fix: incorrect service version on CVE-2024-5314 and CVE-2024-5315 #16
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
For the two tasks CVE-2024-5314 and CVE-2024-5315, the CVE is for version 9.0.1, while the version deployed is version 8.0.4. This is several years older than the version the CVE was found in, so while the vulnerabilities still exist in this version there are likely other vulnerabilities in the older version that could potentially make a benchmark inaccurate in finding this specific vulnerability. This PR fixes this to change the version to the version listed in the CVE description.