Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:28495
HistoryDec 06, 2020 - 4:49 a.m.

Cross-Site Scripting (XSS)

2020-12-0604:49:51
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9
pcs:stretch
cross-site scripting
node name
validation
inject
execute
arbitrary
javascript
clusters

EPSS

0.001

Percentile

36.4%

pcs:stretch is vulnerable to a cross-site scripting. Improper validations of Node name field allow attackers to inject and execute arbitrary Javascript when creating or adding existing clusters.