Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-3529

Опубликовано: 02 июн. 2021
Источник: nvd
CVSS3: 7.1
CVSS2: 6.8
EPSS Низкий

Описание

A flaw was found in noobaa-core in versions before 5.7.0. This flaw results in the name of an arbitrarily URL being copied into an HTML document as plain text between tags, including potentially a payload script. The input was echoed unmodified in the application response, resulting in arbitrary JavaScript being injected into an application's response. The highest threat to the system is for confidentiality, availability, and integrity.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:redhat:noobaa-operator:*:*:*:*:*:*:*:*
Версия до 5.7.0 (исключая)
Конфигурация 2
cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*

EPSS

Процентиль: 45%
0.00225
Низкий

7.1 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 7.1
redhat
почти 5 лет назад

A flaw was found in noobaa-core in versions before 5.7.0. This flaw results in the name of an arbitrarily URL being copied into an HTML document as plain text between tags, including potentially a payload script. The input was echoed unmodified in the application response, resulting in arbitrary JavaScript being injected into an application's response. The highest threat to the system is for confidentiality, availability, and integrity.

github
больше 3 лет назад

A flaw was found in noobaa-core in versions before 5.7.0. This flaw results in the name of an arbitrarily URL being copied into an HTML document as plain text between tags, including potentially a payload script. The input was echoed unmodified in the application response, resulting in arbitrary JavaScript being injected into an application's response. The highest threat to the system is for confidentiality, availability, and integrity.

EPSS

Процентиль: 45%
0.00225
Низкий

7.1 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-79