From d7a1c17cba45b80adb479801425fe06452b8b1a0 Mon Sep 17 00:00:00 2001 From: Chuan-kai Lin Date: Fri, 26 Jul 2024 09:02:49 -0700 Subject: [PATCH] Update file overwrite CVE reference --- CHANGELOG.md | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 9644937..e593e5d 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -19,10 +19,11 @@ ## Release 2.18.1 (2024-07-25) -# Security Updates +### Security Updates -- Fixes CVE-2024-41807, an arbitrary file overwrite that can be triggered when - using untrusted third-party queries from a git repository. See the +- Resolves CVE-2023-4759, an arbitrary file overwrite in Eclipse JGit + that can be triggered when using untrusted third-party queries from a + git repository. See the [security advisory](https://github.com/github/codeql-cli-binaries/security/advisories/GHSA-x4gx-f2xv-6wj9) for more information. - The following dependencies have been updated. These updates include