Advisory for CVE-2024-43785 (terminal sanitization) in gitoxide-core #2046
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This adds a notice for CVE-2024-43785 (GHSA-88g2-r9rw-g55h) in
gitoxide-core
. See also GitoxideLabs/gitoxide#1534.This low-risk CWE-150 vulnerability is currently unpatched, but following coordination, it was decided to disclose it to the public with an advisory, as described in GitoxideLabs/gitoxide#1534.
Having a RUSTSEC advisory (as well as the existing GHSA) further serves the purpose of informing users, and should help avoid unnecessary skew between the information available in different advisory databases.
I will make sure to open another PR to update the RUSTSEC advisory when a fix, or other substantially changed information, is available (unless someone else ends up doing so first).
cc @Byron