Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-927p-xrc2-x2gj

Опубликовано: 28 мая 2024
Источник: github
Github: Прошло ревью
CVSS3: 8.2

Описание

ansibleguy-webui Cross-site Scripting vulnerability

Impact

Multiple forms in version <0.0.21 allowed injection of HTML elements. These are returned to the user after executing job actions and thus evaluated by the browser.

Patches

We recommend to upgrade to version >= 0.0.21

References

Пакеты

Наименование

ansibleguy-webui

pip
Затронутые версииВерсия исправления

< 0.0.21

0.0.21

EPSS

Процентиль: 48%
0.00249
Низкий

8.2 High

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 8.2
nvd
больше 1 года назад

ansibleguy-webui is an open source WebUI for using Ansible. Multiple forms in versions < 0.0.21 allowed injection of HTML elements. These are returned to the user after executing job actions and thus evaluated by the browser. These issues have been addressed in version 0.0.21 (0.0.21.post2 on pypi). Users are advised to upgrade. There are no known workarounds for these issues.

EPSS

Процентиль: 48%
0.00249
Низкий

8.2 High

CVSS3

Дефекты

CWE-79