Hi wollomatic,
Thanks for turning this around as fast as you did, and for publishing it. GitHub closes the advisory thread once an advisory is published, so I can't leave this there and am opening it here instead.
GHSA-c7vj-4cqh-8cv9 doesn't carry a CVE ID, and it's still absent from the GitHub Advisory Database. Both usually come from the same thing: nobody has requested an ID.
If you're willing, the Request CVE button on the advisory page handles it. GitHub is a CNA, so pressing it gets an ID assigned without filing anything with MITRE. It's owner-only, so it isn't mine to press.
The advisory is already complete: Critical, CWE-424 and CWE-863, affected >= 1.8.0, <= 1.12.3, patched 1.13.0. There's nothing to prepare first.
The reason to want the ID is that scanners and distribution trackers key on CVEs. Anyone still running 1.12.3 hears about it through their normal tooling rather than by reading the release notes.
If GitHub comes back with questions, send them my way and I will answer.
Kevin
Hi wollomatic,
Thanks for turning this around as fast as you did, and for publishing it. GitHub closes the advisory thread once an advisory is published, so I can't leave this there and am opening it here instead.
GHSA-c7vj-4cqh-8cv9doesn't carry a CVE ID, and it's still absent from the GitHub Advisory Database. Both usually come from the same thing: nobody has requested an ID.If you're willing, the Request CVE button on the advisory page handles it. GitHub is a CNA, so pressing it gets an ID assigned without filing anything with MITRE. It's owner-only, so it isn't mine to press.
The advisory is already complete: Critical, CWE-424 and CWE-863, affected
>= 1.8.0, <= 1.12.3, patched1.13.0. There's nothing to prepare first.The reason to want the ID is that scanners and distribution trackers key on CVEs. Anyone still running 1.12.3 hears about it through their normal tooling rather than by reading the release notes.
If GitHub comes back with questions, send them my way and I will answer.
Kevin