Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-fjhh-67wv-7gr4: Reflected Cross site scripting (XSS) in kairosdb

KairosDB through 1.2.2 has XSS in view.html because of showErrorMessage in js/graph.js, as demonstrated by view.html?q= with a ‘"sampling":{"value":"<script>’ substring.

ghsa
#xss#js#git

Reflected Cross site scripting (XSS) in kairosdb

Moderate severity GitHub Reviewed Published Nov 3, 2022 • Updated Nov 3, 2022

ghsa: Latest News

GHSA-qrm9-f75w-hg4c: Ash Authentication has flawed token revocation checking logic in actions generated by `mix ash_authentication.install`