Lucene search

K
osvGoogleOSV:GO-2024-2721
HistoryMay 09, 2024 - 10:01 p.m.

Cross site scripting in github.com/tiagorlampert/CHAOS

2024-05-0922:01:10
Google
osv.dev
6
cross site scripting
github
jwt token
malicious request
software

5.7 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.2%

A malicious actor may be able to extract a JWT token via malicious “/command” request. This is a form of cross site scripting (XSS).

5.7 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.2%