diff --git a/advisories/github-reviewed/2024/03/GHSA-c2x9-vw5h-39vc/GHSA-c2x9-vw5h-39vc.json b/advisories/github-reviewed/2024/03/GHSA-c2x9-vw5h-39vc/GHSA-c2x9-vw5h-39vc.json index 8bdfe52c44e..3754f3ff439 100644 --- a/advisories/github-reviewed/2024/03/GHSA-c2x9-vw5h-39vc/GHSA-c2x9-vw5h-39vc.json +++ b/advisories/github-reviewed/2024/03/GHSA-c2x9-vw5h-39vc/GHSA-c2x9-vw5h-39vc.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-c2x9-vw5h-39vc", - "modified": "2024-05-02T18:42:26Z", + "modified": "2025-01-21T18:19:26Z", "published": "2024-03-12T21:30:59Z", "aliases": [ "CVE-2024-27894" @@ -11,7 +11,7 @@ "severity": [ { "type": "CVSS_V3", - "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H" + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], "affected": [ diff --git a/advisories/github-reviewed/2024/03/GHSA-g627-r579-rw35/GHSA-g627-r579-rw35.json b/advisories/github-reviewed/2024/03/GHSA-g627-r579-rw35/GHSA-g627-r579-rw35.json index 69994d8a881..f05d67d7a18 100644 --- a/advisories/github-reviewed/2024/03/GHSA-g627-r579-rw35/GHSA-g627-r579-rw35.json +++ b/advisories/github-reviewed/2024/03/GHSA-g627-r579-rw35/GHSA-g627-r579-rw35.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-g627-r579-rw35", - "modified": "2024-05-02T18:44:43Z", + "modified": "2025-01-21T18:19:07Z", "published": "2024-03-12T21:30:59Z", "aliases": [ "CVE-2024-28098" @@ -11,7 +11,7 @@ "severity": [ { "type": "CVSS_V3", - "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N" + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N" } ], "affected": [ diff --git a/advisories/github-reviewed/2024/06/GHSA-qg33-x2c5-6p44/GHSA-qg33-x2c5-6p44.json b/advisories/github-reviewed/2024/06/GHSA-qg33-x2c5-6p44/GHSA-qg33-x2c5-6p44.json index 45900dfb081..829abf7938d 100644 --- a/advisories/github-reviewed/2024/06/GHSA-qg33-x2c5-6p44/GHSA-qg33-x2c5-6p44.json +++ b/advisories/github-reviewed/2024/06/GHSA-qg33-x2c5-6p44/GHSA-qg33-x2c5-6p44.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-qg33-x2c5-6p44", - "modified": "2024-06-11T19:29:16Z", + "modified": "2025-01-21T18:18:10Z", "published": "2024-06-10T21:30:38Z", "aliases": [ "CVE-2024-37014" ], "summary": "Langflow remote code execution vulnerability", - "details": "Langflow through 0.6.19 allows remote code execution if untrusted users are able to reach the \"POST /api/v1/custom_component\" endpoint and provide a Python script.", + "details": "Langflow allows remote code execution if untrusted users are able to reach the \"POST /api/v1/custom_component\" endpoint and provide a Python script.", "severity": [ { "type": "CVSS_V3", @@ -28,7 +28,7 @@ "introduced": "0" }, { - "last_affected": "0.6.19" + "fixed": "1.0.15" } ] } @@ -47,6 +47,10 @@ { "type": "PACKAGE", "url": "https://github.com/langflow-ai/langflow" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/langflow/PYSEC-2024-177.yaml" } ], "database_specific": { diff --git a/advisories/github-reviewed/2024/07/GHSA-cx7h-h87r-jpgr/GHSA-cx7h-h87r-jpgr.json b/advisories/github-reviewed/2024/07/GHSA-cx7h-h87r-jpgr/GHSA-cx7h-h87r-jpgr.json index a160f3361b2..aa6b0f4715c 100644 --- a/advisories/github-reviewed/2024/07/GHSA-cx7h-h87r-jpgr/GHSA-cx7h-h87r-jpgr.json +++ b/advisories/github-reviewed/2024/07/GHSA-cx7h-h87r-jpgr/GHSA-cx7h-h87r-jpgr.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-cx7h-h87r-jpgr", - "modified": "2024-07-25T16:38:42Z", + "modified": "2025-01-21T18:18:40Z", "published": "2024-07-25T16:38:42Z", "aliases": [], "summary": "The kstring integration in gix-attributes is unsound", @@ -33,6 +33,10 @@ "type": "WEB", "url": "https://github.com/Byron/gitoxide/issues/1460" }, + { + "type": "WEB", + "url": "https://github.com/GitoxideLabs/gitoxide/issues/1460" + }, { "type": "WEB", "url": "https://github.com/rustsec/advisory-db/commit/884aaa1646132bc3a27ba058197d6ef039bec294"