Skip to content

Conversation

@morningstarxcdcode
Copy link

Updates

  • Affected products
  • CVSS v3
  • CVSS v4

Comments
just minor changes

@Copilot Copilot AI review requested due to automatic review settings October 25, 2025 08:48
Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR updates the security advisory for fast-redact's prototype pollution vulnerability (GHSA-ffrw-9mx8-89p8) by changing the CVSS scoring system from v4 to v3 and updating the modification timestamp.

  • Updated CVSS scoring from v4.0 to v3.1 with a new score vector
  • Updated the modification timestamp to reflect the changes

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N"
Copy link

Copilot AI Oct 25, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The CVSS v3.1 score vector indicates zero impact across all categories (C:N/I:N/A:N), which contradicts the advisory description stating this vulnerability causes 'denial of service (DoS) as the minimum consequence.' The Availability impact should be set to at least 'L' (Low) or higher to reflect the DoS risk.

Suggested change
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N"
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"

Copilot uses AI. Check for mistakes.
@github-actions github-actions bot changed the base branch from main to morningstarxcdcode/advisory-improvement-6348 October 25, 2025 08:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant