Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-10215

Опубликовано: 02 окт. 2019
Источник: redhat
CVSS3: 6.1

Описание

Bootstrap-3-Typeahead after version 4.0.2 is vulnerable to a cross-site scripting flaw in the highlighter() function. An attacker could exploit this via user interaction to execute code in the user's browser.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 3.10golang-github-prometheus-prometheusNot affected
Red Hat OpenShift Container Platform 3.11golang-github-prometheus-prometheusNot affected
Red Hat OpenShift Container Platform 3.9golang-github-prometheus-prometheusNot affected
Red Hat OpenShift Container Platform 4.2openshift4/ose-prometheusFixedRHSA-2019:377113.11.2019

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=1735506bootstrap3-typeahead.js: Cross-site scripting via highlighter() function

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
nvd
больше 6 лет назад

Bootstrap-3-Typeahead after version 4.0.2 is vulnerable to a cross-site scripting flaw in the highlighter() function. An attacker could exploit this via user interaction to execute code in the user's browser.

suse-cvrf
больше 5 лет назад

Security update for SUSE Manager Client Tools

suse-cvrf
больше 5 лет назад

Security update for SUSE Manager Client Tools

6.1 Medium

CVSS3