[GHSA-77r5-gw3j-2mpf] Next.js Vulnerable to HTTP Request Smuggling#6636
[GHSA-77r5-gw3j-2mpf] Next.js Vulnerable to HTTP Request Smuggling#6636mistressxalexis wants to merge 1 commit intomainfrom
Conversation
|
Hi @mistressxalexis, I see your CVSS suggestion CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N. Can you explain the rationale for changing Attack Complexity from H to L, Scope from C to U, Confidentiality from L to N and Integrity from H to N or link to analysis/supporting references? If you'd like, we can run this through a CVSS calculator: https://www.first.org/cvss/calculator/3.1 and will update if we agree. |
|
👋 This pull request has been marked as stale because it has been open with no activity. You can: comment on the issue or remove the stale label to hold stale off for a while, add the |
Updates
Comments
Y