Beveiligingsadvies

CVE-2020-8031

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2021-02-11 15:10:15
Laatst bijgewerkt 2024-09-16 18:08:47
Toegewezen door suse
CVSS-score 6.3
Status PUBLISHED

Beschrijving

A Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Open Build Service allows remote attackers to store JS code in markdown that is not properly escaped, impacting confidentiality and integrity. This issue affects: Open Build Service versions prior to 2.10.8.