-
Notifications
You must be signed in to change notification settings - Fork 473
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
NIST CVE database has CVE-2022-23639 misrecorded? #1151
Comments
If tool reports a vulnerability to |
It looks like a bug in the database, or am I missing something? |
I guess it's a bug in your vulnerability report tool. |
This string: Similarly, the CVE record also references |
Sigh. GitHub again. They've done strange things about our report before, but it seems that was not the only problem. |
Great, thanks! |
I'm not sure this is your issue directly, but there seems to be a problem with how CVE-2022-23639 that was fixed here is referring to crossbeam, such that Black Duck is flagging Crossbeam 0.8.4 which clearly is post the fix.
Reading the "Known Affected Software Configurations", it clearly suggests that it's
crossbeam
that is the problem rather thancrossbeam-utils
, but I'm not very familiar with CVE records. In any case, something is not quite right with how the vulnerability is being reported.The text was updated successfully, but these errors were encountered: