Описание
The VisualEditor extension through 1.34 for MediaWiki allows XSS via pasted content containing an element with a data-ve-clipboard-key attribute.
Отчет
The VisualEditor extension of MediaWiki is not included in OpenShift Container Platform.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat OpenShift Container Platform 3.11 | mediawiki | Not affected | ||
| Red Hat OpenShift Container Platform 4 | mediawiki | Not affected |
Показывать по
10
Дополнительная информация
Статус:
Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=1809045mediawiki: pasted content containing an element with a specific attribute allows for XSS
6.1 Medium
CVSS3
Связанные уязвимости
CVSS3: 6.1
nvd
около 6 лет назад
The VisualEditor extension through 1.34 for MediaWiki allows XSS via pasted content containing an element with a data-ve-clipboard-key attribute.
github
больше 3 лет назад
The VisualEditor extension through 1.34 for MediaWiki allows XSS via pasted content containing an element with a data-ve-clipboard-key attribute.
6.1 Medium
CVSS3