Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[GHSA-599f-7c49-w659] Arbitrary code execution in Apache Commons Text #2273

Conversation

jensdietrich
Copy link

Updates

  • Affected products

Comments
Several other components are also affected as a result of cloning or shading. Proof-of-Vulnerability projects with tests to verify the presence of the CVE can be found here: https://github.com/jensdietrich/xshady-release/.

@github-actions github-actions bot changed the base branch from main to jensdietrich/advisory-improvement-2273 May 17, 2023 02:02
@darakian
Copy link
Contributor

Hey @jensdietrich, sorry for the delay. Same question as #2258
Can you elaborate on what the results are and how they were generated?

@jensdietrich
Copy link
Author

Please see my response for #2258 -- do let me know if more info is needed for this specific PR.

@darakian
Copy link
Contributor

Borked again on overlapping version ranges, but I've put the change in manually 👍

@darakian darakian closed this Jun 12, 2023
@github-actions github-actions bot deleted the jensdietrich-GHSA-599f-7c49-w659 branch June 12, 2023 22:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants