You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Our vulnerability scanner (Trivy) reports CVE-2024-47535 as aHIGH severity vulnerability. However when I look at GHSA-xq3w-v528-46rv it only says MODERATE.
This seems to be caused by the fact that CVSSv3 and CVSSv4 are declared (CVSSv4 seems to be used for severity calculation since it's newer) but CVSSv4 has a few unexpected values that result in conflicts:
Subsequent System Confidentiality is HIGH. This should likely be NONE as only a DoS occurs.
Subsequent System Integrity is also set to HIGH. This should also likely be NONE (see above)
Please either fix the CVSSv4 or describe why you did choose those values, like you did for CVSSv3.
The text was updated successfully, but these errors were encountered:
Our vulnerability scanner (Trivy) reports CVE-2024-47535 as a
HIGH
severity vulnerability. However when I look at GHSA-xq3w-v528-46rv it only saysMODERATE
.This seems to be caused by the fact that CVSSv3 and CVSSv4 are declared (CVSSv4 seems to be used for
severity
calculation since it's newer) but CVSSv4 has a few unexpected values that result in conflicts:Subsequent System Confidentiality
isHIGH
. This should likely beNONE
as only a DoS occurs.Subsequent System Integrity
is also set toHIGH
. This should also likely beNONE
(see above)Please either fix the CVSSv4 or describe why you did choose those values, like you did for CVSSv3.
The text was updated successfully, but these errors were encountered: