Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-969f-386j-4c9x

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

A cross-site scripting vulnerability was reported in the oVirt-engine's OAuth authorization endpoint before version 4.3.8. URL parameters were included in the HTML response without escaping. This flaw would allow an attacker to craft malicious HTML pages that can run scripts in the context of the user's oVirt session.

A cross-site scripting vulnerability was reported in the oVirt-engine's OAuth authorization endpoint before version 4.3.8. URL parameters were included in the HTML response without escaping. This flaw would allow an attacker to craft malicious HTML pages that can run scripts in the context of the user's oVirt session.

EPSS

Процентиль: 53%
0.00307
Низкий

Связанные уязвимости

CVSS3: 5.4
redhat
около 6 лет назад

A cross-site scripting vulnerability was reported in the oVirt-engine's OAuth authorization endpoint before version 4.3.8. URL parameters were included in the HTML response without escaping. This flaw would allow an attacker to craft malicious HTML pages that can run scripts in the context of the user's oVirt session.

CVSS3: 6.1
nvd
почти 6 лет назад

A cross-site scripting vulnerability was reported in the oVirt-engine's OAuth authorization endpoint before version 4.3.8. URL parameters were included in the HTML response without escaping. This flaw would allow an attacker to craft malicious HTML pages that can run scripts in the context of the user's oVirt session.

EPSS

Процентиль: 53%
0.00307
Низкий