Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2020-14422 Security Vulnerability #66

Open
seymoneg opened this issue Dec 2, 2024 · 1 comment
Open

CVE-2020-14422 Security Vulnerability #66

seymoneg opened this issue Dec 2, 2024 · 1 comment

Comments

@seymoneg
Copy link

seymoneg commented Dec 2, 2024

@phihag I wanted to follow up regarding the NIST vulnerability CVE-2020-14422 where the hash values are being improperly computed. This issue has a Mend severity score of 5.9.

I noticed that there's an open PR that addresses this issue and has been approved as well as another open issue asking about a fix for the same vulnerability (#63).

Given this repository's importance and the severity of the vulnerability, it would be greatly appreciated if the open PR could be merged #56. I understand that the repository has been inactive for some time, but merging this would mitigate the risk for the users that rely on it.

Thank you.

@seymoneg
Copy link
Author

seymoneg commented Dec 9, 2024

@phihag just following up with the issue, could you please merge the PR? Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant