Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f339-r2mr-9cr3

Опубликовано: 18 авг. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 2.1
CVSS3: 4.3

Описание

A vulnerability was detected in ThingsBoard 4.1. This vulnerability affects unknown code of the component Add Gateway Handler. The manipulation leads to improper neutralization of special elements used in a template engine. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor replies, that "[t]he fix will come within upcoming release (v4.2) and will be inherited by maintenance releases of LTS versions (starting 4.0)."

A vulnerability was detected in ThingsBoard 4.1. This vulnerability affects unknown code of the component Add Gateway Handler. The manipulation leads to improper neutralization of special elements used in a template engine. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor replies, that "[t]he fix will come within upcoming release (v4.2) and will be inherited by maintenance releases of LTS versions (starting 4.0)."

EPSS

Процентиль: 7%
0.00032
Низкий

2.1 Low

CVSS4

4.3 Medium

CVSS3

Дефекты

CWE-791

Связанные уязвимости

CVSS3: 4.3
nvd
7 дней назад

A vulnerability was detected in ThingsBoard 4.1. This vulnerability affects unknown code of the component Add Gateway Handler. The manipulation leads to improper neutralization of special elements used in a template engine. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor replies, that "[t]he fix will come within upcoming release (v4.2) and will be inherited by maintenance releases of LTS versions (starting 4.0)."

EPSS

Процентиль: 7%
0.00032
Низкий

2.1 Low

CVSS4

4.3 Medium

CVSS3

Дефекты

CWE-791