There were XSS vulnerabilities discovered and reported in the Dispatch application, affecting name and description parameters of Incident Priority, Incident Type, Tag Type, and Incident Filter. This vulnerability can be exploited by an authenticated user.
References
Link | Resource |
---|---|
https://github.com/Netflix/dispatch/releases/tag/v20201106 | Third Party Advisory |
https://github.com/Netflix/security-bulletins/blob/master/advisories/nflx-2020-004.md | Third Party Advisory |
https://github.com/Netflix/dispatch/releases/tag/v20201106 | Third Party Advisory |
https://github.com/Netflix/security-bulletins/blob/master/advisories/nflx-2020-004.md | Third Party Advisory |
Configurations
History
21 Nov 2024, 05:40
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/Netflix/dispatch/releases/tag/v20201106 - Third Party Advisory | |
References | () https://github.com/Netflix/security-bulletins/blob/master/advisories/nflx-2020-004.md - Third Party Advisory |
Information
Published : 2020-11-09 15:15
Updated : 2024-11-21 05:40
NVD link : CVE-2020-9299
Mitre link : CVE-2020-9299
CVE.ORG link : CVE-2020-9299
JSON object : View
Products Affected
netflix
- dispatch
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')