Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Version range of GHSA-95mg-jgfx-54v9 #4388

Open
raboof opened this issue May 13, 2024 · 0 comments
Open

Version range of GHSA-95mg-jgfx-54v9 #4388

raboof opened this issue May 13, 2024 · 0 comments

Comments

@raboof
Copy link

raboof commented May 13, 2024

The version range of GHSA-95mg-jgfx-54v9 follows the version range of CVE-2023-46104 which suggests version 3.0.1 is unaffected.

However, unfortunately, version 3.0.1 is in fact affected by this problem. Since we have a policy of not widening affected version ranges for already-published CVEs, we have created the follow-up CVE-2024-23952 CVE for this issue.

I see GHSA-95mg-jgfx-54v9 still suggests 3.0.1 is not affected, but there doesn't appear to be a GHSA for CVE-2024-23952.

Would you prefer we widen the range of GHSA-95mg-jgfx-54v9 and add CVE-2024-23952 as an alias, or allocate a new GHSA?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant