Skip to content

Conversation

@Stonefox36
Copy link

Updates

  • Affected products
  • CVSS v3
  • Severity

Comments
Exposure of Sensitive Information to an Unauthorized Actor (CWE-200)
Improper Removal of Sensitive Information Before Storage or Transfer (CWE-212)
Suggest improvements
Suggestions are submitted as a pull request to be reviewed by the GitHub Security Curators team.
Reason for change *

advisory-database bot and others added 23 commits August 25, 2025 15:33
@github-actions github-actions bot changed the base branch from main to Stonefox36/advisory-improvement-6045 August 26, 2025 10:39
@yhidad31
Copy link

Hi @Stonefox36, we see your CVSS suggestion CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H. Can you explain the rationale for changing Privileges Required and Availability from None to High, or link to analysis/supporting references? If you'd like, we can run this through the CVSS calculator: https://www.first.org/cvss/calculator/3-1 and the score can be updated if we agree.

@Stonefox36
Copy link
Author

Stonefox36 commented Aug 27, 2025 via email

@Stonefox36 Stonefox36 changed the base branch from Stonefox36/advisory-improvement-6045 to Wrathchyld-GHSA-27v7-qhfv-rqq8 August 27, 2025 00:39
@github-actions
Copy link

👋 This pull request has been marked as stale because it has been open with no activity. You can: comment on the issue or remove the stale label to hold stale off for a while, add the Keep label to hold stale off permanently, or do nothing. If you do nothing this pull request will be closed eventually by the stale bot. Please see CONTRIBUTING.md for more policy details.

@github-actions github-actions bot added the Stale label Sep 12, 2025
@github-actions github-actions bot closed this Sep 28, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants