Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2024-47535 / GHSA-xq3w-v528-46rv: Recheck CVSSv4 #14473

Open
AB-xdev opened this issue Nov 18, 2024 · 0 comments
Open

CVE-2024-47535 / GHSA-xq3w-v528-46rv: Recheck CVSSv4 #14473

AB-xdev opened this issue Nov 18, 2024 · 0 comments

Comments

@AB-xdev
Copy link

AB-xdev commented Nov 18, 2024

Our vulnerability scanner (Trivy) reports CVE-2024-47535 as a HIGH severity vulnerability. However when I look at GHSA-xq3w-v528-46rv it only says MODERATE.

This seems to be caused by the fact that CVSSv3 and CVSSv4 are declared (CVSSv4 seems to be used for severity calculation since it's newer) but CVSSv4 has a few unexpected values that result in conflicts:

  • Subsequent System Confidentiality is HIGH. This should likely be NONE as only a DoS occurs.
  • Subsequent System Integrity is also set to HIGH. This should also likely be NONE (see above)

Please either fix the CVSSv4 or describe why you did choose those values, like you did for CVSSv3.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant