Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Please publish commit for CVE fix #5896

Open
bastien-roucaries opened this issue Nov 3, 2024 · 10 comments
Open

Please publish commit for CVE fix #5896

bastien-roucaries opened this issue Nov 3, 2024 · 10 comments
Labels
bug Undesired behaviour unverified Some days we don't have a clue

Comments

@bastien-roucaries
Copy link

Hi,

Can we get the commit for CVE-2024-43365, CVE-2024-43364, CVE-2024-43363, and CVE-2024-43362

Bastien on behalf of debian project

@bastien-roucaries bastien-roucaries added bug Undesired behaviour unverified Some days we don't have a clue labels Nov 3, 2024
@TheWitness
Copy link
Member

@netniV and @bastien-roucaries,

Are these new or published already in 1.2.28?

@TheWitness
Copy link
Member

Just checked. @bastien-roucaries they have been made public. Can you not see the patches from the security section?

@bastien-roucaries
Copy link
Author

@TheWitness no no patch from security section

@TheWitness
Copy link
Member

There are pointers to the pull request though. Is that not enough?

@bastien-roucaries
Copy link
Author

No they are no pointer to the public access GHS
And https://github.com/search?q=repo%3ACacti%2Fcacti%20GHSA-fgc6-g8gc-wcg5&type=code return only the changelog

@TheWitness
Copy link
Member

That's disappointing. I'll look in my AM.

@bastien-roucaries
Copy link
Author

@TheWitness any news ?

@TheWitness
Copy link
Member

@netniV, @bastien-roucaries says he can not see the details in the Security Incidents to get the commit's for the security incidents. Can he not see our notes including the comments that pointed out the commit numbers? Is there any way to fix this?

@TheWitness
Copy link
Member

@bastien-roucaries, look at this ticket too. I've already answered this one once.

#5798

But it would be nice for you to get all the details. If you are going to be the Debian guy moving forward, we can add you to the security team.

@carnil
Copy link

carnil commented Nov 9, 2024

I can second this request, when having to fix cacti for instance in Debian, we cannot simply rebase to a newer version, so need to identify fixes for the security issues and backport the commits as needed.

Thanks a lot for your work on developing cacti!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Undesired behaviour unverified Some days we don't have a clue
Projects
None yet
Development

No branches or pull requests

3 participants