MEDIUM
snoyberg keter Proxy.hs cross site scripting
Published Jan 5, 2023
6.1
MEDIUMCVSS 3.1
EPSS 0.53%
Description
A vulnerability has been found in snoyberg keter up to 1.8.1 and classified as problematic. This vulnerability affects unknown code of the file Keter/Proxy.hs. The manipulation of the argument host leads to cross site scripting. The attack can be initiated remotely. Upgrading to version 1.8.2 is able to address this issue. The name of the patch is d41f3697926b231782a3ad8050f5af1ce5cc40b7. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-217444.
Affected products
-
- Version 1.8.0StatusaffectedConstraints-
- Version 1.8.1StatusaffectedConstraints-
- Version
- < 1.8.2
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- https://github.com/snoyberg/keter/commit/d41f3697926b231782a3ad8050f5af1ce5cc40b7 patchThird Party Advisory
- https://github.com/snoyberg/keter/pull/246 issue-trackingPatchThird Party Advisory
- https://github.com/snoyberg/keter/releases/tag/keter%2F1.8.2 patchRelease NotesThird Party Advisory
- https://vuldb.com/?ctiid.217444 signaturepermissions-requiredThird Party Advisory
- https://vuldb.com/?id.217444 vdb-entrytechnical-descriptionThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/snoyberg/keter/commit/d41f3697926b231782a3ad8050f5af1ce5cc40b7 | patchThird Party Advisory | |
| https://github.com/snoyberg/keter/pull/246 | issue-trackingPatchThird Party Advisory | |
| https://github.com/snoyberg/keter/releases/tag/keter%2F1.8.2 | patchRelease NotesThird Party Advisory | |
| https://vuldb.com/?ctiid.217444 | signaturepermissions-requiredThird Party Advisory | |
| https://vuldb.com/?id.217444 | vdb-entrytechnical-descriptionThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Jan 5, 2023
Updated Aug 3, 2024
Reserved Jan 5, 2023
Link CVE-2022-4877
CISA Vulnrichment
Updated n/a