OSSIndex / vulns

Report missing advisories and corrections on OSS Index
17 stars 12 forks source link

Incorrect versions in vulnerability #319

Closed davecramer closed 2 years ago

davecramer commented 2 years ago

Vulnerability URL Provide the URL to the vulnerability. For example:

https://ossindex.sonatype.org/vulnerability/sonatype-2022-4402

Component URL Provide the URL to the component. For example:

https://github.com/pgjdbc/pgjdbc/commit/739e599d52ad80f8dcd6efedc6157859b1a9d637

Description The commit above which is referenced in the vulnerability actually fixes the vulnerability The correct effected versions < 42.2.26 42.3.x 42.4.0

See https://github.com/pgjdbc/pgjdbc/security/advisories/GHSA-r38f-c4h4-hqq2 for details.

Please update this ASAP.

ken-duck commented 2 years ago

From what I can tell, this has been fixed: https://ossindex.sonatype.org/component/pkg:maven/org.postgresql/postgresql@42.2.26