From c4f87aebe7ce8935351707167fe099c130f3147a Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 5 Jul 2024 21:20:25 +0000 Subject: [PATCH] Publish Advisories GHSA-7jp9-vgmq-c8r5 GHSA-m8cj-3v68-3cxj GHSA-wmvm-9vqv-5qpp --- .../06/GHSA-7jp9-vgmq-c8r5/GHSA-7jp9-vgmq-c8r5.json | 4 ++-- .../06/GHSA-m8cj-3v68-3cxj/GHSA-m8cj-3v68-3cxj.json | 6 +++++- .../06/GHSA-wmvm-9vqv-5qpp/GHSA-wmvm-9vqv-5qpp.json | 11 +++++++---- 3 files changed, 14 insertions(+), 7 deletions(-) diff --git a/advisories/github-reviewed/2024/06/GHSA-7jp9-vgmq-c8r5/GHSA-7jp9-vgmq-c8r5.json b/advisories/github-reviewed/2024/06/GHSA-7jp9-vgmq-c8r5/GHSA-7jp9-vgmq-c8r5.json index 5fe4562c2d3..9868a9c80ae 100644 --- a/advisories/github-reviewed/2024/06/GHSA-7jp9-vgmq-c8r5/GHSA-7jp9-vgmq-c8r5.json +++ b/advisories/github-reviewed/2024/06/GHSA-7jp9-vgmq-c8r5/GHSA-7jp9-vgmq-c8r5.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7jp9-vgmq-c8r5", - "modified": "2024-06-13T23:18:26Z", + "modified": "2024-07-05T21:19:09Z", "published": "2024-06-13T21:30:52Z", "aliases": [ "CVE-2024-36586" @@ -55,7 +55,7 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-269" ], "severity": "HIGH", "github_reviewed": true, diff --git a/advisories/github-reviewed/2024/06/GHSA-m8cj-3v68-3cxj/GHSA-m8cj-3v68-3cxj.json b/advisories/github-reviewed/2024/06/GHSA-m8cj-3v68-3cxj/GHSA-m8cj-3v68-3cxj.json index fd8c2cd01c2..ab76057c63a 100644 --- a/advisories/github-reviewed/2024/06/GHSA-m8cj-3v68-3cxj/GHSA-m8cj-3v68-3cxj.json +++ b/advisories/github-reviewed/2024/06/GHSA-m8cj-3v68-3cxj/GHSA-m8cj-3v68-3cxj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-m8cj-3v68-3cxj", - "modified": "2024-06-13T19:33:57Z", + "modified": "2024-07-05T21:19:28Z", "published": "2024-06-13T09:31:00Z", "aliases": [ "CVE-2024-34102" @@ -137,6 +137,10 @@ { "type": "WEB", "url": "https://helpx.adobe.com/security/products/magento/apsb24-40.html" + }, + { + "type": "WEB", + "url": "https://www.vicarius.io/vsociety/posts/cosmicsting-critical-unauthenticated-xxe-vulnerability-in-adobe-commerce-and-magento-cve-2024-34102" } ], "database_specific": { diff --git a/advisories/github-reviewed/2024/06/GHSA-wmvm-9vqv-5qpp/GHSA-wmvm-9vqv-5qpp.json b/advisories/github-reviewed/2024/06/GHSA-wmvm-9vqv-5qpp/GHSA-wmvm-9vqv-5qpp.json index 554b90877ea..2a39190604c 100644 --- a/advisories/github-reviewed/2024/06/GHSA-wmvm-9vqv-5qpp/GHSA-wmvm-9vqv-5qpp.json +++ b/advisories/github-reviewed/2024/06/GHSA-wmvm-9vqv-5qpp/GHSA-wmvm-9vqv-5qpp.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-wmvm-9vqv-5qpp", - "modified": "2024-06-17T21:21:47Z", + "modified": "2024-07-05T21:18:35Z", "published": "2024-06-16T15:30:44Z", "aliases": [ "CVE-2024-38459" @@ -9,7 +9,10 @@ "summary": "langchain_experimental Code Execution via Python REPL access", "details": "langchain_experimental (aka LangChain Experimental) before 0.0.61 for LangChain provides Python REPL access without an opt-in step. NOTE; this issue exists because of an incomplete fix for CVE-2024-27444.", "severity": [ - + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } ], "affected": [ { @@ -60,9 +63,9 @@ ], "database_specific": { "cwe_ids": [ - + "CWE-276" ], - "severity": "MODERATE", + "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2024-06-17T21:21:47Z", "nvd_published_at": "2024-06-16T15:15:51Z"