OpenObserve Cross-site Scripting (XSS) vulnerability in `openobserve/web/src/views/MemberSubscription.vue`
Published Jul 25, 2024
7.2
HIGHCVSS 3.1
EPSS 0.36%
Description
OpenObserve is an open-source observability platform. Starting in version 0.4.4 and prior to version 0.10.0, OpenObserve contains a cross-site scripting vulnerability in line 32 of `openobserve/web/src/views/MemberSubscription.vue`. Version 0.10.0 sanitizes incoming html.
Affected products
-
Affected
- ≥ 0.4.4, < 0.10.0
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Openobserve | Openobserve | unknown | Affected
|
- ≥ 0.4.4 · < 0.10.0
-
Affected
- ≥ 0.4.4, < 0.10.0
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Openobserve | Openobserve | unknown | Affected
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-39198 Advisory
- https://github.com/openobserve/openobserve/blob/v0.5.2/web/src/views/MemberSubscription.vue#L32 x_refsource_MISCProduct
- https://github.com/openobserve/openobserve/commit/2334377ebc8b74beb06ab3e5712dbdb1be1eff02 x_refsource_MISCPatch
- https://github.com/openobserve/openobserve/commit/64587261968217dfb8af4c4f6054d58bbc6d331d x_refsource_MISCPatch
- https://github.com/openobserve/openobserve/security/advisories/GHSA-rw8w-37p9-mrrp x_refsource_CONFIRMThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-39198 | Advisory | |
| https://github.com/openobserve/openobserve/blob/v0.5.2/web/src/views/MemberSubscription.vue#L32 | x_refsource_MISCProduct | |
| https://github.com/openobserve/openobserve/commit/2334377ebc8b74beb06ab3e5712dbdb1be1eff02 | x_refsource_MISCPatch | |
| https://github.com/openobserve/openobserve/commit/64587261968217dfb8af4c4f6054d58bbc6d331d | x_refsource_MISCPatch | |
| https://github.com/openobserve/openobserve/security/advisories/GHSA-rw8w-37p9-mrrp | x_refsource_CONFIRMThird Party Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data