From 87e983ce68473a50f47a2e5d4f394f19957c54ab Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 17 Jun 2024 21:22:12 +0000 Subject: [PATCH] Publish Advisories GHSA-w877-jfw7-46rj GHSA-wmvm-9vqv-5qpp --- .../GHSA-w877-jfw7-46rj.json | 77 +++++++++++++++++++ .../GHSA-wmvm-9vqv-5qpp.json | 37 +++++++-- 2 files changed, 109 insertions(+), 5 deletions(-) create mode 100644 advisories/github-reviewed/2024/06/GHSA-w877-jfw7-46rj/GHSA-w877-jfw7-46rj.json rename advisories/{unreviewed => github-reviewed}/2024/06/GHSA-wmvm-9vqv-5qpp/GHSA-wmvm-9vqv-5qpp.json (56%) diff --git a/advisories/github-reviewed/2024/06/GHSA-w877-jfw7-46rj/GHSA-w877-jfw7-46rj.json b/advisories/github-reviewed/2024/06/GHSA-w877-jfw7-46rj/GHSA-w877-jfw7-46rj.json new file mode 100644 index 00000000000..6c95e9eea71 --- /dev/null +++ b/advisories/github-reviewed/2024/06/GHSA-w877-jfw7-46rj/GHSA-w877-jfw7-46rj.json @@ -0,0 +1,77 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w877-jfw7-46rj", + "modified": "2024-06-17T21:20:44Z", + "published": "2024-06-17T21:20:44Z", + "aliases": [ + "CVE-2024-37902" + ], + "summary": "DeepJavaLibrary API absolute path traversal", + "details": "## Summary\n\nDeepJavaLibrary(DJL) versions 0.1.0 through 0.27.0 do not prevent absolute path archived artifacts from inserting archived files directly into the system, overwriting system files. This is fixed in DJL 0.28.0 and patched in DJL Large Model Inference containers 0.27.0.\n\n**Impacted versions: 0.1.0 through 0.27.0**\n\n## Patches\n\nPatched Deep Learning Containers:\n[v1.1-djl-0.27.0-inf-cpu-full](https://github.com/aws/deep-learning-containers/releases/tag/v1.1-djl-0.27.0-inf-cpu-full)\n[v1.4-djl-0.27.0-inf-ds-0.12.6](https://github.com/aws/deep-learning-containers/releases/tag/v1.4-djl-0.27.0-inf-ds-0.12.6)\n[v1.4-djl-0.27.0-inf-trt-0.8.0](https://github.com/aws/deep-learning-containers/releases/tag/v1.4-djl-0.27.0-inf-trt-0.8.0)\n[v1.3-djl-0.27.0-inf-neuronx-sdk2.18.1](https://github.com/aws/deep-learning-containers/releases/tag/v1.3-djl-0.27.0-inf-neuronx-sdk2.18.1)\n\nPatched Library:\n[v0.28.0](https://github.com/deepjavalibrary/djl/releases/tag/v0.28.0)\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Maven", + "name": "ai.djl:api" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0.1.0" + }, + { + "fixed": "0.28.0" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/deepjavalibrary/djl/security/advisories/GHSA-w877-jfw7-46rj" + }, + { + "type": "WEB", + "url": "https://github.com/aws/deep-learning-containers/releases/tag/v1.1-djl-0.27.0-inf-cpu-full" + }, + { + "type": "WEB", + "url": "https://github.com/aws/deep-learning-containers/releases/tag/v1.3-djl-0.27.0-inf-neuronx-sdk2.18.1" + }, + { + "type": "WEB", + "url": "https://github.com/aws/deep-learning-containers/releases/tag/v1.4-djl-0.27.0-inf-ds-0.12.6" + }, + { + "type": "WEB", + "url": "https://github.com/aws/deep-learning-containers/releases/tag/v1.4-djl-0.27.0-inf-trt-0.8.0" + }, + { + "type": "PACKAGE", + "url": "https://github.com/deepjavalibrary/djl" + }, + { + "type": "WEB", + "url": "https://github.com/deepjavalibrary/djl/releases/tag/v0.28.0" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "CRITICAL", + "github_reviewed": true, + "github_reviewed_at": "2024-06-17T21:20:44Z", + "nvd_published_at": null + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/06/GHSA-wmvm-9vqv-5qpp/GHSA-wmvm-9vqv-5qpp.json b/advisories/github-reviewed/2024/06/GHSA-wmvm-9vqv-5qpp/GHSA-wmvm-9vqv-5qpp.json similarity index 56% rename from advisories/unreviewed/2024/06/GHSA-wmvm-9vqv-5qpp/GHSA-wmvm-9vqv-5qpp.json rename to advisories/github-reviewed/2024/06/GHSA-wmvm-9vqv-5qpp/GHSA-wmvm-9vqv-5qpp.json index 204a2b10430..554b90877ea 100644 --- a/advisories/unreviewed/2024/06/GHSA-wmvm-9vqv-5qpp/GHSA-wmvm-9vqv-5qpp.json +++ b/advisories/github-reviewed/2024/06/GHSA-wmvm-9vqv-5qpp/GHSA-wmvm-9vqv-5qpp.json @@ -1,17 +1,36 @@ { "schema_version": "1.4.0", "id": "GHSA-wmvm-9vqv-5qpp", - "modified": "2024-06-16T15:30:44Z", + "modified": "2024-06-17T21:21:47Z", "published": "2024-06-16T15:30:44Z", "aliases": [ "CVE-2024-38459" ], + "summary": "langchain_experimental Code Execution via Python REPL access", "details": "langchain_experimental (aka LangChain Experimental) before 0.0.61 for LangChain provides Python REPL access without an opt-in step. NOTE; this issue exists because of an incomplete fix for CVE-2024-27444.", "severity": [ ], "affected": [ - + { + "package": { + "ecosystem": "PyPI", + "name": "langchain-experimental" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.0.61" + } + ] + } + ] + } ], "references": [ { @@ -26,18 +45,26 @@ "type": "WEB", "url": "https://github.com/langchain-ai/langchain/commit/ce0b0f22a175139df8f41cdcfb4d2af411112009" }, + { + "type": "PACKAGE", + "url": "https://github.com/langchain-ai/langchain" + }, { "type": "WEB", "url": "https://github.com/langchain-ai/langchain/compare/langchain-experimental==0.0.60...langchain-experimental==0.0.61" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/langchain-experimental/PYSEC-2024-53.yaml" } ], "database_specific": { "cwe_ids": [ ], - "severity": null, - "github_reviewed": false, - "github_reviewed_at": null, + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-06-17T21:21:47Z", "nvd_published_at": "2024-06-16T15:15:51Z" } } \ No newline at end of file