[GHSA-569q-mpph-wgww] Better Auth affected by external request basePath modification DoS - #8942
Conversation
|
Hi there @Bekacru! A community member has suggested an improvement to your security advisory. If approved, this change will affect the global advisory listed at github.com/advisories. It will not affect the version listed in your project repository. This change will be reviewed by our Security Curation Team. If you have thoughts or feedback, please share them in a comment here! If this PR has already been closed, you can start a new community contribution for this advisory |
|
Apologies — this PR does not reflect what I intended to submit, and I'd suggest not merging it as-is. The form appears to reject the alias because the CVE is already held by the unreviewed record, so this likely needs a curator-side merge rather than a form submission. |
|
Closing this in favour of #8943, which contains only the change I actually intended: adding |
The previous submission for this advisory (github#8942) was still open when this PR was created, so the check failed with "You already have a pending improvement for this advisory". github#8942 is now closed; this empty commit re-triggers the check. No file changes.
Updates
Comments
Note: I did not intend to change the CVSS score. The stored vector ends with the CVSS 4.0 Threat metric /E:P, which this form's calculator rejects ("vector string contains an error"); I dropped only that suffix so the form would validate. The Base metrics are unchanged.