Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-6778

Опубликовано: 18 дек. 2023
Источник: nvd
CVSS3: 5.4
CVSS3: 5.4
EPSS Низкий

Описание

Cross-site Scripting (XSS) - Stored in GitHub repository allegroai/clearml-server prior to 1.13.0.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:clear:clearml_server:*:*:*:*:*:*:*:*
Версия до 1.13.0 (исключая)

EPSS

Процентиль: 42%
0.00195
Низкий

5.4 Medium

CVSS3

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 7.5
github
около 2 лет назад

Cross-site Scripting (XSS) - Stored in GitHub repository allegroai/clearml-server prior to 1.13.0. This vulnerability affects the ClearML Open Source Server which is not designed to be used as a publicly available service. Security recommendations stress it should be placed behind a company firewall or VPN. This vulnerability only affects users within the same organisation (I.e when a malicious party already has access to the internal network and to a user's ClearML login credentials).

EPSS

Процентиль: 42%
0.00195
Низкий

5.4 Medium

CVSS3

5.4 Medium

CVSS3

Дефекты

CWE-79