-
Notifications
You must be signed in to change notification settings - Fork 334
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
GHSA-3h3x-2hwv-hr52: remove v2 version from affected versions list #4950
Conversation
Hey @qmuntal 👋 Out of curiosity do you know where this issue was addressed in the code? I've looked around a little and basedthis comment from the redhat bug
I was looking for a change to |
The issue was fixed in this PR: golang-fips/openssl#198. The |
Mmmm that's unfortunate. I take it that the relevant code for the change is simply not in the |
Yep, |
Gotcha. Thanks for taking the time to walk me through the context. Let me get this going for you :) |
Hi @qmuntal! Thank you so much for contributing to the GitHub Advisory Database. This database is free, open, and accessible to all, and it's people like you who make it great. Thanks for choosing to help others. We hope you send in more contributions in the future! |
I'm an owner of the github.com/golang-fips/openssl repo and also main contributor: https://github.com/golang-fips/openssl/graphs/contributors.
GHSA-3h3x-2hwv-hr52
has been unintentionally assigned to thev2
major version, when onlyv1
is affected.This PR removed the
v2
version from the affected versions list.