Skip to content

Improve https://github.com/advisories/GHSA-6q8m-42qq-64r7 - #1745

Merged
advisory-database[bot] merged 1 commit into
github:MarkAckert/advisory-improvement-1745from
MarkAckert:MarkAckert-GHSA-6q8m-42qq-64r7
Mar 2, 2023
Merged

Improve https://github.com/advisories/GHSA-6q8m-42qq-64r7#1745
advisory-database[bot] merged 1 commit into
github:MarkAckert/advisory-improvement-1745from
MarkAckert:MarkAckert-GHSA-6q8m-42qq-64r7

Conversation

@MarkAckert

@MarkAckert MarkAckert commented Mar 2, 2023

Copy link
Copy Markdown

Copied/following from #1744 to fix a minor mistake in 'fixed' version fields.

Updates

  • Affected products
  • CVSS
  • References
  • Severity

Comments
I am part of the team that submitted the CVE Request. Due to confusion in communicating versioning, this advisory appears to be incorrect. We marked the CVE as impacting Zowe versions < 1.28.2 or < 2.5.0 which is understood by many of our consumers, but not by automation. We'll fix this going forward. The actual Imperative versions affected are < 4.18.10 or >= 5.0.0, < 5.7.1, and the PRs which fixed the issue were added to the references section. As for verifying my authenticity, I am a Zowe Organization Owner/Administrator and Zowe CLI Squad Member (which owns the Imperative framework). I can provide additional information if required, please let me know if that's the case.

@github-actions
github-actions Bot changed the base branch from main to MarkAckert/advisory-improvement-1745 March 2, 2023 16:41
@shelbyc

shelbyc commented Mar 2, 2023

Copy link
Copy Markdown
Contributor

@MarkAckert Before I merge the changes, I have a question about versions 4.18.10 and 4.18.11.
https://github.com/zowe/imperative/commits/v4.18.10 merged changes from PR 900, but changes from PR 901 weren't merged until https://github.com/zowe/imperative/commits/v4.18.11. Is version 4.18.10 considered fixed with just the commits from PR 900?

https://github.com/zowe/imperative/commits/v5.7.1 merged changes from PR 902, which looks like it covers changes from 900 and 901.

@t1m0thyj

t1m0thyj commented Mar 2, 2023

Copy link
Copy Markdown

Is version 4.18.10 considered fixed with just the commits from PR 900?

That's right 👍 The relevant commit is the one named "Replace execSync with spawnSync" which was present in PR 900. PR 901 is separate and unrelated - it was for npm@9 compatibility.

As for verifying my authenticity, I am also a Zowe CLI Squad Member and admin of the Imperative repository.

@advisory-database
advisory-database Bot merged this pull request into github:MarkAckert/advisory-improvement-1745 Mar 2, 2023
@advisory-database

Copy link
Copy Markdown
Contributor

Hi @MarkAckert! Thank you so much for contributing to the GitHub Advisory Database. This database is free, open, and accessible to all, and it's people like you who make it great. Thanks for choosing to help others. We hope you send in more contributions in the future!

@shelbyc

shelbyc commented Mar 2, 2023

Copy link
Copy Markdown
Contributor

Thank you both for providing and clarifying information about GHSA-6q8m-42qq-64r7/CVE-2021-4326!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants