Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[GHSA-76mp-659p-rw65] Updating CVSS 3.x Availability Rating #5208

Open
wants to merge 1 commit into
base: anonymous-nlp-student/advisory-improvement-5208
Choose a base branch
from

Conversation

anonymous-nlp-student
Copy link

Summary

The Availability (A) rating for CVE-2021-32620 / GHSA-76mp-659p-rw65 should be revised from High (H) to None (N). This is because the vulnerability does not disrupt the wiki’s functionality or hinder access for others, as seen in typical Denial-of-Service (DoS) attacks.

A user disabled on a wiki using email verification for registration can re-activate himself by using the activation link provided for his registration.

Supporting Examples

Notably, a similar CVE for the same package has already been rated as A:N:

  • CVE-2022-36090 / GHSA-jgc8-gvcx-9vfx (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N)

    Some resources are missing a check for inactive (not yet activated or disabled) users in XWiki, including the REST service: so a disabled user can enable themselves using a REST call. On the same way some resources handler created by extensions are not protected by default: so an inactive users could perform actions for such extensions.

@github-actions github-actions bot changed the base branch from main to anonymous-nlp-student/advisory-improvement-5208 January 21, 2025 03:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant