From 017b40132cfacc8e20f5599e7222ba1588e3a98a Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 17 Sep 2024 21:25:04 +0000 Subject: [PATCH] Publish Advisories GHSA-6rgh-r6j3-3223 GHSA-f2jm-rw3h-6phg GHSA-6rgh-r6j3-3223 GHSA-f2jm-rw3h-6phg --- .../GHSA-6rgh-r6j3-3223.json | 93 +++++++++++++++++++ .../GHSA-f2jm-rw3h-6phg.json | 69 ++++++++++++++ .../GHSA-6rgh-r6j3-3223.json | 35 ------- .../GHSA-f2jm-rw3h-6phg.json | 42 --------- 4 files changed, 162 insertions(+), 77 deletions(-) create mode 100644 advisories/github-reviewed/2024/09/GHSA-6rgh-r6j3-3223/GHSA-6rgh-r6j3-3223.json create mode 100644 advisories/github-reviewed/2024/09/GHSA-f2jm-rw3h-6phg/GHSA-f2jm-rw3h-6phg.json delete mode 100644 advisories/unreviewed/2024/09/GHSA-6rgh-r6j3-3223/GHSA-6rgh-r6j3-3223.json delete mode 100644 advisories/unreviewed/2024/09/GHSA-f2jm-rw3h-6phg/GHSA-f2jm-rw3h-6phg.json diff --git a/advisories/github-reviewed/2024/09/GHSA-6rgh-r6j3-3223/GHSA-6rgh-r6j3-3223.json b/advisories/github-reviewed/2024/09/GHSA-6rgh-r6j3-3223/GHSA-6rgh-r6j3-3223.json new file mode 100644 index 00000000000..42e159a1141 --- /dev/null +++ b/advisories/github-reviewed/2024/09/GHSA-6rgh-r6j3-3223/GHSA-6rgh-r6j3-3223.json @@ -0,0 +1,93 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6rgh-r6j3-3223", + "modified": "2024-09-17T21:23:56Z", + "published": "2024-09-17T15:31:23Z", + "aliases": [ + "CVE-2024-47049" + ], + "summary": "czim/file-handling vulnerable to SSRF and directory traversal", + "details": "The czim/file-handling package before 1.5.0 and 2.x before 2.3.0 (used with PHP Composer) does not properly validate URLs within makeFromUrl and makeFromAny, leading to SSRF, and to directory traversal for the reading of local files.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:L/SA:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "czim/file-handling" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "1.5.0" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "Packagist", + "name": "czim/file-handling" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.0.0" + }, + { + "fixed": "2.3.0" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47049" + }, + { + "type": "WEB", + "url": "https://github.com/czim/file-handling/commit/95dfda850536bf35e684619598b9d02f4c97680d" + }, + { + "type": "WEB", + "url": "https://github.com/czim/file-handling/commit/dcf879896efe3457f51af9c8eab9f70dfc709a99" + }, + { + "type": "PACKAGE", + "url": "https://github.com/czim/file-handling" + }, + { + "type": "WEB", + "url": "https://github.com/czim/file-handling/blob/2.3.0/SECURITY.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22", + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-09-17T21:23:56Z", + "nvd_published_at": "2024-09-17T14:15:17Z" + } +} \ No newline at end of file diff --git a/advisories/github-reviewed/2024/09/GHSA-f2jm-rw3h-6phg/GHSA-f2jm-rw3h-6phg.json b/advisories/github-reviewed/2024/09/GHSA-f2jm-rw3h-6phg/GHSA-f2jm-rw3h-6phg.json new file mode 100644 index 00000000000..96393b1b7a8 --- /dev/null +++ b/advisories/github-reviewed/2024/09/GHSA-f2jm-rw3h-6phg/GHSA-f2jm-rw3h-6phg.json @@ -0,0 +1,69 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f2jm-rw3h-6phg", + "modified": "2024-09-17T21:23:31Z", + "published": "2024-09-17T12:30:32Z", + "aliases": [ + "CVE-2024-5998" + ], + "summary": "LangChain pickle deserialization of untrusted data", + "details": "A vulnerability in the `FAISS.deserialize_from_bytes` function of langchain-ai/langchain allows for pickle deserialization of untrusted data. This can lead to the execution of arbitrary commands via the `os.system` function. The issue affects versions prior to 0.2.10.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "PyPI", + "name": "langchain" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.2.10" + } + ] + } + ] + } + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5998" + }, + { + "type": "WEB", + "url": "https://github.com/langchain-ai/langchain/commit/604dfe2d99246b0c09f047c604f0c63eafba31e7" + }, + { + "type": "PACKAGE", + "url": "https://github.com/langchain-ai/langchain" + }, + { + "type": "WEB", + "url": "https://huntr.com/bounties/fa3a2753-57c3-4e08-a176-d7a3ffda28fe" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-09-17T21:23:31Z", + "nvd_published_at": "2024-09-17T12:15:02Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-6rgh-r6j3-3223/GHSA-6rgh-r6j3-3223.json b/advisories/unreviewed/2024/09/GHSA-6rgh-r6j3-3223/GHSA-6rgh-r6j3-3223.json deleted file mode 100644 index db397babdb5..00000000000 --- a/advisories/unreviewed/2024/09/GHSA-6rgh-r6j3-3223/GHSA-6rgh-r6j3-3223.json +++ /dev/null @@ -1,35 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-6rgh-r6j3-3223", - "modified": "2024-09-17T15:31:23Z", - "published": "2024-09-17T15:31:23Z", - "aliases": [ - "CVE-2024-47049" - ], - "details": "The czim/file-handling package before 1.5.0 and 2.x before 2.3.0 (used with PHP Composer) does not properly validate URLs within makeFromUrl and makeFromAny, leading to SSRF, and to directory traversal for the reading of local files.", - "severity": [ - - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-47049" - }, - { - "type": "WEB", - "url": "https://github.com/czim/file-handling/blob/2.3.0/SECURITY.md" - } - ], - "database_specific": { - "cwe_ids": [ - - ], - "severity": null, - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2024-09-17T14:15:17Z" - } -} \ No newline at end of file diff --git a/advisories/unreviewed/2024/09/GHSA-f2jm-rw3h-6phg/GHSA-f2jm-rw3h-6phg.json b/advisories/unreviewed/2024/09/GHSA-f2jm-rw3h-6phg/GHSA-f2jm-rw3h-6phg.json deleted file mode 100644 index e234de8beae..00000000000 --- a/advisories/unreviewed/2024/09/GHSA-f2jm-rw3h-6phg/GHSA-f2jm-rw3h-6phg.json +++ /dev/null @@ -1,42 +0,0 @@ -{ - "schema_version": "1.4.0", - "id": "GHSA-f2jm-rw3h-6phg", - "modified": "2024-09-17T12:30:32Z", - "published": "2024-09-17T12:30:32Z", - "aliases": [ - "CVE-2024-5998" - ], - "details": "A vulnerability in the FAISS.deserialize_from_bytes function of langchain-ai/langchain allows for pickle deserialization of untrusted data. This can lead to the execution of arbitrary commands via the os.system function. The issue affects the latest version of the product.", - "severity": [ - { - "type": "CVSS_V3", - "score": "CVSS:3.0/AV:P/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L" - } - ], - "affected": [ - - ], - "references": [ - { - "type": "ADVISORY", - "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5998" - }, - { - "type": "WEB", - "url": "https://github.com/langchain-ai/langchain/commit/604dfe2d99246b0c09f047c604f0c63eafba31e7" - }, - { - "type": "WEB", - "url": "https://huntr.com/bounties/fa3a2753-57c3-4e08-a176-d7a3ffda28fe" - } - ], - "database_specific": { - "cwe_ids": [ - "CWE-502" - ], - "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, - "nvd_published_at": "2024-09-17T12:15:02Z" - } -} \ No newline at end of file