Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2023-4759 fix for 5.x version? #30

Closed
huangfeng212 opened this issue Feb 26, 2024 · 1 comment
Closed

CVE-2023-4759 fix for 5.x version? #30

huangfeng212 opened this issue Feb 26, 2024 · 1 comment

Comments

@huangfeng212
Copy link

huangfeng212 commented Feb 26, 2024

Description

Will there be fix of https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-4759 for the 5.x version? I see from maven central there is no fix https://mvnrepository.com/artifact/org.eclipse.jgit/org.eclipse.jgit. However our project staying with java8 and can not use the 6.x version

I found this thread https://www.eclipse.org/forums/index.php/m/1862132/?srch=CVE-2023-4759#msg_1862132 and according to that, the new 5.13.3 should have the cve fixed, but from the maven-central, it still shows that version has the cve. I also encountered same error when I build my project, I think the authority at https://nvd.nist.gov/vuln/detail/CVE-2023-4759 need to update that this 5.13.3 version is also a fixed version.
https://nvd.nist.gov/vuln/detail/CVE-2023-4759

Motivation

Can't find a CVE free version for 5.x(java8)

Alternatives considered

No response

Additional context

No response

@tomaswolf
Copy link
Contributor

5.13.3 has that CVE fixed.

As you wrote, NIST should update the listing. We did send an update request, but they say "This vulnerability has been modified since it was last analyzed by the NVD. It is awaiting reanalysis which may result in further changes to the information provided."

There's nothing more we can do.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants