ddollar / foreman

Manage Procfile-based applications
http://ddollar.github.com/foreman
MIT License
6.01k stars 630 forks source link

Security CVE-2022-3874 #795

Closed Doltair closed 11 months ago

Doltair commented 11 months ago

https://scout.docker.com/vulnerabilities/id/CVE-2022-3874?utm_source=desktop&utm_medium=ExternalLink

irphilli commented 11 months ago

Saw this come through as well, but it looks like this is being falsely attributed to this gem.

The "foreman" referenced in the CVE is part of Red Hat Satellite. References:

Doltair commented 11 months ago

So weird yeah. How can we dismiss this false tagging of CVE? :cry:

irphilli commented 11 months ago

It looks like it has been withdrawn: https://github.com/advisories/GHSA-9jfq-54vc-9rr2

Doltair commented 11 months ago

all good now! it's not showing anymore from the scans! 😃 .

Closing this issue.