diff --git a/http/cves/2023/CVE-2023-4451.yaml b/http/cves/2023/CVE-2023-4451.yaml index 940a6e2995..d08d2f7d88 100644 --- a/http/cves/2023/CVE-2023-4451.yaml +++ b/http/cves/2023/CVE-2023-4451.yaml @@ -7,9 +7,14 @@ info: description: | Cross-site Scripting (XSS) - Reflected in GitHub repository cockpit-hq/cockpit prior to 2.6.4. reference: - - https://nvd.nist.gov/vuln/detail/CVE-2023-4451 - https://huntr.dev/bounties/4e111c3e-6cf3-4b4c-b3c1-a540bf30f8fa/ - https://github.com/Cockpit-HQ/Cockpit/commit/30609466c817e39f9de1871559603e93cd4d0d0c + - https://nvd.nist.gov/vuln/detail/CVE-2023-4451 + classification: + cve-id: CVE-2023-4451 + cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N + cvss-score: 6.1 + cwe-id: CWE-79 metadata: max-request: 1 verified: true @@ -26,9 +31,7 @@ http: - type: word part: body words: - - "" - - "Cockpit" - condition: and + - "Space :: does not exist" - type: word part: header