Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6g6q-c7q8-8r7m

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

A Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Open Build Service allows remote attackers to store JS code in markdown that is not properly escaped, impacting confidentiality and integrity. This issue affects: Open Build Service versions prior to 2.10.8.

A Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Open Build Service allows remote attackers to store JS code in markdown that is not properly escaped, impacting confidentiality and integrity. This issue affects: Open Build Service versions prior to 2.10.8.

EPSS

Процентиль: 44%
0.00217
Низкий

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.3
ubuntu
почти 5 лет назад

A Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Open Build Service allows remote attackers to store JS code in markdown that is not properly escaped, impacting confidentiality and integrity. This issue affects: Open Build Service versions prior to 2.10.8.

CVSS3: 6.3
nvd
почти 5 лет назад

A Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Open Build Service allows remote attackers to store JS code in markdown that is not properly escaped, impacting confidentiality and integrity. This issue affects: Open Build Service versions prior to 2.10.8.

CVSS3: 6.3
debian
почти 5 лет назад

A Improper Neutralization of Input During Web Page Generation ('Cross- ...

EPSS

Процентиль: 44%
0.00217
Низкий

Дефекты

CWE-79