Scout is a web-based visualizer for VCF-files. Due to the lack of sanitization in the filename, it is possible bypass intended file extension and make users download malicious files with any extension. With malicious content injected inside the file data and users unknowingly downloading it and opening may lead to the compromise of users' devices or data. This vulnerability is fixed in 4.89.
History

Mon, 30 Sep 2024 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Clinical-genomics
Clinical-genomics scout
CPEs cpe:2.3:a:clinical-genomics:scout:-:*:*:*:*:*:*:*
Vendors & Products Clinical-genomics
Clinical-genomics scout
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 30 Sep 2024 15:45:00 +0000

Type Values Removed Values Added
Description Scout is a web-based visualizer for VCF-files. Due to the lack of sanitization in the filename, it is possible bypass intended file extension and make users download malicious files with any extension. With malicious content injected inside the file data and users unknowingly downloading it and opening may lead to the compromise of users' devices or data. This vulnerability is fixed in 4.89.
Title Scout contains insufficient output escaping of attachment names
Weaknesses CWE-116
References
Metrics cvssV3_1

{'score': 4.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-09-30T15:26:49.421Z

Updated: 2024-09-30T16:31:07.889Z

Reserved: 2024-09-25T21:46:10.929Z

Link: CVE-2024-47531

cve-icon Vulnrichment

Updated: 2024-09-30T16:31:02.300Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-09-30T16:15:09.750

Modified: 2024-10-04T13:51:25.567

Link: CVE-2024-47531

cve-icon Redhat

No data.