Skip to content

Conversation

@EliahKagan
Copy link
Contributor

@EliahKagan EliahKagan commented Sep 6, 2024

This adds a notice for CVE-2024-45405 (GHSA-m8rp-vv92-46c7) in gix-path.

When first opened, this PR didn't include the CVE number or link to the global GHSA, since those had not yet been created. But I have since edited this PR to include them.

(Although they involve the same crate and the same public functions, this gix-path vulnerability is a separate vulnerability from RUSTSEC-2024-0367/CVE-2024-45305/GHSA-v26r-4c9c-h3j6.)

cc @Byron

- `<` `>` around a bare URL
- manual linking and rendering of referenced commit hash
- manual linking of a bare CVE number to associated global GHSA
@EliahKagan EliahKagan marked this pull request as draft September 6, 2024 16:46
@EliahKagan EliahKagan changed the title Advisory for GHSA-m8rp-vv92-46c7 (incomplete unescaping) in gix-path Advisory for CVE-2024-45405 (incomplete unescaping) in gix-path Sep 6, 2024
@EliahKagan EliahKagan marked this pull request as ready for review September 6, 2024 16:55
Now that it has been published there as well.
@Shnatsel Shnatsel merged commit 987de17 into rustsec:main Sep 7, 2024
@Shnatsel
Copy link
Member

Shnatsel commented Sep 7, 2024

Thank you!

@EliahKagan EliahKagan deleted the gix-path-quoted branch September 7, 2024 04:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants