[GHSA-c9ff-59g8-m36q] Add finder credit and affected Maven ranges (CVE-2026-84218) - #9645
Conversation
|
Thanks! Aside from the credit, would the curation team be able to consider this advisory for review (i.e., upgrade it from the NVD mirror entry to a reviewed advisory)? It affects a system/distro package (jolokia), so I understand ecosystem version-range mapping may be limited, but happy to help with any additional information (affected versions, fixed versions, references) that makes the review possible. |
73547de to
cdfef13
Compare
|
Context for the added Fix commit: 6ef036d78c3b40602f5e32352e97aed7c0fd5241 — "[Fixes #1049] Deny all target JMX URLs by default if not allowed ... Resolves CVE-2026-84218" — shipped in v2.6.2 (2026-09-02; compare v2.6.2...6ef036d confirms the commit is contained in the tag). 2.x range: 1.x range: Happy to adjust if the curation team prefers a different range treatment. |
Adds a
creditsentry crediting Sandipan Roy (@ByteHackr) asFINDERfor this advisory, and adds the CVE record JSON as a supporting WEB reference.Public evidence supporting this credit:
creatorfield: "Sandipan Roy", accountsaroy)The
creditsstructure follows the OSV schema and the convention already used in this repository (e.g. merged PR #7190 and open PR #9446).Per CONTRIBUTING.md this PR touches exactly one advisory.