Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-42346

Опубликовано: 20 сент. 2024
Источник: nvd
CVSS3: 7.6
CVSS3: 5.4
EPSS Низкий

Описание

Galaxy is a free, open-source system for analyzing data, authoring workflows, training and education, publishing tools, managing infrastructure, and more. The editor visualization, /visualizations endpoint, can be used to store HTML tags and trigger javascript execution upon edit operation. All supported branches of Galaxy (and more back to release_20.05) were amended with the supplied patches. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:galaxyproject:galaxy:*:*:*:*:*:*:*:*
Версия до 24.1.1 (исключая)

EPSS

Процентиль: 92%
0.07854
Низкий

7.6 High

CVSS3

5.4 Medium

CVSS3

Дефекты

CWE-79

EPSS

Процентиль: 92%
0.07854
Низкий

7.6 High

CVSS3

5.4 Medium

CVSS3

Дефекты

CWE-79