Cross-site scripting (XSS) vulnerability in the Web UI of StackStorm versions prior to 3.8.0 allowed logged in users with write access to pack rules to inject arbitrary script or HTML that may be executed in Web UI for other logged in users.
References
Link | Resource |
---|---|
https://stackstorm.com/2022/12/v3-8-0-released/ | Vendor Advisory |
https://stackstorm.com/2022/12/v3-8-0-released/ | Vendor Advisory |
Configurations
History
21 Nov 2024, 07:27
Type | Values Removed | Values Added |
---|---|---|
References | () https://stackstorm.com/2022/12/v3-8-0-released/ - Vendor Advisory |
Information
Published : 2022-12-05 23:15
Updated : 2024-11-21 07:27
NVD link : CVE-2022-43706
Mitre link : CVE-2022-43706
CVE.ORG link : CVE-2022-43706
JSON object : View
Products Affected
stackstorm
- stackstorm
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')