmjx-5x2m/GHSA-cvpp-rmjx-5x2m.json b/advisories/unreviewed/2025/05/GHSA-cvpp-rmjx-5x2m/GHSA-cvpp-rmjx-5x2m.json new file mode 100644 index 00000000000..652ffea7f2d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-cvpp-rmjx-5x2m/GHSA-cvpp-rmjx-5x2m.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cvpp-rmjx-5x2m", + "modified": "2025-05-14T00:32:21Z", + "published": "2025-05-14T00:32:21Z", + "aliases": [ + "CVE-2025-47905" + ], + "details": "Varnish Cache before 7.6.3 and 7.7 before 7.7.1, and Varnish Enterprise before 6.0.13r14, allow client-side desync via HTTP/1 requests, because the product incorrectly permits CRLF to be skipped to delimit chunk boundaries.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-47905" + }, + { + "type": "WEB", + "url": "https://varnish-cache.org/security/VSV00016.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-444" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T22:15:24Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hwrg-xmjh-93xc/GHSA-hwrg-xmjh-93xc.json b/advisories/unreviewed/2025/05/GHSA-hwrg-xmjh-93xc/GHSA-hwrg-xmjh-93xc.json index 7cf1f309e9f..a8aaeb2d741 100644 --- a/advisories/unreviewed/2025/05/GHSA-hwrg-xmjh-93xc/GHSA-hwrg-xmjh-93xc.json +++ b/advisories/unreviewed/2025/05/GHSA-hwrg-xmjh-93xc/GHSA-hwrg-xmjh-93xc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-hwrg-xmjh-93xc", - "modified": "2025-05-13T21:30:54Z", + "modified": "2025-05-14T00:32:21Z", "published": "2025-05-13T21:30:54Z", "aliases": [ "CVE-2024-28956" @@ -26,6 +26,14 @@ { "type": "WEB", "url": "https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01153.html" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2025/05/12/5" + }, + { + "type": "WEB", + "url": "http://xenbits.xen.org/xsa/advisory-469.html" } ], "database_specific": { diff --git a/advisories/unreviewed/2025/05/GHSA-w443-5h3j-jqcp/GHSA-w443-5h3j-jqcp.json b/advisories/unreviewed/2025/05/GHSA-w443-5h3j-jqcp/GHSA-w443-5h3j-jqcp.json new file mode 100644 index 00000000000..0f20d201cf9 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-w443-5h3j-jqcp/GHSA-w443-5h3j-jqcp.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w443-5h3j-jqcp", + "modified": "2025-05-14T00:32:21Z", + "published": "2025-05-14T00:32:21Z", + "aliases": [ + "CVE-2025-4574" + ], + "details": "In crossbeam-channel rust crate, the internal `Channel` type's `Drop` method has a race condition which could, in some circumstances, lead to a double-free that could result in memory corruption.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4574" + }, + { + "type": "WEB", + "url": "https://github.com/crossbeam-rs/crossbeam/pull/1187" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2025-4574" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2358890" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-415" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-13T22:15:25Z" + } +} \ No newline at end of file