[GHSA-8ffj-4hx4-9pgf] [CVE-2026-39413] - Request for CVSS correction or clarification
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 42/100
- Tipo di issue
- Bug
- Chiarezza
- Abbastanza chiara
- Stato di attività
- Tranquilla
- Ambito
- security
Direzione di ricerca
Inizia con l’avviso CVE-2026-39413 e confronta il suo vettore CVSS attuale con i dettagli dell’attacco riportati nell’issue e con il riferimento CVSS collegato. Verifica le affermazioni sulla falsificazione di JWT senza autenticazione e sull’impatto sugli amministratori; il lavoro è completato quando il vettore e la giustificazione dell’avviso sono corretti, oppure quando la valutazione esistente è documentata come accurata.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Hi GitHub,
Our automated CVSS enrichment pipeline detected some discrepancies between GitHub's provided vector and ours. Since this also passed a GitHub review, I thought it would be helpful to share my insights here, so that the vector or its justification might be corrected. For reference, this was the output from our AI pipeline: https://graph.volerion.com/view?id=CVE-2026-39413.
The current vector states AC:H, PR:H, UI:R, but an actual attack seems to involve only an unauthenticated attacker forging a valid JWT via a 'none' algorithm, therefore encountering none of those exploitation barriers.
Additionally, I would make the point that C:H/I:N/A:N is best changed to C:H/I:H/A:N to better reflect the potential administrator access an attacker might obtain after successful exploitation.
This comes down to a final vector of:
https://volerion.com/cvss/3.1#vector=CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
A pretty steep upgrade from a base score of 4.2 to 9.1.
I have hundreds more in the pipeline for 2026 alone, but unfortunately, I don't have the bandwidth to go through them all of them in this manner. Feel free to email me at karel@volerion.com and perhaps we can work out a more streamlined method of setting the records straight.
Thanks!
- Lingua principale
- Nessun dato sulla lingua
- Stelle
- 2.5k
- Fork
- 772
- Merge medio
- 3g 15h
- PR unite (30g)
- 46
Guida per i contributori
Apri la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di github/advisory-database
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
github/advisory-database#9255 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
github/advisory-database#9164 · 1 reazione ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
github/advisory-database#8994 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
github/advisory-database#8898 · 4 commenti · 1 reazione ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
github/advisory-database#8841 ·
Tutte le issue di github/advisory-database
Issue simili
-
good first issue
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 95/100
AOSSIE-Org/DebateAI#582 · 2 commenti ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 70/100
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 70/100
oasisprotocol/oasis-sdk#2523 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
-
cost:cheap severity:medium
Difficoltà 2/5 1-3 ore Idoneità per principianti 70/100
fairagro/m4.2_sql_to_arc#227 ·