Skip to content

Correct affected range/fixed version for GHSA-xcvc-5hgv-phqg (CVE-2024-7041)#8777

Open
Classic298 wants to merge 1 commit into
github:Classic298/advisory-improvement-8777from
Classic298:fix-ghsa-xcvc-5hgv-phqg-range
Open

Correct affected range/fixed version for GHSA-xcvc-5hgv-phqg (CVE-2024-7041)#8777
Classic298 wants to merge 1 commit into
github:Classic298/advisory-improvement-8777from
Classic298:fix-ghsa-xcvc-5hgv-phqg-range

Conversation

@Classic298

Copy link
Copy Markdown

Corrects the affected range for GHSA-xcvc-5hgv-phqg (CVE-2024-7041).

The record currently ends the range at last_affected: 0.3.8, which understates the affected versions. The IDOR in /api/v1/memories/{id}/update (model method update_memory_by_id filtering by id only, no user_id) persisted well past v0.3.8. It was fixed in v0.6.3 by commit bdef1001a, which switched the route to update_memory_by_id_and_user_id (filter_by(id=id, user_id=user_id)). v0.6.2 is still vulnerable, so the affected range extends to 0.6.2 and the fix first ships in 0.6.3.

This PR replaces last_affected: 0.3.8 with fixed: 0.6.3 so the range covers every affected release and terminates at the first fixed release.

@github-actions
github-actions Bot changed the base branch from main to Classic298/advisory-improvement-8777 July 22, 2026 21:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant