You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
As of November 10, the assigned CVE-2018-1000620 does not yet reflect that the backported fix was made in 3.1.3. This is throwing off GitHub's security alerts as well.
It looks like you may be able to notify cve@mitre.org (the source of the CVE) and support@github.com about the backported fix and they will update their databases. I don't see any other formal channels to use.
This thread has been automatically locked due to inactivity. Please open a new issue for related bugs or questions following the new issue template instructions.
lockbot
locked as resolved and limited conversation to collaborators
Jan 9, 2020
Sign up for freeto subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Labels
bugBug or defectltsBackport for maintained old version
Backport fix #34
The text was updated successfully, but these errors were encountered: