github / advisory-database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Creative Commons Attribution 4.0 International
1.75k stars 336 forks source link

[GHSA-3q4w-rf2j-fx5x] Observable Response Discrepancy vulnerability in HumHub... #4988

Open kaerez opened 3 weeks ago

kaerez commented 3 weeks ago

Updates

Comments

  1. Provide repo. details
  2. All current and past versions are vulnerable
  3. Add GHSA credit: Erez Kalman
JonathanLEvans commented 3 weeks ago

Hi @kaerez, I cannot find HumHub in any of the supported ecosystems. Could you provide a link to where HumHub can be found in one of the ecosystems?

github-actions[bot] commented 1 week ago

👋 This pull request has been marked as stale because it has been open with no activity. You can: comment on the issue or remove the stale label to hold stale off for a while, add the Keep label to hold stale off permanently, or do nothing. If you do nothing this pull request will be closed eventually by the stale bot. Please see CONTRIBUTING.md for more policy details.