CVE-2019-20903-アトラスキット/エディターコアのXSS
説明
The hyperlinks functionality in atlaskit/editor-core in before version 113.1.5 allows remote attackers to inject arbitrary HTML or JavaScript via a Cross-Site Scripting (XSS) vulnerability in link targets.
Affected versions:
- バージョン < 113.1.5
Fixed versions:
- 113.1.5
深刻度
This is an independent assessment and you should evaluate its applicability to your own IT environment.
CVSS v3 score: 5.4 => Medium severity
Exploitability Metrics
攻撃ベクトル | ネットワーク |
---|---|
攻撃の複雑さ | 低 |
必要な権限 | 低 |
ユーザー相互作用 | 必須 |
Scope Metric
範囲 | Changed |
---|
Impact Metrics
機密性 | 低 |
---|---|
整合性 | 低 |
可用性 | なし |
https://asecurityteam.bitbucket.io/cvss_v3/#CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
最終更新日: 2020 年 10 月 1 日
Powered by Confluence and Scroll Viewport.