From e7d09ebb2db3c34f8fe06d43ed0ac98e6d9828ea Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 9 Apr 2025 16:46:33 +0000 Subject: [PATCH] Publish GHSA-f98p-9pp6-7q6c --- .../05/GHSA-f98p-9pp6-7q6c/GHSA-f98p-9pp6-7q6c.json | 13 +++++++++++-- 1 file changed, 11 insertions(+), 2 deletions(-) diff --git a/advisories/github-reviewed/2022/05/GHSA-f98p-9pp6-7q6c/GHSA-f98p-9pp6-7q6c.json b/advisories/github-reviewed/2022/05/GHSA-f98p-9pp6-7q6c/GHSA-f98p-9pp6-7q6c.json index 2cadf2f39fb..bea3bd0773b 100644 --- a/advisories/github-reviewed/2022/05/GHSA-f98p-9pp6-7q6c/GHSA-f98p-9pp6-7q6c.json +++ b/advisories/github-reviewed/2022/05/GHSA-f98p-9pp6-7q6c/GHSA-f98p-9pp6-7q6c.json @@ -1,14 +1,19 @@ { "schema_version": "1.4.0", "id": "GHSA-f98p-9pp6-7q6c", - "modified": "2024-03-05T18:53:37Z", + "modified": "2025-04-09T16:44:52Z", "published": "2022-05-01T23:45:13Z", "aliases": [ "CVE-2008-1947" ], "summary": "Apache Tomcat Cross-site scripting (XSS) vulnerability", "details": "Cross-site scripting (XSS) vulnerability in Apache Tomcat 5.5.9 through 5.5.26 and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via the name parameter (aka the hostname attribute) to `host-manager/html/add`.", - "severity": [], + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N" + } + ], "affected": [ { "package": { @@ -216,6 +221,10 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2008:0648" }, + { + "type": "WEB", + "url": "http://lists.apple.com/archives/security-announce/2008/Oct/msg00001.html" + }, { "type": "WEB", "url": "http://lists.opensuse.org/opensuse-security-announce/2008-07/msg00001.html"