From fb1363a2ae37930274dc7989256ea900955a6d44 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 24 Jan 2025 21:33:16 +0000 Subject: [PATCH] Advisory Database Sync --- .../GHSA-9wv6-86v2-598j.json | 6 +- .../GHSA-c4q5-6c82-3qpw.json | 6 +- .../GHSA-q3v6-hm2v-pw99.json | 6 +- .../GHSA-28jg-wmv9-mfgw.json | 1 + .../GHSA-2vjv-62j5-c7h3.json | 1 + .../GHSA-37v8-9c9h-3mqr.json | 1 + .../GHSA-468x-cmwp-xx5p.json | 1 + .../GHSA-9cj6-j99v-7v9w.json | 4 +- .../GHSA-f69p-jvr2-8j5x.json | 4 +- .../GHSA-hfvw-hqwf-qh99.json | 4 +- .../GHSA-j399-wjqp-rm25.json | 1 + .../GHSA-pxh3-rc47-3fvp.json | 1 + .../GHSA-w5q8-36w3-w88m.json | 3 +- .../GHSA-wqwx-rqf8-56vm.json | 1 + .../GHSA-6xmc-rr6q-vxqm.json | 3 +- .../GHSA-h288-5fq8-5pfw.json | 6 +- .../GHSA-27h7-5545-9242.json | 3 +- .../GHSA-3w6m-h87r-x45q.json | 56 +++++++++++++++++++ .../GHSA-46mv-5cpj-wjxv.json | 6 +- .../GHSA-4fp6-v5fm-gmq5.json | 2 +- .../GHSA-5c45-mgcf-3hhj.json | 3 +- .../GHSA-5wvx-g27j-hxx8.json | 6 +- .../GHSA-72hc-p753-5jcm.json | 37 ++++++++++++ .../GHSA-7g4r-w73h-m3xp.json | 15 +++-- .../GHSA-9349-rr4x-vwcg.json | 56 +++++++++++++++++++ .../GHSA-ch5m-r77h-m55x.json | 3 +- .../GHSA-fmwx-pf24-4xr8.json | 52 +++++++++++++++++ .../GHSA-g57h-qqhx-4ccp.json | 56 +++++++++++++++++++ .../GHSA-g623-4877-q5wj.json | 4 +- .../GHSA-gq6v-gg7f-p4rm.json | 4 +- .../GHSA-h95h-q9r2-fmg8.json | 48 ++++++++++++++++ .../GHSA-jp33-53rj-cx8p.json | 33 +++++++++++ .../GHSA-jvmq-2wfh-h2cw.json | 3 +- .../GHSA-prxw-w37v-wjgg.json | 15 +++-- .../GHSA-q375-28p2-pq93.json | 56 +++++++++++++++++++ .../GHSA-q4hm-qhcv-ghfp.json | 56 +++++++++++++++++++ .../GHSA-q798-pww9-q6hp.json | 15 +++-- .../GHSA-q8mh-7468-wg32.json | 56 +++++++++++++++++++ .../GHSA-r9fv-h47r-823f.json | 6 +- .../GHSA-vqr3-vrrg-f3jh.json | 37 ++++++++++++ .../GHSA-w5hq-hm5m-4548.json | 15 +++-- 41 files changed, 657 insertions(+), 35 deletions(-) create mode 100644 advisories/unreviewed/2025/01/GHSA-3w6m-h87r-x45q/GHSA-3w6m-h87r-x45q.json create mode 100644 advisories/unreviewed/2025/01/GHSA-72hc-p753-5jcm/GHSA-72hc-p753-5jcm.json create mode 100644 advisories/unreviewed/2025/01/GHSA-9349-rr4x-vwcg/GHSA-9349-rr4x-vwcg.json create mode 100644 advisories/unreviewed/2025/01/GHSA-fmwx-pf24-4xr8/GHSA-fmwx-pf24-4xr8.json create mode 100644 advisories/unreviewed/2025/01/GHSA-g57h-qqhx-4ccp/GHSA-g57h-qqhx-4ccp.json create mode 100644 advisories/unreviewed/2025/01/GHSA-h95h-q9r2-fmg8/GHSA-h95h-q9r2-fmg8.json create mode 100644 advisories/unreviewed/2025/01/GHSA-jp33-53rj-cx8p/GHSA-jp33-53rj-cx8p.json create mode 100644 advisories/unreviewed/2025/01/GHSA-q375-28p2-pq93/GHSA-q375-28p2-pq93.json create mode 100644 advisories/unreviewed/2025/01/GHSA-q4hm-qhcv-ghfp/GHSA-q4hm-qhcv-ghfp.json create mode 100644 advisories/unreviewed/2025/01/GHSA-q8mh-7468-wg32/GHSA-q8mh-7468-wg32.json create mode 100644 advisories/unreviewed/2025/01/GHSA-vqr3-vrrg-f3jh/GHSA-vqr3-vrrg-f3jh.json diff --git a/advisories/github-reviewed/2024/09/GHSA-9wv6-86v2-598j/GHSA-9wv6-86v2-598j.json b/advisories/github-reviewed/2024/09/GHSA-9wv6-86v2-598j/GHSA-9wv6-86v2-598j.json index 80b0b097323..f57a6b5424f 100644 --- a/advisories/github-reviewed/2024/09/GHSA-9wv6-86v2-598j/GHSA-9wv6-86v2-598j.json +++ b/advisories/github-reviewed/2024/09/GHSA-9wv6-86v2-598j/GHSA-9wv6-86v2-598j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9wv6-86v2-598j", - "modified": "2024-09-12T17:09:42Z", + "modified": "2025-01-24T21:31:27Z", "published": "2024-09-09T20:19:15Z", "aliases": [ "CVE-2024-45296" @@ -151,6 +151,10 @@ { "type": "WEB", "url": "https://github.com/pillarjs/path-to-regexp/releases/tag/v6.3.0" + }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250124-0001" } ], "database_specific": { diff --git a/advisories/github-reviewed/2024/10/GHSA-c4q5-6c82-3qpw/GHSA-c4q5-6c82-3qpw.json b/advisories/github-reviewed/2024/10/GHSA-c4q5-6c82-3qpw/GHSA-c4q5-6c82-3qpw.json index 1692b3916d9..bd6487f3f7b 100644 --- a/advisories/github-reviewed/2024/10/GHSA-c4q5-6c82-3qpw/GHSA-c4q5-6c82-3qpw.json +++ b/advisories/github-reviewed/2024/10/GHSA-c4q5-6c82-3qpw/GHSA-c4q5-6c82-3qpw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c4q5-6c82-3qpw", - "modified": "2024-10-28T17:59:29Z", + "modified": "2025-01-24T21:31:27Z", "published": "2024-10-28T09:30:53Z", "aliases": [ "CVE-2024-38821" @@ -151,6 +151,10 @@ "type": "PACKAGE", "url": "https://github.com/spring-projects/spring-security" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250124-0006" + }, { "type": "WEB", "url": "https://spring.io/security/cve-2024-38821" diff --git a/advisories/github-reviewed/2024/12/GHSA-q3v6-hm2v-pw99/GHSA-q3v6-hm2v-pw99.json b/advisories/github-reviewed/2024/12/GHSA-q3v6-hm2v-pw99/GHSA-q3v6-hm2v-pw99.json index 30ead4bd062..973b8784f01 100644 --- a/advisories/github-reviewed/2024/12/GHSA-q3v6-hm2v-pw99/GHSA-q3v6-hm2v-pw99.json +++ b/advisories/github-reviewed/2024/12/GHSA-q3v6-hm2v-pw99/GHSA-q3v6-hm2v-pw99.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-q3v6-hm2v-pw99", - "modified": "2025-01-10T15:59:23Z", + "modified": "2025-01-24T21:31:27Z", "published": "2024-12-02T15:31:41Z", "aliases": [ "CVE-2024-38827" @@ -155,6 +155,10 @@ "type": "PACKAGE", "url": "https://github.com/spring-projects/spring-security" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250124-0007" + }, { "type": "WEB", "url": "https://spring.io/security/cve-2024-38827" diff --git a/advisories/unreviewed/2023/05/GHSA-28jg-wmv9-mfgw/GHSA-28jg-wmv9-mfgw.json b/advisories/unreviewed/2023/05/GHSA-28jg-wmv9-mfgw/GHSA-28jg-wmv9-mfgw.json index 7a4b24c8524..7685f8665b9 100644 --- a/advisories/unreviewed/2023/05/GHSA-28jg-wmv9-mfgw/GHSA-28jg-wmv9-mfgw.json +++ b/advisories/unreviewed/2023/05/GHSA-28jg-wmv9-mfgw/GHSA-28jg-wmv9-mfgw.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1284", "CWE-20" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2023/05/GHSA-2vjv-62j5-c7h3/GHSA-2vjv-62j5-c7h3.json b/advisories/unreviewed/2023/05/GHSA-2vjv-62j5-c7h3/GHSA-2vjv-62j5-c7h3.json index 512c85cf7ba..a88bb1e4d05 100644 --- a/advisories/unreviewed/2023/05/GHSA-2vjv-62j5-c7h3/GHSA-2vjv-62j5-c7h3.json +++ b/advisories/unreviewed/2023/05/GHSA-2vjv-62j5-c7h3/GHSA-2vjv-62j5-c7h3.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1284", "CWE-20" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2023/05/GHSA-37v8-9c9h-3mqr/GHSA-37v8-9c9h-3mqr.json b/advisories/unreviewed/2023/05/GHSA-37v8-9c9h-3mqr/GHSA-37v8-9c9h-3mqr.json index 620edb49d60..d8214e9b5dd 100644 --- a/advisories/unreviewed/2023/05/GHSA-37v8-9c9h-3mqr/GHSA-37v8-9c9h-3mqr.json +++ b/advisories/unreviewed/2023/05/GHSA-37v8-9c9h-3mqr/GHSA-37v8-9c9h-3mqr.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1284", "CWE-20" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2023/05/GHSA-468x-cmwp-xx5p/GHSA-468x-cmwp-xx5p.json b/advisories/unreviewed/2023/05/GHSA-468x-cmwp-xx5p/GHSA-468x-cmwp-xx5p.json index 5966c89f998..fd968b8cbf5 100644 --- a/advisories/unreviewed/2023/05/GHSA-468x-cmwp-xx5p/GHSA-468x-cmwp-xx5p.json +++ b/advisories/unreviewed/2023/05/GHSA-468x-cmwp-xx5p/GHSA-468x-cmwp-xx5p.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1284", "CWE-20" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2023/05/GHSA-9cj6-j99v-7v9w/GHSA-9cj6-j99v-7v9w.json b/advisories/unreviewed/2023/05/GHSA-9cj6-j99v-7v9w/GHSA-9cj6-j99v-7v9w.json index 04fc74e2312..6cfade75bfd 100644 --- a/advisories/unreviewed/2023/05/GHSA-9cj6-j99v-7v9w/GHSA-9cj6-j99v-7v9w.json +++ b/advisories/unreviewed/2023/05/GHSA-9cj6-j99v-7v9w/GHSA-9cj6-j99v-7v9w.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-770" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/05/GHSA-f69p-jvr2-8j5x/GHSA-f69p-jvr2-8j5x.json b/advisories/unreviewed/2023/05/GHSA-f69p-jvr2-8j5x/GHSA-f69p-jvr2-8j5x.json index dd2db0ac3c0..bab7b357cb4 100644 --- a/advisories/unreviewed/2023/05/GHSA-f69p-jvr2-8j5x/GHSA-f69p-jvr2-8j5x.json +++ b/advisories/unreviewed/2023/05/GHSA-f69p-jvr2-8j5x/GHSA-f69p-jvr2-8j5x.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-426" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/05/GHSA-hfvw-hqwf-qh99/GHSA-hfvw-hqwf-qh99.json b/advisories/unreviewed/2023/05/GHSA-hfvw-hqwf-qh99/GHSA-hfvw-hqwf-qh99.json index 2f50b7d75bf..3060274c7f8 100644 --- a/advisories/unreviewed/2023/05/GHSA-hfvw-hqwf-qh99/GHSA-hfvw-hqwf-qh99.json +++ b/advisories/unreviewed/2023/05/GHSA-hfvw-hqwf-qh99/GHSA-hfvw-hqwf-qh99.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-426" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2023/05/GHSA-j399-wjqp-rm25/GHSA-j399-wjqp-rm25.json b/advisories/unreviewed/2023/05/GHSA-j399-wjqp-rm25/GHSA-j399-wjqp-rm25.json index 9c4ceb65289..08f4134cb9a 100644 --- a/advisories/unreviewed/2023/05/GHSA-j399-wjqp-rm25/GHSA-j399-wjqp-rm25.json +++ b/advisories/unreviewed/2023/05/GHSA-j399-wjqp-rm25/GHSA-j399-wjqp-rm25.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1284", "CWE-20" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2023/05/GHSA-pxh3-rc47-3fvp/GHSA-pxh3-rc47-3fvp.json b/advisories/unreviewed/2023/05/GHSA-pxh3-rc47-3fvp/GHSA-pxh3-rc47-3fvp.json index 4bc74e7f6a8..6c9a66d1af9 100644 --- a/advisories/unreviewed/2023/05/GHSA-pxh3-rc47-3fvp/GHSA-pxh3-rc47-3fvp.json +++ b/advisories/unreviewed/2023/05/GHSA-pxh3-rc47-3fvp/GHSA-pxh3-rc47-3fvp.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1284", "CWE-20" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2023/05/GHSA-w5q8-36w3-w88m/GHSA-w5q8-36w3-w88m.json b/advisories/unreviewed/2023/05/GHSA-w5q8-36w3-w88m/GHSA-w5q8-36w3-w88m.json index a1f7ea2af00..dda443c1852 100644 --- a/advisories/unreviewed/2023/05/GHSA-w5q8-36w3-w88m/GHSA-w5q8-36w3-w88m.json +++ b/advisories/unreviewed/2023/05/GHSA-w5q8-36w3-w88m/GHSA-w5q8-36w3-w88m.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-287" + "CWE-287", + "CWE-295" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2023/05/GHSA-wqwx-rqf8-56vm/GHSA-wqwx-rqf8-56vm.json b/advisories/unreviewed/2023/05/GHSA-wqwx-rqf8-56vm/GHSA-wqwx-rqf8-56vm.json index a96b4cbf5fe..10e30fe6fd8 100644 --- a/advisories/unreviewed/2023/05/GHSA-wqwx-rqf8-56vm/GHSA-wqwx-rqf8-56vm.json +++ b/advisories/unreviewed/2023/05/GHSA-wqwx-rqf8-56vm/GHSA-wqwx-rqf8-56vm.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-1284", "CWE-20" ], "severity": "MODERATE", diff --git a/advisories/unreviewed/2024/03/GHSA-6xmc-rr6q-vxqm/GHSA-6xmc-rr6q-vxqm.json b/advisories/unreviewed/2024/03/GHSA-6xmc-rr6q-vxqm/GHSA-6xmc-rr6q-vxqm.json index a7218590d65..4d5777260b9 100644 --- a/advisories/unreviewed/2024/03/GHSA-6xmc-rr6q-vxqm/GHSA-6xmc-rr6q-vxqm.json +++ b/advisories/unreviewed/2024/03/GHSA-6xmc-rr6q-vxqm/GHSA-6xmc-rr6q-vxqm.json @@ -34,7 +34,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-121" + "CWE-121", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/12/GHSA-h288-5fq8-5pfw/GHSA-h288-5fq8-5pfw.json b/advisories/unreviewed/2024/12/GHSA-h288-5fq8-5pfw/GHSA-h288-5fq8-5pfw.json index 8edc6581704..46352a9f5d0 100644 --- a/advisories/unreviewed/2024/12/GHSA-h288-5fq8-5pfw/GHSA-h288-5fq8-5pfw.json +++ b/advisories/unreviewed/2024/12/GHSA-h288-5fq8-5pfw/GHSA-h288-5fq8-5pfw.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-h288-5fq8-5pfw", - "modified": "2024-12-11T15:31:16Z", + "modified": "2025-01-24T21:31:27Z", "published": "2024-12-11T09:32:03Z", "aliases": [ "CVE-2024-11053" @@ -31,6 +31,10 @@ "type": "WEB", "url": "https://curl.se/docs/CVE-2024-11053.json" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250124-0012" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2024/12/11/1" diff --git a/advisories/unreviewed/2025/01/GHSA-27h7-5545-9242/GHSA-27h7-5545-9242.json b/advisories/unreviewed/2025/01/GHSA-27h7-5545-9242/GHSA-27h7-5545-9242.json index fc33c500e06..777a703120a 100644 --- a/advisories/unreviewed/2025/01/GHSA-27h7-5545-9242/GHSA-27h7-5545-9242.json +++ b/advisories/unreviewed/2025/01/GHSA-27h7-5545-9242/GHSA-27h7-5545-9242.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-120" + "CWE-120", + "CWE-787" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-3w6m-h87r-x45q/GHSA-3w6m-h87r-x45q.json b/advisories/unreviewed/2025/01/GHSA-3w6m-h87r-x45q/GHSA-3w6m-h87r-x45q.json new file mode 100644 index 00000000000..b2ece147217 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-3w6m-h87r-x45q/GHSA-3w6m-h87r-x45q.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-3w6m-h87r-x45q", + "modified": "2025-01-24T21:31:28Z", + "published": "2025-01-24T21:31:28Z", + "aliases": [ + "CVE-2025-0710" + ], + "details": "A vulnerability classified as problematic has been found in CampCodes School Management Software 1.0. Affected is an unknown function of the file /notice-list of the component Notice Board Page. The manipulation of the argument Notice leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0710" + }, + { + "type": "WEB", + "url": "https://github.com/anamika126/Stackofvulnerabilities/blob/main/Stored%20Cross%20Site%20Scripting%20-%20Notice%20Board.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.293238" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.293238" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.484934" + }, + { + "type": "WEB", + "url": "https://www.campcodes.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T21:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-46mv-5cpj-wjxv/GHSA-46mv-5cpj-wjxv.json b/advisories/unreviewed/2025/01/GHSA-46mv-5cpj-wjxv/GHSA-46mv-5cpj-wjxv.json index 4d37e7c6797..f274610da86 100644 --- a/advisories/unreviewed/2025/01/GHSA-46mv-5cpj-wjxv/GHSA-46mv-5cpj-wjxv.json +++ b/advisories/unreviewed/2025/01/GHSA-46mv-5cpj-wjxv/GHSA-46mv-5cpj-wjxv.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-46mv-5cpj-wjxv", - "modified": "2025-01-21T21:30:55Z", + "modified": "2025-01-24T21:31:27Z", "published": "2025-01-21T21:30:55Z", "aliases": [ "CVE-2025-21502" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21502" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250124-0009" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpujan2025.html" diff --git a/advisories/unreviewed/2025/01/GHSA-4fp6-v5fm-gmq5/GHSA-4fp6-v5fm-gmq5.json b/advisories/unreviewed/2025/01/GHSA-4fp6-v5fm-gmq5/GHSA-4fp6-v5fm-gmq5.json index 32e80e48693..f7a51a102e2 100644 --- a/advisories/unreviewed/2025/01/GHSA-4fp6-v5fm-gmq5/GHSA-4fp6-v5fm-gmq5.json +++ b/advisories/unreviewed/2025/01/GHSA-4fp6-v5fm-gmq5/GHSA-4fp6-v5fm-gmq5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-4fp6-v5fm-gmq5", - "modified": "2025-01-22T09:32:01Z", + "modified": "2025-01-24T21:31:27Z", "published": "2025-01-22T09:32:01Z", "aliases": [ "CVE-2024-12117" diff --git a/advisories/unreviewed/2025/01/GHSA-5c45-mgcf-3hhj/GHSA-5c45-mgcf-3hhj.json b/advisories/unreviewed/2025/01/GHSA-5c45-mgcf-3hhj/GHSA-5c45-mgcf-3hhj.json index b5fd9ec2ece..7a2af7ff276 100644 --- a/advisories/unreviewed/2025/01/GHSA-5c45-mgcf-3hhj/GHSA-5c45-mgcf-3hhj.json +++ b/advisories/unreviewed/2025/01/GHSA-5c45-mgcf-3hhj/GHSA-5c45-mgcf-3hhj.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-256" + "CWE-256", + "CWE-522" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-5wvx-g27j-hxx8/GHSA-5wvx-g27j-hxx8.json b/advisories/unreviewed/2025/01/GHSA-5wvx-g27j-hxx8/GHSA-5wvx-g27j-hxx8.json index 9f16ecaae25..e76965168b7 100644 --- a/advisories/unreviewed/2025/01/GHSA-5wvx-g27j-hxx8/GHSA-5wvx-g27j-hxx8.json +++ b/advisories/unreviewed/2025/01/GHSA-5wvx-g27j-hxx8/GHSA-5wvx-g27j-hxx8.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-5wvx-g27j-hxx8", - "modified": "2025-01-21T21:30:55Z", + "modified": "2025-01-24T21:31:27Z", "published": "2025-01-21T21:30:55Z", "aliases": [ "CVE-2025-21492" @@ -19,6 +19,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-21492" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250124-0011" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpujan2025.html" diff --git a/advisories/unreviewed/2025/01/GHSA-72hc-p753-5jcm/GHSA-72hc-p753-5jcm.json b/advisories/unreviewed/2025/01/GHSA-72hc-p753-5jcm/GHSA-72hc-p753-5jcm.json new file mode 100644 index 00000000000..822d9c4cbea --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-72hc-p753-5jcm/GHSA-72hc-p753-5jcm.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-72hc-p753-5jcm", + "modified": "2025-01-24T21:31:28Z", + "published": "2025-01-24T21:31:28Z", + "aliases": [ + "CVE-2024-57277" + ], + "details": "InnoShop V.0.3.8 and below is vulnerable to Cross Site Scripting (XSS) via SVG file upload.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57277" + }, + { + "type": "WEB", + "url": "https://github.com/innocommerce/innoshop/issues/115" + }, + { + "type": "WEB", + "url": "https://github.com/yamerooo123/ResearchNBugBountyEncyclopedia/blob/main/Researches/Innocommerce/Findings.md" + }, + { + "type": "WEB", + "url": "https://youtu.be/ved96wsIYlQ" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T20:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-7g4r-w73h-m3xp/GHSA-7g4r-w73h-m3xp.json b/advisories/unreviewed/2025/01/GHSA-7g4r-w73h-m3xp/GHSA-7g4r-w73h-m3xp.json index 3c859010dd9..cdbe4e6e306 100644 --- a/advisories/unreviewed/2025/01/GHSA-7g4r-w73h-m3xp/GHSA-7g4r-w73h-m3xp.json +++ b/advisories/unreviewed/2025/01/GHSA-7g4r-w73h-m3xp/GHSA-7g4r-w73h-m3xp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-7g4r-w73h-m3xp", - "modified": "2025-01-22T00:33:35Z", + "modified": "2025-01-24T21:31:27Z", "published": "2025-01-22T00:33:35Z", "aliases": [ "CVE-2024-24442" ], "details": "A NULL pointer dereference in the ngap_app::handle_receive routine of OpenAirInterface CN5G AMF (oai-cn5g-amf) up to v2.0.0 allows attackers to cause a Denial of Service (DoS) via a crafted NGAP message.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-476" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-21T22:15:11Z" diff --git a/advisories/unreviewed/2025/01/GHSA-9349-rr4x-vwcg/GHSA-9349-rr4x-vwcg.json b/advisories/unreviewed/2025/01/GHSA-9349-rr4x-vwcg/GHSA-9349-rr4x-vwcg.json new file mode 100644 index 00000000000..4521f7e7759 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-9349-rr4x-vwcg/GHSA-9349-rr4x-vwcg.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9349-rr4x-vwcg", + "modified": "2025-01-24T21:31:28Z", + "published": "2025-01-24T21:31:28Z", + "aliases": [ + "CVE-2025-0705" + ], + "details": "A vulnerability has been found in JoeyBling bootplus up to 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d and classified as problematic. Affected by this vulnerability is the function qrCode of the file src/main/java/io/github/controller/QrCodeController.java. The manipulation of the argument text leads to open redirect. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0705" + }, + { + "type": "WEB", + "url": "https://github.com/JoeyBling/bootplus/issues/27" + }, + { + "type": "WEB", + "url": "https://github.com/JoeyBling/bootplus/issues/27#issue-2786941847" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.293233" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.293233" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.480844" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-601" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T19:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-ch5m-r77h-m55x/GHSA-ch5m-r77h-m55x.json b/advisories/unreviewed/2025/01/GHSA-ch5m-r77h-m55x/GHSA-ch5m-r77h-m55x.json index 25690fce9ba..f14ba57ed7b 100644 --- a/advisories/unreviewed/2025/01/GHSA-ch5m-r77h-m55x/GHSA-ch5m-r77h-m55x.json +++ b/advisories/unreviewed/2025/01/GHSA-ch5m-r77h-m55x/GHSA-ch5m-r77h-m55x.json @@ -30,7 +30,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-288" + "CWE-288", + "CWE-306" ], "severity": "CRITICAL", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-fmwx-pf24-4xr8/GHSA-fmwx-pf24-4xr8.json b/advisories/unreviewed/2025/01/GHSA-fmwx-pf24-4xr8/GHSA-fmwx-pf24-4xr8.json new file mode 100644 index 00000000000..ed19d6270da --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-fmwx-pf24-4xr8/GHSA-fmwx-pf24-4xr8.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fmwx-pf24-4xr8", + "modified": "2025-01-24T21:31:28Z", + "published": "2025-01-24T21:31:28Z", + "aliases": [ + "CVE-2025-0708" + ], + "details": "A vulnerability was found in fumiao opencms 2.2. It has been declared as problematic. This vulnerability affects unknown code of the file /admin/model/addOrUpdate of the component Add Model Management Page. The manipulation of the argument 模板前缀 leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0708" + }, + { + "type": "WEB", + "url": "https://gitee.com/fumiao/opencms/issues/IBI2XM" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.293236" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.293236" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.482662" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T20:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-g57h-qqhx-4ccp/GHSA-g57h-qqhx-4ccp.json b/advisories/unreviewed/2025/01/GHSA-g57h-qqhx-4ccp/GHSA-g57h-qqhx-4ccp.json new file mode 100644 index 00000000000..3a670e0b63d --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-g57h-qqhx-4ccp/GHSA-g57h-qqhx-4ccp.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g57h-qqhx-4ccp", + "modified": "2025-01-24T21:31:28Z", + "published": "2025-01-24T21:31:28Z", + "aliases": [ + "CVE-2025-0704" + ], + "details": "A vulnerability, which was classified as problematic, was found in JoeyBling bootplus up to 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d. Affected is the function qrCode of the file src/main/java/io/github/controller/QrCodeController.java. The manipulation of the argument w/h leads to resource consumption. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0704" + }, + { + "type": "WEB", + "url": "https://github.com/JoeyBling/bootplus/issues/26" + }, + { + "type": "WEB", + "url": "https://github.com/JoeyBling/bootplus/issues/26#issue-2786934642" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.293232" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.293232" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.480843" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-400" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T19:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-g623-4877-q5wj/GHSA-g623-4877-q5wj.json b/advisories/unreviewed/2025/01/GHSA-g623-4877-q5wj/GHSA-g623-4877-q5wj.json index 7f97b268809..1b6f6731d5c 100644 --- a/advisories/unreviewed/2025/01/GHSA-g623-4877-q5wj/GHSA-g623-4877-q5wj.json +++ b/advisories/unreviewed/2025/01/GHSA-g623-4877-q5wj/GHSA-g623-4877-q5wj.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-89" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-gq6v-gg7f-p4rm/GHSA-gq6v-gg7f-p4rm.json b/advisories/unreviewed/2025/01/GHSA-gq6v-gg7f-p4rm/GHSA-gq6v-gg7f-p4rm.json index e85dc880c54..027ac5dae38 100644 --- a/advisories/unreviewed/2025/01/GHSA-gq6v-gg7f-p4rm/GHSA-gq6v-gg7f-p4rm.json +++ b/advisories/unreviewed/2025/01/GHSA-gq6v-gg7f-p4rm/GHSA-gq6v-gg7f-p4rm.json @@ -29,7 +29,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-89" + ], "severity": "CRITICAL", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/01/GHSA-h95h-q9r2-fmg8/GHSA-h95h-q9r2-fmg8.json b/advisories/unreviewed/2025/01/GHSA-h95h-q9r2-fmg8/GHSA-h95h-q9r2-fmg8.json new file mode 100644 index 00000000000..6354c174faf --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-h95h-q9r2-fmg8/GHSA-h95h-q9r2-fmg8.json @@ -0,0 +1,48 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h95h-q9r2-fmg8", + "modified": "2025-01-24T21:31:28Z", + "published": "2025-01-24T21:31:28Z", + "aliases": [ + "CVE-2025-0707" + ], + "details": "A vulnerability was found in Rise Group Rise Mode Temp CPU 2.1. It has been classified as critical. This affects an unknown part in the library CRYPTBASE.dll of the component Startup. The manipulation leads to untrusted search path. The attack needs to be approached locally.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0707" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.293235" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.293235" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.481088" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-426" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T20:15:34Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-jp33-53rj-cx8p/GHSA-jp33-53rj-cx8p.json b/advisories/unreviewed/2025/01/GHSA-jp33-53rj-cx8p/GHSA-jp33-53rj-cx8p.json new file mode 100644 index 00000000000..35903e15bcb --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-jp33-53rj-cx8p/GHSA-jp33-53rj-cx8p.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jp33-53rj-cx8p", + "modified": "2025-01-24T21:31:27Z", + "published": "2025-01-24T21:31:27Z", + "aliases": [ + "CVE-2024-57095" + ], + "details": "SQL injection vulnerability in Go-CMS v.1.1.10 allows a remote attacker to execute arbitrary code via a crafted payload.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57095" + }, + { + "type": "WEB", + "url": "https://github.com/Xi-Yuer/GO-CMS/issues/6" + }, + { + "type": "WEB", + "url": "https://gist.github.com/wjlin0/ff3ee8afb8f8001faff89bbc03805605" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T20:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-jvmq-2wfh-h2cw/GHSA-jvmq-2wfh-h2cw.json b/advisories/unreviewed/2025/01/GHSA-jvmq-2wfh-h2cw/GHSA-jvmq-2wfh-h2cw.json index 62912a41f13..654017e2eca 100644 --- a/advisories/unreviewed/2025/01/GHSA-jvmq-2wfh-h2cw/GHSA-jvmq-2wfh-h2cw.json +++ b/advisories/unreviewed/2025/01/GHSA-jvmq-2wfh-h2cw/GHSA-jvmq-2wfh-h2cw.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-256" + "CWE-256", + "CWE-522" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2025/01/GHSA-prxw-w37v-wjgg/GHSA-prxw-w37v-wjgg.json b/advisories/unreviewed/2025/01/GHSA-prxw-w37v-wjgg/GHSA-prxw-w37v-wjgg.json index 1d6d0c9df9c..a3ebfd91e97 100644 --- a/advisories/unreviewed/2025/01/GHSA-prxw-w37v-wjgg/GHSA-prxw-w37v-wjgg.json +++ b/advisories/unreviewed/2025/01/GHSA-prxw-w37v-wjgg/GHSA-prxw-w37v-wjgg.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-prxw-w37v-wjgg", - "modified": "2025-01-22T00:33:35Z", + "modified": "2025-01-24T21:31:27Z", "published": "2025-01-22T00:33:35Z", "aliases": [ "CVE-2024-24451" ], "details": "A stack overflow in the sctp_server::sctp_receiver_thread component of OpenAirInterface CN5G AMF (oai-cn5g-amf) up to v2.0.0 allows attackers to cause a Denial of Service (DoS) by repeatedly establishing SCTP connections with the N2 interface.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], "affected": [], "references": [ { @@ -24,8 +29,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-21T22:15:12Z" diff --git a/advisories/unreviewed/2025/01/GHSA-q375-28p2-pq93/GHSA-q375-28p2-pq93.json b/advisories/unreviewed/2025/01/GHSA-q375-28p2-pq93/GHSA-q375-28p2-pq93.json new file mode 100644 index 00000000000..9808731740f --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-q375-28p2-pq93/GHSA-q375-28p2-pq93.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q375-28p2-pq93", + "modified": "2025-01-24T21:31:28Z", + "published": "2025-01-24T21:31:28Z", + "aliases": [ + "CVE-2025-0703" + ], + "details": "A vulnerability, which was classified as problematic, has been found in JoeyBling bootplus up to 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d. This issue affects some unknown processing of the file src/main/java/io/github/controller/SysFileController.java. The manipulation of the argument name leads to path traversal. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0703" + }, + { + "type": "WEB", + "url": "https://github.com/JoeyBling/bootplus/issues/25" + }, + { + "type": "WEB", + "url": "https://github.com/JoeyBling/bootplus/issues/25#issue-2786928618" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.293231" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.293231" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.480842" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T19:15:13Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-q4hm-qhcv-ghfp/GHSA-q4hm-qhcv-ghfp.json b/advisories/unreviewed/2025/01/GHSA-q4hm-qhcv-ghfp/GHSA-q4hm-qhcv-ghfp.json new file mode 100644 index 00000000000..2529a345da7 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-q4hm-qhcv-ghfp/GHSA-q4hm-qhcv-ghfp.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q4hm-qhcv-ghfp", + "modified": "2025-01-24T21:31:28Z", + "published": "2025-01-24T21:31:28Z", + "aliases": [ + "CVE-2025-0706" + ], + "details": "A vulnerability was found in JoeyBling bootplus up to 247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/sys/admin.html. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0706" + }, + { + "type": "WEB", + "url": "https://github.com/JoeyBling/bootplus/issues/28" + }, + { + "type": "WEB", + "url": "https://github.com/JoeyBling/bootplus/issues/28#issue-2786945699" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.293234" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.293234" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.480845" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T20:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-q798-pww9-q6hp/GHSA-q798-pww9-q6hp.json b/advisories/unreviewed/2025/01/GHSA-q798-pww9-q6hp/GHSA-q798-pww9-q6hp.json index 0b7eccb4086..c70224be73a 100644 --- a/advisories/unreviewed/2025/01/GHSA-q798-pww9-q6hp/GHSA-q798-pww9-q6hp.json +++ b/advisories/unreviewed/2025/01/GHSA-q798-pww9-q6hp/GHSA-q798-pww9-q6hp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-q798-pww9-q6hp", - "modified": "2025-01-24T00:31:46Z", + "modified": "2025-01-24T21:31:27Z", "published": "2025-01-24T00:31:46Z", "aliases": [ "CVE-2023-46400" ], "details": "KWHotel 0.47 is vulnerable to CSV Formula Injection in the add guest function.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-1236" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-23T22:15:12Z" diff --git a/advisories/unreviewed/2025/01/GHSA-q8mh-7468-wg32/GHSA-q8mh-7468-wg32.json b/advisories/unreviewed/2025/01/GHSA-q8mh-7468-wg32/GHSA-q8mh-7468-wg32.json new file mode 100644 index 00000000000..7b790cf2268 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-q8mh-7468-wg32/GHSA-q8mh-7468-wg32.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q8mh-7468-wg32", + "modified": "2025-01-24T21:31:28Z", + "published": "2025-01-24T21:31:28Z", + "aliases": [ + "CVE-2025-0709" + ], + "details": "A vulnerability was found in Dcat-Admin 2.2.1-beta. It has been rated as problematic. This issue affects some unknown processing of the file /admin/auth/roles of the component Roles Page. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0709" + }, + { + "type": "WEB", + "url": "https://github.com/taynes-llllzt/taynes/issues/7" + }, + { + "type": "WEB", + "url": "https://github.com/taynes-llllzt/taynes/issues/7#issue-2792259251" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.293237" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.293237" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.483364" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T21:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-r9fv-h47r-823f/GHSA-r9fv-h47r-823f.json b/advisories/unreviewed/2025/01/GHSA-r9fv-h47r-823f/GHSA-r9fv-h47r-823f.json index 3a1fcffc4ae..d89041fa84e 100644 --- a/advisories/unreviewed/2025/01/GHSA-r9fv-h47r-823f/GHSA-r9fv-h47r-823f.json +++ b/advisories/unreviewed/2025/01/GHSA-r9fv-h47r-823f/GHSA-r9fv-h47r-823f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-r9fv-h47r-823f", - "modified": "2025-01-20T18:30:49Z", + "modified": "2025-01-24T21:31:27Z", "published": "2025-01-20T15:31:22Z", "aliases": [ "CVE-2024-13176" @@ -46,6 +46,10 @@ "type": "WEB", "url": "https://openssl-library.org/news/secadv/20250120.txt" }, + { + "type": "WEB", + "url": "https://security.netapp.com/advisory/ntap-20250124-0005" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2025/01/20/2" diff --git a/advisories/unreviewed/2025/01/GHSA-vqr3-vrrg-f3jh/GHSA-vqr3-vrrg-f3jh.json b/advisories/unreviewed/2025/01/GHSA-vqr3-vrrg-f3jh/GHSA-vqr3-vrrg-f3jh.json new file mode 100644 index 00000000000..71830555e3f --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-vqr3-vrrg-f3jh/GHSA-vqr3-vrrg-f3jh.json @@ -0,0 +1,37 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vqr3-vrrg-f3jh", + "modified": "2025-01-24T21:31:28Z", + "published": "2025-01-24T21:31:27Z", + "aliases": [ + "CVE-2024-57041" + ], + "details": "A persistent cross-site scripting (XSS) vulnerability in NodeBB v3.11.0 allows remote attackers to store arbitrary code in the 'about me' section of their profile.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57041" + }, + { + "type": "WEB", + "url": "https://github.com/NodeBB/NodeBB/commit/4e69bff72fd04779064d37e46a43080e6c328adf" + }, + { + "type": "WEB", + "url": "https://www.tonysec.com/posts/cve-2024-57041" + }, + { + "type": "WEB", + "url": "http://nodebb.com" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-24T20:15:33Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-w5hq-hm5m-4548/GHSA-w5hq-hm5m-4548.json b/advisories/unreviewed/2025/01/GHSA-w5hq-hm5m-4548/GHSA-w5hq-hm5m-4548.json index dfc3cd4fb25..094153de5df 100644 --- a/advisories/unreviewed/2025/01/GHSA-w5hq-hm5m-4548/GHSA-w5hq-hm5m-4548.json +++ b/advisories/unreviewed/2025/01/GHSA-w5hq-hm5m-4548/GHSA-w5hq-hm5m-4548.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-w5hq-hm5m-4548", - "modified": "2025-01-24T00:31:47Z", + "modified": "2025-01-24T21:31:27Z", "published": "2025-01-24T00:31:47Z", "aliases": [ "CVE-2024-57556" ], "details": "Cross Site Scripting vulnerability in nbubna store v.2.14.2 and before allows a remote attacker to execute arbitrary code via the store.deep.js component", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-01-23T22:15:15Z"