Open
Description
Whatever process is used to create GitHub Security Advisories does not consume version ranges from CVE metadata properly.
This results, for example, in GHSA-g975-f26h-93g8 claiming that version 2.24.2 is affected, when https://github.com/CVEProject/cvelist/blob/9a1d65a12274643c9bad407acb8368f2b60d2b5c/2022/43xxx/CVE-2022-43408.json#L22-L25 specifically excludes it.
This creates a ton of unnecessary confusion for users and false positive security scan results, and should be fixed.
Metadata
Metadata
Assignees
Labels
No labels