-
Notifications
You must be signed in to change notification settings - Fork 1.1k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Backport CVE-2024-43368 to trix v1 and update advisory #1184
Comments
trix 1.3.3 and 1.3.4 are released, and 1.3.3 seems to be backported the fix of CVE-2024-43368. |
Thanks for the heads-up, It appears that GHSA-qm2q-9f3q-2vcv needs an update to consider trix >= 1.3.3 safe, just like it happened with the previous CVE reported
|
tagliala
changed the title
Backport CVE-2024-43368 to trix v1
Backport CVE-2024-43368 to trix v1 and update advisory
Dec 10, 2024
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Hello,
is there by any chance the possibility to backport the fix for CVE-2024-43368 to v1 and release a new version?
Follow up:
The text was updated successfully, but these errors were encountered: