PT-2021-20871 · Unknown · Noobaa-Core

Pedro Sampaio

·

Published

2021-06-02

·

Updated

2021-06-15

·

CVE-2021-3529

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions: noobaa-core versions prior to 5.7.0
Description: A flaw in noobaa-core results in the name of an arbitrarily URL being copied into an HTML document as plain text between tags, including potentially a payload script. The input was echoed unmodified in the application response, resulting in arbitrary JavaScript being injected into an application's response. The highest threat to the system is for confidentiality, availability, and integrity.
Recommendations: For versions prior to 5.7.0, update to version 5.7.0 or later to resolve the issue. As a temporary workaround, consider restricting the input that can be echoed in the application response to prevent arbitrary JavaScript injection.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-3529

Affected Products

Noobaa-Core