Roave / SecurityAdvisories

:closed_lock_with_key: Security advisories as a simple composer exclusion list, updated daily
MIT License
2.7k stars 105 forks source link

Vulnerable package not in security advisories #113

Closed 8ctopus closed 1 year ago

8ctopus commented 1 year ago

While looking at my apache logs, I found bots scanning the following package which is most likely vulnerable to some sort of attack which is not yet in the security advisories.

https://packagist.org/packages/htmlawed/htmlawed

I opened an issue with the package itself: https://github.com/kesar/HTMLawed/issues/24

Ocramius commented 1 year ago

This repository will pick it up as soon as a GitHub advisory is published: nothing to do here 😁