openresty / luajit2

OpenResty's Branch of LuaJIT 2
https://luajit.org/luajit.html
Other
1.2k stars 193 forks source link

Vulnerability scan detects many CVE vulnerabilities #150

Open ganl opened 2 years ago

ganl commented 2 years ago

13a5085214c2050331271d7ffbedc76

zhuizhuhaomeng commented 2 years ago

thank you for your report. Can you please tell us how to check if all the CVE has been fixed?

ganl commented 2 years ago

The vulnerability is scanned by the binary inspection tool, the affected component is lua 5.1, but this issue says that luajit is not affected.

image

Same CVE: https://nvd.nist.gov/vuln/detail/CVE-2020-15888 https://nvd.nist.gov/vuln/detail/CVE-2020-15945