Skip to content

[GHSA-hpx4-xjp7-m4vr] snipe/snipe-it: fix landed in 5.4.4, not 5.4.3 - #9348

Open
zyl71 wants to merge 1 commit into
github:zyl71/advisory-improvement-9348from
zyl71:fix/GHSA-hpx4-xjp7-m4vr
Open

[GHSA-hpx4-xjp7-m4vr] snipe/snipe-it: fix landed in 5.4.4, not 5.4.3#9348
zyl71 wants to merge 1 commit into
github:zyl71/advisory-improvement-9348from
zyl71:fix/GHSA-hpx4-xjp7-m4vr

Conversation

@zyl71

@zyl71 zyl71 commented Sep 5, 2026

Copy link
Copy Markdown

Updates

  • Affected products

Comments
The record says versions before 5.4.3 are vulnerable and 5.4.3 is patched, but the referenced fix commit f623d05d0c3487ae24c4f13907e4709484e5bf41 ("Escape checkout target name", 2022-04-24) postdates the 5.4.3 release (tag v5.4.3 and the Packagist release are dated 2022-04-15) and is not contained in it: grokability/snipe-it@f623d05...v5.4.3 reports v5.4.3 as behind the commit. The first release that contains the fix is v5.4.4 (2022-05-04; grokability/snipe-it@f623d05...v5.4.4). The huntr report's "fixed in 5.4.3" appears to be a mistake. Suggested change: affected < 5.4.4, patched 5.4.4.

@github-actions
github-actions Bot changed the base branch from main to zyl71/advisory-improvement-9348 September 5, 2026 03:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant