diff --git a/advisories/github-reviewed/2025/03/GHSA-754f-8gm6-c4r2/GHSA-754f-8gm6-c4r2.json b/advisories/github-reviewed/2025/03/GHSA-754f-8gm6-c4r2/GHSA-754f-8gm6-c4r2.json index d54af746109..6c144b1e30f 100644 --- a/advisories/github-reviewed/2025/03/GHSA-754f-8gm6-c4r2/GHSA-754f-8gm6-c4r2.json +++ b/advisories/github-reviewed/2025/03/GHSA-754f-8gm6-c4r2/GHSA-754f-8gm6-c4r2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-754f-8gm6-c4r2", - "modified": "2025-03-12T20:54:42Z", + "modified": "2025-03-12T21:35:34Z", "published": "2025-03-12T20:54:42Z", "aliases": [ "CVE-2025-25292" @@ -11,7 +11,7 @@ "severity": [ { "type": "CVSS_V4", - "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U" + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:P" } ], "affected": [ @@ -63,6 +63,10 @@ "type": "WEB", "url": "https://github.com/omniauth/omniauth-saml/security/advisories/GHSA-hw46-3hmr-x9xv" }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25292" + }, { "type": "WEB", "url": "https://github.com/SAML-Toolkits/ruby-saml/commit/e76c5b36bac40aedbf1ba7ffaaf495be63328cd9" @@ -75,6 +79,10 @@ "type": "WEB", "url": "https://about.gitlab.com/releases/2025/03/12/patch-release-gitlab-17-9-2-released" }, + { + "type": "WEB", + "url": "https://github.blog/security/sign-in-as-anyone-bypassing-saml-sso-authentication-with-parser-differentials" + }, { "type": "PACKAGE", "url": "https://github.com/SAML-Toolkits/ruby-saml" @@ -96,6 +104,6 @@ "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2025-03-12T20:54:42Z", - "nvd_published_at": null + "nvd_published_at": "2025-03-12T21:15:42Z" } } \ No newline at end of file