Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[GHSA-65xf-588v-56fv] An issue in the _readFileSync function of Simple... #4876

Open
wants to merge 1 commit into
base: m3t3kh4n/advisory-improvement-4876
Choose a base branch
from

Conversation

m3t3kh4n
Copy link

@m3t3kh4n m3t3kh4n commented Oct 8, 2024

Updates

  • Affected products
  • CVSS v3
  • CVSS v4
  • References
  • Source code location
  • Summary

Comments

  • Title was added
  • Source Code Location was added
  • Affected products were added (ecosystem and package)
  • CVSSv4 assessment was recalculated
  • An extra reference was added

@github-actions github-actions bot changed the base branch from main to m3t3kh4n/advisory-improvement-4876 October 8, 2024 07:52
@shelbyc
Copy link
Contributor

shelbyc commented Oct 8, 2024

Hi @m3t3kh4n, my colleagues and I have chosen to not review this advisory and issue Dependabot alerts. When we read the researcher reports (1, 2) we noticed that the proofs of concept provided by the researcher didn't actually grant an attacker access to any files they didn't normally have access to. If you have other evidence that CVE-2024-46503 can be exploited by threat actors to gain access to files they don't already have access to, you're welcome to provide it and my colleagues and I will read the evidence.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants