Auto-Update: 2024-07-26T10:00:17.266954+00:00

This commit is contained in:
cad-safe-bot 2024-07-26 10:03:13 +00:00
parent 4f1c2866d5
commit 1e352e4863
3 changed files with 45 additions and 8 deletions

View File

@ -0,0 +1,37 @@
{
"id": "CVE-2024-25090",
"sourceIdentifier": "security@apache.org",
"published": "2024-07-26T09:15:09.700",
"lastModified": "2024-07-26T09:15:09.700",
"vulnStatus": "Received",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Insufficient input validation and sanitation in Profile name & screenname, Bookmark name & description and blogroll name features in all versions of Apache Roller on all platforms allows an authenticated user to perform an XSS attack. Mitigation: if you do not have Roller configured for untrusted users, then you need to do nothing because you trust your users to author raw HTML and other web content. If you are running with untrusted users then you should upgrade to Roller 6.1.3.\n\nThis issue affects Apache Roller: from 5.0.0 before 6.1.3.\n\nUsers are recommended to upgrade to version 6.1.3, which fixes the issue."
}
],
"metrics": {},
"weaknesses": [
{
"source": "security@apache.org",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-20"
},
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"references": [
{
"url": "https://lists.apache.org/thread/lb50jqyxwf8jrfpydl6dc5zpqtpgrrwd",
"source": "security@apache.org"
}
]
}

View File

@ -13,13 +13,13 @@ Repository synchronizes with the NVD every 2 hours.
### Last Repository Update
```plain
2024-07-26T08:00:17.463971+00:00
2024-07-26T10:00:17.266954+00:00
```
### Most recent CVE Modification Timestamp synchronized with NVD
```plain
2024-07-26T06:15:02.927000+00:00
2024-07-26T09:15:09.700000+00:00
```
### Last Data Feed Release
@ -33,15 +33,14 @@ Download and Changelog: [Click](https://github.com/fkie-cad/nvd-json-data-feeds/
### Total Number of included CVEs
```plain
257997
257998
```
### CVEs added in the last Commit
Recently added CVEs: `2`
Recently added CVEs: `1`
- [CVE-2024-40897](CVE-2024/CVE-2024-408xx/CVE-2024-40897.json) (`2024-07-26T06:15:02.290`)
- [CVE-2024-6490](CVE-2024/CVE-2024-64xx/CVE-2024-6490.json) (`2024-07-26T06:15:02.927`)
- [CVE-2024-25090](CVE-2024/CVE-2024-250xx/CVE-2024-25090.json) (`2024-07-26T09:15:09.700`)
### CVEs modified in the last Commit

View File

@ -245894,6 +245894,7 @@ CVE-2024-25087,0,0,c72ecbfe33bc1bedb424c3a8db8ed1e75d362fa6fbd3c127b6373b38910f7
CVE-2024-25088,0,0,9b1375c3c781149325c14c39fa835c2c88a69323c212b1013c4ad4d387aa77de,2024-07-05T17:04:50.340000
CVE-2024-25089,0,0,4d3ddaeeeaf0e005a5320fd57126d38836ae358b9586c6957758efb8e6b78742,2024-02-13T00:38:12.137000
CVE-2024-2509,0,0,e1632462213f3b340d9efadccdf81857ddba6b28ec7154489106797e9e1ad3ed,2024-07-03T01:53:19.050000
CVE-2024-25090,1,1,af195bd25126d0f8d62b334cb8f260e12aae7bfe4a1dc1cbf05893e15452706d,2024-07-26T09:15:09.700000
CVE-2024-25091,0,0,dea1cc9b372ccb28bdcce1ba1190ac3b21c3361d4c64bb82853a0d551bd6db2f,2024-03-01T14:04:04.827000
CVE-2024-25092,0,0,93228461014d21e76377d62123a9b74976fcddddff96fb9097cb4fcb49528f7c,2024-06-10T02:52:08.267000
CVE-2024-25093,0,0,b8e6c12d6bc03129058956c6365ec4ac1bf71d6b0585045592f329dee7756d25,2024-02-29T13:49:29.390000
@ -255700,7 +255701,7 @@ CVE-2024-4087,0,0,559dc8fcb531eb7d96e390fa33463b50a20c5a688e8dbefeb3187bf1d2c5f7
CVE-2024-40872,0,0,f2809cb57fd2b96503f7a1d210b92f81105355a60a5707cf70672f7e05382fae,2024-07-25T17:15:10.977000
CVE-2024-40873,0,0,6464041a53dae5152fc9c7c2516ca31b2e32b6c821b3bd662ccac1119c2697d8,2024-07-25T18:15:03.800000
CVE-2024-4088,0,0,61cc31924b86843bbd20c326ef7465dc1aa394b548458b2e1a9fc62c09ede628,2024-06-11T17:11:30.193000
CVE-2024-40897,1,1,6fcd0c18adce87a895e17b3f7d2a2534ed292b3842f49f746d66cdf95990bb48,2024-07-26T06:15:02.290000
CVE-2024-40897,0,0,6fcd0c18adce87a895e17b3f7d2a2534ed292b3842f49f746d66cdf95990bb48,2024-07-26T06:15:02.290000
CVE-2024-40898,0,0,6d797ebcdf9c53e0eade3a2c00a2f7d68b1d101b3405603dd30cc2157b772084,2024-07-18T12:28:43.707000
CVE-2024-40899,0,0,e950acc969e56b6fc4b2198a92989ebcef19e4b4c9a9c8ad08fee90da2bba031,2024-07-12T16:34:58.687000
CVE-2024-40900,0,0,d5b683c8350615b20febf47a29bbffae93edd0a350147e3cd873aa7a5a37926c,2024-07-12T16:34:58.687000
@ -257759,7 +257760,7 @@ CVE-2024-6484,0,0,bc633abd6bfb9da06585afdfb273066dfbc508847026385eb612d46f7c70ed
CVE-2024-6485,0,0,b143d2f5de1cad2c57f83d18fe64abfe0ba2da69210341aec4863f07cdd850cb,2024-07-11T18:09:58.777000
CVE-2024-6488,0,0,0c5ecb49d7296b409f5d61bd70a5d017ad6f69068345855a00f0bd7c78566faa,2024-07-04T21:15:10.403000
CVE-2024-6489,0,0,9e9ca0d507c7dd8804b1fd0a0aa043e3fe6638bfc4af4b9ea109d44e00b0a114,2024-07-22T13:00:53.287000
CVE-2024-6490,1,1,523efbefae0ca4180ba4585412d5587c630d9e8d5a5787727194de0bf4d71a70,2024-07-26T06:15:02.927000
CVE-2024-6490,0,0,523efbefae0ca4180ba4585412d5587c630d9e8d5a5787727194de0bf4d71a70,2024-07-26T06:15:02.927000
CVE-2024-6491,0,0,777eb845cac0fc56ad6345347b6b7dff4d99542463073dd5b5752a23e8a26dec,2024-07-22T13:00:53.287000
CVE-2024-6492,0,0,82f79625038ad5debf137137104e45e1e353947b9c4b14df742baece7a047a71,2024-07-17T13:34:20.520000
CVE-2024-6495,0,0,b5144ce6ead337054723bddaa938cbde5875226dc2ad6f1282d875ef6548d915,2024-07-12T16:34:58.687000

Can't render this file because it is too large.