Stored XSS in Kubeflow Pipeline View
Published Nov 18, 2024
7.1
HIGHCVSS 4.0
EPSS 0.21%
Description
There exists a stored XSS Vulnerability in Kubeflow Pipeline View web UI. The Kubeflow Web UI allows to create new pipelines. When creating a new pipeline, it is possible to add a description. The description field allows html tags, which are not filtered properly. Leading to a stored XSS. We recommend upgrading past commit 930c35f1c543998e60e8d648ce93185c9b5dbe8d
Affected products
-
- Version 0StatusaffectedConstraints
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Kubeflow | Kubeflow Pipeline View | unaffected |
|
-
- Version 0StatusaffectedConstraints
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Kubeflow | Kubeflow W Pipeline View | n/a |
|
No Red Hat product state for this CVE.
github.com/kubeflow/pipelines
Go
Introduced 0 Fixed not fixed
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/kubeflow/pipelines | 0 | not fixed |
Remediation
No remediation recorded yet.
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-50317 Advisory
- https://github.com/kubeflow/pipelines/pull/10315 Issue TrackingPatch
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-50317 | Advisory | |
| https://github.com/kubeflow/pipelines/pull/10315 | Issue TrackingPatch |
Change history (0)
No recorded changes yet.