Publish Advisories

GHSA-6rgh-r6j3-3223
GHSA-f2jm-rw3h-6phg
GHSA-6rgh-r6j3-3223
GHSA-f2jm-rw3h-6phg
This commit is contained in:
advisory-database[bot]
2024-09-17 21:25:04 +00:00
parent 4773d65394
commit 017b40132c
4 changed files with 162 additions and 77 deletions
@@ -0,0 +1,93 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6rgh-r6j3-3223",
"modified": "2024-09-17T21:23:56Z",
"published": "2024-09-17T15:31:23Z",
"aliases": [
"CVE-2024-47049"
],
"summary": "czim/file-handling vulnerable to SSRF and directory traversal",
"details": "The czim/file-handling package before 1.5.0 and 2.x before 2.3.0 (used with PHP Composer) does not properly validate URLs within makeFromUrl and makeFromAny, leading to SSRF, and to directory traversal for the reading of local files.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:L/SA:N"
}
],
"affected": [
{
"package": {
"ecosystem": "Packagist",
"name": "czim/file-handling"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "1.5.0"
}
]
}
]
},
{
"package": {
"ecosystem": "Packagist",
"name": "czim/file-handling"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "2.0.0"
},
{
"fixed": "2.3.0"
}
]
}
]
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47049"
},
{
"type": "WEB",
"url": "https://github.com/czim/file-handling/commit/95dfda850536bf35e684619598b9d02f4c97680d"
},
{
"type": "WEB",
"url": "https://github.com/czim/file-handling/commit/dcf879896efe3457f51af9c8eab9f70dfc709a99"
},
{
"type": "PACKAGE",
"url": "https://github.com/czim/file-handling"
},
{
"type": "WEB",
"url": "https://github.com/czim/file-handling/blob/2.3.0/SECURITY.md"
}
],
"database_specific": {
"cwe_ids": [
"CWE-22",
"CWE-918"
],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-09-17T21:23:56Z",
"nvd_published_at": "2024-09-17T14:15:17Z"
}
}
@@ -0,0 +1,69 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f2jm-rw3h-6phg",
"modified": "2024-09-17T21:23:31Z",
"published": "2024-09-17T12:30:32Z",
"aliases": [
"CVE-2024-5998"
],
"summary": "LangChain pickle deserialization of untrusted data",
"details": "A vulnerability in the `FAISS.deserialize_from_bytes` function of langchain-ai/langchain allows for pickle deserialization of untrusted data. This can lead to the execution of arbitrary commands via the `os.system` function. The issue affects versions prior to 0.2.10.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:P/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N"
}
],
"affected": [
{
"package": {
"ecosystem": "PyPI",
"name": "langchain"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "0.2.10"
}
]
}
]
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5998"
},
{
"type": "WEB",
"url": "https://github.com/langchain-ai/langchain/commit/604dfe2d99246b0c09f047c604f0c63eafba31e7"
},
{
"type": "PACKAGE",
"url": "https://github.com/langchain-ai/langchain"
},
{
"type": "WEB",
"url": "https://huntr.com/bounties/fa3a2753-57c3-4e08-a176-d7a3ffda28fe"
}
],
"database_specific": {
"cwe_ids": [
"CWE-502"
],
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2024-09-17T21:23:31Z",
"nvd_published_at": "2024-09-17T12:15:02Z"
}
}
@@ -1,35 +0,0 @@
{
"schema_version": "1.4.0",
"id": "GHSA-6rgh-r6j3-3223",
"modified": "2024-09-17T15:31:23Z",
"published": "2024-09-17T15:31:23Z",
"aliases": [
"CVE-2024-47049"
],
"details": "The czim/file-handling package before 1.5.0 and 2.x before 2.3.0 (used with PHP Composer) does not properly validate URLs within makeFromUrl and makeFromAny, leading to SSRF, and to directory traversal for the reading of local files.",
"severity": [
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47049"
},
{
"type": "WEB",
"url": "https://github.com/czim/file-handling/blob/2.3.0/SECURITY.md"
}
],
"database_specific": {
"cwe_ids": [
],
"severity": null,
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-17T14:15:17Z"
}
}
@@ -1,42 +0,0 @@
{
"schema_version": "1.4.0",
"id": "GHSA-f2jm-rw3h-6phg",
"modified": "2024-09-17T12:30:32Z",
"published": "2024-09-17T12:30:32Z",
"aliases": [
"CVE-2024-5998"
],
"details": "A vulnerability in the FAISS.deserialize_from_bytes function of langchain-ai/langchain allows for pickle deserialization of untrusted data. This can lead to the execution of arbitrary commands via the os.system function. The issue affects the latest version of the product.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.0/AV:P/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L"
}
],
"affected": [
],
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5998"
},
{
"type": "WEB",
"url": "https://github.com/langchain-ai/langchain/commit/604dfe2d99246b0c09f047c604f0c63eafba31e7"
},
{
"type": "WEB",
"url": "https://huntr.com/bounties/fa3a2753-57c3-4e08-a176-d7a3ffda28fe"
}
],
"database_specific": {
"cwe_ids": [
"CWE-502"
],
"severity": "MODERATE",
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-09-17T12:15:02Z"
}
}