[GHSA-632q-77qj-c89q] Improve advisory details: reference incomplete fix for CVE-2024-28709#6787
Conversation
|
CVE-2024-28709 and CVE-2024-28710 are not related. The affected completely different parts of the code and vectors. |
|
👋 This pull request has been marked as stale because it has been open with no activity. You can: comment on the issue or remove the stale label to hold stale off for a while, add the |
|
👋 This pull request has been marked as stale because it has been open with no activity. You can: comment on the issue or remove the stale label to hold stale off for a while, add the |
Proposed Change
Add cross-reference between CVE-2024-28709 and CVE-2024-28710 to document the incomplete fix relationship.
Evidence
htmlentities()to survey title/comment fieldshtmlentities()encoding to the Alert Widget message component