PT-2024-37737 · Lightdash · Lightdash
Kennethchiong
·
Published
2024-08-30
·
Updated
2024-09-03
·
CVE-2024-6585
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Lightdash version 0.1024.6
Description
Multiple stored cross-site scripting (XSS) vulnerabilities in the markdown dashboard and dashboard comment functionality allow remote authenticated threat actors to inject malicious scripts into vulnerable web pages. A threat actor could potentially exploit this vulnerability to store malicious JavaScript which executes in the context of a user’s session with the application.
Recommendations
For version 0.1024.6, consider upgrading to a newer version to mitigate the risk of compromised user data and sessions. As a temporary workaround, restrict access to the markdown dashboard and dashboard comment functionality to minimize the risk of exploitation. Avoid using the vulnerable functionality until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lightdash