Pixar's Tractor software, versions 2.2 and earlier, contains a stored cross-site scripting vulnerability
Published Dec 13, 2018
5.4
MEDIUMCVSS 3.0
EPSS 0.79%
Description
Pixar's Tractor software, versions 2.2 and earlier, contain a stored cross-site scripting vulnerability in the field that allows a user to add a note to an existing node. The stored information is displayed when a user requests information about the node. An attacker could insert Javascript into this note field that is then saved and displayed to the end user. An attacker might include Javascript that could execute on an authenticated user's system that could lead to website redirects, session cookie hijacking, social engineering, etc. As this is stored with the information about the node, all other authenticated users with access to this data are also vulnerable.
Affected products
-
- Version 2.2StatusaffectedConstraints<=2.2
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Pixar has released an updated version of this software that mitigates this vulnerability, Tractor version 2.3 (build 1923604). Affected users should update to this version.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
AV:N/AC:M/Au:S/C:N/I:P/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Table of values (11 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.79% (0.00786) | 54.50th | v5 (v2026.06.15) |
| Sep 20, 2026 | 0.79% (0.00786) | 54.60th | v5 (v2026.06.15) |
| Jul 20, 2024 | 0.05% (0.00050) | 19.93th | v3 (v2023.03.01) |
| Jun 12, 2024 | 0.05% (0.00050) | 19.29th | v3 (v2023.03.01) |
| Jun 5, 2024 | 0.05% (0.00050) | 17.27th | v3 (v2023.03.01) |
| Oct 19, 2023 | 0.05% (0.00054) | 19.68th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.06% (0.00057) | 21.77th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.89% (0.00885) | 27.89th | v2 (v2022.01.01) |
| Feb 4, 2022 | 0.89% (0.00885) | 10.50th | v2 (v2022.01.01) |
| Feb 3, 2022 | 0.66% (0.00663) | 18.75th | v5 (v2026.06.15) |
| Apr 14, 2021 | 0.66% (0.00663) | 0.00th | v1 |
References (2)
- http://www.securityfocus.com/bid/106209 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://www.kb.cert.org/vuls/id/756913/ third-party-advisoryx_refsource_CERT-VNThird Party AdvisoryUS Government Resource
| Link | Providers | Tags |
|---|---|---|
| http://www.securityfocus.com/bid/106209 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| https://www.kb.cert.org/vuls/id/756913/ | third-party-advisoryx_refsource_CERT-VNThird Party AdvisoryUS Government Resource |
Change history (0)
No recorded changes yet.