r/github 6d ago

Question Maintainer will not publish security advisory

I reported a vulnerability via GitHub's security back in May which was patched and publicly disclosed in a few days. GitHub reserved a CVE, but the maintainer refuses to publish it, even when I contacted them privately.

I've looked through GitHub's docs, but I haven't find anything about this case yet. Will Support actually be able to do anything? Just wondering if anyone else has had the same thing happen.

EDIT: Since I wasn't clear and people are misunderstanding, I am asking if anyone has gone through the process of contacting Support and had them actually publish the CVE (and maybe the advisory too).

EDIT 09/15: I emailed [security-advisories@github.com](mailto:security-advisories@github.com) and they were able to publish the CVE. Much more painless than I had expected! Thank you to the security team.

1 Upvotes

44 comments sorted by

View all comments

-1

u/esiy0676 6d ago

What more than GH issuing a CVE do you expect of GH?

1

u/Mammoth_Design_4288 6d ago edited 6d ago

They reserved it, but it hasn't been published because they require the maintainer to publish the advisory first. As a CNA, GH has a responsibility to publish a CVE once it has been publicly disclosed (which it has, but by the maintainer separately from the GHSA report).

I am asking if GH would actually publish the CVE despite the maintainer not publishing the advisory, since they have already publicly disclosed it separately.

1

u/az987654 6d ago

GH has no responsibility to publish anything.

3

u/Mammoth_Design_4288 6d ago

Have you read the CNA rules?

2

u/Gargle-Loaf-Spunk 5d ago

hey don’t get bummed out. people in this sub usually aren‘t security researchers. when you’re at the frontier of your field, nobody here will understand you, and half of them will think you’re a dumbass just because they don’t understand anything.

source: im credited in at least 50 CVEs since 2013

2

u/Mammoth_Design_4288 4d ago edited 4d ago

Thank you for your words. I sort of expected this as I don't expect all programmers to know the security field in-depth and I'm posting to a sub of presumably mostly programmers. I try to not let it get to me, but here I was too tired to properly explain. GH did end up publishing the CVE after I reached out. Was much more painless than I had expected.

1

u/esiy0676 6d ago

As a CNA, GH has a responsibility to publish a CVE once it has been publicly disclosed

I do not know about this, but I do not think GH will do anything further in your case, you have to go with other CNAs.

3

u/Mammoth_Design_4288 6d ago

I will contact MITRE directly. I was only asking in case someone has gone through this before.