6.1

CVE-2022-42466

XSS vulnerability, eg for String properties.

Prior to 2.0.0-M9, it was possible for an end-user to set the value of an editable string property of a domain object to a value that would be rendered unchanged when the value was saved. In particular, the end-user could enter javascript or similar and this would be executed. As of this release, the inputted strings are properly escaped when rendered.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apache ≫ Isis Version < 2.0.0
Apache ≫ Isis Version 2.0.0 Update milestone1
Apache ≫ Isis Version 2.0.0 Update milestone2
Apache ≫ Isis Version 2.0.0 Update milestone3
Apache ≫ Isis Version 2.0.0 Update milestone4
Apache ≫ Isis Version 2.0.0 Update milestone5
Apache ≫ Isis Version 2.0.0 Update milestone6
Apache ≫ Isis Version 2.0.0 Update milestone7
Apache ≫ Isis Version 2.0.0 Update milestone8
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.26% 0.671
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CISA-ADP 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

http://www.openwall.com/lists/oss-security/2022/10/19/2
Third Party Advisory
Mailing List
https://lists.apache.org/thread/83ftj5jgtv3mbm28w3trjyvd591jztrz
Vendor Advisory
Mailing List