Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[GHSA-cxf7-qrc5-9446] Remote shell execution vulnerability in image_processing #1118

Conversation

wonda-tea-coffee
Copy link

Updates

  • Affected products
  • Description

Comments
As noted below, this vulnerability has not been fixed.
janko/image_processing#100

@github
Copy link
Collaborator

github commented Dec 7, 2022

Hi there @janko! A community member has suggested an improvement to your security advisory. If approved, this change will affect the global advisory listed at github.com/advisories. It will not affect the version listed in your project repository.

This change will be reviewed by our highly-trained Security Curation Team. If you have thoughts or feedback, please share them in a comment here! If this PR has already been closed, you can start a new community contribution for this advisory

@github-actions github-actions bot changed the base branch from main to wonda-tea-coffee/advisory-improvement-1118 December 7, 2022 09:01
@CallmeMari
Copy link

Hi @wonda-tea-coffee, thank you for your contribution. The remote shell execution vulnerability this advisory is describing has been fixed for the #apply function. A new GitHub Security Advisory would be a better way to inform users about other vulnerable functions.

@wonda-tea-coffee
Copy link
Author

Hi @CallmeMari, Thank you for your reply.
janko/image_processing#100 also mentions a vulnerability about the apply function.
Therefore, the apply function is still vulnerable to RCE vulnerabilities.

@ronwoch
Copy link

ronwoch commented Dec 22, 2022

Hi @wonda-tea-coffee,
I agree that the issue seems to indicate that the initial fix was not a complete success. In cases like this, it is usually best to request the Maintainers to release an additional security advisory to clarify that the original fix was not successful.

@wonda-tea-coffee
Copy link
Author

@ronwoch
I see.
Then I will close this Issue.

@github-actions github-actions bot deleted the wonda-tea-coffee-GHSA-cxf7-qrc5-9446 branch December 22, 2022 03:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants