From ebdc553c3c7f131f35d1c710b4d66cdb9c62ae7e Mon Sep 17 00:00:00 2001
From: "advisory-database[bot]"
<45398580+advisory-database[bot]@users.noreply.github.com>
Date: Wed, 8 Jan 2025 21:33:47 +0000
Subject: [PATCH] Advisory Database Sync
---
.../GHSA-gjv9-7pj8-fwm8.json | 1 +
.../GHSA-xch8-fp3g-32mq.json | 2 +-
.../GHSA-xmp7-hhpr-wjgh.json | 4 +-
.../GHSA-468q-95jp-jm7r.json | 6 +-
.../GHSA-4768-6h8x-hrm7.json | 4 +-
.../GHSA-8jpv-8gq9-xh47.json | 4 +-
.../GHSA-cppv-r3f5-6vhx.json | 4 +-
.../GHSA-g5vg-jgjf-3787.json | 4 +-
.../GHSA-h6jq-vpc9-8qxh.json | 4 +-
.../GHSA-hqx2-pqrp-v2ph.json | 4 +-
.../GHSA-j59m-2g2f-c3pc.json | 6 +-
.../GHSA-j5gc-9h38-mfq7.json | 4 +-
.../GHSA-j6c9-6p46-r4qr.json | 4 +-
.../GHSA-jp64-wfc3-5jqr.json | 6 +-
.../GHSA-prwg-rhfj-26j7.json | 4 +-
.../GHSA-qvfx-98wv-873p.json | 4 +-
.../GHSA-r3f5-wxc6-qc5c.json | 4 +-
.../GHSA-x6hg-f949-cqff.json | 6 +-
.../GHSA-xr6g-q8cc-8f25.json | 6 +-
.../GHSA-4rjg-w3c9-89p9.json | 4 +-
.../GHSA-cj2v-p5xc-w33f.json | 6 +-
.../GHSA-j6vr-hf47-35cx.json | 4 +-
.../GHSA-qm3g-8hq8-9m7p.json | 4 +-
.../GHSA-qqr7-5v2h-fcpq.json | 4 +-
.../GHSA-qr75-5g36-rrxc.json | 6 +-
.../GHSA-rm6f-2h3x-p4m2.json | 6 +-
.../GHSA-2r5m-mx77-x6w5.json | 4 +-
.../GHSA-6r33-7cp5-q454.json | 4 +-
.../GHSA-75xg-g2r2-475p.json | 4 +-
.../GHSA-882m-54cg-63q7.json | 1 +
.../GHSA-c8pj-qvfv-m958.json | 4 +-
.../GHSA-cpv9-x52v-j5m3.json | 6 +-
.../GHSA-r3r2-738c-mhc2.json | 6 +-
.../GHSA-v249-g5w5-7hcv.json | 6 +-
.../GHSA-4prh-h48w-ph58.json | 4 +-
.../GHSA-5wmm-cc98-6cv6.json | 6 +-
.../GHSA-9ggc-jprr-xmm8.json | 6 +-
.../GHSA-ffvj-6488-98wf.json | 4 +-
.../GHSA-mpfh-52c6-26gq.json | 6 +-
.../GHSA-qhh4-7q77-h8mr.json | 4 +-
.../GHSA-qw7q-7pgr-v8ph.json | 3 +-
.../GHSA-whv2-3vp2-c4mv.json | 4 +-
.../GHSA-wjg2-hjqv-2pvp.json | 6 +-
.../GHSA-www9-grm3-8mc4.json | 3 +-
.../GHSA-x8fw-rvr9-2hx5.json | 15 +++--
.../GHSA-2rfg-hm52-w7vq.json | 2 +-
.../GHSA-6vhv-fv5r-vfg6.json | 15 +++--
.../GHSA-7q89-2pq5-3fpq.json | 2 +-
.../GHSA-x4w8-rv9m-fp3j.json | 1 +
.../GHSA-wp8q-76mh-g25x.json | 15 +++--
.../GHSA-65hj-3frp-cwqp.json | 15 +++--
.../GHSA-6mmh-m294-9j5g.json | 3 +-
.../GHSA-9g8r-v4m3-ff3f.json | 3 +-
.../GHSA-9pwp-p2rw-34f5.json | 15 +++--
.../GHSA-ccwq-3vpf-86cw.json | 1 +
.../GHSA-fgfp-pp34-jxvv.json | 15 +++--
.../GHSA-j2rf-6gjq-cpq6.json | 15 +++--
.../GHSA-rxh5-6q4f-cfwp.json | 15 +++--
.../GHSA-x7xx-q6m5-jw79.json | 15 +++--
.../GHSA-27x5-2866-42xg.json | 25 +++++++++
.../GHSA-3r2p-7j7f-fc8q.json | 34 +++++++++++
.../GHSA-7wr9-8g48-p7wg.json | 15 +++--
.../GHSA-8h93-28hg-fj84.json | 41 ++++++++++++++
.../GHSA-8qh8-gwrc-mfxf.json | 56 +++++++++++++++++++
.../GHSA-948c-8jvf-p44x.json | 15 +++--
.../GHSA-c26g-rhr3-gf6v.json | 40 +++++++++++++
.../GHSA-fv26-qm6r-mmq5.json | 40 +++++++++++++
.../GHSA-fvfx-9ggm-qjqg.json | 52 +++++++++++++++++
.../GHSA-gxfw-pm97-x2qf.json | 15 +++--
.../GHSA-h4qv-2mm7-9gwm.json | 15 +++--
.../GHSA-hjr5-q2v6-7chx.json | 44 +++++++++++++++
.../GHSA-hq4q-hgg3-4hgc.json | 25 +++++++++
.../GHSA-hxfw-qgg7-73mj.json | 56 +++++++++++++++++++
.../GHSA-jxq8-vf97-xqr3.json | 15 +++--
.../GHSA-p48v-w2c7-4756.json | 15 +++--
.../GHSA-w3wc-83g3-v333.json | 15 +++--
.../GHSA-w5p9-49f2-7v55.json | 25 +++++++++
.../GHSA-w6w8-xwp9-3vwq.json | 33 +++++++++++
.../GHSA-wfxv-g67w-6q5r.json | 25 +++++++++
79 files changed, 819 insertions(+), 125 deletions(-)
create mode 100644 advisories/unreviewed/2025/01/GHSA-27x5-2866-42xg/GHSA-27x5-2866-42xg.json
create mode 100644 advisories/unreviewed/2025/01/GHSA-3r2p-7j7f-fc8q/GHSA-3r2p-7j7f-fc8q.json
create mode 100644 advisories/unreviewed/2025/01/GHSA-8h93-28hg-fj84/GHSA-8h93-28hg-fj84.json
create mode 100644 advisories/unreviewed/2025/01/GHSA-8qh8-gwrc-mfxf/GHSA-8qh8-gwrc-mfxf.json
create mode 100644 advisories/unreviewed/2025/01/GHSA-c26g-rhr3-gf6v/GHSA-c26g-rhr3-gf6v.json
create mode 100644 advisories/unreviewed/2025/01/GHSA-fv26-qm6r-mmq5/GHSA-fv26-qm6r-mmq5.json
create mode 100644 advisories/unreviewed/2025/01/GHSA-fvfx-9ggm-qjqg/GHSA-fvfx-9ggm-qjqg.json
create mode 100644 advisories/unreviewed/2025/01/GHSA-hjr5-q2v6-7chx/GHSA-hjr5-q2v6-7chx.json
create mode 100644 advisories/unreviewed/2025/01/GHSA-hq4q-hgg3-4hgc/GHSA-hq4q-hgg3-4hgc.json
create mode 100644 advisories/unreviewed/2025/01/GHSA-hxfw-qgg7-73mj/GHSA-hxfw-qgg7-73mj.json
create mode 100644 advisories/unreviewed/2025/01/GHSA-w5p9-49f2-7v55/GHSA-w5p9-49f2-7v55.json
create mode 100644 advisories/unreviewed/2025/01/GHSA-w6w8-xwp9-3vwq/GHSA-w6w8-xwp9-3vwq.json
create mode 100644 advisories/unreviewed/2025/01/GHSA-wfxv-g67w-6q5r/GHSA-wfxv-g67w-6q5r.json
diff --git a/advisories/unreviewed/2023/06/GHSA-gjv9-7pj8-fwm8/GHSA-gjv9-7pj8-fwm8.json b/advisories/unreviewed/2023/06/GHSA-gjv9-7pj8-fwm8/GHSA-gjv9-7pj8-fwm8.json
index 47f60322e0c..bf653c5eb73 100644
--- a/advisories/unreviewed/2023/06/GHSA-gjv9-7pj8-fwm8/GHSA-gjv9-7pj8-fwm8.json
+++ b/advisories/unreviewed/2023/06/GHSA-gjv9-7pj8-fwm8/GHSA-gjv9-7pj8-fwm8.json
@@ -26,6 +26,7 @@
],
"database_specific": {
"cwe_ids": [
+ "CWE-203",
"CWE-668"
],
"severity": "MODERATE",
diff --git a/advisories/unreviewed/2023/06/GHSA-xch8-fp3g-32mq/GHSA-xch8-fp3g-32mq.json b/advisories/unreviewed/2023/06/GHSA-xch8-fp3g-32mq/GHSA-xch8-fp3g-32mq.json
index 931eea1f938..7e08349dc2f 100644
--- a/advisories/unreviewed/2023/06/GHSA-xch8-fp3g-32mq/GHSA-xch8-fp3g-32mq.json
+++ b/advisories/unreviewed/2023/06/GHSA-xch8-fp3g-32mq/GHSA-xch8-fp3g-32mq.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xch8-fp3g-32mq",
- "modified": "2023-11-25T12:30:22Z",
+ "modified": "2025-01-08T21:32:18Z",
"published": "2023-06-02T15:30:17Z",
"aliases": [
"CVE-2023-33476"
diff --git a/advisories/unreviewed/2023/06/GHSA-xmp7-hhpr-wjgh/GHSA-xmp7-hhpr-wjgh.json b/advisories/unreviewed/2023/06/GHSA-xmp7-hhpr-wjgh/GHSA-xmp7-hhpr-wjgh.json
index 78c5f1844a1..31614780d0c 100644
--- a/advisories/unreviewed/2023/06/GHSA-xmp7-hhpr-wjgh/GHSA-xmp7-hhpr-wjgh.json
+++ b/advisories/unreviewed/2023/06/GHSA-xmp7-hhpr-wjgh/GHSA-xmp7-hhpr-wjgh.json
@@ -25,7 +25,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-416"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/02/GHSA-468q-95jp-jm7r/GHSA-468q-95jp-jm7r.json b/advisories/unreviewed/2024/02/GHSA-468q-95jp-jm7r/GHSA-468q-95jp-jm7r.json
index f6d1eef4bae..7b319476eb7 100644
--- a/advisories/unreviewed/2024/02/GHSA-468q-95jp-jm7r/GHSA-468q-95jp-jm7r.json
+++ b/advisories/unreviewed/2024/02/GHSA-468q-95jp-jm7r/GHSA-468q-95jp-jm7r.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-468q-95jp-jm7r",
- "modified": "2024-02-29T03:33:16Z",
+ "modified": "2025-01-08T21:32:20Z",
"published": "2024-02-29T03:33:16Z",
"aliases": [
"CVE-2024-1171"
@@ -29,7 +29,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/02/GHSA-4768-6h8x-hrm7/GHSA-4768-6h8x-hrm7.json b/advisories/unreviewed/2024/02/GHSA-4768-6h8x-hrm7/GHSA-4768-6h8x-hrm7.json
index 79f11e13349..6b1d5b30565 100644
--- a/advisories/unreviewed/2024/02/GHSA-4768-6h8x-hrm7/GHSA-4768-6h8x-hrm7.json
+++ b/advisories/unreviewed/2024/02/GHSA-4768-6h8x-hrm7/GHSA-4768-6h8x-hrm7.json
@@ -29,7 +29,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-352"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/02/GHSA-8jpv-8gq9-xh47/GHSA-8jpv-8gq9-xh47.json b/advisories/unreviewed/2024/02/GHSA-8jpv-8gq9-xh47/GHSA-8jpv-8gq9-xh47.json
index 846229b6995..50d3fb60006 100644
--- a/advisories/unreviewed/2024/02/GHSA-8jpv-8gq9-xh47/GHSA-8jpv-8gq9-xh47.json
+++ b/advisories/unreviewed/2024/02/GHSA-8jpv-8gq9-xh47/GHSA-8jpv-8gq9-xh47.json
@@ -29,7 +29,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/02/GHSA-cppv-r3f5-6vhx/GHSA-cppv-r3f5-6vhx.json b/advisories/unreviewed/2024/02/GHSA-cppv-r3f5-6vhx/GHSA-cppv-r3f5-6vhx.json
index 81ad8d1e331..191d6747ba7 100644
--- a/advisories/unreviewed/2024/02/GHSA-cppv-r3f5-6vhx/GHSA-cppv-r3f5-6vhx.json
+++ b/advisories/unreviewed/2024/02/GHSA-cppv-r3f5-6vhx/GHSA-cppv-r3f5-6vhx.json
@@ -41,7 +41,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/02/GHSA-g5vg-jgjf-3787/GHSA-g5vg-jgjf-3787.json b/advisories/unreviewed/2024/02/GHSA-g5vg-jgjf-3787/GHSA-g5vg-jgjf-3787.json
index 9c80a951f9e..a9c1535a220 100644
--- a/advisories/unreviewed/2024/02/GHSA-g5vg-jgjf-3787/GHSA-g5vg-jgjf-3787.json
+++ b/advisories/unreviewed/2024/02/GHSA-g5vg-jgjf-3787/GHSA-g5vg-jgjf-3787.json
@@ -29,7 +29,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-352"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/02/GHSA-h6jq-vpc9-8qxh/GHSA-h6jq-vpc9-8qxh.json b/advisories/unreviewed/2024/02/GHSA-h6jq-vpc9-8qxh/GHSA-h6jq-vpc9-8qxh.json
index 43dfbfc5cbd..537bc6fac38 100644
--- a/advisories/unreviewed/2024/02/GHSA-h6jq-vpc9-8qxh/GHSA-h6jq-vpc9-8qxh.json
+++ b/advisories/unreviewed/2024/02/GHSA-h6jq-vpc9-8qxh/GHSA-h6jq-vpc9-8qxh.json
@@ -29,7 +29,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-352"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/02/GHSA-hqx2-pqrp-v2ph/GHSA-hqx2-pqrp-v2ph.json b/advisories/unreviewed/2024/02/GHSA-hqx2-pqrp-v2ph/GHSA-hqx2-pqrp-v2ph.json
index d0f0b5fb503..b6cfe60db3a 100644
--- a/advisories/unreviewed/2024/02/GHSA-hqx2-pqrp-v2ph/GHSA-hqx2-pqrp-v2ph.json
+++ b/advisories/unreviewed/2024/02/GHSA-hqx2-pqrp-v2ph/GHSA-hqx2-pqrp-v2ph.json
@@ -29,7 +29,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-352"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/02/GHSA-j59m-2g2f-c3pc/GHSA-j59m-2g2f-c3pc.json b/advisories/unreviewed/2024/02/GHSA-j59m-2g2f-c3pc/GHSA-j59m-2g2f-c3pc.json
index cf992ad3169..910ead8ea06 100644
--- a/advisories/unreviewed/2024/02/GHSA-j59m-2g2f-c3pc/GHSA-j59m-2g2f-c3pc.json
+++ b/advisories/unreviewed/2024/02/GHSA-j59m-2g2f-c3pc/GHSA-j59m-2g2f-c3pc.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j59m-2g2f-c3pc",
- "modified": "2024-02-29T03:33:16Z",
+ "modified": "2025-01-08T21:32:20Z",
"published": "2024-02-29T03:33:16Z",
"aliases": [
"CVE-2024-1276"
@@ -33,7 +33,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/02/GHSA-j5gc-9h38-mfq7/GHSA-j5gc-9h38-mfq7.json b/advisories/unreviewed/2024/02/GHSA-j5gc-9h38-mfq7/GHSA-j5gc-9h38-mfq7.json
index 32068d7b381..7a3e7677034 100644
--- a/advisories/unreviewed/2024/02/GHSA-j5gc-9h38-mfq7/GHSA-j5gc-9h38-mfq7.json
+++ b/advisories/unreviewed/2024/02/GHSA-j5gc-9h38-mfq7/GHSA-j5gc-9h38-mfq7.json
@@ -29,7 +29,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-352"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/02/GHSA-j6c9-6p46-r4qr/GHSA-j6c9-6p46-r4qr.json b/advisories/unreviewed/2024/02/GHSA-j6c9-6p46-r4qr/GHSA-j6c9-6p46-r4qr.json
index 0dc5556c909..d9064a3c0b2 100644
--- a/advisories/unreviewed/2024/02/GHSA-j6c9-6p46-r4qr/GHSA-j6c9-6p46-r4qr.json
+++ b/advisories/unreviewed/2024/02/GHSA-j6c9-6p46-r4qr/GHSA-j6c9-6p46-r4qr.json
@@ -29,7 +29,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-352"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/02/GHSA-jp64-wfc3-5jqr/GHSA-jp64-wfc3-5jqr.json b/advisories/unreviewed/2024/02/GHSA-jp64-wfc3-5jqr/GHSA-jp64-wfc3-5jqr.json
index 47c1f0c06eb..4e6c4d96dc2 100644
--- a/advisories/unreviewed/2024/02/GHSA-jp64-wfc3-5jqr/GHSA-jp64-wfc3-5jqr.json
+++ b/advisories/unreviewed/2024/02/GHSA-jp64-wfc3-5jqr/GHSA-jp64-wfc3-5jqr.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jp64-wfc3-5jqr",
- "modified": "2024-02-29T03:33:17Z",
+ "modified": "2025-01-08T21:32:20Z",
"published": "2024-02-29T03:33:17Z",
"aliases": [
"CVE-2024-1448"
@@ -33,7 +33,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/02/GHSA-prwg-rhfj-26j7/GHSA-prwg-rhfj-26j7.json b/advisories/unreviewed/2024/02/GHSA-prwg-rhfj-26j7/GHSA-prwg-rhfj-26j7.json
index 19879087cd2..ea2bf4702a7 100644
--- a/advisories/unreviewed/2024/02/GHSA-prwg-rhfj-26j7/GHSA-prwg-rhfj-26j7.json
+++ b/advisories/unreviewed/2024/02/GHSA-prwg-rhfj-26j7/GHSA-prwg-rhfj-26j7.json
@@ -29,7 +29,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-862"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/02/GHSA-qvfx-98wv-873p/GHSA-qvfx-98wv-873p.json b/advisories/unreviewed/2024/02/GHSA-qvfx-98wv-873p/GHSA-qvfx-98wv-873p.json
index 843193f0c4a..d8d161fb951 100644
--- a/advisories/unreviewed/2024/02/GHSA-qvfx-98wv-873p/GHSA-qvfx-98wv-873p.json
+++ b/advisories/unreviewed/2024/02/GHSA-qvfx-98wv-873p/GHSA-qvfx-98wv-873p.json
@@ -29,7 +29,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-352"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/02/GHSA-r3f5-wxc6-qc5c/GHSA-r3f5-wxc6-qc5c.json b/advisories/unreviewed/2024/02/GHSA-r3f5-wxc6-qc5c/GHSA-r3f5-wxc6-qc5c.json
index dbccefffb1f..9caa186b06a 100644
--- a/advisories/unreviewed/2024/02/GHSA-r3f5-wxc6-qc5c/GHSA-r3f5-wxc6-qc5c.json
+++ b/advisories/unreviewed/2024/02/GHSA-r3f5-wxc6-qc5c/GHSA-r3f5-wxc6-qc5c.json
@@ -29,7 +29,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-862"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/02/GHSA-x6hg-f949-cqff/GHSA-x6hg-f949-cqff.json b/advisories/unreviewed/2024/02/GHSA-x6hg-f949-cqff/GHSA-x6hg-f949-cqff.json
index cbdc8bccb77..6270d1ad013 100644
--- a/advisories/unreviewed/2024/02/GHSA-x6hg-f949-cqff/GHSA-x6hg-f949-cqff.json
+++ b/advisories/unreviewed/2024/02/GHSA-x6hg-f949-cqff/GHSA-x6hg-f949-cqff.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x6hg-f949-cqff",
- "modified": "2024-02-29T03:33:16Z",
+ "modified": "2025-01-08T21:32:20Z",
"published": "2024-02-29T03:33:16Z",
"aliases": [
"CVE-2024-1172"
@@ -37,7 +37,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/02/GHSA-xr6g-q8cc-8f25/GHSA-xr6g-q8cc-8f25.json b/advisories/unreviewed/2024/02/GHSA-xr6g-q8cc-8f25/GHSA-xr6g-q8cc-8f25.json
index ae95bf1b3bb..90ac088c3e4 100644
--- a/advisories/unreviewed/2024/02/GHSA-xr6g-q8cc-8f25/GHSA-xr6g-q8cc-8f25.json
+++ b/advisories/unreviewed/2024/02/GHSA-xr6g-q8cc-8f25/GHSA-xr6g-q8cc-8f25.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-xr6g-q8cc-8f25",
- "modified": "2024-02-29T03:33:16Z",
+ "modified": "2025-01-08T21:32:20Z",
"published": "2024-02-29T03:33:16Z",
"aliases": [
"CVE-2024-1236"
@@ -37,7 +37,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/03/GHSA-4rjg-w3c9-89p9/GHSA-4rjg-w3c9-89p9.json b/advisories/unreviewed/2024/03/GHSA-4rjg-w3c9-89p9/GHSA-4rjg-w3c9-89p9.json
index f515753264e..e76b7ef639c 100644
--- a/advisories/unreviewed/2024/03/GHSA-4rjg-w3c9-89p9/GHSA-4rjg-w3c9-89p9.json
+++ b/advisories/unreviewed/2024/03/GHSA-4rjg-w3c9-89p9/GHSA-4rjg-w3c9-89p9.json
@@ -37,7 +37,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/03/GHSA-cj2v-p5xc-w33f/GHSA-cj2v-p5xc-w33f.json b/advisories/unreviewed/2024/03/GHSA-cj2v-p5xc-w33f/GHSA-cj2v-p5xc-w33f.json
index 9b4419e4921..5d8167db9fb 100644
--- a/advisories/unreviewed/2024/03/GHSA-cj2v-p5xc-w33f/GHSA-cj2v-p5xc-w33f.json
+++ b/advisories/unreviewed/2024/03/GHSA-cj2v-p5xc-w33f/GHSA-cj2v-p5xc-w33f.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cj2v-p5xc-w33f",
- "modified": "2024-03-02T15:30:24Z",
+ "modified": "2025-01-08T21:32:21Z",
"published": "2024-03-02T15:30:24Z",
"aliases": [
"CVE-2024-1398"
@@ -33,7 +33,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/03/GHSA-j6vr-hf47-35cx/GHSA-j6vr-hf47-35cx.json b/advisories/unreviewed/2024/03/GHSA-j6vr-hf47-35cx/GHSA-j6vr-hf47-35cx.json
index 89c9c3eb2d4..6d6f57b1416 100644
--- a/advisories/unreviewed/2024/03/GHSA-j6vr-hf47-35cx/GHSA-j6vr-hf47-35cx.json
+++ b/advisories/unreviewed/2024/03/GHSA-j6vr-hf47-35cx/GHSA-j6vr-hf47-35cx.json
@@ -29,7 +29,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-862"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/03/GHSA-qm3g-8hq8-9m7p/GHSA-qm3g-8hq8-9m7p.json b/advisories/unreviewed/2024/03/GHSA-qm3g-8hq8-9m7p/GHSA-qm3g-8hq8-9m7p.json
index 5cbf25b6ee2..2493b34e2fd 100644
--- a/advisories/unreviewed/2024/03/GHSA-qm3g-8hq8-9m7p/GHSA-qm3g-8hq8-9m7p.json
+++ b/advisories/unreviewed/2024/03/GHSA-qm3g-8hq8-9m7p/GHSA-qm3g-8hq8-9m7p.json
@@ -41,7 +41,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/03/GHSA-qqr7-5v2h-fcpq/GHSA-qqr7-5v2h-fcpq.json b/advisories/unreviewed/2024/03/GHSA-qqr7-5v2h-fcpq/GHSA-qqr7-5v2h-fcpq.json
index a9edbbb6f8c..301cd4b7303 100644
--- a/advisories/unreviewed/2024/03/GHSA-qqr7-5v2h-fcpq/GHSA-qqr7-5v2h-fcpq.json
+++ b/advisories/unreviewed/2024/03/GHSA-qqr7-5v2h-fcpq/GHSA-qqr7-5v2h-fcpq.json
@@ -29,7 +29,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-502"
+ ],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/03/GHSA-qr75-5g36-rrxc/GHSA-qr75-5g36-rrxc.json b/advisories/unreviewed/2024/03/GHSA-qr75-5g36-rrxc/GHSA-qr75-5g36-rrxc.json
index c6710d46846..2472676de2f 100644
--- a/advisories/unreviewed/2024/03/GHSA-qr75-5g36-rrxc/GHSA-qr75-5g36-rrxc.json
+++ b/advisories/unreviewed/2024/03/GHSA-qr75-5g36-rrxc/GHSA-qr75-5g36-rrxc.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-qr75-5g36-rrxc",
- "modified": "2024-03-13T18:31:33Z",
+ "modified": "2025-01-08T21:32:21Z",
"published": "2024-03-13T18:31:33Z",
"aliases": [
"CVE-2024-1537"
@@ -29,7 +29,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/03/GHSA-rm6f-2h3x-p4m2/GHSA-rm6f-2h3x-p4m2.json b/advisories/unreviewed/2024/03/GHSA-rm6f-2h3x-p4m2/GHSA-rm6f-2h3x-p4m2.json
index 1c0ba515d9e..7a383535c1f 100644
--- a/advisories/unreviewed/2024/03/GHSA-rm6f-2h3x-p4m2/GHSA-rm6f-2h3x-p4m2.json
+++ b/advisories/unreviewed/2024/03/GHSA-rm6f-2h3x-p4m2/GHSA-rm6f-2h3x-p4m2.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rm6f-2h3x-p4m2",
- "modified": "2024-03-13T18:31:33Z",
+ "modified": "2025-01-08T21:32:21Z",
"published": "2024-03-13T18:31:33Z",
"aliases": [
"CVE-2024-1536"
@@ -29,7 +29,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/04/GHSA-2r5m-mx77-x6w5/GHSA-2r5m-mx77-x6w5.json b/advisories/unreviewed/2024/04/GHSA-2r5m-mx77-x6w5/GHSA-2r5m-mx77-x6w5.json
index 4957dbf5760..5f0a8a5f3e4 100644
--- a/advisories/unreviewed/2024/04/GHSA-2r5m-mx77-x6w5/GHSA-2r5m-mx77-x6w5.json
+++ b/advisories/unreviewed/2024/04/GHSA-2r5m-mx77-x6w5/GHSA-2r5m-mx77-x6w5.json
@@ -29,7 +29,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/04/GHSA-6r33-7cp5-q454/GHSA-6r33-7cp5-q454.json b/advisories/unreviewed/2024/04/GHSA-6r33-7cp5-q454/GHSA-6r33-7cp5-q454.json
index dc483c0f5a7..2b26abd73fe 100644
--- a/advisories/unreviewed/2024/04/GHSA-6r33-7cp5-q454/GHSA-6r33-7cp5-q454.json
+++ b/advisories/unreviewed/2024/04/GHSA-6r33-7cp5-q454/GHSA-6r33-7cp5-q454.json
@@ -29,7 +29,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/04/GHSA-75xg-g2r2-475p/GHSA-75xg-g2r2-475p.json b/advisories/unreviewed/2024/04/GHSA-75xg-g2r2-475p/GHSA-75xg-g2r2-475p.json
index 0390f530e0f..63947e3d8ef 100644
--- a/advisories/unreviewed/2024/04/GHSA-75xg-g2r2-475p/GHSA-75xg-g2r2-475p.json
+++ b/advisories/unreviewed/2024/04/GHSA-75xg-g2r2-475p/GHSA-75xg-g2r2-475p.json
@@ -29,7 +29,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/04/GHSA-882m-54cg-63q7/GHSA-882m-54cg-63q7.json b/advisories/unreviewed/2024/04/GHSA-882m-54cg-63q7/GHSA-882m-54cg-63q7.json
index 0b6e35190f9..9455aed431f 100644
--- a/advisories/unreviewed/2024/04/GHSA-882m-54cg-63q7/GHSA-882m-54cg-63q7.json
+++ b/advisories/unreviewed/2024/04/GHSA-882m-54cg-63q7/GHSA-882m-54cg-63q7.json
@@ -30,6 +30,7 @@
],
"database_specific": {
"cwe_ids": [
+ "CWE-639",
"CWE-863"
],
"severity": "HIGH",
diff --git a/advisories/unreviewed/2024/04/GHSA-c8pj-qvfv-m958/GHSA-c8pj-qvfv-m958.json b/advisories/unreviewed/2024/04/GHSA-c8pj-qvfv-m958/GHSA-c8pj-qvfv-m958.json
index 06531a9c6e2..2a979789ae8 100644
--- a/advisories/unreviewed/2024/04/GHSA-c8pj-qvfv-m958/GHSA-c8pj-qvfv-m958.json
+++ b/advisories/unreviewed/2024/04/GHSA-c8pj-qvfv-m958/GHSA-c8pj-qvfv-m958.json
@@ -29,7 +29,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/04/GHSA-cpv9-x52v-j5m3/GHSA-cpv9-x52v-j5m3.json b/advisories/unreviewed/2024/04/GHSA-cpv9-x52v-j5m3/GHSA-cpv9-x52v-j5m3.json
index e95591bb2ee..3a9a071a803 100644
--- a/advisories/unreviewed/2024/04/GHSA-cpv9-x52v-j5m3/GHSA-cpv9-x52v-j5m3.json
+++ b/advisories/unreviewed/2024/04/GHSA-cpv9-x52v-j5m3/GHSA-cpv9-x52v-j5m3.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cpv9-x52v-j5m3",
- "modified": "2024-04-09T21:32:00Z",
+ "modified": "2025-01-08T21:32:21Z",
"published": "2024-04-09T21:32:00Z",
"aliases": [
"CVE-2024-2974"
@@ -29,7 +29,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-922"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/04/GHSA-r3r2-738c-mhc2/GHSA-r3r2-738c-mhc2.json b/advisories/unreviewed/2024/04/GHSA-r3r2-738c-mhc2/GHSA-r3r2-738c-mhc2.json
index 559d98721be..ef08756e6fc 100644
--- a/advisories/unreviewed/2024/04/GHSA-r3r2-738c-mhc2/GHSA-r3r2-738c-mhc2.json
+++ b/advisories/unreviewed/2024/04/GHSA-r3r2-738c-mhc2/GHSA-r3r2-738c-mhc2.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-r3r2-738c-mhc2",
- "modified": "2024-04-09T21:32:00Z",
+ "modified": "2025-01-08T21:32:21Z",
"published": "2024-04-09T21:32:00Z",
"aliases": [
"CVE-2024-2623"
@@ -33,7 +33,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/04/GHSA-v249-g5w5-7hcv/GHSA-v249-g5w5-7hcv.json b/advisories/unreviewed/2024/04/GHSA-v249-g5w5-7hcv/GHSA-v249-g5w5-7hcv.json
index dcb689f5b28..bdf7c13cf6f 100644
--- a/advisories/unreviewed/2024/04/GHSA-v249-g5w5-7hcv/GHSA-v249-g5w5-7hcv.json
+++ b/advisories/unreviewed/2024/04/GHSA-v249-g5w5-7hcv/GHSA-v249-g5w5-7hcv.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-v249-g5w5-7hcv",
- "modified": "2024-04-09T21:32:00Z",
+ "modified": "2025-01-08T21:32:21Z",
"published": "2024-04-09T21:32:00Z",
"aliases": [
"CVE-2024-2650"
@@ -29,7 +29,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/05/GHSA-4prh-h48w-ph58/GHSA-4prh-h48w-ph58.json b/advisories/unreviewed/2024/05/GHSA-4prh-h48w-ph58/GHSA-4prh-h48w-ph58.json
index 7e5da65d171..09b35012103 100644
--- a/advisories/unreviewed/2024/05/GHSA-4prh-h48w-ph58/GHSA-4prh-h48w-ph58.json
+++ b/advisories/unreviewed/2024/05/GHSA-4prh-h48w-ph58/GHSA-4prh-h48w-ph58.json
@@ -37,7 +37,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/05/GHSA-5wmm-cc98-6cv6/GHSA-5wmm-cc98-6cv6.json b/advisories/unreviewed/2024/05/GHSA-5wmm-cc98-6cv6/GHSA-5wmm-cc98-6cv6.json
index 7b694902611..3996d254870 100644
--- a/advisories/unreviewed/2024/05/GHSA-5wmm-cc98-6cv6/GHSA-5wmm-cc98-6cv6.json
+++ b/advisories/unreviewed/2024/05/GHSA-5wmm-cc98-6cv6/GHSA-5wmm-cc98-6cv6.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-5wmm-cc98-6cv6",
- "modified": "2024-05-14T18:30:55Z",
+ "modified": "2025-01-08T21:32:22Z",
"published": "2024-05-14T18:30:55Z",
"aliases": [
"CVE-2024-4430"
@@ -33,7 +33,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/05/GHSA-9ggc-jprr-xmm8/GHSA-9ggc-jprr-xmm8.json b/advisories/unreviewed/2024/05/GHSA-9ggc-jprr-xmm8/GHSA-9ggc-jprr-xmm8.json
index 8d039c34ad2..b536a3a81f7 100644
--- a/advisories/unreviewed/2024/05/GHSA-9ggc-jprr-xmm8/GHSA-9ggc-jprr-xmm8.json
+++ b/advisories/unreviewed/2024/05/GHSA-9ggc-jprr-xmm8/GHSA-9ggc-jprr-xmm8.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9ggc-jprr-xmm8",
- "modified": "2024-05-22T06:30:39Z",
+ "modified": "2025-01-08T21:32:22Z",
"published": "2024-05-22T06:30:39Z",
"aliases": [
"CVE-2024-4971"
@@ -29,7 +29,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/05/GHSA-ffvj-6488-98wf/GHSA-ffvj-6488-98wf.json b/advisories/unreviewed/2024/05/GHSA-ffvj-6488-98wf/GHSA-ffvj-6488-98wf.json
index 4ce4cbbf8eb..26c8fea8ef8 100644
--- a/advisories/unreviewed/2024/05/GHSA-ffvj-6488-98wf/GHSA-ffvj-6488-98wf.json
+++ b/advisories/unreviewed/2024/05/GHSA-ffvj-6488-98wf/GHSA-ffvj-6488-98wf.json
@@ -45,7 +45,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/05/GHSA-mpfh-52c6-26gq/GHSA-mpfh-52c6-26gq.json b/advisories/unreviewed/2024/05/GHSA-mpfh-52c6-26gq/GHSA-mpfh-52c6-26gq.json
index e99bfc0c8c1..3a8f4ae2c0a 100644
--- a/advisories/unreviewed/2024/05/GHSA-mpfh-52c6-26gq/GHSA-mpfh-52c6-26gq.json
+++ b/advisories/unreviewed/2024/05/GHSA-mpfh-52c6-26gq/GHSA-mpfh-52c6-26gq.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-mpfh-52c6-26gq",
- "modified": "2024-05-02T18:30:55Z",
+ "modified": "2025-01-08T21:32:22Z",
"published": "2024-05-02T18:30:55Z",
"aliases": [
"CVE-2024-3728"
@@ -33,7 +33,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/05/GHSA-qhh4-7q77-h8mr/GHSA-qhh4-7q77-h8mr.json b/advisories/unreviewed/2024/05/GHSA-qhh4-7q77-h8mr/GHSA-qhh4-7q77-h8mr.json
index 546c1943959..7968d648863 100644
--- a/advisories/unreviewed/2024/05/GHSA-qhh4-7q77-h8mr/GHSA-qhh4-7q77-h8mr.json
+++ b/advisories/unreviewed/2024/05/GHSA-qhh4-7q77-h8mr/GHSA-qhh4-7q77-h8mr.json
@@ -29,7 +29,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/05/GHSA-qw7q-7pgr-v8ph/GHSA-qw7q-7pgr-v8ph.json b/advisories/unreviewed/2024/05/GHSA-qw7q-7pgr-v8ph/GHSA-qw7q-7pgr-v8ph.json
index 72d483af465..5d0442331c3 100644
--- a/advisories/unreviewed/2024/05/GHSA-qw7q-7pgr-v8ph/GHSA-qw7q-7pgr-v8ph.json
+++ b/advisories/unreviewed/2024/05/GHSA-qw7q-7pgr-v8ph/GHSA-qw7q-7pgr-v8ph.json
@@ -30,7 +30,8 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-324"
+ "CWE-324",
+ "CWE-672"
],
"severity": "MODERATE",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/05/GHSA-whv2-3vp2-c4mv/GHSA-whv2-3vp2-c4mv.json b/advisories/unreviewed/2024/05/GHSA-whv2-3vp2-c4mv/GHSA-whv2-3vp2-c4mv.json
index 06dbace77e2..4061e083258 100644
--- a/advisories/unreviewed/2024/05/GHSA-whv2-3vp2-c4mv/GHSA-whv2-3vp2-c4mv.json
+++ b/advisories/unreviewed/2024/05/GHSA-whv2-3vp2-c4mv/GHSA-whv2-3vp2-c4mv.json
@@ -37,7 +37,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-434"
+ ],
"severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/05/GHSA-wjg2-hjqv-2pvp/GHSA-wjg2-hjqv-2pvp.json b/advisories/unreviewed/2024/05/GHSA-wjg2-hjqv-2pvp/GHSA-wjg2-hjqv-2pvp.json
index 1c699c1a915..5af371788a8 100644
--- a/advisories/unreviewed/2024/05/GHSA-wjg2-hjqv-2pvp/GHSA-wjg2-hjqv-2pvp.json
+++ b/advisories/unreviewed/2024/05/GHSA-wjg2-hjqv-2pvp/GHSA-wjg2-hjqv-2pvp.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wjg2-hjqv-2pvp",
- "modified": "2024-05-14T18:30:53Z",
+ "modified": "2025-01-08T21:32:22Z",
"published": "2024-05-14T18:30:53Z",
"aliases": [
"CVE-2024-3923"
@@ -33,7 +33,9 @@
}
],
"database_specific": {
- "cwe_ids": [],
+ "cwe_ids": [
+ "CWE-79"
+ ],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
diff --git a/advisories/unreviewed/2024/05/GHSA-www9-grm3-8mc4/GHSA-www9-grm3-8mc4.json b/advisories/unreviewed/2024/05/GHSA-www9-grm3-8mc4/GHSA-www9-grm3-8mc4.json
index 087a60b9a6d..3dcc04848ed 100644
--- a/advisories/unreviewed/2024/05/GHSA-www9-grm3-8mc4/GHSA-www9-grm3-8mc4.json
+++ b/advisories/unreviewed/2024/05/GHSA-www9-grm3-8mc4/GHSA-www9-grm3-8mc4.json
@@ -30,7 +30,8 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-324"
+ "CWE-324",
+ "CWE-672"
],
"severity": "MODERATE",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/07/GHSA-x8fw-rvr9-2hx5/GHSA-x8fw-rvr9-2hx5.json b/advisories/unreviewed/2024/07/GHSA-x8fw-rvr9-2hx5/GHSA-x8fw-rvr9-2hx5.json
index a808f36e8b9..c76c5958fb9 100644
--- a/advisories/unreviewed/2024/07/GHSA-x8fw-rvr9-2hx5/GHSA-x8fw-rvr9-2hx5.json
+++ b/advisories/unreviewed/2024/07/GHSA-x8fw-rvr9-2hx5/GHSA-x8fw-rvr9-2hx5.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x8fw-rvr9-2hx5",
- "modified": "2024-07-30T09:31:51Z",
+ "modified": "2025-01-08T21:32:23Z",
"published": "2024-07-30T09:31:51Z",
"aliases": [
"CVE-2024-42107"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nice: Don't process extts if PTP is disabled\n\nThe ice_ptp_extts_event() function can race with ice_ptp_release() and\nresult in a NULL pointer dereference which leads to a kernel panic.\n\nPanic occurs because the ice_ptp_extts_event() function calls\nptp_clock_event() with a NULL pointer. The ice driver has already\nreleased the PTP clock by the time the interrupt for the next external\ntimestamp event occurs.\n\nTo fix this, modify the ice_ptp_extts_event() function to check the\nPTP state and bail early if PTP is not ready.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-367"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-30T08:15:03Z"
diff --git a/advisories/unreviewed/2024/08/GHSA-2rfg-hm52-w7vq/GHSA-2rfg-hm52-w7vq.json b/advisories/unreviewed/2024/08/GHSA-2rfg-hm52-w7vq/GHSA-2rfg-hm52-w7vq.json
index f7b1939e86f..a52d8c801f7 100644
--- a/advisories/unreviewed/2024/08/GHSA-2rfg-hm52-w7vq/GHSA-2rfg-hm52-w7vq.json
+++ b/advisories/unreviewed/2024/08/GHSA-2rfg-hm52-w7vq/GHSA-2rfg-hm52-w7vq.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-2rfg-hm52-w7vq",
- "modified": "2024-08-08T06:30:54Z",
+ "modified": "2025-01-08T21:32:23Z",
"published": "2024-08-08T06:30:54Z",
"aliases": [
"CVE-2024-7548"
diff --git a/advisories/unreviewed/2024/08/GHSA-6vhv-fv5r-vfg6/GHSA-6vhv-fv5r-vfg6.json b/advisories/unreviewed/2024/08/GHSA-6vhv-fv5r-vfg6/GHSA-6vhv-fv5r-vfg6.json
index facd16261c2..c0b2dd1a681 100644
--- a/advisories/unreviewed/2024/08/GHSA-6vhv-fv5r-vfg6/GHSA-6vhv-fv5r-vfg6.json
+++ b/advisories/unreviewed/2024/08/GHSA-6vhv-fv5r-vfg6/GHSA-6vhv-fv5r-vfg6.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6vhv-fv5r-vfg6",
- "modified": "2024-08-21T09:31:31Z",
+ "modified": "2025-01-08T21:32:23Z",
"published": "2024-08-21T09:31:31Z",
"aliases": [
"CVE-2022-48884"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5: Fix command stats access after free\n\nCommand may fail while driver is reloading and can't accept FW commands\ntill command interface is reinitialized. Such command failure is being\nlogged to command stats. This results in NULL pointer access as command\nstats structure is being freed and reallocated during mlx5 devlink\nreload (see kernel log below).\n\nFix it by making command stats statically allocated on driver probe.\n\nKernel log:\n[ 2394.808802] BUG: unable to handle kernel paging request at 000000000002a9c0\n[ 2394.810610] PGD 0 P4D 0\n[ 2394.811811] Oops: 0002 [#1] SMP NOPTI\n...\n[ 2394.815482] RIP: 0010:native_queued_spin_lock_slowpath+0x183/0x1d0\n...\n[ 2394.829505] Call Trace:\n[ 2394.830667] _raw_spin_lock_irq+0x23/0x26\n[ 2394.831858] cmd_status_err+0x55/0x110 [mlx5_core]\n[ 2394.833020] mlx5_access_reg+0xe7/0x150 [mlx5_core]\n[ 2394.834175] mlx5_query_port_ptys+0x78/0xa0 [mlx5_core]\n[ 2394.835337] mlx5e_ethtool_get_link_ksettings+0x74/0x590 [mlx5_core]\n[ 2394.836454] ? kmem_cache_alloc_trace+0x140/0x1c0\n[ 2394.837562] __rh_call_get_link_ksettings+0x33/0x100\n[ 2394.838663] ? __rtnl_unlock+0x25/0x50\n[ 2394.839755] __ethtool_get_link_ksettings+0x72/0x150\n[ 2394.840862] duplex_show+0x6e/0xc0\n[ 2394.841963] dev_attr_show+0x1c/0x40\n[ 2394.843048] sysfs_kf_seq_show+0x9b/0x100\n[ 2394.844123] seq_read+0x153/0x410\n[ 2394.845187] vfs_read+0x91/0x140\n[ 2394.846226] ksys_read+0x4f/0xb0\n[ 2394.847234] do_syscall_64+0x5b/0x1a0\n[ 2394.848228] entry_SYSCALL_64_after_hwframe+0x65/0xca",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-476"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-21T07:15:04Z"
diff --git a/advisories/unreviewed/2024/08/GHSA-7q89-2pq5-3fpq/GHSA-7q89-2pq5-3fpq.json b/advisories/unreviewed/2024/08/GHSA-7q89-2pq5-3fpq/GHSA-7q89-2pq5-3fpq.json
index f269315b8b4..bf00d0bc1cf 100644
--- a/advisories/unreviewed/2024/08/GHSA-7q89-2pq5-3fpq/GHSA-7q89-2pq5-3fpq.json
+++ b/advisories/unreviewed/2024/08/GHSA-7q89-2pq5-3fpq/GHSA-7q89-2pq5-3fpq.json
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7q89-2pq5-3fpq",
- "modified": "2024-08-13T06:30:48Z",
+ "modified": "2025-01-08T21:32:23Z",
"published": "2024-08-13T06:30:48Z",
"aliases": [
"CVE-2024-7092"
diff --git a/advisories/unreviewed/2024/08/GHSA-x4w8-rv9m-fp3j/GHSA-x4w8-rv9m-fp3j.json b/advisories/unreviewed/2024/08/GHSA-x4w8-rv9m-fp3j/GHSA-x4w8-rv9m-fp3j.json
index 3b84a5f6e94..7a7962c4745 100644
--- a/advisories/unreviewed/2024/08/GHSA-x4w8-rv9m-fp3j/GHSA-x4w8-rv9m-fp3j.json
+++ b/advisories/unreviewed/2024/08/GHSA-x4w8-rv9m-fp3j/GHSA-x4w8-rv9m-fp3j.json
@@ -27,6 +27,7 @@
"database_specific": {
"cwe_ids": [
"CWE-119",
+ "CWE-787",
"CWE-843"
],
"severity": "HIGH",
diff --git a/advisories/unreviewed/2024/09/GHSA-wp8q-76mh-g25x/GHSA-wp8q-76mh-g25x.json b/advisories/unreviewed/2024/09/GHSA-wp8q-76mh-g25x/GHSA-wp8q-76mh-g25x.json
index ed5e5416c04..a4d837df487 100644
--- a/advisories/unreviewed/2024/09/GHSA-wp8q-76mh-g25x/GHSA-wp8q-76mh-g25x.json
+++ b/advisories/unreviewed/2024/09/GHSA-wp8q-76mh-g25x/GHSA-wp8q-76mh-g25x.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wp8q-76mh-g25x",
- "modified": "2024-09-18T09:30:35Z",
+ "modified": "2025-01-08T21:32:24Z",
"published": "2024-09-18T09:30:35Z",
"aliases": [
"CVE-2024-46715"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndriver: iio: add missing checks on iio_info's callback access\n\nSome callbacks from iio_info structure are accessed without any check, so\nif a driver doesn't implement them trying to access the corresponding\nsysfs entries produce a kernel oops such as:\n\n[ 2203.527791] Unable to handle kernel NULL pointer dereference at virtual address 00000000 when execute\n[...]\n[ 2203.783416] Call trace:\n[ 2203.783429] iio_read_channel_info_avail from dev_attr_show+0x18/0x48\n[ 2203.789807] dev_attr_show from sysfs_kf_seq_show+0x90/0x120\n[ 2203.794181] sysfs_kf_seq_show from seq_read_iter+0xd0/0x4e4\n[ 2203.798555] seq_read_iter from vfs_read+0x238/0x2a0\n[ 2203.802236] vfs_read from ksys_read+0xa4/0xd4\n[ 2203.805385] ksys_read from ret_fast_syscall+0x0/0x54\n[ 2203.809135] Exception stack(0xe0badfa8 to 0xe0badff0)\n[ 2203.812880] dfa0: 00000003 b6f10f80 00000003 b6eab000 00020000 00000000\n[ 2203.819746] dfc0: 00000003 b6f10f80 7ff00000 00000003 00000003 00000000 00020000 00000000\n[ 2203.826619] dfe0: b6e1bc88 bed80958 b6e1bc94 b6e1bcb0\n[ 2203.830363] Code: bad PC value\n[ 2203.832695] ---[ end trace 0000000000000000 ]---",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -32,8 +37,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-476"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-18T07:15:03Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-65hj-3frp-cwqp/GHSA-65hj-3frp-cwqp.json b/advisories/unreviewed/2024/12/GHSA-65hj-3frp-cwqp/GHSA-65hj-3frp-cwqp.json
index 87b85bb4cbc..292e12371e4 100644
--- a/advisories/unreviewed/2024/12/GHSA-65hj-3frp-cwqp/GHSA-65hj-3frp-cwqp.json
+++ b/advisories/unreviewed/2024/12/GHSA-65hj-3frp-cwqp/GHSA-65hj-3frp-cwqp.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-65hj-3frp-cwqp",
- "modified": "2024-12-27T15:31:51Z",
+ "modified": "2025-01-08T21:32:24Z",
"published": "2024-12-27T15:31:51Z",
"aliases": [
"CVE-2024-53200"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Fix null check for pipe_ctx->plane_state in hwss_setup_dpp\n\nThis commit addresses a null pointer dereference issue in\nhwss_setup_dpp(). The issue could occur when pipe_ctx->plane_state is\nnull. The fix adds a check to ensure `pipe_ctx->plane_state` is not null\nbefore accessing. This prevents a null pointer dereference.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -32,8 +37,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-476"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-27T14:15:27Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-6mmh-m294-9j5g/GHSA-6mmh-m294-9j5g.json b/advisories/unreviewed/2024/12/GHSA-6mmh-m294-9j5g/GHSA-6mmh-m294-9j5g.json
index 43c2c91106b..60e7cbde0ba 100644
--- a/advisories/unreviewed/2024/12/GHSA-6mmh-m294-9j5g/GHSA-6mmh-m294-9j5g.json
+++ b/advisories/unreviewed/2024/12/GHSA-6mmh-m294-9j5g/GHSA-6mmh-m294-9j5g.json
@@ -46,7 +46,8 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-74"
+ "CWE-74",
+ "CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/12/GHSA-9g8r-v4m3-ff3f/GHSA-9g8r-v4m3-ff3f.json b/advisories/unreviewed/2024/12/GHSA-9g8r-v4m3-ff3f/GHSA-9g8r-v4m3-ff3f.json
index ae9b78f4bab..c0f18a9ae33 100644
--- a/advisories/unreviewed/2024/12/GHSA-9g8r-v4m3-ff3f/GHSA-9g8r-v4m3-ff3f.json
+++ b/advisories/unreviewed/2024/12/GHSA-9g8r-v4m3-ff3f/GHSA-9g8r-v4m3-ff3f.json
@@ -46,7 +46,8 @@
],
"database_specific": {
"cwe_ids": [
- "CWE-74"
+ "CWE-74",
+ "CWE-89"
],
"severity": "MODERATE",
"github_reviewed": false,
diff --git a/advisories/unreviewed/2024/12/GHSA-9pwp-p2rw-34f5/GHSA-9pwp-p2rw-34f5.json b/advisories/unreviewed/2024/12/GHSA-9pwp-p2rw-34f5/GHSA-9pwp-p2rw-34f5.json
index f0303c37514..159c7198442 100644
--- a/advisories/unreviewed/2024/12/GHSA-9pwp-p2rw-34f5/GHSA-9pwp-p2rw-34f5.json
+++ b/advisories/unreviewed/2024/12/GHSA-9pwp-p2rw-34f5/GHSA-9pwp-p2rw-34f5.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-9pwp-p2rw-34f5",
- "modified": "2024-12-27T15:31:51Z",
+ "modified": "2025-01-08T21:32:24Z",
"published": "2024-12-27T15:31:51Z",
"aliases": [
"CVE-2024-53201"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Fix null check for pipe_ctx->plane_state in dcn20_program_pipe\n\nThis commit addresses a null pointer dereference issue in\ndcn20_program_pipe(). Previously, commit 8e4ed3cf1642 (\"drm/amd/display:\nAdd null check for pipe_ctx->plane_state in dcn20_program_pipe\")\npartially fixed the null pointer dereference issue. However, in\ndcn20_update_dchubp_dpp(), the variable pipe_ctx is passed in, and\nplane_state is accessed again through pipe_ctx. Multiple if statements\ndirectly call attributes of plane_state, leading to potential null\npointer dereference issues. This patch adds necessary null checks to\nensure stability.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-476"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-27T14:15:27Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-ccwq-3vpf-86cw/GHSA-ccwq-3vpf-86cw.json b/advisories/unreviewed/2024/12/GHSA-ccwq-3vpf-86cw/GHSA-ccwq-3vpf-86cw.json
index ec0c38d0e0d..0a4d0c18466 100644
--- a/advisories/unreviewed/2024/12/GHSA-ccwq-3vpf-86cw/GHSA-ccwq-3vpf-86cw.json
+++ b/advisories/unreviewed/2024/12/GHSA-ccwq-3vpf-86cw/GHSA-ccwq-3vpf-86cw.json
@@ -30,6 +30,7 @@
],
"database_specific": {
"cwe_ids": [
+ "CWE-434",
"CWE-94"
],
"severity": "HIGH",
diff --git a/advisories/unreviewed/2024/12/GHSA-fgfp-pp34-jxvv/GHSA-fgfp-pp34-jxvv.json b/advisories/unreviewed/2024/12/GHSA-fgfp-pp34-jxvv/GHSA-fgfp-pp34-jxvv.json
index c61f23ee5ca..852cda22d69 100644
--- a/advisories/unreviewed/2024/12/GHSA-fgfp-pp34-jxvv/GHSA-fgfp-pp34-jxvv.json
+++ b/advisories/unreviewed/2024/12/GHSA-fgfp-pp34-jxvv/GHSA-fgfp-pp34-jxvv.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-fgfp-pp34-jxvv",
- "modified": "2024-12-27T15:31:51Z",
+ "modified": "2025-01-08T21:32:24Z",
"published": "2024-12-27T15:31:51Z",
"aliases": [
"CVE-2024-53207"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: MGMT: Fix possible deadlocks\n\nThis fixes possible deadlocks like the following caused by\nhci_cmd_sync_dequeue causing the destroy function to run:\n\n INFO: task kworker/u19:0:143 blocked for more than 120 seconds.\n Tainted: G W O 6.8.0-2024-03-19-intel-next-iLS-24ww14 #1\n \"echo 0 > /proc/sys/kernel/hung_task_timeout_secs\" disables this message.\n task:kworker/u19:0 state:D stack:0 pid:143 tgid:143 ppid:2 flags:0x00004000\n Workqueue: hci0 hci_cmd_sync_work [bluetooth]\n Call Trace:\n \n __schedule+0x374/0xaf0\n schedule+0x3c/0xf0\n schedule_preempt_disabled+0x1c/0x30\n __mutex_lock.constprop.0+0x3ef/0x7a0\n __mutex_lock_slowpath+0x13/0x20\n mutex_lock+0x3c/0x50\n mgmt_set_connectable_complete+0xa4/0x150 [bluetooth]\n ? kfree+0x211/0x2a0\n hci_cmd_sync_dequeue+0xae/0x130 [bluetooth]\n ? __pfx_cmd_complete_rsp+0x10/0x10 [bluetooth]\n cmd_complete_rsp+0x26/0x80 [bluetooth]\n mgmt_pending_foreach+0x4d/0x70 [bluetooth]\n __mgmt_power_off+0x8d/0x180 [bluetooth]\n ? _raw_spin_unlock_irq+0x23/0x40\n hci_dev_close_sync+0x445/0x5b0 [bluetooth]\n hci_set_powered_sync+0x149/0x250 [bluetooth]\n set_powered_sync+0x24/0x60 [bluetooth]\n hci_cmd_sync_work+0x90/0x150 [bluetooth]\n process_one_work+0x13e/0x300\n worker_thread+0x2f7/0x420\n ? __pfx_worker_thread+0x10/0x10\n kthread+0x107/0x140\n ? __pfx_kthread+0x10/0x10\n ret_from_fork+0x3d/0x60\n ? __pfx_kthread+0x10/0x10\n ret_from_fork_asm+0x1b/0x30\n ",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -36,8 +41,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-667"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-27T14:15:28Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-j2rf-6gjq-cpq6/GHSA-j2rf-6gjq-cpq6.json b/advisories/unreviewed/2024/12/GHSA-j2rf-6gjq-cpq6/GHSA-j2rf-6gjq-cpq6.json
index e2b2044b552..3a00e616673 100644
--- a/advisories/unreviewed/2024/12/GHSA-j2rf-6gjq-cpq6/GHSA-j2rf-6gjq-cpq6.json
+++ b/advisories/unreviewed/2024/12/GHSA-j2rf-6gjq-cpq6/GHSA-j2rf-6gjq-cpq6.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-j2rf-6gjq-cpq6",
- "modified": "2024-12-27T15:31:53Z",
+ "modified": "2025-01-08T21:32:24Z",
"published": "2024-12-27T15:31:53Z",
"aliases": [
"CVE-2024-56541"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath12k: fix use-after-free in ath12k_dp_cc_cleanup()\n\nDuring ath12k module removal, in ath12k_core_deinit(),\nath12k_mac_destroy() un-registers ah->hw from mac80211 and frees\nthe ah->hw as well as all the ar's in it. After this\nath12k_core_soc_destroy()-> ath12k_dp_free()-> ath12k_dp_cc_cleanup()\ntries to access one of the freed ar's from pending skb.\n\nThis is because during mac destroy, driver failed to flush few\ndata packets, which were accessed later in ath12k_dp_cc_cleanup()\nand freed, but using ar from the packet led to this use-after-free.\n\nBUG: KASAN: use-after-free in ath12k_dp_cc_cleanup.part.0+0x5e2/0xd40 [ath12k]\nWrite of size 4 at addr ffff888150bd3514 by task modprobe/8926\nCPU: 0 UID: 0 PID: 8926 Comm: modprobe Not tainted\n6.11.0-rc2-wt-ath+ #1746\nHardware name: Intel(R) Client Systems NUC8i7HVK/NUC8i7HVB, BIOS\nHNKBLi70.86A.0067.2021.0528.1339 05/28/2021\n\nCall Trace:\n \n dump_stack_lvl+0x7d/0xe0\n print_address_description.constprop.0+0x33/0x3a0\n print_report+0xb5/0x260\n ? kasan_addr_to_slab+0x24/0x80\n kasan_report+0xd8/0x110\n ? ath12k_dp_cc_cleanup.part.0+0x5e2/0xd40 [ath12k]\n ? ath12k_dp_cc_cleanup.part.0+0x5e2/0xd40 [ath12k]\n kasan_check_range+0xf3/0x1a0\n __kasan_check_write+0x14/0x20\n ath12k_dp_cc_cleanup.part.0+0x5e2/0xd40 [ath12k]\n ath12k_dp_free+0x178/0x420 [ath12k]\n ath12k_core_stop+0x176/0x200 [ath12k]\n ath12k_core_deinit+0x13f/0x210 [ath12k]\n ath12k_pci_remove+0xad/0x1c0 [ath12k]\n pci_device_remove+0x9b/0x1b0\n device_remove+0xbf/0x150\n device_release_driver_internal+0x3c3/0x580\n ? __kasan_check_read+0x11/0x20\n driver_detach+0xc4/0x190\n bus_remove_driver+0x130/0x2a0\n driver_unregister+0x68/0x90\n pci_unregister_driver+0x24/0x240\n ? find_module_all+0x13e/0x1e0\n ath12k_pci_exit+0x10/0x20 [ath12k]\n __do_sys_delete_module+0x32c/0x580\n ? module_flags+0x2f0/0x2f0\n ? kmem_cache_free+0xf0/0x410\n ? __fput+0x56f/0xab0\n ? __fput+0x56f/0xab0\n ? debug_smp_processor_id+0x17/0x20\n __x64_sys_delete_module+0x4f/0x70\n x64_sys_call+0x522/0x9f0\n do_syscall_64+0x64/0x130\n entry_SYSCALL_64_after_hwframe+0x4b/0x53\nRIP: 0033:0x7f8182c6ac8b\n\nCommit 24de1b7b231c (\"wifi: ath12k: fix flush failure in recovery\nscenarios\") added the change to decrement the pending packets count\nin case of recovery which make sense as ah->hw as well all\nar's in it are intact during recovery, but during core deinit there\nis no use in decrementing packets count or waking up the empty waitq\nas the module is going to be removed also ar's from pending skb's\ncan't be used and the packets should just be released back.\n\nTo fix this, avoid accessing ar from skb->cb when driver is being\nunregistered.\n\nTested-on: QCN9274 hw2.0 PCI WLAN.WBE.1.1.1-00214-QCAHKSWPL_SILICONZ-1\nTested-on: WCN7850 hw2.0 PCI WLAN.HMT.1.0.c5-00481-QCAHMTSWPL_V1.0_V2.0_SILICONZ-3",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-416"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-27T14:15:33Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-rxh5-6q4f-cfwp/GHSA-rxh5-6q4f-cfwp.json b/advisories/unreviewed/2024/12/GHSA-rxh5-6q4f-cfwp/GHSA-rxh5-6q4f-cfwp.json
index d6443231506..4a0a173690d 100644
--- a/advisories/unreviewed/2024/12/GHSA-rxh5-6q4f-cfwp/GHSA-rxh5-6q4f-cfwp.json
+++ b/advisories/unreviewed/2024/12/GHSA-rxh5-6q4f-cfwp/GHSA-rxh5-6q4f-cfwp.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-rxh5-6q4f-cfwp",
- "modified": "2024-12-27T15:31:52Z",
+ "modified": "2025-01-08T21:32:24Z",
"published": "2024-12-27T15:31:52Z",
"aliases": [
"CVE-2024-53222"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nzram: fix NULL pointer in comp_algorithm_show()\n\nLTP reported a NULL pointer dereference as followed:\n\n CPU: 7 UID: 0 PID: 5995 Comm: cat Kdump: loaded Not tainted 6.12.0-rc6+ #3\n Hardware name: QEMU KVM Virtual Machine, BIOS 0.0.0 02/06/2015\n pstate: 40400005 (nZcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--)\n pc : __pi_strcmp+0x24/0x140\n lr : zcomp_available_show+0x60/0x100 [zram]\n sp : ffff800088b93b90\n x29: ffff800088b93b90 x28: 0000000000000001 x27: 0000000000400cc0\n x26: 0000000000000ffe x25: ffff80007b3e2388 x24: 0000000000000000\n x23: ffff80007b3e2390 x22: ffff0004041a9000 x21: ffff80007b3e2900\n x20: 0000000000000000 x19: 0000000000000000 x18: 0000000000000000\n x17: 0000000000000000 x16: 0000000000000000 x15: 0000000000000000\n x14: 0000000000000000 x13: 0000000000000000 x12: 0000000000000000\n x11: 0000000000000000 x10: ffff80007b3e2900 x9 : ffff80007b3cb280\n x8 : 0101010101010101 x7 : 0000000000000000 x6 : 0000000000000000\n x5 : 0000000000000040 x4 : 0000000000000000 x3 : 00656c722d6f7a6c\n x2 : 0000000000000000 x1 : ffff80007b3e2900 x0 : 0000000000000000\n Call trace:\n __pi_strcmp+0x24/0x140\n comp_algorithm_show+0x40/0x70 [zram]\n dev_attr_show+0x28/0x80\n sysfs_kf_seq_show+0x90/0x140\n kernfs_seq_show+0x34/0x48\n seq_read_iter+0x1d4/0x4e8\n kernfs_fop_read_iter+0x40/0x58\n new_sync_read+0x9c/0x168\n vfs_read+0x1a8/0x1f8\n ksys_read+0x74/0x108\n __arm64_sys_read+0x24/0x38\n invoke_syscall+0x50/0x120\n el0_svc_common.constprop.0+0xc8/0xf0\n do_el0_svc+0x24/0x38\n el0_svc+0x38/0x138\n el0t_64_sync_handler+0xc0/0xc8\n el0t_64_sync+0x188/0x190\n\nThe zram->comp_algs[ZRAM_PRIMARY_COMP] can be NULL in zram_add() if\ncomp_algorithm_set() has not been called. User can access the zram device\nby sysfs after device_add_disk(), so there is a time window to trigger the\nNULL pointer dereference. Move it ahead device_add_disk() to make sure\nwhen user can access the zram device, it is ready. comp_algorithm_set()\nis protected by zram->init_lock in other places and no such problem.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-476"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-27T14:15:30Z"
diff --git a/advisories/unreviewed/2024/12/GHSA-x7xx-q6m5-jw79/GHSA-x7xx-q6m5-jw79.json b/advisories/unreviewed/2024/12/GHSA-x7xx-q6m5-jw79/GHSA-x7xx-q6m5-jw79.json
index 3b027718e81..1396843ab24 100644
--- a/advisories/unreviewed/2024/12/GHSA-x7xx-q6m5-jw79/GHSA-x7xx-q6m5-jw79.json
+++ b/advisories/unreviewed/2024/12/GHSA-x7xx-q6m5-jw79/GHSA-x7xx-q6m5-jw79.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-x7xx-q6m5-jw79",
- "modified": "2024-12-27T15:31:51Z",
+ "modified": "2025-01-08T21:32:24Z",
"published": "2024-12-27T15:31:51Z",
"aliases": [
"CVE-2024-53199"
],
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: imx-audmix: Add NULL check in imx_audmix_probe\n\ndevm_kasprintf() can return a NULL pointer on failure,but this\nreturned value in imx_audmix_probe() is not checked.\nAdd NULL check in imx_audmix_probe(), to handle kernel NULL\npointer dereference error.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-476"
+ ],
+ "severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-27T14:15:27Z"
diff --git a/advisories/unreviewed/2025/01/GHSA-27x5-2866-42xg/GHSA-27x5-2866-42xg.json b/advisories/unreviewed/2025/01/GHSA-27x5-2866-42xg/GHSA-27x5-2866-42xg.json
new file mode 100644
index 00000000000..6443a41855f
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-27x5-2866-42xg/GHSA-27x5-2866-42xg.json
@@ -0,0 +1,25 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-27x5-2866-42xg",
+ "modified": "2025-01-08T21:32:26Z",
+ "published": "2025-01-08T21:32:26Z",
+ "aliases": [
+ "CVE-2024-45345"
+ ],
+ "details": "Rejected reason: reserved but not needed",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45345"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-08T20:15:27Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-3r2p-7j7f-fc8q/GHSA-3r2p-7j7f-fc8q.json b/advisories/unreviewed/2025/01/GHSA-3r2p-7j7f-fc8q/GHSA-3r2p-7j7f-fc8q.json
new file mode 100644
index 00000000000..fca895e2fb8
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-3r2p-7j7f-fc8q/GHSA-3r2p-7j7f-fc8q.json
@@ -0,0 +1,34 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-3r2p-7j7f-fc8q",
+ "modified": "2025-01-08T21:32:26Z",
+ "published": "2025-01-08T21:32:26Z",
+ "aliases": [
+ "CVE-2024-54010"
+ ],
+ "details": "A vulnerability in the firewall component of HPE Aruba Networking CX 10000 Series Switches exists. It could allow an unauthenticated adjacent attacker to conduct a packet forwarding attack against the ICMP and UDP protocol. For this attack to be successful an attacker requires a switch configuration that allows packets routing (at layer 3). Configurations that do not allow network traffic routing are not impacted. Successful exploitation could allow an attacker to bypass security policies, potentially leading to unauthorized data exposure.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54010"
+ },
+ {
+ "type": "WEB",
+ "url": "https://csaf.arubanetworks.com/2024/hpe_aruba_networking_-_hpesbnw04772.txt"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": "LOW",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-08T21:15:12Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-7wr9-8g48-p7wg/GHSA-7wr9-8g48-p7wg.json b/advisories/unreviewed/2025/01/GHSA-7wr9-8g48-p7wg/GHSA-7wr9-8g48-p7wg.json
index 4da07f945b4..f710fa393f1 100644
--- a/advisories/unreviewed/2025/01/GHSA-7wr9-8g48-p7wg/GHSA-7wr9-8g48-p7wg.json
+++ b/advisories/unreviewed/2025/01/GHSA-7wr9-8g48-p7wg/GHSA-7wr9-8g48-p7wg.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7wr9-8g48-p7wg",
- "modified": "2025-01-07T18:30:49Z",
+ "modified": "2025-01-08T21:32:24Z",
"published": "2025-01-07T18:30:49Z",
"aliases": [
"CVE-2024-46601"
],
"details": "Elspec Engineering G5 Digital Fault Recorder Firmware v1.2.1.12 was discovered to contain a buffer overflow.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-120"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-07T16:15:34Z"
diff --git a/advisories/unreviewed/2025/01/GHSA-8h93-28hg-fj84/GHSA-8h93-28hg-fj84.json b/advisories/unreviewed/2025/01/GHSA-8h93-28hg-fj84/GHSA-8h93-28hg-fj84.json
new file mode 100644
index 00000000000..e6aac37b1ff
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-8h93-28hg-fj84/GHSA-8h93-28hg-fj84.json
@@ -0,0 +1,41 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-8h93-28hg-fj84",
+ "modified": "2025-01-08T21:32:25Z",
+ "published": "2025-01-08T21:32:25Z",
+ "aliases": [
+ "CVE-2024-53526"
+ ],
+ "details": "composio >=0.5.40 is vulnerable to Command Execution in composio_openai, composio_claude, and composio_julep via the handle_tool_calls function.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53526"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/ComposioHQ/composio/issues/1073"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/ComposioHQ/composio/blob/11ee7470aa6543097ee30bb036af8e9726dc7a85/python/plugins/claude/composio_claude/toolset.py#L156"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/ComposioHQ/composio/blob/11ee7470aa6543097ee30bb036af8e9726dc7a85/python/plugins/julep/composio_julep/toolset.py#L21"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/ComposioHQ/composio/blob/11ee7470aa6543097ee30bb036af8e9726dc7a85/python/plugins/openai/composio_openai/toolset.py#L184"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-08T19:15:37Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-8qh8-gwrc-mfxf/GHSA-8qh8-gwrc-mfxf.json b/advisories/unreviewed/2025/01/GHSA-8qh8-gwrc-mfxf/GHSA-8qh8-gwrc-mfxf.json
new file mode 100644
index 00000000000..68926f5b4cf
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-8qh8-gwrc-mfxf/GHSA-8qh8-gwrc-mfxf.json
@@ -0,0 +1,56 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-8qh8-gwrc-mfxf",
+ "modified": "2025-01-08T21:32:25Z",
+ "published": "2025-01-08T21:32:25Z",
+ "aliases": [
+ "CVE-2024-13189"
+ ],
+ "details": "A vulnerability classified as critical has been found in ZeroWdd myblog 1.0. This affects an unknown part of the file src/main/java/com/wdd/myblog/config/MyBlogMvcConfig.java. The manipulation leads to permission issues. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
+ },
+ {
+ "type": "CVSS_V4",
+ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13189"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/ZeroWdd/myblog/issues/1"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/ZeroWdd/myblog/issues/1#issue-2759828006"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?ctiid.290781"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?id.290781"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?submit.469223"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-266"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-08T20:15:27Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-948c-8jvf-p44x/GHSA-948c-8jvf-p44x.json b/advisories/unreviewed/2025/01/GHSA-948c-8jvf-p44x/GHSA-948c-8jvf-p44x.json
index 2aba6523fd5..c2db37eccb9 100644
--- a/advisories/unreviewed/2025/01/GHSA-948c-8jvf-p44x/GHSA-948c-8jvf-p44x.json
+++ b/advisories/unreviewed/2025/01/GHSA-948c-8jvf-p44x/GHSA-948c-8jvf-p44x.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-948c-8jvf-p44x",
- "modified": "2025-01-07T18:30:52Z",
+ "modified": "2025-01-08T21:32:25Z",
"published": "2025-01-07T18:30:52Z",
"aliases": [
"CVE-2024-55411"
],
"details": "An issue in the snxpcamd.sys component of SUNIX Multi I/O Card v10.1.0.0 allows attackers to perform arbitrary read and write actions via supplying crafted IOCTL requests.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-732"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-07T18:15:20Z"
diff --git a/advisories/unreviewed/2025/01/GHSA-c26g-rhr3-gf6v/GHSA-c26g-rhr3-gf6v.json b/advisories/unreviewed/2025/01/GHSA-c26g-rhr3-gf6v/GHSA-c26g-rhr3-gf6v.json
new file mode 100644
index 00000000000..536c44e15c7
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-c26g-rhr3-gf6v/GHSA-c26g-rhr3-gf6v.json
@@ -0,0 +1,40 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-c26g-rhr3-gf6v",
+ "modified": "2025-01-08T21:32:25Z",
+ "published": "2025-01-08T21:32:25Z",
+ "aliases": [
+ "CVE-2024-54818"
+ ],
+ "details": "SourceCodester Computer Laboratory Management System 1.0 is vulnerable to Incorrect Access Control. via /php-lms/admin/?page=user/list.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-54818"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/CloseC4ll/vulnerability-research/tree/main/CVE-2024-54818"
+ },
+ {
+ "type": "WEB",
+ "url": "https://portswigger.net/web-security/access-control#how-to-prevent-access-control-vulnerabilities"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-281"
+ ],
+ "severity": "HIGH",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-08T19:15:38Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-fv26-qm6r-mmq5/GHSA-fv26-qm6r-mmq5.json b/advisories/unreviewed/2025/01/GHSA-fv26-qm6r-mmq5/GHSA-fv26-qm6r-mmq5.json
new file mode 100644
index 00000000000..c6b7dafbd71
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-fv26-qm6r-mmq5/GHSA-fv26-qm6r-mmq5.json
@@ -0,0 +1,40 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-fv26-qm6r-mmq5",
+ "modified": "2025-01-08T21:32:26Z",
+ "published": "2025-01-08T21:32:26Z",
+ "aliases": [
+ "CVE-2025-0194"
+ ],
+ "details": "An issue was discovered in GitLab CE/EE affecting all versions starting from 17.4 prior to 17.5.1, starting from 17.6 prior to 17.6.1, and starting from 17.7 prior to 17.7.1. Under certain conditions, access tokens may have been logged when API requests were made in a specific manner.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0194"
+ },
+ {
+ "type": "WEB",
+ "url": "https://about.gitlab.com/releases/2025/01/08/patch-release-gitlab-17-7-1-released/#possible-access-token-exposure-in-gitlab-logs"
+ },
+ {
+ "type": "WEB",
+ "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/489459"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-538"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-08T20:15:29Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-fvfx-9ggm-qjqg/GHSA-fvfx-9ggm-qjqg.json b/advisories/unreviewed/2025/01/GHSA-fvfx-9ggm-qjqg/GHSA-fvfx-9ggm-qjqg.json
new file mode 100644
index 00000000000..5ce09517bdd
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-fvfx-9ggm-qjqg/GHSA-fvfx-9ggm-qjqg.json
@@ -0,0 +1,52 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-fvfx-9ggm-qjqg",
+ "modified": "2025-01-08T21:32:25Z",
+ "published": "2025-01-08T21:32:25Z",
+ "aliases": [
+ "CVE-2024-13188"
+ ],
+ "details": "A vulnerability was found in MicroWorld eScan Antivirus 7.0.32 on Linux. It has been rated as critical. Affected by this issue is some unknown functionality of the file /opt/MicroWorld/var/ of the component Installation Handler. The manipulation leads to incorrect default permissions. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
+ },
+ {
+ "type": "CVSS_V4",
+ "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13188"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/hawkteam404/RnD_Public/blob/main/escan_incorrect_default_perm.md"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?ctiid.290780"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?id.290780"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?submit.468796"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-266"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-08T19:15:30Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-gxfw-pm97-x2qf/GHSA-gxfw-pm97-x2qf.json b/advisories/unreviewed/2025/01/GHSA-gxfw-pm97-x2qf/GHSA-gxfw-pm97-x2qf.json
index 34391e502c1..2223a130cf7 100644
--- a/advisories/unreviewed/2025/01/GHSA-gxfw-pm97-x2qf/GHSA-gxfw-pm97-x2qf.json
+++ b/advisories/unreviewed/2025/01/GHSA-gxfw-pm97-x2qf/GHSA-gxfw-pm97-x2qf.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-gxfw-pm97-x2qf",
- "modified": "2025-01-07T18:30:49Z",
+ "modified": "2025-01-08T21:32:25Z",
"published": "2025-01-07T18:30:49Z",
"aliases": [
"CVE-2024-55556"
],
"details": "A vulnerability in Crater Invoice allows an unauthenticated attacker with knowledge of the APP_KEY to achieve remote command execution on the server by manipulating the laravel_session cookie, exploiting arbitrary deserialization through the encrypted session data. The exploitation vector of this vulnerability relies on an attacker obtaining Laravel's secret APP_KEY, which would allow them to decrypt and manipulate session cookies (laravel_session) containing serialized data. By altering this data and re-encrypting it with the APP_KEY, the attacker could trigger arbitrary deserialization on the server, potentially leading to remote command execution (RCE). The vulnerability is primarily exploited by accessing an exposed cookie and manipulating it using the secret key to gain malicious access to the server.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -28,8 +33,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-502"
+ ],
+ "severity": "CRITICAL",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-07T16:15:37Z"
diff --git a/advisories/unreviewed/2025/01/GHSA-h4qv-2mm7-9gwm/GHSA-h4qv-2mm7-9gwm.json b/advisories/unreviewed/2025/01/GHSA-h4qv-2mm7-9gwm/GHSA-h4qv-2mm7-9gwm.json
index 648ca8a77d8..86f62f10255 100644
--- a/advisories/unreviewed/2025/01/GHSA-h4qv-2mm7-9gwm/GHSA-h4qv-2mm7-9gwm.json
+++ b/advisories/unreviewed/2025/01/GHSA-h4qv-2mm7-9gwm/GHSA-h4qv-2mm7-9gwm.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-h4qv-2mm7-9gwm",
- "modified": "2025-01-08T18:30:48Z",
+ "modified": "2025-01-08T21:32:25Z",
"published": "2025-01-08T18:30:48Z",
"aliases": [
"CVE-2024-51442"
],
"details": "Command Injection in Minidlna version v1.3.3 and before allows an attacker to execute arbitrary OS commands via a specially crafted minidlna.conf configuration file.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -32,8 +37,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-77"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-08T18:15:16Z"
diff --git a/advisories/unreviewed/2025/01/GHSA-hjr5-q2v6-7chx/GHSA-hjr5-q2v6-7chx.json b/advisories/unreviewed/2025/01/GHSA-hjr5-q2v6-7chx/GHSA-hjr5-q2v6-7chx.json
new file mode 100644
index 00000000000..8c20561b523
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-hjr5-q2v6-7chx/GHSA-hjr5-q2v6-7chx.json
@@ -0,0 +1,44 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-hjr5-q2v6-7chx",
+ "modified": "2025-01-08T21:32:26Z",
+ "published": "2025-01-08T21:32:26Z",
+ "aliases": [
+ "CVE-2024-12431"
+ ],
+ "details": "An issue was discovered in GitLab CE/EE affecting all versions starting from 15.5 before 17.5.5, 17.6 before 17.6.3, and 17.7 before 17.7.1, in which unauthorized users could manipulate the status of issues in public projects.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12431"
+ },
+ {
+ "type": "WEB",
+ "url": "https://hackerone.com/reports/2877710"
+ },
+ {
+ "type": "WEB",
+ "url": "https://about.gitlab.com/releases/2025/01/08/patch-release-gitlab-17-7-1-released/#unauthorized-user-can-manipulate-status-of-issues-in-public-projects"
+ },
+ {
+ "type": "WEB",
+ "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/508742"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-862"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-08T21:15:11Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-hq4q-hgg3-4hgc/GHSA-hq4q-hgg3-4hgc.json b/advisories/unreviewed/2025/01/GHSA-hq4q-hgg3-4hgc/GHSA-hq4q-hgg3-4hgc.json
new file mode 100644
index 00000000000..dd5c57e005a
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-hq4q-hgg3-4hgc/GHSA-hq4q-hgg3-4hgc.json
@@ -0,0 +1,25 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-hq4q-hgg3-4hgc",
+ "modified": "2025-01-08T21:32:25Z",
+ "published": "2025-01-08T21:32:25Z",
+ "aliases": [
+ "CVE-2024-45342"
+ ],
+ "details": "Rejected reason: reserved but not needed",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45342"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-08T20:15:27Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-hxfw-qgg7-73mj/GHSA-hxfw-qgg7-73mj.json b/advisories/unreviewed/2025/01/GHSA-hxfw-qgg7-73mj/GHSA-hxfw-qgg7-73mj.json
new file mode 100644
index 00000000000..057f440966c
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-hxfw-qgg7-73mj/GHSA-hxfw-qgg7-73mj.json
@@ -0,0 +1,56 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-hxfw-qgg7-73mj",
+ "modified": "2025-01-08T21:32:26Z",
+ "published": "2025-01-08T21:32:26Z",
+ "aliases": [
+ "CVE-2024-13190"
+ ],
+ "details": "A vulnerability classified as critical was found in ZeroWdd myblog 1.0. This vulnerability affects unknown code of the file src/main/resources/mapper/BlogMapper.xml. The manipulation of the argument findBlogList/getTotalBlogs leads to xml injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
+ },
+ {
+ "type": "CVSS_V4",
+ "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
+ }
+ ],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-13190"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/ZeroWdd/myblog/issues/2"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/ZeroWdd/myblog/issues/2#issue-2759833644"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?ctiid.290782"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?id.290782"
+ },
+ {
+ "type": "WEB",
+ "url": "https://vuldb.com/?submit.469226"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-74"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-08T21:15:12Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-jxq8-vf97-xqr3/GHSA-jxq8-vf97-xqr3.json b/advisories/unreviewed/2025/01/GHSA-jxq8-vf97-xqr3/GHSA-jxq8-vf97-xqr3.json
index 0f2cde153c9..fd6bd2f1d8a 100644
--- a/advisories/unreviewed/2025/01/GHSA-jxq8-vf97-xqr3/GHSA-jxq8-vf97-xqr3.json
+++ b/advisories/unreviewed/2025/01/GHSA-jxq8-vf97-xqr3/GHSA-jxq8-vf97-xqr3.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-jxq8-vf97-xqr3",
- "modified": "2025-01-07T18:30:49Z",
+ "modified": "2025-01-08T21:32:25Z",
"published": "2025-01-07T18:30:49Z",
"aliases": [
"CVE-2024-55008"
],
"details": "JATOS 3.9.4 contains a denial-of-service (DoS) vulnerability in the authentication system, where an attacker can prevent legitimate users from accessing their accounts by repeatedly sending multiple failed login attempts. Specifically, by submitting 3 incorrect login attempts every minute, the attacker can trigger the account lockout mechanism on the account level, effectively locking the user out indefinitely. Since the lockout is applied to the user account and not based on the IP address, any attacker can trigger the lockout on any user account, regardless of their privileges.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-307"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-07T16:15:36Z"
diff --git a/advisories/unreviewed/2025/01/GHSA-p48v-w2c7-4756/GHSA-p48v-w2c7-4756.json b/advisories/unreviewed/2025/01/GHSA-p48v-w2c7-4756/GHSA-p48v-w2c7-4756.json
index e7c43f97514..b3ec5267acc 100644
--- a/advisories/unreviewed/2025/01/GHSA-p48v-w2c7-4756/GHSA-p48v-w2c7-4756.json
+++ b/advisories/unreviewed/2025/01/GHSA-p48v-w2c7-4756/GHSA-p48v-w2c7-4756.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-p48v-w2c7-4756",
- "modified": "2025-01-08T18:30:48Z",
+ "modified": "2025-01-08T21:32:25Z",
"published": "2025-01-08T18:30:48Z",
"aliases": [
"CVE-2024-55517"
],
"details": "An issue was discovered in the Interllect Core Search in Polaris FT Intellect Core Banking 9.5. Input passed through the groupType parameter in /SCGController is mishandled before being used in SQL queries, allowing SQL injection in an authenticated session.",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -20,8 +25,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-89"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-08T16:15:36Z"
diff --git a/advisories/unreviewed/2025/01/GHSA-w3wc-83g3-v333/GHSA-w3wc-83g3-v333.json b/advisories/unreviewed/2025/01/GHSA-w3wc-83g3-v333/GHSA-w3wc-83g3-v333.json
index ab6f16b0fec..320c27e93b1 100644
--- a/advisories/unreviewed/2025/01/GHSA-w3wc-83g3-v333/GHSA-w3wc-83g3-v333.json
+++ b/advisories/unreviewed/2025/01/GHSA-w3wc-83g3-v333/GHSA-w3wc-83g3-v333.json
@@ -1,13 +1,18 @@
{
"schema_version": "1.4.0",
"id": "GHSA-w3wc-83g3-v333",
- "modified": "2025-01-07T21:30:55Z",
+ "modified": "2025-01-08T21:32:25Z",
"published": "2025-01-07T21:30:55Z",
"aliases": [
"CVE-2024-40427"
],
"details": "Stack Buffer Overflow in PX4-Autopilot v1.14.3, which allows attackers to execute commands to exploit this vulnerability and cause the program to refuse to execute",
- "severity": [],
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H"
+ }
+ ],
"affected": [],
"references": [
{
@@ -24,8 +29,10 @@
}
],
"database_specific": {
- "cwe_ids": [],
- "severity": null,
+ "cwe_ids": [
+ "CWE-120"
+ ],
+ "severity": "HIGH",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-07T19:15:32Z"
diff --git a/advisories/unreviewed/2025/01/GHSA-w5p9-49f2-7v55/GHSA-w5p9-49f2-7v55.json b/advisories/unreviewed/2025/01/GHSA-w5p9-49f2-7v55/GHSA-w5p9-49f2-7v55.json
new file mode 100644
index 00000000000..040e91aab27
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-w5p9-49f2-7v55/GHSA-w5p9-49f2-7v55.json
@@ -0,0 +1,25 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-w5p9-49f2-7v55",
+ "modified": "2025-01-08T21:32:25Z",
+ "published": "2025-01-08T21:32:25Z",
+ "aliases": [
+ "CVE-2024-45344"
+ ],
+ "details": "Rejected reason: reserved but not needed",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45344"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-08T20:15:27Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-w6w8-xwp9-3vwq/GHSA-w6w8-xwp9-3vwq.json b/advisories/unreviewed/2025/01/GHSA-w6w8-xwp9-3vwq/GHSA-w6w8-xwp9-3vwq.json
new file mode 100644
index 00000000000..1cc8301f1fa
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-w6w8-xwp9-3vwq/GHSA-w6w8-xwp9-3vwq.json
@@ -0,0 +1,33 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-w6w8-xwp9-3vwq",
+ "modified": "2025-01-08T21:32:26Z",
+ "published": "2025-01-08T21:32:26Z",
+ "aliases": [
+ "CVE-2024-52869"
+ ],
+ "details": "Certain Teradata account-handling code through 2024-11-04, used with SUSE Enterprise Linux Server, mismanages groups. Specifically, when there is an operating system move from SUSE Enterprise Linux Server (SLES) 12 Service Pack (SP) 2 or 3 to SLES 15 SP2 on Teradata Database systems, some service/system user accounts, and possibly systems administrator created user accounts, are incorrectly assigned to groups that allow higher system-level privileges than intended for those user accounts. Depending on the usage of these accounts, this may lead to full system compromise.",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52869"
+ },
+ {
+ "type": "WEB",
+ "url": "https://chrismanson.com/CVE/cve-2024-52869.html"
+ },
+ {
+ "type": "WEB",
+ "url": "https://www.teradata.com/trust-security-center/data-security"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-08T21:15:12Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2025/01/GHSA-wfxv-g67w-6q5r/GHSA-wfxv-g67w-6q5r.json b/advisories/unreviewed/2025/01/GHSA-wfxv-g67w-6q5r/GHSA-wfxv-g67w-6q5r.json
new file mode 100644
index 00000000000..12f8957bce8
--- /dev/null
+++ b/advisories/unreviewed/2025/01/GHSA-wfxv-g67w-6q5r/GHSA-wfxv-g67w-6q5r.json
@@ -0,0 +1,25 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-wfxv-g67w-6q5r",
+ "modified": "2025-01-08T21:32:25Z",
+ "published": "2025-01-08T21:32:25Z",
+ "aliases": [
+ "CVE-2024-45343"
+ ],
+ "details": "Rejected reason: reserved but not needed",
+ "severity": [],
+ "affected": [],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45343"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [],
+ "severity": null,
+ "github_reviewed": false,
+ "github_reviewed_at": null,
+ "nvd_published_at": "2025-01-08T20:15:27Z"
+ }
+}
\ No newline at end of file