Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2755-2mm4-rm5c

Опубликовано: 22 апр. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 2.1
CVSS3: 6.1

Описание

http.cookies.Morsel.js_output() returns an inline inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value.

http.cookies.Morsel.js_output() returns an inline inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value.

EPSS

Процентиль: 14%
0.00229
Низкий

2.1 Low

CVSS4

6.1 Medium

CVSS3

Дефекты

CWE-116
CWE-150

Связанные уязвимости

CVSS3: 6.1
ubuntu
3 месяца назад

http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value.

CVSS3: 6.8
redhat
3 месяца назад

http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value.

CVSS3: 6.1
nvd
3 месяца назад

http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value.

msrc
3 месяца назад

BaseCookie.js_output() does not neutralize embedded characters

CVSS3: 6.1
debian
3 месяца назад

http.cookies.Morsel.js_output() returns an inline <script> snippet and ...

EPSS

Процентиль: 14%
0.00229
Низкий

2.1 Low

CVSS4

6.1 Medium

CVSS3

Дефекты

CWE-116
CWE-150