CVE-2023-34540

Langchain before v0.0.225 was discovered to contain a remote code execution (RCE) vulnerability in the component JiraAPIWrapper (aka the JIRA API wrapper). This vulnerability allows attackers to execute arbitrary code via crafted input. As noted in the "releases/tag" reference, a fix is available.
Configurations

Configuration 1 (hide)

cpe:2.3:a:langchain:langchain:0.0.171:*:*:*:*:*:*:*

History

13 Mar 2024, 22:15

Type Values Removed Values Added
Summary (en) Langchain before v0.0.225 was discovered to contain a remote code execution (RCE) vulnerability in the component JiraAPIWrapper(). This vulnerability allows attackers to execute arbitrary code via providing crafted input. (en) Langchain before v0.0.225 was discovered to contain a remote code execution (RCE) vulnerability in the component JiraAPIWrapper (aka the JIRA API wrapper). This vulnerability allows attackers to execute arbitrary code via crafted input. As noted in the "releases/tag" reference, a fix is available.

07 Mar 2024, 20:15

Type Values Removed Values Added
Summary (en) An issue discovered in Langchain before 0.0.225 allows attacker to run arbitrary code via jira.run('other' substring. (en) Langchain before v0.0.225 was discovered to contain a remote code execution (RCE) vulnerability in the component JiraAPIWrapper(). This vulnerability allows attackers to execute arbitrary code via providing crafted input.

Information

Published : 2023-06-14 15:15

Updated : 2024-03-13 22:15


NVD link : CVE-2023-34540

Mitre link : CVE-2023-34540

CVE.ORG link : CVE-2023-34540


JSON object : View

Products Affected

langchain

  • langchain