PT-2024-37737 · Lightdash · Lightdash

Kennethchiong

·

Published

2024-08-30

·

Updated

2024-09-03

·

CVE-2024-6585

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Lightdash version 0.1024.6
Description Multiple stored cross-site scripting (XSS) vulnerabilities in the markdown dashboard and dashboard comment functionality allow remote authenticated threat actors to inject malicious scripts into vulnerable web pages. A threat actor could potentially exploit this vulnerability to store malicious JavaScript which executes in the context of a user’s session with the application.
Recommendations For version 0.1024.6, consider upgrading to a newer version to mitigate the risk of compromised user data and sessions. As a temporary workaround, restrict access to the markdown dashboard and dashboard comment functionality to minimize the risk of exploitation. Avoid using the vulnerable functionality until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-6585
GHSA-6529-6JV3-66Q2

Affected Products

Lightdash