Описание
In Nunjucks versions prior to version 3.2.4, it was
possible to bypass the restrictions which are provided by the autoescape
functionality. If there are two user-controlled parameters on the same
line used in the views, it was possible to inject cross site scripting
payloads using the backslash \ character.
A flaw was found in Nunjucks versions prior to 3.2.4. This vulnerability can allow attackers to inject cross-site scripting (XSS) payloads via bypassing autoescape functionality by using a backslash () character when two user-controlled parameters are on the same line in the views.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Developer Hub | rhdh-hub-container | Not affected | ||
| Red Hat Developer Hub | rhdh-operator-container | Not affected |
Показывать по
Дополнительная информация
Статус:
5.4 Medium
CVSS3
Связанные уязвимости
In Nunjucks versions prior to version 3.2.4, it was possible to bypass the restrictions which are provided by the autoescape functionality. If there are two user-controlled parameters on the same line used in the views, it was possible to inject cross site scripting payloads using the backslash \ character.
In Nunjucks versions prior to version 3.2.4, it was possible to bypass the restrictions which are provided by the autoescape functionality. If there are two user-controlled parameters on the same line used in the views, it was possible to inject cross site scripting payloads using the backslash \ character.
In Nunjucks versions prior to version 3.2.4, it was possible to bypas ...
Nunjucks autoescape bypass leads to cross site scripting
5.4 Medium
CVSS3