Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[GHSA-jfh8-c2jp-5v3q] Remote code injection in Log4j #2445

Conversation

jensdietrich
Copy link

Updates

  • Affected products

Comments
Several other components are also affected as a result of cloning or shading. Proof-of-Vulnerability projects with tests to verify the presence of the CVE can be found here: https://github.com/jensdietrich/xshady-release/ , the process was the same used for #2258 .

@github-actions github-actions bot changed the base branch from main to jensdietrich/advisory-improvement-2445 June 22, 2023 01:57
@darakian darakian added the Keep label Jul 15, 2023
@jensdietrich
Copy link
Author

@darakian This PR has been stuck for some time now, same issue here: #2444. Is there anything we can do to help? We have a number of similar PRs in the pipeline, we expect to find clones for most of the artifacts associated with the CVEs listed in https://github.com/jensdietrich/xshady/ (29 CVEs atm, 6 already reported as PRs, 4 PRs accepted, 2 open including this one), we are running the analyses atm. Please let us know what the best way is to go about this.

@darakian
Copy link
Contributor

darakian commented Sep 5, 2023

Hey @jensdietrich, sorry about the delay. We've been swamped on our end. I'll try to get to this and the other PR this week 🙇

@darakian
Copy link
Contributor

Manually merged in

@darakian darakian closed this Sep 19, 2023
@github-actions github-actions bot deleted the jensdietrich-GHSA-jfh8-c2jp-5v3q branch September 19, 2023 22:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants