Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[GHSA-37q5-v5qm-c9v8] Transformers Deserialization of Untrusted Data vulnerability #4237

Open
wants to merge 1 commit into
base: retr0reg/advisory-improvement-4237
Choose a base branch
from

Conversation

retr0reg
Copy link

Updates

  • Affected products
  • CVSS
  • Description
  • References

Comments
I am the author of this report on huntr.com. I fixed a few grammatic mistakes and updated the poc.py.
Additionally, The reason for changing the Severity to Low is that the CVSS cannot directly show the severity of this vulnerability. Maintainers in huntr.com cannot rate a vulnerability directly into 'Low' since they can only adjust the CVSS scoring into the Low category.

@github-actions github-actions bot changed the base branch from main to retr0reg/advisory-improvement-4237 April 12, 2024 00:53
@JonathanLEvans
Copy link

Hi @retr0reg, we too need a CVSS vector. Do have a better one?

@taladrane
Copy link
Collaborator

👋 This pull request has been marked as stale because it has been open with no activity. You can: comment on the issue or remove the stale label to hold stale off for a while, add the Keep label to hold stale off permanently, or do nothing. If you do nothing this pull request will be closed eventually by the stale bot. Please see CONTRIBUTING.md for more policy details.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants