Improve https://github.com/advisories/GHSA-6q8m-42qq-64r7 - #1745
Conversation
|
@MarkAckert Before I merge the changes, I have a question about versions 4.18.10 and 4.18.11. https://github.com/zowe/imperative/commits/v5.7.1 merged changes from PR 902, which looks like it covers changes from 900 and 901. |
That's right 👍 The relevant commit is the one named "Replace execSync with spawnSync" which was present in PR 900. PR 901 is separate and unrelated - it was for npm@9 compatibility. As for verifying my authenticity, I am also a Zowe CLI Squad Member and admin of the Imperative repository. |
|
Hi @MarkAckert! Thank you so much for contributing to the GitHub Advisory Database. This database is free, open, and accessible to all, and it's people like you who make it great. Thanks for choosing to help others. We hope you send in more contributions in the future! |
|
Thank you both for providing and clarifying information about GHSA-6q8m-42qq-64r7/CVE-2021-4326! |
Copied/following from #1744 to fix a minor mistake in 'fixed' version fields.
Updates
Comments
I am part of the team that submitted the CVE Request. Due to confusion in communicating versioning, this advisory appears to be incorrect. We marked the CVE as impacting Zowe versions < 1.28.2 or < 2.5.0 which is understood by many of our consumers, but not by automation. We'll fix this going forward. The actual Imperative versions affected are < 4.18.10 or >= 5.0.0, < 5.7.1, and the PRs which fixed the issue were added to the references section. As for verifying my authenticity, I am a Zowe Organization Owner/Administrator and Zowe CLI Squad Member (which owns the Imperative framework). I can provide additional information if required, please let me know if that's the case.