Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9qg7-6j9m-fqcj

Опубликовано: 10 окт. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

A vulnerability  Bypass of the script allowlist configuration in HCL AION. 

An incorrectly configured Content-Security-Policy header may allow unauthorized scripts to execute, increasing the risk of cross-site scripting and other injection-based attacks.This issue affects AION: 2.0.

A vulnerability  Bypass of the script allowlist configuration in HCL AION. 

An incorrectly configured Content-Security-Policy header may allow unauthorized scripts to execute, increasing the risk of cross-site scripting and other injection-based attacks.This issue affects AION: 2.0.

EPSS

Процентиль: 12%
0.0004
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
4 месяца назад

A vulnerability  Bypass of the script allowlist configuration in HCL AION.  An incorrectly configured Content-Security-Policy header may allow unauthorized scripts to execute, increasing the risk of cross-site scripting and other injection-based attacks.This issue affects AION: 2.0.

EPSS

Процентиль: 12%
0.0004
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79