Skip to content

Conversation

@joeyh
Copy link
Contributor

@joeyh joeyh commented Nov 13, 2025

Reporting a security hole I discovered in crypton-x509-store. x509-store has the same security hole, but is no longer being maintained.


Advisory

  • It's not duplicated
  • All fields are filled
  • It is validated by hsec-tools

hsec-tools

  • Previous advisories are still valid

Copy link
Collaborator

@TristanCacqueray TristanCacqueray left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, thanks!


[[affected]]
package = "cryptonite"
cvss = "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

CVSS version 4 is not yet supported, would you mind using version 3.1 instead?

Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

+1


[[affected]]
package = "cryptonite"
cvss = "CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N"
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

+1

@frasertweedale
Copy link
Collaborator

Thank you very much @joeyh. I'll take care of the needed updates and cleanups, and merge it tonight.

@frasertweedale
Copy link
Collaborator

Assigned HSEC-2025-0006. Minor editorial changes. Rebased and adapated to the new repo layout.

@joeyh I force pushed to your main branch to update the PR, sorry if it alarms you :)

@frasertweedale
Copy link
Collaborator

We need another fixup in the tools before we merge this: #303

@frasertweedale frasertweedale merged commit 0c30319 into haskell:main Nov 17, 2025
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants