CVE
Common Vulnerabilities and Exposures is a dictionary of common names (CVE Identifiers) for publicly known information security vulnerabilities maintained by the MITRE Corporation.
CVSS
Common Vulnerability Scoring System is a vendor agnostic, industry open standard designed to convey the severity of a vulnerability. CVSS scores may be used to determine the urgency for update deployment within an organization and can range from 0.0 (no vulnerability) to 10.0 (critical). ClickUp uses CVSSv3 in vulnerability assessments to present an immutable characterization of security vulnerabilities. ClickUp assigns all relevant security vulnerabilities a non-zero score. Customers performing their own risk assessments of vulnerabilities that may impact them can benefit from using the same industry-recognized CVSS metrics.
Mitigations
Mitigations are existing conditions that a potential attacker would need to overcome to mount a successful attack or that would limit the severity of an attack. Examples of such conditions include default settings, common configurations and general best practices.
Workarounds
Workarounds are settings or configuration changes that a user or administrator can apply to help protect against an attack.
ACKNOWLEDGEMENTS
ClickUp would like to thank Mykola Grymalyuk of RIPEDA Consulting for their involvement in helping protect our customers.
TIMELINE
- Email received - December 23, 2023
- Reply to security researcher - December 27, 2023
- Issue accepted - December 27, 2023
- CVE number requested - January 9, 2024
- Issue fixed and available to customers - January 16, 2024
- CVE number received - January 25, 2024
- Published SAN - 8 Mar, 2024
CHANGE LOG
8 Mar, 2024
Initial Publication
FIRST PUBLISHED DATE
8 Mar, 2024
LAST MODIFIED DATE
19 Mar, 2024