Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

Suggest improvements form drops the CVSS 3.1 vector when an advisory has both 3.1 and 4.0

未关闭
#9,628 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

维护者通常 1 天内回复

还没有人认领这个 Issue。

评估

难度
3/5
预计耗时
1-2 天
新手友好度
48/100
Issue 类型
缺陷
描述清晰度
描述清楚
活跃度
活跃
领域
security

调研方向

Start by examining the “Suggest improvements for this vulnerability” form and the generated changes in pull request #9627 for advisory GHSA-984m-rj28-8c6x. Reproduce a range-only edit on an advisory containing both CVSS 3.1 and 4.0 vectors, then verify that the CVSS 3.1 vector remains in the submitted advisory.

由索引模型根据 Issue 内容生成。

描述

I used the "Suggest improvements for this vulnerability" form on GHSA-984m-rj28-8c6x to change the range of one entry. I did not touch the severity. But the pull request #9627 also removes the CVSS_V3 entry and keeps only CVSS_V4. Here is the part of its diff.

   "severity": [
-    {
-      "type": "CVSS_V3",
-      "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"
-    },
     {
       "type": "CVSS_V4",
       "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"

The advisory has both vectors. The form has a "Severity" select with "Assess severity using CVSS v4" and one "Vector string" field, so it can hold only one vector. When I submit the form, the other vector is lost.

I expect the form to keep the CVSS 3.1 vector when I do not edit the severity.

主要语言
没有语言数据
星标
2.5k
派生
789
平均合并
5 天 11 小时
30 天内合并 PR
70

环境准备

  • 没有 Dockerfile 或 Docker Compose 文件
  • 没有 Pull Request 模板
  • 阅读贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

github/advisory-database 的其他 Issue

查看 github/advisory-database 的全部 Issue

相似的 Issue

更多 Security Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。