Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Dumbmoron

#44312of 53,633
6Total CVSS
Vulnerabilities · 1
PT-2024-34662
6.0
2024-11-04
Cobalt · Cobalt · CVE-2024-51498
**Name of the Vulnerable Software and Affected Versions** cobalt versions prior to 10.2.1 **Description** A malicious cobalt instance could serve links with the `javascript:` protocol, resulting in Cross-site Scripting (XSS) when the user tries to download an item from a picker. This issue has been present since commit `66bac03e` and was mitigated in commit `97977efa` for correctly configured web instances. **Recommendations** For versions prior to 10.2.1, upgrade to version 10.2.1 or later to fully resolve the issue. For users unable to upgrade, enable a content-security-policy as a temporary mitigation measure.