File size: 1,368 Bytes
ebd50f7
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
[
  {
    "cve_id": "CVE-2024-3094",
    "title": "Malicious backdoor in xz/liblzma upstream tarballs",
    "cvss_score": 10.0,
    "severity": "critical",
    "published": "2024-03-29",
    "summary": "A supply-chain backdoor was introduced into xz-utils releases, allowing remote code execution under specific SSH configurations.",
    "remediation": "Downgrade to a known-good xz-utils version, verify package integrity, and rotate any credentials exposed on affected hosts.",
    "affected_assets": ["ASSET-001"]
  },
  {
    "cve_id": "CVE-2021-44228",
    "title": "Apache Log4j2 remote code execution (Log4Shell)",
    "cvss_score": 10.0,
    "severity": "critical",
    "published": "2021-12-10",
    "summary": "JNDI lookups in Log4j 2.x allow unauthenticated remote code execution via crafted log messages.",
    "remediation": "Upgrade Log4j to 2.17.1+ or set log4j2.formatMsgNoLookups=true; restart affected services.",
    "affected_assets": ["ASSET-002"]
  },
  {
    "cve_id": "CVE-2023-0001",
    "title": "Example informational finding (mock)",
    "cvss_score": 4.3,
    "severity": "medium",
    "published": "2023-01-15",
    "summary": "Illustrative low-severity entry used to exercise risk-scoring on non-critical findings.",
    "remediation": "Apply vendor patch during the next maintenance window.",
    "affected_assets": ["ASSET-003"]
  }
]