Headline
GHSA-xr7p-8q82-878q: teler dashboard vulnerable to DOM-based cross-site scripting (XSS)
Description
teler prior to version <= 2.0.0-rc.4 is vulnerable to DOM-based cross-site scripting (XSS) in the teler dashboard. When teler requests messages from the event stream on the /events
endpoint, the log data displayed on the dashboard are not sanitized.
Impact
This only affects authenticated users and can only be exploited based on detected threats if the log contains a DOM scripting payload. This indicates a low severity and there is no significant impact on the users.
Affected Version
This issue was introduced from version v2.0.0-rc
to v2.0.0-rc.3
& v2.0.0-dev
.
Patches
This vulnerability has been fixed on version v2.0.0-rc.4
& v2.0.0-dev.2
.
Workarounds
Here are some workarounds to handle this case:
- Deactivate the live event dashboard from the configuration file, or
- Upgrade teler version to
v2.0.0-rc.4
orv2.0.0-dev.2
& above.
References
- https://github.com/kitabisa/teler/commit/20f59eda2420ac64e29f199a61230a0abc875e8e
Description
teler prior to version <= 2.0.0-rc.4 is vulnerable to DOM-based cross-site scripting (XSS) in the teler dashboard. When teler requests messages from the event stream on the /events endpoint, the log data displayed on the dashboard are not sanitized.
Impact
This only affects authenticated users and can only be exploited based on detected threats if the log contains a DOM scripting payload. This indicates a low severity and there is no significant impact on the users.
Affected Version
This issue was introduced from version v2.0.0-rc to v2.0.0-rc.3 & v2.0.0-dev.
Patches
This vulnerability has been fixed on version v2.0.0-rc.4 & v2.0.0-dev.2.
Workarounds
Here are some workarounds to handle this case:
- Deactivate the live event dashboard from the configuration file, or
- Upgrade teler version to v2.0.0-rc.4 or v2.0.0-dev.2 & above.
References
- kitabisa/teler@20f59ed
References
- GHSA-xr7p-8q82-878q
- kitabisa/teler@20f59ed
Related news
teler is an real-time intrusion detection and threat alert dashboard. teler prior to version 2.0.0-rc.4 is vulnerable to DOM-based cross-site scripting (XSS) in the teler dashboard. When teler requests messages from the event stream on the `/events` endpoint, the log data displayed on the dashboard are not sanitized. This only affects authenticated users and can only be exploited based on detected threats if the log contains a DOM scripting payload. This vulnerability has been fixed on version `v2.0.0-rc.4`. Users are advised to upgrade. There are no known workarounds for this vulnerability.