Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:40426
HistoryMay 09, 2023 - 4:20 a.m.

Cross Site Scripting (XSS)

2023-05-0904:20:41
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12
cross site scripting
onos-api
authorizationurl
yaml file
vulnerability

EPSS

0.001

Percentile

39.8%

onos-api is vulnerable to Cross Site Scripting. The vulnerability exists due to the vulnerable swagger dependency used in the library since it does not properly sanitize the authorizationUrl, which allows an attacker to execute arbitrary code when uploading a crafted YAML file.

EPSS

0.001

Percentile

39.8%

Related for VERACODE:40426