From c70356eb3b4c369a924d049f1479efa44d9e562f Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 28 Jun 2024 21:44:23 +0000 Subject: [PATCH] Publish Advisories GHSA-qqcv-vg9f-5rr3 GHSA-xfhp-jf8p-mh5w --- .../06/GHSA-qqcv-vg9f-5rr3/GHSA-qqcv-vg9f-5rr3.json | 12 ++++++++++-- .../06/GHSA-xfhp-jf8p-mh5w/GHSA-xfhp-jf8p-mh5w.json | 6 +++++- 2 files changed, 15 insertions(+), 3 deletions(-) diff --git a/advisories/github-reviewed/2024/06/GHSA-qqcv-vg9f-5rr3/GHSA-qqcv-vg9f-5rr3.json b/advisories/github-reviewed/2024/06/GHSA-qqcv-vg9f-5rr3/GHSA-qqcv-vg9f-5rr3.json index 11d5d9bf84d..b566d2d66ab 100644 --- a/advisories/github-reviewed/2024/06/GHSA-qqcv-vg9f-5rr3/GHSA-qqcv-vg9f-5rr3.json +++ b/advisories/github-reviewed/2024/06/GHSA-qqcv-vg9f-5rr3/GHSA-qqcv-vg9f-5rr3.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-qqcv-vg9f-5rr3", - "modified": "2024-06-28T14:34:16Z", + "modified": "2024-06-28T21:40:06Z", "published": "2024-06-27T21:32:08Z", "aliases": [ "CVE-2024-5710" @@ -28,7 +28,7 @@ "introduced": "0" }, { - "last_affected": "1.34.34" + "fixed": "1.40.15" } ] } @@ -40,6 +40,14 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-5710" }, + { + "type": "WEB", + "url": "https://github.com/BerriAI/litellm/commit/da3ae00bd68f451ed8ddf0bc0a9fd34bde5554d6" + }, + { + "type": "WEB", + "url": "https://github.com/BerriAI/litellm/blob/224148d6133ee50801cb129cbd21ccc213992e25/litellm/proxy/auth/user_api_key_auth.py#L1020" + }, { "type": "PACKAGE", "url": "https://github.com/berriai/litellm" diff --git a/advisories/github-reviewed/2024/06/GHSA-xfhp-jf8p-mh5w/GHSA-xfhp-jf8p-mh5w.json b/advisories/github-reviewed/2024/06/GHSA-xfhp-jf8p-mh5w/GHSA-xfhp-jf8p-mh5w.json index b8a425e655a..7186a755b35 100644 --- a/advisories/github-reviewed/2024/06/GHSA-xfhp-jf8p-mh5w/GHSA-xfhp-jf8p-mh5w.json +++ b/advisories/github-reviewed/2024/06/GHSA-xfhp-jf8p-mh5w/GHSA-xfhp-jf8p-mh5w.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-xfhp-jf8p-mh5w", - "modified": "2024-06-25T20:14:06Z", + "modified": "2024-06-28T21:43:53Z", "published": "2024-06-25T18:31:22Z", "aliases": [ "CVE-2024-6257" @@ -48,6 +48,10 @@ "type": "WEB", "url": "https://discuss.hashicorp.com/t/hcsec-2024-13-hashicorp-go-getter-vulnerable-to-code-execution-on-git-update-via-git-config-manipulation/68081" }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-xfhp-jf8p-mh5w" + }, { "type": "PACKAGE", "url": "https://github.com/hashicorp/go-getter"