Описание
Valhalla is an open source routing engine and accompanying libraries for use with OpenStreetMap data. Versions 3.6.3 and prior are vulnerable to reflected cross-site scripting (XSS) due to improper neutralization of input in the JSONP callback parameter. When a request specifies a JSONP callback, the value is reflected directly into the HTTP response body with Content-Type: application/javascript, without any validation, output encoding, or allowlist filtering. An attacker can craft a URL containing arbitrary JavaScript in the callback parameter; if a victim is induced to load that URL via a
EPSS
Процентиль: 5%
0.00149
Низкий
6.1 Medium
CVSS3
Дефекты
CWE-79
Связанные уязвимости
CVSS3: 6.1
debian
около 2 месяцев назад
Valhalla is an open source routing engine and accompanying libraries f ...
EPSS
Процентиль: 5%
0.00149
Низкий
6.1 Medium
CVSS3
Дефекты
CWE-79