Skip to content

Comments

[GHSA-8jxr-mccc-mwg8] Improve advisory details: reference incomplete fix for CVE-2024-43795#6788

Open
decsecre583 wants to merge 1 commit intogithub:decsecre583/advisory-improvement-6788from
decsecre583:decsecre583-patch-55
Open

[GHSA-8jxr-mccc-mwg8] Improve advisory details: reference incomplete fix for CVE-2024-43795#6788
decsecre583 wants to merge 1 commit intogithub:decsecre583/advisory-improvement-6788from
decsecre583:decsecre583-patch-55

Conversation

@decsecre583
Copy link

@decsecre583 decsecre583 commented Feb 6, 2026

Proposed Change

Add cross-reference between CVE-2024-43795 and CVE-2024-46977 to document the incomplete fix relationship.

Evidence

  • Both discovered by GitHub Security Lab (GHSL-2024-128 and GHSL-2024-127) in the same audit
  • CVE-2024-43795 fixes XSS in the login functionality
  • CVE-2024-46977 fixes path traversal in LocalMode's open_local_file — same ScreensController component
  • Both require upgrade to OpenC3 COSMOS 5.19.0
  • Same affected version range: < 5.19.0

@github-actions github-actions bot changed the base branch from main to decsecre583/advisory-improvement-6788 February 6, 2026 04:35
@JonathanLEvans
Copy link

Hi @decsecre583,

Could you explain how CVE-2024-43795 is an incomplete fix of CVE-2024-46977 when they were fixed in the same version and are completely different vulnerability types?

@github-actions
Copy link

👋 This pull request has been marked as stale because it has been open with no activity. You can: comment on the issue or remove the stale label to hold stale off for a while, add the Keep label to hold stale off permanently, or do nothing. If you do nothing this pull request will be closed eventually by the stale bot. Please see CONTRIBUTING.md for more policy details.

@github-actions github-actions bot added the Stale label Feb 22, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants