Skip to content

Conversation

pitrou
Copy link

@pitrou pitrou commented Nov 9, 2023

Updates

  • Affected products
  • Severity
  • Source code location
  • Summary

Comments
I'm part of the Project Management Committee (PMC) for Apache Arrow and I coordinated the response to the vulnerability report.

}
],
"database_specific": {
"last_known_affected_version_range": "< 14.0.0"
Copy link
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Seems like I made a mistake here.

Suggested change
"last_known_affected_version_range": "< 14.0.0"
"last_known_affected_version_range": "< 14.0.1"

@github-actions github-actions bot changed the base branch from main to pitrou/advisory-improvement-2922 November 9, 2023 10:10
@pitrou
Copy link
Author

pitrou commented Nov 9, 2023

Also, how do we get the advisory to be published in https://github.com/apache/arrow/security/advisories ?

(note that Apache projects are bit special: only the Apache Software Foundation's infrastructure team has admin access to GitHub repositories, project maintainers don't)

@shelbyc
Copy link
Contributor

shelbyc commented Nov 9, 2023

Also, how do we get the advisory to be published in https://github.com/apache/arrow/security/advisories ?

(note that Apache projects are bit special: only the Apache Software Foundation's infrastructure team has admin access to GitHub repositories, project maintainers don't)

Hi @pitrou, thanks for reaching out about CVE-2023-47248! Documentation about how to publish a repository security advisory is available here: https://docs.github.com/en/code-security/security-advisories/working-with-repository-security-advisories/about-repository-security-advisories

I think a fix commit would be a good link to have in the references. Is this the fix for CVE-2023-47428? apache/arrow@f141709

@pitrou
Copy link
Author

pitrou commented Nov 9, 2023

Hi @pitrou, thanks for reaching out about CVE-2023-47248! Documentation about how to publish a repository security advisory is available here: https://docs.github.com/en/code-security/security-advisories/working-with-repository-security-advisories/about-repository-security-advisories

Ah! I was hoping that you would be able to automatically create a repository security advisory from this one?

I think a fix commit would be a good link to have in the references. Is this the fix for CVE-2023-47428? apache/arrow@f141709

Yes, it is.

@pitrou
Copy link
Author

pitrou commented Nov 9, 2023

I think a fix commit would be a good link to have in the references. Is this the fix for CVE-2023-47428? apache/arrow@f141709

Also, you could add a link to https://pypi.org/project/pyarrow-hotfix/ or https://github.com/pitrou/pyarrow-hotfix as a mitigation.

@advisory-database advisory-database bot merged commit e0dff8a into pitrou/advisory-improvement-2922 Nov 9, 2023
@advisory-database
Copy link
Contributor

Hi @pitrou! Thank you so much for contributing to the GitHub Advisory Database. This database is free, open, and accessible to all, and it's people like you who make it great. Thanks for choosing to help others. We hope you send in more contributions in the future!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants