GHSA/SYNC: 1 new faraday advisory#1058
Conversation
| unaffected_versions: | ||
| - "< 2.0.0" | ||
| patched_versions: | ||
| - ">= 2.14.2" |
There was a problem hiding this comment.
https://nvd.nist.gov/vuln/detail/CVE-2026-33637 says
This issue has been fixed in version 2.14.3.
But there is no 2.14.3 :-o https://rubygems.org/gems/faraday/versions. So something is off in here. Is CVE wrong? Should we report?
There was a problem hiding this comment.
Yes, nvd website data is wrong so I did not use it. Check the release notes URL.
There was a problem hiding this comment.
Unclicked "Resolve comment" button - will wait for your feedback.
There was a problem hiding this comment.
All good, just wondering if there's known contact where to report such a mistakes.
There was a problem hiding this comment.
Yes, nvd website data is wrong so I did not use it. Check the release notes URL.
Try GitHub Security Advisory (GHSA) web site - see that NVD website got the data from there.
There was a problem hiding this comment.
If you want to fix this data, this can be worked separately from this PR.
GHSA/SYNC: 1 new faraday advisory