From ef29e7d4a15fd36b9892648f5dc1ace63620e984 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 9 Oct 2024 21:07:15 +0000 Subject: [PATCH] Publish Advisories GHSA-9hx2-hgq2-2g4f GHSA-mvg9-xffr-p774 GHSA-77gc-v2xv-rvvh GHSA-rwv7-3v45-hg29 GHSA-v9pc-9mvp-x87g --- .../GHSA-9hx2-hgq2-2g4f.json | 16 ++++++++++-- .../GHSA-mvg9-xffr-p774.json | 16 ++++++++++-- .../GHSA-77gc-v2xv-rvvh.json | 23 +++++++++++------ .../GHSA-rwv7-3v45-hg29.json | 25 ++++++++++++------- .../GHSA-v9pc-9mvp-x87g.json | 16 +++++++++--- 5 files changed, 71 insertions(+), 25 deletions(-) diff --git a/advisories/github-reviewed/2021/03/GHSA-9hx2-hgq2-2g4f/GHSA-9hx2-hgq2-2g4f.json b/advisories/github-reviewed/2021/03/GHSA-9hx2-hgq2-2g4f/GHSA-9hx2-hgq2-2g4f.json index 1f0749d9239..7a396eee494 100644 --- a/advisories/github-reviewed/2021/03/GHSA-9hx2-hgq2-2g4f/GHSA-9hx2-hgq2-2g4f.json +++ b/advisories/github-reviewed/2021/03/GHSA-9hx2-hgq2-2g4f/GHSA-9hx2-hgq2-2g4f.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-9hx2-hgq2-2g4f", - "modified": "2024-03-26T18:50:33Z", + "modified": "2024-10-09T21:05:46Z", "published": "2021-03-29T16:35:46Z", "aliases": [ "CVE-2021-25292" @@ -12,13 +12,17 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N" } ], "affected": [ { "package": { "ecosystem": "PyPI", - "name": "Pillow" + "name": "pillow" }, "ranges": [ { @@ -52,6 +56,14 @@ "type": "WEB", "url": "https://github.com/python-pillow/Pillow/commit/6207b44ab1ff4a91d8ddc7579619876d0bb191a4" }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-9hx2-hgq2-2g4f" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2021-38.yaml" + }, { "type": "WEB", "url": "https://github.com/python-pillow/Pillow" diff --git a/advisories/github-reviewed/2021/03/GHSA-mvg9-xffr-p774/GHSA-mvg9-xffr-p774.json b/advisories/github-reviewed/2021/03/GHSA-mvg9-xffr-p774/GHSA-mvg9-xffr-p774.json index afd08fe59ce..a01ccaf3b97 100644 --- a/advisories/github-reviewed/2021/03/GHSA-mvg9-xffr-p774/GHSA-mvg9-xffr-p774.json +++ b/advisories/github-reviewed/2021/03/GHSA-mvg9-xffr-p774/GHSA-mvg9-xffr-p774.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-mvg9-xffr-p774", - "modified": "2024-03-26T18:52:14Z", + "modified": "2024-10-09T21:06:27Z", "published": "2021-03-29T16:35:57Z", "aliases": [ "CVE-2021-25291" @@ -12,13 +12,17 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N" } ], "affected": [ { "package": { "ecosystem": "PyPI", - "name": "Pillow" + "name": "pillow" }, "ranges": [ { @@ -48,6 +52,14 @@ "type": "WEB", "url": "https://github.com/python-pillow/Pillow/commit/cbdce6c5d054fccaf4af34b47f212355c64ace7a" }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-mvg9-xffr-p774" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2021-37.yaml" + }, { "type": "PACKAGE", "url": "https://github.com/python-pillow/Pillow" diff --git a/advisories/github-reviewed/2021/06/GHSA-77gc-v2xv-rvvh/GHSA-77gc-v2xv-rvvh.json b/advisories/github-reviewed/2021/06/GHSA-77gc-v2xv-rvvh/GHSA-77gc-v2xv-rvvh.json index 1546712c519..897783f8b31 100644 --- a/advisories/github-reviewed/2021/06/GHSA-77gc-v2xv-rvvh/GHSA-77gc-v2xv-rvvh.json +++ b/advisories/github-reviewed/2021/06/GHSA-77gc-v2xv-rvvh/GHSA-77gc-v2xv-rvvh.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-77gc-v2xv-rvvh", - "modified": "2021-12-02T15:30:43Z", + "modified": "2024-10-09T21:04:06Z", "published": "2021-06-08T18:49:02Z", "aliases": [ "CVE-2021-25287" @@ -12,18 +12,17 @@ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N" } ], "affected": [ { "package": { "ecosystem": "PyPI", - "name": "Pillow" - }, - "ecosystem_specific": { - "affected_functions": [ - "PIL.Image.open" - ] + "name": "pillow" }, "ranges": [ { @@ -57,6 +56,14 @@ "type": "WEB", "url": "https://github.com/python-pillow/Pillow/commit/3bf5eddb89afdf690eceaa52bc4d3546ba9a5f87" }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-77gc-v2xv-rvvh" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2021-137.yaml" + }, { "type": "PACKAGE", "url": "https://github.com/python-pillow/Pillow" @@ -78,7 +85,7 @@ "cwe_ids": [ "CWE-125" ], - "severity": "CRITICAL", + "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2021-06-03T21:44:57Z", "nvd_published_at": "2021-06-02T16:15:00Z" diff --git a/advisories/github-reviewed/2021/06/GHSA-rwv7-3v45-hg29/GHSA-rwv7-3v45-hg29.json b/advisories/github-reviewed/2021/06/GHSA-rwv7-3v45-hg29/GHSA-rwv7-3v45-hg29.json index 4b43898af4a..a1e0c558547 100644 --- a/advisories/github-reviewed/2021/06/GHSA-rwv7-3v45-hg29/GHSA-rwv7-3v45-hg29.json +++ b/advisories/github-reviewed/2021/06/GHSA-rwv7-3v45-hg29/GHSA-rwv7-3v45-hg29.json @@ -1,29 +1,28 @@ { "schema_version": "1.4.0", "id": "GHSA-rwv7-3v45-hg29", - "modified": "2021-12-02T15:30:22Z", + "modified": "2024-10-09T21:04:37Z", "published": "2021-06-08T18:49:28Z", "aliases": [ "CVE-2021-25288" ], - "summary": "Out-of-bounds Read", + "summary": "Pillow Out-of-bounds Read vulnerability", "details": "An issue was discovered in Pillow before 8.2.0. There is an out-of-bounds read in J2kDecode, in j2ku_gray_i. This dates to Pillow 2.4.0.", "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N" } ], "affected": [ { "package": { "ecosystem": "PyPI", - "name": "Pillow" - }, - "ecosystem_specific": { - "affected_functions": [ - "PIL.Image.open" - ] + "name": "pillow" }, "ranges": [ { @@ -53,6 +52,14 @@ "type": "WEB", "url": "https://github.com/python-pillow/Pillow/commit/3bf5eddb89afdf690eceaa52bc4d3546ba9a5f87" }, + { + "type": "ADVISORY", + "url": "https://github.com/advisories/GHSA-rwv7-3v45-hg29" + }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2021-138.yaml" + }, { "type": "PACKAGE", "url": "https://github.com/python-pillow/Pillow" @@ -74,7 +81,7 @@ "cwe_ids": [ "CWE-125" ], - "severity": "CRITICAL", + "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2021-06-03T21:36:38Z", "nvd_published_at": "2021-06-02T16:15:00Z" diff --git a/advisories/github-reviewed/2022/05/GHSA-v9pc-9mvp-x87g/GHSA-v9pc-9mvp-x87g.json b/advisories/github-reviewed/2022/05/GHSA-v9pc-9mvp-x87g/GHSA-v9pc-9mvp-x87g.json index 29d8131dc9e..56c2643e92a 100644 --- a/advisories/github-reviewed/2022/05/GHSA-v9pc-9mvp-x87g/GHSA-v9pc-9mvp-x87g.json +++ b/advisories/github-reviewed/2022/05/GHSA-v9pc-9mvp-x87g/GHSA-v9pc-9mvp-x87g.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-v9pc-9mvp-x87g", - "modified": "2024-04-22T22:34:49Z", + "modified": "2024-10-09T21:04:57Z", "published": "2022-05-17T02:47:20Z", "aliases": [ "CVE-2016-3076" @@ -12,6 +12,10 @@ { "type": "CVSS_V3", "score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N" } ], "affected": [ @@ -44,6 +48,10 @@ "type": "WEB", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1321929" }, + { + "type": "WEB", + "url": "https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2017-92.yaml" + }, { "type": "PACKAGE", "url": "https://github.com/python-pillow/Pillow" @@ -54,18 +62,18 @@ }, { "type": "WEB", - "url": "http://pillow.readthedocs.io/en/4.1.x/releasenotes/3.1.2.html" + "url": "https://web.archive.org/web/20200227174644/http://www.securityfocus.com/bid/98042" }, { "type": "WEB", - "url": "http://www.securityfocus.com/bid/98042" + "url": "http://pillow.readthedocs.io/en/4.1.x/releasenotes/3.1.2.html" } ], "database_specific": { "cwe_ids": [ "CWE-119" ], - "severity": "MODERATE", + "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2024-04-22T22:34:49Z", "nvd_published_at": "2017-04-24T18:59:00Z"