diff --git a/2024/13xxx/CVE-2024-13914.json b/2024/13xxx/CVE-2024-13914.json new file mode 100644 index 00000000000..48ba8f535ec --- /dev/null +++ b/2024/13xxx/CVE-2024-13914.json @@ -0,0 +1,18 @@ +{ + "data_type": "CVE", + "data_format": "MITRE", + "data_version": "4.0", + "CVE_data_meta": { + "ID": "CVE-2024-13914", + "ASSIGNER": "cve@mitre.org", + "STATE": "RESERVED" + }, + "description": { + "description_data": [ + { + "lang": "eng", + "value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided." + } + ] + } +} \ No newline at end of file diff --git a/2025/1xxx/CVE-2025-1803.json b/2025/1xxx/CVE-2025-1803.json new file mode 100644 index 00000000000..c150c2bd665 --- /dev/null +++ b/2025/1xxx/CVE-2025-1803.json @@ -0,0 +1,18 @@ +{ + "data_version": "4.0", + "data_type": "CVE", + "data_format": "MITRE", + "CVE_data_meta": { + "ID": "CVE-2025-1803", + "ASSIGNER": "security@wordfence.com", + "STATE": "REJECT" + }, + "description": { + "description_data": [ + { + "lang": "eng", + "value": "** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage." + } + ] + } +} \ No newline at end of file diff --git a/2025/1xxx/CVE-2025-1804.json b/2025/1xxx/CVE-2025-1804.json new file mode 100644 index 00000000000..f314aef3309 --- /dev/null +++ b/2025/1xxx/CVE-2025-1804.json @@ -0,0 +1,18 @@ +{ + "data_type": "CVE", + "data_format": "MITRE", + "data_version": "4.0", + "CVE_data_meta": { + "ID": "CVE-2025-1804", + "ASSIGNER": "cve@mitre.org", + "STATE": "RESERVED" + }, + "description": { + "description_data": [ + { + "lang": "eng", + "value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided." + } + ] + } +} \ No newline at end of file diff --git a/2025/27xxx/CVE-2025-27416.json b/2025/27xxx/CVE-2025-27416.json index c82a22c5cfa..ed4a03274a4 100644 --- a/2025/27xxx/CVE-2025-27416.json +++ b/2025/27xxx/CVE-2025-27416.json @@ -1,18 +1,73 @@ { + "data_version": "4.0", "data_type": "CVE", "data_format": "MITRE", - "data_version": "4.0", "CVE_data_meta": { "ID": "CVE-2025-27416", - "ASSIGNER": "cve@mitre.org", - "STATE": "RESERVED" + "ASSIGNER": "security-advisories@github.com", + "STATE": "PUBLIC" }, "description": { "description_data": [ { "lang": "eng", - "value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided." + "value": "Scratch-Coding-Hut.github.io is the website for Coding Hut. The website as of 28 February 2025 contained a sign in with scratch username and password form. Any user who used the sign in page would be susceptible to any other user signing into their account. As of time of publication, a fix is not available but work on a fix is underway. As a workaround, users should avoid signing in." } ] + }, + "problemtype": { + "problemtype_data": [ + { + "description": [ + { + "lang": "eng", + "value": "CWE-287: Improper Authentication", + "cweId": "CWE-287" + } + ] + } + ] + }, + "affects": { + "vendor": { + "vendor_data": [ + { + "vendor_name": "Scratch-Coding-Hut", + "product": { + "product_data": [ + { + "product_name": "Scratch-Coding-Hut.github.io", + "version": { + "version_data": [ + { + "version_affected": "=", + "version_value": "<= 2025-02-28" + } + ] + } + } + ] + } + } + ] + } + }, + "references": { + "reference_data": [ + { + "url": "https://github.com/Scratch-Coding-Hut/Scratch-Coding-Hut.github.io/security/advisories/GHSA-xx32-r9wr-whff", + "refsource": "MISC", + "name": "https://github.com/Scratch-Coding-Hut/Scratch-Coding-Hut.github.io/security/advisories/GHSA-xx32-r9wr-whff" + }, + { + "url": "https://github.com/Scratch-Coding-Hut/Scratch-Coding-Hut.github.io/issues/3", + "refsource": "MISC", + "name": "https://github.com/Scratch-Coding-Hut/Scratch-Coding-Hut.github.io/issues/3" + } + ] + }, + "source": { + "advisory": "GHSA-xx32-r9wr-whff", + "discovery": "UNKNOWN" } } \ No newline at end of file