diff --git a/advisories/unreviewed/2024/06/GHSA-43c4-9qgj-x742/GHSA-43c4-9qgj-x742.json b/advisories/github-reviewed/2024/06/GHSA-43c4-9qgj-x742/GHSA-43c4-9qgj-x742.json similarity index 60% rename from advisories/unreviewed/2024/06/GHSA-43c4-9qgj-x742/GHSA-43c4-9qgj-x742.json rename to advisories/github-reviewed/2024/06/GHSA-43c4-9qgj-x742/GHSA-43c4-9qgj-x742.json index 62e07fc0bd5..29e6edf6f57 100644 --- a/advisories/unreviewed/2024/06/GHSA-43c4-9qgj-x742/GHSA-43c4-9qgj-x742.json +++ b/advisories/github-reviewed/2024/06/GHSA-43c4-9qgj-x742/GHSA-43c4-9qgj-x742.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-43c4-9qgj-x742", - "modified": "2024-06-04T12:31:04Z", + "modified": "2024-06-05T13:17:49Z", "published": "2024-06-04T12:31:04Z", "aliases": [ "CVE-2024-37053" ], + "summary": "MLFlow unsafe deserialization", "details": "Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling a maliciously uploaded scikit-learn model to run arbitrary code on an end user’s system when interacted with.", "severity": [ { @@ -14,13 +15,35 @@ } ], "affected": [ - + { + "package": { + "ecosystem": "PyPI", + "name": "mlflow" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "1.1.0" + }, + { + "last_affected": "2.13.1" + } + ] + } + ] + } ], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37053" }, + { + "type": "PACKAGE", + "url": "https://github.com/mlflow/mlflow" + }, { "type": "WEB", "url": "https://hiddenlayer.com/sai-security-advisory/mlflow-june2024" @@ -31,8 +54,8 @@ "CWE-502" ], "severity": "HIGH", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-06-05T13:17:49Z", "nvd_published_at": "2024-06-04T12:15:10Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-76cg-cfhx-373f/GHSA-76cg-cfhx-373f.json b/advisories/github-reviewed/2024/06/GHSA-76cg-cfhx-373f/GHSA-76cg-cfhx-373f.json similarity index 60% rename from advisories/unreviewed/2024/06/GHSA-76cg-cfhx-373f/GHSA-76cg-cfhx-373f.json rename to advisories/github-reviewed/2024/06/GHSA-76cg-cfhx-373f/GHSA-76cg-cfhx-373f.json index b59e1d1b32b..11ee637e102 100644 --- a/advisories/unreviewed/2024/06/GHSA-76cg-cfhx-373f/GHSA-76cg-cfhx-373f.json +++ b/advisories/github-reviewed/2024/06/GHSA-76cg-cfhx-373f/GHSA-76cg-cfhx-373f.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-76cg-cfhx-373f", - "modified": "2024-06-04T12:31:04Z", + "modified": "2024-06-05T13:18:30Z", "published": "2024-06-04T12:31:04Z", "aliases": [ "CVE-2024-37052" ], + "summary": "MLFlow unsafe deserialization", "details": "Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling a maliciously uploaded scikit-learn model to run arbitrary code on an end user’s system when interacted with.", "severity": [ { @@ -14,13 +15,35 @@ } ], "affected": [ - + { + "package": { + "ecosystem": "PyPI", + "name": "mlflow" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "1.1.0" + }, + { + "last_affected": "2.13.1" + } + ] + } + ] + } ], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37052" }, + { + "type": "PACKAGE", + "url": "https://github.com/mlflow/mlflow" + }, { "type": "WEB", "url": "https://hiddenlayer.com/sai-security-advisory/mlflow-june2024" @@ -31,8 +54,8 @@ "CWE-502" ], "severity": "HIGH", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-06-05T13:18:30Z", "nvd_published_at": "2024-06-04T12:15:10Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-7p8j-qv6x-f4g4/GHSA-7p8j-qv6x-f4g4.json b/advisories/github-reviewed/2024/06/GHSA-7p8j-qv6x-f4g4/GHSA-7p8j-qv6x-f4g4.json similarity index 60% rename from advisories/unreviewed/2024/06/GHSA-7p8j-qv6x-f4g4/GHSA-7p8j-qv6x-f4g4.json rename to advisories/github-reviewed/2024/06/GHSA-7p8j-qv6x-f4g4/GHSA-7p8j-qv6x-f4g4.json index 117f0d59ff0..ee4de1a9eee 100644 --- a/advisories/unreviewed/2024/06/GHSA-7p8j-qv6x-f4g4/GHSA-7p8j-qv6x-f4g4.json +++ b/advisories/github-reviewed/2024/06/GHSA-7p8j-qv6x-f4g4/GHSA-7p8j-qv6x-f4g4.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-7p8j-qv6x-f4g4", - "modified": "2024-06-04T12:31:04Z", + "modified": "2024-06-05T13:18:19Z", "published": "2024-06-04T12:31:04Z", "aliases": [ "CVE-2024-37056" ], + "summary": "MLFlow unsafe deserialization", "details": "Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.23.0 or newer, enabling a maliciously uploaded LightGBM scikit-learn model to run arbitrary code on an end user’s system when interacted with.", "severity": [ { @@ -14,13 +15,35 @@ } ], "affected": [ - + { + "package": { + "ecosystem": "PyPI", + "name": "mlflow" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "1.23.0" + }, + { + "last_affected": "2.13.1" + } + ] + } + ] + } ], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37056" }, + { + "type": "PACKAGE", + "url": "https://github.com/mlflow/mlflow" + }, { "type": "WEB", "url": "https://hiddenlayer.com/sai-security-advisory/mlflow-june2024" @@ -31,8 +54,8 @@ "CWE-502" ], "severity": "HIGH", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-06-05T13:18:19Z", "nvd_published_at": "2024-06-04T12:15:11Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-ghv6-9r9j-wh4j/GHSA-ghv6-9r9j-wh4j.json b/advisories/github-reviewed/2024/06/GHSA-ghv6-9r9j-wh4j/GHSA-ghv6-9r9j-wh4j.json similarity index 60% rename from advisories/unreviewed/2024/06/GHSA-ghv6-9r9j-wh4j/GHSA-ghv6-9r9j-wh4j.json rename to advisories/github-reviewed/2024/06/GHSA-ghv6-9r9j-wh4j/GHSA-ghv6-9r9j-wh4j.json index 25097eeb302..56c0b51f4bb 100644 --- a/advisories/unreviewed/2024/06/GHSA-ghv6-9r9j-wh4j/GHSA-ghv6-9r9j-wh4j.json +++ b/advisories/github-reviewed/2024/06/GHSA-ghv6-9r9j-wh4j/GHSA-ghv6-9r9j-wh4j.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-ghv6-9r9j-wh4j", - "modified": "2024-06-04T12:31:04Z", + "modified": "2024-06-05T13:17:58Z", "published": "2024-06-04T12:31:04Z", "aliases": [ "CVE-2024-37054" ], + "summary": "MLFlow unsafe deserialization", "details": "Deserialization of untrusted data can occur in versions of the MLflow platform running version 0.9.0 or newer, enabling a maliciously uploaded PyFunc model to run arbitrary code on an end user’s system when interacted with.", "severity": [ { @@ -14,13 +15,35 @@ } ], "affected": [ - + { + "package": { + "ecosystem": "PyPI", + "name": "mlflow" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0.9.0" + }, + { + "last_affected": "2.13.1" + } + ] + } + ] + } ], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37054" }, + { + "type": "PACKAGE", + "url": "https://github.com/mlflow/mlflow" + }, { "type": "WEB", "url": "https://hiddenlayer.com/sai-security-advisory/mlflow-june2024" @@ -31,8 +54,8 @@ "CWE-502" ], "severity": "HIGH", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-06-05T13:17:58Z", "nvd_published_at": "2024-06-04T12:15:11Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-j8mg-pqc5-x9gj/GHSA-j8mg-pqc5-x9gj.json b/advisories/github-reviewed/2024/06/GHSA-j8mg-pqc5-x9gj/GHSA-j8mg-pqc5-x9gj.json similarity index 60% rename from advisories/unreviewed/2024/06/GHSA-j8mg-pqc5-x9gj/GHSA-j8mg-pqc5-x9gj.json rename to advisories/github-reviewed/2024/06/GHSA-j8mg-pqc5-x9gj/GHSA-j8mg-pqc5-x9gj.json index 36b1fc573b3..a994be33154 100644 --- a/advisories/unreviewed/2024/06/GHSA-j8mg-pqc5-x9gj/GHSA-j8mg-pqc5-x9gj.json +++ b/advisories/github-reviewed/2024/06/GHSA-j8mg-pqc5-x9gj/GHSA-j8mg-pqc5-x9gj.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-j8mg-pqc5-x9gj", - "modified": "2024-06-04T12:31:05Z", + "modified": "2024-06-05T13:18:38Z", "published": "2024-06-04T12:31:05Z", "aliases": [ "CVE-2024-37057" ], + "summary": "MLFlow unsafe deserialization", "details": "Deserialization of untrusted data can occur in versions of the MLflow platform running version 2.0.0rc0 or newer, enabling a maliciously uploaded Tensorflow model to run arbitrary code on an end user’s system when interacted with.", "severity": [ { @@ -14,13 +15,35 @@ } ], "affected": [ - + { + "package": { + "ecosystem": "PyPI", + "name": "mlflow" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "2.0.0rc0" + }, + { + "last_affected": "2.13.1" + } + ] + } + ] + } ], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37057" }, + { + "type": "PACKAGE", + "url": "https://github.com/mlflow/mlflow" + }, { "type": "WEB", "url": "https://hiddenlayer.com/sai-security-advisory/mlflow-june2024" @@ -31,8 +54,8 @@ "CWE-502" ], "severity": "HIGH", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-06-05T13:18:38Z", "nvd_published_at": "2024-06-04T12:15:11Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-x38x-g6gr-jqff/GHSA-x38x-g6gr-jqff.json b/advisories/github-reviewed/2024/06/GHSA-x38x-g6gr-jqff/GHSA-x38x-g6gr-jqff.json similarity index 60% rename from advisories/unreviewed/2024/06/GHSA-x38x-g6gr-jqff/GHSA-x38x-g6gr-jqff.json rename to advisories/github-reviewed/2024/06/GHSA-x38x-g6gr-jqff/GHSA-x38x-g6gr-jqff.json index e26d8c04705..e015e7aca18 100644 --- a/advisories/unreviewed/2024/06/GHSA-x38x-g6gr-jqff/GHSA-x38x-g6gr-jqff.json +++ b/advisories/github-reviewed/2024/06/GHSA-x38x-g6gr-jqff/GHSA-x38x-g6gr-jqff.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-x38x-g6gr-jqff", - "modified": "2024-06-04T12:31:04Z", + "modified": "2024-06-05T13:18:08Z", "published": "2024-06-04T12:31:04Z", "aliases": [ "CVE-2024-37055" ], + "summary": "MLFlow unsafe deserialization", "details": "Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.24.0 or newer, enabling a maliciously uploaded pmdarima model to run arbitrary code on an end user’s system when interacted with.", "severity": [ { @@ -14,13 +15,35 @@ } ], "affected": [ - + { + "package": { + "ecosystem": "PyPI", + "name": "mlflow" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "1.24.0" + }, + { + "last_affected": "2.13.1" + } + ] + } + ] + } ], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-37055" }, + { + "type": "PACKAGE", + "url": "https://github.com/mlflow/mlflow" + }, { "type": "WEB", "url": "https://hiddenlayer.com/sai-security-advisory/mlflow-june2024" @@ -31,8 +54,8 @@ "CWE-502" ], "severity": "HIGH", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-06-05T13:18:08Z", "nvd_published_at": "2024-06-04T12:15:11Z" } } \ No newline at end of file