Add CVSS score and analyst credit for GHSA-mj6p-3pc9-wf5m (proxy DoS)#7601
Open
TheeCryptoChad wants to merge 1 commit intogithub:TheeCryptoChad/advisory-improvement-7601from
Open
Conversation
Add NVD-sourced CVSS v3.1 score (7.5 HIGH) which was missing from the severity array. Update severity from MODERATE to HIGH to match NVD assessment. Improve description with additional technical detail about the exploit path. Add analyst credit.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
This PR improves the advisory for
GHSA-mj6p-3pc9-wf5m(proxynpm package, CVE-2023-2968).Changes
1. Add missing CVSS v3.1 score
The
severityarray was empty ([]). The NVD entry for CVE-2023-2968 has a published CVSS v3.1 vector:Source: https://nvd.nist.gov/vuln/detail/CVE-2023-2968
2. Update severity from MODERATE to HIGH
The
database_specific.severitywas set toMODERATE. The NVD-assigned base score of 7.5 falls in the HIGH range (7.0–8.9). Updating to match the authoritative NVD assessment.3. Improve description
Expanded the description to include the vulnerable code path, the conditions required to trigger the crash, and a note about the fix.
4. Add analyst credit
Adding analyst credit for the contributor who identified the missing CVSS data and prepared this improvement.