Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-ID for recent XSS issues ? #590

Closed
dregad opened this issue Mar 29, 2018 · 5 comments
Closed

CVE-ID for recent XSS issues ? #590

dregad opened this issue Mar 29, 2018 · 5 comments
Labels

Comments

@dregad
Copy link

dregad commented Mar 29, 2018

I was wondering if a CVE ID had been assigned to the XSS issues fixed in #495 / 1.7.0.

If not, it might be a good idea to request one, and reference it in the various discussion threads.

@aidantwoods
Copy link
Collaborator

I've now requested one though the DWF since they appear to deal specifically with CVEs for open-source.

You can view the submission here: https://pending-requests-v5.distributedweaknessfiling.org/

@dregad
Copy link
Author

dregad commented Mar 29, 2018

Cheers !

@dregad
Copy link
Author

dregad commented Apr 11, 2018

I just checked the status and CVE-2018-1000162 has been assigned by DWF, but MITRE have not yet accepted it (CVEProject/cvelist#411)

@aidantwoods
Copy link
Collaborator

A-ha, I received an email last week with the CVE and have been checking the MITRE site for when it goes though. I hadn't seen that PR though! The batch seems to be held up by another CVE, so I'd expect that our CVE passes through okay. I was planning on holding off referencing the assigned CVE in #495 until it's accepted by MITRE

@aidantwoods
Copy link
Collaborator

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants