Published Security Advisory for Serendipity Stuck Without CVE Assignment (since 4 Days new) #203348
Replies: 2 comments 1 reply
|
Hi Team, can someone please look into this? |
|
Hi @DevVaibhav07, This community is managed by GitHub employees, but it is not a support forum. The only place to go for answers to account-specific questions like this one is opening a ticket on our Support page. This is a public forum, and the community is unable to assist with nor escalate your ticket, but we can assure you it is in the right place. There are an extremely high volume of Support tickets right now, yours will be answered in the order it was received based on the amount of tickets ahead of yours. Please open only one ticket per request. As no other Community Discussions team members will be able to provide additional help with account related questions I am going to close this discussion. We appreciate your understanding and patience while Support works through your request! |
Uh oh!
There was an error while loading. Please reload this page.
🏷️ Discussion Type
Question
💬 Feature/Topic Area
Other
Discussion Details
Hi GitHub Security Team,I am experiencing the manual curation queue backlog detailed in the official blog post (Inside the Advisory Database and what happens when vulnerability volume breaks records).An advisory for the Serendipity Weblog Engine (v2.6.1) was recently published. Because the ecosystem tag was incorrectly set to "Other" instead of "Composer", it bypassed the automated registry validation and is now stuck in the manual verification queue.Since the advisory is already published and live, the metadata is locked and cannot be retroactively modified to trigger the automated Composer pipeline.Could a human curator please review this published advisory and manually assign/link the CVE identifier?Link to Published Advisory: GHSA-v645-243f-jwgh and GHSA-77rw-27c5-4hxm
All reactions