Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Address CVE-2018-1227 @ NVD #8906

Open
kallisti5 opened this issue Feb 2, 2024 · 2 comments
Open

Address CVE-2018-1227 @ NVD #8906

kallisti5 opened this issue Feb 2, 2024 · 2 comments
Labels

Comments

@kallisti5
Copy link

Summary

https://nvd.nist.gov/vuln/detail/CVE-2018-1227 has been open for a loooong time without an end version. Every time we review CVE's for products, this pops up as a false positive.

Expectation

Maybe reach out to NVD and tag an "end version" so it doesn't show up as a false positive?

@kallisti5 kallisti5 added the bug label Feb 2, 2024
@taylorsilva
Copy link
Member

Great point! Not sure if they'll accept an end version since some unknown actor still owns the domain. It does redirect to concourse-ci.org now though. I'll send them a message and see, but not hopeful about the outcome.

@taylorsilva
Copy link
Member

Three weeks later and still no reply from them. I did submit a request through some form on their website.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants