Dev rejects CVE severity, makes his GitHub repo read-only

Fedor Indutny, due to a CVE report filed against his project, started getting hounded by people on the internet bringing the vulnerability to his attention.
In recent times, open-source developers have been met with an uptick in receiving debatable or, in some cases, outright bogus CVE reports filed for their projects without confirmation.
This can lead to unwarranted panic among the users of these projects and alerts being generated by security scanners, all of which turn into a source of headache for developers.
The 'node-ip' project exists on the npmjs.com registry as the 'ip' package which scores 17 million downloads weekly, making it one of the most popular IP address parsing utilities in use by JavaScript developers.
It has to do with CVE-2023-42282, a vulnerability disclosed in the project earlier this year.
The CVE has to do with the utility not correctly identifying private IP addresses supplied to it in a non-standard format, such as hexadecimal.
Although Indutny did indeed fix the issue in later versions of his project, he disputed that the bug constituted an actual vulnerability and that too of an elevated severity.
Disputing a CVE is no straightforward task either, as a GitHub security team member explained.
It requires a project maintainer to chase the CVE Numbering Authorities that had originally issued the CVE. CNAs have conventionally comprised NIST's NVD and MITRE. Over the past few years, technology companies and security vendors joined the list and are also able to issue CVEs at will.
These CVEs, along with the vulnerability description and the reported severity rating, are then syndicated and republished by other security databases, such as GitHub advisories.
Following Indutny's post on social media, GitHub lowered the severity of the CVE in their database and suggested the developer turn on private vulnerability reporting to better manage incoming reports and cut noise.
The CVE system, originally designed to help security researchers ethically report vulnerabilities in a project and catalog these after responsible disclosure, has lately attracted a segment of community members filing unverified reports.
Developers and project maintainers have pushed back.
Another npm project, micromatch which gets 64 million weekly downloads has had 'high' severity ReDoS vulnerabilities reported against it with its creators being chased by community members inquiring about the issues.
As opposed to representing an exploitable vulnerability, it ended up being a nuisance report that developers had already been chased about.
Other than just being an annoyance for project maintainers, the act of getting CVEs issued for unverified vulnerability reports is akin to stirring up a Denial of Service against a project, its creators, and its wider consumer base, and for good reasons.
A third problem arises for projects without an active maintainer.
Abandoned software projects that have not been touched in years contain vulnerabilities that, even when disclosed, will never be fixed and there exists no means to contact their original maintainer.
On receiving a vulnerability report from a researcher, these organizations may not always be able to sufficiently vet every such report independently.
CISA: Most critical open source projects not using memory safe code.


This Cyber News was published on www.bleepingcomputer.com. Publication date: Sun, 30 Jun 2024 14:35:28 +0000


Cyber News related to Dev rejects CVE severity, makes his GitHub repo read-only

Dev rejects CVE severity, makes his GitHub repo read-only - Fedor Indutny, due to a CVE report filed against his project, started getting hounded by people on the internet bringing the vulnerability to his attention. In recent times, open-source developers have been met with an uptick in receiving debatable ...
4 days ago Bleepingcomputer.com
Dev rejects CVE severity, makes his GitHub repo read-only - Fedor Indutny, due to a CVE report filed against his project, started getting hounded by people on the internet bringing the vulnerability to his attention. In recent times, open-source developers have been met with an uptick in receiving debatable ...
4 days ago Bleepingcomputer.com
Dev rejects CVE severity, makes his GitHub repo read-only - Fedor Indutny, due to a CVE report filed against his project, started getting hounded by people on the internet bringing the vulnerability to his attention. In recent times, open-source developers have been met with an uptick in receiving debatable ...
2 days ago Bleepingcomputer.com
WikiLeaks Founder Julian Assange Returns to Australia a Free Man After US Legal Battle Ends - WikiLeaks founder Julian Assange returned to his homeland Australia aboard a charter jet and raised a celebratory clenched fist as his supporters cheered on Wednesday, hours after pleading guilty to obtaining and publishing U.S. military secrets in a ...
1 week ago Securityweek.com
CVE-2023-52578 - In the Linux kernel, the following vulnerability has been resolved: ...
4 months ago
Securing the code: navigating code and GitHub secrets scanning - Enter the world of GitHub secrets scanning tools, the vigilant sentinels of your digital gala. Secrets scanning in GitHub is anchored by two fundamental strategies: proactive prevention and reactive detection, each serving a critical function in ...
6 months ago Securityboulevard.com
E-Crime Rapper 'Punchmade Dev' Debuts Card Shop - The rapper and social media personality Punchmade Dev is perhaps best known for his flashy videos singing the praises of a cybercrime lifestyle. There wasn't much to support a conclusion that Punchmade was actually doing the cybercrime things he ...
5 months ago Krebsonsecurity.com
GitHub, PyTorch and More Organizations Found Vulnerable to Self-Hosted Runner Attacks - Last July, we published an article exploring the dangers of vulnerable self-hosted runners and how they can lead to severe software supply chain attacks. GitHub itself was found vulnerable, as well as various notable organizations, such as PyTorch, ...
5 months ago Securityboulevard.com
CVE-2023-52784 - In the Linux kernel, the following vulnerability has been resolved: bonding: stop the device in bond_setup_by_slave() Commit 9eed321cde22 ("net: lapbether: only support ethernet devices") has been able to keep syzbot away from net/lapb, until today. ...
1 month ago Tenable.com
An Obsession With Impact: The Inspiring Journey of a Dreamer That Led to a Career at Microsoft - Bruce's early years were far from easy. At the tender age of 11, Bruce's mother brought home a discarded computer from his workplace. Like any child of the '90s, having a computer in his room made Bruce feel like he had struck gold. Bruce has ...
4 months ago Msrc.microsoft.com
CVE-2021-47268 - In the Linux kernel, the following vulnerability has been resolved: ...
1 month ago
Meet the Cybersecurity Defender of 2023 for the Asia Pacific Region - Securing data in today's information-saturated, hyperconnected world is not for the faint of heart. It takes savvy leadership and security ambassadors with a vision to lead the charge into a more secure digital future. Here at Cisco, we build a ...
6 months ago Feedpress.me
GitHub code-signing certificates stolen - Another day, another access-token-based database breach. This time, the victim is Microsoft's GitHub business. On December 6, 2022, repositories from our atom, desktop, and other deprecated GitHub-owned organizations were cloned by a compromised ...
1 year ago Nakedsecurity.sophos.com
Ex-Ubiquiti Programmer Admits to Attempting to Blackmail Company - Nickolas Sharp, a former employee of Ubiquiti, a networking device maker, pleaded guilty today to stealing a large amount of data from the company's network and attempting to extort them while pretending to be an anonymous hacker and whistleblower. ...
1 year ago Bleepingcomputer.com
Blockchain dev's wallet emptied in "job interview" using npm package - The recruiter in question asked the developer to download npm packages from a GitHub repository, and hours later the developer discovered his MetaMask wallet had been emptied. Take-home job exercise empties dev's crypto wallet. Moments later, the ...
6 months ago Bleepingcomputer.com
BreachForums admin jailed for flouting pretrial rules The Register - The cybercriminal behind BreachForums was this week arrested for violating the terms of his pretrial release and will now be held in custody until his sentencing hearing. He was granted pretrial release on a $300,000 bond under a number of ...
5 months ago Go.theregister.com
BreachForums admin jailed for flouting pretrial rules The Register - The cybercriminal behind BreachForums was this week arrested for violating the terms of his pretrial release and will now be held in custody until his sentencing hearing. He was granted pretrial release on a $300,000 bond under a number of ...
5 months ago Theregister.com
CVE-2024-27916 - Minder is a software supply chain security platform. Prior to version 0.0.33, a Minder user can use the endpoints `GetRepositoryByName`, `DeleteRepositoryByName`, and `GetArtifactByName` to access any repository in the database, irrespective of who ...
3 months ago
CVE-2021-32638 - Github's CodeQL action is provided to run CodeQL-based code scanning on non-GitHub CI/CD systems and requires a GitHub access token to connect to a GitHub repository. The runner and its documentation previously suggested passing the GitHub token ...
2 years ago
CVE-2021-47103 - In the Linux kernel, the following vulnerability has been resolved: ...
4 months ago
CVE-2022-24731 - Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. Argo CD starting with version 1.5.0 but before versions 2.1.11, 2.2.6, and 2.3.0 is vulnerable to a path traversal vulnerability, allowing a malicious user with read/write ...
2 years ago
CVE-2024-27093 - Minder is a Software Supply Chain Security Platform. In version 0.0.31 and earlier, it is possible for an attacker to register a repository with a invalid or differing upstream ID, which causes Minder to report the repository as registered, but not ...
4 months ago
CVE-2023-30853 - Gradle Build Action allows users to execute a Gradle Build in their GitHub Actions workflow. A vulnerability impacts GitHub workflows using the Gradle Build Action prior to version 2.4.2 that have executed the Gradle Build Tool with the configuration ...
1 year ago
Cloud engineer wreaks havoc on bank's network after firing The Register - An ex-First Republic Bank cloud engineer was sentenced to two years in prison for causing more than $220,000 in damage to his former employer's computer network after allegedly using his company-issued laptop to watch pornography. Miklos Daniel ...
6 months ago Go.theregister.com
Cloud engineer wreaks havoc on bank's network after firing The Register - An ex-First Republic Bank cloud engineer was sentenced to two years in prison for causing more than $220,000 in damage to his former employer's computer network after allegedly using his company-issued laptop to watch pornography. Miklos Daniel ...
6 months ago Theregister.com

Latest Cyber News


Cyber Trends (last 7 days)


Trending Cyber News (last 7 days)