mirror of
https://github.com/fkie-cad/nvd-json-data-feeds.git
synced 2025-07-09 16:05:11 +00:00
36 lines
1.5 KiB
JSON
36 lines
1.5 KiB
JSON
{
|
|
"id": "CVE-2024-5906",
|
|
"sourceIdentifier": "psirt@paloaltonetworks.com",
|
|
"published": "2024-06-12T17:15:53.000",
|
|
"lastModified": "2024-06-13T18:36:09.010",
|
|
"vulnStatus": "Awaiting Analysis",
|
|
"descriptions": [
|
|
{
|
|
"lang": "en",
|
|
"value": "A cross-site scripting (XSS) vulnerability in Palo Alto Networks Prisma Cloud Compute software enables a malicious administrator with add/edit permissions for identity providers to store a JavaScript payload using the web interface on Prisma Cloud Compute. This enables a malicious administrator to perform actions in the context of another user's browser when accessed by that other user."
|
|
},
|
|
{
|
|
"lang": "es",
|
|
"value": "Una vulnerabilidad de cross-site scripting (XSS) en el software Prisma Cloud Compute de Palo Alto Networks permite a un administrador malicioso con permisos de agregar/editar para proveedores de identidades almacenar un payload de JavaScript utilizando la interfaz web en Prisma Cloud Compute. Esto permite a un administrador malicioso realizar acciones en el contexto del navegador de otro usuario cuando ese otro usuario accede."
|
|
}
|
|
],
|
|
"metrics": {},
|
|
"weaknesses": [
|
|
{
|
|
"source": "psirt@paloaltonetworks.com",
|
|
"type": "Secondary",
|
|
"description": [
|
|
{
|
|
"lang": "en",
|
|
"value": "CWE-79"
|
|
}
|
|
]
|
|
}
|
|
],
|
|
"references": [
|
|
{
|
|
"url": "https://security.paloaltonetworks.com/CVE-2024-5906",
|
|
"source": "psirt@paloaltonetworks.com"
|
|
}
|
|
]
|
|
} |