Publish Advisories

GHSA-7jp9-vgmq-c8r5
GHSA-m8cj-3v68-3cxj
GHSA-wmvm-9vqv-5qpp
This commit is contained in:
advisory-database[bot]
2024-07-05 21:20:25 +00:00
parent 5712761070
commit c4f87aebe7
3 changed files with 14 additions and 7 deletions
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-7jp9-vgmq-c8r5",
"modified": "2024-06-13T23:18:26Z",
"modified": "2024-07-05T21:19:09Z",
"published": "2024-06-13T21:30:52Z",
"aliases": [
"CVE-2024-36586"
@@ -55,7 +55,7 @@
],
"database_specific": {
"cwe_ids": [
"CWE-269"
],
"severity": "HIGH",
"github_reviewed": true,
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-m8cj-3v68-3cxj",
"modified": "2024-06-13T19:33:57Z",
"modified": "2024-07-05T21:19:28Z",
"published": "2024-06-13T09:31:00Z",
"aliases": [
"CVE-2024-34102"
@@ -137,6 +137,10 @@
{
"type": "WEB",
"url": "https://helpx.adobe.com/security/products/magento/apsb24-40.html"
},
{
"type": "WEB",
"url": "https://www.vicarius.io/vsociety/posts/cosmicsting-critical-unauthenticated-xxe-vulnerability-in-adobe-commerce-and-magento-cve-2024-34102"
}
],
"database_specific": {
@@ -1,7 +1,7 @@
{
"schema_version": "1.4.0",
"id": "GHSA-wmvm-9vqv-5qpp",
"modified": "2024-06-17T21:21:47Z",
"modified": "2024-07-05T21:18:35Z",
"published": "2024-06-16T15:30:44Z",
"aliases": [
"CVE-2024-38459"
@@ -9,7 +9,10 @@
"summary": "langchain_experimental Code Execution via Python REPL access",
"details": "langchain_experimental (aka LangChain Experimental) before 0.0.61 for LangChain provides Python REPL access without an opt-in step. NOTE; this issue exists because of an incomplete fix for CVE-2024-27444.",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
}
],
"affected": [
{
@@ -60,9 +63,9 @@
],
"database_specific": {
"cwe_ids": [
"CWE-276"
],
"severity": "MODERATE",
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2024-06-17T21:21:47Z",
"nvd_published_at": "2024-06-16T15:15:51Z"