Skip to content

CVE Update Request: CVE-2024-46528 #128

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
smartcat999 opened this issue Oct 22, 2024 · 1 comment
Closed

CVE Update Request: CVE-2024-46528 #128

smartcat999 opened this issue Oct 22, 2024 · 1 comment
Assignees
Labels
bug This issue or pull request addresses broken functionality cvss Issues around CVSS scores references

Comments

@smartcat999
Copy link

Dear CISA Team,

I am writing to request an update for CVE-2024-46528 in the National Vulnerability Database.

  1. CVE ID: CVE-2024-46528

  2. Requested Changes:

    a. Confidentiality Impact:

    • Current: High
    • Requested Change: Low

    b. Hyperlink Update:

    c. Additional Reference:

  3. Justification for Changes:
    The Confidentiality Impact has been reassessed and determined to be Low based on further analysis of the vulnerability's scope and potential effects. The hyperlink update is to reflect the current official website of KubeSphere. The additional reference provides more detailed information about the vulnerability and its mitigation.

  4. Additional Information:

    • Affected Versions:
      KubeSphere 4.x: < 4.1.3
      KubeSphere 3.x: >= 3.0.0, <= 3.4.1
      KubeSphere Enterprise 4.x: < 4.1.3
      KubeSphere Enterprise 3.x: >= 3.0.0, <= 3.5.0
    • The CVSS vector string should be updated to reflect the change in Confidentiality Impact.
@jwoytek-cisa jwoytek-cisa added bug This issue or pull request addresses broken functionality cvss Issues around CVSS scores labels Oct 23, 2024
@jwoytek-cisa jwoytek-cisa self-assigned this Oct 23, 2024
@jwoytek-cisa
Copy link
Collaborator

Hello @smartcat999 and thank you for the updates. It looks like our Vulnrichment data has been updated as requested. However, your request asked for updates to the National Vulnerability Database (NVD). You will need to contact NVD to request any changes to the data that the provide. We can only update CISA Vulnrichment here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug This issue or pull request addresses broken functionality cvss Issues around CVSS scores references
Projects
None yet
Development

No branches or pull requests

2 participants