You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Describe the data quality issue observed
Recently, we found that last affected version of CVE-2023-24163 is incorrect. According to its release note and issue pages, hutool fixed CVE-2023-24163 in verision 5.8.21. However, last affected version listed in OSV is 5.8.11. This incorrect information may mislead developers using this software.
Suggested changes to record
Update the fix version to 5.8.21.
That said, the source of the record, including the version information in the description ultimately comes from the CVE List, and from the MITRE CNA-LR, I have also notified them via https://cveform.mitre.org/
I expect the GitHub Advisory Database record correction to go through promptly, but I do not know how long the NVD or CVE List corrections will take.
GHSA-6c25-cxcc-pmc4 is now correct in the GitHub Advisory Database and OSV.dev CVE-2023-24163 is now correct in the CVE List, and this will eventually flow through to the NVD and OSV.dev once it has.
The CVE ID
This issue is related with CVE-2023-24163 and GHSA-6c25-cxcc-pmc4
Describe the data quality issue observed
Recently, we found that last affected version of CVE-2023-24163 is incorrect. According to its release note and issue pages, hutool fixed CVE-2023-24163 in verision 5.8.21. However, last affected version listed in OSV is 5.8.11. This incorrect information may mislead developers using this software.
Suggested changes to record
Update the fix version to 5.8.21.
Additional context
References:
gitee issue page: https://gitee.com/dromara/hutool/issues/I6AJWJ#note_20057806_link
github issue page: dromara/hutool#3149
hutool release note: https://github.com/dromara/hutool/releases
The text was updated successfully, but these errors were encountered: