diff --git a/advisories/github-reviewed/2024/09/GHSA-6rgh-r6j3-3223/GHSA-6rgh-r6j3-3223.json b/advisories/github-reviewed/2024/09/GHSA-6rgh-r6j3-3223/GHSA-6rgh-r6j3-3223.json new file mode 100644 index 00000000000..42e159a1141 --- /dev/null +++ b/advisories/github-reviewed/2024/09/GHSA-6rgh-r6j3-3223/GHSA-6rgh-r6j3-3223.json @@ -0,0 +1,93 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6rgh-r6j3-3223", + "modified": "2024-09-17T21:23:56Z", + "published": "2024-09-17T15:31:23Z", + "aliases": [ + "CVE-2024-47049" + ], + "summary": "czim/file-handling vulnerable to SSRF and directory traversal", + "details": "The czim/file-handling package before 1.5.0 and 2.x before 2.3.0 (used with PHP Composer) does not properly validate URLs within makeFromUrl and makeFromAny, leading to SSRF, and to directory traversal for the reading of local files.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:L/SA:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "czim/file-handling" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.5.0" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "czim/file-handling" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.0.0" + }, + { + "fixed": "2.3.0" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47049" + }, + { + "type": "WEB", + "url": "https://github.com/czim/file-handling/commit/95dfda850536bf35e684619598b9d02f4c97680d" + }, + { + "type": "WEB", + "url": "https://github.com/czim/file-handling/commit/dcf879896efe3457f51af9c8eab9f70dfc709a99" + }, + { + "type": "PACKAGE", + "url": "https://github.com/czim/file-handling" + }, + { + "type": "WEB", + "url": "https://github.com/czim/file-handling/blob/2.3.0/SECURITY.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22", + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-09-17T21:23:56Z", + "nvd_published_at": "2024-09-17T14:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/09/GHSA-f2jm-rw3h-6phg/GHSA-f2jm-rw3h-6phg.json b/advisories/github-reviewed/2024/09/GHSA-f2jm-rw3h-6phg/GHSA-f2jm-rw3h-6phg.json new file mode 100644 index 00000000000..96393b1b7a8 --- /dev/null +++ b/advisories/github-reviewed/2024/09/GHSA-f2jm-rw3h-6phg/GHSA-f2jm-rw3h-6phg.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f2jm-rw3h-6phg", + "modified": "2024-09-17T21:23:31Z", + "published": "2024-09-17T12:30:32Z", + "aliases": [ + "CVE-2024-5998" + ], + "summary": "LangChain pickle deserialization of untrusted data", + "details": "A vulnerability in the `FAISS.deserialize_from_bytes` function of langchain-ai/langchain allows for pickle deserialization of untrusted data. This can lead to the execution of arbitrary commands via the `os.system` function. The issue affects versions prior to 0.2.10.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "PyPI", + "name": "langchain" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.2.10" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5998" + }, + { + "type": "WEB", + "url": "https://github.com/langchain-ai/langchain/commit/604dfe2d99246b0c09f047c604f0c63eafba31e7" + }, + { + "type": "PACKAGE", + "url": "https://github.com/langchain-ai/langchain" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/fa3a2753-57c3-4e08-a176-d7a3ffda28fe" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-09-17T21:23:31Z", + "nvd_published_at": "2024-09-17T12:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-6rgh-r6j3-3223/GHSA-6rgh-r6j3-3223.json b/advisories/unreviewed/2024/09/GHSA-6rgh-r6j3-3223/GHSA-6rgh-r6j3-3223.json deleted file mode 100644 index db397babdb5..00000000000 --- a/advisories/unreviewed/2024/09/GHSA-6rgh-r6j3-3223/GHSA-6rgh-r6j3-3223.json +++ /dev/null @@ -1,35 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-6rgh-r6j3-3223", - "modified": "2024-09-17T15:31:23Z", - "published": "2024-09-17T15:31:23Z", - "aliases": [ - "CVE-2024-47049" - ], - "details": "The czim/file-handling package before 1.5.0 and 2.x before 2.3.0 (used with PHP Composer) does not properly validate URLs within makeFromUrl and makeFromAny, leading to SSRF, and to directory traversal for the reading of local files.", - "severity": [ - - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47049" - }, - { - "type": "WEB", - "url": "https://github.com/czim/file-handling/blob/2.3.0/SECURITY.md" - } - ], - "database_specific": { - "cwe_ids": [ - - ], - "severity": null, - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2024-09-17T14:15:17Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-f2jm-rw3h-6phg/GHSA-f2jm-rw3h-6phg.json b/advisories/unreviewed/2024/09/GHSA-f2jm-rw3h-6phg/GHSA-f2jm-rw3h-6phg.json deleted file mode 100644 index e234de8beae..00000000000 --- a/advisories/unreviewed/2024/09/GHSA-f2jm-rw3h-6phg/GHSA-f2jm-rw3h-6phg.json +++ /dev/null @@ -1,42 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-f2jm-rw3h-6phg", - "modified": "2024-09-17T12:30:32Z", - "published": "2024-09-17T12:30:32Z", - "aliases": [ - "CVE-2024-5998" - ], - "details": "A vulnerability in the FAISS.deserialize_from_bytes function of langchain-ai/langchain allows for pickle deserialization of untrusted data. This can lead to the execution of arbitrary commands via the os.system function. The issue affects the latest version of the product.", - "severity": [ - { - "type": "CVSS_V3", - "score": "CVSS:3.0/AV:P/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L" - } - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5998" - }, - { - "type": "WEB", - "url": "https://github.com/langchain-ai/langchain/commit/604dfe2d99246b0c09f047c604f0c63eafba31e7" - }, - { - "type": "WEB", - "url": "https://huntr.com/bounties/fa3a2753-57c3-4e08-a176-d7a3ffda28fe" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-502" - ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2024-09-17T12:15:02Z" - } -} \ No newline at end of file