Skip to content

Commit a5c443c

Browse files
thatnealpatelgopherbot
authored andcommitted
data/reports: add 23 reports
- data/reports/GO-2025-3459.yaml - data/reports/GO-2025-3460.yaml - data/reports/GO-2025-3461.yaml - data/reports/GO-2025-3465.yaml - data/reports/GO-2025-3466.yaml - data/reports/GO-2025-3467.yaml - data/reports/GO-2025-3468.yaml - data/reports/GO-2025-3470.yaml - data/reports/GO-2025-3472.yaml - data/reports/GO-2025-3474.yaml - data/reports/GO-2025-3475.yaml - data/reports/GO-2025-3477.yaml - data/reports/GO-2025-3479.yaml - data/reports/GO-2025-3480.yaml - data/reports/GO-2025-3481.yaml - data/reports/GO-2025-3482.yaml - data/reports/GO-2025-3483.yaml - data/reports/GO-2025-3484.yaml - data/reports/GO-2025-3489.yaml - data/reports/GO-2025-3490.yaml - data/reports/GO-2025-3491.yaml - data/reports/GO-2025-3492.yaml - data/reports/GO-2025-3495.yaml Fixes #3459 Fixes #3460 Fixes #3461 Fixes #3465 Fixes #3466 Fixes #3467 Fixes #3468 Fixes #3470 Fixes #3472 Fixes #3474 Fixes #3475 Fixes #3477 Fixes #3479 Fixes #3480 Fixes #3481 Fixes #3482 Fixes #3483 Fixes #3484 Fixes #3489 Fixes #3490 Fixes #3491 Fixes #3492 Fixes #3495 Change-Id: I3ddc8c94fc7a3c681c4f59504ffd5907f38316ab Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/654257 Auto-Submit: Neal Patel <nealpatel@google.com> Commit-Queue: Neal Patel <nealpatel@google.com> Reviewed-by: Zvonimir Pavlinovic <zpavlinovic@google.com> LUCI-TryBot-Result: Go LUCI <golang-scoped@luci-project-accounts.iam.gserviceaccount.com>
1 parent 890c00c commit a5c443c

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

46 files changed

+2212
-0
lines changed

data/osv/GO-2025-3459.json

+47
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,47 @@
1+
{
2+
"schema_version": "1.3.1",
3+
"id": "GO-2025-3459",
4+
"modified": "0001-01-01T00:00:00Z",
5+
"published": "0001-01-01T00:00:00Z",
6+
"aliases": [
7+
"CVE-2025-24016"
8+
],
9+
"summary": "Remote code execution in Wazuh server in github.com/wazuh/wazuh",
10+
"details": "Remote code execution in Wazuh server in github.com/wazuh/wazuh",
11+
"affected": [
12+
{
13+
"package": {
14+
"name": "github.com/wazuh/wazuh",
15+
"ecosystem": "Go"
16+
},
17+
"ranges": [
18+
{
19+
"type": "SEMVER",
20+
"events": [
21+
{
22+
"introduced": "4.4.0+incompatible"
23+
},
24+
{
25+
"fixed": "4.9.1+incompatible"
26+
}
27+
]
28+
}
29+
],
30+
"ecosystem_specific": {}
31+
}
32+
],
33+
"references": [
34+
{
35+
"type": "ADVISORY",
36+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24016"
37+
},
38+
{
39+
"type": "WEB",
40+
"url": "https://github.com/wazuh/wazuh/security/advisories/GHSA-hcrc-79hj-m3qh"
41+
}
42+
],
43+
"database_specific": {
44+
"url": "https://pkg.go.dev/vuln/GO-2025-3459",
45+
"review_status": "UNREVIEWED"
46+
}
47+
}

data/osv/GO-2025-3460.json

+49
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,49 @@
1+
{
2+
"schema_version": "1.3.1",
3+
"id": "GO-2025-3460",
4+
"modified": "0001-01-01T00:00:00Z",
5+
"published": "0001-01-01T00:00:00Z",
6+
"aliases": [
7+
"CVE-2025-24976",
8+
"GHSA-phw4-mc57-4hwc"
9+
],
10+
"summary": "Distribution's token authentication allows attacker to inject an untrusted signing key in a JWT in github.com/distribution/distribution",
11+
"details": "Distribution's token authentication allows attacker to inject an untrusted signing key in a JWT in github.com/distribution/distribution",
12+
"affected": [
13+
{
14+
"package": {
15+
"name": "github.com/distribution/distribution",
16+
"ecosystem": "Go"
17+
},
18+
"ranges": [
19+
{
20+
"type": "SEMVER",
21+
"events": [
22+
{
23+
"introduced": "0"
24+
}
25+
]
26+
}
27+
],
28+
"ecosystem_specific": {}
29+
}
30+
],
31+
"references": [
32+
{
33+
"type": "ADVISORY",
34+
"url": "https://github.com/distribution/distribution/security/advisories/GHSA-phw4-mc57-4hwc"
35+
},
36+
{
37+
"type": "ADVISORY",
38+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24976"
39+
},
40+
{
41+
"type": "FIX",
42+
"url": "https://github.com/distribution/distribution/commit/5ea9aa028db65ca5665f6af2c20ecf9dc34e5fcd"
43+
}
44+
],
45+
"database_specific": {
46+
"url": "https://pkg.go.dev/vuln/GO-2025-3460",
47+
"review_status": "UNREVIEWED"
48+
}
49+
}

data/osv/GO-2025-3461.json

+52
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,52 @@
1+
{
2+
"schema_version": "1.3.1",
3+
"id": "GO-2025-3461",
4+
"modified": "0001-01-01T00:00:00Z",
5+
"published": "0001-01-01T00:00:00Z",
6+
"aliases": [
7+
"CVE-2025-25199",
8+
"GHSA-29c6-3hcj-89cf"
9+
],
10+
"summary": "go-crypto-winnative BCryptGenerateSymmetricKey memory leak in github.com/microsoft/go-crypto-winnative",
11+
"details": "go-crypto-winnative BCryptGenerateSymmetricKey memory leak in github.com/microsoft/go-crypto-winnative",
12+
"affected": [
13+
{
14+
"package": {
15+
"name": "github.com/microsoft/go-crypto-winnative",
16+
"ecosystem": "Go"
17+
},
18+
"ranges": [
19+
{
20+
"type": "SEMVER",
21+
"events": [
22+
{
23+
"introduced": "0"
24+
},
25+
{
26+
"fixed": "0.0.0-20250211154640-f49c8e1379ea"
27+
}
28+
]
29+
}
30+
],
31+
"ecosystem_specific": {}
32+
}
33+
],
34+
"references": [
35+
{
36+
"type": "ADVISORY",
37+
"url": "https://github.com/microsoft/go-crypto-winnative/security/advisories/GHSA-29c6-3hcj-89cf"
38+
},
39+
{
40+
"type": "ADVISORY",
41+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25199"
42+
},
43+
{
44+
"type": "FIX",
45+
"url": "https://github.com/microsoft/go-crypto-winnative/commit/f49c8e1379ea4b147d5bff1b3be5b0ff45792e41"
46+
}
47+
],
48+
"database_specific": {
49+
"url": "https://pkg.go.dev/vuln/GO-2025-3461",
50+
"review_status": "UNREVIEWED"
51+
}
52+
}

data/osv/GO-2025-3465.json

+78
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,78 @@
1+
{
2+
"schema_version": "1.3.1",
3+
"id": "GO-2025-3465",
4+
"modified": "0001-01-01T00:00:00Z",
5+
"published": "0001-01-01T00:00:00Z",
6+
"aliases": [
7+
"CVE-2025-0426",
8+
"GHSA-jgfp-53c3-624w"
9+
],
10+
"summary": "Node Denial of Service via kubelet Checkpoint API in k8s.io/kubernetes",
11+
"details": "Node Denial of Service via kubelet Checkpoint API in k8s.io/kubernetes",
12+
"affected": [
13+
{
14+
"package": {
15+
"name": "k8s.io/kubernetes",
16+
"ecosystem": "Go"
17+
},
18+
"ranges": [
19+
{
20+
"type": "SEMVER",
21+
"events": [
22+
{
23+
"introduced": "0"
24+
},
25+
{
26+
"fixed": "1.29.14"
27+
},
28+
{
29+
"introduced": "1.30.0"
30+
},
31+
{
32+
"fixed": "1.30.10"
33+
},
34+
{
35+
"introduced": "1.31.0"
36+
},
37+
{
38+
"fixed": "1.31.6"
39+
},
40+
{
41+
"introduced": "1.32.0"
42+
},
43+
{
44+
"fixed": "1.32.2"
45+
}
46+
]
47+
}
48+
],
49+
"ecosystem_specific": {}
50+
}
51+
],
52+
"references": [
53+
{
54+
"type": "ADVISORY",
55+
"url": "https://github.com/advisories/GHSA-jgfp-53c3-624w"
56+
},
57+
{
58+
"type": "ADVISORY",
59+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0426"
60+
},
61+
{
62+
"type": "WEB",
63+
"url": "http://www.openwall.com/lists/oss-security/2025/02/13/1"
64+
},
65+
{
66+
"type": "WEB",
67+
"url": "https://github.com/kubernetes/kubernetes/issues/130016"
68+
},
69+
{
70+
"type": "WEB",
71+
"url": "https://groups.google.com/g/kubernetes-security-announce/c/KiODfu8i6w8"
72+
}
73+
],
74+
"database_specific": {
75+
"url": "https://pkg.go.dev/vuln/GO-2025-3465",
76+
"review_status": "UNREVIEWED"
77+
}
78+
}

data/osv/GO-2025-3466.json

+53
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,53 @@
1+
{
2+
"schema_version": "1.3.1",
3+
"id": "GO-2025-3466",
4+
"modified": "0001-01-01T00:00:00Z",
5+
"published": "0001-01-01T00:00:00Z",
6+
"aliases": [
7+
"CVE-2024-57603",
8+
"GHSA-772m-773g-qmhc"
9+
],
10+
"summary": "Missing rate limit in MaysWind ezBookkeeping in github.com/mayswind/ezbookkeeping",
11+
"details": "Missing rate limit in MaysWind ezBookkeeping in github.com/mayswind/ezbookkeeping",
12+
"affected": [
13+
{
14+
"package": {
15+
"name": "github.com/mayswind/ezbookkeeping",
16+
"ecosystem": "Go"
17+
},
18+
"ranges": [
19+
{
20+
"type": "SEMVER",
21+
"events": [
22+
{
23+
"introduced": "0"
24+
}
25+
]
26+
}
27+
],
28+
"ecosystem_specific": {}
29+
}
30+
],
31+
"references": [
32+
{
33+
"type": "ADVISORY",
34+
"url": "https://github.com/advisories/GHSA-772m-773g-qmhc"
35+
},
36+
{
37+
"type": "ADVISORY",
38+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-57603"
39+
},
40+
{
41+
"type": "REPORT",
42+
"url": "https://github.com/mayswind/ezbookkeeping/issues/33"
43+
},
44+
{
45+
"type": "WEB",
46+
"url": "https://hkohi.ca/vulnerability/1"
47+
}
48+
],
49+
"database_specific": {
50+
"url": "https://pkg.go.dev/vuln/GO-2025-3466",
51+
"review_status": "UNREVIEWED"
52+
}
53+
}

data/osv/GO-2025-3467.json

+73
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,73 @@
1+
{
2+
"schema_version": "1.3.1",
3+
"id": "GO-2025-3467",
4+
"modified": "0001-01-01T00:00:00Z",
5+
"published": "0001-01-01T00:00:00Z",
6+
"aliases": [
7+
"CVE-2025-25204",
8+
"GHSA-fgw4-v983-mgp8"
9+
],
10+
"summary": "`gh attestation verify` returns incorrect exit code during verification if no attestations are present in github.com/cli/cli",
11+
"details": "`gh attestation verify` returns incorrect exit code during verification if no attestations are present in github.com/cli/cli",
12+
"affected": [
13+
{
14+
"package": {
15+
"name": "github.com/cli/cli",
16+
"ecosystem": "Go"
17+
},
18+
"ranges": [
19+
{
20+
"type": "SEMVER",
21+
"events": [
22+
{
23+
"introduced": "0"
24+
}
25+
]
26+
}
27+
],
28+
"ecosystem_specific": {}
29+
},
30+
{
31+
"package": {
32+
"name": "github.com/cli/cli/v2",
33+
"ecosystem": "Go"
34+
},
35+
"ranges": [
36+
{
37+
"type": "SEMVER",
38+
"events": [
39+
{
40+
"introduced": "2.49.0"
41+
},
42+
{
43+
"fixed": "2.67.0"
44+
}
45+
]
46+
}
47+
],
48+
"ecosystem_specific": {}
49+
}
50+
],
51+
"references": [
52+
{
53+
"type": "ADVISORY",
54+
"url": "https://github.com/cli/cli/security/advisories/GHSA-fgw4-v983-mgp8"
55+
},
56+
{
57+
"type": "ADVISORY",
58+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-25204"
59+
},
60+
{
61+
"type": "FIX",
62+
"url": "https://github.com/cli/cli/pull/10421"
63+
},
64+
{
65+
"type": "REPORT",
66+
"url": "https://github.com/cli/cli/issues/10418"
67+
}
68+
],
69+
"database_specific": {
70+
"url": "https://pkg.go.dev/vuln/GO-2025-3467",
71+
"review_status": "UNREVIEWED"
72+
}
73+
}

0 commit comments

Comments
 (0)