Skip to content
This repository has been archived by the owner on Jul 13, 2023. It is now read-only.

Github notifying us of CVE-2017-0889 for 5.2.0 #2547

Closed
zaksoup opened this issue Feb 7, 2018 · 3 comments
Closed

Github notifying us of CVE-2017-0889 for 5.2.0 #2547

zaksoup opened this issue Feb 7, 2018 · 3 comments

Comments

@zaksoup
Copy link

zaksoup commented Feb 7, 2018

Hi Paperclip folks,

Github sent us an email earlier today telling us that 5.2.0 is vulnerable to CVE-2017-0889, but we believed that 5.2.0 contained the fix to CVE-2017-0889, as confirmed by the release page, the PR, and the NIST website.

We're going to upgrade to 5.2.1 to be on the safe side, but just wanted to ping y'all over here about this warning - maybe github has incorrect data?

@zaksoup and @glassresistor
Code for America

@reedloden
Copy link

@mveytsman / @phillmv -- can one of you help get this fixed? Not sure what data source GitHub is using. Note that https://github.com/rubysec/ruby-advisory-db/blob/master/gems/paperclip/CVE-2017-0889.yml is correct.

@mveytsman
Copy link

Thanks for the ping @reedloden.

This does indeed look like an issue with GitHub's data, I'll ping this issue again when we fix it.

@mveytsman
Copy link

This should be fixed now.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants