Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p56w-h56q-c97x

Опубликовано: 08 нояб. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.2

Описание

YugabyteDB is vulnerable to cross site scripting (XSS) via log injection. Writing invalidated user input to log files can allow an attacker to forge log entries or inject malicious content into the logs.

YugabyteDB is vulnerable to cross site scripting (XSS) via log injection. Writing invalidated user input to log files can allow an attacker to forge log entries or inject malicious content into the logs.

EPSS

Процентиль: 37%
0.00157
Низкий

7.2 High

CVSS3

Дефекты

CWE-117
CWE-79

Связанные уязвимости

CVSS3: 6.5
nvd
около 2 лет назад

YugabyteDB is vulnerable to cross site scripting (XSS) via log injection. Writing invalidated user input to log files can allow an unprivileged attacker to forge log entries or inject malicious content into the logs.

EPSS

Процентиль: 37%
0.00157
Низкий

7.2 High

CVSS3

Дефекты

CWE-117
CWE-79