Problems with GHSA-2v4p-qf9q-27wj
Los mantenedores suelen responder en 1 día
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 4/5
- Tiempo estimado
- 3-5 días
- Aptitud para principiantes
- 38/100
Línea de trabajo
Start by reading GHSA-2v4p-qf9q-27wj and comparing its patched-version metadata with advisory-database PR #9608. Trace how the advisory database records and publishes the affected range, then verify that scanners no longer report grpc-go 1.84.0 as vulnerable; confirm whether any further maintainer action is required.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
The grpc-go team recently published a security advisory: https://github.com/advisories/GHSA-2v4p-qf9q-27wj
The fix for the above vulnerability was made to our master branch after we cut the branch for release 1.84.0. The advisory initially mentioned that the vulnerability affected versions <=1.83.1, because at that point the most recent release was 1.83.1. As part of publishing the advisory we also pushed out a couple of patch releases, 1.82.2 and 1.83.2 and marked them as the patched versions in the advisory.
After publishing the advisory, we cherry-picked the change into the 1.84.x branch and pushed out 1.84.0 release that contained the fix.
But scanning tools are listing 1.84.0 to be affected by this vulnerability and downstream users of grpc-go using 1.84.0 are showing up as vulnerable.
How do we go about fixing this?
- I updated the patched versions in the advisory. I don't know if this is sufficient.
- I also approved https://github.com/github/advisory-database/pull/9608 that directly fixes the database. When and by whom would this PR be merged? Is this sufficient?
Please let us know if there is something more needs to be done from our side.
Thanks
- Lenguaje dominante
- Sin datos de lenguaje
- Estrellas
- 2.5k
- Forks
- 772
- Merge medio
- 5 d 5 h
- PR fusionados (30 d)
- 87
Preparar el entorno
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de github/advisory-database
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
github/advisory-database#9255 ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
github/advisory-database#9164 · 1 reacción ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
github/advisory-database#8994 ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
github/advisory-database#8898 · 4 comentarios · 1 reacción ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
github/advisory-database#8841 ·
Los mantenedores suelen responder en 1 día
Todos los issues de github/advisory-database
Issues similares
-
bug good first issue
Dificultad 2/5 1-3 horas Aptitud para principiantes 88/100
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 88/100
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 82/100
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 88/100
google/adk-python#7292 ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 88/100