Skip to content

Commit fc21c65

Browse files
Advisory Database Sync
1 parent fc08c95 commit fc21c65

File tree

70 files changed

+1779
-114
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

70 files changed

+1779
-114
lines changed

advisories/unreviewed/2025/02/GHSA-r385-c5fc-x56c/GHSA-r385-c5fc-x56c.json renamed to advisories/github-reviewed/2025/02/GHSA-r385-c5fc-x56c/GHSA-r385-c5fc-x56c.json

Lines changed: 27 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -1,26 +1,47 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-r385-c5fc-x56c",
4-
"modified": "2025-02-10T21:31:39Z",
4+
"modified": "2025-12-18T15:30:18Z",
55
"published": "2025-02-10T21:31:39Z",
66
"aliases": [
77
"CVE-2024-57177"
88
],
9-
"details": "A host header injection vulnerability exists in the NPM package of perfood/couch-auth <= 0.21.2. By sending a specially crafted host header in the email change confirmation request, it is possible to trigger a SSTI which can be leveraged to run limited commands or leak server-side information",
9+
"summary": "CouchAuth has a Server-Side Template Injection vulnerability in its email functionality",
10+
"details": "A host header injection vulnerability exists in the NPM package of perfood/couch-auth <= 0.21.2. By sending a specially crafted host header in the email change confirmation request, it is possible to trigger a SSTI which can be leveraged to run limited commands or leak server-side information.",
1011
"severity": [
1112
{
1213
"type": "CVSS_V3",
1314
"score": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"
1415
}
1516
],
16-
"affected": [],
17+
"affected": [
18+
{
19+
"package": {
20+
"ecosystem": "npm",
21+
"name": "@perfood/couch-auth"
22+
},
23+
"ranges": [
24+
{
25+
"type": "ECOSYSTEM",
26+
"events": [
27+
{
28+
"introduced": "0"
29+
},
30+
{
31+
"last_affected": "0.21.2"
32+
}
33+
]
34+
}
35+
]
36+
}
37+
],
1738
"references": [
1839
{
1940
"type": "ADVISORY",
2041
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57177"
2142
},
2243
{
23-
"type": "WEB",
44+
"type": "PACKAGE",
2445
"url": "https://github.com/perfood/couch-auth"
2546
},
2647
{
@@ -34,8 +55,8 @@
3455
"CWE-74"
3556
],
3657
"severity": "MODERATE",
37-
"github_reviewed": false,
38-
"github_reviewed_at": null,
58+
"github_reviewed": true,
59+
"github_reviewed_at": "2025-12-18T15:30:17Z",
3960
"nvd_published_at": "2025-02-10T20:15:41Z"
4061
}
4162
}

advisories/unreviewed/2022/05/GHSA-66mx-93rr-rg39/GHSA-66mx-93rr-rg39.json

Lines changed: 13 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-66mx-93rr-rg39",
4-
"modified": "2022-05-24T17:43:22Z",
4+
"modified": "2025-12-18T15:30:24Z",
55
"published": "2022-05-24T17:43:22Z",
66
"aliases": [
77
"CVE-2021-27803"
@@ -23,6 +23,18 @@
2323
"type": "WEB",
2424
"url": "https://lists.debian.org/debian-lts-announce/2021/03/msg00003.html"
2525
},
26+
{
27+
"type": "WEB",
28+
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/IZGUR5XFHATVXTRAEJMODS7ROYHA56NX"
29+
},
30+
{
31+
"type": "WEB",
32+
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KOGP2VIVVXXQ6CZ2HU4DKGPDB4WR24XF"
33+
},
34+
{
35+
"type": "WEB",
36+
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SEHS2CFGH3KCSNPHBHNGN5SGV6QPMLZ4"
37+
},
2638
{
2739
"type": "WEB",
2840
"url": "https://lists.fedoraproject.org/archives/list/[email protected]/message/IZGUR5XFHATVXTRAEJMODS7ROYHA56NX"

advisories/unreviewed/2022/05/GHSA-96g2-7cqx-5ggh/GHSA-96g2-7cqx-5ggh.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-96g2-7cqx-5ggh",
4-
"modified": "2022-05-24T17:22:01Z",
4+
"modified": "2025-12-18T15:30:24Z",
55
"published": "2022-05-24T17:22:01Z",
66
"aliases": [
77
"CVE-2020-14145"

advisories/unreviewed/2022/05/GHSA-hc96-xw56-vfwh/GHSA-hc96-xw56-vfwh.json

Lines changed: 86 additions & 26 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-hc96-xw56-vfwh",
4-
"modified": "2022-07-26T00:00:43Z",
4+
"modified": "2025-12-18T15:30:24Z",
55
"published": "2022-05-24T17:39:30Z",
66
"aliases": [
77
"CVE-2021-3177"
@@ -25,111 +25,171 @@
2525
},
2626
{
2727
"type": "WEB",
28-
"url": "https://www.oracle.com/security-alerts/cpuoct2021.html"
28+
"url": "https://bugs.python.org/issue42938"
2929
},
3030
{
3131
"type": "WEB",
32-
"url": "https://www.oracle.com/security-alerts/cpujul2022.html"
32+
"url": "https://lists.fedoraproject.org/archives/list/[email protected]/message/FONHJIOZOFD7CD35KZL6SVBUTMBPGZGA"
3333
},
3434
{
3535
"type": "WEB",
36-
"url": "https://www.oracle.com/security-alerts/cpujan2022.html"
36+
"url": "https://lists.fedoraproject.org/archives/list/[email protected]/message/FPE7SMXYUIWPOIZV4DQYXODRXMFX3C5E"
3737
},
3838
{
3939
"type": "WEB",
40-
"url": "https://www.oracle.com//security-alerts/cpujul2021.html"
40+
"url": "https://lists.fedoraproject.org/archives/list/[email protected]/message/HCQTCSP6SCVIYNIRUJC5X7YBVUHPLSC4"
4141
},
4242
{
4343
"type": "WEB",
44-
"url": "https://security.netapp.com/advisory/ntap-20210226-0003"
44+
"url": "https://lists.fedoraproject.org/archives/list/[email protected]/message/MGSV6BJQLRQ6RKVUXK7JGU7TP4QFGQXC"
4545
},
4646
{
4747
"type": "WEB",
48-
"url": "https://security.gentoo.org/glsa/202101-18"
48+
"url": "https://lists.fedoraproject.org/archives/list/[email protected]/message/MP572OLHMS7MZO4KUPSCIMSZIA5IZZ62"
4949
},
5050
{
5151
"type": "WEB",
52-
"url": "https://python-security.readthedocs.io/vuln/ctypes-buffer-overflow-pycarg_repr.html"
52+
"url": "https://lists.fedoraproject.org/archives/list/[email protected]/message/NODWHDIFBQE5RU5PUWUVE47JOT5VCMJ2"
5353
},
5454
{
5555
"type": "WEB",
56-
"url": "https://news.ycombinator.com/item?id=26185005"
56+
"url": "https://lists.fedoraproject.org/archives/list/[email protected]/message/NQPARTLNSFQVMMQHPNBFOCOZOO3TMQNA"
5757
},
5858
{
5959
"type": "WEB",
60-
"url": "https://lists.fedoraproject.org/archives/list/[email protected]/message/Z7GZV74KM72O2PEJN2C4XP3V5Q5MZUOO"
60+
"url": "https://lists.fedoraproject.org/archives/list/[email protected]/message/NXSMBHES3ANXXS2RSO5G6Q24BR4B2PWK"
6161
},
6262
{
6363
"type": "WEB",
64-
"url": "https://lists.fedoraproject.org/archives/list/[email protected]/message/YDTZVGSXQ7HR7OCGSUHTRNTMBG43OMKU"
64+
"url": "https://lists.fedoraproject.org/archives/list/[email protected]/message/V6XJAULOS5JVB2L67NCKKMJ5NTKZJBSD"
6565
},
6666
{
6767
"type": "WEB",
6868
"url": "https://lists.fedoraproject.org/archives/list/[email protected]/message/Y4KSYYWMGAKOA2JVCQA422OINT6CKQ7O"
6969
},
7070
{
7171
"type": "WEB",
72-
"url": "https://lists.fedoraproject.org/archives/list/[email protected]/message/V6XJAULOS5JVB2L67NCKKMJ5NTKZJBSD"
72+
"url": "https://lists.fedoraproject.org/archives/list/[email protected]/message/YDTZVGSXQ7HR7OCGSUHTRNTMBG43OMKU"
7373
},
7474
{
7575
"type": "WEB",
76-
"url": "https://lists.fedoraproject.org/archives/list/[email protected]/message/NXSMBHES3ANXXS2RSO5G6Q24BR4B2PWK"
76+
"url": "https://lists.fedoraproject.org/archives/list/[email protected]/message/Z7GZV74KM72O2PEJN2C4XP3V5Q5MZUOO"
7777
},
7878
{
7979
"type": "WEB",
80-
"url": "https://lists.fedoraproject.org/archives/list/[email protected]/message/NQPARTLNSFQVMMQHPNBFOCOZOO3TMQNA"
80+
"url": "https://news.ycombinator.com/item?id=26185005"
8181
},
8282
{
8383
"type": "WEB",
84-
"url": "https://lists.fedoraproject.org/archives/list/[email protected]/message/NODWHDIFBQE5RU5PUWUVE47JOT5VCMJ2"
84+
"url": "https://python-security.readthedocs.io/vuln/ctypes-buffer-overflow-pycarg_repr.html"
8585
},
8686
{
8787
"type": "WEB",
88-
"url": "https://lists.fedoraproject.org/archives/list/[email protected]/message/MP572OLHMS7MZO4KUPSCIMSZIA5IZZ62"
88+
"url": "https://security.gentoo.org/glsa/202101-18"
8989
},
9090
{
9191
"type": "WEB",
92-
"url": "https://lists.fedoraproject.org/archives/list/[email protected]/message/MGSV6BJQLRQ6RKVUXK7JGU7TP4QFGQXC"
92+
"url": "https://security.netapp.com/advisory/ntap-20210226-0003"
9393
},
9494
{
9595
"type": "WEB",
96-
"url": "https://lists.fedoraproject.org/archives/list/[email protected]/message/HCQTCSP6SCVIYNIRUJC5X7YBVUHPLSC4"
96+
"url": "https://www.oracle.com//security-alerts/cpujul2021.html"
9797
},
9898
{
9999
"type": "WEB",
100-
"url": "https://lists.fedoraproject.org/archives/list/[email protected]/message/FPE7SMXYUIWPOIZV4DQYXODRXMFX3C5E"
100+
"url": "https://www.oracle.com/security-alerts/cpujan2022.html"
101101
},
102102
{
103103
"type": "WEB",
104-
"url": "https://lists.fedoraproject.org/archives/list/[email protected]/message/FONHJIOZOFD7CD35KZL6SVBUTMBPGZGA"
104+
"url": "https://www.oracle.com/security-alerts/cpujul2022.html"
105105
},
106106
{
107107
"type": "WEB",
108-
"url": "https://lists.fedoraproject.org/archives/list/[email protected]/message/CCFZMVRQUKCBQIG5F2CBVADK63NFSE4A"
108+
"url": "https://www.oracle.com/security-alerts/cpuoct2021.html"
109109
},
110110
{
111111
"type": "WEB",
112-
"url": "https://lists.fedoraproject.org/archives/list/[email protected].org/message/BRHOCQYX3QLDGDQGTWQAUUT2GGIZCZUO"
112+
"url": "https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E"
113113
},
114114
{
115115
"type": "WEB",
116-
"url": "https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html"
116+
"url": "https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772@%3Cdev.mina.apache.org%3E"
117+
},
118+
{
119+
"type": "WEB",
120+
"url": "https://lists.debian.org/debian-lts-announce/2021/04/msg00005.html"
117121
},
118122
{
119123
"type": "WEB",
120124
"url": "https://lists.debian.org/debian-lts-announce/2022/02/msg00013.html"
121125
},
122126
{
123127
"type": "WEB",
124-
"url": "https://lists.debian.org/debian-lts-announce/2021/04/msg00005.html"
128+
"url": "https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html"
125129
},
126130
{
127131
"type": "WEB",
128-
"url": "https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772@%3Cdev.mina.apache.org%3E"
132+
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BRHOCQYX3QLDGDQGTWQAUUT2GGIZCZUO"
129133
},
130134
{
131135
"type": "WEB",
132-
"url": "https://bugs.python.org/issue42938"
136+
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CCFZMVRQUKCBQIG5F2CBVADK63NFSE4A"
137+
},
138+
{
139+
"type": "WEB",
140+
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FONHJIOZOFD7CD35KZL6SVBUTMBPGZGA"
141+
},
142+
{
143+
"type": "WEB",
144+
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FPE7SMXYUIWPOIZV4DQYXODRXMFX3C5E"
145+
},
146+
{
147+
"type": "WEB",
148+
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HCQTCSP6SCVIYNIRUJC5X7YBVUHPLSC4"
149+
},
150+
{
151+
"type": "WEB",
152+
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MGSV6BJQLRQ6RKVUXK7JGU7TP4QFGQXC"
153+
},
154+
{
155+
"type": "WEB",
156+
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MP572OLHMS7MZO4KUPSCIMSZIA5IZZ62"
157+
},
158+
{
159+
"type": "WEB",
160+
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NODWHDIFBQE5RU5PUWUVE47JOT5VCMJ2"
161+
},
162+
{
163+
"type": "WEB",
164+
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NQPARTLNSFQVMMQHPNBFOCOZOO3TMQNA"
165+
},
166+
{
167+
"type": "WEB",
168+
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NXSMBHES3ANXXS2RSO5G6Q24BR4B2PWK"
169+
},
170+
{
171+
"type": "WEB",
172+
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/V6XJAULOS5JVB2L67NCKKMJ5NTKZJBSD"
173+
},
174+
{
175+
"type": "WEB",
176+
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y4KSYYWMGAKOA2JVCQA422OINT6CKQ7O"
177+
},
178+
{
179+
"type": "WEB",
180+
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YDTZVGSXQ7HR7OCGSUHTRNTMBG43OMKU"
181+
},
182+
{
183+
"type": "WEB",
184+
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z7GZV74KM72O2PEJN2C4XP3V5Q5MZUOO"
185+
},
186+
{
187+
"type": "WEB",
188+
"url": "https://lists.fedoraproject.org/archives/list/[email protected]/message/BRHOCQYX3QLDGDQGTWQAUUT2GGIZCZUO"
189+
},
190+
{
191+
"type": "WEB",
192+
"url": "https://lists.fedoraproject.org/archives/list/[email protected]/message/CCFZMVRQUKCBQIG5F2CBVADK63NFSE4A"
133193
}
134194
],
135195
"database_specific": {

advisories/unreviewed/2022/05/GHSA-jr78-hfw4-xp7g/GHSA-jr78-hfw4-xp7g.json

Lines changed: 21 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-jr78-hfw4-xp7g",
4-
"modified": "2022-05-13T01:22:35Z",
4+
"modified": "2025-12-18T15:30:24Z",
55
"published": "2022-05-13T01:22:35Z",
66
"aliases": [
77
"CVE-2019-6111"
@@ -59,6 +59,10 @@
5959
"type": "WEB",
6060
"url": "https://lists.fedoraproject.org/archives/list/[email protected]/message/W3YVQ2BPTOVDCFDVNC2GGF5P5ISFG37G"
6161
},
62+
{
63+
"type": "WEB",
64+
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W3YVQ2BPTOVDCFDVNC2GGF5P5ISFG37G"
65+
},
6266
{
6367
"type": "WEB",
6468
"url": "https://lists.debian.org/debian-lts-announce/2019/03/msg00030.html"
@@ -67,18 +71,34 @@
6771
"type": "WEB",
6872
"url": "https://lists.apache.org/thread.html/e47597433b351d6e01a5d68d610b4ba195743def9730e49561e8cf3f@%3Cdev.mina.apache.org%3E"
6973
},
74+
{
75+
"type": "WEB",
76+
"url": "https://lists.apache.org/thread.html/e47597433b351d6e01a5d68d610b4ba195743def9730e49561e8cf3f%40%3Cdev.mina.apache.org%3E"
77+
},
7078
{
7179
"type": "WEB",
7280
"url": "https://lists.apache.org/thread.html/d540139359de999b0f1c87d05b715be4d7d4bec771e1ae55153c5c7a@%3Cdev.mina.apache.org%3E"
7381
},
82+
{
83+
"type": "WEB",
84+
"url": "https://lists.apache.org/thread.html/d540139359de999b0f1c87d05b715be4d7d4bec771e1ae55153c5c7a%40%3Cdev.mina.apache.org%3E"
85+
},
7486
{
7587
"type": "WEB",
7688
"url": "https://lists.apache.org/thread.html/c7301cab36a86825359e1b725fc40304d1df56dc6d107c1fe885148b@%3Cdev.mina.apache.org%3E"
7789
},
90+
{
91+
"type": "WEB",
92+
"url": "https://lists.apache.org/thread.html/c7301cab36a86825359e1b725fc40304d1df56dc6d107c1fe885148b%40%3Cdev.mina.apache.org%3E"
93+
},
7894
{
7995
"type": "WEB",
8096
"url": "https://lists.apache.org/thread.html/c45d9bc90700354b58fb7455962873c44229841880dcb64842fa7d23@%3Cdev.mina.apache.org%3E"
8197
},
98+
{
99+
"type": "WEB",
100+
"url": "https://lists.apache.org/thread.html/c45d9bc90700354b58fb7455962873c44229841880dcb64842fa7d23%40%3Cdev.mina.apache.org%3E"
101+
},
82102
{
83103
"type": "WEB",
84104
"url": "https://cvsweb.openbsd.org/src/usr.bin/ssh/scp.c"

advisories/unreviewed/2022/05/GHSA-mv2j-4mm8-9xgv/GHSA-mv2j-4mm8-9xgv.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-mv2j-4mm8-9xgv",
4-
"modified": "2022-05-13T01:22:35Z",
4+
"modified": "2025-12-18T15:30:24Z",
55
"published": "2022-05-13T01:22:35Z",
66
"aliases": [
77
"CVE-2019-6110"

advisories/unreviewed/2025/10/GHSA-447q-wwcf-54f8/GHSA-447q-wwcf-54f8.json

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-447q-wwcf-54f8",
4-
"modified": "2025-10-28T12:30:17Z",
4+
"modified": "2025-12-18T15:30:24Z",
55
"published": "2025-10-28T12:30:17Z",
66
"aliases": [
77
"CVE-2025-40075"
@@ -18,6 +18,10 @@
1818
"type": "WEB",
1919
"url": "https://git.kernel.org/stable/c/07613a95326ebad2d1b88d883cd72546025a4f3e"
2020
},
21+
{
22+
"type": "WEB",
23+
"url": "https://git.kernel.org/stable/c/4b89397807eb04986427c4786d065e9442834ad4"
24+
},
2125
{
2226
"type": "WEB",
2327
"url": "https://git.kernel.org/stable/c/50c127a69cd6285300931853b352a1918cfa180f"

0 commit comments

Comments
 (0)