Back

HIGH

Stored XSS in Kubeflow Pipeline View

Published Nov 18, 2024

Description

There exists a stored XSS Vulnerability in Kubeflow Pipeline View web UI. The Kubeflow Web UI allows to create new pipelines. When creating a new pipeline, it is possible to add a description. The description field allows html tags, which are not filtered properly. Leading to a stored XSS. We recommend upgrading past commit 930c35f1c543998e60e8d648ce93185c9b5dbe8d

Affected products

Remediation

No remediation recorded yet.

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Google
Published Nov 18, 2024
Updated Nov 21, 2024
Reserved Oct 4, 2024
CISA Vulnrichment
Updated Nov 18, 2024
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner Google
Published Nov 18, 2024
Updated Nov 21, 2024
Exploited since n/a
EUVD-2024-50317