Skip to content

Commit

Permalink
Browse files Browse the repository at this point in the history
  • Loading branch information
advisory-database[bot] committed Dec 19, 2024
1 parent 7693031 commit 99a1b06
Showing 1 changed file with 4 additions and 2 deletions.
Original file line number Diff line number Diff line change
@@ -1,9 +1,11 @@
{
"schema_version": "1.4.0",
"id": "GHSA-47h8-jmp3-9f28",
"modified": "2024-12-19T15:14:06Z",
"modified": "2024-12-19T22:41:16Z",
"published": "2024-12-19T15:14:06Z",
"aliases": [],
"aliases": [
"CVE-2024-56327"
],
"summary": "pyrage vulnerable to malicious plugin names, recipients, or identities causing arbitrary binary execution",
"details": "`pyrage` uses the Rust `age` crate for its underlying operations, and `age` is vulnerable to GHSA-4fg7-vxc8-qx5w.\n\nAll details of GHSA-4fg7-vxc8-qx5w are relevant to `pyrage` for the versions specified in this advisory. See GHSA-4fg7-vxc8-qx5w for full details.\n\nVersions of `pyrage` before 1.2.0 lack plugin support and are therefore **not affected**.\n\nAn equivalent issue was fixed in [the reference Go implementation of age](https://github.com/FiloSottile/age), see advisory [GHSA-32gq-x56h-299c](https://github.com/FiloSottile/age/security/advisories/GHSA-32gq-x56h-299c).\n\nThanks to ⬡-49016 for reporting this issue.",
"severity": [],
Expand Down

0 comments on commit 99a1b06

Please sign in to comment.