Description
A flaw was found in noobaa-core in versions before 5.7.0. This flaw results in the name of an arbitrarily URL being copied into an HTML document as plain text between tags, including potentially a payload script. The input was echoed unmodified in the application response, resulting in arbitrary JavaScript being injected into an application's response. The highest threat to the system is for confidentiality, availability, and integrity.
Published: 2021-06-02
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2021-26845 A flaw was found in noobaa-core in versions before 5.7.0. This flaw results in the name of an arbitrarily URL being copied into an HTML document as plain text between tags, including potentially a payload script. The input was echoed unmodified in the application response, resulting in arbitrary JavaScript being injected into an application's response. The highest threat to the system is for confidentiality, availability, and integrity.
History

No history.

Subscriptions

Redhat Noobaa-operator Openshift Container Platform Openshift Container Storage
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-03T17:01:07.751Z

Reserved: 2021-04-30T00:00:00.000Z

Link: CVE-2021-3529

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-06-02T17:15:08.660

Modified: 2024-11-21T06:21:46.380

Link: CVE-2021-3529

cve-icon Redhat

Severity : Moderate

Publid Date: 2021-04-16T00:00:00Z

Links: CVE-2021-3529 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses