From 9aa3af24ae25c95dfa5d0e988105eaed659d9f7a Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 21 Mar 2024 16:18:21 +0000 Subject: [PATCH] Publish GHSA-8rf6-w2mx-4xjh --- .../08/GHSA-8rf6-w2mx-4xjh/GHSA-8rf6-w2mx-4xjh.json | 11 +++++++---- 1 file changed, 7 insertions(+), 4 deletions(-) diff --git a/advisories/github-reviewed/2019/08/GHSA-8rf6-w2mx-4xjh/GHSA-8rf6-w2mx-4xjh.json b/advisories/github-reviewed/2019/08/GHSA-8rf6-w2mx-4xjh/GHSA-8rf6-w2mx-4xjh.json index 6d50a077ee7..d2c7053ffed 100644 --- a/advisories/github-reviewed/2019/08/GHSA-8rf6-w2mx-4xjh/GHSA-8rf6-w2mx-4xjh.json +++ b/advisories/github-reviewed/2019/08/GHSA-8rf6-w2mx-4xjh/GHSA-8rf6-w2mx-4xjh.json @@ -1,16 +1,19 @@ { "schema_version": "1.4.0", "id": "GHSA-8rf6-w2mx-4xjh", - "modified": "2021-12-03T14:37:54Z", + "modified": "2024-03-21T16:17:11Z", "published": "2019-08-19T23:45:47Z", "withdrawn": "2019-08-20T14:13:17Z", "aliases": [ "CVE-2019-15149" ], - "summary": "TODO", - "details": "** DISPUTED ** core.py in Mitogen before 0.2.8 has a typo that drops the unidirectional-routing protection mechanism in the case of a child that is initiated by another child. The Ansible extension is unaffected. NOTE: the vendor disputes this issue because it is exploitable only in conjunction with hypothetical other factors, i.e., an affected use case within a library caller, and a bug in the message receiver policy code that led to reliance on this extra protection mechanism.", + "summary": "Undirectional routing wasn't respected in some cases in Mitogen", + "details": "core.py in Mitogen before 0.2.8 has a typo that drops the unidirectional-routing protection mechanism in the case of a child that is initiated by another child. The Ansible extension is unaffected. NOTE: the vendor disputes this issue because it is exploitable only in conjunction with hypothetical other factors, i.e., an affected use case within a library caller, and a bug in the message receiver policy code that led to reliance on this extra protection mechanism.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } ], "affected": [ {