{"id":"GHSA-pw5x-x5jw-ccmh","summary":"Gentoo Portage missing PGP validation of executed code","details":"In Gentoo Portage before 3.0.47, there is missing PGP validation of executed code: the standalone emerge-webrsync downloads a .gpgsig file but does not perform signature verification.","aliases":["CVE-2016-20021","PYSEC-2024-10"],"modified":"2024-08-30T23:57:12.000989Z","published":"2024-01-12T03:30:49Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2024-08-30T23:37:34Z","nvd_published_at":"2024-01-12T03:15:08Z","cwe_ids":["CWE-347"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2016-20021"},{"type":"WEB","url":"https://github.com/gentoo/portage/commit/28cd240fb23d880b8641a058831c6762db71c3e2"},{"type":"WEB","url":"https://bugs.gentoo.org/597800"},{"type":"PACKAGE","url":"https://github.com/gentoo/portage"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/portage/PYSEC-2024-10.yaml"},{"type":"WEB","url":"https://gitweb.gentoo.org/proj/portage.git/tree/NEWS"},{"type":"WEB","url":"https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=5b3c80502e96406b4b175e2ee79eb65f3f3cd9f6"},{"type":"WEB","url":"https://wiki.gentoo.org/wiki/Portage"}],"affected":[{"package":{"name":"portage","ecosystem":"PyPI","purl":"pkg:pypi/portage"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.0.47"}]}],"versions":["3.0.18","3.0.19","3.0.20","3.0.21","3.0.22","3.0.23","3.0.24","3.0.25","3.0.26","3.0.27","3.0.28","3.0.29","3.0.30","3.0.31","3.0.32","3.0.33","3.0.34","3.0.35","3.0.36","3.0.37","3.0.38","3.0.38.1","3.0.39","3.0.40","3.0.41","3.0.42","3.0.43","3.0.44","3.0.45","3.0.45.1","3.0.45.2","3.0.45.3","3.0.46"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/01/GHSA-pw5x-x5jw-ccmh/GHSA-pw5x-x5jw-ccmh.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U"}]}