mirror of
https://github.com/fkie-cad/nvd-json-data-feeds.git
synced 2025-05-28 09:11:28 +00:00
60 lines
2.2 KiB
JSON
60 lines
2.2 KiB
JSON
{
|
|
"id": "CVE-2024-55888",
|
|
"sourceIdentifier": "security-advisories@github.com",
|
|
"published": "2024-12-12T20:15:22.017",
|
|
"lastModified": "2024-12-12T20:15:22.017",
|
|
"vulnStatus": "Awaiting Analysis",
|
|
"cveTags": [],
|
|
"descriptions": [
|
|
{
|
|
"lang": "en",
|
|
"value": "Hush Line is an open-source whistleblower management system. Starting in version 0.1.0 and prior to version 0.3.5, the productions server appeared to have been misconfigured and missed providing any content security policy or security headers. This could result in bypassing of cross-site scripting filters. Version 0.3.5 fixed the issue."
|
|
},
|
|
{
|
|
"lang": "es",
|
|
"value": "Hush Line es un sistema de gesti\u00f3n de denunciantes de c\u00f3digo abierto. A partir de la versi\u00f3n 0.1.0 y antes de la versi\u00f3n 0.3.5, el servidor de producci\u00f3n parec\u00eda estar mal configurado y no proporcionaba ninguna pol\u00edtica de seguridad de contenido ni encabezados de seguridad. Esto pod\u00eda provocar que se eludieran los filtros de Cross-Site Scripting. La versi\u00f3n 0.3.5 solucion\u00f3 el problema."
|
|
}
|
|
],
|
|
"metrics": {
|
|
"cvssMetricV31": [
|
|
{
|
|
"source": "security-advisories@github.com",
|
|
"type": "Secondary",
|
|
"cvssData": {
|
|
"version": "3.1",
|
|
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L",
|
|
"baseScore": 7.1,
|
|
"baseSeverity": "HIGH",
|
|
"attackVector": "NETWORK",
|
|
"attackComplexity": "LOW",
|
|
"privilegesRequired": "NONE",
|
|
"userInteraction": "REQUIRED",
|
|
"scope": "CHANGED",
|
|
"confidentialityImpact": "LOW",
|
|
"integrityImpact": "LOW",
|
|
"availabilityImpact": "LOW"
|
|
},
|
|
"exploitabilityScore": 2.8,
|
|
"impactScore": 3.7
|
|
}
|
|
]
|
|
},
|
|
"weaknesses": [
|
|
{
|
|
"source": "security-advisories@github.com",
|
|
"type": "Primary",
|
|
"description": [
|
|
{
|
|
"lang": "en",
|
|
"value": "CWE-1021"
|
|
}
|
|
]
|
|
}
|
|
],
|
|
"references": [
|
|
{
|
|
"url": "https://github.com/scidsg/hushline/security/advisories/GHSA-m592-g8qv-hrqx",
|
|
"source": "security-advisories@github.com"
|
|
}
|
|
]
|
|
} |