Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add CVE-2024-4990 #724

Merged
merged 4 commits into from
Jul 30, 2024
Merged
Changes from 2 commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 8 additions & 0 deletions yiisoft/yii2/CVE-2024-4990.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
title: Unsafe Reflection in base Component class
link: https://github.com/yiisoft/yii2/security/advisories/GHSA-cjcc-p67m-7qxm
cve: CVE-2024-4990
branches:
2.0.49.x:
time: null
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
time: null
time: 2024-05-30 17:23:00

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

If I understood the time field correctly, that should hold the timestamp of the commit which fixed it in that branch. So if it is not for that branch, then I would go with 2024-05-30 since that was the commit yiisoft/yii2@628d406 which fixed it in the 2.0.50 branch. If that field is understood as fixed in that branch I would rather use 2024-06-04 16:23:00 from yiisoft/yii2@62d081f since that was merged to branch 2.0.49.x.

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@DBX12 makes sense, can you apply that change then?

Copy link
Contributor Author

@DBX12 DBX12 Jul 29, 2024

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hi @naderman
can you clarify how the time field is to be understood? :)
Edit: I misread your comment, so you can disregard that question. Also, the related CVE got updated again so I've pushed an update.

versions: ['<=2.0.49']
DBX12 marked this conversation as resolved.
Show resolved Hide resolved
reference: composer://yiisoft/yii2
Loading