Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-47h8-jmp3-9f28

Опубликовано: 19 дек. 2024
Источник: github
Github: Прошло ревью
CVSS4: 7.7
CVSS3: 9.8

Описание

pyrage vulnerable to malicious plugin names, recipients, or identities causing arbitrary binary execution

pyrage uses the Rust age crate for its underlying operations, and age is vulnerable to GHSA-4fg7-vxc8-qx5w.

All details of GHSA-4fg7-vxc8-qx5w are relevant to pyrage for the versions specified in this advisory. See GHSA-4fg7-vxc8-qx5w for full details.

Versions of pyrage before 1.2.0 lack plugin support and are therefore not affected.

An equivalent issue was fixed in the reference Go implementation of age, see advisory GHSA-32gq-x56h-299c.

Thanks to ⬡-49016 for reporting this issue.

Пакеты

Наименование

pyrage

pip
Затронутые версииВерсия исправления

>= 1.2.0, < 1.2.3

1.2.3

EPSS

Процентиль: 54%
0.00318
Низкий

7.7 High

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-1395
CWE-25
CWE-94

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 1 года назад

pyrage is a set of Python bindings for the rage file encryption library (age in Rust). `pyrage` uses the Rust `age` crate for its underlying operations, and `age` is vulnerable to GHSA-4fg7-vxc8-qx5w. All details of GHSA-4fg7-vxc8-qx5w are relevant to `pyrage` for the versions specified in this advisory. See GHSA-4fg7-vxc8-qx5w for full details. Versions of `pyrage` before 1.2.0 lack plugin support and are therefore **not affected**. An equivalent issue was fixed in [the reference Go implementation of age](https://github.com/FiloSottile/age), see advisory GHSA-32gq-x56h-299c. This issue has been addressed in version 1.2.3 and all users are advised to update. There are no known workarounds for this vulnerability.

CVSS3: 9.8
nvd
около 1 года назад

pyrage is a set of Python bindings for the rage file encryption library (age in Rust). `pyrage` uses the Rust `age` crate for its underlying operations, and `age` is vulnerable to GHSA-4fg7-vxc8-qx5w. All details of GHSA-4fg7-vxc8-qx5w are relevant to `pyrage` for the versions specified in this advisory. See GHSA-4fg7-vxc8-qx5w for full details. Versions of `pyrage` before 1.2.0 lack plugin support and are therefore **not affected**. An equivalent issue was fixed in [the reference Go implementation of age](https://github.com/FiloSottile/age), see advisory GHSA-32gq-x56h-299c. This issue has been addressed in version 1.2.3 and all users are advised to update. There are no known workarounds for this vulnerability.

EPSS

Процентиль: 54%
0.00318
Низкий

7.7 High

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-1395
CWE-25
CWE-94