[GHSA-mw8w-q3f7-2v85] Podinfo affected by Arbitrary File Upload that leads to Stored Cross-Site Scripting (XSS)#7160
Conversation
There was a problem hiding this comment.
Pull request overview
This PR updates the GHSA advisory record for GHSA-mw8w-q3f7-2v85 (Podinfo arbitrary file upload leading to stored XSS), aiming to reflect updated affected versions and scoring information.
Changes:
- Removes the populated top-level
severityentries (CVSS v3.1/v4.0) and replaces them with an empty array. - Updates the affected range to use a
fixedevent at6.11.1and addsdatabase_specific.last_known_affected_version_range. - Bumps the
modifiedtimestamp.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
This looks like a form submission bug, I only added the version with the fix |
ed7081c
into
stefanprodan/advisory-improvement-7160
|
Hi @stefanprodan! Thank you so much for contributing to the GitHub Advisory Database. This database is free, open, and accessible to all, and it's people like you who make it great. Thanks for choosing to help others. We hope you send in more contributions in the future! |
Updates
Comments
CVE fixed in https://github.com/stefanprodan/podinfo/releases/tag/6.11.1