Published Security Advisory for Serendipity Stuck Without CVE Assignment (since 4 Days) #203347
Unanswered
DevVaibhav07
asked this question in
Code Security
Replies: 1 comment
|
Hi Team, can someone please look into this? |
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
🏷️ Discussion Type
Question
💬 Feature/Topic Area
Other
Discussion Details
Hi GitHub Security Team,I am experiencing the manual curation queue backlog detailed in the official blog post (Inside the Advisory Database and what happens when vulnerability volume breaks records).An advisory for the Serendipity Weblog Engine (v2.6.1) was recently published. Because the ecosystem tag was incorrectly set to "Other" instead of "Composer", it bypassed the automated registry validation and is now stuck in the manual verification queue.Since the advisory is already published and live, the metadata is locked and cannot be retroactively modified to trigger the automated Composer pipeline.Could a human curator please review this published advisory and manually assign/link the CVE identifier?Link to Published Advisory: GHSA-v645-243f-jwgh
All reactions