diff --git a/advisories/github-reviewed/2019/08/GHSA-8rf6-w2mx-4xjh/GHSA-8rf6-w2mx-4xjh.json b/advisories/github-reviewed/2019/08/GHSA-8rf6-w2mx-4xjh/GHSA-8rf6-w2mx-4xjh.json index 6d50a077ee7..d2c7053ffed 100644 --- a/advisories/github-reviewed/2019/08/GHSA-8rf6-w2mx-4xjh/GHSA-8rf6-w2mx-4xjh.json +++ b/advisories/github-reviewed/2019/08/GHSA-8rf6-w2mx-4xjh/GHSA-8rf6-w2mx-4xjh.json @@ -1,16 +1,19 @@ { "schema_version": "1.4.0", "id": "GHSA-8rf6-w2mx-4xjh", - "modified": "2021-12-03T14:37:54Z", + "modified": "2024-03-21T16:17:11Z", "published": "2019-08-19T23:45:47Z", "withdrawn": "2019-08-20T14:13:17Z", "aliases": [ "CVE-2019-15149" ], - "summary": "TODO", - "details": "** DISPUTED ** core.py in Mitogen before 0.2.8 has a typo that drops the unidirectional-routing protection mechanism in the case of a child that is initiated by another child. The Ansible extension is unaffected. NOTE: the vendor disputes this issue because it is exploitable only in conjunction with hypothetical other factors, i.e., an affected use case within a library caller, and a bug in the message receiver policy code that led to reliance on this extra protection mechanism.", + "summary": "Undirectional routing wasn't respected in some cases in Mitogen", + "details": "core.py in Mitogen before 0.2.8 has a typo that drops the unidirectional-routing protection mechanism in the case of a child that is initiated by another child. The Ansible extension is unaffected. NOTE: the vendor disputes this issue because it is exploitable only in conjunction with hypothetical other factors, i.e., an affected use case within a library caller, and a bug in the message receiver policy code that led to reliance on this extra protection mechanism.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ {