Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jgrp-9rqg-rqhp

Опубликовано: 26 янв. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.4

Описание

On NGINX Controller API Management versions 3.18.0-3.19.0, an authenticated attacker with access to the "user" or "admin" role can use undisclosed API endpoints on NGINX Controller API Management to inject JavaScript code that is executed on managed NGINX data plane instances. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

On NGINX Controller API Management versions 3.18.0-3.19.0, an authenticated attacker with access to the "user" or "admin" role can use undisclosed API endpoints on NGINX Controller API Management to inject JavaScript code that is executed on managed NGINX data plane instances. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

EPSS

Процентиль: 48%
0.00247
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79
CWE-94

Связанные уязвимости

CVSS3: 5.4
nvd
около 4 лет назад

On NGINX Controller API Management versions 3.18.0-3.19.0, an authenticated attacker with access to the "user" or "admin" role can use undisclosed API endpoints on NGINX Controller API Management to inject JavaScript code that is executed on managed NGINX data plane instances. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

EPSS

Процентиль: 48%
0.00247
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79
CWE-94