Immuta v2.8.2 is affected by stored XSS that allows a low-privileged user to escalate privileges to administrative permissions. Additionally, unauthenticated attackers can phish unauthenticated Immuta users to steal credentials or force actions on authenticated users through reflected, DOM-based XSS.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2020-11-05T14:30:49
Updated: 2024-08-04T13:30:23.513Z
Reserved: 2020-07-26T00:00:00
Link: CVE-2020-15952
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2020-11-05T15:15:32.767
Modified: 2020-11-12T18:17:34.790
Link: CVE-2020-15952
Redhat
No data.