{
	"document":{
		"aggregate_severity":{
			"namespace":"https://nvd.nist.gov/vuln-metrics/cvss",
			"text":"Medium"
		},
		"category":"csaf_vex",
		"csaf_version":"2.0",
		"distribution":{
			"tlp":{
				"label":"WHITE",
				"url":"https:/www.first.org/tlp/"
			}
		},
		"lang":"en",
		"notes":[
			{
				"text":"python-tqdm security update",
				"category":"general",
				"title":"Synopsis"
			},
			{
				"text":"An update for python-tqdm is now available for openEuler-22.03-LTS.",
				"category":"general",
				"title":"Summary"
			},
			{
				"text":"tqdm derives from the Arabic word taqaddum which can mean \"progress\". Instantly  make your loops show a smart progress meter - just wrap any iterable with  tqdm(interable), and you are done!\n\nSecurity Fix(es):\n\ntqdm is an open source progress bar for Python and CLI. Any optional non-boolean CLI arguments (e.g. `--delim`, `--buf-size`, `--manpath`) are passed through python's `eval`, allowing arbitrary code execution. This issue is only locally exploitable and had been addressed in release version 4.66.3. All users are advised to upgrade. There are no known workarounds for this vulnerability.(CVE-2024-34062)",
				"category":"general",
				"title":"Description"
			},
			{
				"text":"An update for python-tqdm is now available for openEuler-22.03-LTS.\n\nopenEuler Security has rated this update as having a security impact of medium. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.",
				"category":"general",
				"title":"Topic"
			},
			{
				"text":"Medium",
				"category":"general",
				"title":"Severity"
			},
			{
				"text":"python-tqdm",
				"category":"general",
				"title":"Affected Component"
			}
		],
		"publisher":{
			"issuing_authority":"openEuler security committee",
			"name":"openEuler",
			"namespace":"https://www.openeuler.org",
			"contact_details":"openeuler-security@openeuler.org",
			"category":"vendor"
		},
		"references":[
			{
				"summary":"openEuler-SA-2024-1554",
				"category":"self",
				"url":"https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2024-1554"
			},
			{
				"summary":"CVE-2024-34062",
				"category":"self",
				"url":"https://www.openeuler.org/en/security/cve/detail?cveId=CVE-2024-34062&packageName=python-tqdm"
			},
			{
				"summary":"nvd cve",
				"category":"external",
				"url":"https://nvd.nist.gov/vuln/detail/CVE-2024-34062"
			},
			{
				"summary":"openEuler-SA-2024-1554 vex file",
				"category":"self",
				"url":"https://repo.openeuler.org/security/data/csaf/advisories/2024/csaf-openeuler-sa-2024-1554.json"
			}
		],
		"title":"An update for python-tqdm is now available for openEuler-22.03-LTS",
		"tracking":{
			"initial_release_date":"2024-05-10T09:17:19+08:00",
			"revision_history":[
				{
					"date":"2024-05-10T09:17:19+08:00",
					"summary":"Initial",
					"number":"1.0.0"
				},
				{
					"date":"2024-10-31T09:17:19+08:00",
					"summary":"final",
					"number":"2.0.0"
				}
			],
			"generator":{
				"date":"2024-10-31T09:17:19+08:00",
				"engine":{
					"name":"openEuler CSAF Tool V1.0"
				}
			},
			"current_release_date":"2024-10-31T09:17:19+08:00",
			"id":"openEuler-SA-2024-1554",
			"version":"2.0.0",
			"status":"final"
		}
	},
	"product_tree":{
		"branches":[
			{
				"name":"openEuler",
				"category":"vendor",
				"branches":[
					{
						"name":"openEuler",
						"branches":[
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:22.03-LTS"
									},
									"product_id":"openEuler-22.03-LTS",
									"name":"openEuler-22.03-LTS"
								},
								"name":"openEuler-22.03-LTS",
								"category":"product_version"
							}
						],
						"category":"product_name"
					},
					{
						"name":"aarch64",
						"branches":[
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:22.03-LTS"
									},
									"product_id":"python3-tqdm-4.56.0-4.oe2203.aarch64.rpm",
									"name":"python3-tqdm-4.56.0-4.oe2203.aarch64.rpm"
								},
								"name":"python3-tqdm-4.56.0-4.oe2203.aarch64.rpm",
								"category":"product_version"
							}
						],
						"category":"architecture"
					},
					{
						"name":"noarch",
						"branches":[
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:22.03-LTS"
									},
									"product_id":"python-tqdm-help-4.56.0-4.oe2203.noarch.rpm",
									"name":"python-tqdm-help-4.56.0-4.oe2203.noarch.rpm"
								},
								"name":"python-tqdm-help-4.56.0-4.oe2203.noarch.rpm",
								"category":"product_version"
							}
						],
						"category":"architecture"
					},
					{
						"name":"src",
						"branches":[
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:22.03-LTS"
									},
									"product_id":"python-tqdm-4.56.0-4.oe2203.src.rpm",
									"name":"python-tqdm-4.56.0-4.oe2203.src.rpm"
								},
								"name":"python-tqdm-4.56.0-4.oe2203.src.rpm",
								"category":"product_version"
							}
						],
						"category":"architecture"
					},
					{
						"name":"x86_64",
						"branches":[
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:22.03-LTS"
									},
									"product_id":"python3-tqdm-4.56.0-4.oe2203.x86_64.rpm",
									"name":"python3-tqdm-4.56.0-4.oe2203.x86_64.rpm"
								},
								"name":"python3-tqdm-4.56.0-4.oe2203.x86_64.rpm",
								"category":"product_version"
							}
						],
						"category":"architecture"
					}
				]
			}
		],
		"relationships":[
			{
				"relates_to_product_reference":"openEuler-22.03-LTS",
				"product_reference":"python3-tqdm-4.56.0-4.oe2203.aarch64.rpm",
				"full_product_name":{
					"product_id":"openEuler-22.03-LTS:python3-tqdm-4.56.0-4.oe2203.aarch64",
					"name":"python3-tqdm-4.56.0-4.oe2203.aarch64 as a component of openEuler-22.03-LTS"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-22.03-LTS",
				"product_reference":"python-tqdm-help-4.56.0-4.oe2203.noarch.rpm",
				"full_product_name":{
					"product_id":"openEuler-22.03-LTS:python-tqdm-help-4.56.0-4.oe2203.noarch",
					"name":"python-tqdm-help-4.56.0-4.oe2203.noarch as a component of openEuler-22.03-LTS"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-22.03-LTS",
				"product_reference":"python-tqdm-4.56.0-4.oe2203.src.rpm",
				"full_product_name":{
					"product_id":"openEuler-22.03-LTS:python-tqdm-4.56.0-4.oe2203.src",
					"name":"python-tqdm-4.56.0-4.oe2203.src as a component of openEuler-22.03-LTS"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-22.03-LTS",
				"product_reference":"python3-tqdm-4.56.0-4.oe2203.x86_64.rpm",
				"full_product_name":{
					"product_id":"openEuler-22.03-LTS:python3-tqdm-4.56.0-4.oe2203.x86_64",
					"name":"python3-tqdm-4.56.0-4.oe2203.x86_64 as a component of openEuler-22.03-LTS"
				},
				"category":"default_component_of"
			}
		]
	},
	"vulnerabilities":[
		{
			"cve":"CVE-2024-34062",
			"notes":[
				{
					"text":"tqdm is an open source progress bar for Python and CLI. Any optional non-boolean CLI arguments (e.g. `--delim`, `--buf-size`, `--manpath`) are passed through python's `eval`, allowing arbitrary code execution. This issue is only locally exploitable and had been addressed in release version 4.66.3. All users are advised to upgrade. There are no known workarounds for this vulnerability.",
					"category":"description",
					"title":"Vulnerability Description"
				}
			],
			"product_status":{
				"fixed":[
					"openEuler-22.03-LTS:python3-tqdm-4.56.0-4.oe2203.aarch64",
					"openEuler-22.03-LTS:python-tqdm-help-4.56.0-4.oe2203.noarch",
					"openEuler-22.03-LTS:python-tqdm-4.56.0-4.oe2203.src",
					"openEuler-22.03-LTS:python3-tqdm-4.56.0-4.oe2203.x86_64"
				]
			},
			"remediations":[
				{
					"product_ids":[
						"openEuler-22.03-LTS:python3-tqdm-4.56.0-4.oe2203.aarch64",
						"openEuler-22.03-LTS:python-tqdm-help-4.56.0-4.oe2203.noarch",
						"openEuler-22.03-LTS:python-tqdm-4.56.0-4.oe2203.src",
						"openEuler-22.03-LTS:python3-tqdm-4.56.0-4.oe2203.x86_64"
					],
					"details":"python-tqdm security update",
					"category":"vendor_fix",
					"url":"https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2024-1554"
				}
			],
			"scores":[
				{
					"cvss_v3":{
						"baseSeverity":"MEDIUM",
						"baseScore":4.8,
						"vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L",
						"version":"3.1"
					},
					"products":[
						"openEuler-22.03-LTS:python3-tqdm-4.56.0-4.oe2203.aarch64",
						"openEuler-22.03-LTS:python-tqdm-help-4.56.0-4.oe2203.noarch",
						"openEuler-22.03-LTS:python-tqdm-4.56.0-4.oe2203.src",
						"openEuler-22.03-LTS:python3-tqdm-4.56.0-4.oe2203.x86_64"
					]
				}
			],
			"threats":[
				{
					"details":"Medium",
					"category":"impact"
				}
			],
			"title":"CVE-2024-34062"
		}
	]
}