Skip to content

Conversation

jerichosy
Copy link

@jerichosy jerichosy commented Sep 30, 2025

Updates

  • Affected products
  • CVSS v3

Comments
Version 1.175.0 of grpc-netty-shaded doesn't exist? I think it's a typo meant to be 1.75.0 (the current latest) instead. This matches the referenced commit grpc/grpc-java@6462ef9 on Aug 18 which was shortly before the release of grpc-netty-shaded 1.75.0 on Aug 21, as previously confirmed in a previous PR comment: #6220 (comment)

Would glad to have this fixed urgently as it is blocking MR pipelines at my company.

@Copilot Copilot AI review requested due to automatic review settings September 30, 2025 11:33
@github
Copy link
Collaborator

github commented Sep 30, 2025

Hi there @normanmaurer! A community member has suggested an improvement to your security advisory. If approved, this change will affect the global advisory listed at github.com/advisories. It will not affect the version listed in your project repository.

This change will be reviewed by our Security Curation Team. If you have thoughts or feedback, please share them in a comment here! If this PR has already been closed, you can start a new community contribution for this advisory

Copy link

@Copilot Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR corrects a version number typo in a security advisory for the MadeYouReset HTTP/2 DDoS vulnerability affecting Netty. The fix changes an incorrect version number and removes a CVSS v3 score while keeping the CVSS v4 score.

  • Fixed incorrect version number from 1.175.0 to 1.75.0 for grpc-netty-shaded
  • Removed CVSS v3 score section
  • Updated modification timestamp

Tip: Customize your code reviews with copilot-instructions.md. Create the file or learn how to get started.

@github-actions github-actions bot changed the base branch from main to jerichosy/advisory-improvement-6231 September 30, 2025 11:34
@jerichosy
Copy link
Author

jerichosy commented Sep 30, 2025

As suggested in another PR, tagging @ejona86 to help confirm and help remedy this typo.

@ejona86
Copy link

ejona86 commented Sep 30, 2025

I commented on #6228 about 1.75.0 being appropriate, which seems to be the first of everyone making their own PR for the same thing. It isn't at all clear to me how this repo works, and it seems that's the case for everyone else as well. #6220 seems to be when grpc-netty-shaded was introduced, since it doesn't seem Norman did it, yet that had the correct version number.

@shelbyc
Copy link
Contributor

shelbyc commented Sep 30, 2025

Closed as a duplicate of #6228

@shelbyc shelbyc closed this Sep 30, 2025
@github-actions github-actions bot deleted the jerichosy-GHSA-prj3-ccx8-p6x4 branch September 30, 2025 15:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants