Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:20915
HistoryJul 29, 2019 - 12:08 a.m.

Cross-Site Scripting (XSS)

2019-07-2900:08:35
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8

0.001 Low

EPSS

Percentile

50.8%

web-console is vulnerable to cross-site scripting. The vulnerability, caused by missing X-Frame-Options and CSRF protections, in the oauth/token/request endpoint could allow a remote attacker to retrieve a token for CLI usage when using non default configs.

0.001 Low

EPSS

Percentile

50.8%