Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4cj8-779h-r25h

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.1

Описание

Cross-site Scripting in Pivotal Spring Batch Admin

Pivotal Spring Batch Admin, all versions, contains a stored XSS vulnerability in the file upload feature. An unauthenticated malicious user with network access to Spring Batch Admin could store an arbitrary web script that would be executed by other users. This issue has not been patched because Spring Batch Admin has reached end of life.

Пакеты

Наименование

org.springframework.batch:spring-batch-admin-manager

maven
Затронутые версииВерсия исправления

<= 2.0.0.M1

Отсутствует

EPSS

Процентиль: 53%
0.00304
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
почти 8 лет назад

Pivotal Spring Batch Admin, all versions, contains a stored XSS vulnerability in the file upload feature. An unauthenticated malicious user with network access to Spring Batch Admin could store an arbitrary web script that would be executed by other users. This issue has not been patched because Spring Batch Admin has reached end of life.

EPSS

Процентиль: 53%
0.00304
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79