VulnerabilityModified
CVE-2020-15951
Immuta v2.8.2 accepts user-supplied project names without properly sanitizing the input, allowing attackers to inject arbitrary HTML content that is rendered as part of the application.
MEDIUM 6.1EPSS 0.97%
Does this matter?
Lower severity and a low EPSS score (0.97%). Track it; it rarely justifies an emergency change on its own.
Description
Immuta v2.8.2 accepts user-supplied project names without properly sanitizing the input, allowing attackers to inject arbitrary HTML content that is rendered as part of the application. An attacker could leverage this to redirect application users to a phishing website in an attempt to steal credentials.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.97% probability · 60th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- immuta/immuta
- Source
- cve@mitre.org
References
- https://labs.bishopfox.com/advisoriesExploit, Third Party Advisory
- https://labs.bishopfox.com/advisories/immuta-version-2.8.2Release Notes, Third Party Advisory
- https://www.immuta.com/Product
- https://labs.bishopfox.com/advisoriesExploit, Third Party Advisory
- https://labs.bishopfox.com/advisories/immuta-version-2.8.2Release Notes, Third Party Advisory
- https://www.immuta.com/Product
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.