[GHSA-rp9m-7r4c-75qg] [CVE-2026-35039] - Request for CVSS correction or clarification
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 35/100
- Tipo di issue
- Bug
- Chiarezza
- Abbastanza chiara
- Stato di attività
- Tranquilla
- Ambito
- security
Direzione di ricerca
Esamina GHSA-rp9m-7r4c-75qg e CVE-2026-35039 insieme alle linee guida CVSS 3.1 collegate e al vettore proposto dal segnalatore. Verifica se il possesso di un JWT valido modifica il PR e se l'impatto dichiarato è giustificato; il lavoro è completato quando la decisione è documentata e i metadati dell'advisory vengono aggiornati, se opportuno.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Hi GitHub,
Our automated CVSS enrichment pipeline detected some discrepancies between GitHub's provided vector and ours. Since this also passed a GitHub review, I thought it would be helpful to share my insights here, so that the vector or its justification might be corrected. For reference, this was the output from our AI pipeline: https://graph.volerion.com/view?id=CVE-2026-35039.
For the current vector, PR:N was set, but exploitation requires an attacker to possess a valid JWT, which is an authentication artifact, and therefore constitutes at least a low privilege requirement.
Additionally, impact could have been downgraded to C:L/I:L due to the fact it may not be reasonable to believe that an attacker could obtain administrator-like control in most implementations involving this library. However, since that is also arguably the most subjective part of the CVSS specification, I won't press that point if you feel otherwise.
My suggestion would be to change PR:N to PR:L which comes down to a final vector of:
https://volerion.com/cvss/3.1#vector=CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Thanks!
- Lingua principale
- Nessun dato sulla lingua
- Stelle
- 2.5k
- Fork
- 772
- Merge medio
- 3g 15h
- PR unite (30g)
- 46
Guida per i contributori
Apri la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di github/advisory-database
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
github/advisory-database#9255 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
github/advisory-database#9164 · 1 reazione ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
github/advisory-database#8994 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
github/advisory-database#8898 · 4 commenti · 1 reazione ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
github/advisory-database#8841 ·
Tutte le issue di github/advisory-database
Issue simili
-
needs-triage
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
-
Nmap
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 85/100
-
Mend: dependency security vulnerability untriaged
Difficoltà 2/5 1-3 ore Idoneità per principianti 70/100
-
blocklist removal
Difficoltà 2/5 1-3 ore Idoneità per principianti 65/100
MetaMask/eth-phishing-detect#296544 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 70/100
Azure/azure-functions-docker#1257 ·