Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f7f8-8qv6-p289

Опубликовано: 06 фев. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 9.9

Описание

A cross-site scripting (XSS) vulnerability in all versions of the web server component of Allegro AI’s ClearML platform allows a remote attacker to execute a JavaScript payload when a user views the Debug Samples tab in the web UI.

A cross-site scripting (XSS) vulnerability in all versions of the web server component of Allegro AI’s ClearML platform allows a remote attacker to execute a JavaScript payload when a user views the Debug Samples tab in the web UI.

EPSS

Процентиль: 18%
0.00059
Низкий

9.9 Critical

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 9.9
nvd
около 2 лет назад

A cross-site scripting (XSS) vulnerability in all versions of the web server component of Allegro AI’s ClearML platform allows a remote attacker to execute a JavaScript payload when a user views the Debug Samples tab in the web UI.

EPSS

Процентиль: 18%
0.00059
Низкий

9.9 Critical

CVSS3

Дефекты

CWE-79