From 7ff1af51d5282848e8033b9607fe64a401f442b6 Mon Sep 17 00:00:00 2001 From: Weston Steimel Date: Thu, 18 Jun 2026 12:44:38 +0100 Subject: [PATCH] associate PYSEC-2024-270 with correct package The package should be `airflow-diagrams` rather than `diagrams` Resolves #312 Signed-off-by: Weston Steimel --- .../PYSEC-2024-270.yaml | 60 ++----------------- 1 file changed, 6 insertions(+), 54 deletions(-) rename vulns/{diagrams => airflow-diagrams}/PYSEC-2024-270.yaml (53%) diff --git a/vulns/diagrams/PYSEC-2024-270.yaml b/vulns/airflow-diagrams/PYSEC-2024-270.yaml similarity index 53% rename from vulns/diagrams/PYSEC-2024-270.yaml rename to vulns/airflow-diagrams/PYSEC-2024-270.yaml index 9240559f..f5533bf6 100644 --- a/vulns/diagrams/PYSEC-2024-270.yaml +++ b/vulns/airflow-diagrams/PYSEC-2024-270.yaml @@ -2,64 +2,14 @@ affected: - ecosystem_specific: {} package: ecosystem: PyPI - name: diagrams - purl: pkg:pypi/diagrams + name: airflow-diagrams + purl: pkg:pypi/airflow-diagrams ranges: - events: - introduced: '0' - last_affected: 2.1.0 type: ECOSYSTEM - versions: - - 0.1.0 - - 0.10.0 - - 0.11.0 - - 0.12.0 - - 0.13.0 - - 0.13.1 - - 0.14.0 - - 0.15.0 - - 0.16.0 - - 0.17.0 - - 0.18.0 - - 0.19.0 - - 0.19.1 - - 0.2.0 - - 0.2.1 - - 0.2.2 - - 0.2.3 - - 0.2.4 - - 0.20.0 - - 0.21.0 - - 0.21.1 - - 0.22.0 - - 0.23.1 - - 0.23.2 - - 0.23.3 - - 0.23.4 - - 0.24.0 - - 0.24.1 - - 0.24.3 - - 0.24.4 - - 0.25.0 - - 0.25.1 - - 0.3.0 - - 0.4.0 - - 0.5.0 - - 0.6.0 - - 0.6.1 - - 0.6.2 - - 0.6.3 - - 0.6.4 - - 0.6.5 - - 0.7.0 - - 0.7.1 - - 0.7.2 - - 0.7.3 - - 0.7.4 - - 0.8.0 - - 0.8.1 - - 0.8.2 - - 0.9.0 + versions: [] aliases: - CVE-2024-28423 details: Airflow-Diagrams v2.1.0 was discovered to contain an arbitrary file upload @@ -69,8 +19,10 @@ id: PYSEC-2024-270 modified: '2026-05-21T14:54:25.345508Z' published: '2024-03-14T19:15:50.877Z' references: -- type: PACKAGE +- type: REPORT url: https://github.com/bayuncao/vul-cve-15 +- type: PACKAGE + url: https://github.com/feluelle/airflow-diagrams severity: - score: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H type: CVSS_V3