Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-32670

Опубликовано: 07 июн. 2021
Источник: nvd
CVSS3: 7.2
CVSS3: 6.1
CVSS2: 4.3
EPSS Низкий

Описание

Datasette is an open source multi-tool for exploring and publishing data. The ?_trace=1 debugging feature in Datasette does not correctly escape generated HTML, resulting in a reflected cross-site scripting vulnerability. This vulnerability is particularly relevant if your Datasette installation includes authenticated features using plugins such as datasette-auth-passwords as an attacker could use the vulnerability to access protected data. Datasette 0.57 and 0.56.1 both include patches for this issue. If you run Datasette behind a proxy you can workaround this issue by rejecting any incoming requests with ?_trace= or &_trace= in their query string parameters.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:datasette:datasette:*:*:*:*:*:*:*:*
Версия до 0.56.1 (исключая)

EPSS

Процентиль: 68%
0.00594
Низкий

7.2 High

CVSS3

6.1 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 7.2
github
около 4 лет назад

Reflected cross-site scripting issue in Datasette

EPSS

Процентиль: 68%
0.00594
Низкий

7.2 High

CVSS3

6.1 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-79