From ec41ee5a06fb5144d0657add96078008b44a1b49 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 4 Feb 2025 18:31:48 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-26v4-3ghx-vmrv.json | 2 +- .../GHSA-3vmp-cf5x-w457.json | 2 +- .../GHSA-cjqq-8xv6-575p.json | 2 +- .../GHSA-g6xh-vmjv-c9qj.json | 2 +- .../GHSA-gf47-3hhj-gv96.json | 3 +- .../GHSA-hj5r-2q87-qf8g.json | 16 ++++++-- .../GHSA-pm93-g4gf-j42f.json | 2 +- .../GHSA-5vr9-7945-27pf.json | 6 ++- .../GHSA-2rx2-wvh6-wg6m.json | 4 +- .../GHSA-8wm5-mg2w-7cq3.json | 3 +- .../GHSA-gc9f-xmg3-m3pp.json | 4 +- .../GHSA-j4vh-r4c7-fpmx.json | 4 +- .../GHSA-qhm5-6q48-xxp4.json | 1 + .../GHSA-qmx9-67mw-5ghq.json | 4 +- .../GHSA-v8x8-32r8-5x52.json | 1 + .../GHSA-92pj-vh86-9j44.json | 3 +- .../GHSA-9mq3-jxwh-fh25.json | 4 +- .../GHSA-g7r6-cg59-6p4f.json | 3 +- .../GHSA-hfm4-r5j9-2q25.json | 4 +- .../GHSA-m3m6-68fj-x8xv.json | 1 + .../GHSA-mfpg-4h2f-6hgr.json | 3 +- .../GHSA-mwpv-999v-x2vh.json | 6 ++- .../GHSA-47mh-5593-5c2x.json | 6 ++- .../GHSA-68wm-4xjg-6p6m.json | 4 +- .../GHSA-73xm-rcxq-249m.json | 4 +- .../GHSA-7jhj-m58m-cg57.json | 4 +- .../GHSA-g3qp-jr64-m396.json | 4 +- .../GHSA-gfrg-8rq8-4fc9.json | 4 +- .../GHSA-jfx7-45mm-rw3j.json | 6 ++- .../GHSA-jh6v-7wrw-4xxr.json | 4 +- .../GHSA-jw6c-wq8m-h8g9.json | 4 +- .../GHSA-jwmq-832r-8m9v.json | 4 +- .../GHSA-m34x-wh4m-w7q3.json | 4 +- .../GHSA-m8hx-m8xm-2r63.json | 6 ++- .../GHSA-mwpf-hrvf-537f.json | 4 +- .../GHSA-q36g-c4c7-q48x.json | 6 ++- .../GHSA-q59m-g738-4273.json | 4 +- .../GHSA-qj2m-5f68-mqwf.json | 4 +- .../GHSA-rq82-xjv7-57jq.json | 4 +- .../GHSA-v2rf-m9c8-8844.json | 4 +- .../GHSA-v596-2mxw-3xh7.json | 4 +- .../GHSA-x2p9-2jc3-8gpp.json | 1 + .../GHSA-x8vj-x24h-rrfv.json | 4 +- .../GHSA-xcp9-jx79-m233.json | 4 +- .../GHSA-xp2p-9wq2-wx5q.json | 4 +- .../GHSA-xrr4-j32g-hj8m.json | 4 +- .../GHSA-xvrf-3569-2x76.json | 4 +- .../GHSA-2244-w4gj-c9vv.json | 6 ++- .../GHSA-48cf-pw67-hg9m.json | 4 +- .../GHSA-829x-599p-43vg.json | 3 +- .../GHSA-mg73-mvvv-5f9h.json | 4 +- .../GHSA-pj7c-pvg3-fjr7.json | 6 ++- .../GHSA-rrh3-c47h-2239.json | 4 +- .../GHSA-xcf2-9gfx-5x8f.json | 4 +- .../GHSA-9533-j5r3-r25x.json | 6 ++- .../GHSA-c8f3-gj35-46cf.json | 1 + .../GHSA-3x6q-q5jm-q33x.json | 2 +- .../GHSA-7h9v-398p-wh5c.json | 6 ++- .../GHSA-xfrr-5gq4-4j32.json | 2 +- .../GHSA-43fc-fqg5-m549.json | 2 +- .../GHSA-5pg9-rxpc-jxgf.json | 6 ++- .../GHSA-j34c-54rj-94x3.json | 2 +- .../GHSA-mfgc-pq48-8r3j.json | 2 +- .../GHSA-x3rw-xr73-fq7h.json | 3 +- .../GHSA-294c-hx25-mgvq.json | 4 +- .../GHSA-3mp2-rhvg-j63c.json | 3 +- .../GHSA-6m5p-mv69-2wfh.json | 1 + .../GHSA-72fc-7pff-vv9c.json | 1 + .../GHSA-86jp-9fvq-qr9r.json | 1 + .../GHSA-cxvp-2gqq-8958.json | 3 +- .../GHSA-pg94-fqwx-cjcv.json | 3 +- .../GHSA-2hmh-wh7q-6wpr.json | 4 +- .../GHSA-35v7-q7c2-qg94.json | 4 +- .../GHSA-3647-958p-fpph.json | 4 +- .../GHSA-4qxc-98vx-fp5g.json | 4 +- .../GHSA-4x4h-rvfw-x95m.json | 4 +- .../GHSA-5558-mmq3-572w.json | 3 +- .../GHSA-5fj8-p786-m6j9.json | 4 +- .../GHSA-5qfx-xmmx-f9c7.json | 15 ++++++-- .../GHSA-6v8w-mg2j-7jw3.json | 15 ++++++-- .../GHSA-6wcx-2p4q-557w.json | 15 ++++++-- .../GHSA-7792-f3h4-qxjq.json | 15 ++++++-- .../GHSA-7hhm-hgmx-pp76.json | 15 ++++++-- .../GHSA-86hg-w33q-7372.json | 15 ++++++-- .../GHSA-8qrr-cpmw-jq92.json | 15 ++++++-- .../GHSA-8x43-6vm2-j847.json | 2 +- .../GHSA-9v8h-2rmp-52m8.json | 3 +- .../GHSA-9w9r-vq29-w437.json | 15 ++++++-- .../GHSA-c5rm-5jj6-xh87.json | 4 +- .../GHSA-cr4f-qgfw-47cw.json | 3 +- .../GHSA-cwjp-xwrc-rmgf.json | 4 +- .../GHSA-fcqg-w4pm-f4j3.json | 4 +- .../GHSA-fp6x-mq75-x6gh.json | 2 +- .../GHSA-fr8h-82qf-8xg7.json | 4 +- .../GHSA-g5fp-9v3p-vv34.json | 4 +- .../GHSA-gc8h-qjvm-5f2g.json | 4 +- .../GHSA-h52p-q8h5-pvqj.json | 4 +- .../GHSA-j2xr-87fv-4jx3.json | 2 +- .../GHSA-mq7g-cwjx-j964.json | 3 +- .../GHSA-q5gp-c57f-33x3.json | 4 +- .../GHSA-qfqw-8w5m-fmv4.json | 15 ++++++-- .../GHSA-qjjp-gpj3-qwwr.json | 4 +- .../GHSA-qpr8-gfg5-hxvp.json | 15 ++++++-- .../GHSA-r4cp-xh3m-7m8h.json | 15 ++++++-- .../GHSA-vjjw-c569-5c3p.json | 4 +- .../GHSA-w7mf-7gmj-4jw8.json | 4 +- .../GHSA-w8gv-53r7-fph6.json | 4 +- .../GHSA-xgj7-v3ff-h29v.json | 15 ++++++-- .../GHSA-365m-6cxm-68v4.json | 11 ++++-- .../GHSA-3pgm-m73m-qrj2.json | 15 ++++++-- .../GHSA-5rhr-255q-cgmp.json | 15 ++++++-- .../GHSA-6wm8-q34j-2mc2.json | 15 ++++++-- .../GHSA-7359-388q-rq9x.json | 15 ++++++-- .../GHSA-73mq-397v-4rm9.json | 15 ++++++-- .../GHSA-76rj-9h8w-cwx9.json | 37 +++++++++++++++++++ .../GHSA-95p6-mvh4-q6jg.json | 34 +++++++++++++++++ .../GHSA-9pv9-rw6v-ggw5.json | 15 ++++++-- .../GHSA-c2vv-2vc2-cv34.json | 15 ++++++-- .../GHSA-c5rf-2f3r-9gr9.json | 36 ++++++++++++++++++ .../GHSA-cgvq-f89h-62cq.json | 2 +- .../GHSA-cmgj-xph9-cc49.json | 36 ++++++++++++++++++ .../GHSA-fwj7-p878-r668.json | 15 ++++++-- .../GHSA-gf66-v569-23vx.json | 15 ++++++-- .../GHSA-h8gw-9qqq-m7gv.json | 34 +++++++++++++++++ .../GHSA-j6vh-r2v3-c7fp.json | 11 ++++-- .../GHSA-jqmp-73q6-rjhg.json | 11 ++++-- .../GHSA-q23h-jx29-2xhg.json | 15 ++++++-- .../GHSA-qv9v-xqjc-jc7f.json | 15 ++++++-- .../GHSA-r378-wj97-j2jv.json | 11 ++++-- .../GHSA-vhj8-f69q-35j6.json | 34 +++++++++++++++++ .../GHSA-vp47-mv7q-f7h2.json | 15 ++++++-- .../GHSA-vvhj-43x9-x8ff.json | 11 ++++-- .../GHSA-w8hm-78qp-v45p.json | 15 ++++++-- .../GHSA-wgvg-989w-h74r.json | 15 ++++++-- 134 files changed, 770 insertions(+), 242 deletions(-) create mode 100644 advisories/unreviewed/2025/02/GHSA-76rj-9h8w-cwx9/GHSA-76rj-9h8w-cwx9.json create mode 100644 advisories/unreviewed/2025/02/GHSA-95p6-mvh4-q6jg/GHSA-95p6-mvh4-q6jg.json create mode 100644 advisories/unreviewed/2025/02/GHSA-c5rf-2f3r-9gr9/GHSA-c5rf-2f3r-9gr9.json create mode 100644 advisories/unreviewed/2025/02/GHSA-cmgj-xph9-cc49/GHSA-cmgj-xph9-cc49.json create mode 100644 advisories/unreviewed/2025/02/GHSA-h8gw-9qqq-m7gv/GHSA-h8gw-9qqq-m7gv.json create mode 100644 advisories/unreviewed/2025/02/GHSA-vhj8-f69q-35j6/GHSA-vhj8-f69q-35j6.json diff --git a/advisories/unreviewed/2022/05/GHSA-26v4-3ghx-vmrv/GHSA-26v4-3ghx-vmrv.json b/advisories/unreviewed/2022/05/GHSA-26v4-3ghx-vmrv/GHSA-26v4-3ghx-vmrv.json index 70aef362e58..0bca1133f4b 100644 --- a/advisories/unreviewed/2022/05/GHSA-26v4-3ghx-vmrv/GHSA-26v4-3ghx-vmrv.json +++ b/advisories/unreviewed/2022/05/GHSA-26v4-3ghx-vmrv/GHSA-26v4-3ghx-vmrv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-26v4-3ghx-vmrv", - "modified": "2022-05-17T00:20:54Z", + "modified": "2025-02-04T18:30:36Z", "published": "2022-05-17T00:20:54Z", "aliases": [ "CVE-2017-16568" diff --git a/advisories/unreviewed/2022/05/GHSA-3vmp-cf5x-w457/GHSA-3vmp-cf5x-w457.json b/advisories/unreviewed/2022/05/GHSA-3vmp-cf5x-w457/GHSA-3vmp-cf5x-w457.json index 5768f414b4d..8d8cea1df97 100644 --- a/advisories/unreviewed/2022/05/GHSA-3vmp-cf5x-w457/GHSA-3vmp-cf5x-w457.json +++ b/advisories/unreviewed/2022/05/GHSA-3vmp-cf5x-w457/GHSA-3vmp-cf5x-w457.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3vmp-cf5x-w457", - "modified": "2022-05-13T01:21:15Z", + "modified": "2025-02-04T18:30:37Z", "published": "2022-05-13T01:21:15Z", "aliases": [ "CVE-2019-0543" diff --git a/advisories/unreviewed/2022/05/GHSA-cjqq-8xv6-575p/GHSA-cjqq-8xv6-575p.json b/advisories/unreviewed/2022/05/GHSA-cjqq-8xv6-575p/GHSA-cjqq-8xv6-575p.json index 99a959582a7..2076d72d65d 100644 --- a/advisories/unreviewed/2022/05/GHSA-cjqq-8xv6-575p/GHSA-cjqq-8xv6-575p.json +++ b/advisories/unreviewed/2022/05/GHSA-cjqq-8xv6-575p/GHSA-cjqq-8xv6-575p.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cjqq-8xv6-575p", - "modified": "2022-05-13T01:10:53Z", + "modified": "2025-02-04T18:30:37Z", "published": "2022-05-13T01:10:53Z", "aliases": [ "CVE-2018-9276" diff --git a/advisories/unreviewed/2022/05/GHSA-g6xh-vmjv-c9qj/GHSA-g6xh-vmjv-c9qj.json b/advisories/unreviewed/2022/05/GHSA-g6xh-vmjv-c9qj/GHSA-g6xh-vmjv-c9qj.json index 19e2f2ee9b9..2712f1af3ce 100644 --- a/advisories/unreviewed/2022/05/GHSA-g6xh-vmjv-c9qj/GHSA-g6xh-vmjv-c9qj.json +++ b/advisories/unreviewed/2022/05/GHSA-g6xh-vmjv-c9qj/GHSA-g6xh-vmjv-c9qj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g6xh-vmjv-c9qj", - "modified": "2022-05-17T00:20:54Z", + "modified": "2025-02-04T18:30:36Z", "published": "2022-05-17T00:20:54Z", "aliases": [ "CVE-2017-16567" diff --git a/advisories/unreviewed/2022/05/GHSA-gf47-3hhj-gv96/GHSA-gf47-3hhj-gv96.json b/advisories/unreviewed/2022/05/GHSA-gf47-3hhj-gv96/GHSA-gf47-3hhj-gv96.json index b761cfa55b8..f36edfdb2af 100644 --- a/advisories/unreviewed/2022/05/GHSA-gf47-3hhj-gv96/GHSA-gf47-3hhj-gv96.json +++ b/advisories/unreviewed/2022/05/GHSA-gf47-3hhj-gv96/GHSA-gf47-3hhj-gv96.json @@ -27,7 +27,8 @@ "database_specific": { "cwe_ids": [ "CWE-119", - "CWE-681" + "CWE-681", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-hj5r-2q87-qf8g/GHSA-hj5r-2q87-qf8g.json b/advisories/unreviewed/2022/05/GHSA-hj5r-2q87-qf8g/GHSA-hj5r-2q87-qf8g.json index 45c3dfd348c..dffc3382429 100644 --- a/advisories/unreviewed/2022/05/GHSA-hj5r-2q87-qf8g/GHSA-hj5r-2q87-qf8g.json +++ b/advisories/unreviewed/2022/05/GHSA-hj5r-2q87-qf8g/GHSA-hj5r-2q87-qf8g.json @@ -1,19 +1,28 @@ { "schema_version": "1.4.0", "id": "GHSA-hj5r-2q87-qf8g", - "modified": "2022-05-24T17:34:50Z", + "modified": "2025-02-04T18:30:37Z", "published": "2022-05-24T17:34:50Z", "aliases": [ "CVE-2020-4006" ], "details": "VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-4006" }, + { + "type": "WEB", + "url": "https://www.kb.cert.org/vuls/id/724367" + }, { "type": "WEB", "url": "https://www.vmware.com/security/advisories/VMSA-2020-0027.html" @@ -21,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/05/GHSA-pm93-g4gf-j42f/GHSA-pm93-g4gf-j42f.json b/advisories/unreviewed/2022/05/GHSA-pm93-g4gf-j42f/GHSA-pm93-g4gf-j42f.json index 661d7add6d3..96a003a1a9b 100644 --- a/advisories/unreviewed/2022/05/GHSA-pm93-g4gf-j42f/GHSA-pm93-g4gf-j42f.json +++ b/advisories/unreviewed/2022/05/GHSA-pm93-g4gf-j42f/GHSA-pm93-g4gf-j42f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pm93-g4gf-j42f", - "modified": "2022-05-13T01:50:52Z", + "modified": "2025-02-04T18:30:37Z", "published": "2022-05-13T01:50:52Z", "aliases": [ "CVE-2018-19410" diff --git a/advisories/unreviewed/2022/11/GHSA-5vr9-7945-27pf/GHSA-5vr9-7945-27pf.json b/advisories/unreviewed/2022/11/GHSA-5vr9-7945-27pf/GHSA-5vr9-7945-27pf.json index 8d1b956e424..ba1d0c38d96 100644 --- a/advisories/unreviewed/2022/11/GHSA-5vr9-7945-27pf/GHSA-5vr9-7945-27pf.json +++ b/advisories/unreviewed/2022/11/GHSA-5vr9-7945-27pf/GHSA-5vr9-7945-27pf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5vr9-7945-27pf", - "modified": "2022-11-10T12:01:04Z", + "modified": "2025-02-04T18:30:38Z", "published": "2022-11-10T12:01:04Z", "aliases": [ "CVE-2022-41125" @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-787" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/04/GHSA-2rx2-wvh6-wg6m/GHSA-2rx2-wvh6-wg6m.json b/advisories/unreviewed/2023/04/GHSA-2rx2-wvh6-wg6m/GHSA-2rx2-wvh6-wg6m.json index bd33b0f4098..7fabab07bcf 100644 --- a/advisories/unreviewed/2023/04/GHSA-2rx2-wvh6-wg6m/GHSA-2rx2-wvh6-wg6m.json +++ b/advisories/unreviewed/2023/04/GHSA-2rx2-wvh6-wg6m/GHSA-2rx2-wvh6-wg6m.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-2rx2-wvh6-wg6m", - "modified": "2024-04-04T03:40:09Z", + "modified": "2025-02-04T18:30:40Z", "published": "2023-04-24T21:30:30Z", "aliases": [ "CVE-2023-2257" ], - "details": "Authentication Bypass in Hub Business integration in Devolutions Workspace Desktop 2023.1.1.3 and earlier on Windows and macOS allows an attacker with access to the user interface to unlock a Hub \nBusiness space without being prompted to enter the password via an \nunimplemented \"Force Login\" security feature.\n\nThis vulnerability occurs only if \"Force Login\" feature is enabled on the Hub Business instance and that an attacker has access to a locked Workspace desktop application configured with a Hub Business space.\n", + "details": "Authentication Bypass in Hub Business integration in Devolutions Workspace Desktop 2023.1.1.3 and earlier on Windows and macOS allows an attacker with access to the user interface to unlock a Hub \nBusiness space without being prompted to enter the password via an \nunimplemented \"Force Login\" security feature.\n\nThis vulnerability occurs only if \"Force Login\" feature is enabled on the Hub Business instance and that an attacker has access to a locked Workspace desktop application configured with a Hub Business space.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2023/04/GHSA-8wm5-mg2w-7cq3/GHSA-8wm5-mg2w-7cq3.json b/advisories/unreviewed/2023/04/GHSA-8wm5-mg2w-7cq3/GHSA-8wm5-mg2w-7cq3.json index aa22480d11d..5f057a7569c 100644 --- a/advisories/unreviewed/2023/04/GHSA-8wm5-mg2w-7cq3/GHSA-8wm5-mg2w-7cq3.json +++ b/advisories/unreviewed/2023/04/GHSA-8wm5-mg2w-7cq3/GHSA-8wm5-mg2w-7cq3.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-312" + "CWE-312", + "CWE-521" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/04/GHSA-gc9f-xmg3-m3pp/GHSA-gc9f-xmg3-m3pp.json b/advisories/unreviewed/2023/04/GHSA-gc9f-xmg3-m3pp/GHSA-gc9f-xmg3-m3pp.json index 6b714e594c6..b9762f927d0 100644 --- a/advisories/unreviewed/2023/04/GHSA-gc9f-xmg3-m3pp/GHSA-gc9f-xmg3-m3pp.json +++ b/advisories/unreviewed/2023/04/GHSA-gc9f-xmg3-m3pp/GHSA-gc9f-xmg3-m3pp.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/04/GHSA-j4vh-r4c7-fpmx/GHSA-j4vh-r4c7-fpmx.json b/advisories/unreviewed/2023/04/GHSA-j4vh-r4c7-fpmx/GHSA-j4vh-r4c7-fpmx.json index b201ddc6b46..3097861475b 100644 --- a/advisories/unreviewed/2023/04/GHSA-j4vh-r4c7-fpmx/GHSA-j4vh-r4c7-fpmx.json +++ b/advisories/unreviewed/2023/04/GHSA-j4vh-r4c7-fpmx/GHSA-j4vh-r4c7-fpmx.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-203" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/04/GHSA-qhm5-6q48-xxp4/GHSA-qhm5-6q48-xxp4.json b/advisories/unreviewed/2023/04/GHSA-qhm5-6q48-xxp4/GHSA-qhm5-6q48-xxp4.json index cefa9ef1d8e..0fa02cf68e9 100644 --- a/advisories/unreviewed/2023/04/GHSA-qhm5-6q48-xxp4/GHSA-qhm5-6q48-xxp4.json +++ b/advisories/unreviewed/2023/04/GHSA-qhm5-6q48-xxp4/GHSA-qhm5-6q48-xxp4.json @@ -30,6 +30,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-209", "CWE-755" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2023/04/GHSA-qmx9-67mw-5ghq/GHSA-qmx9-67mw-5ghq.json b/advisories/unreviewed/2023/04/GHSA-qmx9-67mw-5ghq/GHSA-qmx9-67mw-5ghq.json index 4dd8bb5f347..bb872c2183a 100644 --- a/advisories/unreviewed/2023/04/GHSA-qmx9-67mw-5ghq/GHSA-qmx9-67mw-5ghq.json +++ b/advisories/unreviewed/2023/04/GHSA-qmx9-67mw-5ghq/GHSA-qmx9-67mw-5ghq.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-770" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/04/GHSA-v8x8-32r8-5x52/GHSA-v8x8-32r8-5x52.json b/advisories/unreviewed/2023/04/GHSA-v8x8-32r8-5x52/GHSA-v8x8-32r8-5x52.json index 248308ff7f3..e2d41d9edeb 100644 --- a/advisories/unreviewed/2023/04/GHSA-v8x8-32r8-5x52/GHSA-v8x8-32r8-5x52.json +++ b/advisories/unreviewed/2023/04/GHSA-v8x8-32r8-5x52/GHSA-v8x8-32r8-5x52.json @@ -42,6 +42,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-120", "CWE-122", "CWE-787" ], diff --git a/advisories/unreviewed/2024/03/GHSA-92pj-vh86-9j44/GHSA-92pj-vh86-9j44.json b/advisories/unreviewed/2024/03/GHSA-92pj-vh86-9j44/GHSA-92pj-vh86-9j44.json index ed30cee2a64..aff982cccec 100644 --- a/advisories/unreviewed/2024/03/GHSA-92pj-vh86-9j44/GHSA-92pj-vh86-9j44.json +++ b/advisories/unreviewed/2024/03/GHSA-92pj-vh86-9j44/GHSA-92pj-vh86-9j44.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-122" + "CWE-122", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-9mq3-jxwh-fh25/GHSA-9mq3-jxwh-fh25.json b/advisories/unreviewed/2024/03/GHSA-9mq3-jxwh-fh25/GHSA-9mq3-jxwh-fh25.json index 0fe4e5627da..e58a9174766 100644 --- a/advisories/unreviewed/2024/03/GHSA-9mq3-jxwh-fh25/GHSA-9mq3-jxwh-fh25.json +++ b/advisories/unreviewed/2024/03/GHSA-9mq3-jxwh-fh25/GHSA-9mq3-jxwh-fh25.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/03/GHSA-g7r6-cg59-6p4f/GHSA-g7r6-cg59-6p4f.json b/advisories/unreviewed/2024/03/GHSA-g7r6-cg59-6p4f/GHSA-g7r6-cg59-6p4f.json index 7989e68f2f2..706511e4404 100644 --- a/advisories/unreviewed/2024/03/GHSA-g7r6-cg59-6p4f/GHSA-g7r6-cg59-6p4f.json +++ b/advisories/unreviewed/2024/03/GHSA-g7r6-cg59-6p4f/GHSA-g7r6-cg59-6p4f.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-20" + "CWE-20", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-hfm4-r5j9-2q25/GHSA-hfm4-r5j9-2q25.json b/advisories/unreviewed/2024/03/GHSA-hfm4-r5j9-2q25/GHSA-hfm4-r5j9-2q25.json index d0c3b29d089..29babb5b43e 100644 --- a/advisories/unreviewed/2024/03/GHSA-hfm4-r5j9-2q25/GHSA-hfm4-r5j9-2q25.json +++ b/advisories/unreviewed/2024/03/GHSA-hfm4-r5j9-2q25/GHSA-hfm4-r5j9-2q25.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-hfm4-r5j9-2q25", - "modified": "2024-03-27T12:30:42Z", + "modified": "2025-02-04T18:30:41Z", "published": "2024-03-27T12:30:42Z", "aliases": [ "CVE-2024-30186" ], - "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BdThemes Prime Slider – Addons For Elementor allows Stored XSS.This issue affects Prime Slider – Addons For Elementor: from n/a through 3.13.1.\n\n", + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BdThemes Prime Slider – Addons For Elementor allows Stored XSS.This issue affects Prime Slider – Addons For Elementor: from n/a through 3.13.1.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/03/GHSA-m3m6-68fj-x8xv/GHSA-m3m6-68fj-x8xv.json b/advisories/unreviewed/2024/03/GHSA-m3m6-68fj-x8xv/GHSA-m3m6-68fj-x8xv.json index 16d753e2ca2..c4e25b98458 100644 --- a/advisories/unreviewed/2024/03/GHSA-m3m6-68fj-x8xv/GHSA-m3m6-68fj-x8xv.json +++ b/advisories/unreviewed/2024/03/GHSA-m3m6-68fj-x8xv/GHSA-m3m6-68fj-x8xv.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-22", "CWE-23" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/03/GHSA-mfpg-4h2f-6hgr/GHSA-mfpg-4h2f-6hgr.json b/advisories/unreviewed/2024/03/GHSA-mfpg-4h2f-6hgr/GHSA-mfpg-4h2f-6hgr.json index e0d561f16e2..53edfcb86c8 100644 --- a/advisories/unreviewed/2024/03/GHSA-mfpg-4h2f-6hgr/GHSA-mfpg-4h2f-6hgr.json +++ b/advisories/unreviewed/2024/03/GHSA-mfpg-4h2f-6hgr/GHSA-mfpg-4h2f-6hgr.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-119" + "CWE-119", + "CWE-787" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/03/GHSA-mwpv-999v-x2vh/GHSA-mwpv-999v-x2vh.json b/advisories/unreviewed/2024/03/GHSA-mwpv-999v-x2vh/GHSA-mwpv-999v-x2vh.json index 6276624df66..9b0638cc141 100644 --- a/advisories/unreviewed/2024/03/GHSA-mwpv-999v-x2vh/GHSA-mwpv-999v-x2vh.json +++ b/advisories/unreviewed/2024/03/GHSA-mwpv-999v-x2vh/GHSA-mwpv-999v-x2vh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mwpv-999v-x2vh", - "modified": "2024-03-06T06:30:41Z", + "modified": "2025-02-04T18:30:41Z", "published": "2024-03-06T06:30:41Z", "aliases": [ "CVE-2024-1760" @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-47mh-5593-5c2x/GHSA-47mh-5593-5c2x.json b/advisories/unreviewed/2024/04/GHSA-47mh-5593-5c2x/GHSA-47mh-5593-5c2x.json index 93ce1d32338..8985dbfbb90 100644 --- a/advisories/unreviewed/2024/04/GHSA-47mh-5593-5c2x/GHSA-47mh-5593-5c2x.json +++ b/advisories/unreviewed/2024/04/GHSA-47mh-5593-5c2x/GHSA-47mh-5593-5c2x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-47mh-5593-5c2x", - "modified": "2024-04-09T21:31:59Z", + "modified": "2025-02-04T18:30:41Z", "published": "2024-04-09T21:31:59Z", "aliases": [ "CVE-2024-1948" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-68wm-4xjg-6p6m/GHSA-68wm-4xjg-6p6m.json b/advisories/unreviewed/2024/04/GHSA-68wm-4xjg-6p6m/GHSA-68wm-4xjg-6p6m.json index d0ff4bdf361..a276cb939d9 100644 --- a/advisories/unreviewed/2024/04/GHSA-68wm-4xjg-6p6m/GHSA-68wm-4xjg-6p6m.json +++ b/advisories/unreviewed/2024/04/GHSA-68wm-4xjg-6p6m/GHSA-68wm-4xjg-6p6m.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-68wm-4xjg-6p6m", - "modified": "2024-04-19T06:30:28Z", + "modified": "2025-02-04T18:30:44Z", "published": "2024-04-19T06:30:28Z", "aliases": [ "CVE-2024-29965" ], - "details": "\nIn Brocade SANnav before v2.3.1, and v2.3.0a, it is possible to back up the appliance from the web interface or the command line interface (\"SSH\"). The resulting backups are world-readable. A local attacker can recover backup files, restore them to a new malicious appliance, and retrieve the passwords of all the switches.\n\n", + "details": "In Brocade SANnav before v2.3.1, and v2.3.0a, it is possible to back up the appliance from the web interface or the command line interface (\"SSH\"). The resulting backups are world-readable. A local attacker can recover backup files, restore them to a new malicious appliance, and retrieve the passwords of all the switches.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-73xm-rcxq-249m/GHSA-73xm-rcxq-249m.json b/advisories/unreviewed/2024/04/GHSA-73xm-rcxq-249m/GHSA-73xm-rcxq-249m.json index 75875d4f90b..a96371445ba 100644 --- a/advisories/unreviewed/2024/04/GHSA-73xm-rcxq-249m/GHSA-73xm-rcxq-249m.json +++ b/advisories/unreviewed/2024/04/GHSA-73xm-rcxq-249m/GHSA-73xm-rcxq-249m.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-73xm-rcxq-249m", - "modified": "2024-04-24T15:30:34Z", + "modified": "2025-02-04T18:30:45Z", "published": "2024-04-24T15:30:34Z", "aliases": [ "CVE-2023-23989" ], - "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Metagauss RegistrationMagic.This issue affects RegistrationMagic: from n/a through 5.1.9.2.\n\n", + "details": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Metagauss RegistrationMagic.This issue affects RegistrationMagic: from n/a through 5.1.9.2.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-7jhj-m58m-cg57/GHSA-7jhj-m58m-cg57.json b/advisories/unreviewed/2024/04/GHSA-7jhj-m58m-cg57/GHSA-7jhj-m58m-cg57.json index 958a059daf6..ad4e1d51fbf 100644 --- a/advisories/unreviewed/2024/04/GHSA-7jhj-m58m-cg57/GHSA-7jhj-m58m-cg57.json +++ b/advisories/unreviewed/2024/04/GHSA-7jhj-m58m-cg57/GHSA-7jhj-m58m-cg57.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-7jhj-m58m-cg57", - "modified": "2024-04-19T06:30:28Z", + "modified": "2025-02-04T18:30:44Z", "published": "2024-04-19T06:30:28Z", "aliases": [ "CVE-2024-29966" ], - "details": "Brocade SANnav OVA before v2.3.1 and v2.3.0a contain hard-coded credentials in the documentation that appear as the appliance's root password. The vulnerability could allow an unauthenticated attacker full access to the Brocade SANnav appliance.\n\n", + "details": "Brocade SANnav OVA before v2.3.1 and v2.3.0a contain hard-coded credentials in the documentation that appear as the appliance's root password. The vulnerability could allow an unauthenticated attacker full access to the Brocade SANnav appliance.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-g3qp-jr64-m396/GHSA-g3qp-jr64-m396.json b/advisories/unreviewed/2024/04/GHSA-g3qp-jr64-m396/GHSA-g3qp-jr64-m396.json index 2a53025a033..664e7746467 100644 --- a/advisories/unreviewed/2024/04/GHSA-g3qp-jr64-m396/GHSA-g3qp-jr64-m396.json +++ b/advisories/unreviewed/2024/04/GHSA-g3qp-jr64-m396/GHSA-g3qp-jr64-m396.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-g3qp-jr64-m396", - "modified": "2024-04-18T00:30:30Z", + "modified": "2025-02-04T18:30:43Z", "published": "2024-04-18T00:30:30Z", "aliases": [ "CVE-2024-29955" ], - "details": "A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a could allow a privileged user to print the SANnav encrypted key in PostgreSQL startup logs. \nThis could provide attackers with an additional, less-protected path to acquiring the encryption key. \n\n", + "details": "A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a could allow a privileged user to print the SANnav encrypted key in PostgreSQL startup logs. \nThis could provide attackers with an additional, less-protected path to acquiring the encryption key.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-gfrg-8rq8-4fc9/GHSA-gfrg-8rq8-4fc9.json b/advisories/unreviewed/2024/04/GHSA-gfrg-8rq8-4fc9/GHSA-gfrg-8rq8-4fc9.json index 53b0bbbce04..0b220219411 100644 --- a/advisories/unreviewed/2024/04/GHSA-gfrg-8rq8-4fc9/GHSA-gfrg-8rq8-4fc9.json +++ b/advisories/unreviewed/2024/04/GHSA-gfrg-8rq8-4fc9/GHSA-gfrg-8rq8-4fc9.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-gfrg-8rq8-4fc9", - "modified": "2024-04-19T06:30:28Z", + "modified": "2025-02-04T18:30:44Z", "published": "2024-04-19T06:30:28Z", "aliases": [ "CVE-2024-29967" ], - "details": "In Brocade SANnav before Brocade SANnav v2.31 and v2.3.0a, it was observed that Docker instances inside the appliance have insecure mount points, allowing reading and writing access to sensitive files. The vulnerability could allow a sudo privileged user on the host OS to read and write access to these files. \n\n", + "details": "In Brocade SANnav before Brocade SANnav v2.31 and v2.3.0a, it was observed that Docker instances inside the appliance have insecure mount points, allowing reading and writing access to sensitive files. The vulnerability could allow a sudo privileged user on the host OS to read and write access to these files.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-jfx7-45mm-rw3j/GHSA-jfx7-45mm-rw3j.json b/advisories/unreviewed/2024/04/GHSA-jfx7-45mm-rw3j/GHSA-jfx7-45mm-rw3j.json index b3c80ea7331..3b7efa2f0e1 100644 --- a/advisories/unreviewed/2024/04/GHSA-jfx7-45mm-rw3j/GHSA-jfx7-45mm-rw3j.json +++ b/advisories/unreviewed/2024/04/GHSA-jfx7-45mm-rw3j/GHSA-jfx7-45mm-rw3j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-jfx7-45mm-rw3j", - "modified": "2024-04-09T21:32:00Z", + "modified": "2025-02-04T18:30:41Z", "published": "2024-04-09T21:32:00Z", "aliases": [ "CVE-2024-3053" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-jh6v-7wrw-4xxr/GHSA-jh6v-7wrw-4xxr.json b/advisories/unreviewed/2024/04/GHSA-jh6v-7wrw-4xxr/GHSA-jh6v-7wrw-4xxr.json index 06924fa102f..90b68d117f4 100644 --- a/advisories/unreviewed/2024/04/GHSA-jh6v-7wrw-4xxr/GHSA-jh6v-7wrw-4xxr.json +++ b/advisories/unreviewed/2024/04/GHSA-jh6v-7wrw-4xxr/GHSA-jh6v-7wrw-4xxr.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-jh6v-7wrw-4xxr", - "modified": "2024-04-19T06:30:27Z", + "modified": "2025-02-04T18:30:44Z", "published": "2024-04-19T06:30:27Z", "aliases": [ "CVE-2024-29959" ], - "details": "A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a prints Brocade Fabric OS switch encrypted passwords in the Brocade SANnav Standby node's support save.\n\n", + "details": "A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a prints Brocade Fabric OS switch encrypted passwords in the Brocade SANnav Standby node's support save.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-jw6c-wq8m-h8g9/GHSA-jw6c-wq8m-h8g9.json b/advisories/unreviewed/2024/04/GHSA-jw6c-wq8m-h8g9/GHSA-jw6c-wq8m-h8g9.json index 45ac42a4993..2319de82e66 100644 --- a/advisories/unreviewed/2024/04/GHSA-jw6c-wq8m-h8g9/GHSA-jw6c-wq8m-h8g9.json +++ b/advisories/unreviewed/2024/04/GHSA-jw6c-wq8m-h8g9/GHSA-jw6c-wq8m-h8g9.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-jw6c-wq8m-h8g9", - "modified": "2024-04-19T06:30:27Z", + "modified": "2025-02-04T18:30:44Z", "published": "2024-04-19T06:30:27Z", "aliases": [ "CVE-2024-29957" ], - "details": "When Brocade SANnav before v2.3.1 and v2.3.0a servers are configured in Disaster Recovery mode, the encryption key is stored in the DR log files. This could provide attackers with an additional, less-protected path to acquiring the encryption key.\n", + "details": "When Brocade SANnav before v2.3.1 and v2.3.0a servers are configured in Disaster Recovery mode, the encryption key is stored in the DR log files. This could provide attackers with an additional, less-protected path to acquiring the encryption key.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-jwmq-832r-8m9v/GHSA-jwmq-832r-8m9v.json b/advisories/unreviewed/2024/04/GHSA-jwmq-832r-8m9v/GHSA-jwmq-832r-8m9v.json index 34b3c18d514..20bca05e581 100644 --- a/advisories/unreviewed/2024/04/GHSA-jwmq-832r-8m9v/GHSA-jwmq-832r-8m9v.json +++ b/advisories/unreviewed/2024/04/GHSA-jwmq-832r-8m9v/GHSA-jwmq-832r-8m9v.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-jwmq-832r-8m9v", - "modified": "2024-04-22T12:30:33Z", + "modified": "2025-02-04T18:30:44Z", "published": "2024-04-22T12:30:33Z", "aliases": [ "CVE-2024-32681" ], - "details": "Missing Authorization vulnerability in BdThemes Prime Slider – Addons For Elementor.This issue affects Prime Slider – Addons For Elementor: from n/a through 3.13.2.\n\n", + "details": "Missing Authorization vulnerability in BdThemes Prime Slider – Addons For Elementor.This issue affects Prime Slider – Addons For Elementor: from n/a through 3.13.2.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-m34x-wh4m-w7q3/GHSA-m34x-wh4m-w7q3.json b/advisories/unreviewed/2024/04/GHSA-m34x-wh4m-w7q3/GHSA-m34x-wh4m-w7q3.json index 9ddef39d6f9..0ff1a943daa 100644 --- a/advisories/unreviewed/2024/04/GHSA-m34x-wh4m-w7q3/GHSA-m34x-wh4m-w7q3.json +++ b/advisories/unreviewed/2024/04/GHSA-m34x-wh4m-w7q3/GHSA-m34x-wh4m-w7q3.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-m34x-wh4m-w7q3", - "modified": "2024-04-17T21:30:46Z", + "modified": "2025-02-04T18:30:43Z", "published": "2024-04-17T21:30:46Z", "aliases": [ "CVE-2024-29950" ], - "details": "The class FileTransfer implemented in Brocade SANnav before v2.3.1, v2.3.0a, uses the ssh-rsa signature scheme, which has a SHA-1 hash.\nThe vulnerability could allow a remote, unauthenticated attacker to perform a man-in-the-middle attack.\n", + "details": "The class FileTransfer implemented in Brocade SANnav before v2.3.1, v2.3.0a, uses the ssh-rsa signature scheme, which has a SHA-1 hash.\nThe vulnerability could allow a remote, unauthenticated attacker to perform a man-in-the-middle attack.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-m8hx-m8xm-2r63/GHSA-m8hx-m8xm-2r63.json b/advisories/unreviewed/2024/04/GHSA-m8hx-m8xm-2r63/GHSA-m8hx-m8xm-2r63.json index 0fc64249741..1eb94e8fe9e 100644 --- a/advisories/unreviewed/2024/04/GHSA-m8hx-m8xm-2r63/GHSA-m8hx-m8xm-2r63.json +++ b/advisories/unreviewed/2024/04/GHSA-m8hx-m8xm-2r63/GHSA-m8hx-m8xm-2r63.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m8hx-m8xm-2r63", - "modified": "2024-04-09T21:32:00Z", + "modified": "2025-02-04T18:30:41Z", "published": "2024-04-09T21:32:00Z", "aliases": [ "CVE-2024-3213" @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-mwpf-hrvf-537f/GHSA-mwpf-hrvf-537f.json b/advisories/unreviewed/2024/04/GHSA-mwpf-hrvf-537f/GHSA-mwpf-hrvf-537f.json index f8b71900d23..af81aa4b676 100644 --- a/advisories/unreviewed/2024/04/GHSA-mwpf-hrvf-537f/GHSA-mwpf-hrvf-537f.json +++ b/advisories/unreviewed/2024/04/GHSA-mwpf-hrvf-537f/GHSA-mwpf-hrvf-537f.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-mwpf-hrvf-537f", - "modified": "2024-04-19T06:30:27Z", + "modified": "2025-02-04T18:30:44Z", "published": "2024-04-19T06:30:27Z", "aliases": [ "CVE-2024-29958" ], - "details": "A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a prints the encryption key in the console when a privileged user executes the script to replace the Brocade SANnav Management Portal standby node. This could provide attackers an additional, less protected path to acquiring the encryption key.\n", + "details": "A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a prints the encryption key in the console when a privileged user executes the script to replace the Brocade SANnav Management Portal standby node. This could provide attackers an additional, less protected path to acquiring the encryption key.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-q36g-c4c7-q48x/GHSA-q36g-c4c7-q48x.json b/advisories/unreviewed/2024/04/GHSA-q36g-c4c7-q48x/GHSA-q36g-c4c7-q48x.json index c582c4c1e5b..8c347ace975 100644 --- a/advisories/unreviewed/2024/04/GHSA-q36g-c4c7-q48x/GHSA-q36g-c4c7-q48x.json +++ b/advisories/unreviewed/2024/04/GHSA-q36g-c4c7-q48x/GHSA-q36g-c4c7-q48x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q36g-c4c7-q48x", - "modified": "2024-04-09T21:32:00Z", + "modified": "2025-02-04T18:30:41Z", "published": "2024-04-09T21:32:00Z", "aliases": [ "CVE-2024-2783" @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/04/GHSA-q59m-g738-4273/GHSA-q59m-g738-4273.json b/advisories/unreviewed/2024/04/GHSA-q59m-g738-4273/GHSA-q59m-g738-4273.json index 9236b0d6512..46e09cb8d7d 100644 --- a/advisories/unreviewed/2024/04/GHSA-q59m-g738-4273/GHSA-q59m-g738-4273.json +++ b/advisories/unreviewed/2024/04/GHSA-q59m-g738-4273/GHSA-q59m-g738-4273.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-q59m-g738-4273", - "modified": "2024-04-17T21:30:49Z", + "modified": "2025-02-04T18:30:43Z", "published": "2024-04-17T21:30:49Z", "aliases": [ "CVE-2024-29951" ], - "details": "Brocade SANnav before v2.3.1 and v2.3.0a uses the SHA-1 hash in internal SSH ports that are not open to remote connection.\n\n", + "details": "Brocade SANnav before v2.3.1 and v2.3.0a uses the SHA-1 hash in internal SSH ports that are not open to remote connection.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-qj2m-5f68-mqwf/GHSA-qj2m-5f68-mqwf.json b/advisories/unreviewed/2024/04/GHSA-qj2m-5f68-mqwf/GHSA-qj2m-5f68-mqwf.json index 5be41700ad6..2199e862655 100644 --- a/advisories/unreviewed/2024/04/GHSA-qj2m-5f68-mqwf/GHSA-qj2m-5f68-mqwf.json +++ b/advisories/unreviewed/2024/04/GHSA-qj2m-5f68-mqwf/GHSA-qj2m-5f68-mqwf.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-qj2m-5f68-mqwf", - "modified": "2024-04-22T12:30:33Z", + "modified": "2025-02-04T18:30:44Z", "published": "2024-04-22T12:30:33Z", "aliases": [ "CVE-2024-32682" ], - "details": "Missing Authorization vulnerability in BdThemes Prime Slider – Addons For Elementor.This issue affects Prime Slider – Addons For Elementor: from n/a through 3.13.2.\n\n", + "details": "Missing Authorization vulnerability in BdThemes Prime Slider – Addons For Elementor.This issue affects Prime Slider – Addons For Elementor: from n/a through 3.13.2.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-rq82-xjv7-57jq/GHSA-rq82-xjv7-57jq.json b/advisories/unreviewed/2024/04/GHSA-rq82-xjv7-57jq/GHSA-rq82-xjv7-57jq.json index 8cc3b520910..a7a447952ce 100644 --- a/advisories/unreviewed/2024/04/GHSA-rq82-xjv7-57jq/GHSA-rq82-xjv7-57jq.json +++ b/advisories/unreviewed/2024/04/GHSA-rq82-xjv7-57jq/GHSA-rq82-xjv7-57jq.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-rq82-xjv7-57jq", - "modified": "2024-04-19T06:30:27Z", + "modified": "2025-02-04T18:30:44Z", "published": "2024-04-19T06:30:27Z", "aliases": [ "CVE-2024-29963" ], - "details": "Brocade SANnav OVA before v2.3.1, and v2.3.0a, contain hardcoded keys used by Docker to reach remote registries over TLS. TLS connections with an exposed key allow an attacker to MITM the traffic. \nNote: Brocade SANnav doesn't have access to remote Docker registries.\n", + "details": "Brocade SANnav OVA before v2.3.1, and v2.3.0a, contain hardcoded keys used by Docker to reach remote registries over TLS. TLS connections with an exposed key allow an attacker to MITM the traffic. \nNote: Brocade SANnav doesn't have access to remote Docker registries.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-v2rf-m9c8-8844/GHSA-v2rf-m9c8-8844.json b/advisories/unreviewed/2024/04/GHSA-v2rf-m9c8-8844/GHSA-v2rf-m9c8-8844.json index 5fdeb0809b9..aaf0758d5d2 100644 --- a/advisories/unreviewed/2024/04/GHSA-v2rf-m9c8-8844/GHSA-v2rf-m9c8-8844.json +++ b/advisories/unreviewed/2024/04/GHSA-v2rf-m9c8-8844/GHSA-v2rf-m9c8-8844.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-v2rf-m9c8-8844", - "modified": "2024-04-19T06:30:27Z", + "modified": "2025-02-04T18:30:44Z", "published": "2024-04-19T06:30:27Z", "aliases": [ "CVE-2024-29962" ], - "details": "Brocade SANnav OVA before v2.3.1 and v2.3.0a have an insecure file permission setting that makes files world-readable. This could allow a local user without the required privileges to access sensitive information or a Java binary.\n\n", + "details": "Brocade SANnav OVA before v2.3.1 and v2.3.0a have an insecure file permission setting that makes files world-readable. This could allow a local user without the required privileges to access sensitive information or a Java binary.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-v596-2mxw-3xh7/GHSA-v596-2mxw-3xh7.json b/advisories/unreviewed/2024/04/GHSA-v596-2mxw-3xh7/GHSA-v596-2mxw-3xh7.json index 6d448dfe810..95ad2920de0 100644 --- a/advisories/unreviewed/2024/04/GHSA-v596-2mxw-3xh7/GHSA-v596-2mxw-3xh7.json +++ b/advisories/unreviewed/2024/04/GHSA-v596-2mxw-3xh7/GHSA-v596-2mxw-3xh7.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-v596-2mxw-3xh7", - "modified": "2024-04-19T06:30:29Z", + "modified": "2025-02-04T18:30:44Z", "published": "2024-04-19T06:30:29Z", "aliases": [ "CVE-2024-29969" ], - "details": "When a Brocade SANnav installation is upgraded from Brocade SANnav v2.2.2 to Brocade SANnav 2.3.0, TLS/SSL weak message authentication code ciphers are added by default for port 18082. \n\n", + "details": "When a Brocade SANnav installation is upgraded from Brocade SANnav v2.2.2 to Brocade SANnav 2.3.0, TLS/SSL weak message authentication code ciphers are added by default for port 18082.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-x2p9-2jc3-8gpp/GHSA-x2p9-2jc3-8gpp.json b/advisories/unreviewed/2024/04/GHSA-x2p9-2jc3-8gpp/GHSA-x2p9-2jc3-8gpp.json index 8e1212725c8..3a79bd684e7 100644 --- a/advisories/unreviewed/2024/04/GHSA-x2p9-2jc3-8gpp/GHSA-x2p9-2jc3-8gpp.json +++ b/advisories/unreviewed/2024/04/GHSA-x2p9-2jc3-8gpp/GHSA-x2p9-2jc3-8gpp.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-384", "CWE-400" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/04/GHSA-x8vj-x24h-rrfv/GHSA-x8vj-x24h-rrfv.json b/advisories/unreviewed/2024/04/GHSA-x8vj-x24h-rrfv/GHSA-x8vj-x24h-rrfv.json index 475d56972d0..df2f7aef42b 100644 --- a/advisories/unreviewed/2024/04/GHSA-x8vj-x24h-rrfv/GHSA-x8vj-x24h-rrfv.json +++ b/advisories/unreviewed/2024/04/GHSA-x8vj-x24h-rrfv/GHSA-x8vj-x24h-rrfv.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-x8vj-x24h-rrfv", - "modified": "2024-04-24T12:30:42Z", + "modified": "2025-02-04T18:30:45Z", "published": "2024-04-24T12:30:42Z", "aliases": [ "CVE-2024-32808" ], - "details": "Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.9.\n\n", + "details": "Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.9.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-xcp9-jx79-m233/GHSA-xcp9-jx79-m233.json b/advisories/unreviewed/2024/04/GHSA-xcp9-jx79-m233/GHSA-xcp9-jx79-m233.json index 3b2d8fae79e..63db7edd7b7 100644 --- a/advisories/unreviewed/2024/04/GHSA-xcp9-jx79-m233/GHSA-xcp9-jx79-m233.json +++ b/advisories/unreviewed/2024/04/GHSA-xcp9-jx79-m233/GHSA-xcp9-jx79-m233.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-xcp9-jx79-m233", - "modified": "2024-04-19T06:30:27Z", + "modified": "2025-02-04T18:30:44Z", "published": "2024-04-19T06:30:27Z", "aliases": [ "CVE-2024-29960" ], - "details": "In the Brocade SANnav server versions before v2.3.1 and v2.3.0a, the SSH keys inside the OVA image are hardcoded and identical in the VM every time SANnav is installed. Any Brocade SANnav VM based on the official OVA images is vulnerable to MITM over SSH. An attacker can decrypt and compromise the SSH traffic to the SANnav appliance.\n\n", + "details": "In the Brocade SANnav server versions before v2.3.1 and v2.3.0a, the SSH keys inside the OVA image are hardcoded and identical in the VM every time SANnav is installed. Any Brocade SANnav VM based on the official OVA images is vulnerable to MITM over SSH. An attacker can decrypt and compromise the SSH traffic to the SANnav appliance.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-xp2p-9wq2-wx5q/GHSA-xp2p-9wq2-wx5q.json b/advisories/unreviewed/2024/04/GHSA-xp2p-9wq2-wx5q/GHSA-xp2p-9wq2-wx5q.json index b03d1dc341e..f5c1f0852ae 100644 --- a/advisories/unreviewed/2024/04/GHSA-xp2p-9wq2-wx5q/GHSA-xp2p-9wq2-wx5q.json +++ b/advisories/unreviewed/2024/04/GHSA-xp2p-9wq2-wx5q/GHSA-xp2p-9wq2-wx5q.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-xp2p-9wq2-wx5q", - "modified": "2024-04-18T03:30:45Z", + "modified": "2025-02-04T18:30:44Z", "published": "2024-04-18T03:30:45Z", "aliases": [ "CVE-2024-29956" ], - "details": "A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a prints the Brocade SANnav password in clear text in supportsave logs when a user schedules a switch Supportsave from Brocade SANnav.\n\n", + "details": "A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a prints the Brocade SANnav password in clear text in supportsave logs when a user schedules a switch Supportsave from Brocade SANnav.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-xrr4-j32g-hj8m/GHSA-xrr4-j32g-hj8m.json b/advisories/unreviewed/2024/04/GHSA-xrr4-j32g-hj8m/GHSA-xrr4-j32g-hj8m.json index 53633a7ee07..51c5b1e2249 100644 --- a/advisories/unreviewed/2024/04/GHSA-xrr4-j32g-hj8m/GHSA-xrr4-j32g-hj8m.json +++ b/advisories/unreviewed/2024/04/GHSA-xrr4-j32g-hj8m/GHSA-xrr4-j32g-hj8m.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-xrr4-j32g-hj8m", - "modified": "2024-04-18T00:30:30Z", + "modified": "2025-02-04T18:30:43Z", "published": "2024-04-18T00:30:30Z", "aliases": [ "CVE-2024-29952" ], - "details": "A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a could allow an authenticated user to print the Auth, Priv, and SSL key store passwords in unencrypted logs by manipulating command variables.\n\n", + "details": "A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a could allow an authenticated user to print the Auth, Priv, and SSL key store passwords in unencrypted logs by manipulating command variables.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/04/GHSA-xvrf-3569-2x76/GHSA-xvrf-3569-2x76.json b/advisories/unreviewed/2024/04/GHSA-xvrf-3569-2x76/GHSA-xvrf-3569-2x76.json index b42c10ad5ff..1d6c4de930d 100644 --- a/advisories/unreviewed/2024/04/GHSA-xvrf-3569-2x76/GHSA-xvrf-3569-2x76.json +++ b/advisories/unreviewed/2024/04/GHSA-xvrf-3569-2x76/GHSA-xvrf-3569-2x76.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-xvrf-3569-2x76", - "modified": "2024-04-24T12:30:42Z", + "modified": "2025-02-04T18:30:45Z", "published": "2024-04-24T12:30:42Z", "aliases": [ "CVE-2024-32772" ], - "details": "Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.9.\n\n", + "details": "Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.9.", "severity": [ { "type": "CVSS_V3", diff --git a/advisories/unreviewed/2024/05/GHSA-2244-w4gj-c9vv/GHSA-2244-w4gj-c9vv.json b/advisories/unreviewed/2024/05/GHSA-2244-w4gj-c9vv/GHSA-2244-w4gj-c9vv.json index c49ca8198ee..3bb57e51b8d 100644 --- a/advisories/unreviewed/2024/05/GHSA-2244-w4gj-c9vv/GHSA-2244-w4gj-c9vv.json +++ b/advisories/unreviewed/2024/05/GHSA-2244-w4gj-c9vv/GHSA-2244-w4gj-c9vv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-2244-w4gj-c9vv", - "modified": "2024-05-02T18:30:54Z", + "modified": "2025-02-04T18:30:45Z", "published": "2024-05-02T18:30:54Z", "aliases": [ "CVE-2024-3550" @@ -45,7 +45,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-48cf-pw67-hg9m/GHSA-48cf-pw67-hg9m.json b/advisories/unreviewed/2024/05/GHSA-48cf-pw67-hg9m/GHSA-48cf-pw67-hg9m.json index ab6820b61c3..ca1f0983403 100644 --- a/advisories/unreviewed/2024/05/GHSA-48cf-pw67-hg9m/GHSA-48cf-pw67-hg9m.json +++ b/advisories/unreviewed/2024/05/GHSA-48cf-pw67-hg9m/GHSA-48cf-pw67-hg9m.json @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-829x-599p-43vg/GHSA-829x-599p-43vg.json b/advisories/unreviewed/2024/05/GHSA-829x-599p-43vg/GHSA-829x-599p-43vg.json index 8e4bc84855b..6511711c440 100644 --- a/advisories/unreviewed/2024/05/GHSA-829x-599p-43vg/GHSA-829x-599p-43vg.json +++ b/advisories/unreviewed/2024/05/GHSA-829x-599p-43vg/GHSA-829x-599p-43vg.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-862" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/05/GHSA-mg73-mvvv-5f9h/GHSA-mg73-mvvv-5f9h.json b/advisories/unreviewed/2024/05/GHSA-mg73-mvvv-5f9h/GHSA-mg73-mvvv-5f9h.json index 612b1e6ba05..2c7282210e4 100644 --- a/advisories/unreviewed/2024/05/GHSA-mg73-mvvv-5f9h/GHSA-mg73-mvvv-5f9h.json +++ b/advisories/unreviewed/2024/05/GHSA-mg73-mvvv-5f9h/GHSA-mg73-mvvv-5f9h.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-pj7c-pvg3-fjr7/GHSA-pj7c-pvg3-fjr7.json b/advisories/unreviewed/2024/05/GHSA-pj7c-pvg3-fjr7/GHSA-pj7c-pvg3-fjr7.json index 852cd4736c4..26b5558e5f9 100644 --- a/advisories/unreviewed/2024/05/GHSA-pj7c-pvg3-fjr7/GHSA-pj7c-pvg3-fjr7.json +++ b/advisories/unreviewed/2024/05/GHSA-pj7c-pvg3-fjr7/GHSA-pj7c-pvg3-fjr7.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pj7c-pvg3-fjr7", - "modified": "2024-05-02T18:30:54Z", + "modified": "2025-02-04T18:30:45Z", "published": "2024-05-02T18:30:54Z", "aliases": [ "CVE-2024-3588" @@ -37,7 +37,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-rrh3-c47h-2239/GHSA-rrh3-c47h-2239.json b/advisories/unreviewed/2024/05/GHSA-rrh3-c47h-2239/GHSA-rrh3-c47h-2239.json index 5ee55e38671..2f3b742d25b 100644 --- a/advisories/unreviewed/2024/05/GHSA-rrh3-c47h-2239/GHSA-rrh3-c47h-2239.json +++ b/advisories/unreviewed/2024/05/GHSA-rrh3-c47h-2239/GHSA-rrh3-c47h-2239.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/05/GHSA-xcf2-9gfx-5x8f/GHSA-xcf2-9gfx-5x8f.json b/advisories/unreviewed/2024/05/GHSA-xcf2-9gfx-5x8f/GHSA-xcf2-9gfx-5x8f.json index 99342f9d1dc..0b69fc69fc6 100644 --- a/advisories/unreviewed/2024/05/GHSA-xcf2-9gfx-5x8f/GHSA-xcf2-9gfx-5x8f.json +++ b/advisories/unreviewed/2024/05/GHSA-xcf2-9gfx-5x8f/GHSA-xcf2-9gfx-5x8f.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-9533-j5r3-r25x/GHSA-9533-j5r3-r25x.json b/advisories/unreviewed/2024/06/GHSA-9533-j5r3-r25x/GHSA-9533-j5r3-r25x.json index bb5efaa5809..2d62a1d3bd2 100644 --- a/advisories/unreviewed/2024/06/GHSA-9533-j5r3-r25x/GHSA-9533-j5r3-r25x.json +++ b/advisories/unreviewed/2024/06/GHSA-9533-j5r3-r25x/GHSA-9533-j5r3-r25x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9533-j5r3-r25x", - "modified": "2024-06-20T12:31:20Z", + "modified": "2025-02-04T18:30:46Z", "published": "2024-06-20T12:31:20Z", "aliases": [ "CVE-2024-5036" @@ -33,7 +33,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/06/GHSA-c8f3-gj35-46cf/GHSA-c8f3-gj35-46cf.json b/advisories/unreviewed/2024/06/GHSA-c8f3-gj35-46cf/GHSA-c8f3-gj35-46cf.json index 8793e2b7116..5f33169f53c 100644 --- a/advisories/unreviewed/2024/06/GHSA-c8f3-gj35-46cf/GHSA-c8f3-gj35-46cf.json +++ b/advisories/unreviewed/2024/06/GHSA-c8f3-gj35-46cf/GHSA-c8f3-gj35-46cf.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-697", "CWE-942" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/07/GHSA-3x6q-q5jm-q33x/GHSA-3x6q-q5jm-q33x.json b/advisories/unreviewed/2024/07/GHSA-3x6q-q5jm-q33x/GHSA-3x6q-q5jm-q33x.json index a4c2ae22d12..7b2aa22e89b 100644 --- a/advisories/unreviewed/2024/07/GHSA-3x6q-q5jm-q33x/GHSA-3x6q-q5jm-q33x.json +++ b/advisories/unreviewed/2024/07/GHSA-3x6q-q5jm-q33x/GHSA-3x6q-q5jm-q33x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3x6q-q5jm-q33x", - "modified": "2024-07-20T09:30:34Z", + "modified": "2025-02-04T18:30:46Z", "published": "2024-07-20T09:30:34Z", "aliases": [ "CVE-2024-6489" diff --git a/advisories/unreviewed/2024/07/GHSA-7h9v-398p-wh5c/GHSA-7h9v-398p-wh5c.json b/advisories/unreviewed/2024/07/GHSA-7h9v-398p-wh5c/GHSA-7h9v-398p-wh5c.json index 875d664773e..acc4a446be5 100644 --- a/advisories/unreviewed/2024/07/GHSA-7h9v-398p-wh5c/GHSA-7h9v-398p-wh5c.json +++ b/advisories/unreviewed/2024/07/GHSA-7h9v-398p-wh5c/GHSA-7h9v-398p-wh5c.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7h9v-398p-wh5c", - "modified": "2024-07-02T09:32:07Z", + "modified": "2025-02-04T18:30:46Z", "published": "2024-07-02T09:32:07Z", "aliases": [ "CVE-2024-5260" @@ -41,7 +41,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-xfrr-5gq4-4j32/GHSA-xfrr-5gq4-4j32.json b/advisories/unreviewed/2024/07/GHSA-xfrr-5gq4-4j32/GHSA-xfrr-5gq4-4j32.json index f1d909663e4..92915bd0992 100644 --- a/advisories/unreviewed/2024/07/GHSA-xfrr-5gq4-4j32/GHSA-xfrr-5gq4-4j32.json +++ b/advisories/unreviewed/2024/07/GHSA-xfrr-5gq4-4j32/GHSA-xfrr-5gq4-4j32.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xfrr-5gq4-4j32", - "modified": "2024-07-20T09:30:34Z", + "modified": "2025-02-04T18:30:46Z", "published": "2024-07-20T09:30:34Z", "aliases": [ "CVE-2024-6491" diff --git a/advisories/unreviewed/2024/11/GHSA-43fc-fqg5-m549/GHSA-43fc-fqg5-m549.json b/advisories/unreviewed/2024/11/GHSA-43fc-fqg5-m549/GHSA-43fc-fqg5-m549.json index 2c253f595c1..57bd2855a8f 100644 --- a/advisories/unreviewed/2024/11/GHSA-43fc-fqg5-m549/GHSA-43fc-fqg5-m549.json +++ b/advisories/unreviewed/2024/11/GHSA-43fc-fqg5-m549/GHSA-43fc-fqg5-m549.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-43fc-fqg5-m549", - "modified": "2024-11-19T12:31:04Z", + "modified": "2025-02-04T18:30:46Z", "published": "2024-11-19T12:31:04Z", "aliases": [ "CVE-2024-11036" diff --git a/advisories/unreviewed/2024/11/GHSA-5pg9-rxpc-jxgf/GHSA-5pg9-rxpc-jxgf.json b/advisories/unreviewed/2024/11/GHSA-5pg9-rxpc-jxgf/GHSA-5pg9-rxpc-jxgf.json index 0c47cea6c2a..0cc2f050224 100644 --- a/advisories/unreviewed/2024/11/GHSA-5pg9-rxpc-jxgf/GHSA-5pg9-rxpc-jxgf.json +++ b/advisories/unreviewed/2024/11/GHSA-5pg9-rxpc-jxgf/GHSA-5pg9-rxpc-jxgf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5pg9-rxpc-jxgf", - "modified": "2024-11-12T15:30:43Z", + "modified": "2025-02-04T18:30:46Z", "published": "2024-11-12T15:30:43Z", "aliases": [ "CVE-2024-50386" @@ -30,6 +30,10 @@ { "type": "WEB", "url": "https://www.shapeblue.com/shapeblue-security-advisory-apache-cloudstack-security-releases-4-18-2-5-and-4-19-1-3" + }, + { + "type": "WEB", + "url": "http://www.openwall.com/lists/oss-security/2024/11/12/3" } ], "database_specific": { diff --git a/advisories/unreviewed/2024/11/GHSA-j34c-54rj-94x3/GHSA-j34c-54rj-94x3.json b/advisories/unreviewed/2024/11/GHSA-j34c-54rj-94x3/GHSA-j34c-54rj-94x3.json index 3db93b7fcba..30667a8ff77 100644 --- a/advisories/unreviewed/2024/11/GHSA-j34c-54rj-94x3/GHSA-j34c-54rj-94x3.json +++ b/advisories/unreviewed/2024/11/GHSA-j34c-54rj-94x3/GHSA-j34c-54rj-94x3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j34c-54rj-94x3", - "modified": "2024-11-18T09:31:13Z", + "modified": "2025-02-04T18:30:46Z", "published": "2024-11-18T09:31:13Z", "aliases": [ "CVE-2024-41967" diff --git a/advisories/unreviewed/2024/11/GHSA-mfgc-pq48-8r3j/GHSA-mfgc-pq48-8r3j.json b/advisories/unreviewed/2024/11/GHSA-mfgc-pq48-8r3j/GHSA-mfgc-pq48-8r3j.json index 0225ad8984c..68d22d2cec4 100644 --- a/advisories/unreviewed/2024/11/GHSA-mfgc-pq48-8r3j/GHSA-mfgc-pq48-8r3j.json +++ b/advisories/unreviewed/2024/11/GHSA-mfgc-pq48-8r3j/GHSA-mfgc-pq48-8r3j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mfgc-pq48-8r3j", - "modified": "2024-11-18T12:30:41Z", + "modified": "2025-02-04T18:30:46Z", "published": "2024-11-18T12:30:41Z", "aliases": [ "CVE-2024-41970" diff --git a/advisories/unreviewed/2024/11/GHSA-x3rw-xr73-fq7h/GHSA-x3rw-xr73-fq7h.json b/advisories/unreviewed/2024/11/GHSA-x3rw-xr73-fq7h/GHSA-x3rw-xr73-fq7h.json index 9804d96083d..f39169aca3a 100644 --- a/advisories/unreviewed/2024/11/GHSA-x3rw-xr73-fq7h/GHSA-x3rw-xr73-fq7h.json +++ b/advisories/unreviewed/2024/11/GHSA-x3rw-xr73-fq7h/GHSA-x3rw-xr73-fq7h.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-277" + "CWE-277", + "CWE-732" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-294c-hx25-mgvq/GHSA-294c-hx25-mgvq.json b/advisories/unreviewed/2024/12/GHSA-294c-hx25-mgvq/GHSA-294c-hx25-mgvq.json index 906bccfc41c..e13314fcee4 100644 --- a/advisories/unreviewed/2024/12/GHSA-294c-hx25-mgvq/GHSA-294c-hx25-mgvq.json +++ b/advisories/unreviewed/2024/12/GHSA-294c-hx25-mgvq/GHSA-294c-hx25-mgvq.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-798" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/12/GHSA-3mp2-rhvg-j63c/GHSA-3mp2-rhvg-j63c.json b/advisories/unreviewed/2024/12/GHSA-3mp2-rhvg-j63c/GHSA-3mp2-rhvg-j63c.json index 0f42e9cadec..9147ce30ea3 100644 --- a/advisories/unreviewed/2024/12/GHSA-3mp2-rhvg-j63c/GHSA-3mp2-rhvg-j63c.json +++ b/advisories/unreviewed/2024/12/GHSA-3mp2-rhvg-j63c/GHSA-3mp2-rhvg-j63c.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-11" + "CWE-11", + "CWE-78" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-6m5p-mv69-2wfh/GHSA-6m5p-mv69-2wfh.json b/advisories/unreviewed/2024/12/GHSA-6m5p-mv69-2wfh/GHSA-6m5p-mv69-2wfh.json index 61c7b4a2402..0dc88628f96 100644 --- a/advisories/unreviewed/2024/12/GHSA-6m5p-mv69-2wfh/GHSA-6m5p-mv69-2wfh.json +++ b/advisories/unreviewed/2024/12/GHSA-6m5p-mv69-2wfh/GHSA-6m5p-mv69-2wfh.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-59", "CWE-61" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/12/GHSA-72fc-7pff-vv9c/GHSA-72fc-7pff-vv9c.json b/advisories/unreviewed/2024/12/GHSA-72fc-7pff-vv9c/GHSA-72fc-7pff-vv9c.json index 3d24f71d7e8..c2fe60236d8 100644 --- a/advisories/unreviewed/2024/12/GHSA-72fc-7pff-vv9c/GHSA-72fc-7pff-vv9c.json +++ b/advisories/unreviewed/2024/12/GHSA-72fc-7pff-vv9c/GHSA-72fc-7pff-vv9c.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-59", "CWE-61" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/12/GHSA-86jp-9fvq-qr9r/GHSA-86jp-9fvq-qr9r.json b/advisories/unreviewed/2024/12/GHSA-86jp-9fvq-qr9r/GHSA-86jp-9fvq-qr9r.json index d22ccc5c407..418bea0a9b9 100644 --- a/advisories/unreviewed/2024/12/GHSA-86jp-9fvq-qr9r/GHSA-86jp-9fvq-qr9r.json +++ b/advisories/unreviewed/2024/12/GHSA-86jp-9fvq-qr9r/GHSA-86jp-9fvq-qr9r.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-59", "CWE-61" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/12/GHSA-cxvp-2gqq-8958/GHSA-cxvp-2gqq-8958.json b/advisories/unreviewed/2024/12/GHSA-cxvp-2gqq-8958/GHSA-cxvp-2gqq-8958.json index 29409af7a3b..6eda310667b 100644 --- a/advisories/unreviewed/2024/12/GHSA-cxvp-2gqq-8958/GHSA-cxvp-2gqq-8958.json +++ b/advisories/unreviewed/2024/12/GHSA-cxvp-2gqq-8958/GHSA-cxvp-2gqq-8958.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-256" + "CWE-256", + "CWE-522" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-pg94-fqwx-cjcv/GHSA-pg94-fqwx-cjcv.json b/advisories/unreviewed/2024/12/GHSA-pg94-fqwx-cjcv/GHSA-pg94-fqwx-cjcv.json index 1571d77bdf0..c92ff4c6b58 100644 --- a/advisories/unreviewed/2024/12/GHSA-pg94-fqwx-cjcv/GHSA-pg94-fqwx-cjcv.json +++ b/advisories/unreviewed/2024/12/GHSA-pg94-fqwx-cjcv/GHSA-pg94-fqwx-cjcv.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-347" + "CWE-347", + "CWE-78" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-2hmh-wh7q-6wpr/GHSA-2hmh-wh7q-6wpr.json b/advisories/unreviewed/2025/01/GHSA-2hmh-wh7q-6wpr/GHSA-2hmh-wh7q-6wpr.json index 54eac682ece..7140dd93b08 100644 --- a/advisories/unreviewed/2025/01/GHSA-2hmh-wh7q-6wpr/GHSA-2hmh-wh7q-6wpr.json +++ b/advisories/unreviewed/2025/01/GHSA-2hmh-wh7q-6wpr/GHSA-2hmh-wh7q-6wpr.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-35v7-q7c2-qg94/GHSA-35v7-q7c2-qg94.json b/advisories/unreviewed/2025/01/GHSA-35v7-q7c2-qg94/GHSA-35v7-q7c2-qg94.json index 85e01c8aedd..5c24d4022d6 100644 --- a/advisories/unreviewed/2025/01/GHSA-35v7-q7c2-qg94/GHSA-35v7-q7c2-qg94.json +++ b/advisories/unreviewed/2025/01/GHSA-35v7-q7c2-qg94/GHSA-35v7-q7c2-qg94.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-3647-958p-fpph/GHSA-3647-958p-fpph.json b/advisories/unreviewed/2025/01/GHSA-3647-958p-fpph/GHSA-3647-958p-fpph.json index cb3a3d5d0e9..5a70372a9bd 100644 --- a/advisories/unreviewed/2025/01/GHSA-3647-958p-fpph/GHSA-3647-958p-fpph.json +++ b/advisories/unreviewed/2025/01/GHSA-3647-958p-fpph/GHSA-3647-958p-fpph.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-4qxc-98vx-fp5g/GHSA-4qxc-98vx-fp5g.json b/advisories/unreviewed/2025/01/GHSA-4qxc-98vx-fp5g/GHSA-4qxc-98vx-fp5g.json index f2e3908602b..bf570e736a7 100644 --- a/advisories/unreviewed/2025/01/GHSA-4qxc-98vx-fp5g/GHSA-4qxc-98vx-fp5g.json +++ b/advisories/unreviewed/2025/01/GHSA-4qxc-98vx-fp5g/GHSA-4qxc-98vx-fp5g.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-4x4h-rvfw-x95m/GHSA-4x4h-rvfw-x95m.json b/advisories/unreviewed/2025/01/GHSA-4x4h-rvfw-x95m/GHSA-4x4h-rvfw-x95m.json index d9f71ff11aa..e4e4b6f4aa3 100644 --- a/advisories/unreviewed/2025/01/GHSA-4x4h-rvfw-x95m/GHSA-4x4h-rvfw-x95m.json +++ b/advisories/unreviewed/2025/01/GHSA-4x4h-rvfw-x95m/GHSA-4x4h-rvfw-x95m.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-732" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-5558-mmq3-572w/GHSA-5558-mmq3-572w.json b/advisories/unreviewed/2025/01/GHSA-5558-mmq3-572w/GHSA-5558-mmq3-572w.json index ae3138fb3cb..b1d5f35c4b2 100644 --- a/advisories/unreviewed/2025/01/GHSA-5558-mmq3-572w/GHSA-5558-mmq3-572w.json +++ b/advisories/unreviewed/2025/01/GHSA-5558-mmq3-572w/GHSA-5558-mmq3-572w.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-5fj8-p786-m6j9/GHSA-5fj8-p786-m6j9.json b/advisories/unreviewed/2025/01/GHSA-5fj8-p786-m6j9/GHSA-5fj8-p786-m6j9.json index a119f411d7c..c5caf4477db 100644 --- a/advisories/unreviewed/2025/01/GHSA-5fj8-p786-m6j9/GHSA-5fj8-p786-m6j9.json +++ b/advisories/unreviewed/2025/01/GHSA-5fj8-p786-m6j9/GHSA-5fj8-p786-m6j9.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-5qfx-xmmx-f9c7/GHSA-5qfx-xmmx-f9c7.json b/advisories/unreviewed/2025/01/GHSA-5qfx-xmmx-f9c7/GHSA-5qfx-xmmx-f9c7.json index 19e1d6c030e..cf18c16fc5a 100644 --- a/advisories/unreviewed/2025/01/GHSA-5qfx-xmmx-f9c7/GHSA-5qfx-xmmx-f9c7.json +++ b/advisories/unreviewed/2025/01/GHSA-5qfx-xmmx-f9c7/GHSA-5qfx-xmmx-f9c7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5qfx-xmmx-f9c7", - "modified": "2025-01-21T21:30:54Z", + "modified": "2025-02-04T18:30:47Z", "published": "2025-01-21T21:30:54Z", "aliases": [ "CVE-2024-57538" ], "details": "Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (anonymous_protect_status) is copied to the stack without length verification.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-21T21:15:11Z" diff --git a/advisories/unreviewed/2025/01/GHSA-6v8w-mg2j-7jw3/GHSA-6v8w-mg2j-7jw3.json b/advisories/unreviewed/2025/01/GHSA-6v8w-mg2j-7jw3/GHSA-6v8w-mg2j-7jw3.json index b13d729e0e3..b899abcf1e2 100644 --- a/advisories/unreviewed/2025/01/GHSA-6v8w-mg2j-7jw3/GHSA-6v8w-mg2j-7jw3.json +++ b/advisories/unreviewed/2025/01/GHSA-6v8w-mg2j-7jw3/GHSA-6v8w-mg2j-7jw3.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6v8w-mg2j-7jw3", - "modified": "2025-01-21T21:30:54Z", + "modified": "2025-02-04T18:30:47Z", "published": "2025-01-21T21:30:54Z", "aliases": [ "CVE-2024-57540" ], "details": "Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (action) is copied to the stack without length verification.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-21T21:15:12Z" diff --git a/advisories/unreviewed/2025/01/GHSA-6wcx-2p4q-557w/GHSA-6wcx-2p4q-557w.json b/advisories/unreviewed/2025/01/GHSA-6wcx-2p4q-557w/GHSA-6wcx-2p4q-557w.json index f980bcfd157..eb321ec2b3a 100644 --- a/advisories/unreviewed/2025/01/GHSA-6wcx-2p4q-557w/GHSA-6wcx-2p4q-557w.json +++ b/advisories/unreviewed/2025/01/GHSA-6wcx-2p4q-557w/GHSA-6wcx-2p4q-557w.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6wcx-2p4q-557w", - "modified": "2025-01-21T21:30:54Z", + "modified": "2025-02-04T18:30:47Z", "published": "2025-01-21T21:30:54Z", "aliases": [ "CVE-2024-57539" ], "details": "Linksys E8450 v1.2.00.360516 was discovered to contain a command injection vulnerability via userEmail.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-77" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-21T21:15:11Z" diff --git a/advisories/unreviewed/2025/01/GHSA-7792-f3h4-qxjq/GHSA-7792-f3h4-qxjq.json b/advisories/unreviewed/2025/01/GHSA-7792-f3h4-qxjq/GHSA-7792-f3h4-qxjq.json index 75246bca0e9..5ca9b9ab74c 100644 --- a/advisories/unreviewed/2025/01/GHSA-7792-f3h4-qxjq/GHSA-7792-f3h4-qxjq.json +++ b/advisories/unreviewed/2025/01/GHSA-7792-f3h4-qxjq/GHSA-7792-f3h4-qxjq.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7792-f3h4-qxjq", - "modified": "2025-01-31T12:33:02Z", + "modified": "2025-02-04T18:30:47Z", "published": "2025-01-31T12:33:02Z", "aliases": [ "CVE-2025-21671" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nzram: fix potential UAF of zram table\n\nIf zram_meta_alloc failed early, it frees allocated zram->table without\nsetting it NULL. Which will potentially cause zram_meta_free to access\nthe table if user reset an failed and uninitialized device.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-31T12:15:28Z" diff --git a/advisories/unreviewed/2025/01/GHSA-7hhm-hgmx-pp76/GHSA-7hhm-hgmx-pp76.json b/advisories/unreviewed/2025/01/GHSA-7hhm-hgmx-pp76/GHSA-7hhm-hgmx-pp76.json index dd0de339aab..5f18626f336 100644 --- a/advisories/unreviewed/2025/01/GHSA-7hhm-hgmx-pp76/GHSA-7hhm-hgmx-pp76.json +++ b/advisories/unreviewed/2025/01/GHSA-7hhm-hgmx-pp76/GHSA-7hhm-hgmx-pp76.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7hhm-hgmx-pp76", - "modified": "2025-02-02T12:30:25Z", + "modified": "2025-02-04T18:30:47Z", "published": "2025-01-31T12:33:02Z", "aliases": [ "CVE-2025-21669" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvsock/virtio: discard packets if the transport changes\n\nIf the socket has been de-assigned or assigned to another transport,\nwe must discard any packets received because they are not expected\nand would cause issues when we access vsk->transport.\n\nA possible scenario is described by Hyunwoo Kim in the attached link,\nwhere after a first connect() interrupted by a signal, and a second\nconnect() failed, we can find `vsk->transport` at NULL, leading to a\nNULL pointer dereference.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -40,8 +45,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-31T12:15:28Z" diff --git a/advisories/unreviewed/2025/01/GHSA-86hg-w33q-7372/GHSA-86hg-w33q-7372.json b/advisories/unreviewed/2025/01/GHSA-86hg-w33q-7372/GHSA-86hg-w33q-7372.json index c6b6c044cbd..4d2045ba738 100644 --- a/advisories/unreviewed/2025/01/GHSA-86hg-w33q-7372/GHSA-86hg-w33q-7372.json +++ b/advisories/unreviewed/2025/01/GHSA-86hg-w33q-7372/GHSA-86hg-w33q-7372.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-86hg-w33q-7372", - "modified": "2025-01-21T21:30:53Z", + "modified": "2025-02-04T18:30:47Z", "published": "2025-01-21T21:30:53Z", "aliases": [ "CVE-2024-55504" ], "details": "An issue in RAR Extractor - Unarchiver Free and Pro v.6.4.0 allows local attackers to inject arbitrary code potentially leading to remote control and unauthorized access to sensitive user data via the exploit_combined.dylib component on MacOS.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-21T19:15:11Z" diff --git a/advisories/unreviewed/2025/01/GHSA-8qrr-cpmw-jq92/GHSA-8qrr-cpmw-jq92.json b/advisories/unreviewed/2025/01/GHSA-8qrr-cpmw-jq92/GHSA-8qrr-cpmw-jq92.json index fdf370830f1..35f7f1dc291 100644 --- a/advisories/unreviewed/2025/01/GHSA-8qrr-cpmw-jq92/GHSA-8qrr-cpmw-jq92.json +++ b/advisories/unreviewed/2025/01/GHSA-8qrr-cpmw-jq92/GHSA-8qrr-cpmw-jq92.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8qrr-cpmw-jq92", - "modified": "2025-01-17T15:32:33Z", + "modified": "2025-02-04T18:30:47Z", "published": "2025-01-17T15:32:33Z", "aliases": [ "CVE-2024-50967" ], "details": "The /rest/rights/ REST API endpoint in Becon DATAGerry through 2.2.0 contains an Incorrect Access Control vulnerability. An attacker can remotely access this endpoint without authentication, leading to unauthorized disclosure of sensitive information.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-862" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-17T15:15:12Z" diff --git a/advisories/unreviewed/2025/01/GHSA-8x43-6vm2-j847/GHSA-8x43-6vm2-j847.json b/advisories/unreviewed/2025/01/GHSA-8x43-6vm2-j847/GHSA-8x43-6vm2-j847.json index 0a7431d9a2b..c906d04ade1 100644 --- a/advisories/unreviewed/2025/01/GHSA-8x43-6vm2-j847/GHSA-8x43-6vm2-j847.json +++ b/advisories/unreviewed/2025/01/GHSA-8x43-6vm2-j847/GHSA-8x43-6vm2-j847.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-8x43-6vm2-j847", - "modified": "2025-01-25T09:30:54Z", + "modified": "2025-02-04T18:30:47Z", "published": "2025-01-25T09:30:54Z", "aliases": [ "CVE-2024-13599" diff --git a/advisories/unreviewed/2025/01/GHSA-9v8h-2rmp-52m8/GHSA-9v8h-2rmp-52m8.json b/advisories/unreviewed/2025/01/GHSA-9v8h-2rmp-52m8/GHSA-9v8h-2rmp-52m8.json index c798fa3828a..cfcaf64516a 100644 --- a/advisories/unreviewed/2025/01/GHSA-9v8h-2rmp-52m8/GHSA-9v8h-2rmp-52m8.json +++ b/advisories/unreviewed/2025/01/GHSA-9v8h-2rmp-52m8/GHSA-9v8h-2rmp-52m8.json @@ -46,7 +46,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-9w9r-vq29-w437/GHSA-9w9r-vq29-w437.json b/advisories/unreviewed/2025/01/GHSA-9w9r-vq29-w437/GHSA-9w9r-vq29-w437.json index 624f8b0a363..0d4c47850f1 100644 --- a/advisories/unreviewed/2025/01/GHSA-9w9r-vq29-w437/GHSA-9w9r-vq29-w437.json +++ b/advisories/unreviewed/2025/01/GHSA-9w9r-vq29-w437/GHSA-9w9r-vq29-w437.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9w9r-vq29-w437", - "modified": "2025-01-31T12:33:02Z", + "modified": "2025-02-04T18:30:47Z", "published": "2025-01-31T12:33:02Z", "aliases": [ "CVE-2025-21670" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nvsock/bpf: return early if transport is not assigned\n\nSome of the core functions can only be called if the transport\nhas been assigned.\n\nAs Michal reported, a socket might have the transport at NULL,\nfor example after a failed connect(), causing the following trace:\n\n BUG: kernel NULL pointer dereference, address: 00000000000000a0\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\n PGD 12faf8067 P4D 12faf8067 PUD 113670067 PMD 0\n Oops: Oops: 0000 [#1] PREEMPT SMP NOPTI\n CPU: 15 UID: 0 PID: 1198 Comm: a.out Not tainted 6.13.0-rc2+\n RIP: 0010:vsock_connectible_has_data+0x1f/0x40\n Call Trace:\n vsock_bpf_recvmsg+0xca/0x5e0\n sock_recvmsg+0xb9/0xc0\n __sys_recvfrom+0xb3/0x130\n __x64_sys_recvfrom+0x20/0x30\n do_syscall_64+0x93/0x180\n entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\nSo we need to check the `vsk->transport` in vsock_bpf_recvmsg(),\nespecially for connected sockets (stream/seqpacket) as we already\ndo in __vsock_connectible_recvmsg().", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-31T12:15:28Z" diff --git a/advisories/unreviewed/2025/01/GHSA-c5rm-5jj6-xh87/GHSA-c5rm-5jj6-xh87.json b/advisories/unreviewed/2025/01/GHSA-c5rm-5jj6-xh87/GHSA-c5rm-5jj6-xh87.json index 48cb6e372e8..b627808dc52 100644 --- a/advisories/unreviewed/2025/01/GHSA-c5rm-5jj6-xh87/GHSA-c5rm-5jj6-xh87.json +++ b/advisories/unreviewed/2025/01/GHSA-c5rm-5jj6-xh87/GHSA-c5rm-5jj6-xh87.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-732" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-cr4f-qgfw-47cw/GHSA-cr4f-qgfw-47cw.json b/advisories/unreviewed/2025/01/GHSA-cr4f-qgfw-47cw/GHSA-cr4f-qgfw-47cw.json index 1d4c42c001b..1e8153056e9 100644 --- a/advisories/unreviewed/2025/01/GHSA-cr4f-qgfw-47cw/GHSA-cr4f-qgfw-47cw.json +++ b/advisories/unreviewed/2025/01/GHSA-cr4f-qgfw-47cw/GHSA-cr4f-qgfw-47cw.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-284" + "CWE-284", + "CWE-639" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-cwjp-xwrc-rmgf/GHSA-cwjp-xwrc-rmgf.json b/advisories/unreviewed/2025/01/GHSA-cwjp-xwrc-rmgf/GHSA-cwjp-xwrc-rmgf.json index 298a4a9e7dd..98ac12513e0 100644 --- a/advisories/unreviewed/2025/01/GHSA-cwjp-xwrc-rmgf/GHSA-cwjp-xwrc-rmgf.json +++ b/advisories/unreviewed/2025/01/GHSA-cwjp-xwrc-rmgf/GHSA-cwjp-xwrc-rmgf.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-862" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-fcqg-w4pm-f4j3/GHSA-fcqg-w4pm-f4j3.json b/advisories/unreviewed/2025/01/GHSA-fcqg-w4pm-f4j3/GHSA-fcqg-w4pm-f4j3.json index 1306d842e57..a17b48d8d35 100644 --- a/advisories/unreviewed/2025/01/GHSA-fcqg-w4pm-f4j3/GHSA-fcqg-w4pm-f4j3.json +++ b/advisories/unreviewed/2025/01/GHSA-fcqg-w4pm-f4j3/GHSA-fcqg-w4pm-f4j3.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-306" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-fp6x-mq75-x6gh/GHSA-fp6x-mq75-x6gh.json b/advisories/unreviewed/2025/01/GHSA-fp6x-mq75-x6gh/GHSA-fp6x-mq75-x6gh.json index 6e9f2cc6462..d2fda00cb53 100644 --- a/advisories/unreviewed/2025/01/GHSA-fp6x-mq75-x6gh/GHSA-fp6x-mq75-x6gh.json +++ b/advisories/unreviewed/2025/01/GHSA-fp6x-mq75-x6gh/GHSA-fp6x-mq75-x6gh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-fp6x-mq75-x6gh", - "modified": "2025-01-26T12:30:32Z", + "modified": "2025-02-04T18:30:47Z", "published": "2025-01-26T12:30:32Z", "aliases": [ "CVE-2024-13505" diff --git a/advisories/unreviewed/2025/01/GHSA-fr8h-82qf-8xg7/GHSA-fr8h-82qf-8xg7.json b/advisories/unreviewed/2025/01/GHSA-fr8h-82qf-8xg7/GHSA-fr8h-82qf-8xg7.json index c42edeebeca..e1ee9272aef 100644 --- a/advisories/unreviewed/2025/01/GHSA-fr8h-82qf-8xg7/GHSA-fr8h-82qf-8xg7.json +++ b/advisories/unreviewed/2025/01/GHSA-fr8h-82qf-8xg7/GHSA-fr8h-82qf-8xg7.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-g5fp-9v3p-vv34/GHSA-g5fp-9v3p-vv34.json b/advisories/unreviewed/2025/01/GHSA-g5fp-9v3p-vv34/GHSA-g5fp-9v3p-vv34.json index 891a605bc4c..94de6a5b0ad 100644 --- a/advisories/unreviewed/2025/01/GHSA-g5fp-9v3p-vv34/GHSA-g5fp-9v3p-vv34.json +++ b/advisories/unreviewed/2025/01/GHSA-g5fp-9v3p-vv34/GHSA-g5fp-9v3p-vv34.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-gc8h-qjvm-5f2g/GHSA-gc8h-qjvm-5f2g.json b/advisories/unreviewed/2025/01/GHSA-gc8h-qjvm-5f2g/GHSA-gc8h-qjvm-5f2g.json index 63e70602ab8..a1193857492 100644 --- a/advisories/unreviewed/2025/01/GHSA-gc8h-qjvm-5f2g/GHSA-gc8h-qjvm-5f2g.json +++ b/advisories/unreviewed/2025/01/GHSA-gc8h-qjvm-5f2g/GHSA-gc8h-qjvm-5f2g.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-h52p-q8h5-pvqj/GHSA-h52p-q8h5-pvqj.json b/advisories/unreviewed/2025/01/GHSA-h52p-q8h5-pvqj/GHSA-h52p-q8h5-pvqj.json index 2a19cc19d63..aaeb8aaa6cf 100644 --- a/advisories/unreviewed/2025/01/GHSA-h52p-q8h5-pvqj/GHSA-h52p-q8h5-pvqj.json +++ b/advisories/unreviewed/2025/01/GHSA-h52p-q8h5-pvqj/GHSA-h52p-q8h5-pvqj.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-j2xr-87fv-4jx3/GHSA-j2xr-87fv-4jx3.json b/advisories/unreviewed/2025/01/GHSA-j2xr-87fv-4jx3/GHSA-j2xr-87fv-4jx3.json index f62561129eb..097b9eee9b1 100644 --- a/advisories/unreviewed/2025/01/GHSA-j2xr-87fv-4jx3/GHSA-j2xr-87fv-4jx3.json +++ b/advisories/unreviewed/2025/01/GHSA-j2xr-87fv-4jx3/GHSA-j2xr-87fv-4jx3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-j2xr-87fv-4jx3", - "modified": "2025-01-30T09:30:37Z", + "modified": "2025-02-04T18:30:47Z", "published": "2025-01-30T09:30:37Z", "aliases": [ "CVE-2024-13642" diff --git a/advisories/unreviewed/2025/01/GHSA-mq7g-cwjx-j964/GHSA-mq7g-cwjx-j964.json b/advisories/unreviewed/2025/01/GHSA-mq7g-cwjx-j964/GHSA-mq7g-cwjx-j964.json index 18345cda250..6522de26936 100644 --- a/advisories/unreviewed/2025/01/GHSA-mq7g-cwjx-j964/GHSA-mq7g-cwjx-j964.json +++ b/advisories/unreviewed/2025/01/GHSA-mq7g-cwjx-j964/GHSA-mq7g-cwjx-j964.json @@ -42,7 +42,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-74" + "CWE-74", + "CWE-89" ], "severity": "MODERATE", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-q5gp-c57f-33x3/GHSA-q5gp-c57f-33x3.json b/advisories/unreviewed/2025/01/GHSA-q5gp-c57f-33x3/GHSA-q5gp-c57f-33x3.json index 9b5cacf6261..3965ea05864 100644 --- a/advisories/unreviewed/2025/01/GHSA-q5gp-c57f-33x3/GHSA-q5gp-c57f-33x3.json +++ b/advisories/unreviewed/2025/01/GHSA-q5gp-c57f-33x3/GHSA-q5gp-c57f-33x3.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-qfqw-8w5m-fmv4/GHSA-qfqw-8w5m-fmv4.json b/advisories/unreviewed/2025/01/GHSA-qfqw-8w5m-fmv4/GHSA-qfqw-8w5m-fmv4.json index 3c45daab19d..e1884a3cf07 100644 --- a/advisories/unreviewed/2025/01/GHSA-qfqw-8w5m-fmv4/GHSA-qfqw-8w5m-fmv4.json +++ b/advisories/unreviewed/2025/01/GHSA-qfqw-8w5m-fmv4/GHSA-qfqw-8w5m-fmv4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qfqw-8w5m-fmv4", - "modified": "2025-01-31T12:33:03Z", + "modified": "2025-02-04T18:30:47Z", "published": "2025-01-31T12:33:03Z", "aliases": [ "CVE-2025-21674" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: Fix inversion dependency warning while enabling IPsec tunnel\n\nAttempt to enable IPsec packet offload in tunnel mode in debug kernel\ngenerates the following kernel panic, which is happening due to two\nissues:\n1. In SA add section, the should be _bh() variant when marking SA mode.\n2. There is not needed flush_workqueue in SA delete routine. It is not\nneeded as at this stage as it is removed from SADB and the running work\nwill be canceled later in SA free.\n\n =====================================================\n WARNING: SOFTIRQ-safe -> SOFTIRQ-unsafe lock order detected\n 6.12.0+ #4 Not tainted\n -----------------------------------------------------\n charon/1337 [HC0[0]:SC0[4]:HE1:SE0] is trying to acquire:\n ffff88810f365020 (&xa->xa_lock#24){+.+.}-{3:3}, at: mlx5e_xfrm_del_state+0xca/0x1e0 [mlx5_core]\n\n and this task is already holding:\n ffff88813e0f0d48 (&x->lock){+.-.}-{3:3}, at: xfrm_state_delete+0x16/0x30\n which would create a new lock dependency:\n (&x->lock){+.-.}-{3:3} -> (&xa->xa_lock#24){+.+.}-{3:3}\n\n but this new dependency connects a SOFTIRQ-irq-safe lock:\n (&x->lock){+.-.}-{3:3}\n\n ... which became SOFTIRQ-irq-safe at:\n lock_acquire+0x1be/0x520\n _raw_spin_lock_bh+0x34/0x40\n xfrm_timer_handler+0x91/0xd70\n __hrtimer_run_queues+0x1dd/0xa60\n hrtimer_run_softirq+0x146/0x2e0\n handle_softirqs+0x266/0x860\n irq_exit_rcu+0x115/0x1a0\n sysvec_apic_timer_interrupt+0x6e/0x90\n asm_sysvec_apic_timer_interrupt+0x16/0x20\n default_idle+0x13/0x20\n default_idle_call+0x67/0xa0\n do_idle+0x2da/0x320\n cpu_startup_entry+0x50/0x60\n start_secondary+0x213/0x2a0\n common_startup_64+0x129/0x138\n\n to a SOFTIRQ-irq-unsafe lock:\n (&xa->xa_lock#24){+.+.}-{3:3}\n\n ... which became SOFTIRQ-irq-unsafe at:\n ...\n lock_acquire+0x1be/0x520\n _raw_spin_lock+0x2c/0x40\n xa_set_mark+0x70/0x110\n mlx5e_xfrm_add_state+0xe48/0x2290 [mlx5_core]\n xfrm_dev_state_add+0x3bb/0xd70\n xfrm_add_sa+0x2451/0x4a90\n xfrm_user_rcv_msg+0x493/0x880\n netlink_rcv_skb+0x12e/0x380\n xfrm_netlink_rcv+0x6d/0x90\n netlink_unicast+0x42f/0x740\n netlink_sendmsg+0x745/0xbe0\n __sock_sendmsg+0xc5/0x190\n __sys_sendto+0x1fe/0x2c0\n __x64_sys_sendto+0xdc/0x1b0\n do_syscall_64+0x6d/0x140\n entry_SYSCALL_64_after_hwframe+0x4b/0x53\n\n other info that might help us debug this:\n\n Possible interrupt unsafe locking scenario:\n\n CPU0 CPU1\n ---- ----\n lock(&xa->xa_lock#24);\n local_irq_disable();\n lock(&x->lock);\n lock(&xa->xa_lock#24);\n \n lock(&x->lock);\n\n *** DEADLOCK ***\n\n 2 locks held by charon/1337:\n #0: ffffffff87f8f858 (&net->xfrm.xfrm_cfg_mutex){+.+.}-{4:4}, at: xfrm_netlink_rcv+0x5e/0x90\n #1: ffff88813e0f0d48 (&x->lock){+.-.}-{3:3}, at: xfrm_state_delete+0x16/0x30\n\n the dependencies between SOFTIRQ-irq-safe lock and the holding lock:\n -> (&x->lock){+.-.}-{3:3} ops: 29 {\n HARDIRQ-ON-W at:\n lock_acquire+0x1be/0x520\n _raw_spin_lock_bh+0x34/0x40\n xfrm_alloc_spi+0xc0/0xe60\n xfrm_alloc_userspi+0x5f6/0xbc0\n xfrm_user_rcv_msg+0x493/0x880\n netlink_rcv_skb+0x12e/0x380\n xfrm_netlink_rcv+0x6d/0x90\n netlink_unicast+0x42f/0x740\n netlink_sendmsg+0x745/0xbe0\n __sock_sendmsg+0xc5/0x190\n __sys_sendto+0x1fe/0x2c0\n __x64_sys_sendto+0xdc/0x1b0\n do_syscall_64+0x6d/0x140\n entry_SYSCALL_64_after_hwframe+0x4b/0x53\n IN-SOFTIRQ-W at:\n lock_acquire+0x1be/0x520\n _raw_spin_lock_bh+0x34/0x40\n xfrm_timer_handler+0x91/0xd70\n __hrtimer_run_queues+0x1dd/0xa60\n \n---truncated---", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-667" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-31T12:15:28Z" diff --git a/advisories/unreviewed/2025/01/GHSA-qjjp-gpj3-qwwr/GHSA-qjjp-gpj3-qwwr.json b/advisories/unreviewed/2025/01/GHSA-qjjp-gpj3-qwwr/GHSA-qjjp-gpj3-qwwr.json index 0a7076fd1b6..6c17598c55b 100644 --- a/advisories/unreviewed/2025/01/GHSA-qjjp-gpj3-qwwr/GHSA-qjjp-gpj3-qwwr.json +++ b/advisories/unreviewed/2025/01/GHSA-qjjp-gpj3-qwwr/GHSA-qjjp-gpj3-qwwr.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-qpr8-gfg5-hxvp/GHSA-qpr8-gfg5-hxvp.json b/advisories/unreviewed/2025/01/GHSA-qpr8-gfg5-hxvp/GHSA-qpr8-gfg5-hxvp.json index 1ab6f4b271a..e948e218c50 100644 --- a/advisories/unreviewed/2025/01/GHSA-qpr8-gfg5-hxvp/GHSA-qpr8-gfg5-hxvp.json +++ b/advisories/unreviewed/2025/01/GHSA-qpr8-gfg5-hxvp/GHSA-qpr8-gfg5-hxvp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qpr8-gfg5-hxvp", - "modified": "2025-01-21T18:31:07Z", + "modified": "2025-02-04T18:30:47Z", "published": "2025-01-21T18:31:07Z", "aliases": [ "CVE-2024-56990" ], "details": "PHPGurukul Hospital Management System 4.0 is vulnerable to Cross Site Scripting (XSS) in /view-medhistory.php and /admin/view-patient.php.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-21T16:15:13Z" diff --git a/advisories/unreviewed/2025/01/GHSA-r4cp-xh3m-7m8h/GHSA-r4cp-xh3m-7m8h.json b/advisories/unreviewed/2025/01/GHSA-r4cp-xh3m-7m8h/GHSA-r4cp-xh3m-7m8h.json index 543c6d9b5bb..7333c22fc20 100644 --- a/advisories/unreviewed/2025/01/GHSA-r4cp-xh3m-7m8h/GHSA-r4cp-xh3m-7m8h.json +++ b/advisories/unreviewed/2025/01/GHSA-r4cp-xh3m-7m8h/GHSA-r4cp-xh3m-7m8h.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-r4cp-xh3m-7m8h", - "modified": "2025-01-31T12:33:02Z", + "modified": "2025-02-04T18:30:47Z", "published": "2025-01-31T12:33:02Z", "aliases": [ "CVE-2025-21673" ], "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: fix double free of TCP_Server_Info::hostname\n\nWhen shutting down the server in cifs_put_tcp_session(), cifsd thread\nmight be reconnecting to multiple DFS targets before it realizes it\nshould exit the loop, so @server->hostname can't be freed as long as\ncifsd thread isn't done. Otherwise the following can happen:\n\n RIP: 0010:__slab_free+0x223/0x3c0\n Code: 5e 41 5f c3 cc cc cc cc 4c 89 de 4c 89 cf 44 89 44 24 08 4c 89\n 1c 24 e8 fb cf 8e 00 44 8b 44 24 08 4c 8b 1c 24 e9 5f fe ff ff <0f>\n 0b 41 f7 45 08 00 0d 21 00 0f 85 2d ff ff ff e9 1f ff ff ff 80\n RSP: 0018:ffffb26180dbfd08 EFLAGS: 00010246\n RAX: ffff8ea34728e510 RBX: ffff8ea34728e500 RCX: 0000000000800068\n RDX: 0000000000800068 RSI: 0000000000000000 RDI: ffff8ea340042400\n RBP: ffffe112041ca380 R08: 0000000000000001 R09: 0000000000000000\n R10: 6170732e31303000 R11: 70726f632e786563 R12: ffff8ea34728e500\n R13: ffff8ea340042400 R14: ffff8ea34728e500 R15: 0000000000800068\n FS: 0000000000000000(0000) GS:ffff8ea66fd80000(0000)\n 000000\n CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 00007ffc25376080 CR3: 000000012a2ba001 CR4:\n PKRU: 55555554\n Call Trace:\n \n ? show_trace_log_lvl+0x1c4/0x2df\n ? show_trace_log_lvl+0x1c4/0x2df\n ? __reconnect_target_unlocked+0x3e/0x160 [cifs]\n ? __die_body.cold+0x8/0xd\n ? die+0x2b/0x50\n ? do_trap+0xce/0x120\n ? __slab_free+0x223/0x3c0\n ? do_error_trap+0x65/0x80\n ? __slab_free+0x223/0x3c0\n ? exc_invalid_op+0x4e/0x70\n ? __slab_free+0x223/0x3c0\n ? asm_exc_invalid_op+0x16/0x20\n ? __slab_free+0x223/0x3c0\n ? extract_hostname+0x5c/0xa0 [cifs]\n ? extract_hostname+0x5c/0xa0 [cifs]\n ? __kmalloc+0x4b/0x140\n __reconnect_target_unlocked+0x3e/0x160 [cifs]\n reconnect_dfs_server+0x145/0x430 [cifs]\n cifs_handle_standard+0x1ad/0x1d0 [cifs]\n cifs_demultiplex_thread+0x592/0x730 [cifs]\n ? __pfx_cifs_demultiplex_thread+0x10/0x10 [cifs]\n kthread+0xdd/0x100\n ? __pfx_kthread+0x10/0x10\n ret_from_fork+0x29/0x50\n ", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-415" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-31T12:15:28Z" diff --git a/advisories/unreviewed/2025/01/GHSA-vjjw-c569-5c3p/GHSA-vjjw-c569-5c3p.json b/advisories/unreviewed/2025/01/GHSA-vjjw-c569-5c3p/GHSA-vjjw-c569-5c3p.json index 136741242ab..5c5e34b0b6f 100644 --- a/advisories/unreviewed/2025/01/GHSA-vjjw-c569-5c3p/GHSA-vjjw-c569-5c3p.json +++ b/advisories/unreviewed/2025/01/GHSA-vjjw-c569-5c3p/GHSA-vjjw-c569-5c3p.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-w7mf-7gmj-4jw8/GHSA-w7mf-7gmj-4jw8.json b/advisories/unreviewed/2025/01/GHSA-w7mf-7gmj-4jw8/GHSA-w7mf-7gmj-4jw8.json index 3daebc68f8a..7bcf165f070 100644 --- a/advisories/unreviewed/2025/01/GHSA-w7mf-7gmj-4jw8/GHSA-w7mf-7gmj-4jw8.json +++ b/advisories/unreviewed/2025/01/GHSA-w7mf-7gmj-4jw8/GHSA-w7mf-7gmj-4jw8.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-w8gv-53r7-fph6/GHSA-w8gv-53r7-fph6.json b/advisories/unreviewed/2025/01/GHSA-w8gv-53r7-fph6/GHSA-w8gv-53r7-fph6.json index b463fa0a734..a14e11db803 100644 --- a/advisories/unreviewed/2025/01/GHSA-w8gv-53r7-fph6/GHSA-w8gv-53r7-fph6.json +++ b/advisories/unreviewed/2025/01/GHSA-w8gv-53r7-fph6/GHSA-w8gv-53r7-fph6.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-863" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-xgj7-v3ff-h29v/GHSA-xgj7-v3ff-h29v.json b/advisories/unreviewed/2025/01/GHSA-xgj7-v3ff-h29v/GHSA-xgj7-v3ff-h29v.json index 2c387cdeb56..0e3e83dfd24 100644 --- a/advisories/unreviewed/2025/01/GHSA-xgj7-v3ff-h29v/GHSA-xgj7-v3ff-h29v.json +++ b/advisories/unreviewed/2025/01/GHSA-xgj7-v3ff-h29v/GHSA-xgj7-v3ff-h29v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-xgj7-v3ff-h29v", - "modified": "2025-01-21T18:31:07Z", + "modified": "2025-02-04T18:30:47Z", "published": "2025-01-21T18:31:07Z", "aliases": [ "CVE-2024-57036" ], "details": "TOTOLINK A810R V4.1.2cu.5032_B20200407 was found to contain a command insertion vulnerability in downloadFile.cgi main function. This vulnerability allows an attacker to execute arbitrary commands by sending HTTP request.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-77" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-21T16:15:14Z" diff --git a/advisories/unreviewed/2025/02/GHSA-365m-6cxm-68v4/GHSA-365m-6cxm-68v4.json b/advisories/unreviewed/2025/02/GHSA-365m-6cxm-68v4/GHSA-365m-6cxm-68v4.json index 3e130dbcc2d..1bf4535fbfc 100644 --- a/advisories/unreviewed/2025/02/GHSA-365m-6cxm-68v4/GHSA-365m-6cxm-68v4.json +++ b/advisories/unreviewed/2025/02/GHSA-365m-6cxm-68v4/GHSA-365m-6cxm-68v4.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-365m-6cxm-68v4", - "modified": "2025-02-03T18:30:43Z", + "modified": "2025-02-04T18:30:48Z", "published": "2025-02-03T18:30:43Z", "aliases": [ "CVE-2024-55456" ], "details": "lunasvg v3.0.1 was discovered to contain a segmentation violation via the component gray_find_cell", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-03T17:15:21Z" diff --git a/advisories/unreviewed/2025/02/GHSA-3pgm-m73m-qrj2/GHSA-3pgm-m73m-qrj2.json b/advisories/unreviewed/2025/02/GHSA-3pgm-m73m-qrj2/GHSA-3pgm-m73m-qrj2.json index c9a79743e5d..b76f823cce7 100644 --- a/advisories/unreviewed/2025/02/GHSA-3pgm-m73m-qrj2/GHSA-3pgm-m73m-qrj2.json +++ b/advisories/unreviewed/2025/02/GHSA-3pgm-m73m-qrj2/GHSA-3pgm-m73m-qrj2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-3pgm-m73m-qrj2", - "modified": "2025-02-03T21:31:50Z", + "modified": "2025-02-04T18:30:48Z", "published": "2025-02-03T21:31:50Z", "aliases": [ "CVE-2025-25065" ], "details": "SSRF vulnerability in the RSS feed parser in Zimbra Collaboration 9.0.0 before Patch 43, 10.0.x before 10.0.12, and 10.1.x before 10.1.4 allows unauthorized redirection to internal network endpoints.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -32,8 +37,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-03T20:15:37Z" diff --git a/advisories/unreviewed/2025/02/GHSA-5rhr-255q-cgmp/GHSA-5rhr-255q-cgmp.json b/advisories/unreviewed/2025/02/GHSA-5rhr-255q-cgmp/GHSA-5rhr-255q-cgmp.json index 6f5036e0d51..2354971b89b 100644 --- a/advisories/unreviewed/2025/02/GHSA-5rhr-255q-cgmp/GHSA-5rhr-255q-cgmp.json +++ b/advisories/unreviewed/2025/02/GHSA-5rhr-255q-cgmp/GHSA-5rhr-255q-cgmp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5rhr-255q-cgmp", - "modified": "2025-02-03T21:31:49Z", + "modified": "2025-02-04T18:30:48Z", "published": "2025-02-03T21:31:49Z", "aliases": [ "CVE-2024-57099" ], "details": "ClassCMS v4.8 has a code execution vulnerability. Attackers can exploit this vulnerability by constructing a payload in the classview parameter of the model management feature, allowing them to execute arbitrary code and potentially take control of the server.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-94" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-03T20:15:34Z" diff --git a/advisories/unreviewed/2025/02/GHSA-6wm8-q34j-2mc2/GHSA-6wm8-q34j-2mc2.json b/advisories/unreviewed/2025/02/GHSA-6wm8-q34j-2mc2/GHSA-6wm8-q34j-2mc2.json index 0a74613159d..773df106f0c 100644 --- a/advisories/unreviewed/2025/02/GHSA-6wm8-q34j-2mc2/GHSA-6wm8-q34j-2mc2.json +++ b/advisories/unreviewed/2025/02/GHSA-6wm8-q34j-2mc2/GHSA-6wm8-q34j-2mc2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-6wm8-q34j-2mc2", - "modified": "2025-02-03T21:31:49Z", + "modified": "2025-02-04T18:30:48Z", "published": "2025-02-03T21:31:49Z", "aliases": [ "CVE-2024-56921" ], "details": "An issue was discovered in Open5gs v2.7.2. InitialUEMessage, Registration request sent at a specific time can crash AMF due to incorrect error handling of gmm_state_exception() function upon receipt of the Nausf_UEAuthentication_Authenticate response.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-617" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-03T20:15:33Z" diff --git a/advisories/unreviewed/2025/02/GHSA-7359-388q-rq9x/GHSA-7359-388q-rq9x.json b/advisories/unreviewed/2025/02/GHSA-7359-388q-rq9x/GHSA-7359-388q-rq9x.json index c9662449e8c..f6614e27e0b 100644 --- a/advisories/unreviewed/2025/02/GHSA-7359-388q-rq9x/GHSA-7359-388q-rq9x.json +++ b/advisories/unreviewed/2025/02/GHSA-7359-388q-rq9x/GHSA-7359-388q-rq9x.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7359-388q-rq9x", - "modified": "2025-02-03T21:31:49Z", + "modified": "2025-02-04T18:30:48Z", "published": "2025-02-03T21:31:49Z", "aliases": [ "CVE-2024-50656" ], "details": "itsourcecode Placement Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the Full Name field in registration.php.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-03T19:15:12Z" diff --git a/advisories/unreviewed/2025/02/GHSA-73mq-397v-4rm9/GHSA-73mq-397v-4rm9.json b/advisories/unreviewed/2025/02/GHSA-73mq-397v-4rm9/GHSA-73mq-397v-4rm9.json index 3e2529808b5..fcc14f3d89c 100644 --- a/advisories/unreviewed/2025/02/GHSA-73mq-397v-4rm9/GHSA-73mq-397v-4rm9.json +++ b/advisories/unreviewed/2025/02/GHSA-73mq-397v-4rm9/GHSA-73mq-397v-4rm9.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-73mq-397v-4rm9", - "modified": "2025-02-03T21:31:49Z", + "modified": "2025-02-04T18:30:48Z", "published": "2025-02-03T21:31:49Z", "aliases": [ "CVE-2024-57450" ], "details": "ChestnutCMS <=1.5.0 is vulnerable to File Upload via the Create template function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-434" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-03T20:15:34Z" diff --git a/advisories/unreviewed/2025/02/GHSA-76rj-9h8w-cwx9/GHSA-76rj-9h8w-cwx9.json b/advisories/unreviewed/2025/02/GHSA-76rj-9h8w-cwx9/GHSA-76rj-9h8w-cwx9.json new file mode 100644 index 00000000000..ba079978508 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-76rj-9h8w-cwx9/GHSA-76rj-9h8w-cwx9.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-76rj-9h8w-cwx9", + "modified": "2025-02-04T18:30:46Z", + "published": "2025-02-04T18:30:46Z", + "aliases": [ + "CVE-2022-43933" + ], + "details": "An information exposure through log file vulnerability exists in Brocade SANnav before Brocade SANnav 2.2.2, where configuration secrets are logged in supportsave. Supportsave file is generated by an admin user troubleshooting the switch. The Logged information may include usernames and passwords, and secret keys.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-43933" + }, + { + "type": "WEB", + "url": "https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/21221" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-532", + "CWE-538" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-11-21T11:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-95p6-mvh4-q6jg/GHSA-95p6-mvh4-q6jg.json b/advisories/unreviewed/2025/02/GHSA-95p6-mvh4-q6jg/GHSA-95p6-mvh4-q6jg.json new file mode 100644 index 00000000000..fa7067d19d6 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-95p6-mvh4-q6jg/GHSA-95p6-mvh4-q6jg.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-95p6-mvh4-q6jg", + "modified": "2025-02-04T18:30:48Z", + "published": "2025-02-04T18:30:48Z", + "aliases": [ + "CVE-2025-23059" + ], + "details": "A vulnerability in the web-based management interface of HPE Aruba Networking ClearPass Policy Manager exposes directories containing sensitive information. If exploited successfully, this vulnerability allows an authenticated remote attacker with high privileges to access and retrieve sensitive data, potentially compromising the integrity and security of the entire system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23059" + }, + { + "type": "WEB", + "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04784en_us&docLocale=en_US" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-04T18:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-9pv9-rw6v-ggw5/GHSA-9pv9-rw6v-ggw5.json b/advisories/unreviewed/2025/02/GHSA-9pv9-rw6v-ggw5/GHSA-9pv9-rw6v-ggw5.json index 44cfa18615c..823ae414833 100644 --- a/advisories/unreviewed/2025/02/GHSA-9pv9-rw6v-ggw5/GHSA-9pv9-rw6v-ggw5.json +++ b/advisories/unreviewed/2025/02/GHSA-9pv9-rw6v-ggw5/GHSA-9pv9-rw6v-ggw5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-9pv9-rw6v-ggw5", - "modified": "2025-02-03T21:31:49Z", + "modified": "2025-02-04T18:30:48Z", "published": "2025-02-03T21:31:49Z", "aliases": [ "CVE-2024-57098" ], "details": "Moss v0.1.3 version has an SQL injection vulnerability that allows attackers to inject carefully designed payloads into the order parameter.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-03T20:15:34Z" diff --git a/advisories/unreviewed/2025/02/GHSA-c2vv-2vc2-cv34/GHSA-c2vv-2vc2-cv34.json b/advisories/unreviewed/2025/02/GHSA-c2vv-2vc2-cv34/GHSA-c2vv-2vc2-cv34.json index 10883198e0d..49ac581d5f1 100644 --- a/advisories/unreviewed/2025/02/GHSA-c2vv-2vc2-cv34/GHSA-c2vv-2vc2-cv34.json +++ b/advisories/unreviewed/2025/02/GHSA-c2vv-2vc2-cv34/GHSA-c2vv-2vc2-cv34.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c2vv-2vc2-cv34", - "modified": "2025-02-03T21:31:50Z", + "modified": "2025-02-04T18:30:48Z", "published": "2025-02-03T21:31:50Z", "aliases": [ "CVE-2024-34897" ], "details": "Nedis SmartLife android app v1.4.0 was discovered to contain an API key disclosure vulnerability.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-732" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-03T21:15:12Z" diff --git a/advisories/unreviewed/2025/02/GHSA-c5rf-2f3r-9gr9/GHSA-c5rf-2f3r-9gr9.json b/advisories/unreviewed/2025/02/GHSA-c5rf-2f3r-9gr9/GHSA-c5rf-2f3r-9gr9.json new file mode 100644 index 00000000000..e04af517438 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-c5rf-2f3r-9gr9/GHSA-c5rf-2f3r-9gr9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-c5rf-2f3r-9gr9", + "modified": "2025-02-04T18:30:48Z", + "published": "2025-02-04T18:30:48Z", + "aliases": [ + "CVE-2024-45659" + ], + "details": "IBM Security Verify Access Appliance and Container 10.0.0 through 10.0.8 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45659" + }, + { + "type": "WEB", + "url": "https://www.ibm.com/support/pages/node/7182386" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-209" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-04T18:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-cgvq-f89h-62cq/GHSA-cgvq-f89h-62cq.json b/advisories/unreviewed/2025/02/GHSA-cgvq-f89h-62cq/GHSA-cgvq-f89h-62cq.json index 80064d9df34..d11579e1f46 100644 --- a/advisories/unreviewed/2025/02/GHSA-cgvq-f89h-62cq/GHSA-cgvq-f89h-62cq.json +++ b/advisories/unreviewed/2025/02/GHSA-cgvq-f89h-62cq/GHSA-cgvq-f89h-62cq.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cgvq-f89h-62cq", - "modified": "2025-02-01T09:30:28Z", + "modified": "2025-02-04T18:30:48Z", "published": "2025-02-01T09:30:28Z", "aliases": [ "CVE-2024-11829" diff --git a/advisories/unreviewed/2025/02/GHSA-cmgj-xph9-cc49/GHSA-cmgj-xph9-cc49.json b/advisories/unreviewed/2025/02/GHSA-cmgj-xph9-cc49/GHSA-cmgj-xph9-cc49.json new file mode 100644 index 00000000000..e4fcf41b5e7 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-cmgj-xph9-cc49/GHSA-cmgj-xph9-cc49.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cmgj-xph9-cc49", + "modified": "2025-02-04T18:30:48Z", + "published": "2025-02-04T18:30:48Z", + "aliases": [ + "CVE-2025-0364" + ], + "details": "BigAntSoft BigAnt Server, up to and including version 5.6.06, is vulnerable to unauthenticated remote code execution via account registration. An unauthenticated remote attacker can create an administrative user through the default exposed SaaS registration mechanism. Once an administrator, the attacker can upload and execute arbitrary PHP code using the \"Cloud Storage Addin,\" leading to unauthenticated code execution.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0364" + }, + { + "type": "WEB", + "url": "https://vulncheck.com/advisories/big-ant-upload-rce" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-288" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-04T18:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-fwj7-p878-r668/GHSA-fwj7-p878-r668.json b/advisories/unreviewed/2025/02/GHSA-fwj7-p878-r668/GHSA-fwj7-p878-r668.json index 123cdc27d44..22fc080d9b3 100644 --- a/advisories/unreviewed/2025/02/GHSA-fwj7-p878-r668/GHSA-fwj7-p878-r668.json +++ b/advisories/unreviewed/2025/02/GHSA-fwj7-p878-r668/GHSA-fwj7-p878-r668.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fwj7-p878-r668", - "modified": "2025-02-03T21:31:50Z", + "modified": "2025-02-04T18:30:48Z", "published": "2025-02-03T21:31:50Z", "aliases": [ "CVE-2024-56898" ], "details": "Incorrect access control in Geovision GV-ASWeb version 6.1.0.0 or less allows unauthorized attackers with low-level privileges to manage and create new user accounts via supplying a crafted HTTP request.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-862" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-03T21:15:14Z" diff --git a/advisories/unreviewed/2025/02/GHSA-gf66-v569-23vx/GHSA-gf66-v569-23vx.json b/advisories/unreviewed/2025/02/GHSA-gf66-v569-23vx/GHSA-gf66-v569-23vx.json index 2b54ca82f5a..d09b3f7cb48 100644 --- a/advisories/unreviewed/2025/02/GHSA-gf66-v569-23vx/GHSA-gf66-v569-23vx.json +++ b/advisories/unreviewed/2025/02/GHSA-gf66-v569-23vx/GHSA-gf66-v569-23vx.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-gf66-v569-23vx", - "modified": "2025-02-03T21:31:50Z", + "modified": "2025-02-04T18:30:48Z", "published": "2025-02-03T21:31:50Z", "aliases": [ "CVE-2025-22978" ], "details": "eladmin <=2.7 is vulnerable to CSV Injection in the exception log download module.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-77" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-03T20:15:36Z" diff --git a/advisories/unreviewed/2025/02/GHSA-h8gw-9qqq-m7gv/GHSA-h8gw-9qqq-m7gv.json b/advisories/unreviewed/2025/02/GHSA-h8gw-9qqq-m7gv/GHSA-h8gw-9qqq-m7gv.json new file mode 100644 index 00000000000..0e4692a886d --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-h8gw-9qqq-m7gv/GHSA-h8gw-9qqq-m7gv.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h8gw-9qqq-m7gv", + "modified": "2025-02-04T18:30:48Z", + "published": "2025-02-04T18:30:48Z", + "aliases": [ + "CVE-2025-23060" + ], + "details": "A vulnerability in HPE Aruba Networking ClearPass Policy Manager may, under certain circumstances, expose sensitive unencrypted information. Exploiting this vulnerability could allow an attacker to perform a man-in-the-middle attack, potentially granting unauthorized access to network resources as well as enabling data tampering.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23060" + }, + { + "type": "WEB", + "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04784en_us&docLocale=en_US" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-04T18:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-j6vh-r2v3-c7fp/GHSA-j6vh-r2v3-c7fp.json b/advisories/unreviewed/2025/02/GHSA-j6vh-r2v3-c7fp/GHSA-j6vh-r2v3-c7fp.json index 8ae2aff770a..c88085b7dea 100644 --- a/advisories/unreviewed/2025/02/GHSA-j6vh-r2v3-c7fp/GHSA-j6vh-r2v3-c7fp.json +++ b/advisories/unreviewed/2025/02/GHSA-j6vh-r2v3-c7fp/GHSA-j6vh-r2v3-c7fp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-j6vh-r2v3-c7fp", - "modified": "2025-02-04T06:30:41Z", + "modified": "2025-02-04T18:30:48Z", "published": "2025-02-04T06:30:41Z", "aliases": [ "CVE-2024-13329" ], "details": "The Solidres WordPress plugin through 0.9.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-04T06:15:29Z" diff --git a/advisories/unreviewed/2025/02/GHSA-jqmp-73q6-rjhg/GHSA-jqmp-73q6-rjhg.json b/advisories/unreviewed/2025/02/GHSA-jqmp-73q6-rjhg/GHSA-jqmp-73q6-rjhg.json index ba5f2560d6a..ddac788b7a1 100644 --- a/advisories/unreviewed/2025/02/GHSA-jqmp-73q6-rjhg/GHSA-jqmp-73q6-rjhg.json +++ b/advisories/unreviewed/2025/02/GHSA-jqmp-73q6-rjhg/GHSA-jqmp-73q6-rjhg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-jqmp-73q6-rjhg", - "modified": "2025-02-04T09:31:08Z", + "modified": "2025-02-04T18:30:48Z", "published": "2025-02-04T09:31:08Z", "aliases": [ "CVE-2025-22204" ], "details": "Improper control of generation of code in the sourcerer extension for Joomla in versions before 11.0.0 lead to a remote code execution vulnerability.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -23,7 +28,7 @@ "cwe_ids": [ "CWE-94" ], - "severity": null, + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-04T08:15:32Z" diff --git a/advisories/unreviewed/2025/02/GHSA-q23h-jx29-2xhg/GHSA-q23h-jx29-2xhg.json b/advisories/unreviewed/2025/02/GHSA-q23h-jx29-2xhg/GHSA-q23h-jx29-2xhg.json index bc1c7b8ee8f..8b9066f5587 100644 --- a/advisories/unreviewed/2025/02/GHSA-q23h-jx29-2xhg/GHSA-q23h-jx29-2xhg.json +++ b/advisories/unreviewed/2025/02/GHSA-q23h-jx29-2xhg/GHSA-q23h-jx29-2xhg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-q23h-jx29-2xhg", - "modified": "2025-02-03T21:31:50Z", + "modified": "2025-02-04T18:30:48Z", "published": "2025-02-03T21:31:50Z", "aliases": [ "CVE-2024-56901" ], "details": "A Cross-Site Request Forgery (CSRF) in the Account Management component of Geovision GV-ASWeb version 6.1.1.0 or less allows attackers to arbitrarily create Admin accounts via a crafted GET request method.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-352" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-03T21:15:14Z" diff --git a/advisories/unreviewed/2025/02/GHSA-qv9v-xqjc-jc7f/GHSA-qv9v-xqjc-jc7f.json b/advisories/unreviewed/2025/02/GHSA-qv9v-xqjc-jc7f/GHSA-qv9v-xqjc-jc7f.json index afa9be13985..130a4d89fed 100644 --- a/advisories/unreviewed/2025/02/GHSA-qv9v-xqjc-jc7f/GHSA-qv9v-xqjc-jc7f.json +++ b/advisories/unreviewed/2025/02/GHSA-qv9v-xqjc-jc7f/GHSA-qv9v-xqjc-jc7f.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-qv9v-xqjc-jc7f", - "modified": "2025-02-03T21:31:50Z", + "modified": "2025-02-04T18:30:48Z", "published": "2025-02-03T21:31:50Z", "aliases": [ "CVE-2024-44449" ], "details": "Cross Site Scripting vulnerability in Quorum onQ OS v.6.0.0.5.2064 allows a remote attacker to obtain sensitive information via the msg parameter in the Login page.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-03T21:15:12Z" diff --git a/advisories/unreviewed/2025/02/GHSA-r378-wj97-j2jv/GHSA-r378-wj97-j2jv.json b/advisories/unreviewed/2025/02/GHSA-r378-wj97-j2jv/GHSA-r378-wj97-j2jv.json index 6a202d3a38d..3c4e80a2eb6 100644 --- a/advisories/unreviewed/2025/02/GHSA-r378-wj97-j2jv/GHSA-r378-wj97-j2jv.json +++ b/advisories/unreviewed/2025/02/GHSA-r378-wj97-j2jv/GHSA-r378-wj97-j2jv.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-r378-wj97-j2jv", - "modified": "2025-02-04T06:30:41Z", + "modified": "2025-02-04T18:30:48Z", "published": "2025-02-04T06:30:41Z", "aliases": [ "CVE-2024-13330" ], "details": "The JustRows free WordPress plugin through 0.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-04T06:15:29Z" diff --git a/advisories/unreviewed/2025/02/GHSA-vhj8-f69q-35j6/GHSA-vhj8-f69q-35j6.json b/advisories/unreviewed/2025/02/GHSA-vhj8-f69q-35j6/GHSA-vhj8-f69q-35j6.json new file mode 100644 index 00000000000..be9c5e719f1 --- /dev/null +++ b/advisories/unreviewed/2025/02/GHSA-vhj8-f69q-35j6/GHSA-vhj8-f69q-35j6.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vhj8-f69q-35j6", + "modified": "2025-02-04T18:30:48Z", + "published": "2025-02-04T18:30:48Z", + "aliases": [ + "CVE-2025-23058" + ], + "details": "A vulnerability in the ClearPass Policy Manager web-based management interface allows a low-privileged (read-only) authenticated remote attacker to gain unauthorized access to data and the ability to execute functions that should be restricted to administrators only with read/write privileges. Successful exploitation could enable a low-privileged user to execute administrative functions leading to an escalation of privileges.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23058" + }, + { + "type": "WEB", + "url": "https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04784en_us&docLocale=en_US" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-02-04T18:15:35Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/02/GHSA-vp47-mv7q-f7h2/GHSA-vp47-mv7q-f7h2.json b/advisories/unreviewed/2025/02/GHSA-vp47-mv7q-f7h2/GHSA-vp47-mv7q-f7h2.json index b13629115f8..09bbfbb5d0b 100644 --- a/advisories/unreviewed/2025/02/GHSA-vp47-mv7q-f7h2/GHSA-vp47-mv7q-f7h2.json +++ b/advisories/unreviewed/2025/02/GHSA-vp47-mv7q-f7h2/GHSA-vp47-mv7q-f7h2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vp47-mv7q-f7h2", - "modified": "2025-02-03T21:31:50Z", + "modified": "2025-02-04T18:30:48Z", "published": "2025-02-03T21:31:50Z", "aliases": [ "CVE-2024-57669" ], "details": "Directory Traversal vulnerability in Zrlog backup-sql-file.jar v.3.0.31 allows a remote attacker to obtain sensitive information via the BackupController.java file.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-03T20:15:34Z" diff --git a/advisories/unreviewed/2025/02/GHSA-vvhj-43x9-x8ff/GHSA-vvhj-43x9-x8ff.json b/advisories/unreviewed/2025/02/GHSA-vvhj-43x9-x8ff/GHSA-vvhj-43x9-x8ff.json index e6cd1b6f99c..720b11d4b92 100644 --- a/advisories/unreviewed/2025/02/GHSA-vvhj-43x9-x8ff/GHSA-vvhj-43x9-x8ff.json +++ b/advisories/unreviewed/2025/02/GHSA-vvhj-43x9-x8ff/GHSA-vvhj-43x9-x8ff.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vvhj-43x9-x8ff", - "modified": "2025-02-03T21:31:50Z", + "modified": "2025-02-04T18:30:48Z", "published": "2025-02-03T21:31:50Z", "aliases": [ "CVE-2024-34896" ], "details": "An issue in Nedis SmartLife Video Doorbell (WIFICDP10GY), Nedis SmartLife IOS v1.4.0 causes users who are disconnected from a previous peer-to-peer connection with the device to still have access to live video feed.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -25,7 +30,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-03T21:15:12Z" diff --git a/advisories/unreviewed/2025/02/GHSA-w8hm-78qp-v45p/GHSA-w8hm-78qp-v45p.json b/advisories/unreviewed/2025/02/GHSA-w8hm-78qp-v45p/GHSA-w8hm-78qp-v45p.json index 0e66655bd6b..93f23751b67 100644 --- a/advisories/unreviewed/2025/02/GHSA-w8hm-78qp-v45p/GHSA-w8hm-78qp-v45p.json +++ b/advisories/unreviewed/2025/02/GHSA-w8hm-78qp-v45p/GHSA-w8hm-78qp-v45p.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w8hm-78qp-v45p", - "modified": "2025-02-03T21:31:50Z", + "modified": "2025-02-04T18:30:48Z", "published": "2025-02-03T21:31:50Z", "aliases": [ "CVE-2025-25064" ], "details": "SQL injection vulnerability in the ZimbraSyncService SOAP endpoint in Zimbra Collaboration 10.0.x before 10.0.12 and 10.1.x before 10.1.4.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-03T20:15:37Z" diff --git a/advisories/unreviewed/2025/02/GHSA-wgvg-989w-h74r/GHSA-wgvg-989w-h74r.json b/advisories/unreviewed/2025/02/GHSA-wgvg-989w-h74r/GHSA-wgvg-989w-h74r.json index ed9740f9abd..710d2e5c0c7 100644 --- a/advisories/unreviewed/2025/02/GHSA-wgvg-989w-h74r/GHSA-wgvg-989w-h74r.json +++ b/advisories/unreviewed/2025/02/GHSA-wgvg-989w-h74r/GHSA-wgvg-989w-h74r.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-wgvg-989w-h74r", - "modified": "2025-02-03T21:31:50Z", + "modified": "2025-02-04T18:30:48Z", "published": "2025-02-03T21:31:50Z", "aliases": [ "CVE-2024-57451" ], "details": "ChestnutCMS <=1.5.0 has a directory traversal vulnerability in contentcore.controller.FileController#getFileList, which allows attackers to view any directory.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-22" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-02-03T21:15:14Z"