Опубликовано: 20 мар. 2020
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4.3
CVSS3: 6.1
Описание
RainLoop Webmail before 1.13.0 lacks XSS protection mechanisms such as xlink:href validation, the X-XSS-Protection header, and the Content-Security-Policy header.
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | DNE | |
| devel | DNE | |
| eoan | ignored | end of life |
| esm-apps/focal | needed | |
| esm-apps/jammy | not-affected | 1.14.0-2 |
| esm-infra-legacy/trusty | DNE | |
| focal | ignored | end of standard support, was needed |
| groovy | not-affected | 1.14.0-2 |
| hirsute | not-affected | 1.14.0-2 |
| impish | not-affected | 1.14.0-2 |
Показывать по
10
EPSS
Процентиль: 42%
0.00199
Низкий
4.3 Medium
CVSS2
6.1 Medium
CVSS3
Связанные уязвимости
CVSS3: 6.1
nvd
почти 6 лет назад
RainLoop Webmail before 1.13.0 lacks XSS protection mechanisms such as xlink:href validation, the X-XSS-Protection header, and the Content-Security-Policy header.
CVSS3: 6.1
debian
почти 6 лет назад
RainLoop Webmail before 1.13.0 lacks XSS protection mechanisms such as ...
CVSS3: 6.1
github
больше 3 лет назад
RainLoop Webmail before 1.13.0 lacks XSS protection mechanisms such as xlink:href validation, the X-XSS-Protection header, and the Content-Security-Policy header.
EPSS
Процентиль: 42%
0.00199
Низкий
4.3 Medium
CVSS2
6.1 Medium
CVSS3