diff --git a/advisories/unreviewed/2025/01/GHSA-838r-w3fq-8qqq/GHSA-838r-w3fq-8qqq.json b/advisories/unreviewed/2025/01/GHSA-838r-w3fq-8qqq/GHSA-838r-w3fq-8qqq.json new file mode 100644 index 00000000000..aacf83e64e0 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-838r-w3fq-8qqq/GHSA-838r-w3fq-8qqq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-838r-w3fq-8qqq", + "modified": "2025-01-28T12:31:08Z", + "published": "2025-01-28T12:31:08Z", + "aliases": [ + "CVE-2025-0065" + ], + "details": "Improper Neutralization of Argument Delimiters in the TeamViewer_service.exe component of TeamViewer Clients prior version 15.62 for Windows allows an attacker with local unprivileged access on a Windows system to elevate privileges via argument injection.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0065" + }, + { + "type": "WEB", + "url": "https://www.teamviewer.com/en/resources/trust-center/security-bulletins/tv-2025-1001" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-88" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-28T11:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-hp5j-2585-qx6g/GHSA-hp5j-2585-qx6g.json b/advisories/unreviewed/2025/01/GHSA-hp5j-2585-qx6g/GHSA-hp5j-2585-qx6g.json new file mode 100644 index 00000000000..9b308d5be7c --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-hp5j-2585-qx6g/GHSA-hp5j-2585-qx6g.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hp5j-2585-qx6g", + "modified": "2025-01-28T12:31:07Z", + "published": "2025-01-28T12:31:07Z", + "aliases": [ + "CVE-2025-0750" + ], + "details": "A vulnerability was found in CRI-O. A path traversal issue in the log management functions (UnMountPodLogs and LinkContainerLogs) may allow an attacker with permissions to create and delete Pods to unmount arbitrary host paths, leading to node-level denial of service by unmounting critical system directories.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0750" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2025-0750" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339405" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-28T10:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-jwh7-xm52-qvh7/GHSA-jwh7-xm52-qvh7.json b/advisories/unreviewed/2025/01/GHSA-jwh7-xm52-qvh7/GHSA-jwh7-xm52-qvh7.json new file mode 100644 index 00000000000..4a1985ce88e --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-jwh7-xm52-qvh7/GHSA-jwh7-xm52-qvh7.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jwh7-xm52-qvh7", + "modified": "2025-01-28T12:31:08Z", + "published": "2025-01-28T12:31:08Z", + "aliases": [ + "CVE-2025-0754" + ], + "details": "The vulnerability was found in OpenShift Service Mesh 2.6.3 and 2.5.6. This issue occurs due to improper sanitization of HTTP headers by Envoy, particularly the x-forwarded-for header. This lack of sanitization can allow attackers to inject malicious payloads into service mesh logs, leading to log injection and spoofing attacks. Such injections can mislead logging mechanisms, enabling attackers to manipulate log entries or execute reflected cross-site scripting (XSS) attacks.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0754" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2025-0754" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339147" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-117" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-28T10:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-wpxv-x75w-vp46/GHSA-wpxv-x75w-vp46.json b/advisories/unreviewed/2025/01/GHSA-wpxv-x75w-vp46/GHSA-wpxv-x75w-vp46.json new file mode 100644 index 00000000000..4c7a652f70a --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-wpxv-x75w-vp46/GHSA-wpxv-x75w-vp46.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wpxv-x75w-vp46", + "modified": "2025-01-28T12:31:07Z", + "published": "2025-01-28T12:31:07Z", + "aliases": [ + "CVE-2025-0752" + ], + "details": "A flaw was found in OpenShift Service Mesh 2.6.3 and 2.5.6. Rate-limiter avoidance, access-control bypass, CPU and memory exhaustion, and replay attacks may be possible due to improper HTTP header sanitization in Envoy.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0752" + }, + { + "type": "WEB", + "url": "https://access.redhat.com/security/cve/CVE-2025-0752" + }, + { + "type": "WEB", + "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2339115" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-444" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-28T10:15:09Z" + } +} \ No newline at end of file