-
Notifications
You must be signed in to change notification settings - Fork 9
CVE-2020-36843 Vulnerability #7
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Comments
@bbottema can i get a fix for this vulnerability ? |
How is this library affected? What's the dependency chain? I haven't seen any sec scans that report this for this library (yet). |
We pull
Maven Link: net.i2p.crypto/eddsa/0.3.0 |
Oh I just saw this library directly depends on it. I'll have a look today, probably. |
Does this sound good ? |
It looks good to me. I want to test this change with a few down stream dependencies first, though. Thank you for the contribution! |
Thanks a lot for maintaining this project 👏 . Can you suggest me how to test ?
What can be a my next steps to get this PR merged and new version of i am a new to Open-source. 😅 |
Now you wait until I've reviewed and tested the change :) About the test. I fI remember correctly, the test fails under Windows machines, but works for Linux machines. I'm not entirely sure why that is, but it's been like that since before I took over the code base. |
Released in 3.2.1. Again, thank you for your help in this. |
Thanks a lot 🙏 Great Project 👏 Great Community as well !! |
This library is vulnerable to CVE-2020-36843. Can we have a patch for this vulnerability ?
The text was updated successfully, but these errors were encountered: