Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

[GHSA-x9r9-48rm-4xm6] FitNesse allows execution of arbitrary OS commands #4816

Open
wants to merge 1 commit into
base: tcnh/advisory-improvement-4816
Choose a base branch
from

Conversation

tcnh
Copy link

@tcnh tcnh commented Sep 17, 2024

Updates

  • Affected products
  • CVSS v3
  • Description

Comments
FitNesse is an acceptance test automation framework, designed to execute fixture code on a host or network system. This CVE does not describe a vulnerability, but FitNesse's core functionality.

@github-actions github-actions bot changed the base branch from main to tcnh/advisory-improvement-4816 September 17, 2024 11:18
@shelbyc
Copy link
Contributor

shelbyc commented Sep 17, 2024

Hi @tcnh, thank you for letting us know about the information in the CVE describing core functionality of FitNesse.

As a next step forward, I recommend contacting the CVE Numbering Authority (CNA) that issued CVE-2024-28125 to dispute the CVE. That CNA is JPCERT/CC. You can email them or use the contact page at https://www.jpcert.or.jp/vh/index.html to let them know that you want to dispute the CVE.

When you contact JPCERT/CC, link them to this thread so that they know there is a publicly available link where someone has disputed the validity of the CVE.

@tcnh
Copy link
Author

tcnh commented Sep 17, 2024

Thanks. Contacted JPCert on this topic by email.

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants