"-Synchronized-Data."

This commit is contained in:
CVE Team 2025-04-03 01:00:31 +00:00
parent 1b71a3040f
commit b5d26e7fe8
No known key found for this signature in database
GPG Key ID: BC5FD8F2443B23B7
4 changed files with 151 additions and 12 deletions

View File

@ -288,7 +288,7 @@
"x_cve_json_5_version_data": {
"versions": [
{
"version": "3:4.4.1-16.rhaos4.13.el9",
"version": "3:4.4.1-15.rhaos4.13.el8",
"lessThan": "*",
"versionType": "rpm",
"status": "unaffected"
@ -358,7 +358,7 @@
"x_cve_json_5_version_data": {
"versions": [
{
"version": "3:4.4.1-32.rhaos4.15.el8",
"version": "3:4.4.1-32.rhaos4.15.el9",
"lessThan": "*",
"versionType": "rpm",
"status": "unaffected"
@ -401,6 +401,20 @@
],
"defaultStatus": "affected"
}
},
{
"version_value": "not down converted",
"x_cve_json_5_version_data": {
"versions": [
{
"version": "v4.16.0-202503121138.p0.g31c3c26.assembly.stream.el9",
"lessThan": "*",
"versionType": "rpm",
"status": "unaffected"
}
],
"defaultStatus": "affected"
}
}
]
}
@ -414,7 +428,7 @@
"x_cve_json_5_version_data": {
"versions": [
{
"version": "5:5.2.2-1.rhaos4.17.el9",
"version": "5:5.2.2-1.rhaos4.17.el8",
"lessThan": "*",
"versionType": "rpm",
"status": "unaffected"
@ -644,6 +658,11 @@
"refsource": "MISC",
"name": "https://access.redhat.com/errata/RHSA-2025:2710"
},
{
"url": "https://access.redhat.com/errata/RHSA-2025:3301",
"refsource": "MISC",
"name": "https://access.redhat.com/errata/RHSA-2025:3301"
},
{
"url": "https://access.redhat.com/security/cve/CVE-2024-9675",
"refsource": "MISC",

View File

@ -147,7 +147,7 @@
"x_cve_json_5_version_data": {
"versions": [
{
"version": "0:1.25.5-30.rhaos4.12.git53dc492.el8",
"version": "0:1.25.5-5.rhaos4.12.git53dc492.el9",
"lessThan": "*",
"versionType": "rpm",
"status": "unaffected"
@ -168,7 +168,7 @@
"x_cve_json_5_version_data": {
"versions": [
{
"version": "0:1.26.5-26.rhaos4.13.giteb3d487.el8",
"version": "0:1.26.5-26.rhaos4.13.giteb3d487.el9",
"lessThan": "*",
"versionType": "rpm",
"status": "unaffected"
@ -189,7 +189,7 @@
"x_cve_json_5_version_data": {
"versions": [
{
"version": "0:1.27.8-12.rhaos4.14.git7597c43.el9",
"version": "0:1.27.8-12.rhaos4.14.git7597c43.el8",
"lessThan": "*",
"versionType": "rpm",
"status": "unaffected"
@ -281,6 +281,20 @@
],
"defaultStatus": "affected"
}
},
{
"version_value": "not down converted",
"x_cve_json_5_version_data": {
"versions": [
{
"version": "v4.16.0-202503121138.p0.g31c3c26.assembly.stream.el9",
"lessThan": "*",
"versionType": "rpm",
"status": "unaffected"
}
],
"defaultStatus": "affected"
}
}
]
}
@ -485,6 +499,11 @@
"refsource": "MISC",
"name": "https://access.redhat.com/errata/RHSA-2025:2710"
},
{
"url": "https://access.redhat.com/errata/RHSA-2025:3301",
"refsource": "MISC",
"name": "https://access.redhat.com/errata/RHSA-2025:3301"
},
{
"url": "https://access.redhat.com/security/cve/CVE-2024-9676",
"refsource": "MISC",

View File

@ -330,12 +330,20 @@
}
},
{
"product_name": "Red Hat OpenShift Container Platform 4",
"product_name": "Red Hat OpenShift Container Platform 4.16",
"version": {
"version_data": [
{
"version_value": "not down converted",
"x_cve_json_5_version_data": {
"versions": [
{
"version": "416.94.202503252048-0",
"lessThan": "*",
"versionType": "rpm",
"status": "unaffected"
}
],
"defaultStatus": "affected"
}
}
@ -390,6 +398,11 @@
"refsource": "MISC",
"name": "https://access.redhat.com/errata/RHSA-2025:2869"
},
{
"url": "https://access.redhat.com/errata/RHSA-2025:3301",
"refsource": "MISC",
"name": "https://access.redhat.com/errata/RHSA-2025:3301"
},
{
"url": "https://access.redhat.com/errata/RHSA-2025:3367",
"refsource": "MISC",

View File

@ -1,18 +1,106 @@
{
"data_version": "4.0",
"data_type": "CVE",
"data_format": "MITRE",
"data_version": "4.0",
"CVE_data_meta": {
"ID": "CVE-2025-3153",
"ASSIGNER": "cve@mitre.org",
"STATE": "RESERVED"
"ASSIGNER": "security@concretecms.org",
"STATE": "PUBLIC"
},
"description": {
"description_data": [
{
"lang": "eng",
"value": "** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided."
"value": "Concrete CMS version 9 below 9.4.0RC2 and versions below 8.5.20 are vulnerable to CSRF and XSS in the Concrete CMS Address attribute because addresses are not properly sanitized in the output when a country is not specified.\u00a0 Attackers are limited to individuals whom a site administrator has granted the ability to fill in an address attribute. It is possible for the attacker to glean limited information from the site but amount and type is restricted by mitigating controls and the level of access of the attacker. Limited data modification is possible. The dashboard page itself could be rendered unavailable. \nThe fix only sanitizes new data uploaded post update to Concrete CMS 9.4.0RC2. Existing database entries added before the update will still be \u201clive\u201d if there were successful exploits added under previous versions; a database search is recommended. The Concrete CMS security team gave this vulnerability CVSS v.4.0 score of 5.1 with vector CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L\u00a0Thanks Myq Larson for reporting."
}
]
}
},
"problemtype": {
"problemtype_data": [
{
"description": [
{
"lang": "eng",
"value": "CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')",
"cweId": "CWE-79"
}
]
},
{
"description": [
{
"lang": "eng",
"value": "CWE-352 Cross-Site Request Forgery (CSRF)",
"cweId": "CWE-352"
}
]
}
]
},
"affects": {
"vendor": {
"vendor_data": [
{
"vendor_name": "Concrete CMS",
"product": {
"product_data": [
{
"product_name": "Concrete CMS",
"version": {
"version_data": [
{
"version_affected": "<=",
"version_name": "9",
"version_value": "9.3.4RC1"
},
{
"version_affected": "<",
"version_name": "5",
"version_value": "8.5.20"
}
]
}
}
]
}
}
]
}
},
"references": {
"reference_data": [
{
"url": "https://github.com/concretecms/concretecms/pull/12512",
"refsource": "MISC",
"name": "https://github.com/concretecms/concretecms/pull/12512"
},
{
"url": "https://github.com/concretecms/concretecms/pull/12511",
"refsource": "MISC",
"name": "https://github.com/concretecms/concretecms/pull/12511"
},
{
"url": "https://documentation.concretecms.org/9-x/developers/introduction/version-history/940-release-notes",
"refsource": "MISC",
"name": "https://documentation.concretecms.org/9-x/developers/introduction/version-history/940-release-notes"
},
{
"url": "https://github.com/concretecms/concretecms/releases/tag/8.5.20",
"refsource": "MISC",
"name": "https://github.com/concretecms/concretecms/releases/tag/8.5.20"
}
]
},
"generator": {
"engine": "Vulnogram 0.2.0"
},
"source": {
"discovery": "UNKNOWN"
},
"credits": [
{
"lang": "en",
"value": "Myq Larson"
}
]
}