Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

May I ask if it's possible to apply for a CVE for this project if a security vulnerability is found? #2870

Closed
sunriseXu opened this issue Apr 11, 2024 · 7 comments
Milestone

Comments

@sunriseXu
Copy link

Description

Hi there, recently, I found a security bug in this project, may I ask if it's possible to apply for a CVE for this project if a security vulnerability is found?

@falkoschindler
Copy link
Contributor

Thanks for bringing this to our attention, @sunriseXu!
We're very interested in documenting and fixing security vulnerabilities in NiceGUI. But we don't have experience with CVEs in our own project yet. What would need to be done from our side? How does it compare to reporting a regular GitHub issue? Can you help us setting things up, or should we ask for help from the community?

@falkoschindler falkoschindler added the question Further information is requested label Apr 11, 2024
@sunriseXu
Copy link
Author

Thanks for your response!
Do you mind enable project private-vulnerability-reporting-for-a-repository, so I can report the bug privately. After maintainers review and confirm the bug, I will submit a CVE request to https://cveform.mitre.org/ to get a CVE id. When the bug is fixed, the bug report can be disclosed which will be referenced by CVE information parts.

@falkoschindler
Copy link
Contributor

falkoschindler commented Apr 11, 2024

@sunriseXu Alright, we enabled private vulnerability reporting. 👍🏻

I assume by enabling this setting this issue is resolved. We will discuss the actual security issue privately.

@falkoschindler falkoschindler removed the question Further information is requested label Apr 11, 2024
@falkoschindler falkoschindler added this to the 1.4.21 milestone Apr 11, 2024
@sunriseXu
Copy link
Author

Thank you!

@falkoschindler
Copy link
Contributor

@sunriseXu No, I just published it because I thought that's the right thing to do after providing a fix in https://github.com/zauberzeug/nicegui/releases/tag/v1.4.21. Shouldn't GitHub's Dependabot start warning other developers about this security issue in NiceGUI? Please correct me if I'm wrong.

@falkoschindler
Copy link
Contributor

@sunriseXu I just edited your description to hide any details until I understand what should be part of the public advisory and what not.

@sunriseXu
Copy link
Author

sunriseXu commented Apr 13, 2024

Thank you for the application for CVE, I have confirmed the bug is fixed. I think it is fine to hide details about vulnerability, just a general description is good. Thanks again for everything and have a great day!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants