CVE-2023-34540

Langchain before v0.0.225 was discovered to contain a remote code execution (RCE) vulnerability in the component JiraAPIWrapper (aka the JIRA API wrapper). This vulnerability allows attackers to execute arbitrary code via crafted input. As noted in the "releases/tag" reference, a fix is available.
Configurations

Configuration 1 (hide)

cpe:2.3:a:langchain:langchain:0.0.171:*:*:*:*:*:*:*

History

13 Mar 2024, 22:15

Type Values Removed Values Added
Summary (en) Langchain before v0.0.225 was discovered to contain a remote code execution (RCE) vulnerability in the component JiraAPIWrapper(). This vulnerability allows attackers to execute arbitrary code via providing crafted input. (en) Langchain before v0.0.225 was discovered to contain a remote code execution (RCE) vulnerability in the component JiraAPIWrapper (aka the JIRA API wrapper). This vulnerability allows attackers to execute arbitrary code via crafted input. As noted in the "releases/tag" reference, a fix is available.

07 Mar 2024, 20:15

Type Values Removed Values Added
Summary (en) An issue discovered in Langchain before 0.0.225 allows attacker to run arbitrary code via jira.run('other' substring. (en) Langchain before v0.0.225 was discovered to contain a remote code execution (RCE) vulnerability in the component JiraAPIWrapper(). This vulnerability allows attackers to execute arbitrary code via providing crafted input.

06 Dec 2023, 21:15

Type Values Removed Values Added
Summary Langchain 0.0.171 is vulnerable to Arbitrary Code Execution. An issue discovered in Langchain before 0.0.225 allows attacker to run arbitrary code via jira.run('other' substring.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CPE cpe:2.3:a:langchain:langchain:0.0.171:*:*:*:*:*:*:*
CWE NVD-CWE-noinfo
References
  • () https://github.com/langchain-ai/langchain/releases/tag/v0.0.225 -
  • () https://github.com/langchain-ai/langchain/pull/6992 -
References (MISC) https://github.com/hwchase17/langchain/issues/4833 - (MISC) https://github.com/hwchase17/langchain/issues/4833 - Exploit, Issue Tracking

14 Jun 2023, 15:30

Type Values Removed Values Added
New CVE

Information

Published : 2023-06-14 15:15

Updated : 2024-03-13 22:15


NVD link : CVE-2023-34540

Mitre link : CVE-2023-34540

CVE.ORG link : CVE-2023-34540


JSON object : View

Products Affected

langchain

  • langchain