Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-3650

Опубликовано: 24 окт. 2014
Источник: redhat
CVSS2: 4.3
EPSS Низкий

Описание

Multiple persistent cross-site scripting (XSS) flaws were found in the way Aerogear handled certain user-supplied content. A remote attacker could use these flaws to compromise the application with specially crafted input.

Отчет

Not Vulnerable. Aerogear is not provided by any Red Hat product.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Enterprise Web Server 1mobileNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=1144212AeroGear: stored XSS via deviceToken

EPSS

Процентиль: 37%
0.00156
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

CVSS3: 5.4
nvd
больше 3 лет назад

Multiple persistent cross-site scripting (XSS) flaws were found in the way Aerogear handled certain user-supplied content. A remote attacker could use these flaws to compromise the application with specially crafted input.

CVSS3: 5.4
github
больше 3 лет назад

Multiple persistent cross-site scripting (XSS) flaws were found in the way Aerogear handled certain user-supplied content. A remote attacker could use these flaws to compromise the application with specially crafted input.

EPSS

Процентиль: 37%
0.00156
Низкий

4.3 Medium

CVSS2