Skip to content
This repository has been archived by the owner on Jan 19, 2023. It is now read-only.

Incorrect vulnerability details for sonatype-2022-4070 (does not apply to yaml.v2) #322

Closed
heyLu opened this issue Aug 19, 2022 · 5 comments
Labels
bug Something isn't working

Comments

@heyLu
Copy link

heyLu commented Aug 19, 2022

Vulnerability URL
Provide the URL to the vulnerability. For example:

https://ossindex.sonatype.org/vulnerability/sonatype-2022-4070?component-type=golang&component-name=gopkg.in%2Fyaml.v2

Component URL
Provide the URL to the component. For example:

https://ossindex.sonatype.org/component/pkg:golang/gopkg.in/yaml.v2

Description

This vulnerability does not apply to yaml.v2, only yaml.v3. This is visible both in the linked issue go-yaml/yaml#665 and the related on at go-yaml/yaml#666 (comment) where it is described that the vulnerability was misattributed to yaml.v2.

@heyLu heyLu added the bug Something isn't working label Aug 19, 2022
@heyLu heyLu changed the title Incorrect vulnerability details Incorrect vulnerability details for sonatype-2022-4070 (does not apply to yaml.v2) Aug 19, 2022
@ken-duck
Copy link
Contributor

This issue has been passed to the research team on our internal tracking system, and I will report back here once more is known.

@Lepidopteron
Copy link

Is there an update on this available?

@hallm4
Copy link

hallm4 commented Dec 20, 2022

It would be great if this could be fixed.

@ken-duck
Copy link
Contributor

Sorry for the delay. I am poking the team right now to see what is up.

@ken-duck
Copy link
Contributor

This should have be resolved since Christmas. Closing.

Thanks for the heads up on the issue.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

4 participants