PT-2023-30319 · Fides · Fides
H0Wl
+1
·
Publicado
2023-11-08
·
Atualizado
2023-11-16
·
CVE-2023-47114
CVSS v3.1
4.3
Média
| Vetor | AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Fides versions prior to 2.23.3
Description
The Fides web application is vulnerable to an HTML injection issue due to the lack of validation of input coming from connected systems and data stores. This can result in malicious JavaScript code execution or phishing attacks when a data subject user accesses an HTML page using the
file:// protocol. Exploitation is limited to rogue Admin UI users, malicious connected system or data store users, and the data subject user if tricked via social engineering into submitting malicious data themselves.Recommendations
For versions prior to 2.23.3, upgrade to version 2.23.3 or later to secure the system against this threat. As a temporary workaround, consider configuring the storage destination to use
json or csv instead of html as the package format to eliminate this vulnerability.Exploit
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Fides