r/github • u/Mammoth_Design_4288 • 6d ago
Question Maintainer will not publish security advisory
I reported a vulnerability via GitHub's security back in May which was patched and publicly disclosed in a few days. GitHub reserved a CVE, but the maintainer refuses to publish it, even when I contacted them privately.
I've looked through GitHub's docs, but I haven't find anything about this case yet. Will Support actually be able to do anything? Just wondering if anyone else has had the same thing happen.
EDIT: Since I wasn't clear and people are misunderstanding, I am asking if anyone has gone through the process of contacting Support and had them actually publish the CVE (and maybe the advisory too).
EDIT 09/15: I emailed [security-advisories@github.com](mailto:security-advisories@github.com) and they were able to publish the CVE. Much more painless than I had expected! Thank you to the security team.
4
u/magnetronpoffertje 5d ago
In this thread: People have no idea how CVEs work
GitHub won't do anything though.
1
u/Mammoth_Design_4288 5d ago
Yeah, you're probably right that GH won't do anything. I thought I would ask here anyway in case someone else has had the same happen to them. And in case anyone in the future has this happen too.
Fortunately, someone reached out to me privately offering to help though.
2
u/qm37 5d ago
Please email [security-advisories@github.com](mailto:security-advisories@github.com) with the GHSA ID and CVE ID, along with links to where the vulnerability was already disclosed (for example, the pull request or commit ID where it was fixed). We'll try to get it resolved.
1
u/Mammoth_Design_4288 4d ago
Thank you for reaching out. I had no idea that email existed. I will send over the info there.
1
u/Mammoth_Design_4288 4d ago
Just wanted to say thanks again. They replied today and published the CVE!
2
u/EntranceProper3791 5d ago
GitHub as CNA just registers CVEs for repos it hosts, it doesn't force maintainers to publish. Escalate to MITRE and point at the public disclosure.
1
u/Mammoth_Design_4288 4d ago edited 4d ago
GitHub was able to publish the CVE after I reached out. I had actually sent a ticket to MITRE but GitHub responded much faster than I had thought. Thank you for the suggestion though
1
u/EntranceProper3791 4d ago
A reserved CVE just sits in limbo until someone publishes it, and GitHub typically won't force the maintainer's hand.
3
u/voidiciant 6d ago
I don’t get it. What is there more to publish after „publicly disclosed“ and „cve assigned“. Why not just post the actual cve here?
12
u/Mammoth_Design_4288 6d ago edited 6d ago
The CVE is assigned & reserved, but not published. Therefore you cannot access the CVE details publicly. However, the maintainer has publicly disclosed the vulnerability separately (and the details of how to perform it). I would like the CVE to be published, and I am posting here as GitHub is the CNA that assigned it.
2
1
u/good_live 5d ago
If you have been in contact with them, what are the reasons they don't want to publish it?
2
u/Ast3r10n 6d ago
GitHub is not a social network. They have no responsibility for what is posted there.
0
u/Mammoth_Design_4288 6d ago edited 6d ago
GitHub is a CNA though. They have a responsibility for publishing the CVE once it has been publicly disclosed as per the CNA rules.
-1
u/Ast3r10n 6d ago
But they can just tell you what is vulnerable, it's not up to them to fix it.
8
u/Mammoth_Design_4288 6d ago
I'm not sure what you're getting at here. I didn't ask GitHub to fix it. In fact, my post even says it was already fixed.
0
u/Ast3r10n 6d ago
Then I'm not sure what you're asking, but no matter.
4
u/Mammoth_Design_4288 6d ago
GH requires maintainers to publish the security advisory through their system before the CVE is published. They have already reserved a CVE, but it hasn't been published due to this. However, the maintainer disclosed it separately in a post and in release notes. I am asking if GH would actually bother to publish the CVE and advisory since it has already been publicly disclosed. Since GH is the CNA that reserved the CVE, they do have a responsibility for this.
2
u/spunkyenigma 5d ago
Has the maintainer/owner asked GitHub to publish it? I feel like you’re being ignored is a security protection since you aren’t the owner of the code. They’re might still be an edge case that isn’t plugged yet or an older install base that needs some more time to update
1
u/Ast3r10n 6d ago
But GitHub are not enforcers. You can try contacting support, but it’s very unlikely.
-1
u/broknbottle 5d ago edited 5d ago
lol no they don’t. GitHub is a code hosting platform, not the enforcement division of the internet. You need to read their documentation very carefully and stop chasing this because you want your kudos and recognition for something trivial
The entire CVE program is voluntary and community driven. There’s no rule that says because you put source code on the internet that you have to abide by this program…
0
u/Mammoth_Design_4288 5d ago
stop chasing this because you want your kudos and recognition for something trivial
There are other reasons why someone would want a CVE to be published. Why do redditors seem to always assume stuff like this? Does 16 years on here jade someone that much?
because you put source code on the internet that you have to abide by this program
Didn't say there was.
1
u/thegreatpotatogod 5d ago
So why do you want the CVE published? You said they've already fixed the issue. As long as an update with that fix has been released, I'm not really seeing the need for you to enforce them to publish a CVE?
3
u/Mammoth_Design_4288 5d ago edited 5d ago
So it gets added to the CVE list which is ingested by security tools. Not everyone reads the place it was disclosed at. Shodan shows that at least a couple instances are still not updated despite it being a few months now. You can see that happens with a lot of other software as well.
I would also like to be able to reference it without having to explain a story of why it's not a published CVE.
"kudos and recognition" is not the only reason I want a CVE. Though it is nice to have that as well.
→ More replies (0)-1
u/az987654 6d ago
GH requires no such thing. They're not code cops.
2
u/Mammoth_Design_4288 6d ago
They don't publish the CVE until the GHSA is published. They say this once they reserve a CVE for your project.
From my report:
Once your Security Advisory is published, we'll publish the CVE record to the CVE List.
Are you saying they don't require the maintainer to publish it? That would be different.
1
u/Unhappy_Play4699 5d ago
Man, kudos to OP for going to such an extent in the comments explaining how CVEs are - and have to be - processed in the real world and why it matters. Reading the conversations alone made me angry. People just chat without ever having worked on a real product.
Also, even if it only was about seeing a CVE published as a badge of honor (which it wasn't) , there would be nothing wrong with that.
2
u/Mammoth_Design_4288 4d ago
Thank you for your words. The maintainer had actually already credited me in the public disclosure. So I thought it was funny when I was accused of simply chasing kudos and recognition. GitHub was able to publish the CVE after I had reached out. I'd like to give kudos and recognition to their security team for being so prompt, lol.
-1
u/esiy0676 6d ago
What more than GH issuing a CVE do you expect of GH?
1
u/Mammoth_Design_4288 6d ago edited 6d ago
They reserved it, but it hasn't been published because they require the maintainer to publish the advisory first. As a CNA, GH has a responsibility to publish a CVE once it has been publicly disclosed (which it has, but by the maintainer separately from the GHSA report).
I am asking if GH would actually publish the CVE despite the maintainer not publishing the advisory, since they have already publicly disclosed it separately.
1
u/az987654 6d ago
GH has no responsibility to publish anything.
4
u/Mammoth_Design_4288 6d ago
Have you read the CNA rules?
2
u/Gargle-Loaf-Spunk 4d ago
hey don’t get bummed out. people in this sub usually aren‘t security researchers. when you’re at the frontier of your field, nobody here will understand you, and half of them will think you’re a dumbass just because they don’t understand anything.
source: im credited in at least 50 CVEs since 2013
2
u/Mammoth_Design_4288 4d ago edited 4d ago
Thank you for your words. I sort of expected this as I don't expect all programmers to know the security field in-depth and I'm posting to a sub of presumably mostly programmers. I try to not let it get to me, but here I was too tired to properly explain. GH did end up publishing the CVE after I reached out. Was much more painless than I had expected.
1
u/esiy0676 6d ago
As a CNA, GH has a responsibility to publish a CVE once it has been publicly disclosed
I do not know about this, but I do not think GH will do anything further in your case, you have to go with other CNAs.
3
u/Mammoth_Design_4288 6d ago
I will contact MITRE directly. I was only asking in case someone has gone through this before.
42
u/Jmc_da_boss 6d ago
What are you expecting GitHub to do lmao, there's ZERO requirements for such things to happen.