PT-2022-10887 · Smallrye · Smallrye

Chess Hazlett

·

Published

2022-08-25

·

Updated

2022-09-02

·

CVE-2021-3914

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions smallrye (affected versions not specified)
Description The smallrye health metrics UI component did not properly sanitize some user inputs, allowing an attacker to conduct cross-site scripting attacks.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2021-3914
GHSA-PVC3-WVXR-7CMF

Affected Products

Smallrye