diff --git a/advisories/github-reviewed/2024/06/GHSA-w877-jfw7-46rj/GHSA-w877-jfw7-46rj.json b/advisories/github-reviewed/2024/06/GHSA-w877-jfw7-46rj/GHSA-w877-jfw7-46rj.json new file mode 100644 index 00000000000..6c95e9eea71 --- /dev/null +++ b/advisories/github-reviewed/2024/06/GHSA-w877-jfw7-46rj/GHSA-w877-jfw7-46rj.json @@ -0,0 +1,77 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w877-jfw7-46rj", + "modified": "2024-06-17T21:20:44Z", + "published": "2024-06-17T21:20:44Z", + "aliases": [ + "CVE-2024-37902" + ], + "summary": "DeepJavaLibrary API absolute path traversal", + "details": "## Summary\n\nDeepJavaLibrary(DJL) versions 0.1.0 through 0.27.0 do not prevent absolute path archived artifacts from inserting archived files directly into the system, overwriting system files. This is fixed in DJL 0.28.0 and patched in DJL Large Model Inference containers 0.27.0.\n\n**Impacted versions: 0.1.0 through 0.27.0**\n\n## Patches\n\nPatched Deep Learning Containers:\n[v1.1-djl-0.27.0-inf-cpu-full](https://github.com/aws/deep-learning-containers/releases/tag/v1.1-djl-0.27.0-inf-cpu-full)\n[v1.4-djl-0.27.0-inf-ds-0.12.6](https://github.com/aws/deep-learning-containers/releases/tag/v1.4-djl-0.27.0-inf-ds-0.12.6)\n[v1.4-djl-0.27.0-inf-trt-0.8.0](https://github.com/aws/deep-learning-containers/releases/tag/v1.4-djl-0.27.0-inf-trt-0.8.0)\n[v1.3-djl-0.27.0-inf-neuronx-sdk2.18.1](https://github.com/aws/deep-learning-containers/releases/tag/v1.3-djl-0.27.0-inf-neuronx-sdk2.18.1)\n\nPatched Library:\n[v0.28.0](https://github.com/deepjavalibrary/djl/releases/tag/v0.28.0)\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Maven", + "name": "ai.djl:api" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0.1.0" + }, + { + "fixed": "0.28.0" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/deepjavalibrary/djl/security/advisories/GHSA-w877-jfw7-46rj" + }, + { + "type": "WEB", + "url": "https://github.com/aws/deep-learning-containers/releases/tag/v1.1-djl-0.27.0-inf-cpu-full" + }, + { + "type": "WEB", + "url": "https://github.com/aws/deep-learning-containers/releases/tag/v1.3-djl-0.27.0-inf-neuronx-sdk2.18.1" + }, + { + "type": "WEB", + "url": "https://github.com/aws/deep-learning-containers/releases/tag/v1.4-djl-0.27.0-inf-ds-0.12.6" + }, + { + "type": "WEB", + "url": "https://github.com/aws/deep-learning-containers/releases/tag/v1.4-djl-0.27.0-inf-trt-0.8.0" + }, + { + "type": "PACKAGE", + "url": "https://github.com/deepjavalibrary/djl" + }, + { + "type": "WEB", + "url": "https://github.com/deepjavalibrary/djl/releases/tag/v0.28.0" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "CRITICAL", + "github_reviewed": true, + "github_reviewed_at": "2024-06-17T21:20:44Z", + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-wmvm-9vqv-5qpp/GHSA-wmvm-9vqv-5qpp.json b/advisories/github-reviewed/2024/06/GHSA-wmvm-9vqv-5qpp/GHSA-wmvm-9vqv-5qpp.json similarity index 56% rename from advisories/unreviewed/2024/06/GHSA-wmvm-9vqv-5qpp/GHSA-wmvm-9vqv-5qpp.json rename to advisories/github-reviewed/2024/06/GHSA-wmvm-9vqv-5qpp/GHSA-wmvm-9vqv-5qpp.json index 204a2b10430..554b90877ea 100644 --- a/advisories/unreviewed/2024/06/GHSA-wmvm-9vqv-5qpp/GHSA-wmvm-9vqv-5qpp.json +++ b/advisories/github-reviewed/2024/06/GHSA-wmvm-9vqv-5qpp/GHSA-wmvm-9vqv-5qpp.json @@ -1,17 +1,36 @@ { "schema_version": "1.4.0", "id": "GHSA-wmvm-9vqv-5qpp", - "modified": "2024-06-16T15:30:44Z", + "modified": "2024-06-17T21:21:47Z", "published": "2024-06-16T15:30:44Z", "aliases": [ "CVE-2024-38459" ], + "summary": "langchain_experimental Code Execution via Python REPL access", "details": "langchain_experimental (aka LangChain Experimental) before 0.0.61 for LangChain provides Python REPL access without an opt-in step. NOTE; this issue exists because of an incomplete fix for CVE-2024-27444.", "severity": [ ], "affected": [ - + { + "package": { + "ecosystem": "PyPI", + "name": "langchain-experimental" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.0.61" + } + ] + } + ] + } ], "references": [ { @@ -26,18 +45,26 @@ "type": "WEB", "url": "https://github.com/langchain-ai/langchain/commit/ce0b0f22a175139df8f41cdcfb4d2af411112009" }, + { + "type": "PACKAGE", + "url": "https://github.com/langchain-ai/langchain" + }, { "type": "WEB", "url": "https://github.com/langchain-ai/langchain/compare/langchain-experimental==0.0.60...langchain-experimental==0.0.61" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/langchain-experimental/PYSEC-2024-53.yaml" } ], "database_specific": { "cwe_ids": [ ], - "severity": null, - "github_reviewed": false, - "github_reviewed_at": null, + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-06-17T21:21:47Z", "nvd_published_at": "2024-06-16T15:15:51Z" } } \ No newline at end of file