#ghsa — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #ghsa, aggregated by home.social.
-
Requested a #CVE ID through a #GitHub Security Advisory on June 27 and still nothing, almost two weeks now. GitHub's docs say it usually takes up to three days.
Anyone else seeing longer waits from the GitHub CNA lately, or is this just me? Curious whether it's a general slowdown or something specific to my request.
-
🚀 49,000 Patches !
We’ve updated our dataset (https://huggingface.co/datasets/CIRCL/vulnerability-cwe-patch) of real-world vulnerabilities, now enriched with #CWE identifiers and #patches collected from platforms like GitHub, GitLab, Bitbucket.
This dataset is designed to support the development of tools for vulnerability classification. Dataset features are:
- #CVE / #GHSA ID
- Title of the #vulnerability
- Vulnerability description
- Patches (URL, Commit message, and Base64-encoded unified diff)
- CWE categorization -
I'm finally allowed to speak about this nice little DoS vulnerability I found in #starlette (and #FastAPI).
#CVE https://www.cve.org/CVERecord?id=CVE-2024-47874
#GHSA https://github.com/encode/starlette/security/advisories/GHSA-f96h-pmfr-66vw -
Hey #Mastodon admins, just a reminder that the details of the critical #security vulnerability GHSA-3fjr-858r-92rw/CVE-2024-23832 is going to be released tomorrow. :MokouWha: I still see some instances out there running a vulnerable version... :koishtare: Sent a DM to the admins of those instances of course. :cirno_fumo_yes: Please upgrade to a patched version (like 4.2.5 and 4.1.13) as soon as possible. :RumiaPray:
#MastoAdmin #FediAdmin #CVE-2024-23832 #CVE202423832 #CVE_2024_23832 #CVE #GHSA-3fjr-858r-92rw #GHSA3fjr858r92rw #GHSA_3fjr_858r_92rw #GHSA #GitHub #GitHubsecurityadvisory #cybersecurity #OriginValidation -
Many important issues raised in https://daniel.haxx.se/blog/2023/03/02/the-curl-nuget-story/ post by @bagder - not only does #NuGet appear to host dozens of really seriously outdated and #vulnerable packages, it also highlights serious issues in automated vulnerability management via vulnerability databases such as #GitHub Security Advisory Database (#GHSA DB). There definitely is room for improvement here.