Spaces:
Sleeping
Sleeping
File size: 1,368 Bytes
ebd50f7 | 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 | [
{
"cve_id": "CVE-2024-3094",
"title": "Malicious backdoor in xz/liblzma upstream tarballs",
"cvss_score": 10.0,
"severity": "critical",
"published": "2024-03-29",
"summary": "A supply-chain backdoor was introduced into xz-utils releases, allowing remote code execution under specific SSH configurations.",
"remediation": "Downgrade to a known-good xz-utils version, verify package integrity, and rotate any credentials exposed on affected hosts.",
"affected_assets": ["ASSET-001"]
},
{
"cve_id": "CVE-2021-44228",
"title": "Apache Log4j2 remote code execution (Log4Shell)",
"cvss_score": 10.0,
"severity": "critical",
"published": "2021-12-10",
"summary": "JNDI lookups in Log4j 2.x allow unauthenticated remote code execution via crafted log messages.",
"remediation": "Upgrade Log4j to 2.17.1+ or set log4j2.formatMsgNoLookups=true; restart affected services.",
"affected_assets": ["ASSET-002"]
},
{
"cve_id": "CVE-2023-0001",
"title": "Example informational finding (mock)",
"cvss_score": 4.3,
"severity": "medium",
"published": "2023-01-15",
"summary": "Illustrative low-severity entry used to exercise risk-scoring on non-critical findings.",
"remediation": "Apply vendor patch during the next maintenance window.",
"affected_assets": ["ASSET-003"]
}
]
|