Skip to content

XSS vulnerability in inventory data

Moderate
amousset published GHSA-46gg-9hhj-xh3f Jul 11, 2023

Package

rudder-webapp (rudder)

Affected versions

< 6.1.14
>= 6.2.0, < 6.2.8

Patched versions

6.1.14
6.2.8

Description

Impact

There are possible XSS in the nodes list page through some inventory items.

Patches

6.1.14 and 6.2.8 which were released on 2021/07/09.

Workarounds

None.

References

#19456 on the bug tracker

Severity

Moderate

CVE ID

No known CVE

Weaknesses