April 28, 2024, 10:48 a.m. | /u/dkarlovi

cybersecurity www.reddit.com

Latest PHP still has obsolete/invalid CVEs from 2007 open: https://github.com/php/php-src/issues/14050

The maintainers claim "there's nothing that can be done" and it seems they're fine with these CVEs being open in perpetuity even though they're obsolete / invalid.

Is there really no way an obsolete/invalid CVE to be closed, what organization / person would the PHP foundation need to contact and what procedure to follow to get this closed? It seems quite unlikely there is just no way to do this …

can claim cve cves cybersecurity foundation maintainers nothing organization php procedure

Digital Security Infrastructure Manager

@ Wizz Air | Budapest, HU, H-1103

Sr. Solution Consultant

@ Highspot | Sydney

Cyber Security Analyst III

@ Love's Travel Stops | Oklahoma City, OK, US, 73120

Lead Security Engineer

@ JPMorgan Chase & Co. | Tampa, FL, United States

GTI Manager of Cybersecurity Operations

@ Grant Thornton | Tulsa, OK, United States

GCP Incident Response Engineer

@ Publicis Groupe | Dallas, Texas, United States