MEDIUM 5.4 PyPI
Koji Cross-site Scripting
GHSA-g2vg-8hfg-79vj · CVE-2024-9427
Published · Modified
Description
A vulnerability in Koji was found. An unsanitized input allows for an XSS attack. Javascript code from a malicious link could be reflected in the resulting web page. It is not expected to be able to submit an action or make a change in Koji due to existing XSS protections in the code.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2024-9427
- WEB https://access.redhat.com/security/cve/CVE-2024-9427
- WEB https://bugzilla.redhat.com/show_bug.cgi?id=2316047
- WEB https://docs.pagure.org/koji/CVEs/CVE-2024-9427
- PACKAGE https://pagure.io/koji
- WEB https://pagure.io/koji/c/8c72d90d7bb991f8fb193851b80847ac9e9474a4?branch=master
Ready to move
Start Securing
Free, no credit card | First findings in minutes