Skip to content

[GHSA-6q8m-42qq-64r7] Imperative CLI vulnerable to Command Injection - #1744

Closed
MarkAckert wants to merge 1 commit into
MarkAckert/advisory-improvement-1744from
MarkAckert-GHSA-6q8m-42qq-64r7
Closed

[GHSA-6q8m-42qq-64r7] Imperative CLI vulnerable to Command Injection#1744
MarkAckert wants to merge 1 commit into
MarkAckert/advisory-improvement-1744from
MarkAckert-GHSA-6q8m-42qq-64r7

Conversation

@MarkAckert

Copy link
Copy Markdown

Updates

  • Affected products
  • CVSS
  • References
  • Severity

Comments
I am part of the team that submitted the CVE Request. Due to confusion in communicating versioning, this advisory appears to be incorrect. We marked the CVE as impacting Zowe versions < 1.28.2 or < 2.5.0 which is understood by many of our consumers, but not by automation. We'll fix this going forward. The actual Imperative versions affected are < 4.18.10 or >= 5.0.0, < 5.7.1, and the PRs which fixed the issue were added to the references section. As for my authenticity, I am a Zowe Organization Owner/Administrator and Zowe CLI Squad Member (which owns the Imperative framework). I can provide additional information to verify my authenticity if required, please let me know if that's the case.

@github-actions
github-actions Bot changed the base branch from main to MarkAckert/advisory-improvement-1744 March 2, 2023 14:54
@MarkAckert

Copy link
Copy Markdown
Author

There is still a minor error in this PR, so I will close it and open a new one.

@MarkAckert MarkAckert closed this Mar 2, 2023
@github-actions
github-actions Bot deleted the MarkAckert-GHSA-6q8m-42qq-64r7 branch March 2, 2023 16:33
@shelbyc

shelbyc commented Mar 2, 2023

Copy link
Copy Markdown
Contributor

@MarkAckert Thank you for letting me know there's a new PR coming! I was just checking PRs 900 and 902 against the commit histories for v4.18.11 and v5.7.2 and will keep an eye out for the new info.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants