A flaw was found in noobaa-core in versions before 5.7.0. This flaw results in the name of an arbitrarily URL being copied into an HTML document as plain text between tags, including potentially a payload script. The input was echoed unmodified in the application response, resulting in arbitrary JavaScript being injected into an application's response. The highest threat to the system is for confidentiality, availability, and integrity.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2021-06-02T16:10:51

Updated: 2024-08-03T17:01:07.751Z

Reserved: 2021-04-30T00:00:00

Link: CVE-2021-3529

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-06-02T17:15:08.660

Modified: 2021-06-15T16:48:52.097

Link: CVE-2021-3529

cve-icon Redhat

Severity : Moderate

Publid Date: 2021-04-16T00:00:00Z

Links: CVE-2021-3529 - Bugzilla