File tree Expand file tree Collapse file tree 3 files changed +71
-31
lines changed
2022/05/GHSA-qrf6-h5fc-7m96
2025/06/GHSA-rvqx-wpfh-mfx7
unreviewed/2022/05/GHSA-qrf6-h5fc-7m96 Expand file tree Collapse file tree 3 files changed +71
-31
lines changed Original file line number Diff line number Diff line change 1+ {
2+ "schema_version" : " 1.4.0" ,
3+ "id" : " GHSA-qrf6-h5fc-7m96" ,
4+ "modified" : " 2025-10-22T19:47:35Z" ,
5+ "published" : " 2022-05-24T17:21:01Z" ,
6+ "aliases" : [
7+ " CVE-2016-11069"
8+ ],
9+ "summary" : " Mattermost Server does not enforce rate limits on password change attempts" ,
10+ "details" : " An issue was discovered in Mattermost Server before 3.2.0. It mishandles brute-force attempts at password change." ,
11+ "severity" : [
12+ {
13+ "type" : " CVSS_V3" ,
14+ "score" : " CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
15+ }
16+ ],
17+ "affected" : [
18+ {
19+ "package" : {
20+ "ecosystem" : " Go" ,
21+ "name" : " github.com/mattermost/mattermost-server"
22+ },
23+ "ranges" : [
24+ {
25+ "type" : " ECOSYSTEM" ,
26+ "events" : [
27+ {
28+ "introduced" : " 0"
29+ },
30+ {
31+ "fixed" : " 3.2.0"
32+ }
33+ ]
34+ }
35+ ]
36+ }
37+ ],
38+ "references" : [
39+ {
40+ "type" : " ADVISORY" ,
41+ "url" : " https://nvd.nist.gov/vuln/detail/CVE-2016-11069"
42+ },
43+ {
44+ "type" : " WEB" ,
45+ "url" : " https://github.com/mattermost/mattermost/commit/c976c2881ce5e34febac8a9850a6bad5d728625e"
46+ },
47+ {
48+ "type" : " PACKAGE" ,
49+ "url" : " https://github.com/mattermost/mattermost"
50+ },
51+ {
52+ "type" : " WEB" ,
53+ "url" : " https://mattermost.com/security-updates"
54+ }
55+ ],
56+ "database_specific" : {
57+ "cwe_ids" : [
58+ " CWE-799"
59+ ],
60+ "severity" : " HIGH" ,
61+ "github_reviewed" : true ,
62+ "github_reviewed_at" : " 2025-10-22T19:47:35Z" ,
63+ "nvd_published_at" : " 2020-06-19T20:15:00Z"
64+ }
65+ }
Original file line number Diff line number Diff line change 11{
22 "schema_version" : " 1.4.0" ,
33 "id" : " GHSA-rvqx-wpfh-mfx7" ,
4- "modified" : " 2025-06-30T14:54:12Z " ,
4+ "modified" : " 2025-10-22T19:48:26Z " ,
55 "published" : " 2025-06-17T20:14:26Z" ,
66 "aliases" : [
77 " CVE-2025-3248"
1111 "severity" : [
1212 {
1313 "type" : " CVSS_V4" ,
14- "score" : " CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
14+ "score" : " CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:A "
1515 }
1616 ],
1717 "affected" : [
7979 "type" : " WEB" ,
8080 "url" : " https://github.com/langflow-ai/langflow/releases/tag/1.3.0"
8181 },
82+ {
83+ "type" : " WEB" ,
84+ "url" : " https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-3248"
85+ },
8286 {
8387 "type" : " WEB" ,
8488 "url" : " https://www.horizon3.ai/attack-research/disclosures/unsafe-at-any-speed-abusing-python-exec-for-unauth-rce-in-langflow-ai"
Load Diff This file was deleted.
You can’t perform that action at this time.
0 commit comments