Skip to content

Add CVSS score and improve GHSA-jjff-q3q4-5hh8 (@andrei-tatar/nora-firebase-common)#7603

Open
TheeCryptoChad wants to merge 1 commit intogithub:TheeCryptoChad/advisory-improvement-7603from
TheeCryptoChad:patch-GHSA-jjff-q3q4-5hh8
Open

Add CVSS score and improve GHSA-jjff-q3q4-5hh8 (@andrei-tatar/nora-firebase-common)#7603
TheeCryptoChad wants to merge 1 commit intogithub:TheeCryptoChad/advisory-improvement-7603from
TheeCryptoChad:patch-GHSA-jjff-q3q4-5hh8

Conversation

@TheeCryptoChad
Copy link
Copy Markdown

Summary

Improves the advisory for GHSA-jjff-q3q4-5hh8 (@andrei-tatar/nora-firebase-common, CVE-2024-30564).

Changes

Add missing CVSS v3.1 vector

The severity array was empty. NVD has a published CVSS v3.1 vector for CVE-2024-30564:

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Source: https://nvd.nist.gov/vuln/detail/CVE-2024-30564

Improve description

Expanded the description with additional technical detail about the vulnerable code path, attack conditions, and impact.

Add analyst credit

Adding analyst credit for the contributor who identified the missing data and prepared this improvement.

Add NVD-sourced CVSS v3.1 vector (CVSS:3.1, score derived from NVD entry for CVE-2024-30564) to the empty severity array. Improve technical description. Add analyst credit.
@github-actions github-actions Bot changed the base branch from main to TheeCryptoChad/advisory-improvement-7603 May 6, 2026 20:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant