Skip to content

Conversation

jlsec-bot
Copy link
Contributor

@jlsec-bot jlsec-bot commented Oct 21, 2025

This action searched --project=libssh2, checking 15 (+0) advisories from NVD and 9 (+0) from EUVD for advisories that pertain here. It identified 3 advisories as being related to the Julia package(s): LibSSH2_jll, and OpenSSH_jll.

3 advisories found concrete vulnerable ranges

  • CVE-2019-17498 for packages: LibSSH2_jll
    • LibSSH2_jll computed ["< 1.10.1+0"]. Its latest version (1.11.3+1) has components: {libssh2 = "1.11.1"}
  • CVE-2020-22218 for packages: LibSSH2_jll
    • LibSSH2_jll computed [">= 1.10.1+0, < 1.11.0+0"]. Its latest version (1.11.3+1) has components: {libssh2 = "1.11.1"}
  • CVE-2023-48795 for packages: LibSSH2_jll, and OpenSSH_jll
    • LibSSH2_jll computed ["< 1.11.3+0"]. Its latest version (1.11.3+1) has components: {libssh2 = "1.11.1"}
    • libssh_jll has no vulnerable versions; some versions contain vulnerable libssh:libssh. Its latest version (0.11.3+0) has components: {libssh = "0.11.3"}
    • OpenSSH_jll computed ["< 9.9.1+0"]. Its latest version (10.2.1+0) has components: {openssh = "10.2p1"}

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants