Skip to content

Conversation

@jlsec-bot
Copy link
Contributor

This action searched recent NVD/EUVD changes/publications, checking 639 (+0) advisories from NVD and 377 (+332) from EUVD for advisories that pertain here. It identified 3 advisories as being related to the Julia package(s): libnode_jll, OpenSSH_jll, and Soup3_jll.

1 advisories failed to parse the source version range

These advisories seem to apply to a Julia package but had trouble identifying exactly how and at which versions.

  • CVE-2023-51767 for packages: OpenSSH_jll
    • OpenSSH_jll computed ["*"]. Its latest version (10.2.1+0) has components: {openssh = "10.2p1"}
      • openbsd:openssh at `` failed to parse

2 advisories apply to all registered versions of a package

These advisories had no obvious failures but computed a range without bounds.

  • CVE-2024-3566 for packages: libnode_jll
    • libnode_jll computed ["*"]. Its latest version (18.12.1+0) has components: {node-v = "18.12.1", nodejs = "18.12.1"}
      • nodejs:node.js at <= 21.7.2 includes all versions
  • CVE-2025-2784 for packages: Soup3_jll
    • Soup3_jll computed ["*"]. Its latest version (3.2.1+0) has components: {libsoup = "3.2.1"}
      • gnome:libsoup at < 3.6.5 includes all versions

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants