Skip to content

Commit

Permalink
Latest data: Sun Nov 24 08:05:47 UTC 2024
Browse files Browse the repository at this point in the history
  • Loading branch information
github.actions committed Nov 24, 2024
1 parent cee4f75 commit 09c068d
Show file tree
Hide file tree
Showing 14 changed files with 24 additions and 985 deletions.
447 changes: 0 additions & 447 deletions audits/airshare-requirements.audit.json

This file was deleted.

170 changes: 0 additions & 170 deletions audits/jupyterlab-requirements.audit.json
Original file line number Diff line number Diff line change
Expand Up @@ -672,175 +672,5 @@
"max_severity": "8.8"
}
]
},
{
"package": {
"name": "tornado",
"version": "6.4.1",
"ecosystem": "PyPI"
},
"dependency_groups": [
"jupyterlab-requirements"
],
"vulnerabilities": [
{
"modified": "2024-11-22T22:35:53Z",
"published": "2024-11-22T20:26:41Z",
"schema_version": "1.6.0",
"id": "GHSA-8w49-h785-mj3c",
"aliases": [
"CVE-2024-52804"
],
"summary": "Tornado has an HTTP cookie parsing DoS vulnerability",
"details": "The algorithm used for parsing HTTP cookies in Tornado versions prior to 6.4.2 sometimes has quadratic complexity, leading to excessive CPU consumption when parsing maliciously-crafted cookie headers. This parsing occurs in the event loop thread and may block the processing of other requests.\n\nSee also CVE-2024-7592 for a similar vulnerability in cpython.",
"affected": [
{
"package": {
"ecosystem": "PyPI",
"name": "tornado",
"purl": "pkg:pypi/tornado"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "6.4.2"
}
]
}
],
"versions": [
"0.2",
"1.0",
"1.1",
"1.1.1",
"1.2",
"1.2.1",
"2.0",
"2.1",
"2.1.1",
"2.2",
"2.2.1",
"2.3",
"2.4",
"2.4.1",
"3.0",
"3.0.1",
"3.0.2",
"3.1",
"3.1.1",
"3.2",
"3.2.1",
"3.2.2",
"4.0",
"4.0.1",
"4.0.2",
"4.1",
"4.1b2",
"4.2",
"4.2.1",
"4.2b1",
"4.3",
"4.3b1",
"4.3b2",
"4.4",
"4.4.1",
"4.4.2",
"4.4.3",
"4.4b1",
"4.5",
"4.5.1",
"4.5.2",
"4.5.3",
"4.5b1",
"4.5b2",
"5.0",
"5.0.1",
"5.0.2",
"5.0a1",
"5.0b1",
"5.1",
"5.1.1",
"5.1b1",
"6.0",
"6.0.1",
"6.0.2",
"6.0.3",
"6.0.4",
"6.0a1",
"6.0b1",
"6.1",
"6.1b1",
"6.1b2",
"6.2",
"6.2b1",
"6.2b2",
"6.3",
"6.3.1",
"6.3.2",
"6.3.3",
"6.3b1",
"6.4",
"6.4.1",
"6.4b1"
],
"database_specific": {
"last_known_affected_version_range": "<= 6.4.1",
"source": "https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/11/GHSA-8w49-h785-mj3c/GHSA-8w49-h785-mj3c.json"
}
}
],
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
}
],
"references": [
{
"type": "WEB",
"url": "https://github.com/tornadoweb/tornado/security/advisories/GHSA-8w49-h785-mj3c"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52804"
},
{
"type": "WEB",
"url": "https://github.com/tornadoweb/tornado/commit/d5ba4a1695fbf7c6a3e54313262639b198291533"
},
{
"type": "PACKAGE",
"url": "https://github.com/tornadoweb/tornado"
}
],
"database_specific": {
"cwe_ids": [
"CWE-400",
"CWE-770"
],
"github_reviewed": true,
"github_reviewed_at": "2024-11-22T20:26:41Z",
"nvd_published_at": "2024-11-22T16:15:34Z",
"severity": "HIGH"
}
}
],
"groups": [
{
"ids": [
"GHSA-8w49-h785-mj3c"
],
"aliases": [
"CVE-2024-52804",
"GHSA-8w49-h785-mj3c"
],
"max_severity": "7.5"
}
]
}
]
4 changes: 2 additions & 2 deletions audits/localstack-requirements.audit.json
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@
],
"vulnerabilities": [
{
"modified": "2024-09-03T22:02:47Z",
"modified": "2024-11-24T05:23:00Z",
"published": "2024-04-26T00:30:35Z",
"schema_version": "1.6.0",
"id": "GHSA-6c5p-j8vq-pqhj",
Expand Down Expand Up @@ -118,7 +118,7 @@
"github_reviewed": true,
"github_reviewed_at": "2024-04-26T16:57:59Z",
"nvd_published_at": "2024-04-26T00:15:09Z",
"severity": "HIGH"
"severity": "CRITICAL"
}
},
{
Expand Down
172 changes: 0 additions & 172 deletions audits/nvchecker-requirements.audit.json

This file was deleted.

Loading

0 comments on commit 09c068d

Please sign in to comment.