From b38268599b526004f220af8b3bc2128d6039ef77 Mon Sep 17 00:00:00 2001 From: Shelby Cunningham Date: Fri, 30 Aug 2024 14:18:57 -0400 Subject: [PATCH] Replace CVE-2024-41661 with CVE-2023-50094 On 29 August 2024, MITRE informed GitHub that CVE-2024-41661, which was issued August 2024 is a duplicate of CVE-2023-50094, which was issued December 2023 or January 2024. We rejected CVE-2024-41661 as a duplicate CVE because CVE-2023-50094 was published first and suggest that the maintainers of reNgine replace all instances of CVE-2024-41661 with CVE-2023-50094, including in the changelog and repository security advisory. --- CHANGELOG.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index b24f1555..e0836811 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -8,7 +8,7 @@ ### Security Update -* (Security) CVE-2024-41661 Stored Cross-Site Scripting (XSS) via DNS Record Poisoning reported by @touhidshaikh Advisory https://github.com/yogeshojha/rengine/security/advisories/GHSA-96q4-fj2m-jqf7 +* (Security) CVE-2023-50094 Stored Cross-Site Scripting (XSS) via DNS Record Poisoning reported by @touhidshaikh Advisory https://github.com/yogeshojha/rengine/security/advisories/GHSA-96q4-fj2m-jqf7 ### Bug Fixes @@ -31,7 +31,7 @@ ## What's Changed ### Security update -* (Security) CVE-2024-41661 Fix Authenticated command injection in WAF detection tool reported by @n-thumann Advisory https://github.com/yogeshojha/rengine/security/advisories/GHSA-fx7f-f735-vgh4 +* (Security) CVE-2023-50094 Fix Authenticated command injection in WAF detection tool reported by @n-thumann Advisory https://github.com/yogeshojha/rengine/security/advisories/GHSA-fx7f-f735-vgh4 ### Bug Fixes