PT-2020-19923 · Open Build Service · Open Build Service

Marcus Meissner

+1

·

Published

2020-05-13

·

Updated

2021-03-15

·

CVE-2020-8020

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions open-build-service versions prior to 7cc32c8e2ff7290698e101d9a80a9dc29a5500fb
Description A Improper Neutralization of Input During Web Page Generation issue allows remote attackers to store arbitrary JS code, causing XSS.
Recommendations For versions prior to 7cc32c8e2ff7290698e101d9a80a9dc29a5500fb, update to a version that includes the fix for this issue to prevent remote attackers from storing arbitrary JS code and causing XSS.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-8020
DLA-2545-1

Affected Products

Open Build Service