Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g9v6-6343-cxw5

Опубликовано: 18 дек. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

Cross-site Scripting (XSS) - Stored in GitHub repository allegroai/clearml-server prior to 1.13.0. This vulnerability affects the ClearML Open Source Server which is not designed to be used as a publicly available service. Security recommendations stress it should be placed behind a company firewall or VPN. This vulnerability only affects users within the same organisation (I.e when a malicious party already has access to the internal network and to a user's ClearML login credentials).

Cross-site Scripting (XSS) - Stored in GitHub repository allegroai/clearml-server prior to 1.13.0. This vulnerability affects the ClearML Open Source Server which is not designed to be used as a publicly available service. Security recommendations stress it should be placed behind a company firewall or VPN. This vulnerability only affects users within the same organisation (I.e when a malicious party already has access to the internal network and to a user's ClearML login credentials).

EPSS

Процентиль: 41%
0.00195
Низкий

7.5 High

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
около 2 лет назад

Cross-site Scripting (XSS) - Stored in GitHub repository allegroai/clearml-server prior to 1.13.0.

EPSS

Процентиль: 41%
0.00195
Низкий

7.5 High

CVSS3

Дефекты

CWE-79