Skip to content

Conversation

shelbyc
Copy link
Contributor

@shelbyc shelbyc commented Aug 30, 2024

On 29 August 2024, MITRE informed GitHub that CVE-2024-41661, which was issued August 2024 is a duplicate of CVE-2023-50094, which was issued December 2023 or January 2024. We rejected CVE-2024-41661 as a duplicate CVE because CVE-2023-50094 was published first. I suggest that the maintainers of reNgine replace all instances of CVE-2024-41661 with CVE-2023-50094, including in the changelog and repository security advisory.

On 29 August 2024, MITRE informed GitHub that CVE-2024-41661, which was issued August 2024 is a duplicate of CVE-2023-50094, which was issued December 2023 or January 2024. We rejected CVE-2024-41661 as a duplicate CVE because CVE-2023-50094 was published first and suggest that the maintainers of reNgine replace all instances of CVE-2024-41661 with CVE-2023-50094, including in the changelog and repository security advisory.
@yogeshojha
Copy link
Owner

Thank you @shelbyc

@yogeshojha yogeshojha merged commit 2f1bbfe into yogeshojha:master Aug 31, 2024
@shelbyc
Copy link
Contributor Author

shelbyc commented Aug 31, 2024

@yogeshojha Thanks for merging my PR! 😃 I wasn't able to change the CVE in GHSA-fx7f-f735-vgh4. Are you willing and able to change the CVE in the advisory from CVE-2024-41661 to CVE-2023-50094?

@yogeshojha
Copy link
Owner

Hi @shelbyc I have made the necessary changes, please let me know if we are good!

@shelbyc
Copy link
Contributor Author

shelbyc commented Aug 31, 2024

GHSA-fx7f-f735-vgh4 has CVE-2023-50094 on it and everything is good now! Thank you for your help!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants