Skip to content

Commit 14eab53

Browse files
Sync EUVD catalog: Sun Sep 6 00:38:07 UTC 2026
Signed-off-by: AboutCode Automation <automation@aboutcode.org>
1 parent a3bf055 commit 14eab53

260 files changed

Lines changed: 5287 additions & 772 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

advisories/2025/02/EUVD-2025-4485.json

Lines changed: 12 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -3,14 +3,14 @@
33
"enisaUuid": "3e67f26c-2de4-3f2c-94bf-75d8025332ec",
44
"description": "A flaw was found in npm-serialize-javascript. The vulnerability occurs because the serialize-javascript module does not properly sanitize certain inputs, such as regex or other JavaScript object types, allowing an attacker to inject malicious code. This code could be executed when deserialized by a web browser, causing Cross-site scripting (XSS) attacks. This issue is critical in environments where serialized data is sent to web clients, potentially compromising the security of the website or web application using this package.",
55
"datePublished": "Feb 10, 2025, 3:27:46 PM",
6-
"dateUpdated": "Sep 4, 2026, 6:34:13 PM",
6+
"dateUpdated": "Sep 5, 2026, 5:03:41 PM",
77
"baseScore": 5.4,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
1010
"references": "https://access.redhat.com/errata/RHBA-2025:0304\nhttps://access.redhat.com/errata/RHSA-2025:0381\nhttps://access.redhat.com/errata/RHSA-2025:10853\nhttps://access.redhat.com/errata/RHSA-2025:1334\nhttps://access.redhat.com/errata/RHSA-2025:1468\nhttps://access.redhat.com/errata/RHSA-2025:21068\nhttps://access.redhat.com/errata/RHSA-2025:21203\nhttps://access.redhat.com/errata/RHSA-2025:3870\nhttps://access.redhat.com/errata/RHSA-2025:4511\nhttps://access.redhat.com/errata/RHSA-2025:8059\nhttps://access.redhat.com/errata/RHSA-2025:8078\nhttps://access.redhat.com/errata/RHSA-2025:8233\nhttps://access.redhat.com/errata/RHSA-2025:8479\nhttps://access.redhat.com/errata/RHSA-2025:8512\nhttps://access.redhat.com/errata/RHSA-2025:8544\nhttps://access.redhat.com/errata/RHSA-2025:8551\nhttps://access.redhat.com/errata/RHSA-2025:9294\nhttps://access.redhat.com/errata/RHSA-2026:1536\nhttps://access.redhat.com/errata/RHSA-2026:2769\nhttps://access.redhat.com/errata/RHSA-2026:62115\nhttps://access.redhat.com/errata/RHSA-2026:8568\nhttps://access.redhat.com/security/cve/CVE-2024-11831\nhttps://bugzilla.redhat.com/show_bug.cgi?id=2312579\nhttps://github.com/yahoo/serialize-javascript/commit/f27d65d3de42affe2aac14607066c293891cec4e\nhttps://github.com/yahoo/serialize-javascript/pull/173\n",
1111
"aliases": "CVE-2024-11831\nGHSA-76p7-773f-r4q5\n",
1212
"assigner": "redhat",
13-
"epss": 1.1,
13+
"epss": 1.12,
1414
"enisaIdProduct": [
1515
{
1616
"id": "03c3ba33-c52a-3616-80fa-436e29fdd324",
@@ -32,16 +32,6 @@
3232
},
3333
"product_version": "patch: 2:18.2.1-381.el8cp"
3434
},
35-
{
36-
"id": "08723281-00f2-3801-a0ca-c0201ff86aa5",
37-
"product": {
38-
"name": "Red Hat Ceph Storage 9",
39-
"vendor": {
40-
"name": "Red Hat"
41-
}
42-
},
43-
"product_version": "patch: 1776359884"
44-
},
4535
{
4636
"id": "09b21c25-43aa-3656-b1c3-caaa5b322d01",
4737
"product": {
@@ -222,6 +212,16 @@
222212
},
223213
"product_version": "patch: v1.16.4-1747979846"
224214
},
215+
{
216+
"id": "cb906647-3db4-3922-a8a3-30bc6a24ccd2",
217+
"product": {
218+
"name": "Red Hat Ceph Storage 9.0",
219+
"vendor": {
220+
"name": "Red Hat"
221+
}
222+
},
223+
"product_version": "patch: 1776359884"
224+
},
225225
{
226226
"id": "e7ba1676-e950-3542-a2e6-a2a4b7e63ea1",
227227
"product": {

advisories/2025/04/EUVD-2025-9524.json

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -3,29 +3,29 @@
33
"enisaUuid": "3c00498b-7691-3e1b-9a72-54b485f418e6",
44
"description": "A flaw was found in Tempo Operator, where it creates a ServiceAccount, ClusterRole, and ClusterRoleBinding when a user deploys a TempoStack or TempoMonolithic instance. This flaw allows a user with full access to their namespace to extract the ServiceAccount token and use it to submit TokenReview and SubjectAccessReview requests, potentially revealing information about other users' permissions. While this does not allow privilege escalation or impersonation, it exposes information that could aid in gathering information for further attacks.",
55
"datePublished": "Apr 2, 2025, 11:07:43 AM",
6-
"dateUpdated": "Aug 25, 2026, 9:33:41 AM",
6+
"dateUpdated": "Sep 5, 2026, 5:33:31 PM",
77
"baseScore": 4.3,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
1010
"references": "https://access.redhat.com/errata/RHSA-2025:3607\nhttps://access.redhat.com/errata/RHSA-2025:3740\nhttps://access.redhat.com/security/cve/CVE-2025-2786\nhttps://bugzilla.redhat.com/show_bug.cgi?id=2354811\nhttps://github.com/grafana/tempo-operator/pull/1145\n",
1111
"aliases": "CVE-2025-2786\nGHSA-28gr-56hr-prp6\n",
1212
"assigner": "redhat",
13-
"epss": 0.34,
13+
"epss": 0.36,
1414
"enisaIdProduct": [
1515
{
16-
"id": "5b1e84cf-278d-3e1d-bd05-2476a6c87973",
16+
"id": "7999fca7-c8f9-3311-a5da-85d393bfec7c",
1717
"product": {
18-
"name": "Red Hat OpenShift distributed tracing 3.5.2",
18+
"name": "Red Hat OpenShift distributed tracing 3.5.3",
1919
"vendor": {
2020
"name": "Red Hat"
2121
}
2222
},
2323
"product_version": "patch: rhosdt-3.5-1743162265"
2424
},
2525
{
26-
"id": "8f12b4ac-4d03-3d2d-aac5-a0b6b0e79fa4",
26+
"id": "d495c522-e886-3e1c-811f-510a7b2f711c",
2727
"product": {
28-
"name": "Red Hat OpenShift distributed tracing 3.5.2",
28+
"name": "Red Hat OpenShift distributed tracing 3.5.3",
2929
"vendor": {
3030
"name": "Red Hat"
3131
}

advisories/2025/04/EUVD-2025-9549.json

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -3,29 +3,29 @@
33
"enisaUuid": "15628cee-8c54-37b3-b2b0-4f0b1d50c213",
44
"description": "A flaw was found in the Tempo Operator. When the Jaeger UI Monitor Tab functionality is enabled in a Tempo instance managed by the Tempo Operator, the Operator creates a ClusterRoleBinding for the Service Account of the Tempo instance to grant the cluster-monitoring-view ClusterRole.\nThis can be exploited if a user has 'create' permissions on TempoStack and 'get' permissions on Secret in a namespace (for example, a user has ClusterAdmin permissions for a specific namespace), as the user can read the token of the Tempo service account and therefore has access to see all cluster metrics.",
55
"datePublished": "Apr 2, 2025, 11:09:55 AM",
6-
"dateUpdated": "Aug 25, 2026, 9:33:45 AM",
6+
"dateUpdated": "Sep 5, 2026, 5:33:32 PM",
77
"baseScore": 4.3,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
1010
"references": "https://access.redhat.com/errata/RHSA-2025:3607\nhttps://access.redhat.com/errata/RHSA-2025:3740\nhttps://access.redhat.com/security/cve/CVE-2025-2842\nhttps://bugzilla.redhat.com/show_bug.cgi?id=2355219\nhttps://github.com/grafana/tempo-operator/pull/1144\n",
1111
"aliases": "CVE-2025-2842\nGHSA-5xf3-gmx4-529v\n",
1212
"assigner": "redhat",
13-
"epss": 0.36,
13+
"epss": 0.38,
1414
"enisaIdProduct": [
1515
{
16-
"id": "54c05450-a839-32ab-b3a6-cc1d9e16d1ab",
16+
"id": "2784905f-b6d6-3f8b-a082-b6b0e4ea0f95",
1717
"product": {
18-
"name": "Red Hat OpenShift distributed tracing 3.5.2",
18+
"name": "Red Hat OpenShift distributed tracing 3.5.3",
1919
"vendor": {
2020
"name": "Red Hat"
2121
}
2222
},
2323
"product_version": "patch: rhosdt-3.5-1744028971"
2424
},
2525
{
26-
"id": "b5993dda-1346-348a-94ac-a3a15debe76c",
26+
"id": "5c08a8bb-b8d0-3480-8706-5fd5515fa1b3",
2727
"product": {
28-
"name": "Red Hat OpenShift distributed tracing 3.5.2",
28+
"name": "Red Hat OpenShift distributed tracing 3.5.3",
2929
"vendor": {
3030
"name": "Red Hat"
3131
}

advisories/2025/05/EUVD-2025-13592.json

Lines changed: 50 additions & 50 deletions
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@
33
"enisaUuid": "d222098e-3470-3ad4-8f3b-202bdc93e820",
44
"description": "A flaw was found in GLib, which is vulnerable to an integer overflow in the g_string_insert_unichar() function. When the position at which to insert the character is large, the position will overflow, leading to a buffer underwrite.",
55
"datePublished": "May 6, 2025, 2:48:39 PM",
6-
"dateUpdated": "Aug 25, 2026, 8:09:17 AM",
6+
"dateUpdated": "Sep 5, 2026, 4:28:00 PM",
77
"baseScore": 4.8,
88
"baseScoreVersion": "3.1",
99
"baseScoreVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L",
@@ -23,19 +23,9 @@
2323
"product_version": "patch: 0:2.80.4-4.el10_0.6"
2424
},
2525
{
26-
"id": "0ad555e7-6b11-390b-b655-0881b9e47ed7",
26+
"id": "097a2cde-5598-3c9d-a9fd-2ea77768c3c7",
2727
"product": {
28-
"name": "Red Hat OpenShift distributed tracing 3.6.0",
29-
"vendor": {
30-
"name": "Red Hat"
31-
}
32-
},
33-
"product_version": "patch: rhosdt-3.6-1753265330"
34-
},
35-
{
36-
"id": "0b1f6cb7-3e08-3924-ae86-30b444c5cde1",
37-
"product": {
38-
"name": "Red Hat OpenShift distributed tracing 3.6.0",
28+
"name": "Red Hat OpenShift distributed tracing 3.6.1",
3929
"vendor": {
4030
"name": "Red Hat"
4131
}
@@ -63,9 +53,9 @@
6353
"product_version": "patch: 0:2.56.4-8.el8_2.2"
6454
},
6555
{
66-
"id": "248cb581-e2c3-3a91-b238-9a69e3f2909f",
56+
"id": "351949fc-7925-36b4-be8e-a0ffbfdd14e2",
6757
"product": {
68-
"name": "Red Hat OpenShift distributed tracing 3.6.0",
58+
"name": "Red Hat OpenShift distributed tracing 3.6.1",
6959
"vendor": {
7060
"name": "Red Hat"
7161
}
@@ -103,24 +93,14 @@
10393
"product_version": "patch: 0:2.56.4-162.el8_8"
10494
},
10595
{
106-
"id": "5145ee54-3c53-3de8-bbc6-c7bfe6350e12",
96+
"id": "5063791a-d80e-3c04-ab23-8c3bcdddfc5d",
10797
"product": {
108-
"name": "Red Hat OpenShift distributed tracing 3.6.0",
98+
"name": "Red Hat OpenShift distributed tracing 3.6.1",
10999
"vendor": {
110100
"name": "Red Hat"
111101
}
112102
},
113-
"product_version": "patch: rhosdt-3.6-1753265411"
114-
},
115-
{
116-
"id": "5a45b436-6a39-3f05-a2a3-8db1c0d872a3",
117-
"product": {
118-
"name": "Red Hat OpenShift distributed tracing 3.6.0",
119-
"vendor": {
120-
"name": "Red Hat"
121-
}
122-
},
123-
"product_version": "patch: rhosdt-3.6-1753269432"
103+
"product_version": "patch: rhosdt-3.6-1753265342"
124104
},
125105
{
126106
"id": "5b6313c9-03b1-3491-83b8-1f9eeeb9a8c6",
@@ -142,26 +122,6 @@
142122
},
143123
"product_version": "patch: 0:2.68.4-16.el9_6.2"
144124
},
145-
{
146-
"id": "7849d4f2-07fe-35e2-aaac-57d74398ba85",
147-
"product": {
148-
"name": "Red Hat OpenShift distributed tracing 3.6.0",
149-
"vendor": {
150-
"name": "Red Hat"
151-
}
152-
},
153-
"product_version": "patch: rhosdt-3.6-1753265394"
154-
},
155-
{
156-
"id": "7dc0760f-90b2-374c-8649-fb9e5fa4baf6",
157-
"product": {
158-
"name": "Red Hat OpenShift distributed tracing 3.6.0",
159-
"vendor": {
160-
"name": "Red Hat"
161-
}
162-
},
163-
"product_version": "patch: rhosdt-3.6-1753265342"
164-
},
165125
{
166126
"id": "80bec807-6392-3ea0-97c4-2c711abc34af",
167127
"product": {
@@ -183,9 +143,9 @@
183143
"product_version": "patch: 0:2.56.4-158.el8_6.2"
184144
},
185145
{
186-
"id": "8fde987b-225c-338c-8dd1-8207fa5bd81d",
146+
"id": "ba437907-1268-335e-9dc6-9d3a532d3d64",
187147
"product": {
188-
"name": "Red Hat OpenShift distributed tracing 3.6.0",
148+
"name": "Red Hat OpenShift distributed tracing 3.6.1",
189149
"vendor": {
190150
"name": "Red Hat"
191151
}
@@ -212,6 +172,16 @@
212172
},
213173
"product_version": "patch: 0:2.56.4-166.el8_10"
214174
},
175+
{
176+
"id": "dd58141b-0e06-3c39-bf20-ca161b0eead8",
177+
"product": {
178+
"name": "Red Hat OpenShift distributed tracing 3.6.1",
179+
"vendor": {
180+
"name": "Red Hat"
181+
}
182+
},
183+
"product_version": "patch: rhosdt-3.6-1753269432"
184+
},
215185
{
216186
"id": "ddac9b6e-43bb-32bf-8dca-7ae554669bf8",
217187
"product": {
@@ -222,6 +192,26 @@
222192
},
223193
"product_version": "patch: 0:2.56.4-158.el8_6.2"
224194
},
195+
{
196+
"id": "ddca59d0-2646-3702-9c29-299fc4995285",
197+
"product": {
198+
"name": "Red Hat OpenShift distributed tracing 3.6.1",
199+
"vendor": {
200+
"name": "Red Hat"
201+
}
202+
},
203+
"product_version": "patch: rhosdt-3.6-1753265330"
204+
},
205+
{
206+
"id": "e285e5d4-afca-3132-b8a2-eab578fe6233",
207+
"product": {
208+
"name": "Red Hat OpenShift distributed tracing 3.6.1",
209+
"vendor": {
210+
"name": "Red Hat"
211+
}
212+
},
213+
"product_version": "patch: rhosdt-3.6-1753265394"
214+
},
225215
{
226216
"id": "f0e0a410-488a-3ed7-8313-e0e403a973f1",
227217
"product": {
@@ -232,6 +222,16 @@
232222
},
233223
"product_version": "patch: 0:2.56.4-162.el8_8"
234224
},
225+
{
226+
"id": "f19d09bd-8aec-3d48-a278-3aa2b68cbffe",
227+
"product": {
228+
"name": "Red Hat OpenShift distributed tracing 3.6.1",
229+
"vendor": {
230+
"name": "Red Hat"
231+
}
232+
},
233+
"product_version": "patch: rhosdt-3.6-1753265411"
234+
},
235235
{
236236
"id": "ffc15292-78ef-3d23-8f01-d6f77c45ee4e",
237237
"product": {

0 commit comments

Comments
 (0)