[ { "cve_id": "CVE-2024-3094", "title": "Malicious backdoor in xz/liblzma upstream tarballs", "cvss_score": 10.0, "severity": "critical", "published": "2024-03-29", "summary": "A supply-chain backdoor was introduced into xz-utils releases, allowing remote code execution under specific SSH configurations.", "remediation": "Downgrade to a known-good xz-utils version, verify package integrity, and rotate any credentials exposed on affected hosts.", "affected_assets": ["ASSET-001"] }, { "cve_id": "CVE-2021-44228", "title": "Apache Log4j2 remote code execution (Log4Shell)", "cvss_score": 10.0, "severity": "critical", "published": "2021-12-10", "summary": "JNDI lookups in Log4j 2.x allow unauthenticated remote code execution via crafted log messages.", "remediation": "Upgrade Log4j to 2.17.1+ or set log4j2.formatMsgNoLookups=true; restart affected services.", "affected_assets": ["ASSET-002"] }, { "cve_id": "CVE-2023-0001", "title": "Example informational finding (mock)", "cvss_score": 4.3, "severity": "medium", "published": "2023-01-15", "summary": "Illustrative low-severity entry used to exercise risk-scoring on non-critical findings.", "remediation": "Apply vendor patch during the next maintenance window.", "affected_assets": ["ASSET-003"] } ]