Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-13083

Опубликовано: 23 июн. 2026
Источник: redhat
CVSS3: 6.9

Описание

A flaw was found in the Pen Drive report generator. Cluster-sourced data is rendered into HTML reports without proper escaping or sanitization. An attacker with cluster administrator privileges can inject a stored cross-site scripting (XSS) payload into cluster objects (such as ClusterVersion spec.channel) that executes in the browser of any user who opens the generated HTML report.

Отчет

This flaw affects Pen Drive versions prior to 1.0.0-2. The vulnerability requires cluster administrator privileges to inject the XSS payload and user interaction (opening the report) for exploitation, limiting the attack surface. The fix is available in Pen Drive 1.0.0-2. The most likely exploitation scenario involves a compromised cluster producing a poisoned must-gather archive that is then processed by Pen Drive, with the resulting report opened by a support engineer.

Меры по смягчению последствий

The following practices would help for avoiding exposure and mitigate this flaw:

  • Upgrade Pen Drive to version 1.0.0-2 or later, which reportedly contains the fix.
  • Until upgraded, review HTML reports generated by Pen Drive before opening them in a browser, or open them in a sandboxed browser environment.
  • If using must-gather archives from untrusted sources, validate the archive content before feeding it to Pen Drive.
  • Consider opening Pen Drive reports with JavaScript disabled in the browser.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Pen Drive Powered by Red Hat Lightspeedpen-drive/pen-drive-scanner-rhel9Fix deferred
Pen Drive Powered by Red Hat Lightspeedpen-drive/pen-drive-scanner-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2491886pen-drive: pen-drive: stored XSS via unescaped cluster data in HTML report

6.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.9
nvd
около 2 месяцев назад

A flaw was found in the Pen Drive report generator. Cluster-sourced data is rendered into HTML reports without proper escaping or sanitization. An attacker with cluster administrator privileges can inject a stored cross-site scripting (XSS) payload into cluster objects (such as ClusterVersion spec.channel) that executes in the browser of any user who opens the generated HTML report.

CVSS3: 6.9
github
около 2 месяцев назад

A flaw was found in the Pen Drive report generator. Cluster-sourced data is rendered into HTML reports without proper escaping or sanitization. An attacker with cluster administrator privileges can inject a stored cross-site scripting (XSS) payload into cluster objects (such as ClusterVersion spec.channel) that executes in the browser of any user who opens the generated HTML report.

6.9 Medium

CVSS3