PT-2020-19923 · Open Build Service · Open Build Service
Marcus Meissner
+1
·
Published
2020-05-13
·
Updated
2021-03-15
·
CVE-2020-8020
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
open-build-service versions prior to 7cc32c8e2ff7290698e101d9a80a9dc29a5500fb
Description
A Improper Neutralization of Input During Web Page Generation issue allows remote attackers to store arbitrary JS code, causing XSS.
Recommendations
For versions prior to 7cc32c8e2ff7290698e101d9a80a9dc29a5500fb, update to a version that includes the fix for this issue to prevent remote attackers from storing arbitrary JS code and causing XSS.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Open Build Service