Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pvc3-wvxr-7cmf

Опубликовано: 26 авг. 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.1

Описание

SmallRye Health UI Cross-site Scripting vulnerability

It was found that the smallrye health metrics UI component did not properly sanitize some user inputs. An attacker could use this flaw to conduct cross-site scripting attacks.

Пакеты

Наименование

io.smallrye:smallrye-health-ui

maven
Затронутые версииВерсия исправления

< 3.1.2

3.1.2

EPSS

Процентиль: 65%
0.0048
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.5
redhat
больше 4 лет назад

It was found that the smallrye health metrics UI component did not properly sanitize some user inputs. An attacker could use this flaw to conduct cross-site scripting attacks.

CVSS3: 6.1
nvd
больше 3 лет назад

It was found that the smallrye health metrics UI component did not properly sanitize some user inputs. An attacker could use this flaw to conduct cross-site scripting attacks.

EPSS

Процентиль: 65%
0.0048
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79