MEDIUM
RDFlib pyrdfa3 __init__.py _get_option cross site scripting
Published Dec 10, 2022
5.4
MEDIUMCVSS 3.1
EPSS 0.59%
Description
A vulnerability was found in RDFlib pyrdfa3 and classified as problematic. This issue affects the function _get_option of the file pyRdfa/__init__.py. The manipulation leads to cross site scripting. The attack may be initiated remotely. The name of the patch is ffd1d62dd50d5f4190013b39cedcdfbd81f3ce3e. It is recommended to apply a patch to fix this issue. The identifier VDB-215249 was assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Affected products
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (6)
- https://github.com/RDFLib/pyrdfa3/commit/ffd1d62dd50d5f4190013b39cedcdfbd81f3ce3e PatchThird Party Advisory
- https://github.com/RDFLib/pyrdfa3/issues/38
- https://github.com/RDFLib/pyrdfa3/pull/40 Issue TrackingPatchThird Party Advisory
- https://github.com/advisories/GHSA-894q-wpg5-mf2h Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-4396
- https://vuldb.com/?id.215249 Third Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/RDFLib/pyrdfa3/commit/ffd1d62dd50d5f4190013b39cedcdfbd81f3ce3e | PatchThird Party Advisory | |
| https://github.com/RDFLib/pyrdfa3/issues/38 | ||
| https://github.com/RDFLib/pyrdfa3/pull/40 | Issue TrackingPatchThird Party Advisory | |
| https://github.com/advisories/GHSA-894q-wpg5-mf2h | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-4396 | ||
| https://vuldb.com/?id.215249 | Third Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Dec 10, 2022
Updated Apr 15, 2025
Reserved Dec 10, 2022
Link CVE-2022-4396
CISA Vulnrichment
GHSA-894Q-WPG5-MF2H Updated Apr 14, 2025