-
Notifications
You must be signed in to change notification settings - Fork 306
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
fix patched version for CVE-2024-50342 #737
fix patched version for CVE-2024-50342 #737
Conversation
@jderusse this correct now? 😆 |
Is the referenced advisory on GitHub wrong too? GHSA-9c3x-r3wp-mgxm |
@@ -21,8 +21,8 @@ branches: | |||
time: ~ | |||
versions: ['>=5.3.0', '<5.4.0'] | |||
5.4.x: | |||
time: 2024-11-05 08:00:00 | |||
versions: ['>=5.4.0', '<5.4.46'] |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
My impression is, that this CVE shouldn't be edited in this PR?
GHSA-9c3x-r3wp-mgxm has been updated because this is the same CVE... |
@nicolas-grekas same CVE as what? There are two CVEs here. One was published last week from what I can tell and one hasn't gotten any published info yet, neither on GitHub nor elsewhere? |
It looks like github has some replication issues:
|
Which corresponds to CVE-2024-50342 |
So any info on what CVE-2024-51996 is? Or why that got merged here without any public info available yet? I guess that's coming now? |
The advisory for CVE-2024-51996 is available here GHSA-cg23-qf8f-62rr |
Alright, PR looks fine then. Should anything else still happen before merging it? |
@jderusse GitHub does not automatically applies updates from repository-level advisories to the advisories of the global database. they import the repository-level advisories into the global database (which also imports other sources). So you would have to contribute on https://github.com/github/advisory-database/ to update the version in the global database. |
No description provided.