Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6f4m-j56w-55c3

Опубликовано: 23 сент. 2023
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Kiali content spoofing vulnerability

A content spoofing vulnerability was found in Kiali. It was discovered that Kiali does not implement error handling when the page or endpoint being accessed cannot be found. This issue allows an attacker to perform arbitrary text injection when an error response is retrieved from the URL being accessed.

Пакеты

Наименование

github.com/kiali/kiali

go
Затронутые версииВерсия исправления

< 1.57.4

1.57.4

EPSS

Процентиль: 29%
0.00107
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-74

Связанные уязвимости

CVSS3: 4.3
redhat
около 3 лет назад

A content spoofing vulnerability was found in Kiali. It was discovered that Kiali does not implement error handling when the page or endpoint being accessed cannot be found. This issue allows an attacker to perform arbitrary text injection when an error response is retrieved from the URL being accessed.

CVSS3: 4.3
nvd
больше 2 лет назад

A content spoofing vulnerability was found in Kiali. It was discovered that Kiali does not implement error handling when the page or endpoint being accessed cannot be found. This issue allows an attacker to perform arbitrary text injection when an error response is retrieved from the URL being accessed.

EPSS

Процентиль: 29%
0.00107
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-74