Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-93pf-mrc8-4g3h: Konga is vulnerable to Cross Site Scripting (XSS) attacks

Konga v0.14.9 is vulnerable to Cross Site Scripting (XSS) via the username parameter.

ghsa
#xss#git

Konga is vulnerable to Cross Site Scripting (XSS) attacks

Moderate severity GitHub Reviewed Published May 14, 2024 to the GitHub Advisory Database • Updated May 14, 2024

ghsa: Latest News

GHSA-675f-rq2r-jw82: JWK Set's HTTP client only overwrites and appends JWK to local cache during refresh