From f8b21cf437adbb7d4904518bf16c75587fcbf01c Mon Sep 17 00:00:00 2001 From: Peter Date: Fri, 25 Oct 2024 13:44:31 +0200 Subject: [PATCH] Improve GHSA-m8cj-3v68-3cxj --- .../2024/06/GHSA-m8cj-3v68-3cxj/GHSA-m8cj-3v68-3cxj.json | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/advisories/github-reviewed/2024/06/GHSA-m8cj-3v68-3cxj/GHSA-m8cj-3v68-3cxj.json b/advisories/github-reviewed/2024/06/GHSA-m8cj-3v68-3cxj/GHSA-m8cj-3v68-3cxj.json index b4806a2c65665..975efdaf60691 100644 --- a/advisories/github-reviewed/2024/06/GHSA-m8cj-3v68-3cxj/GHSA-m8cj-3v68-3cxj.json +++ b/advisories/github-reviewed/2024/06/GHSA-m8cj-3v68-3cxj/GHSA-m8cj-3v68-3cxj.json @@ -10,8 +10,8 @@ "details": "Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution. An attacker could exploit this vulnerability by sending a crafted XML document that references external entities. Exploitation of this issue does not require user interaction.", "severity": [ { - "type": "CVSS_V3", - "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H" } ], "affected": [