Skip to content
This repository was archived by the owner on Jul 13, 2023. It is now read-only.
This repository was archived by the owner on Jul 13, 2023. It is now read-only.

Github notifying us of CVE-2017-0889 for 5.2.0 #2547

@zaksoup

Description

@zaksoup

Hi Paperclip folks,

Github sent us an email earlier today telling us that 5.2.0 is vulnerable to CVE-2017-0889, but we believed that 5.2.0 contained the fix to CVE-2017-0889, as confirmed by the release page, the PR, and the NIST website.

We're going to upgrade to 5.2.1 to be on the safe side, but just wanted to ping y'all over here about this warning - maybe github has incorrect data?

@zaksoup and @glassresistor
Code for America

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions