Skip to content

GHSA-9cxr-76pm-j3wf - Seemingly incorrect severity for DOS vulnerability #5353

Closed
@ghsa-retrieval

Description

@ghsa-retrieval

The vulnerability CVE-2024-53299 in Wicket has the matching entry GHSA-9cxr-76pm-j3wf in the advisory database. The severity according to GitHub's advisory is critical, while the description states that it is only a denial of service vulnerability. While assessments can deviate, a pure DOS vulnerability should at most be a medium severity when using a scoring based on CVSS 3.1 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) or high for CVSS 4 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N). CISA ADP seems to conclude that exploitation even requires local privileges and thus rates it as a medium as well.

Please consider reviewing the severity and adapting it as necessary.

GitHub advisory entry:

CISA ADP:

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions