advisory-database icon indicating copy to clipboard operation
advisory-database copied to clipboard

[GHSA-8h5w-f6q9-wg35]: remove vulnerability since it is rejected

Open dippie8 opened this issue 1 year ago • 4 comments

A fix version is available for langchain and the vuln CVE-2023-32785. With this PR I modify the range, making known the version no longer affected.

dippie8 avatar Jan 29 '24 14:01 dippie8

Hi @dippie8 do you have any references to support this change?

CallmeMari avatar Jan 29 '24 20:01 CallmeMari

@CallmeMari sorry, doing a deeper investigation I changed the PR. As reported by NVD:

CVE has been marked "REJECT" in the CVE List. These CVEs are stored in the NVD, but do not show up in search results.

They also added in the description:

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2023-36189. Reason: This record is a duplicate of CVE-2023-36189. Notes: All CVE users should reference CVE-2023-36189 instead of this record. All references and descriptions in this record have been removed to prevent accidental usage.

Therefore, this vulnerability represents a duplicate of CVE-2023-36189, that is already reported by you here and I think that GHSA-8h5w-f6q9-wg35 should be removed.

dippie8 avatar Feb 06 '24 17:02 dippie8

👋 This pull request has been marked as stale because it has been open with no activity. You can: comment on the issue or remove the stale label to hold stale off for a while, add the Keep label to hold stale off permanently, or do nothing. If you do nothing this pull request will be closed eventually by the stale bot. Please see CONTRIBUTING.md for more policy details.

taladrane avatar Feb 22 '24 00:02 taladrane

👋 This pull request has been marked as stale because it has been open with no activity. You can: comment on the issue or remove the stale label to hold stale off for a while, add the Keep label to hold stale off permanently, or do nothing. If you do nothing this pull request will be closed eventually by the stale bot. Please see CONTRIBUTING.md for more policy details.

taladrane avatar Mar 10 '24 00:03 taladrane