Skip to content

[GHSA-jm43-hrq7-r7w6] Privilege escalation through link refactoring#7290

Closed
manuelleduc wants to merge 3 commits intogithub:manuelleduc/advisory-improvement-7290from
manuelleduc:manuelleduc-GHSA-jm43-hrq7-r7w6
Closed

[GHSA-jm43-hrq7-r7w6] Privilege escalation through link refactoring#7290
manuelleduc wants to merge 3 commits intogithub:manuelleduc/advisory-improvement-7290from
manuelleduc:manuelleduc-GHSA-jm43-hrq7-r7w6

Conversation

@manuelleduc
Copy link
Copy Markdown

I updated the "affected versions" of GHSA-jm43-hrq7-r7w6 to be more accurate and the affected versions (we noticed false positive).

@github-actions github-actions bot changed the base branch from main to manuelleduc/advisory-improvement-7290 April 3, 2026 12:10
@manuelleduc manuelleduc changed the title Improve GHSA-jm43-hrq7-r7w6 [GHSA-jm43-hrq7-r7w6] Privilege escalation through link refactoring Apr 9, 2026
@shelbyc
Copy link
Copy Markdown
Contributor

shelbyc commented Apr 13, 2026

Hi @manuelleduc and @surli, I can't add 8.0-milestone-1 as a fixed version because https://github.com/xwiki/xwiki-platform/releases/tag/xwiki-platform-8.0-milestone-1 indicates that 8.0-milestone-1 predates the existence of a patch, Listing the VVR as >= 7.4.5, < 8.0-milestone-1 as the VVR and 16.4.7 as the patched version is enough to keep false positive alerts from appearing.

@shelbyc shelbyc closed this Apr 13, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants