Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Issue CVEs for vulnerabilities fixed by #6167 and #6163 #6345

Open
ebickle opened this issue Apr 8, 2024 · 1 comment
Open

Issue CVEs for vulnerabilities fixed by #6167 and #6163 #6345

ebickle opened this issue Apr 8, 2024 · 1 comment
Assignees
Labels
priority::medium A medium priority issue that should be resolved soon target::1.x A task that is targeted for a 1.x release type::enhancement Used when improving a feature

Comments

@ebickle
Copy link

ebickle commented Apr 8, 2024

Describe the issue

The release notes for version 1.6.4 fixed two vulnerabilities that are missing CVEs, and as a result are not found by GitHub Dependabot or other tools dependent on the GitHub Advisory Database or other CVE databases.

https://github.com/axios/axios/releases/tag/v1.6.4

Could these be published as CVEs? One easy way to do so is to create a GitHub security advisory on the repository: https://docs.github.com/en/code-security/security-advisories/working-with-repository-security-advisories/publishing-a-repository-security-advisory

Thanks!

Example Code

No response

Expected behavior

When possible, security vulnerabilities should be reported as advisories via CVEs so they can be automatically detected by tools.

Axios Version

No response

Adapter Version

No response

Browser

No response

Browser Version

No response

Node.js Version

No response

OS

No response

Additional Library Versions

No response

Additional context/Screenshots

No response

@jasonsaayman
Copy link
Member

thanks i will have a look

@jasonsaayman jasonsaayman self-assigned this Apr 20, 2024
@jasonsaayman jasonsaayman added priority::medium A medium priority issue that should be resolved soon type::enhancement Used when improving a feature target::1.x A task that is targeted for a 1.x release labels Apr 20, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
priority::medium A medium priority issue that should be resolved soon target::1.x A task that is targeted for a 1.x release type::enhancement Used when improving a feature
Projects
None yet
Development

No branches or pull requests

2 participants