Описание
In Apollo change requests, comments added by users could contain a javascript URI link that when rendered will result in an XSS that require user interaction.
Ссылки
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.308.0 (исключая)
cpe:2.3:a:palantir:apollo_autopilot:*:*:*:*:*:*:*:*
EPSS
Процентиль: 39%
0.00175
Низкий
4.1 Medium
CVSS3
5.4 Medium
CVSS3
Дефекты
CWE-84
CWE-79
Связанные уязвимости
CVSS3: 4.1
github
больше 2 лет назад
In Apollo change requests, comments added by users could contain a javascript URI link that when rendered will result in an XSS that require user interaction.
EPSS
Процентиль: 39%
0.00175
Низкий
4.1 Medium
CVSS3
5.4 Medium
CVSS3
Дефекты
CWE-84
CWE-79