Publish Advisories

GHSA-cpcw-9h9m-wqw9
GHSA-m95h-p4gg-wfw3
This commit is contained in:
advisory-database[bot]
2024-02-16 21:59:37 +00:00
parent 5e58897359
commit 42e12f40c5
2 changed files with 5 additions and 5 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-cpcw-9h9m-wqw9",
"modified": "2024-02-16T21:56:21Z",
"modified": "2024-02-16T21:57:45Z",
"published": "2024-02-06T15:32:06Z",
"aliases": [
"CVE-2024-24590"
@@ -11,7 +11,7 @@
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
@@ -1,17 +1,17 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m95h-p4gg-wfw3",
"modified": "2024-02-13T21:56:54Z",
"modified": "2024-02-16T21:57:25Z",
"published": "2024-02-06T15:32:07Z",
"aliases": [
"CVE-2024-24591"
],
"summary": "Allegro AI ClearML path traversal vulnerability",
"details": "A path traversal vulnerability in version 1.4.0 or newer of Allegro AIs ClearML platform enables a maliciously uploaded dataset to write local or remote files to an arbitrary location on an end users system when interacted with.\n",
"details": "A path traversal vulnerability in versions 1.4.0 to 1.14.1 of the client SDK of Allegro AIs ClearML platform enables a maliciously uploaded dataset to write local or remote files to an arbitrary location on an end users system when interacted with.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [