Логотип exploitDog
bind:CVE-2021-43776
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-43776

Количество 2

Количество 2

nvd логотип

CVE-2021-43776

около 4 лет назад

Backstage is an open platform for building developer portals. In affected versions the auth-backend plugin allows a malicious actor to trick another user into visiting a vulnerable URL that executes an XSS attack. This attack can potentially allow the attacker to exfiltrate access tokens or other secrets from the user's browser. The default CSP does prevent this attack, but it is expected that some deployments have these policies disabled due to incompatibilities. This is vulnerability is patched in version `0.4.9` of `@backstage/plugin-auth-backend`.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-w7fj-336r-vw49

около 4 лет назад

Cross-Site Scripting vulnerability in @backstage/plugin-auth-backend

CVSS3: 7.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-43776

Backstage is an open platform for building developer portals. In affected versions the auth-backend plugin allows a malicious actor to trick another user into visiting a vulnerable URL that executes an XSS attack. This attack can potentially allow the attacker to exfiltrate access tokens or other secrets from the user's browser. The default CSP does prevent this attack, but it is expected that some deployments have these policies disabled due to incompatibilities. This is vulnerability is patched in version `0.4.9` of `@backstage/plugin-auth-backend`.

CVSS3: 7.4
0%
Низкий
около 4 лет назад
github логотип
GHSA-w7fj-336r-vw49

Cross-Site Scripting vulnerability in @backstage/plugin-auth-backend

CVSS3: 7.4
0%
Низкий
около 4 лет назад

Уязвимостей на страницу