Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-2142

Опубликовано: 26 нояб. 2024
Источник: redhat
CVSS3: 5.4

Описание

In Nunjucks versions prior to version 3.2.4, it was possible to bypass the restrictions which are provided by the autoescape functionality. If there are two user-controlled parameters on the same line used in the views, it was possible to inject cross site scripting payloads using the backslash \ character.

A flaw was found in Nunjucks versions prior to 3.2.4. This vulnerability can allow attackers to inject cross-site scripting (XSS) payloads via bypassing autoescape functionality by using a backslash () character when two user-controlled parameters are on the same line in the views.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Developer Hubrhdh-hub-containerNot affected
Red Hat Developer Hubrhdh-operator-containerNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2328903Nunjucks: Nunjucks autoescape bypass leads to cross site scripting

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
почти 2 года назад

In Nunjucks versions prior to version 3.2.4, it was possible to bypass the restrictions which are provided by the autoescape functionality. If there are two user-controlled parameters on the same line used in the views, it was possible to inject cross site scripting payloads using the backslash \ character.

CVSS3: 6.1
nvd
почти 2 года назад

In Nunjucks versions prior to version 3.2.4, it was possible to bypass the restrictions which are provided by the autoescape functionality. If there are two user-controlled parameters on the same line used in the views, it was possible to inject cross site scripting payloads using the backslash \ character.

CVSS3: 6.1
debian
почти 2 года назад

In Nunjucks versions prior to version 3.2.4, it was possible to bypas ...

CVSS3: 6.1
github
больше 3 лет назад

Nunjucks autoescape bypass leads to cross site scripting

5.4 Medium

CVSS3