You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
As part of a research experiment, we developed a tool that allows us to crawl through existing vulnerabilities in upstream projects, that are potentially not fixed in fork.
We have a suspicion that your repository, which shares commits withhttps://github.com/civetweb/civetweb is still vulnerable to CVE-2018-12684
Hi, great project!
As part of a research experiment, we developed a tool that allows us to crawl through existing vulnerabilities in upstream projects, that are potentially not fixed in fork.
We have a suspicion that your repository, which shares commits withhttps://github.com/civetweb/civetweb is still vulnerable to CVE-2018-12684
The vulnerability has been fixed upstream via this commit civetweb/civetweb@8fd069f
However, we could not find the patch applied in this repository
libhttp/src/httplib_ssi.c
Line 205 in cec0e67
If possible, we would like to know whether it is indeed vulnerable to the vulnerability we described.
Your insight would be very valuable for our experiment.
Do not hesitate to contact us if you want more information.
Thanks again.
The text was updated successfully, but these errors were encountered: