Back

MEDIUM

jaeger-ui: xss allows an attacker to perform arbitrary jaeger queries and exfiltrate returned data

Published Jul 17, 2023

Description

Cross Site Scripting (XSS) vulnerability in Jaegertracing Jaeger UI before v.1.31.0 allows a remote attacker to execute arbitrary code via the KeyValuesTable component.

Affected products

Remediation

Red Hat statement

KeyValuesTable.tsx is only referenced by AccordianKeyValues.tsx, which does not reference the offending routine formatValue.

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jul 17, 2023
Updated Oct 30, 2024
Reserved Jun 25, 2023
CISA Vulnrichment
Updated Oct 30, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jul 17, 2023