Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[GHSA-2q4h-h5jp-942w] Firejail before 0.9.64.4 allows attackers to bypass... #1814

Closed

Conversation

kmk3
Copy link

@kmk3 kmk3 commented Mar 23, 2023

Updates

  • Affected products
  • Description
  • References
  • Source code location
  • Summary

Comments
Add a few more relevant links and extend the description

@github-actions github-actions bot changed the base branch from main to kmk3/advisory-improvement-1814 March 23, 2023 09:55
@kmk3
Copy link
Author

kmk3 commented Mar 23, 2023

Notes:

The title is empty, but the title field is marked as required, so I tried to
come up with a good enough title, though I'm not sure how well it fits. Feel
free to change it.

Affected products -> Ecosystem is marked as required, but there is no valid
option. So I just set it to the first one (Composer) and put the
affected/patched versions in the description instead of their respective
fields.

I would suggest to avoid marking empty fields as required if the entry already
exists on the system, to make it easier to contribute.

@darakian
Copy link
Contributor

Hey @kmk3 sorry but we only work on the advisories which fit into our ecosystem model for the moment.

@kmk3
Copy link
Author

kmk3 commented Mar 25, 2023

Hey @kmk3 sorry but we only work on the advisories which fit into our
ecosystem model for the moment.

Is there any way to at least link the source code repository to the advisory?

The GHSA page currently shows this:

  • Source code: No known source code

Also, there are many CVEs attributed to firejail in the database:

But currently none of them show up in the project's Security -> Advisories
section:

Edit: This issue is currently under discussion:

@darakian
Copy link
Contributor

Is there any way to at least link the source code repository to the advisory?

Not at the moment sorry :(

@kmk3
Copy link
Author

kmk3 commented Mar 28, 2023

Is there any way to at least link the source code repository to the
advisory?

Not at the moment sorry :(

Alright, closing.

@kmk3 kmk3 closed this Mar 28, 2023
@github-actions github-actions bot deleted the kmk3-GHSA-2q4h-h5jp-942w branch March 28, 2023 05:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants