File tree Expand file tree Collapse file tree 4 files changed +144
-0
lines changed
advisories/unreviewed/2025/10 Expand file tree Collapse file tree 4 files changed +144
-0
lines changed Original file line number Diff line number Diff line change 1+ {
2+ "schema_version" : " 1.4.0" ,
3+ "id" : " GHSA-54cc-2jj5-99fc" ,
4+ "modified" : " 2025-10-26T18:30:16Z" ,
5+ "published" : " 2025-10-26T18:30:16Z" ,
6+ "aliases" : [
7+ " CVE-2025-12275"
8+ ],
9+ "details" : " Mail Configuration File Manipulation + Command Execution.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5." ,
10+ "severity" : [
11+ {
12+ "type" : " CVSS_V4" ,
13+ "score" : " CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
14+ }
15+ ],
16+ "affected" : [],
17+ "references" : [
18+ {
19+ "type" : " ADVISORY" ,
20+ "url" : " https://nvd.nist.gov/vuln/detail/CVE-2025-12275"
21+ },
22+ {
23+ "type" : " WEB" ,
24+ "url" : " https://azure-access.com/security-advisories"
25+ }
26+ ],
27+ "database_specific" : {
28+ "cwe_ids" : [
29+ " CWE-20"
30+ ],
31+ "severity" : " CRITICAL" ,
32+ "github_reviewed" : false ,
33+ "github_reviewed_at" : null ,
34+ "nvd_published_at" : " 2025-10-26T17:15:51Z"
35+ }
36+ }
Original file line number Diff line number Diff line change 1+ {
2+ "schema_version" : " 1.4.0" ,
3+ "id" : " GHSA-5pvj-27wv-7mqc" ,
4+ "modified" : " 2025-10-26T18:30:16Z" ,
5+ "published" : " 2025-10-26T18:30:16Z" ,
6+ "aliases" : [
7+ " CVE-2025-12285"
8+ ],
9+ "details" : " Missing Initial Password Change.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5." ,
10+ "severity" : [
11+ {
12+ "type" : " CVSS_V4" ,
13+ "score" : " CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
14+ }
15+ ],
16+ "affected" : [],
17+ "references" : [
18+ {
19+ "type" : " ADVISORY" ,
20+ "url" : " https://nvd.nist.gov/vuln/detail/CVE-2025-12285"
21+ },
22+ {
23+ "type" : " WEB" ,
24+ "url" : " https://azure-access.com/security-advisories"
25+ }
26+ ],
27+ "database_specific" : {
28+ "cwe_ids" : [
29+ " CWE-20"
30+ ],
31+ "severity" : " CRITICAL" ,
32+ "github_reviewed" : false ,
33+ "github_reviewed_at" : null ,
34+ "nvd_published_at" : " 2025-10-26T17:15:52Z"
35+ }
36+ }
Original file line number Diff line number Diff line change 1+ {
2+ "schema_version" : " 1.4.0" ,
3+ "id" : " GHSA-72pv-qvjj-jq58" ,
4+ "modified" : " 2025-10-26T18:30:16Z" ,
5+ "published" : " 2025-10-26T18:30:16Z" ,
6+ "aliases" : [
7+ " CVE-2025-12278"
8+ ],
9+ "details" : " Logout Functionality not Working.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5." ,
10+ "severity" : [
11+ {
12+ "type" : " CVSS_V4" ,
13+ "score" : " CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
14+ }
15+ ],
16+ "affected" : [],
17+ "references" : [
18+ {
19+ "type" : " ADVISORY" ,
20+ "url" : " https://nvd.nist.gov/vuln/detail/CVE-2025-12278"
21+ },
22+ {
23+ "type" : " WEB" ,
24+ "url" : " https://azure-access.com/security-advisories"
25+ }
26+ ],
27+ "database_specific" : {
28+ "cwe_ids" : [
29+ " CWE-20"
30+ ],
31+ "severity" : " MODERATE" ,
32+ "github_reviewed" : false ,
33+ "github_reviewed_at" : null ,
34+ "nvd_published_at" : " 2025-10-26T17:15:52Z"
35+ }
36+ }
Original file line number Diff line number Diff line change 1+ {
2+ "schema_version" : " 1.4.0" ,
3+ "id" : " GHSA-fwwv-7q49-jm9f" ,
4+ "modified" : " 2025-10-26T18:30:16Z" ,
5+ "published" : " 2025-10-26T18:30:16Z" ,
6+ "aliases" : [
7+ " CVE-2025-12284"
8+ ],
9+ "details" : " Lack of Input Validation in the web UI might lead to potential exploitation.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5." ,
10+ "severity" : [
11+ {
12+ "type" : " CVSS_V4" ,
13+ "score" : " CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
14+ }
15+ ],
16+ "affected" : [],
17+ "references" : [
18+ {
19+ "type" : " ADVISORY" ,
20+ "url" : " https://nvd.nist.gov/vuln/detail/CVE-2025-12284"
21+ },
22+ {
23+ "type" : " WEB" ,
24+ "url" : " https://azure-access.com/security-advisories"
25+ }
26+ ],
27+ "database_specific" : {
28+ "cwe_ids" : [
29+ " CWE-20"
30+ ],
31+ "severity" : " MODERATE" ,
32+ "github_reviewed" : false ,
33+ "github_reviewed_at" : null ,
34+ "nvd_published_at" : " 2025-10-26T17:15:52Z"
35+ }
36+ }
You can’t perform that action at this time.
0 commit comments