mirror of
https://github.com/fkie-cad/nvd-json-data-feeds.git
synced 2025-05-28 01:02:25 +00:00
76 lines
2.8 KiB
JSON
76 lines
2.8 KiB
JSON
{
|
|
"id": "CVE-2024-26140",
|
|
"sourceIdentifier": "security-advisories@github.com",
|
|
"published": "2024-02-20T22:15:08.950",
|
|
"lastModified": "2024-02-22T19:07:37.840",
|
|
"vulnStatus": "Awaiting Analysis",
|
|
"cveTags": [],
|
|
"descriptions": [
|
|
{
|
|
"lang": "en",
|
|
"value": "com.yetanalytics/lrs is the Yet Analytics Core LRS Library. Prior to version 1.2.17 of the LRS library and version 0.7.5 of SQL LRS, a maliciously crafted xAPI statement could be used to perform script or other tag injection in the LRS Statement Browser. The problem is patched in version 1.2.17 of the LRS library and version 0.7.5 of SQL LRS. No known workarounds exist."
|
|
},
|
|
{
|
|
"lang": "es",
|
|
"value": "com.yetanalytics/lrs es la librer\u00eda LRS principal de Yet Analytics. Antes de la versi\u00f3n 1.2.17 de la librer\u00eda LRS y la versi\u00f3n 0.7.5 de SQL LRS, se pod\u00eda utilizar una declaraci\u00f3n xAPI creada con fines malintencionados para realizar una inyecci\u00f3n de script u otras etiquetas en el navegador de declaraciones LRS. El problema se solucion\u00f3 en la versi\u00f3n 1.2.17 de la librer\u00eda LRS y en la versi\u00f3n 0.7.5 de SQL LRS. No existen workarounds conocidas."
|
|
}
|
|
],
|
|
"metrics": {
|
|
"cvssMetricV31": [
|
|
{
|
|
"source": "security-advisories@github.com",
|
|
"type": "Secondary",
|
|
"cvssData": {
|
|
"version": "3.1",
|
|
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L",
|
|
"attackVector": "NETWORK",
|
|
"attackComplexity": "LOW",
|
|
"privilegesRequired": "LOW",
|
|
"userInteraction": "REQUIRED",
|
|
"scope": "UNCHANGED",
|
|
"confidentialityImpact": "NONE",
|
|
"integrityImpact": "LOW",
|
|
"availabilityImpact": "LOW",
|
|
"baseScore": 4.6,
|
|
"baseSeverity": "MEDIUM"
|
|
},
|
|
"exploitabilityScore": 2.1,
|
|
"impactScore": 2.5
|
|
}
|
|
]
|
|
},
|
|
"weaknesses": [
|
|
{
|
|
"source": "security-advisories@github.com",
|
|
"type": "Secondary",
|
|
"description": [
|
|
{
|
|
"lang": "en",
|
|
"value": "CWE-79"
|
|
}
|
|
]
|
|
}
|
|
],
|
|
"references": [
|
|
{
|
|
"url": "https://clojars.org/com.yetanalytics/lrs/versions/1.2.17",
|
|
"source": "security-advisories@github.com"
|
|
},
|
|
{
|
|
"url": "https://github.com/yetanalytics/lrs/commit/d7f4883bc2252337d25e8bba2c7f9d172f5b0621",
|
|
"source": "security-advisories@github.com"
|
|
},
|
|
{
|
|
"url": "https://github.com/yetanalytics/lrs/releases/tag/v1.2.17",
|
|
"source": "security-advisories@github.com"
|
|
},
|
|
{
|
|
"url": "https://github.com/yetanalytics/lrs/security/advisories/GHSA-7rw2-3hhp-rc46",
|
|
"source": "security-advisories@github.com"
|
|
},
|
|
{
|
|
"url": "https://github.com/yetanalytics/lrsql/releases/tag/v0.7.5",
|
|
"source": "security-advisories@github.com"
|
|
}
|
|
]
|
|
} |