[Git][security-tracker-team/security-tracker][master] CVE-2024-1892/python-scrapy: link GHSA to help disambiguate CVE-2024-3572

Sylvain Beucler (@beuc) gitlab at salsa.debian.org
Fri May 3 17:20:29 BST 2024



Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker


Commits:
274e77ed by Sylvain Beucler at 2024-05-03T18:19:48+02:00
CVE-2024-1892/python-scrapy: link GHSA to help disambiguate CVE-2024-3572

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -4981,7 +4981,6 @@ CVE-2024-3572 (The scrapy/scrapy project is vulnerable to XML External Entity (X
 	NOTE: The CVE and bounty descriptions discuss general XML issues (not specifically XXE), but
 	NOTE: the bounty comments and the patch discuss a compression bomb.
 	NOTE: https://github.com/scrapy/scrapy/security/advisories/GHSA-7j7m-v7m3-jqm7 (compression bomb)
-	NOTE: (or https://github.com/scrapy/scrapy/security/advisories/GHSA-cc65-xxvf-f7r9 (XML ReDoS) ?)
 CVE-2024-3571 (langchain-ai/langchain is vulnerable to path traversal due to improper ...)
 	NOT-FOR-US: langchain
 CVE-2024-3493 (A specific malformed fragmented packet type (fragmented packets may be ...)
@@ -19393,6 +19392,7 @@ CVE-2024-1892 (A Regular Expression Denial of Service (ReDoS) vulnerability exis
 	[buster] - python-scrapy <no-dsa> (Minor issue)
 	NOTE: https://huntr.com/bounties/271f94f2-1e05-4616-ac43-41752389e26b/
 	NOTE: https://github.com/scrapy/scrapy/commit/479619b340f197a8f24c5db45bc068fb8755f2c5 (2.11.1)
+	NOTE: https://github.com/scrapy/scrapy/security/advisories/GHSA-cc65-xxvf-f7r9
 CVE-2024-1866
 	REJECTED
 CVE-2024-1865



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/274e77ed2b2f65fdf13049db6459ef71e50a21de

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/274e77ed2b2f65fdf13049db6459ef71e50a21de
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20240503/ab6d505f/attachment.htm>


More information about the debian-security-tracker-commits mailing list