Skip to content

Commit

Permalink
generated content from 2025-01-23
Browse files Browse the repository at this point in the history
  • Loading branch information
gitadvisor committed Jan 23, 2025
1 parent a79d988 commit cde24a6
Show file tree
Hide file tree
Showing 3 changed files with 46 additions and 0 deletions.
2 changes: 2 additions & 0 deletions mapping.csv
Original file line number Diff line number Diff line change
Expand Up @@ -264916,3 +264916,5 @@ vulnerability,CVE-2025-23227,vulnerability--61c48d30-26d6-4b5c-b296-d539241cad44
vulnerability,CVE-2025-24034,vulnerability--36207490-f528-4b2f-9d14-203625dd40c1
vulnerability,CVE-2025-24033,vulnerability--4f589dd2-6614-488f-b30c-57bb15ced5b3
vulnerability,CVE-2025-24353,vulnerability--85dcd26b-842f-47c3-93e5-152daed37a30
vulnerability,CVE-2025-23012,vulnerability--da876d7d-4263-4d34-8cdc-fb2cdc834b2c
vulnerability,CVE-2025-23011,vulnerability--0424aa6f-c071-427c-bcb7-49f8c8ab6454
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
{
"type": "bundle",
"id": "bundle--a861f6d4-ad2d-4440-bb31-b7c39b40f40e",
"objects": [
{
"type": "vulnerability",
"spec_version": "2.1",
"id": "vulnerability--0424aa6f-c071-427c-bcb7-49f8c8ab6454",
"created_by_ref": "identity--8ce3f695-d5a4-4dc8-9e93-a65af453a31a",
"created": "2025-01-23T21:17:57.255509Z",
"modified": "2025-01-23T21:17:57.255509Z",
"name": "CVE-2025-23011",
"description": "Fedora Repository 3.8.1 allows path traversal when extracting uploaded archives (\"Zip Slip\"). A remote, authenticated attacker can upload a specially crafted archive that will extract an arbitrary JSP file to a location that can be executed by an unauthenticated GET request. Fedora Repository 3.8.1 was released on 2015-06-11 and is no longer maintained. Migrate to a currently supported version (6.5.1 as of 2025-01-23).",
"external_references": [
{
"source_name": "cve",
"external_id": "CVE-2025-23011"
}
]
}
]
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
{
"type": "bundle",
"id": "bundle--84065efd-79fb-4db8-9802-5c5d6c3e6980",
"objects": [
{
"type": "vulnerability",
"spec_version": "2.1",
"id": "vulnerability--da876d7d-4263-4d34-8cdc-fb2cdc834b2c",
"created_by_ref": "identity--8ce3f695-d5a4-4dc8-9e93-a65af453a31a",
"created": "2025-01-23T21:17:57.252936Z",
"modified": "2025-01-23T21:17:57.252936Z",
"name": "CVE-2025-23012",
"description": "Fedora Repository 3.8.x includes a service account (fedoraIntCallUser) with default credentials and privileges to read read local files by manipulating datastreams. Fedora Repository 3.8.1 was released on 2015-06-11 and is no longer maintained. Migrate to a currently supported version (6.5.1 as of 2025-01-23).",
"external_references": [
{
"source_name": "cve",
"external_id": "CVE-2025-23012"
}
]
}
]
}

0 comments on commit cde24a6

Please sign in to comment.