PT-2021-20871 · Unknown · Noobaa-Core
Pedro Sampaio
·
Published
2021-06-02
·
Updated
2021-06-15
·
CVE-2021-3529
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions:
noobaa-core versions prior to 5.7.0
Description:
A flaw in noobaa-core results in the name of an arbitrarily URL being copied into an HTML document as plain text between tags, including potentially a payload script. The input was echoed unmodified in the application response, resulting in arbitrary JavaScript being injected into an application's response. The highest threat to the system is for confidentiality, availability, and integrity.
Recommendations:
For versions prior to 5.7.0, update to version 5.7.0 or later to resolve the issue. As a temporary workaround, consider restricting the input that can be echoed in the application response to prevent arbitrary JavaScript injection.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Noobaa-Core