CVE-2024-52308 - Fleet not detecting GitHub / gh CLI CVE #24009
Labels
bug
Something isn't working as documented
customer-stazzema
#g-endpoint-ops
Endpoint ops product group
:incoming
New issue in triage process.
:release
Ready to write code. Scheduled in a release. See "Making changes" in handbook.
~released bug
This bug was found in a stable release.
Fleet version:
Fleet 4.58.0 • Go go1.23.1
Web browser and operating system:
N/A
💥 Actual behavior
CVE-2024-52308 - GHSA-p2h2-3vg9-4p87
THis CVE affects the Github CLI - the binary name is
gh
FleetDM seems not able to detect it probably because the CPE
cpe:2.3:a:github:cli:*:*:*:*:*:*:*:*,
calls the appcli
and notgh
?Github calls it
gh
in their documentation.🧑💻 Steps to reproduce
Look for CVE-2024-52308 in Fleet vulnerability data.
N/A
The text was updated successfully, but these errors were encountered: