Skip to content

Add CVSS score and improve GHSA-xgj4-2hrf-j4xg (survey-creator)#7604

Open
TheeCryptoChad wants to merge 1 commit intogithub:TheeCryptoChad/advisory-improvement-7604from
TheeCryptoChad:patch-GHSA-xgj4-2hrf-j4xg
Open

Add CVSS score and improve GHSA-xgj4-2hrf-j4xg (survey-creator)#7604
TheeCryptoChad wants to merge 1 commit intogithub:TheeCryptoChad/advisory-improvement-7604from
TheeCryptoChad:patch-GHSA-xgj4-2hrf-j4xg

Conversation

@TheeCryptoChad
Copy link
Copy Markdown

Summary

Improves the advisory for GHSA-xgj4-2hrf-j4xg (survey-creator, CVE-2024-28635).

Changes

Add missing CVSS v3.1 vector

The severity array was empty. NVD has a published CVSS v3.1 vector for CVE-2024-28635:

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Source: https://nvd.nist.gov/vuln/detail/CVE-2024-28635

Improve description

Expanded the description with additional technical detail about the vulnerable code path, attack conditions, and impact.

Add analyst credit

Adding analyst credit for the contributor who identified the missing data and prepared this improvement.

Add NVD-sourced CVSS v3.1 vector (CVSS:3.1, score derived from NVD entry for CVE-2024-28635) to the empty severity array. Improve technical description. Add analyst credit.
@github-actions github-actions Bot changed the base branch from main to TheeCryptoChad/advisory-improvement-7604 May 6, 2026 20:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant