All security advisories
demo-advisory-0001
DEMO advisory — privilege escalation in the demo seed
High
- Published
- Updated
- Revision
- 2
- Affected versions
- < 2.5.1-demo
- Fixed in
- 2.5.1-demo
- CVSS score
- 8.1
- CVE ids
- CVE-2026-00000
- CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Description
DEMO advisory body. This describes no real vulnerability.
Workaround until the fix is installed
A customer inside an air gap may wait weeks for the fixed build. This is what they can do in the meantime.
DEMO workaround. Not a real mitigation.
Version matrix
"Not affected" is a valuable answer in its own right: it saves an upgrade for a customer who cannot easily perform one.
| Branch | Status | Range | Fixed in | Note |
|---|---|---|---|---|
| 2.5.x | Affected | 2.5.0-demo – 2.5.0-demo | 2.5.1-demo | — |
| 2.4.x | Affected | 2.4.0-demo – 2.4.7-demo | 2.4.8-demo | — |
| 2.3.x | Not affected | — | — | DEMO — the affected component did not exist before 2.4. |
Revision history
A security document with silent edits is not evidence.
- Revision 2DEMO — an additional affected branch was added.
- Revision 1Initial publication.
CSAF 2.0 document
The same advisory, in the format a vulnerability-management tool reads.
The portal view
Customers additionally see whether it affects the version they declared.