Skip to content

please help the jq project add GHSA-8mxc-vqrq-gcm8 to their Security Notices #5385

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
eslerm opened this issue Mar 21, 2025 · 4 comments
Closed

Comments

@eslerm
Copy link

eslerm commented Mar 21, 2025

Hi Github Advisory Curation Team,

Could you please assist jq in adding GHSA-8mxc-vqrq-gcm8 to their Security tab? Upstream is interested: jqlang/jq#3296 (comment)

ref: https://github.com/github/advisory-database/blob/main/advisories/unreviewed/2025/02/GHSA-8mxc-vqrq-gcm8/GHSA-8mxc-vqrq-gcm8.json

@shelbyc
Copy link
Contributor

shelbyc commented Mar 21, 2025

Hi @eslerm, there isn't a procedure for retroactively adding a global advisory to a repository. However, the maintainers of jq are welcome to make a new repository GitHub Security Advisory about CVE-2024-53427 to discuss the vulnerability. As I said in #5383 (comment), jq isn't in one of the GitHub Advisory Database's supported ecosystems, so we can't review the advisory for inclusion in the reviewed set of advisories. But if jq want to include their perspective as maintainers in the CVE record, they can publish a repo GHSA and send it to https://cveform.mitre.org when they request an update as a publicly available reference to support updates they want to make to the CVE record.

@shelbyc shelbyc closed this as completed Mar 21, 2025
@eslerm
Copy link
Author

eslerm commented Mar 21, 2025

Thank you @shelbyc 🙏 I hadn't seen @kbsteere's PR 👍

To publish a repo GHSA, does jq need to file a GitHub Private Vulnerability Report?

@shelbyc
Copy link
Contributor

shelbyc commented Mar 21, 2025

To publish a repo GHSA, does jq need to file a GitHub Private Vulnerability Report?

No, they just need someone with sufficient privileges to create an advisory. Private Vulnerability Reporting is a tool for researchers, rather than maintainers, to create a private repo GHSA to enable coordinated vulnerability disclosure.

@eslerm
Copy link
Author

eslerm commented Mar 21, 2025

Thanks @shelbyc

iiuc, either a jq owner or "Security Managers" for the org are allowed to do that. I'll relay to jq. Cheers!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants