Skip to content

[GHSA-8jxr-mccc-mwg8] Improve advisory details: reference incomplete fix for CVE-2024-43795#6788

Open
decsecre583 wants to merge 1 commit intogithub:decsecre583/advisory-improvement-6788from
decsecre583:decsecre583-patch-55
Open

[GHSA-8jxr-mccc-mwg8] Improve advisory details: reference incomplete fix for CVE-2024-43795#6788
decsecre583 wants to merge 1 commit intogithub:decsecre583/advisory-improvement-6788from
decsecre583:decsecre583-patch-55

Conversation

@decsecre583
Copy link

@decsecre583 decsecre583 commented Feb 6, 2026

Proposed Change

Add cross-reference between CVE-2024-43795 and CVE-2024-46977 to document the incomplete fix relationship.

Evidence

  • Both discovered by GitHub Security Lab (GHSL-2024-128 and GHSL-2024-127) in the same audit
  • CVE-2024-43795 fixes XSS in the login functionality
  • CVE-2024-46977 fixes path traversal in LocalMode's open_local_file — same ScreensController component
  • Both require upgrade to OpenC3 COSMOS 5.19.0
  • Same affected version range: < 5.19.0

@github-actions github-actions bot changed the base branch from main to decsecre583/advisory-improvement-6788 February 6, 2026 04:35
@JonathanLEvans
Copy link

Hi @decsecre583,

Could you explain how CVE-2024-43795 is an incomplete fix of CVE-2024-46977 when they were fixed in the same version and are completely different vulnerability types?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants