{"id":"CGA-8935-636c-xff5","modified":"2026-09-07T01:29:33.767555869Z","published":"2025-11-09T09:54:54Z","upstream":["CVE-2019-3842","GHSA-c23j-qp89-q76c"],"references":[{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/STR36RJE4ZZIORMDXRERVBHMPRNRTHAC/"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r58af02e294bd07f487e2c64ffc0a29b837db5600e33b6e698b9d696b%40%3Cissues.bookkeeper.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/rf4c02775860db415b4955778a131c2795223f61cb8c6a450893651e4%40%3Cissues.bookkeeper.apache.org%3E"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2019/04/msg00022.html"},{"type":"ADVISORY","url":"http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00062.html"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3842"},{"type":"EVIDENCE","url":"https://www.exploit-db.com/exploits/46743/"},{"type":"EVIDENCE","url":"http://packetstormsecurity.com/files/152610/systemd-Seat-Verification-Active-Session-Spoofing.html"}],"affected":[{"package":{"name":"py3.11-systemd","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/py3.11-systemd?arch=aarch64"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0"}]}],"ecosystem_specific":{"components":[{"latest_event_status":"false_positive_determination","latest_event_timestamp":"2026-01-16T19:34:58Z","component_name":"py3.11-systemd","component_version":"235-r0","component_type":"apk","component_location":"/.PKGINFO","component_purl":"pkg:apk/py3.11-systemd@235-r0"}]},"database_specific":{"source":"https://advisories.cgr.dev/chainguard/v3/osv/CGA-8935-636c-xff5.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}