File tree Expand file tree Collapse file tree 1 file changed +9
-13
lines changed
advisories/github-reviewed/2024/10/GHSA-45pg-36p6-83v9 Expand file tree Collapse file tree 1 file changed +9
-13
lines changed Original file line number Diff line number Diff line change 1
1
{
2
2
"schema_version" : " 1.4.0" ,
3
3
"id" : " GHSA-45pg-36p6-83v9" ,
4
- "modified" : " 2024-11-12T19:57:59Z " ,
4
+ "modified" : " 2024-11-12T19:58:00Z " ,
5
5
"published" : " 2024-10-29T15:32:05Z" ,
6
6
"aliases" : [
7
7
" CVE-2024-8309"
11
11
"severity" : [
12
12
{
13
13
"type" : " CVSS_V3" ,
14
- "score" : " CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L"
15
- },
16
- {
17
- "type" : " CVSS_V4" ,
18
- "score" : " CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N"
14
+ "score" : " CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
19
15
}
20
16
],
21
17
"affected" : [
22
18
{
23
19
"package" : {
24
20
"ecosystem" : " PyPI" ,
25
- "name" : " langchain-community "
21
+ "name" : " langchain"
26
22
},
27
23
"ranges" : [
28
24
{
29
25
"type" : " ECOSYSTEM" ,
30
26
"events" : [
31
27
{
32
- "introduced" : " 0.2.0 "
28
+ "introduced" : " 0"
33
29
},
34
30
{
35
- "fixed" : " 0.2.19 "
31
+ "fixed" : " 0.2.0 "
36
32
}
37
33
]
38
34
}
41
37
{
42
38
"package" : {
43
39
"ecosystem" : " PyPI" ,
44
- "name" : " langchain"
40
+ "name" : " langchain-community "
45
41
},
46
42
"ranges" : [
47
43
{
48
44
"type" : " ECOSYSTEM" ,
49
45
"events" : [
50
46
{
51
- "introduced" : " 0"
47
+ "introduced" : " 0.2.0 "
52
48
},
53
49
{
54
- "fixed" : " 0.2.0 "
50
+ "fixed" : " 0.2.19 "
55
51
}
56
52
]
57
53
}
89
85
" CWE-74" ,
90
86
" CWE-89"
91
87
],
92
- "severity" : " LOW " ,
88
+ "severity" : " CRITICAL " ,
93
89
"github_reviewed" : true ,
94
90
"github_reviewed_at" : " 2024-10-29T19:54:15Z" ,
95
91
"nvd_published_at" : " 2024-10-29T13:15:10Z"
You can’t perform that action at this time.
0 commit comments