From a691431a8a63d7e3179545f3fb3d92db53dfb729 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 16 Sep 2024 23:02:42 +0000 Subject: [PATCH] Publish Advisories GHSA-pvhp-v9qp-xf5r GHSA-xp5m-4c9f-498q --- .../GHSA-pvhp-v9qp-xf5r.json | 39 +++++++------------ .../GHSA-xp5m-4c9f-498q.json | 14 ++++++- 2 files changed, 27 insertions(+), 26 deletions(-) diff --git a/advisories/github-reviewed/2018/07/GHSA-pvhp-v9qp-xf5r/GHSA-pvhp-v9qp-xf5r.json b/advisories/github-reviewed/2018/07/GHSA-pvhp-v9qp-xf5r/GHSA-pvhp-v9qp-xf5r.json index e0e664fdd2d..3c027cb1f87 100644 --- a/advisories/github-reviewed/2018/07/GHSA-pvhp-v9qp-xf5r/GHSA-pvhp-v9qp-xf5r.json +++ b/advisories/github-reviewed/2018/07/GHSA-pvhp-v9qp-xf5r/GHSA-pvhp-v9qp-xf5r.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-pvhp-v9qp-xf5r", - "modified": "2023-08-31T21:39:49Z", + "modified": "2024-09-16T23:00:29Z", "published": "2018-07-23T19:50:48Z", "aliases": [ "CVE-2011-4103" @@ -9,7 +9,14 @@ "summary": "Django-piston and Django-tastypie do not properly deserialize YAML data", "details": "emitters.py in Django Piston before 0.2.3 and 0.2.x before 0.2.2.1 does not properly deserialize YAML data, which allows remote attackers to execute arbitrary Python code via vectors related to the yaml.load method.\n\nDjango Tastypie has a very similar vulnerability.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N" + } ], "affected": [ { @@ -29,28 +36,6 @@ } ] } - ], - "database_specific": { - "last_known_affected_version_range": "<= 0.2.2.0" - } - }, - { - "package": { - "ecosystem": "PyPI", - "name": "django-piston" - }, - "ranges": [ - { - "type": "ECOSYSTEM", - "events": [ - { - "introduced": "0.2.2.2" - }, - { - "fixed": "0.2.3" - } - ] - } ] } ], @@ -75,6 +60,10 @@ "type": "ADVISORY", "url": "https://github.com/advisories/GHSA-pvhp-v9qp-xf5r" }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/django-piston/PYSEC-2014-24.yaml" + }, { "type": "WEB", "url": "https://www.djangoproject.com/weblog/2011/nov/01/piston-and-tastypie-security-releases" @@ -92,7 +81,7 @@ "cwe_ids": [ "CWE-20" ], - "severity": "HIGH", + "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2020-06-16T21:50:09Z", "nvd_published_at": null diff --git a/advisories/github-reviewed/2018/07/GHSA-xp5m-4c9f-498q/GHSA-xp5m-4c9f-498q.json b/advisories/github-reviewed/2018/07/GHSA-xp5m-4c9f-498q/GHSA-xp5m-4c9f-498q.json index 7529df47646..1f3f2aafcf7 100644 --- a/advisories/github-reviewed/2018/07/GHSA-xp5m-4c9f-498q/GHSA-xp5m-4c9f-498q.json +++ b/advisories/github-reviewed/2018/07/GHSA-xp5m-4c9f-498q/GHSA-xp5m-4c9f-498q.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xp5m-4c9f-498q", - "modified": "2023-09-05T18:25:18Z", + "modified": "2024-09-16T23:02:16Z", "published": "2018-07-13T15:17:18Z", "aliases": [ "CVE-2017-6591" @@ -12,6 +12,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N" } ], "affected": [ @@ -34,6 +38,14 @@ "type": "ADVISORY", "url": "https://github.com/advisories/GHSA-xp5m-4c9f-498q" }, + { + "type": "PACKAGE", + "url": "https://github.com/barraq/django-epiceditor" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/django-epiceditor/PYSEC-2017-86.yaml" + }, { "type": "WEB", "url": "https://web.archive.org/web/20170706013108/http://www.morningchen.com/2017/03/09/Cross-site-scripting-vulnerability-in-django-epiceditor"