diff --git a/advisories/github-reviewed/2024/06/GHSA-3hjh-jh2h-vrg6/GHSA-3hjh-jh2h-vrg6.json b/advisories/github-reviewed/2024/06/GHSA-3hjh-jh2h-vrg6/GHSA-3hjh-jh2h-vrg6.json index 61404608c60..083e8b25de0 100644 --- a/advisories/github-reviewed/2024/06/GHSA-3hjh-jh2h-vrg6/GHSA-3hjh-jh2h-vrg6.json +++ b/advisories/github-reviewed/2024/06/GHSA-3hjh-jh2h-vrg6/GHSA-3hjh-jh2h-vrg6.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3hjh-jh2h-vrg6", - "modified": "2024-06-14T23:25:31Z", + "modified": "2024-11-04T15:27:57Z", "published": "2024-06-06T21:30:36Z", "aliases": [ "CVE-2024-2965" @@ -33,6 +33,25 @@ ] } ] + }, + { + "package": { + "ecosystem": "PyPI", + "name": "langchain" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.2.5" + } + ] + } + ] } ], "references": [ @@ -44,6 +63,10 @@ "type": "WEB", "url": "https://github.com/langchain-ai/langchain/pull/22903" }, + { + "type": "WEB", + "url": "https://github.com/langchain-ai/langchain/commit/73c42306745b0831aa6fe7fe4eeb70d2c2d87a82" + }, { "type": "WEB", "url": "https://github.com/langchain-ai/langchain/commit/9a877c7adbd06f90a2518152f65b562bd90487cc" @@ -52,6 +75,10 @@ "type": "PACKAGE", "url": "https://github.com/langchain-ai/langchain" }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/langchain/PYSEC-2024-118.yaml" + }, { "type": "WEB", "url": "https://huntr.com/bounties/90b0776d-9fa6-4841-aac4-09fde5918cae" diff --git a/advisories/github-reviewed/2024/06/GHSA-3xr8-qfvj-9p9j/GHSA-3xr8-qfvj-9p9j.json b/advisories/github-reviewed/2024/06/GHSA-3xr8-qfvj-9p9j/GHSA-3xr8-qfvj-9p9j.json index 35dd1480c38..988b7a11d89 100644 --- a/advisories/github-reviewed/2024/06/GHSA-3xr8-qfvj-9p9j/GHSA-3xr8-qfvj-9p9j.json +++ b/advisories/github-reviewed/2024/06/GHSA-3xr8-qfvj-9p9j/GHSA-3xr8-qfvj-9p9j.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-3xr8-qfvj-9p9j", - "modified": "2024-06-06T22:55:45Z", + "modified": "2024-11-04T15:27:17Z", "published": "2024-06-06T21:30:37Z", "aliases": [ "CVE-2024-4888" @@ -12,6 +12,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N" } ], "affected": [ @@ -58,7 +62,7 @@ "CWE-20", "CWE-862" ], - "severity": "MODERATE", + "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2024-06-06T22:55:45Z", "nvd_published_at": "2024-06-06T19:16:03Z" diff --git a/advisories/github-reviewed/2024/09/GHSA-w73r-8mm4-cfvf/GHSA-w73r-8mm4-cfvf.json b/advisories/github-reviewed/2024/09/GHSA-w73r-8mm4-cfvf/GHSA-w73r-8mm4-cfvf.json index f4e29e65fe4..afe3a1fde3f 100644 --- a/advisories/github-reviewed/2024/09/GHSA-w73r-8mm4-cfvf/GHSA-w73r-8mm4-cfvf.json +++ b/advisories/github-reviewed/2024/09/GHSA-w73r-8mm4-cfvf/GHSA-w73r-8mm4-cfvf.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-w73r-8mm4-cfvf", - "modified": "2024-09-19T21:46:15Z", + "modified": "2024-11-04T15:27:42Z", "published": "2024-09-13T18:31:48Z", "aliases": [ "CVE-2024-6582" @@ -62,7 +62,7 @@ "CWE-287", "CWE-306" ], - "severity": "MODERATE", + "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2024-09-13T19:29:14Z", "nvd_published_at": "2024-09-13T17:15:13Z"