Skip to content

Commit

Permalink
6 changes (1 new | 5 updated):
Browse files Browse the repository at this point in the history
  • Loading branch information
cvelistV5 Github Action committed Mar 5, 2025
1 parent 83b08da commit 8776f22
Show file tree
Hide file tree
Showing 6 changed files with 257 additions and 6 deletions.
34 changes: 33 additions & 1 deletion cves/2020/5xxx/CVE-2020-5026.json
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@
"assignerShortName": "ibm",
"dateReserved": "2019-12-30T00:00:00.000Z",
"datePublished": "2023-03-01T21:28:02.073Z",
"dateUpdated": "2024-08-04T08:22:09.092Z"
"dateUpdated": "2025-03-05T21:32:26.612Z"
},
"containers": {
"cna": {
Expand Down Expand Up @@ -127,6 +127,38 @@
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/193662"
}
]
},
{
"metrics": [
{
"other": {
"type": "ssvc",
"content": {
"timestamp": "2025-03-05T21:32:21.607989Z",
"id": "CVE-2020-5026",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"version": "2.0.3"
}
}
}
],
"title": "CISA ADP Vulnrichment",
"providerMetadata": {
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP",
"dateUpdated": "2025-03-05T21:32:26.612Z"
}
}
]
}
Expand Down
36 changes: 34 additions & 2 deletions cves/2023/0xxx/CVE-2023-0193.json
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@
"assignerShortName": "nvidia",
"dateReserved": "2023-01-11T05:48:47.581Z",
"datePublished": "2023-03-02T01:19:51.597Z",
"dateUpdated": "2024-08-02T05:02:44.145Z"
"dateUpdated": "2025-03-05T21:30:00.350Z"
},
"containers": {
"cna": {
Expand Down Expand Up @@ -92,7 +92,7 @@
"providerMetadata": {
"orgId": "9576f279-3576-44b5-a4af-b9a8644b2de6",
"shortName": "nvidia",
"dateUpdated": "2023-03-10T20:04:40.537099Z"
"dateUpdated": "2023-03-10T20:04:40.537Z"
},
"references": [
{
Expand Down Expand Up @@ -122,6 +122,38 @@
]
}
]
},
{
"metrics": [
{
"other": {
"type": "ssvc",
"content": {
"timestamp": "2025-03-05T21:29:52.543670Z",
"id": "CVE-2023-0193",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"version": "2.0.3"
}
}
}
],
"title": "CISA ADP Vulnrichment",
"providerMetadata": {
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP",
"dateUpdated": "2025-03-05T21:30:00.350Z"
}
}
]
}
Expand Down
34 changes: 33 additions & 1 deletion cves/2023/25xxx/CVE-2023-25806.json
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@
"assignerShortName": "GitHub_M",
"dateReserved": "2023-02-15T16:34:48.772Z",
"datePublished": "2023-03-02T03:04:26.889Z",
"dateUpdated": "2024-08-02T11:32:12.694Z"
"dateUpdated": "2025-03-05T21:28:42.975Z"
},
"containers": {
"cna": {
Expand Down Expand Up @@ -102,6 +102,38 @@
"url": "https://github.com/opensearch-project/security/security/advisories/GHSA-c6wg-cm5x-rqvj"
}
]
},
{
"metrics": [
{
"other": {
"type": "ssvc",
"content": {
"timestamp": "2025-03-05T21:28:22.405522Z",
"id": "CVE-2023-25806",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"version": "2.0.3"
}
}
}
],
"title": "CISA ADP Vulnrichment",
"providerMetadata": {
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP",
"dateUpdated": "2025-03-05T21:28:42.975Z"
}
}
]
}
Expand Down
34 changes: 33 additions & 1 deletion cves/2023/26xxx/CVE-2023-26046.json
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@
"assignerShortName": "GitHub_M",
"dateReserved": "2023-02-17T22:44:03.150Z",
"datePublished": "2023-03-02T00:14:57.196Z",
"dateUpdated": "2024-08-02T11:39:06.638Z"
"dateUpdated": "2025-03-05T21:30:47.218Z"
},
"containers": {
"cna": {
Expand Down Expand Up @@ -128,6 +128,38 @@
"url": "https://github.com/kitabisa/teler-waf/releases/tag/v0.1.1"
}
]
},
{
"metrics": [
{
"other": {
"type": "ssvc",
"content": {
"timestamp": "2025-03-05T21:30:36.670679Z",
"id": "CVE-2023-26046",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"version": "2.0.3"
}
}
}
],
"title": "CISA ADP Vulnrichment",
"providerMetadata": {
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP",
"dateUpdated": "2025-03-05T21:30:47.218Z"
}
}
]
}
Expand Down
34 changes: 33 additions & 1 deletion cves/2023/26xxx/CVE-2023-26477.json
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@
"assignerShortName": "GitHub_M",
"dateReserved": "2023-02-23T23:22:58.573Z",
"datePublished": "2023-03-02T17:52:40.359Z",
"dateUpdated": "2024-08-02T11:53:52.972Z"
"dateUpdated": "2025-03-05T21:27:38.903Z"
},
"containers": {
"cna": {
Expand Down Expand Up @@ -136,6 +136,38 @@
"url": "https://jira.xwiki.org/browse/XWIKI-19757"
}
]
},
{
"metrics": [
{
"other": {
"type": "ssvc",
"content": {
"timestamp": "2025-03-05T21:27:26.418613Z",
"id": "CVE-2023-26477",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"version": "2.0.3"
}
}
}
],
"title": "CISA ADP Vulnrichment",
"providerMetadata": {
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP",
"dateUpdated": "2025-03-05T21:27:38.903Z"
}
}
]
}
Expand Down
91 changes: 91 additions & 0 deletions cves/2025/27xxx/CVE-2025-27508.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,91 @@
{
"dataType": "CVE_RECORD",
"dataVersion": "5.1",
"cveMetadata": {
"cveId": "CVE-2025-27508",
"assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"state": "PUBLISHED",
"assignerShortName": "GitHub_M",
"dateReserved": "2025-02-26T18:11:52.306Z",
"datePublished": "2025-03-05T21:32:42.470Z",
"dateUpdated": "2025-03-05T21:32:42.470Z"
},
"containers": {
"cna": {
"title": "Emissary Use of a Broken or Risky Cryptographic Algorithm",
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-327",
"lang": "en",
"description": "CWE-327: Use of a Broken or Risky Cryptographic Algorithm",
"type": "CWE"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "NONE",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"version": "3.1"
}
}
],
"references": [
{
"name": "https://github.com/NationalSecurityAgency/emissary/security/advisories/GHSA-hw43-fcmm-3m5g",
"tags": [
"x_refsource_CONFIRM"
],
"url": "https://github.com/NationalSecurityAgency/emissary/security/advisories/GHSA-hw43-fcmm-3m5g"
},
{
"name": "https://github.com/NationalSecurityAgency/emissary/commit/da3a81a8977577597ff2a944820a5ae4e9762368",
"tags": [
"x_refsource_MISC"
],
"url": "https://github.com/NationalSecurityAgency/emissary/commit/da3a81a8977577597ff2a944820a5ae4e9762368"
}
],
"affected": [
{
"vendor": "NationalSecurityAgency",
"product": "emissary",
"versions": [
{
"version": "< 8.24.0",
"status": "affected"
}
]
}
],
"providerMetadata": {
"orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
"shortName": "GitHub_M",
"dateUpdated": "2025-03-05T21:32:42.470Z"
},
"descriptions": [
{
"lang": "en",
"value": "Emissary is a P2P based data-driven workflow engine. The ChecksumCalculator class within allows for hashing and checksum generation, but it includes or defaults to algorithms that are no longer recommended for secure cryptographic use cases (e.g., SHA-1, CRC32, and SSDEEP). These algorithms, while possibly valid for certain non-security-critical tasks, can expose users to security risks if used in scenarios where strong cryptographic guarantees are required. This issue is fixed in 8.24.0."
}
],
"source": {
"advisory": "GHSA-hw43-fcmm-3m5g",
"discovery": "UNKNOWN"
}
}
}
}

0 comments on commit 8776f22

Please sign in to comment.