From 61a3aa6ac4203eccf8bcc3a1b413405a7b2ab97f Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 27 Sep 2024 21:29:09 +0000 Subject: [PATCH] Publish Advisories GHSA-gf2q-j2qq-pjf2 GHSA-prgp-w7vf-ch62 --- .../05/GHSA-gf2q-j2qq-pjf2/GHSA-gf2q-j2qq-pjf2.json | 11 +++++++++-- .../08/GHSA-prgp-w7vf-ch62/GHSA-prgp-w7vf-ch62.json | 10 +++++++++- 2 files changed, 18 insertions(+), 3 deletions(-) diff --git a/advisories/github-reviewed/2022/05/GHSA-gf2q-j2qq-pjf2/GHSA-gf2q-j2qq-pjf2.json b/advisories/github-reviewed/2022/05/GHSA-gf2q-j2qq-pjf2/GHSA-gf2q-j2qq-pjf2.json index 48927b1f250..effd15308a7 100644 --- a/advisories/github-reviewed/2022/05/GHSA-gf2q-j2qq-pjf2/GHSA-gf2q-j2qq-pjf2.json +++ b/advisories/github-reviewed/2022/05/GHSA-gf2q-j2qq-pjf2/GHSA-gf2q-j2qq-pjf2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-gf2q-j2qq-pjf2", - "modified": "2023-08-16T20:36:06Z", + "modified": "2024-09-27T21:28:19Z", "published": "2022-05-17T05:22:32Z", "aliases": [ "CVE-2012-3542" @@ -9,7 +9,14 @@ "summary": "OpenStack Keystone Allows Remote User Account Creation", "details": "OpenStack Keystone, as used in OpenStack Folsom before folsom-rc1 and OpenStack Essex (2012.1), allows remote attackers to add an arbitrary user to an arbitrary tenant via a request to update the user's default tenant to the administrative API. NOTE: this identifier was originally incorrectly assigned to an open redirect issue, but the correct identifier for that issue is CVE-2012-3540.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N" + } ], "affected": [ { diff --git a/advisories/github-reviewed/2023/08/GHSA-prgp-w7vf-ch62/GHSA-prgp-w7vf-ch62.json b/advisories/github-reviewed/2023/08/GHSA-prgp-w7vf-ch62/GHSA-prgp-w7vf-ch62.json index ca67fa0dc83..b5fd63f735c 100644 --- a/advisories/github-reviewed/2023/08/GHSA-prgp-w7vf-ch62/GHSA-prgp-w7vf-ch62.json +++ b/advisories/github-reviewed/2023/08/GHSA-prgp-w7vf-ch62/GHSA-prgp-w7vf-ch62.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-prgp-w7vf-ch62", - "modified": "2023-10-30T20:15:55Z", + "modified": "2024-09-27T21:26:54Z", "published": "2023-08-15T18:31:32Z", "aliases": [ "CVE-2023-39659" @@ -12,6 +12,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" } ], "affected": [ @@ -63,6 +67,10 @@ { "type": "WEB", "url": "https://github.com/langchain-ai/langchain/releases/tag/v0.0.325" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/langchain/PYSEC-2023-147.yaml" } ], "database_specific": {